Privacy policy

Last updated: August 2026

This English version is a non-binding convenience translation provided for information purposes only. Solely the German version of this page is legally binding; in the event of any discrepancy, the German version prevails.

1. Controller and privacy contact

The controller under the EU General Data Protection Regulation (GDPR) is:
EBS Euchner Büro- und Schulsysteme GmbH
Ernst-Leitz-Straße 3
D-63150 Heusenstamm, Germany
Phone: +49 6104 3313
Email: info@ebs-euchner.com

Represented by managing director Robert Euchner. Quickard is a product of EBS Euchner Büro- und Schulsysteme GmbH. You may also use these contact details for privacy requests.

2. Purposes and legal bases

We process personal data to provide and secure Quickard, perform user and subscription agreements, communicate, comply with legal obligations and — only where separately permitted — measure reach or provide newsletters. Depending on the operation, the legal basis is Art. 6 (1) lit. b GDPR (contract or pre-contractual steps), lit. c (legal obligation), lit. f (legitimate interests, especially secure and economic operation), or lit. a (consent). Where we rely on lit. f, the relevant interest is identified below. We do not make decisions based solely on automated processing that produce legal or similarly significant effects within Art. 22 GDPR.

3. Roles for customer cards and forms

EBS is the controller for the Quickard account, billing, platform security and its own website content. Where a customer adds data about employees or other people to a card or collects contact or newsletter data on a public card for its own purposes, that customer generally determines the purposes and means and EBS processes the data as processor. The customer must provide its own Art. 13 or 14 GDPR information and establish a legal basis. The customer's privacy notice must therefore also be accessible on its card.

4. Hosting, database and server logs

The core application, database, authentication and file storage are provided using self-hosted server and Supabase software on infrastructure operated under our responsibility. Access generates technically necessary logs including IP address, time, requested resource, status code, data volume, referrer and user agent. We use them for delivery, stability, IT security and misuse or incident analysis (Art. 6 (1) lit. f GDPR). Routine logs are generally deleted after 30 days; relevant extracts may be retained until a specific security incident has been investigated and contained.

5. Account, sign-in and OAuth

For registration and sign-in we process email address, authentication and security data, timestamps, organization, team and role information (Art. 6 (1) lit. b and f GDPR). You may sign in through Apple or Google. In that case Apple Distribution International Ltd. or Google Ireland Limited provides an account identifier and, depending on your approval, your name, email address and profile information; the provider also learns about the sign-in. The link is made at your request to enter into or perform the agreement (Art. 6 (1) lit. b GDPR) and can additionally be revoked in your provider account.

6. Contract, billing and evidence of declarations

To enter into and administer the agreement, we process master data, plan, organization and billing data, order and payment status, invoices, quotas and support communication (Art. 6 (1) lit. b GDPR). Acceptance of terms, requests for immediate performance, and cancellation or withdrawal declarations are recorded with their content, version, time and technical evidence to comply with legal duties and prove declarations (Art. 6 (1) lit. c and f GDPR).

7. Card, organization and media data

We store card and organization data you enter, including name, role, company, contact details, logos, profile images, audio and other media, links and design settings, to provide the selected plan (Art. 6 (1) lit. b GDPR). For third-party data, EBS generally acts on the customer's instructions; the customer must be authorized to store and publish it.

8. Public contact page, QR code and vCard

Each card has a public contact page at quickard.de/<slug>. Released content is available worldwide without sign-in, can be shared through a link or QR code, indexed by search engines and downloaded as a vCard. Publish only data whose public distribution is intended and lawful. Access generates the technical data described in section 4 and, where applicable, reach data described in section 11.

9. Contact forms and leads on customer cards

When a visitor submits a contact form, the entered contact details and message are stored, displayed to the relevant Quickard customer and may be reported by email. The customer is generally the controller for handling the request; EBS provides the form, storage and transmission as processor. The customer determines the legal basis, usually Art. 6 (1) lit. b GDPR for requested pre-contractual steps or lit. f for another requested response. A consent checkbox is not required for this purpose, but the customer's privacy information must be directly accessible at the form.

10. Newsletter forms on customer cards

When a newsletter block is used, the visitor must accept a customer-specific, unticked consent statement. We record the email address, card/page and block reference, responsible company, linked privacy notice, full consent wording and version, request and confirmation times, and a non-reversible keyed hash of the requesting IP address. We then send a confirmation link through Resend that is valid for 48 hours. Merely opening the link changes nothing; only an explicit click on “Confirm subscription” completes double opt-in and displays the address in the customer's inbox. A confirmation email contains a personal unsubscribe link; unsubscribing likewise requires an explicit button and immediately removes the address from the operational recipient list. The customer is generally the controller for the newsletter, consent, later mailing and unsubscribe process; EBS provides collection and double opt-in as processor. The legal basis is consent under Art. 6 (1) lit. a GDPR together with Section 7 (2) German UWG.

10a. Product information, reminders and direct marketing

For product information and broadcasts, we process email address, account status, consent or objection status, the time, version and exact wording displayed for consent, and delivery data. Product news is disabled by default; historical accounts without complete proof of consent are not contacted. We send marketing email only with voluntary, demonstrable consent (Art. 6 (1) lit. a GDPR and Section 7 (2) German UWG) or under the narrow existing-customer exception in Section 7 (3) UWG, in which case Art. 6 (1) lit. f GDPR applies. Recipients may withdraw consent or object to marketing use at any time free of charge for the future.

11. Public-card reach measurement (Umami and card events)

On public cards we measure reach with a self-hosted, cookieless Umami instance and our own card-event system. No analytics cookies are set and no cookie banner is shown for that purpose. The data may include time, card identifier, path, referrer domain, event type, browser/device class, approximate location, IP address and user agent. Our own system derives a daily rotating hash from IP address, user agent, card identifier, day and a secret value; the raw IP is not stored as a card event. To prevent duplicate counts, the key qk_an_v:<Kartenadresse> may be stored temporarily in sessionStorage. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in reach measurement and product improvement) and, where applicable, Section 25 (2) German TDDDG for technically necessary storage. The cookie banner on public cards appears only when the page embeds Google Maps or YouTube/Vimeo (section 12). Card events are deleted automatically after 180 days. Pure server-side security analysis without terminal access likewise relies on Art. 6 (1) lit. f GDPR.

12. Embedded content: Google Maps, YouTube and Vimeo

Customers may embed Google Maps and videos from YouTube (including youtube-nocookie.com) or Vimeo. On public cards, neither the Google Maps frame nor YouTube/Vimeo frames, cover videos or YouTube preview images are created before consent. Visitors can enable the “Google Maps” and “YouTube and Vimeo” categories separately and withdraw either at any time. Only then does the browser connect directly to the provider; at least IP address, time, page, referrer and browser data are transmitted, and providers may read or store further identifiers on the device. Google Ireland Limited and Vimeo.com, Inc., USA, are relevant providers. The legal bases are Section 25 (1) German TDDDG and Art. 6 (1) lit. a GDPR. A deliberately selected external directions link opens Google Maps immediately. Other customer-configured external image, audio, font or document files may load directly from the provider identifiable in the URL; customers must identify those sources in their own privacy information and hold necessary media, font and trademark rights.

13. Apple Wallet and Google Wallet

At your request, card data can be transferred into an Apple Wallet pass or Google Wallet object. Apple passes are delivered as signed pass files. To update an added pass we also process Apple device/library identifiers, push token, pass identifier and registration time and send update signals through Apple Push Notification Service. Google receives the necessary pass and card data through its Wallet API. Providers are Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland, and Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is Art. 6 (1) lit. b GDPR. Apple or Google also processes an added pass under its own terms.

14. Payments through Stripe

Paid plans and subscriptions are processed by Stripe. Stripe processes contact, billing, payment, device and transaction data; we do not receive full payment instrument data. We retain the identifiers and status information required for contract, payment and invoice administration. The EEA provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The legal bases are Art. 6 (1) lit. b and c GDPR.

15. Transactional email through Resend

We send confirmations, invitations, pass delivery, reminders, newsletter double opt-in and other transactional email through Resend (Plus Five Five, Inc., USA). Recipient, subject, complete content and technical sending, delivery and error data are processed. Incoming webhooks are reduced before storage to required, predefined delivery and error fields; we do not store complete raw events, opening events or click events. Our email templates do not load fonts from Google servers. Required transactional email relies on Art. 6 (1) lit. b and f GDPR; newsletter confirmation relies on the requested consent under Art. 6 (1) lit. a GDPR. Where Resend acts on our behalf, processing is governed by an Art. 28 agreement and the section 19 safeguards.

16. Quin AI assistant and OpenAI

When you use Quin, chat messages, context and required system instructions are sent through the API to OpenAI Ireland Ltd. They may contain personal or confidential information; do not enter special-category data or third-party secrets. With separate consent that can be withdrawn at any time, Quin may retrieve additional account, card or analytics data about you (Art. 6 (1) lit. a GDPR). Data about other cardholders, employees, form senders or newsletter recipients may only be sent to OpenAI on a documented instruction of the relevant controller, with a sufficient legal basis and data-subject notice; otherwise it is excluded from AI access. The basic chat and requested memory notes provide the assistance (Art. 6 (1) lit. b GDPR). Quickard does not store the full chat history but may store derived notes until you delete them separately. According to OpenAI, API input and output is not used for model training by default; retention depends on the production API configuration.

17. Error and security monitoring (GlitchTip/Sentry SDK)

We use a Sentry-compatible SDK with a self-hosted GlitchTip instance to detect technical errors and security incidents. An error report may contain time, affected code and URL, device, browser and operating-system information, technical execution and error data, and IP address. Session replay and performance tracing are disabled by default and ordinary user content or complete form entries are not intended to be collected. The legal basis is our legitimate interest in stability and security under Art. 6 (1) lit. f GDPR. Error data is deleted once it is no longer required for analysis and prevention.

17a. Support, administrative access, audit and feedback

Authorized staff may access account, organization, card, contact, form and billing data where support or platform administration requires it. Security-relevant administrative access is logged with administrator account, organization, time, IP address and user agent. Voluntary Quin feedback, NPS ratings and support messages may include user/organization reference, score, comment, page and technical context. Purposes are support, troubleshooting, abuse prevention, auditability and product improvement (Art. 6 (1) lit. b or f GDPR). Access is role-restricted and data is deleted when handling, security and evidence purposes end.

17b. Illegal-content reports and authority orders

For a Digital Services Act report, we process reporter contact data, the relevant URL or card address, reasons, evidence, good-faith statement, communications and our decision. Purposes are receiving and assessing the report, protecting all parties' rights, complying with law and proving its handling (Art. 6 (1) lit. c and f GDPR). Data may be disclosed to affected users, authorities, courts or advisers only where required and lawful. Suspected offences posing a threat to life or safety are reported to law-enforcement or judicial authorities as required by law. Data is kept until the procedure ends and afterwards only for applicable evidence and limitation periods.

18. Cookies and local browser storage

Technically necessary items include session/authentication cookies, the active-organization cookie qk_active_org and, after a manual language choice, the qk_locale language cookie for one year. Maintenance access may be stored for 24 hours. localStorage or sessionStorage may also hold theme, prefilled registration email, an onboarding draft including billing/card data, support-window position and Quin hints. On public cards with Google Maps or YouTube/Vimeo blocks, qk_public_consent stores the version, decision time and selection for those embeds so the choice can be enforced and withdrawn; without such blocks no cookie banner appears. The section 11 analytics key may be stored temporarily in sessionStorage. Necessary functional storage relies on Section 25 (2) German TDDDG and Art. 6 (1) lit. b or f GDPR. Third-party embeds (section 12) rely on Section 25 (1) German TDDDG and Art. 6 (1) lit. a GDPR. We do not use our own profiling advertising cookies.

19. Recipients, processors and international transfers

Depending on the feature, recipients include infrastructure and hosting providers, Stripe, Resend, Apple, Google, OpenAI and map or video providers selected by a customer. Where a provider processes on our instructions, we enter into an Art. 28 GDPR agreement; for certain operations other providers act as separate controllers. Transfers outside the EEA only take place in accordance with Art. 44 et seq. GDPR, in particular under an adequacy decision, including valid EU-US Data Privacy Framework certification, or EU Standard Contractual Clauses and supplementary safeguards.

20. Retention

We delete data when its purpose and required evidence period have ended and no retention duty applies. The main criteria are:
· Routine server logs: generally 30 days; incident data until the investigation ends.
· Card events described in section 11: automatically after 180 days.
· Contact and confirmed newsletter entries in the customer inbox: automatically after 365 days, or earlier on a lawful instruction or when the purpose ends.
· Unconfirmed newsletter requests: seven days after the 48-hour confirmation link expires; unsubscribe evidence: three years after unsubscribing; active consent evidence until unsubscribing or an earlier lawful instruction.
· Account, card, media and Quin-memory data: for the contract term, then deletion through the account-deletion process unless a separate duty or legitimate claim-preservation need applies.
· Contract, consent, cancellation and withdrawal evidence: generally until possible contractual claims have expired; the regular German limitation period is three years and generally begins at year end.
· Books, inventories, opening balance sheets and annual statements: ten years; accounting records and invoices: eight years; incoming and outgoing commercial letters: six years (German HGB, AO and UStG).
Statutory periods generally begin at the end of the calendar year. Deleted data may remain in secured backups until scheduled overwriting; during that period it is not used for other purposes.

21. Your privacy rights

Subject to the statutory conditions, you have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). You may withdraw consent at any time for the future without affecting prior lawful processing. For data controlled by a Quickard customer, you may contact that customer or us; we will forward the request where necessary.

22. Specific notice about the right to object

Where we process data under Art. 6 (1) lit. f GDPR, you may object at any time on grounds relating to your particular situation. We will then stop unless we demonstrate compelling legitimate grounds that override your interests or need the data to establish, exercise or defend legal claims. You may object to direct marketing at any time without giving reasons.

23. Right to complain to a supervisory authority

Without prejudice to other remedies, you may complain to a data protection authority, particularly at your habitual residence, workplace or the place of the alleged infringement. The authority responsible for EBS is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 3163, 65021 Wiesbaden, Germany
datenschutz.hessen.de