Legal
Privacy Policy
Nature, scope, and purposes of the processing of personal data when using our website and Frank. Last updated: June 2026.
Protecting the confidentiality, integrity, and availability of the data we collect, process, or store on our website and in connection with the use of Frank is very important to us. With this privacy policy, we inform you about the nature, scope, and purposes of the processing of personal data in connection with the use of our website (https://www.salesfrank.com), our social media presence, and in connection with the use of Frank, to the extent that we are the controller, as well as about your rights as a data subject. Personal data means any data that relates directly or indirectly to you, such as your name, address, or usage behavior on a website.
1. Controller, Contact, and EU Representative
The controller within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR) for the data processing described in this privacy policy is:
Another Side Ventures FZ-LLC (“SalesFrank”, “we”, “us”)
Al Shohada Road 158
Ras Al Khaimah, United Arab Emirates
Email: info@salesfrank.com
All servers on which Frank is operated and on which data is processed are located exclusively within the European Union. A dedicated German entity is currently being established; this notice will be updated accordingly once that process is complete.
As a company headquartered outside the EU, we have appointed a representative in the European Union pursuant to Art. 27 GDPR. This representative is also your point of contact for all data protection matters:
heyData GmbH (Martin Bastius)
Schützenstraße 5, 10117 Berlin, Germany
Email: datenschutz@heydata.eu
1.1 Purposes of Processing and Legal Bases
In principle, the following may serve as a legal basis for data processing:
- Art. 6(1)(a) GDPR for processing for which we obtain consent.
- Art. 6(1)(b) GDPR, insofar as the processing is necessary for the performance of a contract or for pre-contractual measures (e.g. for inquiries about our services).
- Art. 6(1)(c) GDPR, where the processing is necessary to comply with a legal obligation to which we are subject (e.g. under tax law).
- Art. 6(1)(f) GDPR, where we can rely on legitimate interests (e.g. for technically necessary cookies).
1.2 Data Processing Outside the EEA
Insofar as we transfer data to service providers outside the EEA, this takes place only under the conditions set out in Art. 44 ff. GDPR. For service providers in the USA, the legal basis is generally an adequacy decision of the European Commission, provided the service provider is certified under the EU-U.S. Data Privacy Framework. In other cases, the legal basis is generally Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, which we have agreed with the respective service provider.
Our company is headquartered in the United Arab Emirates (UAE). However, all personal data is processed and stored exclusively on servers located within the EU (Microsoft Azure, Frankfurt region) — no data is stored in the UAE. Administrative remote access by authorized personnel from the UAE takes place exclusively via encrypted connections (VPN with multi-factor authentication) and, insofar as it constitutes a transfer to a third country, is safeguarded by Standard Contractual Clauses (Art. 46(2)(c) GDPR) in conjunction with a documented Transfer Impact Assessment (TIA). We provide the relevant documentation upon request.
1.3 Retention Period
Unless expressly stated otherwise, we delete stored data as soon as it is no longer required for its intended purpose and no statutory retention obligations apply. Otherwise, we restrict processing, i.e. the data is blocked and no longer processed for other purposes (e.g. in the case of commercial or tax law retention obligations).
1.4 Rights of Data Subjects
With respect to your personal data, you have the following rights:
- Right of access,
- Right to rectification or erasure,
- Right to restriction of processing,
- Right to object to processing,
- Right to data portability,
- Right to withdraw consent given, at any time.
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.
1.5 Obligation to Provide Data
Within the scope of a business relationship, you are only required to provide us with the data that is necessary for its establishment, performance, and termination, or which we are legally obligated to collect. Without this data, we are generally unable to conclude a contract or provide a service. Mandatory fields are marked as such.
1.6 No Automated Decision-Making in Individual Cases
To establish and carry out a business relationship, we do not, as a rule, use fully automated decision-making pursuant to Art. 22 GDPR. Should we use such procedures in individual cases, we will inform you separately where legally required.
1.7 Contacting Us
When you contact us (e.g. by email or telephone), we store the data provided (e.g. name and email address) in order to respond to your inquiry. The legal basis is our legitimate interest in responding to inquiries addressed to us (Art. 6(1)(f) GDPR). We delete the data as soon as storage is no longer necessary, or restrict processing where statutory retention obligations apply.
2. Newsletter
Interested parties can subscribe to a free newsletter. Registration takes place via the corresponding field on our website. We process the data provided in this context (in particular the email address) exclusively for sending the newsletter. The legal basis is your consent (Art. 6(1)(a) GDPR).
Sending and managing the newsletter, as well as the associated form data, takes place via our own automation infrastructure (n8n), which is operated on servers within the EU. No transfer to third-party providers outside the EEA takes place. Consent can be withdrawn at any time, e.g. via the unsubscribe link in each email or by notifying us at the email address provided above. The lawfulness of processing carried out prior to the withdrawal remains unaffected.
3. Data Processing on Our Website
3.1 Note for Visitors from Germany
Our website stores information on visitors' terminal equipment (e.g. cookies) or accesses information already stored there. Insofar as this is strictly necessary to provide an expressly requested service or to ensure IT security, it is based on § 25(2) No. 2 TDDDG. Otherwise, such storage or access is based on your consent (§ 25(1) TDDDG). The subsequent processing is governed by the following sections and the GDPR.
3.2 Informational Use of the Website
When the website is used purely for informational purposes, we collect the personal data that your browser transmits to our server in order to ensure stability and security. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). This data includes, in particular: IP address, date and time of the request, content of the request, HTTP status code, amount of data transferred, referring website, browser, operating system, and language. This data is stored in log files and deleted once storage is no longer necessary, and at the latest after 14 days.
3.3 Web Hosting and Provision of the Website
Our website is operated on the servers of a hosting provider located within the European Union. No transfer to a third country outside the EEA takes place. The provider processes the data transmitted via the website (e.g. content, usage, and meta/communication data) exclusively as a processor acting on our instructions. The legal basis is our legitimate interest in a secure and stable provision of the website (Art. 6(1)(f) GDPR).
3.4 Contact and Test Call Forms
On our website, you can contact us via forms or request a free test call from Frank. We store the data requested there (e.g. name, email address, telephone number, and, where applicable, details of your request) as well as the content of the message. Processing and forwarding take place via our own automation infrastructure (n8n) on servers within the EU. The legal basis is our legitimate interest in responding to inquiries addressed to us and in carrying out the test call you requested (Art. 6(1)(f) GDPR), as well as the performance of pre-contractual measures (Art. 6(1)(b) GDPR). We delete the data as soon as storage is no longer necessary, or restrict processing where retention obligations apply.
3.5 Booking Appointments (cal.com)
We use the service cal.com to schedule appointments on our website. When booking, the data you enter (e.g. name, email address, requested appointment) as well as meta/communication data are processed. Processing takes place exclusively on servers within the European Union; no transfer to a third country outside the EEA takes place. The legal basis is our legitimate interest in offering you a user-friendly way to schedule appointments (Art. 6(1)(f) GDPR), as well as the performance of pre-contractual measures (Art. 6(1)(b) GDPR). Further information can be found in the provider's privacy policy at https://cal.com/privacy.
3.6 Technically Necessary Cookies
Insofar as cookies are required for the operation of our website or its functions (“technically necessary cookies”), the legal basis is our legitimate interest in providing a functional website (Art. 6(1)(f) GDPR). We use these, for example, to store login and language settings.
3.7 Consent-Based Services (Analytics & Marketing)
We use the following services only on the basis of your consent (Art. 6(1)(a) GDPR or § 25(1) TDDDG). You may withdraw your consent at any time with effect for the future.
Meta Pixel
We use Meta Pixel to measure and optimize our advertisements on Facebook and Instagram. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. In this context, usage and meta/communication data (e.g. pages visited, IP address, device information) is processed and transferred to Meta Platforms Inc. in the USA. The legal basis for the transfer to the USA is the European Commission's adequacy decision (EU-U.S. Data Privacy Framework). Further information: https://www.facebook.com/privacy/policy.
Google Analytics (GA4)
We use Google Analytics 4 to analyze usage behavior on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In this context, usage and meta/communication data (e.g. pages visited, access times, truncated IP address) is processed and transferred to Google LLC in the USA. The legal basis for the transfer is the European Commission's adequacy decision (EU-U.S. Data Privacy Framework). Further information: https://policies.google.com/privacy.
Google Tag Manager
To manage the tags we use, we employ Google Tag Manager, provided by Google Ireland Limited. The Tag Manager itself does not collect personal data for analytical purposes, but serves to trigger other tags (e.g. the services listed above). Insofar as this results in a transfer to Google LLC in the USA, the legal basis is the European Commission's adequacy decision (EU-U.S. Data Privacy Framework).
PostHog
We use PostHog for product and usage analysis, to understand how our website is used and to improve it. The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. In this context, usage and meta/communication data (e.g. pages visited, clicks, access times, device/browser information, truncated IP address) is processed. We use PostHog's EU cloud: the data is processed and stored exclusively on servers within the European Union (Frankfurt am Main); no transfer to a third country outside the EEA takes place. Further information: https://posthog.com/privacy.
3.8 heyData Privacy Seal
We have integrated a privacy seal on our website. The provider is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. In doing so, the provider processes meta/communication data (e.g. IP addresses) within the EU. The legal basis is our legitimate interest in providing visitors with confirmation of our data protection compliance (Art. 6(1)(f) GDPR). The data is masked after collection, so that it can no longer be attributed to a specific person. Further information: https://heydata.eu/datenschutzerklaerung.
4. Social Media
We maintain a presence on social networks in order to present our company and our services. The operators of these networks regularly process their users' data for advertising purposes and create profiles based on usage behavior. It cannot be ruled out that these operators or their servers are located in non-EU countries and process data there. If you contact us via our profiles, we process the data you provide in order to respond to your inquiry; the legal basis is our legitimate interest (Art. 6(1)(f) GDPR). We maintain profiles on:
5. Changes to This Privacy Policy
We reserve the right to amend this privacy policy with effect for the future. The current version is always available here.
6. Questions and Comments
If you have any questions or comments regarding this privacy policy, please contact us using the contact details provided above.