Privacy Notice

Last updated: Jul 20th, 2026

1. Introduction

Below we provide information about the processing of personal data when using

  • our website https://www.telli.com/
  • our social media profiles.

Personal data is any data that can be related to a specific natural person, e.g. their name or their IP address.

1.1. Contact details

The controller within the meaning of Art. 4(7) of the EU General Data Protection Regulation (GDPR) is telli technologies GmbH, Knaackstraße 78, 10435 Berlin, Germany, e-mail: finn@telli.com. We are legally represented by Finn zur Mühlen, Sebastianos Hapte-Selassie, Philipp Baumanns.

Our data protection officer can be reached via heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, e-mail: datenschutz@heydata.eu.

1.2. Scope of the data processing, purposes of processing and legal bases

We set out the scope of the data processing, the purposes of processing and the legal bases in detail below. In principle, the following may be considered as a legal basis for data processing:

  • Art. 6(1)(a) GDPR serves as our legal basis for processing operations for which we obtain consent.
  • Art. 6(1)(b) GDPR is the legal basis where the processing of personal data is necessary for the performance of a contract, e.g. where a site visitor purchases a product from us or we perform a service for them. This legal basis also applies to processing that is necessary in order to take steps prior to entering into a contract, for example in the case of enquiries about our products or services.
  • Art. 6(1)(c) GDPR applies where we fulfil a legal obligation by processing personal data, as may be the case, for example, under tax law.
  • Art. 6(1)(f) GDPR serves as the legal basis where we can rely on legitimate interests for the processing of personal data, e.g. for cookies that are necessary for the technical operation of our website.

1.3. Data processing outside the EEA

Insofar as we transfer data to service providers or other third parties outside the EEA, adequacy decisions of the EU Commission pursuant to Art. 45(3) GDPR guarantee the security of the data during the transfer, where such decisions exist, as is the case, for example, for the United Kingdom, Canada and Israel.

When transferring data to service providers in the USA, the legal basis for the data transfer is an adequacy decision of the EU Commission, provided that the service provider has additionally certified itself under the EU-US Data Privacy Framework.

In other cases (e.g. where no adequacy decision exists), the legal basis for the data transfer is, as a rule, i.e. unless we provide a differing notice, standard contractual clauses. These are a set of rules adopted by the EU Commission and form part of the contract with the respective third party. Pursuant to Art. 46(2)(b) GDPR, they ensure the security of the data transfer. Many of the providers have provided contractual guarantees going beyond the standard contractual clauses, which protect the data beyond the standard contractual clauses. These include, for example, guarantees regarding the encryption of the data or regarding an obligation on the part of the third party to notify data subjects if law enforcement authorities seek to access data.

1.4. Storage period

Unless expressly stated within this privacy notice, the data stored by us is erased as soon as it is no longer necessary for its intended purpose and no statutory retention obligations preclude erasure. Insofar as the data is not erased because it is necessary for other legally permissible purposes, its processing is restricted, i.e. the data is blocked and not processed for other purposes. This applies, for example, to data that we are required to retain for reasons of commercial or tax law.

1.5. Rights of data subjects

Data subjects have the following rights vis-à-vis us with regard to the personal data relating to them:

  • right of access,
  • right to rectification or erasure,
  • right to restriction of processing,
  • right to object to the processing,
  • right to data portability,
  • right to withdraw a consent given, at any time.

Data subjects also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data. Contact details of the data protection supervisory authorities are available at https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html.

1.6. Obligation to provide data

Within the scope of a business relationship or other relationship, customers, prospective customers or third parties only have to provide us with the personal data that is necessary for the establishment, performance and termination of the business relationship or other relationship, or that we are legally obliged to collect. Without this data, we will, as a rule, have to refuse to conclude a contract or to provide a service, or will no longer be able to perform an existing contract or other relationship.

Mandatory information is marked as such.

1.7. No automated decision-making in individual cases

In principle, we do not use fully automated decision-making pursuant to Article 22 GDPR for the establishment and performance of a business relationship or other relationship. Should we use such procedures in individual cases, we will provide separate information about this insofar as this is required by law.

1.8. Contacting us

When you contact us, e.g. by e-mail or telephone, the data provided to us (e.g. names and e-mail addresses) is stored by us in order to answer questions. The legal basis for the processing is our legitimate interest (Art. 6(1)(f) GDPR) in answering enquiries addressed to us. We erase the data arising in this context once its storage is no longer necessary, or we restrict the processing if statutory retention obligations exist.

1.9. Customer surveys

From time to time we conduct customer surveys in order to get to know our customers and their wishes better. In doing so, we collect the data requested in each case. It is our legitimate interest to get to know our customers and their wishes better, so that the legal basis for the associated data processing is Art. 6(1)(f) GDPR. We erase the data once the results of the surveys have been evaluated.

2. Newsletter

If you are already a customer of ours and did not indicate otherwise when your data was collected, we reserve the right to inform you by e-mail about our own similar goods or services (Section 7(3) UWG [German Act Against Unfair Competition]). You can object to this use of your e-mail address at any time (e.g. via the link in every e-mail), without incurring any costs other than the transmission costs according to the basic rates. For non-purchasers (e.g. users of PAYG free minutes, future trials or ordinary website visitors), promotional e-mails are sent exclusively on the basis of your express consent by way of an opt-in procedure (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time with effect for the future.

Prospective customers have the option of subscribing to a free newsletter. We process the data provided upon registration exclusively for sending the newsletter. Registration takes place by selecting the corresponding field on our website, by ticking the corresponding box in a paper document, or by another unambiguous action by which prospective customers declare their consent to the processing of their data, so that the legal basis is Art. 6(1)(a) GDPR. Consent can be withdrawn at any time, e.g. by clicking the corresponding link in the newsletter or by notifying us at the e-mail address stated above. The processing of the data up to the withdrawal remains lawful even in the event of a withdrawal.

We send newsletters using LinkedIn. In doing so, the provider processes content data, usage data, meta/communication data and contact data.

3. Data processing on our website

3.1. Notice for website visitors from Germany

Our website stores information on the terminal equipment of website visitors (e.g. cookies) or accesses information already stored on the terminal equipment (e.g. IP addresses). Which information this is in detail can be found in the following sections.

This storage and this access take place on the basis of the following provisions:

  • Insofar as this storage or this access is strictly necessary in order for us to provide the service of our website expressly requested by website visitors (e.g. to operate a chatbot used by the website visitor or to ensure the IT security of our website), it takes place on the basis of Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG).
  • Otherwise, this storage or this access takes place on the basis of the website visitors' consent (Section 25(1) TDDDG).

The subsequent data processing takes place in accordance with the following sections and on the basis of the provisions of the GDPR.

3.2. Informational use of the website

In the case of informational use of the website, i.e. where site visitors do not separately transmit information to us, we collect the personal data that the browser transmits to our server in order to ensure the stability and security of our website. This constitutes our legitimate interest, so that the legal basis is Art. 6(1)(f) GDPR.

This data is:

  • IP address
  • date and time of the request
  • time zone difference to Greenwich Mean Time (GMT)
  • content of the request (specific page)
  • access status/HTTP status code
  • amount of data transferred in each case
  • website from which the request originates
  • browser
  • operating system and its interface
  • language and version of the browser software.

This data is also stored in log files. It is erased when its storage is no longer necessary, at the latest after 14 days.

3.3. Web hosting and provision of the website

Our website is hosted by Webflow. The provider is Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. In doing so, the provider processes the personal data transmitted via the website, e.g. content, usage, meta/communication data or contact data in the USA. Further information can be found in the provider's privacy policy at https://webflow.com/legal/eu-privacy-policy.

It is our legitimate interest to provide a website, so that the legal basis for the data processing described is Art. 6(1)(f) GDPR.

The legal basis for the transfer to a country outside the EEA is standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is ensured by standard data protection clauses adopted in accordance with the examination procedure pursuant to Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider.

We use the content delivery network Vercel for our website. The provider is Vercel Inc., 340 S Lemon Ave Unit 4133 Walnut, CA, USA. In doing so, the provider processes the personal data transmitted via the website, e.g. content data, usage data, meta/communication data or contact data, in the USA. Further information can be found in the provider's privacy policy at https://vercel.com/legal/privacy-policy.

We have a legitimate interest in using sufficient storage and delivery capacities in order to ensure optimal data throughput even during high load peaks. The legal basis for the data processing described is therefore Art. 6(1)(f) GDPR.

The legal basis for the transfer to a country outside the EEA is an adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is ensured because the EU Commission has decided, by way of an adequacy decision pursuant to Art. 45(3) GDPR, that the third country offers an adequate level of protection.

3.4. Contact form

When you contact us via the contact form on our website, we store the data requested there and the content of the message. The legal basis for the processing is our legitimate interest in answering enquiries addressed to us. The legal basis for the processing is therefore Art. 6(1)(f) GDPR. We erase the data arising in this context once its storage is no longer necessary, or we restrict the processing if statutory retention obligations exist.

3.5. Job advertisements

We publish job advertisements on our website, on pages connected to the website, or on third-party websites. The processing of the data provided in the context of the application takes place in order to carry out the application procedure. Insofar as this data is necessary for our decision to establish an employment relationship, the legal basis is Art. 88(1) GDPR in conjunction with Section 26(1) BDSG [German Federal Data Protection Act]. We have marked the data required to carry out the application procedure accordingly, or we indicate it. If applicants do not provide this data, we cannot process the application. Any further data is voluntary and not required for an application. If applicants provide further information, the basis is their consent (Art. 6(1)(a) GDPR).

We ask applicants to refrain from including in their CV and cover letter any information on political opinions, religious beliefs and similarly sensitive data. Such information is not required for an application. If applicants nevertheless provide such information, we cannot prevent its processing in the course of processing the CV or cover letter. Its processing is then likewise based on the applicants' consent (Art. 9(2)(a) GDPR).

Finally, we process applicants' data for further application procedures where they have given us their consent to do so. In this case, the legal basis is Art. 6(1)(a) GDPR.

We pass on the applicants' data to the responsible employees of the human resources department, to our processors in the area of recruiting, and to the other employees involved in the application procedure.

If, following the application procedure, we enter into an employment relationship with the applicant, we do not erase the data until after the end of the employment relationship. Otherwise, we erase the data at the latest six months after the rejection of an applicant.

If applicants have given us their consent to also use their data for further application procedures, we do not erase their data until one year after receipt of the application.

3.6. Booking of appointments

Site visitors can book appointments with us on our website. For this purpose, in addition to the data entered, we process meta or communication data. We have a legitimate interest in offering prospective customers a user-friendly means of arranging appointments. The legal basis for the data processing is therefore Art. 6(1)(f) GDPR. Insofar as we use a third-party tool for arranging appointments, the information on this can be found under "Third-party providers".

3.7. Technically necessary cookies

Our website uses cookies. Cookies are small text files that are stored in the web browser on a site visitor's terminal device. Cookies help to make the offering more user-friendly, effective and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter “technically necessary cookies”), the legal basis for the associated data processing is Art. 6(1)(f) GDPR. We have a legitimate interest in providing customers and other site visitors with a functional website. Specifically, we use technically necessary cookies for the following purpose or purposes:

  • cookies that store log-in data,
  • cookies that adopt language settings, and
  • Flash cookies that are set in order to play back media content.

3.8. Third-party providers

3.8.1. Webflow

We use Webflow for the design and provision of our website. The provider is Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the USA.

The legal basis for the processing is Art. 6(1)(a) GDPR. The processing takes place on the basis of consent. Data subjects can withdraw their consent at any time, e.g. by contacting us using the contact details provided in our privacy notice. The withdrawal does not affect the lawfulness of the processing up to the withdrawal.

The legal basis for the transfer to a country outside the EEA is standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is ensured by standard data protection clauses adopted in accordance with the examination procedure pursuant to Art. 93(2) GDPR (Art. 46(2)(c) GDPR), which we have agreed with the provider.

The data is erased once the purpose of its collection ceases to apply and no retention obligation precludes this. Further information is available in the provider's privacy policy at https://webflow.com/legal/eu-privacy-policy.

3.8.2. heyData

We have embedded a data protection seal on our website. The provider is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. The provider processes meta/communication data (e.g. IP addresses) in the EU.

The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in providing website visitors with confirmation of our data protection compliance. At the same time, the provider has a legitimate interest in ensuring that only customers with existing contracts use its seals, which is why a mere image copy of the certificate does not constitute a viable alternative for such confirmation.

The data is masked after collection so that there is no longer any personal reference. Further information is available in the provider's privacy policy at https://heydata.eu/datenschutzerklaerung.

3.8.4. Cookiebot (Usercentrics)

In order to manage your consents for the use of cookies and similar technologies, we use the consent tool Cookiebot. In this context, your IP address and your consent status are processed and stored in order to be able to document and comply with your preferences. The legal basis is the fulfilment of legal obligations pursuant to Art. 6(1)(c) GDPR.

3.8.5. Google Tag Manager & 3.8.6. Meta Pixel

Insofar as you have given us your consent via our cookie banner, we use Google Tag Manager to manage website tags as well as the Meta Pixel for analysis and for targeted marketing. The processing takes place exclusively on the basis of your consent pursuant to Section 25 TDDDG in conjunction with Art. 6(1)(a) GDPR. Any transfer of data to third countries (e.g. the USA) is safeguarded by appropriate guarantees such as the EU-US Data Privacy Framework.

3.8.7. Product analysis (PostHog)

In order to analyse the use of our app (app.telli.com) and to improve our product, we use the tool PostHog. The processing takes place on the basis of our legitimate interest in product optimisation pursuant to Art. 6(1)(f) GDPR.

3.9. Registration, customer account and use of the platform

When you register for our self-serve plans and create a customer account, we process your company and contact data for the purpose of initiating and performing the contract. The legal basis for this is Art. 6(1)(b) GDPR. During the subsequent use of our platform (app.telli.com), we process technically and functionally arising data such as login data, configurations and system logs in order to provide the service securely and free of errors. The legal basis for this is likewise Art. 6(1)(b) GDPR. The data arising in the context of the customer account is stored for the duration of the term of the contract and in order to fulfil subsequent statutory retention periods (e.g. under tax and commercial law).

3.10. “Call Me Now” demo call

On our website, we offer the option of a “Call Me Now” demo call in order to test our AI technology. In this context, we process your telephone number, carry out an SMS verification for security purposes, and record the AI test call including any transcription. In accordance with Art. 50 of the AI Regulation (AI Act), we expressly point out that during this test call you are interacting with an AI system. In doing so, we act as the controller. The legal basis for the processing is your consent (Art. 6(1)(a) GDPR).

4. Data processing on social media platforms

We are present on social media networks in order to present our organisation and our services there. The operators of these networks regularly process their users' data for advertising purposes. Among other things, they create user profiles from users' online behaviour, which are used, for example, to display advertising on the networks' pages and elsewhere on the internet that corresponds to the users' interests. For this purpose, the operators of the networks store information on usage behaviour in cookies on the users' computers. It also cannot be ruled out that the operators combine this information with further data. Users can obtain further information, as well as guidance on how users can object to the processing by the site operators, in the privacy policies of the respective operators listed below. It may also be the case that the operators or their servers are located in non-EU states, so that they process data there. This may give rise to risks for users, e.g. because the enforcement of their rights is made more difficult or state authorities gain access to the data.

When users of the networks contact us via our profiles, we process the data provided to us in order to answer the enquiries. This constitutes our legitimate interest, so that the legal basis is Art. 6(1)(f) GDPR.

4.1. LinkedIn

We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available here: https://www.linkedin.com/legal/privacy-policy?_l=de_DE. An option to object to the data processing is available via the advertising settings: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

5. Changes to this privacy notice

We reserve the right to amend this privacy notice with effect for the future. A current version is available here in each case.

6. Questions and comments

For any questions or comments regarding this privacy notice, we are happy to be available at the contact details provided above.