Data Protection Notice for Contract Partners

With the following information, we would like to provide you with an overview of the processing of your personal data by us and your data protection rights. The relevance of the information listed here depends on the type and scope of the services you use or have agreed upon.

Who is responsible for data processing, and whom can I contact?

The responsible party is

anevis solutions GmbH
Friedrich-Bergius-Ring 15, 97076 Würzburg
Phone: +49 931 46621710
info@anevis-solutions.com

You can reach our company’s data protection officer at

anevis solutions GmbH
Data Protection Officer
Friedrich-Bergius-Ring 15, 97076 Würzburg
Phone: +49 931 46621717
privacy@anevis-solutions.com

Which sources and data do we use?

We process personal data that we receive directly from you in the context of our business relationship, as well as, if applicable, from other data subjects (e.g., employees, other service providers) whose data is transmitted to us in connection with your business relationship. Furthermore, to the extent necessary for the provision of our services, we may legitimately obtain personal data from publicly accessible sources (e.g., commercial register, associations, press, internet) or receive it from other authorized third parties.

Relevant personal data includes name, address, phone number, and email address, advertising and sales data, documentation data (e.g., meeting minutes), and all other data necessary for the provision of our services.

For what purposes do we process your data (purpose of processing) and on what legal basis?

We process personal data in accordance with the provisions of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

a. For the fulfillment of contractual obligations (Art. 6 para. 1 b GDPR)

Data processing is carried out for the provision and mediation of financial services within the framework of the execution of our contracts with our customers or for the implementation of pre-contractual measures taken upon request. The purposes of data processing are primarily determined by the specific product (e.g., private or institutional factsheet, website charts, PRIIP calculations, sustainability reports, or other anevis products).

b. Within the framework of balancing interests (Art. 6 para. 1 f GDPR)

To the extent necessary, we process your data beyond the actual fulfillment of the contract to protect our legitimate interests or third parties. Examples:

  • Review and optimization of procedures for needs analysis for direct customer approach, within the framework of legal requirements and with due regard to the right to object.
  • Advertising or market and opinion research, provided you have not objected to the use of your data.
  • Assertion of legal claims and defense in legal disputes.
  • Ensuring IT security and IT operations of the company, e.g., through the use of technical and organizational protective measures such as access restrictions, encryption, and firewalls.
  • Prevention and investigation of criminal offenses.
  • Measures for business management and further development of services and products.

c. Based on your consent (Art. 6 para. 1 a GDPR)

If you have given us consent to process personal data for specific purposes (e.g., newsletter dispatch), the lawfulness of this processing is based on your consent. Granted consent can be revoked at any time. This also applies to the revocation of declarations of consent given to us before the GDPR came into force, i.e., before May 25, 2018. The revocation of consent is effective only for the future and does not affect the lawfulness of data processing carried out before the revocation.

d. Analysis of customer communication for quality assurance and service improvement

To continuously improve our service for you and ensure that we always handle your concerns to your full satisfaction, we conduct analyses of our written customer communication (emails). Below, we transparently explain how this process works and what rights you have.

i) Purpose of processing

The analysis serves exclusively the following purposes:

  • Improvement of service quality: We want to continuously evaluate and improve the quality of responses from our customer service team.
  • Early detection of customer dissatisfaction: By analyzing the tonality, we can detect potential misunderstandings or dissatisfaction early and proactively find a solution for you.
  • Identification of training needs and praise: We use the insights to train our employees specifically. It is equally important to us to recognize outstanding service performance and to be able to praise our employees for positive customer feedback.

ii) Legal basis and balancing of interests

We base this processing on our legitimate interest according to Art. 6 para. 1 lit. f GDPR.

We are aware that the complete content of your email communication is processed in this process. We have carefully weighed our legitimate interest – ensuring and increasing our service quality – against your right to the protection of your personal data. We have concluded that our interests prevail because we have taken the following comprehensive protective measures:

  • Processing takes place exclusively on local, secured IT systems and not with external AI service providers.
  • Access to the data and analysis results is limited to a tiny, specially trained group of persons in our quality assurance team who are bound to confidentiality. The aggregated results are passed on to the head of the Operations team.
  • No automated decisions are made that affect you. Each result merely serves as a basis for manual review by our employees.
  • Your emails will under no circumstances be used to train or further develop AI models (see separate point below).
  • You have a simple and obvious right to object to this processing at any time.

iii) Functionality and technology used

The process is as follows:

  1. Email communication between you and our company is read from our email system.
  2. To correctly capture the context, nuances, and course of a concern, the email is analyzed in its entirety. Automated removal of data (such as signatures or histories) has proven to be technically error-prone. It would increase the risk of misinterpreting the concern, which would counteract the purpose of quality improvement.
  3. The email is evaluated by AI software (Artificial Intelligence) on our internal system for its general tonality (e.g., positive, neutral, negative).
  4. The result of this AI analysis is exclusively reviewed and interpreted by the experienced employees of the quality assurance team mentioned above.

iv) Categories of data processed

Since no pseudonymization takes place, the following data categories are processed for analysis:

  • The complete content of your email communication, including the main text, previous messages in the thread, email headers (with sender, recipient, timestamp), and all information from your signature (e.g., name, company, position, contact details).

v) No use of your data for AI training

We expressly assure you: Your emails will never be used to train or further develop our AI models. The analysis serves exclusively the application purpose described above (“inference”). For the development and training of our systems, we exclusively use fully pseudonymized, manually post-processed datasets or entirely fictitious data, which have also been cleansed of any trade secrets.

vi) No automated decision-making

It is again expressly pointed out that the AI analysis merely serves as a supporting tool. No automated decisions are made that have legal or similarly significant effects for you. Each analysis result is evaluated by a human before any measures for service improvement are initiated.

vii) Storage duration

The results of the sentiment analysis are stored only as long as necessary for the purpose of quality assurance and internal evaluation. These analysis results will be deleted after 6 months at the latest. The original emails are subject to the regular retention periods for business communication.

viii) Your right to object according to Art. 21 GDPR

Since we base this processing on our legitimate interest, you have the right to object to this processing at any time for reasons arising from your particular situation. We will then stop processing your data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms.

You can send your objection informally to the following email address: privacy@anevis-solutions.com

ix) Further data subject rights

Information on your other rights, such as access, rectification, erasure, and data portability, can be found in the section “What data protection rights do I have?”

Who receives my data?

Within the company, those departments that need access to your data to fulfill our contractual and legal obligations receive it. Service providers and vicarious agents commissioned by us may also receive data for these purposes. These are companies in the categories of IT services and sales and marketing.

Data is only passed on to third parties after proper consent or under special conditions, if legal provisions require it. Recipients of personal data may include, for example:

  • Public bodies and institutions (law enforcement agencies, Federal Financial Supervisory Authority), if there is a legal or official obligation.
  • Other financial service institutions, comparable institutions, or service providers to whom we transmit personal data (e.g., correspondence data) for the purpose of conducting the business relationship with you.
  • Creditors or insolvency administrators who inquire in the context of enforcement.
  • Service providers we use in the context of order processing relationships.

 

Further data recipients may be those entities for which you have given us your consent to data transmission or to whom we are authorized to transmit personal data based on a balancing of interests.

Will data be transferred to a third country or an international organization?

Data transfer to entities in countries outside the European Union (so-called third countries) takes place if this is necessary for the fulfillment of our contractual obligations by service providers commissioned by us, based on your consent, legal regulations, or to protect our legitimate interests.

In all cases of transfer to third countries, we ensure that an adequate level of data protection is guaranteed. This is primarily done by:

  • The existence of an adequacy decision by the European Commission (Art. 45 GDPR) for the respective third country.
  • The application of appropriate safeguards, such as standard contractual clauses of the European Commission (Art. 46 GDPR), supplemented by necessary additional protective measures (Transfer Impact Assessments), if required.

In exceptional cases, data transfer to a third country may also occur without the above-mentioned safeguards if one of the conditions according to Art. 49 para. 1 GDPR is met. This is the case for:

  • Your explicit consent for the specific individual case.
  • The necessity for the fulfillment of a contract with you or for the implementation of pre-contractual measures at your request.
  • Legal regulations, e.g., for combating money laundering or terrorist financing.

No further transfer of personal data takes place unless legally required.

How long will my data be stored?

We process and store your personal data for as long as this is necessary for the fulfillment of our contractual and legal obligations. It should be noted that our business relationship is a long-term obligation that is designed for years.

Suppose the data is no longer required for the fulfillment of contractual or legal obligations. In that case, it will be regularly deleted, unless its temporary further processing is necessary for the following purposes:

  • Fulfillment of commercial and tax law retention obligations, which may arise, for example, from: German Commercial Code (HGB), Tax Code (AO). The periods specified therein for retention or documentation usually range from two to ten years.
  • Preservation of evidence within the framework of statutory limitation periods. According to §§ 195 ff of the German Civil Code (BGB), these limitation periods can be up to 30 years, with the regular limitation period being 3 years.

What data protection rights do I have?

Every data subject has the right to information according to Article 15 GDPR, the right to rectification according to Article 16 GDPR, the right to erasure according to Article 17 GDPR, the right to restriction of processing according to Article 18 GDPR, the right to object according to Article 21 GDPR, and the right to data portability according to Article 20 GDPR. For the right to information and the right to erasure, the restrictions according to §§ 34 and 35 BDSG apply. Furthermore, there is a right to complain to a competent data protection supervisory authority (Article 77 GDPR in conjunction with § 19 BDSG).

You can revoke any consent given to us for the processing of personal data at any time. This also applies to the revocation of declarations of consent given to us before the GDPR came into force, i.e., before May 25, 2018. Please note that the revocation is only effective for the future. Processing that took place before the revocation is not affected by it.

Am I obliged to provide data?

Within the framework of our business relationship, you must provide the personal data that is necessary for the establishment, execution, and termination of a business relationship and for the fulfillment of the associated contractual obligations, or for which we are legally obliged to collect. Without this data, we will generally not be able to conclude a contract with you, execute it, and terminate it.

Is automated decision-making used?

We generally do not use fully automated decision-making according to Article 22 GDPR for the establishment or execution of the business relationship.

Does profiling take place?

Automated decision-making, including profiling according to Art. 22 GDPR, does not take place.

Information on the right to object according to Article 21 GDPR

You have the right to object at any time to the processing of your personal data if it is based on a balancing of interests (Art. 6 para. 1 lit. f GDPR) or in the public interest (Art. 6 para. 1 lit. e GDPR) – provided that there are reasons arising from your particular situation.

Furthermore, you can object to the processing of your data for direct marketing purposes at any time without giving reasons. In this case, your data will no longer be processed for advertising purposes.

Please send your objection informally, stating your name and address, with the subject “Objection” to:

anevis solutions GmbH
Friedrich-Bergius-Ring 15, 97076 Würzburg
Phone: +49 931 46621717
privacy@anevis-solutions.com

As of: 20. October 2025