top of page
  • LinkedIn
  • Instagram
  • Facebook

Privacy Policy

Last Updated: July 2026

1. Data Protection at a Glance

General Information

The following notice provides a simple overview of what happens to your personal data when you visit our website or participate in our services. Personal data is any data with which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.

Data Collection on Our Website

Who is responsible for data collection on this website?

The data processing on this website is carried out by the website operator. You can find the operator's contact details in the Impressum (Legal Notice) of this website.

How do we collect your data?

On one hand, your data is collected when you communicate it to us. This can, for example, be data that you enter into our B2B consultation or employee registration forms. Other data is collected automatically or after your consent by our IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of the page view).

What do we use your data for?

Part of the data is collected to ensure the error-free provision of the website. Other data can be used to analyze your user behavior or to fulfill our core matching and event organization services.

What rights do you have regarding your data?

You have the right to receive information about the origin, recipient, and purpose of your stored personal data free of charge at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right to lodge a complaint with the competent supervisory authority.

2. Controller Identity (Responsible Party)

The party responsible for data processing on this website and within our services (the "Controller") is:

EXMACHINE UG (haftungsbeschränkt) i. G.

Wilhelm-Kabus-Str. 22-24

10829 Berlin (Engelnest Coworking Space)

Germany

Represented by: K. Haldun Oz, Managing Director

Contact Email: hello@exmachine.co

Note: Since the company is currently in formation (in Gründung), the Managing Director represents the pre-company (Vorgesellschaft) and carries direct responsibility.

3. Categories of Data, Purposes, and Legal Basis

We process personal data in compliance with the European General Data Protection Regulation (GDPR / DSGVO) and the German Federal Data Protection Act (BDSG).

A. Website Visits and Log Files

When you access our website, your browser automatically transmits data to our server. This information is temporarily stored in log files.

  • Data processed: IP address, date and time of access, browser type/version, operating system, referrer URL.

  • Purpose: Ensuring a smooth connection setup, comfortable use of our website, and system security.

  • Legal Basis: Art. 6(1)(f) GDPR (Legitimate Interest in maintaining website stability and security).

B. B2B Consultation Requests & Custom Events (HR Departments & Corporations)

When an HR representative or corporate client fills out our contact forms to request a free consultation, book a standard event, or request a tailored corporate project via our Custom Events framework.

  • Data processed: Company Name, Corporate Email, Corporate Phone Number, Event Type (including Custom Event specifications), Preferred Date, Estimated Number of Guests, and any operational notes entered in "Tell Us About Your Vision".

  • Purpose: Handling corporate requests, planning tailored company event formats, automated pricing/quoting, scheduling business-to-business communications, and executing pre-contractual evaluations.

  • Legal Basis: Art. 6(1)(b) GDPR (Processing is necessary for taking steps prior to entering into a contract or for the performance of a corporate service contract).

C. Employee Registration and AI-Powered Matching (B2C & Custom Event Participants)

When employees register for an exclusive Exmachine event or a private company session under our Custom Events track via our digital forms distributed by their respective HR departments.

  • Data processed: Full name, gender, corporate email address, physical address (solely for shipping masks), age (minimum 18 years required), professional profile details (salary band, education level), and personal matching preferences (5 shared interests, 5 personal dealbreakers).

  • Purpose:

    1. Executing data-driven compatibility calculations through our smart matching algorithm to curate compatible configurations (e.g., 3 female and 3 male participants per table/company setup).

    2. Operational and logistical management (shipping physical masks and materials to corporate offices or directly to participants).

    3. Facilitating secure, anonymous interactions at the standard or custom corporate events under strict pseudonyms (city code names).

    4. Next-day mutual match notifications via secure email workflows.

  • Legal Basis: Art. 6(1)(a) GDPR (Explicit Consent given by the participant via the required checkbox before submission) and Art. 6(1)(b) GDPR (Fulfillment of the service contract).

4. Automated Decision-Making and Profiling (Smart Matching)

To provide our core networking format, we utilize a data-driven matching protocol that cross-references participant profiles based on metric compatibility (including education level, salary band, shared interests, and personal dealbreakers). This process involves structured algorithmic evaluation via secure third-party Large Language Model (LLM) APIs (specifically Google Cloud Gemini Pro Enterprise API).

  • Data Minimization in AI Processing: When sending data to the matching API, we apply data minimization principles. Data transferred is limited strictly to the parameters required for table optimization. Your data is processed via secure European enterprise endpoints and is strictly never utilized by third-party providers to train public AI models.

  • Logic Involved: The system analyzes the submitted operational criteria to generate high-compatibility seating shortlists (optimizing configurations to 3 female and 3 male participants per company), minimizing social mismatching.

  • Human Intervention: No final selection that legally or significantly affects a participant is made entirely automatically. A human event manager manually reviews and approves the configurations generated by the sheets/API protocol before final event verification, mask distribution, and logistical execution.

  • Your Rights: Under Art. 22(3) GDPR, participants have the right to express their point of view regarding the matching criteria, request manual human intervention, or opt-out of the current selection pool at any time by contacting hello@exmachine.co.

 

5. Anonymity Framework and Data Sharing

  • Anonymity at the Event: During the experience, your real identity, exact company of employment, and direct contact details are completely hidden. You are identified solely by your mask and your unique anonymous city code badge.

  • Data Sharing with Other Participants: Your contact information is strictly confidential and is never shared openly. It is only released to another specific participant if—and only if—both parties explicitly confirm a mutual choice via our secure follow-up system the next day.

  • Data Sharing with Third-Party Processors (Data Recipients): We do not sell, trade, or rent your personal datasets. To run our digital infrastructure and operations, data is securely processed under strict Data Processing Agreements (DPA) according to Art. 28 GDPR with the following categories of recipients:

    1. Website & Cloud Database Infrastructure: Wix.com Ltd. (EU-based cloud hosting servers).

    2. Algorithmic Processing Infrastructure: Google Cloud EMEA (Gemini Pro Enterprise API infrastructure deployed via secure European data centers).

    3. Logistics Partners: Local courier and postal services within Germany (strictly limited to name and address for physical mask shipment to your office or designated address).

    4. Communications: Secure email infrastructure providers used to distribute mutual match notifications.

6. Data Retention and Erasure (How Long We Keep Your Data)

We follow the principles of data minimization and storage limitation.

  • Unmatched Profiles: If you submit a questionnaire but are not shortlisted for the current event, your operational questionnaire data is stored securely and used only for future event invitations, provided you have consented. If you do not wish to remain in the loop, your profile is permanently deleted immediately.

  • Event Participants: Operational profiles used for active matching are preserved for up to 30 days following the conclusion of the event to handle late match requests and post-event feedback cycles. After this period, data is either fully deleted or irreversibly anonymized for analytical forecasting.

  • B2B Client Data: Commercial data (invoices, contracts, correspondence with HR) is retained in accordance with German statutory commercial and tax retention periods ($\S\ 257$ HGB, $\S\ 147$ AO), which generally mandate 10 years.

7. Your Rights Under GDPR

As a data subject, you hold the following statutory rights under the GDPR:

  • Art. 15 GDPR (Right of Access): You can request a copy of all personal data we hold about you.

  • Art. 16 GDPR (Right to Rectification): You can demand the immediate correction of inaccurate data.

  • Art. 17 GDPR (Right to Erasure / "Right to be Forgotten"): You can demand the deletion of your data unless statutory retention rules apply.

  • Art. 18 GDPR (Right to Restriction of Processing): You can block further processing of your data under specific legal conditions.

  • Art. 20 GDPR (Right to Data Portability): You have the right to receive your data in a structured, machine-readable format.

  • Art. 21 GDPR (Right to Object): You have the right to object at any time to processing based on legitimate interests or direct marketing.

  • Art. 7(3) GDPR (Right to Withdraw Consent): You can revoke your data processing consent at any time with future effect.

To exercise any of these rights, please send an explicit email to hello@exmachine.co.

Right to Lodge a Complaint with a Supervisory Authority

If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR. The competent authority for our location is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Alt-Moabit 59-61, 10555 Berlin

Email: mailbox@datenschutz-berlin.de

8. Cookies and Tracking Technologies

Our website utilizes cookies. Technical (essential) cookies are deployed based on Art. 6(1)(f) GDPR to guarantee site navigation and stability. Non-essential tracking cookies (e.g., Google Ads, LinkedIn Ads) to evaluate marketing reach are strictly deactivated by default. They will only deploy if you explicitly trigger consent via our Cookie Banner. For a detailed breakdown of specific scripts, storage durations, and opting out, please consult our dedicated Cookie Policy page.

9. Changes to this Privacy Policy

We reserve the right to amend this privacy policy to adapt it to changing legal frameworks or technical updates to our platform. The current version will always be accessible directly on our website.

bottom of page