1. Controller
The entity responsible for data processing on this website is: Xcelsus GmbH, Emmy-Noether-Ring 8, 85716 Unterschleißheim
Email: gdpr@xcelsus.de
2. Collection and Storage of Personal Data and the Nature and Purpose of Their Use
a) When Visiting the Website
When you visit our website, the browser used on your device automatically sends information to the server of our website. This information is temporarily stored in a log file. The following information is collected without your intervention and stored until automated deletion after 30 days:
- IP address of the requesting computer
The mentioned data is processed by us for the following purposes:
- Ensuring a smooth connection setup of the website
- Ensuring comfortable use of our website
- Evaluation of system security and stability
b) When Registering on the Website
When registering on our website, the following personal data is collected:
- Name
- Address
- Company name
- Company address
These data are processed for the following purposes:
- Invoicing
- Customer service
- Website improvement
c) Employee Data Management
When users manage employee data, the following personal data is collected:
- Employee names
- Employee contact details
These data are processed for the following purposes:
- Employee data management
- Internal communication
d) Menu Management and Image Upload
When users manage their menu and upload images, the following data is collected:
- Menu data
- Uploaded images
These data are processed for the following purposes:
- Displaying the menu on the website
- Enhancing user experience
e) Logo Upload
When users upload their logo, the following data is collected:
- Uploaded logo
These data are processed for the following purposes:
- Personalizing the user profile
- Displaying on the website
f) Customer Orders
When customers place orders, the following personal data is collected:
- Name
- Contact details
- Order details
These data are processed for the following purposes:
- Order processing
- Customer service
3. Data Sharing
Your personal data will not be transferred to third parties for purposes other than those listed below. We only share your personal data with third parties if:
- You have given your explicit consent
- The transfer is necessary for the establishment, exercise, or defense of legal claims and there is no reason to assume that you have an overriding legitimate interest in not having your data shared
- There is a legal obligation for the transfer
- It is legally permissible and necessary for the processing of contractual relationships with you
4. Storage Duration
IP addresses are deleted after 30 days. Data required for invoicing and customer service are stored until the termination of the contractual relationship. Employee data, menu data, uploaded images, and logos are also stored until the termination of the contractual relationship.
5. Data Security
We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments. The data is stored on a secure SQL server hosted by Azure.
6. Rights of Data Subjects
You have the right:
- To request information about your personal data processed by us in accordance with Art. 15 GDPR
- To request the correction of incorrect or incomplete personal data stored by us without delay in accordance with Art. 16 GDPR
- To request the deletion of your personal data stored by us in accordance with Art. 17 GDPR, unless the processing is necessary to fulfill a legal obligation
7. Exercising Data Subject Rights
To exercise your rights, you can contact us via the contact form or by email at gdpr@xcelsus.de.
8. Use of Cookies
We only use necessary cookies to ensure the basic functions of the website.

