Privacy policy
Information pursuant to Art. 13 and 14 GDPR. Last updated: 17 August 2026. The German version is the legally authoritative one.
1. About this privacy notice
This privacy notice explains how grow.file GmbH (“grow.file”, “we”, “us”, “our”) processes personal data in connection with our public website at growfile.de (the “Website”).
The Website is informational. It has no user accounts, no login, no forms and no shop.
This notice does not cover the grow.file competence platform, which is not publicly available and will have its own privacy notice. It does not cover third-party websites reached via links from the Website.
Questions about this notice: privacy@growfile.de.
2. Controller and contact
The controller within the meaning of Article 4(7) GDPR is:
grow.file GmbH
Garskestraße 31
04205 Leipzig, Germany
Email: hello@growfile.de
Privacy enquiries: privacy@growfile.de
Represented by: Prof. Dr. Gerlind Große, Managing Director
2.1 Data Protection Officer
We have not appointed a Data Protection Officer; we are not required to do so under Article 37(1) GDPR or § 38(1) BDSG.
3. General principles of data processing
We process personal data on the following legal bases:
- Article 6(1)(a) GDPR — consent, for retaining an application beyond the standard period. Consent can be withdrawn at any time with effect for the future.
- Article 6(1)(b) GDPR — contract or pre-contractual steps, for enquiries about working together and for job applications.
- Article 6(1)(c) GDPR — legal obligation, for commercial and tax-law retention of correspondence.
- Article 6(1)(f) GDPR — legitimate interests, for the secure and reliable operation of the Website. We have weighed these interests against the rights and freedoms of data subjects.
We collect personal data only to the extent necessary for the purpose described in each section below. We do not sell personal data and do not use it for advertising.
4. When you visit our website
4.1 Server log data
Loading a page on growfile.de transmits the following to our hosting provider:
- IP address,
- date and time of the request,
- the address requested and the HTTP method,
- referrer URL,
- response status code and volume of data transferred,
- browser type and version, and operating system.
Legal basis: Article 6(1)(f) GDPR. Purpose: delivery, security and error diagnosis. This data is not combined with other sources and is not used to identify individual visitors. Storage period: 180 days.
4.2 Cookies and similar technologies
The Website sets no cookies — none for analytics, none for advertising, and none for session management. No information is stored in or read from your terminal equipment beyond your browser's ordinary HTTP cache. § 25 TTDSG does not apply.
4.3 Analytics and third-party content
We use no web analytics, no reach measurement and no tracking.
The Website loads no resources from third-party servers:
- fonts are served from our own server; we use no font CDN,
- there are no embedded videos, maps, social media widgets, comment systems, chat widgets or external image hosts,
- the only script is a local file that closes the mobile navigation menu.
Visiting the Website discloses your IP address to our hosting provider and to no one else.
5. When you contact us
5.1 Email enquiries
The Website has no contact form; contact is by email.
We process your email address, your name where given, and the content of your message, in order to deal with your enquiry. Legal basis: Article 6(1)(b) GDPR where the enquiry concerns entering into or performing a contract, otherwise Article 6(1)(f) GDPR.
Email is not encrypted end-to-end. For sensitive material, contact us first to agree a route.
5.2 Job applications
Applications to jobs@growfile.de are processed solely for the selection procedure concerned. Data processed: name, contact details, CV, qualifications, references and covering letter.
Legal basis: § 26(1) BDSG in conjunction with Article 6(1)(b) GDPR.
Where no position is offered, application documents are deleted six months after the end of the procedure.
Where you ask us to retain your documents for future openings, the legal basis is Article 6(1)(a) GDPR and they are deleted after a further twelve months or on withdrawal of consent, whichever is earlier.
Applications are received in a mailbox operated by our email provider; see section 7.
6. Required provision of personal data
Reading the Website requires no personal data.
Contacting us requires a reply address and the content of your request. Applying for a role requires the information needed to assess the application. Provision is voluntary; without it we cannot answer the enquiry or consider the application.
7. Categories of recipients
Within grow.file GmbH, access is limited to those whose role requires it.
The following external recipients process personal data on our behalf as processors under Article 28 GDPR:
- Website hosting — Elestio, on infrastructure provided by Hetzner Online GmbH, Gunzenhausen, as sub-processor. Server location: Falkenstein, Germany.
- Email — mailbox.org, operated by Heinlein Support GmbH, Berlin. Server location: Germany.
We disclose personal data to public authorities, courts and legal advisors where obliged or permitted by law.
A data processing agreement under Article 28 GDPR is in place with each processor.
8. Transfer to third countries
No personal data is transferred to a country outside the European Economic Area. Hosting and email are operated on servers in Germany by providers established in the European Union.
9. Security
We use technical and organisational measures appropriate to the risk. For the Website these are:
- TLS encryption of all traffic, with HTTP permanently redirected to HTTPS and HTTP Strict Transport Security enabled,
- a static site with no database, no login, no forms and no server-side application code,
X-Content-Type-Options,Referrer-Policyand related response headers,- no third-party code,
- access controls and least privilege for staff and processors,
- regular review of dependencies and infrastructure.
10. Storage period
| Data | Storage period |
|---|---|
| Server access logs | 180 days |
| Email correspondence (general enquiries) | Deleted once the matter is concluded. Correspondence qualifying as a commercial or business letter: 6 years (§ 257(1)(2), (4) HGB); where tax-relevant: 10 years (§ 147 AO) |
| Job applications, unsuccessful | 6 months after the end of the procedure |
| Job applications, retained on consent | up to a further 12 months, or until consent is withdrawn |
Erasure requests: privacy@growfile.de.
11. Your rights
You have the following rights in respect of your personal data:
- Access (Article 15 GDPR),
- Rectification (Article 16 GDPR),
- Erasure (Article 17 GDPR),
- Restriction of processing (Article 18 GDPR),
- Data portability (Article 20 GDPR),
- Objection (Article 21 GDPR) to processing based on Article 6(1)(f) GDPR,
- Withdrawal of consent (Article 7(3) GDPR), without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights: privacy@growfile.de. We respond without undue delay and at the latest within one month.
You have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority competent for grow.file GmbH is:
Die Sächsische Datenschutzbeauftragte
Devrientstraße 5
01067 Dresden, Germany
Email: saechsdsb@slt.sachsen.de
You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.
12. Automated decision-making, including profiling
We carry out no automated decision-making, including profiling, within the meaning of Article 22 GDPR in connection with the Website. The Website runs no models and makes no inferences about visitors.
13. Changes to this notice
We may update this notice to reflect changes to the Website, to our processors or to applicable law. The date above indicates the last revision.