Privacy Policy
The controller within the meaning of data protection law is:
Omnora GmbH
Gutleutstraße 163-167
60327 Frankfurt am Main
CEO: Sebastian Walker
VAT ID: DE278351416
HRB: 139240
Register court: Frankfurt am Main
Last updated: 18.09.2026
Collection of general information
When you access our website, information of a general nature is collected automatically. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider, the IP address of your device and similar data. This information is technically necessary to correctly deliver the website content you request and is inevitably generated when using the internet. The legal basis is our legitimate interest in the secure and stable provision of the website (Art. 6(1)(f) GDPR). The log data is deleted automatically after a short period.
Applicable legal bases
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. Where the legal basis is not specified in this privacy policy, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing to provide our services, perform contractual measures and respond to enquiries is Art. 6(1)(b) GDPR; the legal basis for processing to comply with our legal obligations is Art. 6(1)(c) GDPR; and the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) GDPR.
Cooperation with processors and third parties
Where, in the course of our processing, we disclose data to other persons or companies (processors or third parties), transfer data to them or otherwise grant them access to the data, this is done only on the basis of a legal permission (for example where a transfer of data to third parties such as payment service providers is necessary for the performance of a contract pursuant to Art. 6(1)(b) GDPR), where you have given your consent, where a legal obligation requires it or on the basis of our legitimate interests (for example when using agents, web hosts, etc.).
Where we engage third parties to process data on the basis of a data processing agreement, this is done on the basis of Art. 28 GDPR.
Our website is hosted by Webflow, Inc. (USA) on our behalf; the transfer to the USA is safeguarded by Webflow's certification under the EU-US Data Privacy Framework and the standard contractual clauses of the European Commission.
Transfers to third countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transferring data to third parties, this only takes place if it is necessary to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process or have data processed in a third country only where the special requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of an adequacy decision of the European Commission (for the USA, the adequacy decision of 10 July 2023, the EU-US Data Privacy Framework, for providers certified under it) or on the basis of the standard contractual clauses adopted by the European Commission. You can check whether a provider is certified under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.
Cookies / Cookiebot
Like many other websites, we use so-called "cookies" via the provider Cookiebot (Usercentrics A/S). Cookies are small text files that are transferred from a web server to your hard drive. Through them we automatically receive certain data about your computer and your internet connection, such as your IP address, the browser you use and your operating system.
Cookies cannot be used to launch programs or transfer viruses to a computer. Based on the information contained in cookies, we can make navigation easier for you and ensure that our web pages are displayed correctly.
Of course, you can also view our website without cookies. Internet browsers are usually set to accept cookies. You can deactivate the use of cookies at any time via your browser settings. Please use the help functions of your internet browser to find out how to change these settings. Please note that individual functions of our website may not work if you have deactivated the use of cookies.
This website distinguishes between technically necessary and technically non-necessary cookies. We use technically necessary cookies on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Non-necessary cookies (such as Google Analytics) are only set if the user has given consent. The legal basis for non-necessary cookies is your consent pursuant to Art. 6(1)(a) GDPR. This consent is stored in the form of a cookie, which is therefore technically necessary. You can change or withdraw your consent at any time by clicking the cookie icon at the bottom of the screen. An overview of the cookies used, including provider, purpose and storage period, can be found in the cookie settings.
Encryption
To protect the security of your data during transmission, we use state-of-the-art encryption methods (TLS) via HTTPS.
Deletion of data
We adhere to the principles of data minimisation and storage limitation. We therefore store your personal data only for as long as is necessary to achieve the purposes stated here or as required by the various retention periods provided for by law. Once the respective purpose no longer applies or these periods have expired, the corresponding data is routinely deleted or its processing restricted in accordance with statutory provisions.
Google services
We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google") described below. The information about your use of our website collected automatically by Google technologies is generally transferred to and stored on a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google's role (processor or independent controller) is indicated for each technology. Further information on data processing by Google can be found in Google's privacy notices.
Google LLC is certified under the EU-US Data Privacy Framework. In addition, our cooperation is based on the standard contractual clauses of the European Commission.
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is used for the technical management and deployment of scripts (e.g. for Google Analytics or marketing tools). The Tag Manager itself does not perform any analyses, does not store cookies and does not create its own usage profiles.
Technical data (e.g. IP address, browser information) is processed to deliver the Tag Manager. Where possible, the Tag Manager is not loaded directly from googletagmanager.com servers but via our own infrastructure (e.g. a so-called GTAG Gateway). This reduces the data transfer to Google and makes the processing of technical connection data more privacy-friendly.
The Tag Manager is used on the basis of Art. 6(1)(f) GDPR (legitimate interest in the efficient and data-protection-compliant management of tracking and marketing services). Where consent is required for the integrated tools, these are only activated by the Tag Manager once you have given your consent pursuant to Art. 6(1)(a) GDPR.
Google Analytics 4
We use Google Analytics 4 on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). With Google Analytics 4 we analyse the use of our website, compile reports on the activities of our visitors and evaluate them in order to optimise our content.
Google Analytics 4 uses cookies and similar technologies. However, the information collected about your use of the website (e.g. pages visited, browser information, operating system, click paths where applicable) is not passed directly to Google but is first processed via our server-side tagging server (SST), which we operate on Google Cloud Run in the EU-West 3 region (Frankfurt).
On this server, your data, in particular the IP address transmitted by your device, is anonymised or pseudonymised before it is forwarded to Google servers for further processing. In this way we reduce the direct exchange of data between your device and Google and strengthen the protection of your personal data.
The data is used by Google on our behalf exclusively to compile reports on website activity and to provide other services relating to website usage. According to our settings, the data is not combined with other Google data. The retention period for Analytics data is 14 months.
In addition, we use the Google Signals function within Google Analytics 4. It enables cross-device reporting, provided you have activated the "personalised advertising" option in your Google account. In this context we receive only anonymous, statistical evaluations and no personal data. You can deactivate this function at any time in your Google account settings.
The legal basis for the use of Google Analytics 4 is your consent pursuant to Art. 6(1)(a) GDPR, which you give via our cookie consent tool. Google Analytics 4 is not used without consent. You can withdraw your consent at any time with effect for the future via the consent tool.
We have concluded a data processing agreement with Google (Art. 28 GDPR). For any transfers to third countries (e.g. the USA), Google LLC is certified under the EU-US Data Privacy Framework; in addition, Google relies on the standard contractual clauses approved by the EU Commission. Further information can be found in Google's privacy notices at https://policies.google.com/privacy?hl=en and https://policies.google.com/technologies/partner-sites
In addition to Google Analytics 4, we also use our server-side tagging container (Google Cloud Run, EU-West 3 region / Frankfurt) to process and forward data to other marketing and analytics tools, e.g. Google Ads or the LinkedIn Conversions API.
The procedure is identical:
- Data on your use of the website is first transferred to our SST server in the EU.
- There, as far as technically possible, it is anonymised or pseudonymised (e.g. by truncating the IP address).
- Only then is the processed information forwarded to the respective providers.
These tools are used only with your express consent (Art. 6(1)(a) GDPR) via our cookie consent tool. Only purely technical log data required to ensure trouble-free operation and IT security may be processed on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Where we pass data to third-party providers (e.g. Google, LinkedIn) on the basis of your consent, data may also be processed in countries outside the EU (in particular the USA). In these cases the transfer is based on the EU-US Data Privacy Framework, the standard contractual clauses approved by the EU Commission or other safeguards.
You can withdraw your consent to the respective services at any time with effect for the future via our consent management tool.
Google Ads conversion tracking
We use Google Ads conversion tracking, a service provided by Google Ireland Limited.
If you reach our website via a Google ad, a cookie with a limited lifetime (max. 90 days) is stored, which serves exclusively to measure advertising effectiveness. We only learn aggregated values, such as how many users clicked on an ad and subsequently completed a conversion. Personal identification is not possible.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. No personal data is transferred without consent.
Google Ads Customer Match
We use the "Customer Match" and "conversion-based Customer Match" functions of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, on our website.
How it works: As part of these functions, data we have received from you (e.g. email address or telephone number) is transmitted to Google in pseudonymised form (hashed using SHA-256). Google matches these hash values against existing Google accounts. This enables us to target our ads more precisely at you or at audiences with similar interests (similar audiences) and to attribute conversions (e.g. blog sign-ups or purchases) more accurately.
Withdrawal: You can withdraw your consent at any time with effect for the future via our consent management tool, or deactivate the use of your data by Google in the Google ad settings (https://adssettings.google.com/).
Legal basis: This function is used exclusively on the basis of your express consent pursuant to Art. 6(1)(a) GDPR.
Data processing: Google processes this data as our processor. We have concluded a corresponding data processing agreement for this purpose. As Google is a US company, a transfer of the data to Google LLC in the USA and access by US authorities cannot be entirely ruled out. According to Google, the transmitted hash values are deleted immediately after the matching process.
Google Remarketing
This website uses the remarketing function of Google Ireland Limited. The function is used to present website visitors with interest-based advertisements within the Google advertising network. A so-called "cookie" is stored in the website visitor's browser, which makes it possible to recognise the visitor when they visit websites that belong to the Google advertising network. On these sites, visitors may be shown advertisements relating to content they previously viewed on websites that use Google's remarketing function. If you do not wish to use Google's remarketing function, you can generally deactivate it by adjusting the relevant settings at http://www.google.com/settings/ads. Alternatively, you can deactivate the use of cookies for interest-based advertising via the Network Advertising Initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.
The legal basis for the use of Google Remarketing is your consent pursuant to Art. 6(1)(a) GDPR, which you give via our consent tool and can withdraw at any time. Google is the independent controller for the subsequent processing in your Google account; the linking of data takes place only on the basis of consent that you give or withdraw with Google.
YouTube videos
We embed YouTube videos on some of our web pages. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; YouTube is a service of Google LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit a page with the YouTube plugin and agree to playback, a connection to YouTube servers is established. YouTube is thereby informed which pages you visit. If you are logged into your YouTube account, YouTube can attribute your browsing behaviour to you personally. You can prevent this by logging out of your YouTube account beforehand.
When a YouTube video is started, the provider sets cookies that collect information about user behaviour. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you give via our consent tool or by actively starting the video. The transfer to the USA is safeguarded by Google LLC's certification under the EU-US Data Privacy Framework.
Further information on data protection at YouTube can be found in the provider's privacy policy at: https://www.google.com/intl/en/policies/privacy/
Google Web Fonts
To display our content correctly and attractively across browsers, we use script libraries and font libraries such as Google Web Fonts (https://www.google.com/webfonts/) on this website. Google Web Fonts are transferred to your browser's cache to avoid multiple loading. If your browser does not support Google Web Fonts or blocks access, content is displayed in a standard font.
Calling up script libraries or font libraries automatically triggers a connection to the operator of the library. In doing so, your IP address is transmitted to the operator. This takes place only with your consent (Art. 6(1)(a) GDPR).
The privacy policy of the library operator Google can be found here: https://www.google.com/policies/privacy/
LinkedIn Insight Tag
We use the LinkedIn Insight Tag of the social network LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; "LinkedIn") on our website.
The LinkedIn Insight Tag enables us to identify visitors to our website as a target group for the delivery of ads ("LinkedIn Ads") and to measure the effectiveness of our advertising measures ("conversion tracking"). Via the tag, we can recognise you within the LinkedIn platform after a visit to our website and show you interest-based advertising there.
When you access our website, a direct connection to LinkedIn servers is established. The following data, among others, may be processed:
- HTTP headers (e.g. IP address, browser information, timestamp of the page view)
- Tag-specific data (tag ID, LinkedIn cookie information)
- Event data (e.g. pages viewed, product interactions, form submissions or purchases)
This data may be linked by LinkedIn to your LinkedIn account. LinkedIn may also use the data for its own purposes, e.g. for profiling or ad delivery. We have no influence over further data processing by LinkedIn.
In addition to the client-side Insight Tag, we use the LinkedIn Conversions API. Event data is transferred to LinkedIn server-side via our server-side tagging container (Google Cloud Run, EU-West 3 region, Frankfurt).
How it works:
- Your website interactions (e.g. purchases, leads, form completions) are first transmitted to our SST server.
- There, data is pseudonymised (e.g. by hashing email addresses with SHA-256) and then forwarded to LinkedIn via a secure interface.
- This ensures that sensitive data is not sent directly from your device to LinkedIn servers in the USA, but is first processed via our EU infrastructure.
The use of both the Insight Tag and the Conversions API serves marketing and optimisation purposes, i.e. the targeted delivery of advertising to relevant user groups and the statistical evaluation of our advertising campaigns.
Legal bases and data transfer
Legal basis: The LinkedIn Insight Tag and the Conversions API are used exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR. No processing takes place without your consent.
Withdrawal: You can withdraw your consent at any time via our consent management tool.
Transfers to the USA: Please note that data may also be transferred to the USA. LinkedIn Corporation (USA) is certified under the EU-US Data Privacy Framework (DPF), so that an adequate level of data protection is ensured. In addition, we rely on the standard contractual clauses (SCCs) approved by the EU Commission.
Further information on data processing by LinkedIn can be found in its privacy policy: https://www.linkedin.com/legal/privacy-policy
HubSpot
We use HubSpot, a service of HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany, to record the use of our website for statistical purposes. For this purpose, so-called "web beacons" and "cookies" are used, which are stored on your computer and enable us to analyse your use of the website. HubSpot evaluates the information collected (e.g. IP address, geographical location, type of browser, duration of the visit and pages accessed) on our behalf to generate reports on visits and pages viewed. We set these analytics cookies only with your consent pursuant to Art. 6(1)(a) GDPR, which you give via our consent tool and can withdraw at any time.
We also use HubSpot to process enquiries submitted via our website. For this purpose, the personal data you provide is processed in contact profiles and, where applicable, supplemented manually by us in order to inform you in a targeted manner about topics you prefer. The legal basis for processing your enquiry is Art. 6(1)(b) GDPR where it is aimed at concluding a contract, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries).
We also use HubSpot to send marketing emails. This includes the provision of content you request via our website (e.g. white papers or webinars). Emails are sent only on the basis of your consent (Art. 6(1)(a) GDPR), which we obtain via a double opt-in procedure. In order to design our emails according to your needs and continuously optimise them, opens and clicks are also analysed. You can unsubscribe from our marketing emails at any time by clicking the unsubscribe link in each email.
We have concluded a data processing agreement with HubSpot; the data is stored on servers in the EU. Access by HubSpot, Inc. (USA) in the course of support services is safeguarded by its certification under the EU-US Data Privacy Framework and the standard contractual clauses. Further information on how HubSpot works can be found in HubSpot's privacy policy at: https://legal.hubspot.com/privacy-policy
Processing of applicant data
To process applicant data and manage open positions, Omnora uses the applicant management system of Personio SE & Co. KG. CVs, documents and correspondence in the course of the application process are stored on Personio servers within the EU; a data processing agreement is in place with Personio. The legal basis for processing your applicant data is Section 26(1) of the German Federal Data Protection Act (BDSG) in conjunction with Art. 6(1)(b) GDPR. In addition, we may take into account publicly available information from professional networks (e.g. LinkedIn, XING); the legal basis for this is Art. 6(1)(f) GDPR.
Omnora will delete the data received during the application phase no later than six months after completion of the application process, unless the applicant has been hired by Omnora or otherwise works with Omnora. If Omnora intends to add your data to its talent pool in order to consider you for future positions, we will obtain your separate consent for this; in that case we store your data for two years from the date of your consent. You can withdraw your consent at any time with effect for the future by informing us informally; we will then delete your data.
Use of the Omnora application
We provide the web application offered by Omnora (the "Application") to our customers as software as a service. If you use the Application as an employee or representative of one of our customers, the customer is the controller under data protection law for the processing of your data in the Application. We process this data as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR and only on the customer's instructions. This concerns the email address used during registration, other account data provided by the customer or by you and, where created and/or processed with the Application, audio and video recordings of persons. The email address is required to create and access the user account; its authenticity is verified by an activation email. Additional details that can be entered in the Application (such as a telephone number or name) are voluntary. Please direct requests for information about this processing and the exercise of your rights to the customer; we will support the customer in doing so.
The Application uses AI-supported functions, including for transcription, speech output, text generation and AI-led interviews. The sub-processors used for these functions are listed in the list of sub-processors in the data processing agreement. We indicate within the Application when you are interacting with an AI system.
For the analysis and improvement of our Application, for in-app communication and product feedback, we process the data described below under our own responsibility on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the further development and stability of the Application and in supporting its users. Cookies and similar technologies in the Application are set for this purpose only with your consent, which you give in the Application's cookie banner and can withdraw at any time. You may also object to the processing at any time (see the section "Your rights").
Intercom
We use "Intercom" from Intercom, Inc., 55 2nd Street, San Francisco, CA 94105, USA, to better understand your use of our Application. In particular, we provide Intercom with a limited set of your data (such as the registration date and some personal data such as your email address) and use Intercom to collect data for analysis purposes when you use our Application. As an analytics service acting on our behalf, Intercom analyses your use of our Application and logs your activities using cookies and similar technologies so that we can improve our service for you. Further information on Intercom's use of cookies can be found at https://www.intercom.com/terms-and-policies#cookie-policy. We also use Intercom as a communication medium, either by email or via messages within our Application, to provide you with relevant information and assistance for optimal use. For further information on Intercom's privacy policy, please visit https://www.intercom.com/terms-and-policies#privacy. The transfer to the USA is safeguarded by Intercom's certification under the EU-US Data Privacy Framework and the standard contractual clauses.
Productboard
We use "Productboard" from Productboard, Inc., 612 Howard Street, San Francisco, CA 94105, USA, to better understand your requirements for using our Application. In particular, we provide Productboard with a limited set of your data (such as your email address) as soon as you vote for a feature or submit a product idea. Further information on Productboard's privacy policy can be found at https://www.productboard.com/privacy-policy/. The transfer to the USA is safeguarded by Productboard's certification under the EU-US Data Privacy Framework and the standard contractual clauses.
PostHog
To analyse the use of our Application, we use PostHog from PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. A pseudonymous user identifier, usage events and device and browser data are processed. The transfer to the USA is safeguarded by the EU-US Data Privacy Framework and the standard contractual clauses.
Your rights to information, rectification, erasure, restriction of processing and objection; withdrawal of consent
You have the right to request confirmation as to whether data concerning you is being processed and to obtain information about this data as well as further information and a copy of the data in accordance with Art. 15 GDPR.
In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
In accordance with Art. 17 GDPR, you have the right to request that data concerning you be erased without undue delay or, alternatively, to request a restriction of the processing of the data in accordance with Art. 18 GDPR.
You have the right to receive the data concerning you that you have provided to us in accordance with Art. 20 GDPR and to request its transmission to other controllers.
You have the right to withdraw consent you have given pursuant to Art. 7(3) GDPR with effect for the future.
Right to object under Art. 21 GDPR: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR. Where your personal data is processed for direct marketing purposes, you have the right to object at any time and without giving reasons to such processing. Objections can be sent informally to datasecurity@omnora.com.
You also have the right under Art. 77 GDPR to lodge a complaint with the competent supervisory authority. The supervisory authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, https://datenschutz.hessen.de.
Changes to this privacy policy
We reserve the right to amend this privacy policy from time to time so that it always complies with current legal requirements or to reflect changes to our services in the privacy policy, e.g. when introducing new services. The new privacy policy will then apply to your next visit.
Questions for the data protection officer
If you have any questions about data protection, please send us an email or contact our data protection officer directly: datasecurity@omnora.com