Privacy Policy

1. Introduction and Scope

The protection of personal data and the confidentiality of information processed by our customers are of great importance to CleverApprove, operated by Zitouni GmbH.

This Privacy Policy explains the nature, scope and purposes of the processing of personal data in connection with the use of CleverApprove and the associated website.

CleverApprove is a web-based software solution for creating, managing and conducting digital approval and review processes. Among other things, users can use the platform to provide documents, files and content for review, grant approvals, exchange feedback and document processes in a traceable manner.

This Privacy Policy applies to:

  • the use of our website at www.cleverapprove.com,
  • the registration and management of user accounts,
  • the use of the CleverApprove platform,
  • communication with us, for example via support or contact channels,
  • the contractual processing and provision of our services.

We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and applicable national data protection provisions.

When using CleverApprove, our customers may process their own personal data and personal data of third parties within the platform, for example in documents, files, comments or approval processes. With regard to such data, we generally act as a processor within the meaning of Art. 28 GDPR. Responsibility for the lawfulness of the processing and compliance with information obligations towards data subjects remains with the respective customer as the controller.

Further information on processing on behalf of customers can be found in the section "Processing on Behalf of Customers pursuant to Art. 28 GDPR" of this Privacy Policy.

2. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Zitouni GmbH
Managing Director: Nabil Zitouni
Hauptstr. 43
69190 Walldorf
Germany

Email: support@cleverapprove.com

Website: www.cleverapprove.com

If you have any questions regarding data protection or wish to exercise your rights as a data subject, you may contact us at the address above at any time.

A Data Protection Officer has not currently been appointed, as the statutory requirements for mandatory appointment under Art. 37 GDPR are currently not met. If a Data Protection Officer is appointed in the future, their contact details will be published here.

3. Definitions

This Privacy Policy uses the terms defined in the General Data Protection Regulation (GDPR). Unless otherwise stated below, the definitions of Art. 4 GDPR apply.

The most important terms in connection with CleverApprove are:

Personal Data

Personal data means any information relating to an identified or identifiable natural person.

This includes, for example, names, email addresses, contact details, user information or information that can be attributed to a specific person.

Processing

Processing means any operation performed on personal data, whether or not by automated means. This includes, in particular, collecting, recording, storing, organizing, retrieving, using, transmitting, restricting or deleting data.

Data Subject

A data subject is any natural person to whom personal data relates.

Controller

The controller is the natural or legal person that determines the purposes and means of processing personal data.

Zitouni GmbH is the controller for personal data that we process ourselves. This includes, in particular, data relating to:

  • the use of our website,
  • the registration and management of user accounts,
  • contract management,
  • payment processing,
  • communication with users and customers,
  • support requests.

With regard to personal data that our customers enter into CleverApprove or process as part of their own processes, our customers generally determine the purposes and scope of processing. Our customers therefore remain the controllers within the meaning of the GDPR.

This applies in particular to personal data contained in documents, files, comments, approval processes or other content.

Processor

A processor processes personal data on behalf of a controller and exclusively in accordance with the controller's documented instructions.

Where our customers use CleverApprove to process their own content and personal data, Zitouni GmbH generally processes such data as a processor in accordance with Art. 28 GDPR.

Processing is carried out exclusively for the purpose of providing the CleverApprove platform, conducting approval processes and technically enabling the functions requested by the customer.

Sub-processors

A sub-processor is a service provider engaged by a processor that processes personal data in order to provide specific services.

Technical service providers may be used for the technical provision and operation of CleverApprove. These include, in particular:

  • technical service providers for server and system infrastructure,
  • providers for sending transactional emails,
  • payment service providers for processing subscriptions and payments.

The service providers used are carefully selected and involved only to the extent necessary. Processing is carried out on the basis of appropriate contractual agreements and in compliance with data protection requirements.

The technical infrastructure of CleverApprove is operated exclusively on servers located in Germany.

Content Data

Content data means all information and files that customers or users upload, store or process within CleverApprove as part of approval processes.

This may include, in particular:

  • documents and files,
  • texts and comments,
  • images and graphics,
  • approval decisions,
  • versions and change histories,
  • other content provided by the customer.

Such content may contain personal data, confidential information or, depending on the particular use case, special categories of personal data within the meaning of Art. 9 GDPR.

Zitouni GmbH processes this content exclusively for the technical provision of CleverApprove and for conducting the approval processes initiated by the customer.

Approval Recipients / Reviewers

Approval recipients or reviewers are persons invited by a customer to view, comment on or approve specific content within an approval process.

These persons may work within or outside the customer's organization.

The respective customer is responsible for ensuring that inviting approval recipients and disclosing content to them is lawful under applicable data protection law.

4. Purposes of Data Processing

We process personal data exclusively for the purposes for which it was collected and only to the extent necessary to provide, administer and improve our services.

The purposes of processing depend on whether we process personal data as controller or as processor.

4.1 Processing of Our Own Data by Zitouni GmbH

As the operator of CleverApprove, we process personal data of our customers, users and prospective customers in particular for the following purposes:

Provision and operation of CleverApprove
We process data to provide access to the platform, user accounts and the technical functions of CleverApprove.

Registration and management of user accounts
We process data to create and manage user accounts, including the administration of organizations, roles and permissions.

Contract performance and customer management
We process data to perform and manage our contractual relationships, including communication, plan management, billing and invoicing.

Payment processing
Required data is transmitted to payment service providers used by us for processing payments and subscriptions.

Communication and support
We process contact details and communication content in order to respond to inquiries, provide technical support and inform users about important information concerning their account or the platform.

Security and stability of the platform
We process technical information and log data to ensure the security, availability and functionality of CleverApprove and to detect and prevent unauthorized access, misuse and security incidents.

Further development and improvement of our services
We may use technical information and anonymized or aggregated data to further develop the functionality, security and usability of CleverApprove.

Compliance with legal obligations
We process data where necessary to comply with legal obligations, such as statutory commercial and tax retention requirements.

4.2 Processing of Customer Data in Connection with the Use of CleverApprove

CleverApprove enables our customers to process their own content and personal data within the platform and to conduct approval processes with internal and external participants.

Within a process, customers may add additional persons and assign different roles to them depending on the permissions granted. These may include, in particular:

  • reviewers / editors who check content and provide feedback,
  • colleagues or team members added for collaboration,
  • viewers who can view content or the status of a process.

Personal data processed in the course of such collaboration may include, in particular:

  • names and contact details of employees, customers, partners or other participants,
  • email addresses of invited users, reviewers and approval recipients,
  • roles and permissions within a process,
  • comments and feedback,
  • approval decisions,
  • timestamps and activities within an approval process.

In addition, customers may upload and process files and documents through CleverApprove. These may include, for example:

  • documents and files,
  • texts and comments,
  • images and graphics,
  • technical documents,
  • contracts or other business documents,
  • approval statuses and version information.

Depending on the customer's use of the platform, the content processed in CleverApprove may contain personal data, confidential information or special categories of personal data pursuant to Art. 9 GDPR.

Zitouni GmbH processes this data exclusively to provide the functions of CleverApprove, including:

  • storing and providing files,
  • organizing review and approval processes,
  • managing users, roles and permissions,
  • sending invitations, notifications and reminders,
  • documenting approval processes,
  • technically ensuring the operation of the platform.

No substantive analysis of files and information uploaded by customers is carried out. In particular, such data is not used for our own advertising purposes and is not used to train AI systems.

The processing of this data is carried out as processing on behalf of the respective customer pursuant to Art. 28 GDPR. The customer remains responsible for the lawfulness of the processing, the selection of participating persons and the assignment of access rights.

5. Legal Bases for Processing

Personal data is processed exclusively on the basis of applicable data protection laws, in particular the General Data Protection Regulation (GDPR).

Depending on the nature and purpose of the processing, processing is based on the following legal grounds:

5.1 Processing for the Performance of Contracts and Pre-Contractual Measures

Personal data is processed pursuant to Art. 6(1)(b) GDPR insofar as this is necessary for the performance of a contractual relationship with our customers.

This includes, in particular:

  • registration and management of user accounts,
  • provision and use of CleverApprove,
  • management of subscriptions and services,
  • communication relating to the performance of the contract,
  • provision of support services.

This also applies to pre-contractual measures, for example inquiries about our services or preparations for entering into a contract.

5.2 Processing Based on Legal Obligations

Personal data is processed pursuant to Art. 6(1)(c) GDPR where we are legally obliged to do so.

This includes, in particular:

  • statutory commercial and tax retention obligations,
  • statutory documentation and record-keeping obligations,
  • obligations towards authorities or other public bodies.

5.3 Processing Based on Legitimate Interests

Where necessary, we process personal data pursuant to Art. 6(1)(f) GDPR to protect our legitimate interests or the legitimate interests of third parties.

Our legitimate interests include, in particular:

  • ensuring the security and stability of CleverApprove,
  • protecting against misuse, unauthorized access and security incidents,
  • technical maintenance and further development of our platform,
  • troubleshooting and resolving technical issues,
  • improving the usability and performance of our services,
  • asserting or defending legal claims.

We always take into account the rights and interests of data subjects and carry out processing only where no overriding interests oppose it.

5.4 Processing Based on Consent

Where the processing of personal data is based on consent, it is carried out pursuant to Art. 6(1)(a) GDPR.

Consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before consent was withdrawn remains unaffected.

This may be relevant in particular if optional services or functions requiring consent are introduced in the future.

5.5 Processing of Customer Data on Behalf of Customers

Personal data that our customers enter into CleverApprove or process as part of their own approval processes is generally processed by Zitouni GmbH as a processor pursuant to Art. 28 GDPR.

The respective customer, as controller, determines the purpose and legal basis of this processing.

In particular, the customer is responsible for ensuring that:

  • an appropriate legal basis for processing exists,
  • data subjects have been properly informed,
  • invited reviewers, editors, colleagues or other participants are lawfully granted access to content.

6. Categories of Personal Data

Different categories of personal data may be processed as part of providing and using CleverApprove. The specific data processed depends on which functions are used and which content our customers enter into the platform.

6.1 Data of Customers, Users and Prospective Customers

When using our website, registering and managing customer accounts, the following personal data may be processed:

Master Data and Contact Data

This includes, in particular:

  • first and last name,
  • business email address,
  • company name,
  • department or organizational unit,
  • position or role,
  • contact details voluntarily provided by users.

Account and Access Data

This includes, in particular:

  • username or login details,
  • password (stored exclusively in encrypted or otherwise appropriately protected form),
  • information about user roles and permissions,
  • membership of organizations or workspaces.

Contract and Payment Data

This includes, in particular:

  • contract information,
  • selected plan,
  • subscription information,
  • billing information,
  • information relating to payment processing.

Payment data is processed through the payment service providers used for payment processing.

6.2 Usage and Technical Data

When using CleverApprove, technical information required for operation, security and further development of the platform may be processed.

This includes, in particular:

  • date and time of access,
  • browser information,
  • operating system information,
  • device information,
  • login timestamps,
  • technical events and error messages,
  • security and system logs.

Activities within the platform may also be documented, for example:

  • creation and modification of processes,
  • file uploads,
  • invitations of additional users,
  • changes to permissions,
  • approvals and rejections,
  • comments and feedback,
  • timestamps of actions.

This data serves, in particular, to ensure security, traceability and the proper functioning of the platform.

6.3 Data Within Approval Processes and Customer Processes

CleverApprove enables customers to conduct digital review and approval processes with internal and external participants.

Customers may process, in particular, the following personal data within the platform:

  • names of employees, customers, partners or other participants,
  • email addresses of reviewers, editors, colleagues or viewers,
  • roles and permissions within a process,
  • comments and annotations,
  • approval decisions,
  • processing and version information.

6.4 Content Data and Uploaded Files

Our customers can provide files and content within CleverApprove for review, coordination and approval.

This may include, in particular:

  • documents,
  • PDF files,
  • images and graphics,
  • texts,
  • presentations,
  • technical documents,
  • contracts,
  • print-ready files,
  • other business files.

The content may contain personal data, such as names, contact details or other information relating to natural persons.

Depending on the customer's area of use, uploaded content may also contain special categories of personal data pursuant to Art. 9 GDPR or other confidential information.

Zitouni GmbH does not select or determine the content uploaded by customers. The respective customer decides which data is processed within CleverApprove.

6.5 Communication Data

When customers or prospective customers contact us, for example by email or through support channels, the following data may be processed:

  • name,
  • email address,
  • communication content,
  • technical information relating to the inquiry,
  • information required to process the request.

This data is used exclusively to process the relevant inquiry and communicate with the user.

7. Visiting Our Website

When visiting our website at www.cleverapprove.com, the web server automatically processes information transmitted by your browser to our server.

This data is technically necessary to provide the website, ensure system stability and security, and detect potential errors or attacks.

The data processed may include, in particular:

  • IP address of the accessing device,
  • date and time of access,
  • pages and files accessed,
  • amount of data transferred,
  • browser type and version,
  • operating system,
  • referrer URL (previously visited website),
  • status information relating to the request.

This data is generally not combined with data from other sources.

Server log data is processed in particular for the following purposes:

  • ensuring trouble-free operation of the website,
  • maintaining technical security,
  • detecting and preventing misuse, attacks and security incidents,
  • troubleshooting and technical optimization.

Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is to provide a secure, stable and functional website and reliable services.

The technical infrastructure of CleverApprove is operated exclusively on servers in Germany. Accordingly, technical data generated when visiting our website is processed within Germany, unless expressly stated otherwise for specific external services.

Server log data is stored only for as long as necessary for the purposes stated above and is subsequently deleted or anonymized, unless statutory obligations or legitimate interests require longer retention.

8. Cookies and Similar Technologies

Our website and the CleverApprove platform use only technically necessary cookies and similar technologies that are required for secure and proper operation.

Cookies are small text files stored on your device that may contain certain technical information. They enable, among other things, the recognition of a session and the provision of specific functions.

We use cookies in particular for the following purposes:

  • maintaining user logins and sessions,
  • authenticating users,
  • protecting against unauthorized access,
  • ensuring technical security,
  • storing necessary technical settings,
  • ensuring the proper functioning of CleverApprove.

The cookies used do not contain information that is evaluated for advertising purposes. We do not analyze user behavior for marketing or tracking purposes.

As these cookies are technically necessary to provide the services and functions expressly requested by you, consent is not required for their use.

The legal basis for the use of technically necessary cookies is § 25(2) no. 2 of the German Telecommunications-Telemedia Data Protection Act (TDDDG) and Art. 6(1)(f) GDPR. Our legitimate interest is the secure and functional provision of our website and the CleverApprove platform.

We currently do not use analytics, statistics, marketing or tracking services.

9. Registration and User Account

Use of CleverApprove by customers and their internal users requires the creation of a user account. During registration and management of a user account, we process personal data required to provide and use the platform.

9.1 Creating a User Account

During registration, the following data may be processed:

  • first and last name,
  • business email address,
  • company name,
  • password,
  • information relating to the organization or workspace,
  • plan and account settings.

This data is processed to:

  • provide a user account,
  • enable access to the platform,
  • authenticate users,
  • provide CleverApprove functions,
  • perform contractual services.

Processing is carried out for the performance of the contract pursuant to Art. 6(1)(b) GDPR.

9.2 Managing Organizations, Users and Permissions

CleverApprove enables customers to manage internal users within their organization and organize collaboration within the platform.

Different roles and permissions may be assigned, including:

  • administrators,
  • creators of approval requests,
  • editors,
  • internal participants.

The following data may be processed for the management of these users:

  • name,
  • email address,
  • user role,
  • permissions,
  • membership of organizations or workspaces,
  • activities within the platform.

Roles and permissions are assigned by the respective customer. The customer is responsible for determining which persons receive access to its content and processes.

9.3 External Reviewers and Recipients of Approval Requests

CleverApprove enables customers to invite external persons to review or approve processes without requiring them to create their own CleverApprove user account.

Customers may, for example, add customers, business partners, clients or other external participants as reviewers or recipients.

The following data of an invited person may be processed for sending an approval request:

  • email address of the invited person,
  • optionally, salutation and name if provided when creating the approval request.

This data is processed to send the approval request, address the invited person and enable access to the relevant process.

The invited person receives an individual link by email through which they can access the associated process and, depending on the permissions defined by the customer, for example:

  • view files,
  • add comments,
  • provide feedback,
  • approve or reject content.

No separate user account is created for external reviewers. Access is limited to the specific process that has been shared with them.

The respective customer is responsible for:

  • selecting the invited persons,
  • ensuring the lawful disclosure of email addresses,
  • determining which content is made accessible to a person,
  • assigning and managing access rights.

9.4 Management and Security of User Accounts

To ensure secure operation of the platform, technical information relating to user accounts may be processed, including:

  • login timestamps,
  • technical session information,
  • security events,
  • failed login attempts.

Passwords are stored only in a technically appropriate form and are not stored in plain text.

Processing of this data is carried out to ensure the security and stability of CleverApprove on the basis of Art. 6(1)(f) GDPR.

9.5 Deletion of User Accounts and Access Data

User accounts are deleted when they are no longer required or the contractual relationship has ended, unless statutory retention obligations or legitimate interests prevent deletion.

Data relating to external recipients and reviewers is processed and deleted in accordance with the use of the relevant process and the settings and instructions of the customer.

The deletion of content and processes is governed by the contractual agreements and settings of the respective customer.

10. Use of CleverApprove and Processing of Customer Content

CleverApprove is a SaaS platform for the digital creation, management and execution of review and approval processes.

Customers can create processes within the platform, provide files, involve internal and external persons, and document reviews and approvals in a traceable manner.

The content and personal data processed in this context are used exclusively to provide the functions offered by CleverApprove.

10.1 Creation and Management of Approval Processes

Customers can create approval requests within CleverApprove and involve participating persons.

The following information may be processed, in particular:

  • name and information relating to a process,
  • creator of a process,
  • participating internal users,
  • invited reviewers and recipients,
  • roles and permissions,
  • comments and feedback,
  • approval status,
  • timestamps of actions,
  • version information.

This data serves to conduct, manage and document review and approval processes in a traceable manner.

10.2 Processing of Files and Documents

Customers can upload files and documents to CleverApprove for review and approval.

These may include, for example:

  • documents,
  • PDF files,
  • images and graphics,
  • presentations,
  • texts,
  • print-ready files,
  • technical documents,
  • other business files.

Uploaded content may contain personal data, such as names, contact details or other information relating to natural persons.

Depending on the customer's particular use case, files may also contain confidential information or special categories of personal data pursuant to Art. 9 GDPR.

Zitouni GmbH does not select or substantively evaluate files uploaded by customers. The customer decides which content is processed.

10.3 Collaboration and Involvement of Additional Persons

CleverApprove enables different participants to collaborate within an approval process.

Depending on their requirements, customers can involve internal users and external recipients.

Internal users may, for example, act as creators, editors or other participants within the customer's organization.

External reviewers or recipients do not receive their own CleverApprove user account. When invited, they receive an email containing an individual link through which they can access only the specific process shared with them.

The following data may be processed:

  • email address of the recipient,
  • optionally, recipient's name if provided by the customer,
  • information relating to the relevant approval process.

The customer is responsible for ensuring that invited persons are authorized to view or process the relevant content.

10.4 Comments, Feedback and Approval Decisions

As part of an approval process, participants may leave comments, annotations or other feedback.

Approval decisions and processing steps may also be documented, including:

  • approval,
  • rejection,
  • status changes,
  • timestamps of actions,
  • participating persons.

This information is used exclusively for collaboration, documentation and traceability within the respective process.

10.5 Versioning and Traceability

CleverApprove may store information relating to different versions and processing steps within a process.

This may include, in particular:

  • uploaded file versions,
  • changes to a process,
  • status changes,
  • approval histories,
  • timestamps and technical information relating to actions.

The storage of this information enables traceable documentation of review and approval processes.

10.6 Archiving of Processes

CleverApprove provides an archiving function for completed or no longer actively processed processes.

Customers can determine when processes are archived. Archiving can be:

  • defined generally for the organization,
  • configured individually for specific processes.

Unless the customer chooses different settings, the standard archiving period is 90 days.

During the archiving period, the associated data remains stored and available in accordance with the customer's permissions.

After the specified archiving period has expired, archived data is automatically deleted unless statutory obligations or other legitimate reasons prevent deletion.

The customer remains responsible for establishing appropriate retention and deletion periods for its own processes.

10.7 No Use of Customer Content for Our Own Purposes

Zitouni GmbH processes customer content exclusively for the technical provision of CleverApprove and for carrying out the approval processes requested by the customer.

Customer content is not used for our own purposes. In particular, customer content is not:

  • used for advertising purposes,
  • disclosed to other customers,
  • analyzed to create our own user profiles,
  • used to train AI systems.

Processing is carried out as processing on behalf of the respective customer pursuant to Art. 28 GDPR.

The customer remains responsible for the lawfulness of the processing, the selection of content and the authorization of participating persons.

11. Email Communication and Notifications

As part of the use of the platform, CleverApprove sends various automated emails required to provide and use its functions.

These include, in particular:

  • invitations to approval processes,
  • notifications about new or updated processes,
  • reminders regarding pending reviews or approvals,
  • information about status changes,
  • security and account notifications,
  • messages for restoring access.

11.1 Sending Approval Requests

When a customer sends an approval request to an internal or external person, CleverApprove processes the recipient data required for this purpose.

This may include, in particular:

  • email address of the recipient,
  • optionally, first and last name if provided by the customer,
  • information relating to the relevant approval process.

The data is used exclusively to send the approval request and enable access to the intended process.

The customer is responsible for ensuring that the disclosure and processing of recipient data is lawful.

11.2 Sending Technical and System-Related Messages

Additional emails may be sent for user account management and the technical provision of CleverApprove, including:

  • registration confirmations,
  • account security notifications,
  • password or access recovery messages,
  • important information about service operation.

These messages serve exclusively to perform the contract, maintain security and ensure proper use of the platform.

11.3 Use of an Email Delivery Service Provider

We use a technical service provider to send automated emails.

Transactional emails are sent via:

Mailjet GmbH
Alt-Moabit 2
10557 Berlin
Germany

Mailjet is a provider for sending electronic messages and supports us in the technical delivery of system and notification emails.

Processing is carried out exclusively for the purpose of email delivery and on the basis of a data processing agreement pursuant to Art. 28 GDPR.

The technical service provider receives only the data necessary to deliver the respective message.

11.4 No Use for Advertising Purposes

System and notification emails sent through CleverApprove are used exclusively to provide platform functions.

Email addresses used for such communications are not used for our own advertising purposes unless separate consent has been obtained.

12. Hosting, Infrastructure and Technical Service Providers

We use technical service providers to provide the server and system infrastructure required for the technical operation and provision of CleverApprove.

Personal data is processed exclusively in connection with the provision, maintenance and security of the CleverApprove platform.

12.1 Technical Operation and Hosting Infrastructure

The technical operation of CleverApprove is provided through our technical service provider:

ServiceSystems, Christian van de Velde
Auf der Wurth 3
26969 Butjadingen
Germany

This provider supplies the technical infrastructure and server systems required to operate the platform.

The servers used for this purpose, provided by Hetzner Online GmbH, are located exclusively in Germany.

The technical infrastructure is used in particular for:

  • operating the CleverApprove application,
  • storing and processing customer data and files,
  • providing platform functions,
  • carrying out technical maintenance,
  • ensuring system availability and stability,
  • creating and managing technical backups.

12.2 Processing by Technical Service Providers

Technical service providers receive access to personal data only to the extent necessary to provide their services.

Access may be required in particular for:

  • maintenance and troubleshooting,
  • ensuring technical operation,
  • resolving security or functional issues,
  • carrying out necessary administrative activities.

Processing is carried out on the basis of appropriate contractual agreements pursuant to Art. 28 GDPR.

Technical service providers are required to process personal data exclusively in accordance with documented instructions and to implement appropriate technical and organizational measures to protect the data.

12.3 Location of Data Processing

Data within the CleverApprove infrastructure is stored and processed exclusively on servers located in Germany.

CleverApprove's infrastructure does not store customer data or uploaded files on servers outside Germany.

Please note, however, that customers may send approval requests to external recipients. If such recipients access the provided content using their own systems or devices, further processing may take place outside Germany or outside the European Union, for example through the recipient's own email or IT systems.

Zitouni GmbH has no control over such processing by recipients or their service providers.

12.4 Other Service Providers Used

In addition to the hosting infrastructure, other technical service providers may be used where necessary for the operation of CleverApprove.

These include, in particular:

  • providers for sending automated emails,
  • payment service providers,
  • technical security and operational service providers.

An overview of the service providers used and their processing activities may form part of the information on our sub-processors.

13. Payment Processing

We use an external payment service provider to process paid subscriptions and payments.

13.1 Processing of Payment Data

Payment processing for CleverApprove is carried out via:

Stripe Payments Europe Limited

Stripe processes payment data in connection with payment processing, subscription management and payment transactions.

The data processed by Stripe may include, in particular:

  • name of the payer,
  • email address,
  • billing and payment information,
  • information about the selected plan,
  • transaction data,
  • information about the payment method.

Credit card and other payment details are not stored or fully processed by Zitouni GmbH. Such payment data is processed directly by Stripe as part of the payment process.

13.2 Purpose of Processing

Processing is carried out in particular for the following purposes:

  • entering into and managing subscriptions,
  • processing payments,
  • allocating payments to customer accounts,
  • creating and providing invoices,
  • managing payment status and contractual information.

Following successful payment, invoices are automatically sent to the email address provided by the customer.

13.3 Legal Basis and Responsibility

Processing is carried out for the performance of the contractual relationship pursuant to Art. 6(1)(b) GDPR and for compliance with legal obligations, in particular commercial and tax requirements pursuant to Art. 6(1)(c) GDPR.

Stripe processes certain payment data as an independent controller in connection with payment processing. Stripe's privacy policy applies additionally to processing carried out by Stripe.

Where Stripe acts as a service provider on our behalf, processing is carried out on the basis of appropriate contractual agreements.

14. Transfers to Third Countries

Customer data within the CleverApprove infrastructure is stored and processed exclusively on servers in Germany.

Customer data and uploaded files are generally not transferred by the CleverApprove infrastructure to countries outside the European Union (EU) or European Economic Area (EEA).

However, processing of personal data in third countries cannot be completely excluded in certain circumstances.

This may apply in particular to the following situations:

14.1 External Recipients of Approval Requests

Customers may send approval requests to external persons who may use their own IT systems or email services whose servers are located outside the EU or EEA.

If a recipient uses a CleverApprove approval link or processes information transmitted by email, personal data may be processed by the recipient's systems or service providers outside the EU.

Zitouni GmbH has no control over such processing by the respective recipient or their service providers.

The customer is responsible for ensuring the lawfulness of transferring data to the recipients selected by the customer.

14.2 Service Providers Used

For certain service providers used by us, processing in third countries may be possible due to their corporate structure or technical infrastructure.

Where personal data is transferred to third countries, we ensure that the requirements of Art. 44 et seq. GDPR are complied with.

Appropriate safeguards may include, in particular:

  • an adequacy decision by the European Commission,
  • Standard Contractual Clauses issued by the European Commission,
  • other safeguards permitted under the GDPR.

Information on the service providers used and the applicable data protection safeguards can be found in the information on our technical service providers and sub-processors.

15. Retention and Deletion

We retain personal data only for as long as necessary for the respective processing purposes or as required by statutory obligations.

The specific retention period depends on the type of data and how CleverApprove is used.

15.1 User Account Data

User account data is stored for as long as the user account exists and is required to provide CleverApprove.

After termination of the contractual relationship or deletion of an account, the associated data is deleted unless statutory retention obligations or legitimate reasons require continued storage.

15.2 Data Within Approval Processes

Processes, files, comments, approvals and associated information created by customers within CleverApprove are stored for as long as necessary for use of the platform and the processes intended by the customer.

Customers can manage the archiving of their processes through the relevant CleverApprove settings.

15.3 Archiving and Automatic Deletion

CleverApprove provides an archiving function for completed or no longer actively processed processes.

Customers can determine when processes are archived:

  • generally for their organization,
  • individually for specific processes.

Unless a different setting is selected, the standard archiving period is 90 days.

After the specified archiving period has expired, archived data is automatically deleted unless statutory obligations or other legitimate reasons prevent deletion.

15.4 Backups

Regular technical backups are created to ensure system availability and recoverability.

Backups are used exclusively for:

  • restoring the platform in the event of technical failures,
  • protecting against data loss,
  • ensuring reliable operation.

Data deleted from the active system may remain in existing backups for a limited period.

Deletion from backups takes place as part of the regular backup rotation and technical deletion processes.

Access to backup data is limited to cases where it is necessary for restoration purposes, technical maintenance or security measures.

15.5 Statutory Retention Obligations

Where data is subject to statutory retention obligations, in particular tax or commercial records such as invoices and payment records, it is stored for the periods required by law.

Such data is processed exclusively to comply with the respective legal obligations and is deleted after the retention periods have expired.

15.6 Deletion by the Customer

Customers can delete data or control its archiving using the available CleverApprove functions.

The customer remains responsible for establishing and complying with appropriate retention and deletion periods for the personal data it processes.

16. Technical and Organizational Measures

We implement appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR to protect personal data.

These measures are designed in particular to protect personal data against unauthorized access, loss, alteration or unlawful processing and to ensure an appropriate level of security corresponding to the risks associated with the processing.

The measures implemented include, in particular:

16.1 Protection of Data Transmission

Communication between users and the CleverApprove platform takes place via encrypted connections.

This protects data during transmission against unauthorized access.

16.2 Access Controls and Permissions

Access to data and functions within CleverApprove is controlled through a role- and permission-based access system.

This ensures that:

  • users can access only content made available to them,
  • customers can manage their own users and permissions,
  • external reviewers have access only to the specific processes shared with them.

16.3 Protection of User Accounts

Appropriate security measures are used to protect user accounts.

These include, in particular:

  • secure authentication procedures,
  • protected storage of access credentials,
  • measures against unauthorized access,
  • logging of security-relevant events.

16.4 Protection of Server and System Infrastructure

The technical infrastructure of CleverApprove is operated on servers located in Germany.

Measures used to protect the infrastructure include, in particular:

  • secure server configuration,
  • regular technical maintenance,
  • protection against unauthorized access,
  • ensuring system availability,
  • regular backups.

16.5 Confidentiality and Access by Service Providers

Technical service providers receive access to personal data only to the extent necessary for operation, maintenance or technical support.

Processing is carried out on the basis of appropriate contractual agreements and in accordance with GDPR requirements.

16.6 Further Development of Security Measures

Technical and organizational measures are regularly reviewed and developed further in accordance with technological developments and data protection requirements.

Complete security of data transmission or IT systems cannot be technically guaranteed. However, we implement appropriate measures to reduce the risk of unauthorized processing or data loss.

17. Processing on Behalf of Customers Pursuant to Art. 28 GDPR

17.1 Processing Customer Data on Behalf of Our Customers

When using CleverApprove, our customers may process personal data relating to their own customers, employees, business partners or other participants within the platform.

This may include, in particular:

  • names and contact details,
  • email addresses,
  • information about persons participating in approval processes,
  • documents and files containing personal data,
  • comments, feedback and approval information.

The respective CleverApprove customer is generally the controller within the meaning of the General Data Protection Regulation for this data.

Zitouni GmbH processes this data exclusively on behalf of the customer and for the provision of CleverApprove services.

17.2 Data Processing Agreement

Processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.

The data processing agreement governs, in particular:

  • subject matter and duration of processing,
  • nature and purpose of processing,
  • categories of personal data,
  • categories of data subjects,
  • obligations and rights of the customer,
  • technical and organizational measures,
  • handling of sub-processors,
  • support in responding to data subject requests and complying with data protection obligations.

17.3 Processing Exclusively in Accordance with Instructions

Zitouni GmbH processes customer personal data exclusively in accordance with documented instructions from the respective customer.

Customer content is not used for our own purposes.

In particular, customer data is not:

  • sold,
  • used for our own marketing purposes,
  • combined with data belonging to other customers,
  • used for our own analyses outside the technical operation of the platform.

17.4 Use of Sub-Processors

Technical service providers may be used to provide CleverApprove and may act as sub-processors pursuant to Art. 28 GDPR.

These include, in particular:

  • ServiceSystems, Christian van de Velde, as the technical operator of the infrastructure,
  • other technical service providers required for hosting, email delivery or secure operation.

Sub-processors are engaged only if they provide appropriate guarantees for the protection of personal data and appropriate contractual agreements are in place.

An up-to-date list of the sub-processors used may form part of CleverApprove's contractual and data protection information.

17.5 Customer Responsibility

The customer remains responsible for:

  • the lawfulness of processing its data,
  • the selection of content processed in CleverApprove,
  • informing data subjects,
  • assigning access rights,
  • complying with its own data protection obligations.

Zitouni GmbH supports the customer, within the scope of contractual agreements and available technical capabilities, in fulfilling its data protection obligations.

18. Rights of Data Subjects

Under the General Data Protection Regulation, data subjects have various rights regarding the processing of their personal data.

18.1 Rights vis-à-vis Zitouni GmbH

Where Zitouni GmbH processes personal data as controller, for example in connection with the website, registration of a user's own account or contract management, data subjects may exercise their data protection rights directly against Zitouni GmbH.

These rights include, in particular:

Right of Access (Art. 15 GDPR)
Data subjects have the right to obtain information about whether and which personal data concerning them is being processed.

Right to Rectification (Art. 16 GDPR)
Data subjects may request the correction of inaccurate personal data or completion of incomplete personal data.

Right to Erasure (Art. 17 GDPR)
Data subjects may request the deletion of their personal data under the statutory conditions.

Right to Restriction of Processing (Art. 18 GDPR)
Data subjects may, under certain conditions, request restriction of the processing of their personal data.

Right to Data Portability (Art. 20 GDPR)
Under the statutory conditions, data subjects have the right to receive personal data in a structured, commonly used and machine-readable format or to request its transmission to another controller.

Right to Object (Art. 21 GDPR)
Data subjects may object to the processing of their personal data where the statutory requirements are met.

Withdrawal of Consent (Art. 7(3) GDPR)
Where processing is based on consent, consent may be withdrawn at any time with effect for the future.

18.2 Rights Relating to Customer Data Within CleverApprove

Personal data processed by our customers within CleverApprove is processed by Zitouni GmbH exclusively as a processor pursuant to Art. 28 GDPR.

In these cases, the respective CleverApprove customer is the controller within the meaning of the GDPR.

Data subjects should therefore generally contact the respective customer that processes their data within CleverApprove.

Zitouni GmbH supports customers, within the scope of its statutory obligations and contractual agreements, in handling such requests where necessary and technically possible.

18.3 Exercising Data Protection Rights

To exercise data protection rights, data subjects may contact us:

Zitouni GmbH
Managing Director: Nabil Zitouni
Hauptstr. 43
69190 Walldorf
Germany

Email: support@cleverapprove.com

We review each request and process it in accordance with the applicable statutory requirements.

18.4 Right to Lodge a Complaint with a Data Protection Supervisory Authority

Irrespective of any other legal remedies, data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates the GDPR.

A complaint may, in particular, be lodged with the supervisory authority responsible for the controller.

19. Automated Decision-Making and Profiling

CleverApprove does not carry out automated decision-making within the meaning of Art. 22 GDPR.

In particular, CleverApprove does not make decisions that produce legal effects concerning data subjects or similarly significantly affect them.

The platform is used exclusively to technically support review and approval processes. Decisions concerning approvals, rejections or other assessments are made by the persons involved.

No automated evaluation, analysis or profiling takes place.

20. Changes to This Privacy Policy

We regularly review this Privacy Policy and amend it where necessary due to technological developments, changes to our services, new CleverApprove functions or legal requirements.

The current version of this Privacy Policy is available on our website.

Where material changes significantly affect your rights or the manner in which personal data is processed, we will inform you in an appropriate manner where legally required.

The version of this Privacy Policy published at the time of use of CleverApprove shall apply.

This site uses a single session cookie strictly required for authentication. No tracking or advertising cookies are used. Privacy policy