Privacy Policy of DiBike Digitize Bike Business Group GmbH & Co. KG

Status: June 2026

1. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

DiBike Digitize Bike Business Group GmbH & Co. KG
Reinhardtstraße 7
10117 Berlin
Germany

E-mail: kontakt@dibike.org
Website: https://dibike.org

Represented by its general partner DiBike Verwaltungs GmbH, represented by Managing Director Nick Becker.

2. General Information on Data Processing

The protection of personal data is important to us. We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR).
We aim to process personal data in a data-minimizing manner and limit processing to the information required for the respective purpose.
Depending on the specific use case, data processing is carried out in particular on the basis of legal permissions, contractual necessity, or granted consent.
Our website and digital services use SSL/TLS encryption to protect confidential information during transmission.

3. Website Usage and Hosting
Hosting

The general DiBike websites and web presences are operated and hosted via Hostinger. When these websites are accessed, technical information required for the operation and security of the website is automatically processed.

For prototypes, demos, landing pages, test versions or pre-release versions of digital services, DiBike may additionally use external development and hosting services, in particular Lovable. Where personal data is submitted via such prototypes or demos, it will be processed exclusively for the purposes specified in each case, for example for registering interest, testing processes or preparing digital services.

When our website is accessed, technical information required for the operation and security of the website is automatically processed. This includes in particular:

  • IP address

  • date and time of access

  • browser type and browser version

  • operating system

  • referrer URL

  • accessed pages

Processing is carried out for the provision of the website, system security, and error analysis.

Cookies and Consent Management

Our website uses cookies and similar technologies.
Some cookies are technically necessary to provide the website. Additional cookies or tracking technologies are only used based on the respective user consent.
Cookie settings are managed via the consent tool CookieYes.

Provider:
CookieYes Limited
Warren Yard, Wolverton Mill, Milton Keynes
England, MK12 5NW, United Kingdom

Further information: https://www.cookieyes.com/privacy-policy/

Google Analytics

We use Google Analytics to analyze and improve our online offering.
Google Analytics uses cookies that enable an analysis of the use of our website. Personal data, in particular IP addresses and usage data, may be processed in this context.

Provider:
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland

A transfer of personal data to the United States cannot be excluded. Google relies on appropriate safeguards for such data transfers, in particular Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.
Google Analytics is used exclusively on the basis of the respective user consent.

Further information: https://policies.google.com/privacy

4. Contact

If you contact us, for example by e-mail, contact form, or chat function, we process the data you provide for the purpose of handling your request.
This includes in particular:

  • name

  • e-mail address

  • telephone number

  • company information

  • contents of the request or communication

Processing is carried out exclusively for communication purposes and to handle the respective request.

Contact Forms

Our website contains contact forms through which inquiries can be submitted to us.

Brevo Chat

We use a chat function provided by Brevo on our website.
In particular, the following data may be processed:

  • name

  • e-mail address

  • chat contents

  • technical connection data

Processing is carried out for handling support or contact inquiries.

Provider:
Brevo (Sendinblue GmbH)
Köpenicker Straße 126
10179 Berlin
Germany

Further information: https://www.brevo.com/legal/privacypolicy/

5. Newsletter and Communication

We use Brevo to send our newsletter.
If you subscribe to our newsletter, we process in particular:

  • e-mail address

  • optionally name

  • technical information regarding registration and confirmation

Registration is carried out using the double opt-in procedure.
Processing is carried out exclusively for sending the newsletter and documenting the subscription.
Unsubscribing from the newsletter is possible at any time.

Provider:
Brevo (Sendinblue GmbH)
Köpenicker Straße 126
10179 Berlin
Germany

Further information: https://www.brevo.com/legal/privacypolicy/

6. Appointments and Forms
Calendly

We use Calendly for certain appointment bookings.
When using Calendly, personal data may be processed, in particular:

  • name

  • e-mail address

  • appointment and communication data

Provider:
Calendly LLC
Atlanta, USA

A transfer of personal data to the United States cannot be excluded. According to Calendly, appropriate safeguards for international data transfers are implemented.

Further information: https://calendly.com/privacy

Microsoft Bookings

We also use Microsoft Bookings for appointment scheduling and management.
The following data may in particular be processed:

  • name

  • e-mail address

  • appointment and communication data

  • organizational information related to the booking

Provider:
Microsoft Ireland Operations Limited
Dublin, Ireland

Further information: https://privacy.microsoft.com/en-us/privacystatement

Microsoft Forms

We use Microsoft Forms for certain forms, registrations, and partnership inquiries.
In particular, contact and company information may be processed.

Provider:
Microsoft Ireland Operations Limited
Dublin, Ireland

Further information: https://privacy.microsoft.com/en-us/privacystatement

7. User Accounts and Registrations

Certain digital services of DiBike may require user accounts or registrations.
In the context of registrations or user accounts, the following data may in particular be processed:

  • company name

  • contact person

  • e-mail address

  • login data

  • technical identifiers

  • IP address

  • registration and access timestamps

Processing is carried out for the provision of protected or registration-based services, user management, and system security.

8. Leasing-Check
General Description

Leasing-Check is a digital service provided by DiBike for the standardised verification of leasing status and service entitlements in company bike leasing.

The service enables registered and authorised bicycle retailers and workshops to retrieve certain leasing-related information from connected leasing providers. Use of the service is permitted exclusively in the context of specific service, maintenance or workshop processes.

Leasing-Check is designed as a read-only service. The service is not a contract platform, payment processing system, billing system or central contract database. DiBike does not carry out its own substantive review, modification or assessment of the contract and entitlement data provided by leasing providers.

Processed Data

In connection with Leasing-Check, the following personal data and technical information in particular may be processed:

Dealer and User Data
  • Company name

  • Address of the business location or usage unit

  • Contact person

  • Email address

  • Login data

  • retailerId

  • userId

  • systemId

  • Registration, activation and access data

  • IP address

Data of Technical Service Providers and ERP or Inventory Management Systems
  • Company name

  • Contact person

  • System information

  • Technical endpoints

  • Integration and registration data

  • API or system identifiers

Search Parameters
  • Email address of the leasing-eligible person

  • Contract number

  • Where applicable, further technical contract or process references, insofar as these are required for the respective query

The input of search parameters is only permitted if they are lawfully available in the context of a specific service, maintenance or workshop case.

Technical Log Data
  • Timestamp

  • IP address

  • retailerId

  • systemId

  • userId

  • Technical search parameters

  • Technical access information

  • Error and status messages

  • Access frequencies

Purpose of Processing

The processing is carried out in particular for the following purposes:

  • Registration, review and activation of retailers and workshops

  • Provision and operation of Leasing-Check

  • Authentication and authorisation of users and systems

  • Performance of service entitlement checks

  • Technical mediation and forwarding of requests to connected leasing providers

  • Display of the information provided by leasing providers

  • System security, error analysis and misuse detection

  • Traceability of access

  • Support, communication and technical assistance

  • Billing of paid services, where applicable


Legal bases

The processing of personal data in connection with Leasing-Check is carried out, depending on the respective processing activity, on the basis of the following legal bases:

  • Art. 6(1)(b) GDPR, insofar as the processing is necessary for registration, provision and use of Leasing-Check or for billing purposes

  • Art. 6(1)(f) GDPR, insofar as the processing is necessary for technical provision, system security, error analysis, misuse detection, logging and further development of the service

  • Art. 6(1)(c) GDPR, insofar as statutory retention or documentation obligations apply

  • Art. 6(1)(a) GDPR, insofar as processing is exceptionally based on consent, for example for certain communication or marketing functions


DiBike’s legitimate interests consist in particular in the secure, stable and misuse-protected operation of Leasing-Check as well as in the traceable and standardised provision of the service for the authorised market participants.

Disclosure of data to leasing providers

In connection with a specific Leasing-Check query, the data required for the query may be transmitted to connected leasing providers. This includes in particular:

  • Search parameters, e.g. email address or contract number

  • retailerId

  • systemId

  • Timestamp and technical context information


The transmission takes place exclusively for the purpose of processing the respective query. Leasing providers respond on the basis of their own data records. Leasing providers do not have mutual access to data, contract information or response data of other leasing providers.

The leasing providers remain independently responsible for the accuracy, timeliness and completeness of the contract, status and entitlement data they provide.

Data minimisation and no central contract database

Leasing-Check follows the principle of data minimisation. Only the data required for the respective query, the operation of the service, system security or misuse detection is processed.

DiBike does not store complete contract databases of the connected leasing providers. Query results and contract information are generally not stored permanently by DiBike, but are processed only to the extent necessary to carry out the specific query.

To avoid unnecessary duplicate queries and for technical mapping purposes, Leasing-Check may temporarily cache search parameters and technical mapping information. Such caching is limited to a maximum period of 12 hours. Contract, budget, service, or performance information is not permanently stored.

Logging and protection against misuse

To ensure proper and secure operation, technical access events are logged. This serves in particular to ensure system security, error analysis, misuse detection and the traceability of access.

Technical logs and security logs are generally stored only for a limited period and are usually deleted after no more than 30 days, unless longer storage is required for security, misuse prevention, documentation or legal reasons.

Hosting and Technical Service Providers

Leasing-Check is operated on servers within the European Union.
Technical service providers may be used for development, operation, and technical implementation.

The service is operated in particular using:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hosting)

  • Campudus GmbH, Ludwig-Erhard-Str. 13a, 84034 Landshut, Germany (technical development and implementation)

For prototypes, demos, test versions or pre-release versions of Leasing-Check, DiBike may additionally use external development and hosting services, in particular Lovable. Productive Leasing-Check queries and contract data are not permanently stored in such prototyping systems unless this is expressly stated.

Automated decision-making

Leasing-Check does not make automated decisions within the meaning of Art. 22 GDPR. The service presents information provided by leasing providers in a standardised form and supports the service decision in the workshop process. The substantive responsibility for contract status, service entitlements and budget information lies with the respective leasing provider.

9. Payment processing and invoicing

For paid services and agreements, DiBike processes personal data to the extent necessary for invoicing, payment processing, contract performance and compliance with statutory retention obligations.

This may include in particular the following data:

  • Name and company

  • Billing address

  • Email address

  • Contract and service data

  • Payment data

  • Invoice data

  • Transaction and payment status data

For invoicing, accounting and tax-related obligations, we use accounting and tax service providers. This may include, in particular, DATEV eG.

For paid subscriptions booked online via Leasing-Check, DiBike may use payment service providers. Where payments are processed via Mollie, additional data may be processed, in particular SEPA direct debit mandate data, transaction data and payment status data.

Provider:

Mollie B.V.
Keizersgracht 126
1015 CW Amsterdam
Netherlands

Further information: https://www.mollie.com/de/privacy

The processing is carried out on the basis of Art. 6(1)(b) GDPR, insofar as it is necessary for contract performance and payment processing, and on the basis of Art. 6(1)(c) GDPR, insofar as statutory retention or documentation obligations apply.

10. External Services and Third-Party Providers

External services or content may be integrated into our website or digital services.

Google Maps

We use Google Maps to display maps and location information.
When using Google Maps, IP addresses and technical usage data may in particular be transmitted to Google.

LinkedIn

Our website may contain links or embedded content from LinkedIn.
When accessing such content, personal data may be processed by LinkedIn.

Additional Services Used
  • Google Analytics

  • Brevo

  • Calendly

  • Microsoft Bookings

  • Microsoft Forms

When using these services, personal data may be processed by the respective providers.

In some cases, personal data may also be transferred to third countries, in particular the United States. Where required, providers rely on appropriate safeguards for such data transfers.

Further information:

LinkedIn: https://www.linkedin.com/legal/privacy-policy
Google: https://policies.google.com/privacy
Brevo: https://www.brevo.com/legal/privacypolicy/
Calendly: https://calendly.com/privacy
Microsoft: https://privacy.microsoft.com/en-us/privacystatement
Lovable: https://lovable.dev/privacy

11. Data Retention

We store personal data only for as long as this is necessary for the respective purposes or as long as statutory retention obligations apply.

The following principles apply in particular to Leasing-Check:

  • User and registration data is stored for the duration of the existing user account or registration and is subsequently deleted, unless statutory retention obligations apply

  • Query results and contract information are generally not stored permanently

  • Technical logs and security logs are usually deleted after no more than 30 days, unless longer storage is required to investigate misuse, security incidents or technical malfunctions, or to comply with legal obligations

  • Invoice and payment data is stored in accordance with statutory commercial and tax retention obligations

  • Communication and support data is deleted once it is no longer required for processing the respective matter, unless statutory retention obligations prevent deletion


Once personal data is no longer required for the respective purposes, it is deleted or anonymised.

12. Rights of Data Subjects

Within the scope of the applicable legal provisions, data subjects have in particular the following rights:

  • right of access

  • right to rectification

  • right to erasure

  • right to restriction of processing

  • right to data portability

  • right to object to processing

  • right to withdraw consent

  • right to lodge a complaint with a supervisory authority

To exercise your rights, you may contact us at any time.

13. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy where necessary, in particular in the event of further developments of our website, digital services, or changes in legal requirements.

The current version published on our website shall apply.

Digitize Bike Business

Open digital infrastructure for the bicycle industry

COnTACT

Networking

© 2025 DiBike Digitize Bike Business Group GmbH & Co. KG