Trust Center

Trust through
Transparency.

All security-relevant information about our products – privacy, hosting, certificates and compliance – in one place.

GDPR-Compliant EU Hosting HTTPS/TLS Data Minimization
7
Products Documented
100%
EU Hosting
ISO
27001 Certified Partners
Art. 28
DPA with all service providers
✓ GDPR
✓ DPA
✓ TOM
✓ EU AI Act
Products
Compliance & Security

All Products at a Glance

Select a product for detailed information on privacy, security and compliance.

Parent Brand · Consulting
PCM Group
Management consulting, funding advisory, software development and strategic investments.
SaaS · Practice Software
Wellpoint
All-in-one practice software for therapists – online appointment booking, patient management, billing.
App · Logbook
GeoTrack
Digital logbook with GPS tracking for businesses and self-employed individuals.
Platform · Media
Lyvio
Secure platform for sharing, organizing and releasing images & videos.
Mobile App · Healthcare
PHE Buddy
Smart app to support PKU patients in their daily phenylalanine control.
Consulting · Content
Tourismus neu denken
Strategy consulting and knowledge platform for tourism businesses in the DACH region.
SaaS · Analytics
Unifyr
Privacy-friendly website statistics for all PCM Group products – consent-controlled, no cross-site tracking, EU hosting.
AI Infrastructure · Data Protection
🤖 Artificial Intelligence & Data Protection
PCM Group relies exclusively on local, EU-hosted AI models – no data transfer to external AI services. Full control over all data.

Infrastructure & Data Center Partners

All PCM Group products rely on two audited, ISO-certified partners – exclusively in Germany/EU.

Hetzner Online GmbH
Primary Data Center Partner
Industriestraße 25 · 91710 Gunzenhausen · Deutschland
www.hetzner.com
LocationsNuremberg (NBG) · Falkenstein (FSN) · Helsinki (HEL)
Legal formGmbH, German law
Founded1997, Gunzenhausen DE
Data transferExclusively EU/EEA
ISO/IEC 27001
Information Security Management (ISMS)
ISO 9001:2015
Quality Management System
ISO 14001:2015
Environmental Management System
ISO 50001:2018
Energy Management System
DIN EN 50600
European Standard for Data Centers
GDPR / DPA
Art. 28 GDPR concluded
Used for
Wellpoint (App Backend)GeoTrack (App Server)Lyvio (Media Storage)PHE Buddy (App Backend)
ALL-INKL.COM
Website Hosting Partner
Neue Medien Münnich · Inh. René Münnich
Hauptstraße 68 · 02742 Friedersdorf · Deutschland
all-inkl.com/datenschutzinformationen
DC locationFriedersdorf, Saxony – Germany
DC ownershipOwn DC (no colocation)
Availability99.9% SLA guaranteed
Data transferExclusively Germany/EU
ISO/IEC 27001
Information Security Management
TÜV-audited
External security audit by TÜV
BSI-compliant
Federal Office for Information Security
GDPR / DPA
Art. 28 GDPR concluded
Redundancy
UPS, redundant cooling & network
24/7 Monitoring
Round-the-clock system monitoring
Used for
pcm-group.atphe-buddy.at (Website)tourismus-neu-denken.atOther PCM Websites
BMD Systemhaus GmbH
Financial Software Partner
BMD Systemhaus GmbH
Herminengasse 1 · 1020 Wien · Österreich
www.bmd.com
Legal formGmbH, Austrian law
Founded1978, Vienna AT
Software locationAustria (EU)
Data transferExclusively Austria/EU
ISO/IEC 27001
Information Security Management (ISMS)
GDPR / DPA
Art. 28 GDPR via Finanzbuchhaltung Monuth KG
§ 132 BAO
7-year retention obligation
WTBG-compliant
Professional secrecy in tax consulting
Audit-proof
GoBD-compliant bookkeeping
Role concept
Access protection & user rights
Used for
Accounting (via Finanzbuchhaltung Monuth KG)PayrollTax Advisory Software
Finmatics GmbH
AI Document Processing
Finmatics GmbH
Gonzagagasse 11 · 1010 Wien · Österreich
finmatics.com
Legal formGmbH, Austrian law
AI processingAustria / EU (no third country)
Subject of processingInvoices & documents (no personal data)
Data transferExclusively EU legal area
GDPR-compliant
Processing exclusively within the EU legal area
DPA
Art. 28 GDPR via Finanzbuchhaltung Monuth KG
AI Transparency
Automatic booking suggestions, approval by tax advisor
No Disclosure
No data sharing with third parties outside EU
Data Minimization
Processing of booking-relevant document data only
Deletion Policy
Data deleted after statutory retention period
Used for
Document processing (via Finanzbuchhaltung Monuth KG)AI booking suggestionsAutomatic account assignment

Global Security Standards

These measures apply to all PCM Group products and platforms.

🔒
Encryption – HTTPS & TLS
Transport and at-rest encryption
Active on all products

All data transmissions are made exclusively via encrypted HTTPS connections with TLS 1.2 or higher. Sensitive data (patient data, health data, GPS data) are additionally encrypted at rest with AES-256.

🇪🇺
EU Hosting – Data Storage
Exclusively EU/EEA data centers
EU-only

All servers and databases are located in data centers within the European Union – operated by Hetzner Online GmbH (Nuremberg/Falkenstein) and ALL-INKL.COM (Friedersdorf). No data transfer to third countries without an explicit legal basis.

⚖️
GDPR Compliance
Legal basis for every processing activity
Compliant

All products and processes are aligned with the requirements of the General Data Protection Regulation (EU) 2016/679. Data processing is carried out exclusively on a proven legal basis (Art. 6 GDPR), for health data pursuant to Art. 9 GDPR.

📋
Data Processing Agreement (DPA)
Art. 28 GDPR – for all SaaS products
Available

For all SaaS products (Wellpoint, GeoTrack, Lyvio, PHE Buddy) we provide a DPA pursuant to Art. 28 GDPR. Requests to datenschutz@pcm-group.at.

🚨
Incident Response
Data Breach Management pursuant to Art. 33 GDPR
Process established

In the event of data breaches we notify affected users and the Austrian Data Protection Authority within the statutory 72-hour deadline (Art. 33 GDPR). All products have 24/7 monitoring and documented incident response processes.

PCM Group

Parent organization for management consulting (PCM Solution), software development (PCM Technology) and strategic investments. Headquarters: Eben im Pongau, Austria.

GDPR-Compliant
🏢
Hosting & Infrastructure – ALL-INKL.COM
ISO/IEC 27001 · TÜV-audited · BSI-compliant · Germany
EU Hosting active
ProviderALL-INKL.COM – Neue Medien Münnich
LocationFriedersdorf, Saxony – Germany (EU)
Data centerOwn DC, no colocation
DPAConcluded pursuant to Art. 28 GDPR
ISO/IEC 27001Information Security
TÜV-auditedExternal security audit
BSI-compliantIT baseline protection
99.9% SLAAvailability guarantee
🔐
Technical Security Measures
TLS, Firewall, Access Control
Active
  • HTTPS/TLS 1.2+ on all connections
  • Firewall & DDoS protection (ALL-INKL)
  • Regular security updates
  • Access on a need-to-know basis
  • Cookie consent management
  • Logging of all system accesses
📊
Tracking & Analytics – Unifyr Analytics
Privacy-friendly statistics, consent-controlled
Consent-controlled

We use Unifyr Analytics (analytics.agentur-circle.com) for privacy-friendly website statistics. No tracking without cookie consent. No sharing with third parties. No cross-site tracking.

📄
Data Subject Rights
Art. 15–21 GDPR
Guaranteed
  • Access (Art. 15 GDPR)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)

Requests to datenschutz@pcm-group.at – response within 30 days.

🔗
Sub-processors
Service providers used & legal basis
Documented
ProviderPurposeLocationBasis
ALL-INKL.COMWebsite hostingGermany (EU)Art. 6 (1) f · DPA
Unifyr AnalyticsWebsite statisticsEUArt. 6 (1) a GDPR
PCM DWPContact form/CRMEUArt. 6 (1) f GDPR
Google FontsFonts (locally embedded)EU (local)Legitimate interest
Agentur Circle GmbHWeb development, design, marketing, Unifyr AnalyticsAustria (EU)Art. 28 GDPR · DPA
Finanzbuchhaltung Monuth KGAccounting, tax consulting, payrollAustria (EU)Art. 6 (1) c GDPR · WTBG
↳ BMD NTCSAccounting & payroll software (sub-processor Monuth)Austria (EU)Via Finanzbuchhaltung Monuth KG
↳ FinmaticsAI document processing & booking suggestions (sub-processor Monuth)Austria / EUVia Finanzbuchhaltung Monuth KG
🏛️
Competent Supervisory Authority
Austrian Data Protection Authority
AuthorityAustrian Data Protection Authority
AddressBarichgasse 40–42, 1030 Vienna
Phone+43 1 52 152-0
Additional Service Providers & Partners
🎨
Agentur Circle GmbH
Web development · Design · Marketing · Unifyr Analytics · Austria
DPA concluded
CompanyAgentur Circle GmbH
LocationAustria (EU)
Legal basisArt. 28 GDPR – DPA concluded
Data transferExclusively within the EU/EEA
Access to customer dataOnly within the scope of commissioned services
  • Development & maintenance of all PCM Group websites and product landing pages
  • Graphics, UI/UX design and corporate identity
  • Online marketing, SEO and performance optimization
  • Operation of Unifyr Analytics (privacy-friendly website statistics)
  • Technical implementation of marketing campaigns
Unifyr AnalyticsEU hosting, no cross-site tracking, consent-controlled
Subject to instructionsYes – acts exclusively on instructions from PCM Group
Technical securityHTTPS, encrypted transmission, need-to-know access
📒
Finanzbuchhaltung Monuth KG
Tax consulting · Accounting · Payroll · Austria
Confidentiality obligation
CompanyFinanzbuchhaltung Monuth KG
LocationAustria (EU)
ActivityAccounting, tax consulting, payroll
Legal basisArt. 6 (1) c GDPR – legal obligation (tax & bookkeeping duty)
Professional secrecyYes – statutory confidentiality obligation under Austrian WTBG
Data transferExclusively Austria / EU
  • Financial data and business documents (receipts, invoices, accounts)
  • Employee data for payroll (name, social security number, salary)
  • Customer data within the scope of accounting (invoice recipients)
  • Tax data for tax authority filings
Software / ServiceProviderPurposeLocation
BMD NTCS BMD Systemhaus GmbH Accounting, payroll & tax advisory software Austria (EU)
Finmatics Finmatics GmbH AI-assisted document processing & automatic booking suggestions Austria / EU
Note on Finmatics: Finmatics processes document data (invoices, delivery notes) using AI for automatic account assignment. Processing takes place exclusively within the EU legal area. No disclosure of personal data to third parties outside the EU.
Retention obligation7 years under Austrian tax law (§ 132 BAO)
Transmission to tax authorityArt. 6 (1) c GDPR – legal obligation
Third-country transferNone – exclusively Austrian tax authorities
BMD & FinmaticsSub-contractors of Finanzbuchhaltung Monuth KG – contractually obligated, GDPR-compliant
Data Protection Requests & DPA

For questions on data protection, DPA requests or data subject rights.

Wellpoint

All-in-one practice software for therapists. Processing of sensitive patient data to the highest data protection standards.

GDPR-Compliant
🏢
Hosting & Infrastructure – Hetzner Online GmbH
ISO/IEC 27001 · ISO 9001 · ISO 14001 · ISO 50001 · DIN EN 50600
EU-only · ISO 27001
ProviderHetzner Online GmbH
LocationsNuremberg (NBG) · Falkenstein (FSN) – Germany
BackupDaily, encrypted, EU-internal
DPAConcluded pursuant to Art. 28 GDPR
ISO/IEC 27001Information Security (ISMS)
ISO 9001:2015Quality Management
ISO 14001:2015Environmental Management
ISO 50001:2018Energy Management
DIN EN 50600DC infrastructure standard
GDPR / DPAArt. 28 concluded
🔐
Health Data – Art. 9 GDPR
Enhanced protection for special categories of data
Enhanced protection active

Wellpoint processes patient data (health data) pursuant to Art. 9 GDPR. Processing only on explicit consent (Art. 9 para. 2 lit. a). All data is stored and transmitted AES-256 encrypted.

🛡️
Technical Measures (TOM)
Complete security architecture
Implemented
  • TLS 1.2+ transport encryption
  • AES-256 at-rest encryption
  • Two-factor authentication
  • Role-based access control
  • Automatic session timeouts
  • Complete audit log
  • Penetration tests (annual)
  • 24/7 system monitoring
📋
Data Processing Agreement (DPA)
Wellpoint as Processor, therapist as Controller
Available

Wellpoint provides each customer with a DPA pursuant to Art. 28 GDPR. As a therapist you are the data controller – Wellpoint is the processor. DPA available by email or via the customer portal.

🗑️
Deletion Policy & Retention Periods
Austrian health law (7 years)
Defined
Treatment records7-year minimum retention (Austrian law)
After contract endComplete deletion on request
Backup deletionWithin 30 days after termination
Export optionSelf-service data export before termination
🔗
Sub-processors
Service providers used
Documented
ProviderPurposeLocationBasis
Hetzner Online GmbHServer & databaseGermany (EU)Art. 28 GDPR · DPA
GoCardless Ltd.Payment processingUnited Kingdom / EUArt. 6 (1) b GDPR
Unifyr AnalyticsMarketing website statisticsEUArt. 6 (1) a GDPR
Agentur Circle GmbHWeb development, design, marketing website wellpoint.atAustria (EU)Art. 28 GDPR · DPA
Finanzbuchhaltung Monuth KGAccounting, invoicing, tax consultingAustria (EU)Art. 6 (1) c GDPR · WTBG
↳ BMD NTCSAccounting & payroll software (sub-processor Monuth)Austria (EU)Via Finanzbuchhaltung Monuth KG
↳ FinmaticsAI document processing & booking suggestions (sub-processor Monuth)Austria / EUVia Finanzbuchhaltung Monuth KG
🚨
Incident Response
72-hour notification obligation Art. 33 GDPR
Process active

In the event of data breaches, affected therapists and the supervisory authority are notified within 72 hours. 24/7 security monitoring through Hetzner infrastructure. Dedicated incident response process documented and tested.

Wellpoint Privacy & DPA

Request a DPA, ask data protection questions or exercise data subject rights.

GeoTrack

Digital logbook with GPS tracking. Processing of location and trip data in accordance with GDPR principles.

GDPR-Compliant
🏢
Hosting & Infrastruktur – Hetzner Online GmbH
ISO/IEC 27001 · ISO 9001 · ISO 14001 · ISO 50001 · DIN EN 50600
EU-only · ISO 27001
ProviderHetzner Online GmbH
LocationsNuremberg (NBG) · Falkenstein (FSN) – Germany
Data transferExclusively EU/EEA
DPAConcluded pursuant to Art. 28 GDPR
ISO/IEC 27001Information Security
ISO 9001:2015Quality Management
ISO 14001:2015Environmental Management
ISO 50001:2018Energy Management
DIN EN 50600DC infrastructure standard
🗺️
GPS Data & Location Processing
Only during active recording – no background tracking
Minimization principle

GPS data is used exclusively for creating the digital logbook. Location recording only during active trip recording – no background tracking. Processing on Hetzner servers in Germany.

GPS/LocationOnly during active trip
Background locationNot used
Contacts/CameraNot used
Data sharingNone without consent
🔐
Technical Security Measures
Encryption, auth, logout
Active
  • HTTPS/TLS for all transmissions
  • Encrypted data storage
  • User authentication required
  • Automatic app logout
  • No data sharing with third parties
  • Audit log for data accesses
🗑️
Deletion & Data Export
Self-service – possible at any time
Self-Service
Data exportAt any time as CSV/PDF
Data deletionSelf-service in the app
After terminationComplete deletion within 30 days
Legal basisArt. 6 (1) b GDPR (contract performance)
🔗
Sub-processors
Service providers used
Documented
ProviderPurposeLocationBasis
Hetzner Online GmbHApp server & databaseGermany (EU)Art. 28 GDPR · DPA
Agentur Circle GmbHWeb development, design, marketing website geotrack.atAustria (EU)Art. 28 GDPR · DPA
Finanzbuchhaltung Monuth KGAccounting, invoicing, tax consultingAustria (EU)Art. 6 (1) c GDPR · WTBG
↳ BMD NTCSAccounting & payroll software (sub-processor Monuth)Austria (EU)Via Finanzbuchhaltung Monuth KG
↳ FinmaticsAI document processing & booking suggestions (sub-processor Monuth)Austria / EUVia Finanzbuchhaltung Monuth KG
Unifyr AnalyticsMarketing website statisticsEUArt. 6 (1) a GDPR
GeoTrack Privacy

Questions about location data processing or data subject requests.

Lyvio

Secure platform for sharing, organizing and releasing images & videos.

GDPR-Compliant
🏢
Hosting & Infrastruktur – Hetzner Online GmbH
ISO/IEC 27001 · ISO 9001 · ISO 14001 · ISO 50001 · DIN EN 50600
EU-only · ISO 27001
ProviderHetzner Online GmbH
LocationsNuremberg (NBG) · Falkenstein (FSN) – Germany
StorageEncrypted, EU-internal
Data transferExclusively EU/EEA
ISO/IEC 27001Information Security
ISO 9001:2015Quality Management
ISO 14001:2015Environmental Management
ISO 50001:2018Energy Management
DIN EN 50600DC infrastructure standard
🔗
Sharing & Access Control
User-controlled, time-limited, revocable
User-controlled

Users have full control over sharing. All share links are time-limited and revocable at any time. No automatic scanning or AI analysis without explicit consent.

🔐
Security Measures
Encryption, auth, backup
Active
  • Encrypted media storage
  • HTTPS/TLS for all transmissions
  • Secure authentication
  • Automatic EU backups
  • Complete access logs
  • Privacy by Design (Art. 25 GDPR)
🚧
Product Status
Under Development – Privacy by Design from the start
Under Development

Lyvio is in the development phase. The data protection architecture is being built entirely according to Privacy by Design and Privacy by Default (Art. 25 GDPR). Full privacy policy available before launch.

🔗
Sub-processors
Service providers used
Documented
ProviderPurposeLocationBasis
Hetzner Online GmbHApp server & media storageGermany (EU)Art. 28 GDPR · DPA
Agentur Circle GmbHWeb development, design, marketing website lyvio.atAustria (EU)Art. 28 GDPR · DPA
Finanzbuchhaltung Monuth KGAccounting, invoicing, tax consultingAustria (EU)Art. 6 (1) c GDPR · WTBG
↳ BMD NTCSAccounting & payroll software (sub-processor Monuth)Austria (EU)Via Finanzbuchhaltung Monuth KG
↳ FinmaticsAI document processing & booking suggestions (sub-processor Monuth)Austria / EUVia Finanzbuchhaltung Monuth KG
Lyvio Privacy

Questions about Lyvio, service providers used or early access.

PHE Buddy

Mobile app for PKU patients. Processing of sensitive health data with the highest protection pursuant to Art. 9 GDPR.

GDPR-Compliant
🏢
Hosting – ALL-INKL.COM (Website) + Hetzner (App)
Dual ISO 27001 – both partners EU-certified
Dual ISO 27001
ProviderALL-INKL.COM – Neue Medien Münnich
LocationFriedersdorf, Saxony – Germany (EU)
ISO/IEC 27001Information Security
TÜV-auditedExternal audit
BSI-compliantIT baseline protection
ProviderHetzner Online GmbH
LocationsNuremberg (NBG) · Falkenstein (FSN) – Germany
ISO/IEC 27001Information Security
ISO 9001:2015Quality Management
ISO 14001:2015Environmental Management
ISO 50001:2018Energy Management
DIN EN 50600DC infrastructure standard
🏥
Health Data – Art. 9 GDPR
Special category – highest protection
Highest protection

PHE Buddy processes health data (phenylalanine values, dietary diary) pursuant to Art. 9 GDPR. Processing only on explicit consent. No data sharing with third parties without explicit consent. AES-256 encryption at rest.

📱
App Permissions & Data Minimization
Only strictly necessary permissions
Minimization principle
CameraOptional (barcode scan)
NotificationsOptional (reminders)
LocationNot used
ContactsNot used
  • Encrypted device storage
  • Optional PIN/biometric protection
  • No advertising, no profiling
  • Offline functionality available
🌍
Multilingual – DE & EN
GDPR for all international users
DE + EN

Privacy policy available in German and English. All international users (DACH + EU) are treated equally – GDPR applies to all.

🔗
Sub-processors
App distribution via Apple & Google
Documented
ProviderPurposeLocationBasis
ALL-INKL.COMWebsite hostingGermany (EU)Art. 28 GDPR · DPA
Hetzner Online GmbHApp backend & dataGermany (EU)Art. 28 GDPR · DPA
Apple App StoreApp distribution (iOS)USA (SCC)Art. 6 (1) b GDPR
Google Play StoreApp distribution (Android)USA (SCC)Art. 6 (1) b GDPR
Agentur Circle GmbHWeb development, design, marketing website phe-buddy.atAustria (EU)Art. 28 GDPR · DPA
Finanzbuchhaltung Monuth KGAccounting, invoicing, tax consultingAustria (EU)Art. 6 (1) c GDPR · WTBG
↳ BMD NTCSAccounting & payroll software (sub-processor Monuth)Austria (EU)Via Finanzbuchhaltung Monuth KG
↳ FinmaticsAI document processing & booking suggestions (sub-processor Monuth)Austria / EUVia Finanzbuchhaltung Monuth KG
PHE Buddy Privacy

Questions about health data or data subject rights.

Tourismus neu denken

Strategy consulting and knowledge platform for reducing OTA dependency for tourism businesses in the DACH region.

GDPR-Compliant
🏢
Hosting & Infrastructure – ALL-INKL.COM
ISO/IEC 27001 · TÜV-audited · BSI-compliant · Germany
EU-only · ISO 27001
ProviderALL-INKL.COM – Neue Medien Münnich
LocationFriedersdorf, Saxony – Germany (EU)
Data centerOwn DC, no colocation
DPAConcluded pursuant to Art. 28 GDPR
ISO/IEC 27001Information Security
TÜV-auditedExternal security audit
BSI-compliantIT baseline protection
99.9% SLAAvailability guarantee
🧮
OTA Cost Calculator – No Data Storage
Calculation runs entirely in the browser (client-side)
No storage

The OTA cost calculator runs entirely in the browser. Entered revenue data is not transmitted to servers and not stored – maximum confidentiality for sensitive business data.

📊
Analytics – Unifyr Analytics
Privacy-friendly, consent-controlled
Consent-controlled

Website statistics via Unifyr Analytics – no tracking without cookie consent. No cross-site tracking, no sharing with ad networks.

🔐
Security Measures
HTTPS, updates, consent
Active
  • HTTPS/TLS across the entire website
  • Regular security updates
  • Cookie consent management
  • No unnecessary data tracking
  • Source citations on all studies
  • Contact data used for specific purpose only
🔗
Sub-processors
Service providers used
Documented
ProviderPurposeLocationBasis
ALL-INKL.COMWebsite hosting tourismus-neu-denken.atGermany (EU)Art. 28 GDPR · DPA
Agentur Circle GmbHWeb development, design, SEO, content, Unifyr AnalyticsAustria (EU)Art. 28 GDPR · DPA
Finanzbuchhaltung Monuth KGAccounting, invoicing, tax consultingAustria (EU)Art. 6 (1) c GDPR · WTBG
↳ BMD NTCSAccounting & payroll software (sub-processor Monuth)Austria (EU)Via Finanzbuchhaltung Monuth KG
↳ FinmaticsAI document processing & booking suggestions (sub-processor Monuth)Austria / EUVia Finanzbuchhaltung Monuth KG
Unifyr AnalyticsWebsite statisticsEUArt. 6 (1) a GDPR
Tourismus neu denken – Privacy

Data protection questions, sub-processors or data subject requests.

Unifyr

Marketing platform with website analytics, central inbox, AI-powered post scheduling, and proprietary tracking pixel – developed by PCM Group & Agentur Circle GmbH, exclusively EU-hosted.

GDPR-Compliant
🧩
Product Modules & Operator
Analytics · Inbox · Post Scheduling · AI · Pixel
EU Hosting active
DeveloperPCM Group (PCM Technology) & Agentur Circle GmbH
OperatorAgentur Circle GmbH
LocationAustria (EU)
DPAArt. 28 GDPR – DPA concluded
Data transferExclusively EU/EEA
Third-country transferNone
ModuleFunctionLegal basis
📊 AnalyticsPrivacy-friendly website statistics, consent-controlled, IP-anonymizedArt. 6 (1) a GDPR
📥 Central InboxConsolidated communication overview for customer inquiries & messagesArt. 6 (1) b GDPR
📅 Post SchedulingAI-powered planning & scheduling of social media contentArt. 6 (1) b GDPR
🤖 AI MarketingAI models for content generation & campaign optimization (EU-side)Art. 6 (1) b GDPR
📡 Unifyr PixelProprietary tracking pixel for technical analysis – active before cookie banner, no sharing with third partiesArt. 6 (1) f GDPR
pcm-group.at wellpoint.at geotrack.at lyvio.at phe-buddy.at tourismus-neu-denken.at
📡
Unifyr Pixel – Privacy Text
Technical Analysis · Before Cookie Banner · No Sharing · Copyable Privacy Policy Text Block
Art. 6(1)f · No Third Parties
Pixel operatorAgentur Circle GmbH (on behalf of the respective website)
ActivationTechnical analysis – active before the cookie banner (no consent required)
PurposeExclusively technical analysis (page views, load times, error detection)
Data collectedAnonymized page views & technical metrics – no personal data
HostingHetzner / ALL-INKL – EU data center, no third country
Sharing with third partiesNone – data remains exclusively with the operator
Legal basisArt. 6 para. 1 lit. f GDPR – Legitimate interest (technical analysis)

Unifyr Pixel

This website uses the Unifyr Pixel, a technical analysis tool by Agentur Circle GmbH, Austria. The pixel is required for the basic technical functionality of the website and collects exclusively anonymized technical data (page views, load times, error detection). No prior cookie consent is required for this.

The collected data is not shared with third parties, advertising networks, or any other external entities. All data is processed exclusively on EU servers (Germany) and is not used for profiling or personal evaluation.

Legal basis: Art. 6 para. 1 lit. f GDPR (Legitimate interest – technical analysis) · Operator: Agentur Circle GmbH · datenschutz@pcm-group.at

🤖
AI Marketing Models
EU-side AI for content & post scheduling · No customer data in external AI
EU-only AI

No customer content flows into external AI services. All AI functions in Unifyr run on EU-hosted models or are operated by instructed processors.

Posting AIContent suggestions & scheduling optimization – EU-side
Content AIText generation for marketing campaigns (no personal data)
Data basisOnly aggregated, non-personal marketing data
StorageAI-generated content remains exclusively on EU servers
External AI servicesNo customer data in Claude.ai, ChatGPT or other external models
🔐
Privacy Principles
Privacy by Design · Consent-controlled · No sharing
Privacy by Design
  • No tracking without active cookie consent
  • No cross-site tracking – data is not linked across products
  • No sharing with advertising networks or third parties
  • No personal user profiles
  • IP anonymization active in analytics & pixel
  • Data remains exclusively within EU jurisdiction
  • Opt-out possible at any time via cookie settings
  • Inbox data visible only to the respective website operator
🏢
Infrastructure & Hosting
Hetzner Online GmbH · ALL-INKL.COM · Germany/EU
EU-only
App backend / PixelHetzner Online GmbH · ISO/IEC 27001 · DE/FI (EU)
Website / E-MailALL-INKL.COM · ISO/IEC 27001 · TÜV-audited · DE (EU)
TransmissionHTTPS/TLS 1.2+ – fully encrypted
OperatorAgentur Circle GmbH (operations) · PCM Group / PCM Technology (development)
AccessAuthorized employees only, need-to-know basis
Third-country transferNone
🔗
Sub-processors
Service providers used & legal basis
Documented
ProviderPurposeLocationBasis
PCM Group / PCM TechnologySoftware development of the Unifyr platformAustria (EU)Internal · Art. 6 (1) b GDPR
Agentur Circle GmbHOperations, hosting, pixel, inbox, post schedulingAustria (EU)Art. 28 GDPR · DPA
Hetzner Online GmbHServer infrastructure, app backend, pixel trackingGermany (EU)Art. 28 GDPR · DPA · ISO 27001
ALL-INKL.COMWebsite hosting, e-mail infrastructureGermany (EU)Art. 28 GDPR · DPA · ISO 27001
Unifyr – Privacy & Pixel

Questions about tracking, consent, pixel integration or data deletion.

AI & Privacy

PCM Group uses AI tools in a differentiated and purpose-bound manner: local models for everything involving personal data, external cloud services exclusively for internal tasks without customer data.

GDPR-Compliant · Documented
Principle

No AI system is granted access to customer data, patient data, or personal user data.

External services (Claude.ai, ChatGPT, Higgsfield) are used internally for marketing, development, and analysis – exclusively with anonymized or purely internal content without personal reference.

🏢
Mittwald mStudio – AI Hosting
Managed local AI models · Data center Germany · GDPR-compliant
Primary AI infrastructure
ProviderMittwald CM Service GmbH & Co. KG
ProductmStudio AI Hosting
Data center locationGermany (EU) – own data center
Data transferExclusively EU/EEA, no third-country transfer
Model hostingLocal inference on dedicated servers
Training on user dataNo – models are not trained with customer data
  • AI requests are processed locally on Mittwald servers in Germany
  • No forwarding to OpenAI, Anthropic, Google or other external AI services
  • Full control over prompts and responses – no external logging
  • User data is not used for model improvement
  • GDPR-compliant DPA concluded with Mittwald
Llama 3Meta – Open Source
MistralMistral AI – EU model
GemmaGoogle – Open Weights
Further open sourceDepending on use case
🔗 Mehr zu Mittwald AI Hosting: mittwald.de/mstudio/ai-hosting
🖥️
Own AI Servers – Ollama
Self-hosted · Full data control · On-premise or EU VPS
Maximum control
TechnologyOllama – Open Source LLM Runtime
OperationOwn servers (operated by PCM Group)
HostingEU-based servers (Hetzner dedicated)
NetworkIsolated – no public API access
Data storageExclusively on own servers
Model updatesInternally controlled and reviewed
Llama 3.1 / 3.2Meta – 8B / 70B parameters
Mistral 7BMistral AI – EU-developed
Phi-3Microsoft – compact & efficient
CodeLlamaSpecialized for code tasks
Qwen 2.5Alibaba – multilingual
FurtherAdapted per project
  • Fully air-gapped from the public internet (internal API only)
  • No external model logging, no telemetry back-channel
  • Access only via authenticated internal services
  • Regular model review for security vulnerabilities
  • HTTPS/TLS also on internal API endpoints
⚙️
All AI Tools & Use Cases
Complete overview – internally documented and assessed under data protection law
Documented
ToolProvider / HostingUse casePersonal dataAssessment
Claude.ai Anthropic (USA)
Cloud service
Marketing texts, campaign planning, software development (test scenarios, code review, development tasks) No customer data – internal content only ⚠️ Internally permitted
no personal reference
ChatGPT / GPT-4o OpenAI (USA)
Cloud service
Marketing activities, copywriting, internal ticket system analysis (anonymized ticket categories, no customer names) No customer data – anonymized ⚠️ Internally permitted
no personal reference
Higgsfield AI Higgsfield (USA)
Cloud service
AI video & image generation for marketing campaigns, social media content, advertising materials No personal reference – purely creative content ⚠️ Internally permitted
Marketing only
Ollama (self-hosted) PCM Group (EU)
Hetzner dedicated
Internal documentation, analysis, draft texts – wherever internal data is processed Fully controlled ✅ Primary
maximum control
Mittwald mStudio AI Mittwald (DE)
EU data center
AI-powered product features, managed local inference EU-only, DPA concluded ✅ Permitted
ISO 27001, DPA
🔐
What Never Enters External AI Services
Binding internal policy
Binding

The following data categories are under no circumstances entered into external cloud AI services (Claude.ai, ChatGPT, Higgsfield or others):

Patient data (Wellpoint)
Health data (PHE Buddy)
GPS & location data (GeoTrack)
Customer contact data (name, e-mail, phone)
Contract data & invoice information
Credentials & passwords
Internal financial data (Finanzbuchhaltung Monuth KG)
Personal ticket contents
Ticket system analysis with ChatGPT: Only aggregated, anonymized ticket categories and error types are analyzed – no customer names, no contact data, no personal content.
⚖️
GDPR & AI – Legal Bases
Art. 6, Art. 28, third-country transfer
Assessed
Legal basis (internal)Art. 6 (1) f GDPR – Legitimate interest for internal process optimization
Third-country transfer (USA)Claude.ai / ChatGPT: Only anonymized, non-personal content – no GDPR use case
Automated decisionsNone – all AI outputs are reviewed and approved by humans
ProfilingNo personal profiling by AI systems
Model trainingNo user data used for training or fine-tuning
Higgsfield (marketing video)Art. 6 (1) f – legitimate interest; no personal reference in generated content
Questions about AI & Privacy

Inquiries about AI infrastructure, models used, or data protection in AI functions.

Technical & Organizational Measures

Complete documentation of TOM pursuant to Art. 32 GDPR for all products and systems of PCM Group. These measures apply as the minimum standard for all service providers and sub-processors used.

Art. 32 GDPR
🔒
Confidentiality
Physical access control · Logical access control · Authorization control · Transfer control
🛡️
Integrity
Transfer · Input · Processor control
Availability & Resilience
Availability control · Recovery · Separation requirement
🚪
1. Physical Access Control
Physical protection of data processing facilities
Implemented

Measures that deny unauthorized persons physical access to data processing facilities used to process personal data.

  • Server infrastructure exclusively in certified data centers (Hetzner Nuremberg/Falkenstein, ALL-INKL Friedersdorf)
  • Access to data center locations only for authorized personnel (biometrics/chip card at Hetzner, 24/7 access control at ALL-INKL)
  • Video surveillance of all access areas in the data centers
  • No own physical servers – exclusively ISO-27001-certified service providers
  • PCM Group office premises: key card/system, alarm system outside business hours
  • Clean desk policy for all employees with access to personal data
🔑
2. Logical Access Control
Prevention of unauthorized system use
Implemented

Measures that prevent data processing systems from being used by unauthorized persons.

  • Password policy: minimum length 12 characters, upper/lowercase letters, special characters, numbers
  • Two-factor authentication (2FA) for all administrative access and cloud services
  • Automatic screen lock after 5 minutes of inactivity
  • Automatic session timeout for all web applications
  • Password manager mandatory for all employees (no reuse)
  • Immediate account deactivation upon employee departure
  • Regular review of active user accounts (quarterly)
  • VPN mandatory for access to internal systems from home office
👁️
3. Authorization Control
Need-to-know – only necessary data access
Implemented

Ensuring that authorized users of a data processing system can only access the data covered by their access authorization.

  • Role-based access control (RBAC) in all product systems
  • Principle of least privilege – each employee receives only the rights necessary for their role
  • Separation of development, test, and production environments
  • No direct database access for end users – exclusively via API layer
  • Database access only for administrators with documented justification
  • Logging of all privileged access (audit log)
  • Regular review of access rights (annually, immediately upon role change)
📤
4. Transfer Control
Protection during transmission and transport
Implemented

Ensuring that personal data cannot be read, copied, altered, or removed without authorization during electronic transmission or transport.

  • Transmission exclusively over encrypted connections (HTTPS/TLS 1.2+)
  • HSTS (HTTP Strict Transport Security) on all product domains
  • No sending of personal data via unencrypted e-mail
  • File transfers exclusively via secured, authenticated channels
  • No transfer of personal data to insecure third countries
  • Logging of data disclosures to sub-processors
  • API communication exclusively via authenticated endpoints (Bearer Token / API Key)
✏️
5. Input Control
Traceability of all data changes
Implemented

Ensuring that it can subsequently be checked and determined whether and by whom personal data has been entered, modified, or removed from data processing systems.

  • Complete audit log for all data changes in product systems (Wellpoint, GeoTrack)
  • Timestamps for creation, modification, and deletion of all records
  • Immutable log files (append-only logs)
  • User ID is stored with every data change
  • Form validation and input sanitizing to protect against manipulation
  • Logs retained for at least 90 days
📋
6. Processor Control
Processing by processors according to instructions
Implemented

Ensuring that personal data processed on behalf of the controller can only be processed in accordance with the controller's instructions.

  • DPA (Data Processing Agreement) with all sub-processors pursuant to Art. 28 GDPR
  • Written instructions to all processors before processing begins
  • Regular review of sub-processors (at least annually)
  • Register of all sub-processors used is kept up to date
  • Sub-processors may not engage further sub-processors without authorization
  • Contractual obligation of all employees to confidentiality (§ 6 DSG)
  • Data protection training for all employees with access to personal data
7. Availability Control
Protection against loss and accidental destruction
Implemented

Ensuring that personal data is protected against accidental destruction or loss.

  • Daily automatic backups of all databases (encrypted, EU-internal)
  • Backup retention: 30 days rolling
  • Redundant server infrastructure (Hetzner: multiple locations)
  • UPS (uninterruptible power supply) and emergency generators at data center locations
  • 99.9% availability SLA at ALL-INKL, guaranteed uptime at Hetzner
  • 24/7 monitoring of all production systems with automatic alerting
  • Disaster recovery plan documented and tested annually
  • Recovery Time Objective (RTO) < 4 hours for critical systems
  • Recovery Point Objective (RPO) < 24 hours
⚖️
8. Separation Requirement
Separate processing for different purposes
Implemented

Ensuring that data collected for different purposes can be processed separately.

  • Logical tenant separation: customer data from different clients is stored in isolation
  • Strict separation of development, test, and production data
  • No use of real data in test/development environments
  • Separate databases per product (Wellpoint, GeoTrack, etc. do not share a database)
  • Marketing data and operational customer data in separate systems
  • Accounting data (Finanzbuchhaltung Monuth KG) separated from operational CRM data
🔐
9. Encryption & Pseudonymization
Art. 32 para. 1 lit. a GDPR
Implemented
Transport encryptionTLS 1.2 / TLS 1.3 on all systems
Encryption at restAES-256 for databases containing health and location data
Password hashingbcrypt / Argon2 (no plaintext passwords)
Backup encryptionAES-256, keys stored separately from the backup
PseudonymizationFor analysis purposes where technically feasible
CertificatesLet's Encrypt / CA-signed certificates, automatic renewal
🚨
10. Incident Response & Notification Procedure
Art. 33 & 34 GDPR – 72-hour deadline
Process established
Step 1 – DetectionAutomatic monitoring reports anomaly → immediate escalation
Step 2 – ContainmentIsolate affected systems, revoke access (target: < 1 hour)
Step 3 – AssessmentDetermine scope, severity, affected data categories and number of persons
Step 4 – Report to DPANotification to Austrian Data Protection Authority within 72 hours (Art. 33)
Step 5 – Data subjectsNotification of affected persons in case of high risk (Art. 34)
Step 6 – DocumentationComplete logging of the incident (Art. 33 para. 5)
  • Dedicated data protection officer / contact person designated internally
  • Incident response contact: datenschutz@pcm-group.at
  • Register of all data protection breaches maintained internally
🏗️
11. Privacy by Design & by Default
Art. 25 GDPR – Data protection by design and by default
Implemented
  • Data protection considered from the beginning of product development (Privacy by Design)
  • Most privacy-friendly settings by default (Privacy by Default)
  • Data Minimization: collect only data strictly necessary for the purpose
  • Storage limitation: deletion concepts defined for all data categories
  • Cookie consent required before tracking (no pre-ticking)
  • New features checked for data protection compliance before launch
  • Data Protection Impact Assessment (DPIA) for high-risk processing
🔄
Review & Update of TOM
Regular effectiveness review
Annual
Review cycleAt least annually and upon significant system changes
ResponsiblePCM Group management in coordination with Agentur Circle GmbH
Last reviewJuly 2026
Next reviewJuly 2027 (or earlier if system changes occur)
DocumentationInternally versioned and dated
Request TOM documentation

Complete TOM documentation available on request for DPA purposes.

EU AI Act Assessment

Classification of all AI systems of PCM Group pursuant to Regulation (EU) 2024/1689 (EU AI Act), in force since August 2024, progressively applicable from 2025–2027.

Compliant · Low Risk
Overall assessment

✅ PCM Group exclusively uses AI systems with low or minimal risk.

No high-risk AI systems in use (Annex III EU AI Act). No prohibited AI practices (Art. 5). Full compliance with transparency obligations under Art. 50.

📊
Risk Classification of Our AI Systems
Overview by EU AI Act risk levels
Low risk
AI tool / use caseRisk levelRationaleRequirements
Claude.ai – Marketing & development▶️ LowInternal use, no customer data input, human reviews outputInternal transparency obligation
ChatGPT – Marketing & ticket analysis▶️ LowAnonymized content, no personal data, no customer contactInternal transparency obligation
Higgsfield AI – Video/image marketing⬇️ MinimalPurely generative creative content, no personal referenceLabeling as AI content
Ollama – Self-hosted, internal⬇️ MinimalFully internal, no external data transfer, no user contactNone specific
Mittwald mStudio AI – Product features▶️ LowEU hosting, user interaction possible, no high-risk areaTransparency obligation
Claude – Software development & tests⬇️ MinimalCode & test scenarios, no personal reference, developer reviews everythingNone specific
Note: No AI system in use falls under Annex III (high-risk AI) of the EU AI Act. In particular, no use in the areas of: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, or administration of justice.
🚫
Prohibited AI Practices – Art. 5 EU AI Act
Confirmation: none of these practices are in use
No prohibited practices

Pursuant to Art. 5 EU AI Act, the following AI practices are prohibited. PCM Group confirms that none of these systems are in use:

Prohibited practicePCM Group status
Subliminal manipulation of persons✅ Not in use
Exploitation of vulnerabilities/age/disability✅ Not in use
Social scoring by public authorities✅ Not in use (private company)
Real-time biometrics in public spaces✅ Not in use
Emotion recognition in the workplace/education✅ Not in use
Biometric categorization by sensitive characteristics✅ Not in use
Scraping biometric data from social media✅ Not in use
💬
Transparency Obligations – Art. 50 EU AI Act
Labeling of AI-generated content
Fulfilled
  • AI-generated text drafts are labeled as such internally and reviewed by a human before sending
  • No use of AI chatbots that pretend to be human
  • No deepfakes or AI-generated media without labeling
  • Users are informed when AI systems are used in the product context
  • AI-supported decision assistance is communicated as such – final decision always rests with the human
👤
Human Oversight
Humans always retain final decision-making authority
Ensured
  • All AI systems are used as assistive tools – no autonomous decision-making without human approval
  • AI outputs are reviewed by an employee before use
  • No AI system has direct write access to production databases
  • Kill switch: all AI services can be deactivated immediately
  • No AI system makes decisions that have legal or significant financial consequences for individuals
📅
EU AI Act – Timeline & Compliance Roadmap
Applicability of requirements by phase
On track
August 2024EU AI Act entered into force
February 2025Prohibited practices applicable (Art. 5) – ✅ PCM Group compliant
August 2025GPAI model requirements – ✅ not affected (no own GPAI model)
August 2026High-risk AI requirements – ✅ not affected (no high-risk AI in use)
August 2027Full application – transparency obligations already fulfilled
Conclusion: Since PCM Group exclusively uses AI systems with minimal or low risk and does not plan any high-risk applications, the essential compliance requirements of the EU AI Act are already fully met.
🏢
Accountability & Internal Governance
Who is responsible for AI compliance?
Overall responsibilityPCM Group management
Technical implementationPCM Technology / Agentur Circle GmbH
Data protection coordinationdatenschutz@pcm-group.at
Review cycleAnnually and upon introduction of new AI systems
Last assessmentJuly 2026
Questions about the EU AI Act & AI use

Inquiries about AI classification or the use of AI in our products.

Data Protection Request