---
title: "Privacy Policy"
description: "Effective date: 28 September 2026"
canonical: "https://coworkingview.com/en/privacy"
---

# Privacy Policy

Effective date: 28 September 2026

On this page

-   [1\. Data Controller](#controller)
-   [2\. Data Protection Officer](#dpo)
-   [3\. Categories of Data Processed](#dataCategories)
-   [4\. Sources of Personal Data](#dataOrigin)
-   [5\. Purposes and Legal Bases for Processing](#purposes)
-   [6\. Storage Periods](#retention)
-   [7\. Recipients](#disclosure)
-   [7b. Service Providers and Processors](#processors)
-   [8\. Transfers to Third Countries](#internationalTransfers)
-   [9\. Security](#security)
-   [9b. Server Log Files](#serverLogs)
-   [10\. Your Rights](#rights)
-   [10b. Right to Object under Art. 21 GDPR](#objection)
-   [11\. Automated Decision-Making and Profiling](#automatedDecisions)
-   [11b. AI Assistant (Google Gemini)](#aiChatbot)
-   [11c. Google reCAPTCHA](#recaptcha)
-   [11d. Location from Your IP Address](#geolocation)
-   [11e. Referral Programme](#referral)
-   [11f. Operators and the Partner Portal](#partnerPortal)
-   [12\. Cookies and Similar Technologies](#cookies)
-   [12b. Advertising and Campaign Measurement](#adMeasurement)
-   [12c. Google Analytics 4](#analytics)
-   [12d. Error Monitoring (Sentry)](#errorMonitoring)
-   [13\. Third-Party Websites and External Links](#thirdPartyLinks)
-   [14\. Minors](#minors)
-   [15\. Changes to this Policy](#changes)
-   [16\. Contact](#contact)

This Privacy Policy tells you, as required by Articles 13 and 14 GDPR, which personal data we process when you visit coworkingview.com, use our AI assistant, send us an enquiry or work with us as an operator, for which purposes, on which legal basis, to whom we disclose it and what rights you have. The applicable law is the GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG). Our Cookie Policy additionally describes how we use cookies and similar technologies.

## 1\. Data Controller

The controller within the meaning of Art. 4(7) GDPR is Carlos Javier Müller González, CoworkingView, Sonnenallee 279, 12057 Berlin, Germany. Email: [info@coworkingview.com](mailto:info@coworkingview.com), phone: +49 151 56130622. Please send all data protection enquiries and requests to exercise your rights to this address.

## 2\. Data Protection Officer

CoworkingView is a sole proprietorship in which fewer than 20 people are regularly engaged in the automated processing of personal data, and its core activity is not the large-scale monitoring of individuals. We are therefore not required to appoint a data protection officer under Art. 37 GDPR or § 38(1) BDSG. The owner is your contact for data protection matters at [info@coworkingview.com](mailto:info@coworkingview.com).

## 3\. Categories of Data Processed

Depending on how you use our services, we process:

-   Contact data: name, email address, phone number and, for operators, postal address.
-   Company data: company name and, where needed for brokerage or invoicing, registration number and VAT ID.
-   Enquiry data: type of space, number of desks, location, budget, period, requested viewing date, your message and the spaces your enquiry relates to.
-   Context of an enquiry: up to ten recently viewed spaces, the page you send the enquiry from, and campaign information (section 12b). We derive city and country from your IP address; we do not store the IP address itself with the enquiry.
-   Contract and billing data: evidence of introductions, operators' contract confirmations, invoices and commission correspondence.
-   Communication data: emails, chat messages to our AI assistant, notes of phone calls.
-   Technical data: IP address, date and time, requested URL, referrer, browser and device type (server log files, section 9b) and the identifiers listed in our Cookie Policy.
-   Partner portal credentials: username or email address and a password stored only as a cryptographic hash.

## 4\. Sources of Personal Data

We collect your data:

-   directly from you — through our forms, the AI assistant, by email or phone;
-   from operators, where they tell us in the course of a brokerage whether and when a contract with you was signed;
-   from another person who named you through our referral programme (section 11e);
-   for operators and their contact persons, also from publicly available sources, in particular their website and imprint (Art. 14 GDPR);
-   automatically when you visit the website (sections 9b and 12).

## 5\. Purposes and Legal Bases for Processing

We process personal data for the following purposes and on the following legal bases:

-   Handling your enquiry, finding and brokering suitable spaces, forwarding it to the operator you selected, arranging viewings — Art. 6(1)(b) GDPR (contract or pre-contractual steps). Where you act for a company, we process your contact data as its contact person under Art. 6(1)(f) GDPR; our legitimate interest is carrying out the mandate with your company.
-   Working with operators, invoicing and evidencing commission claims — Art. 6(1)(b) and (f) GDPR.
-   Onboarding and looking after operators: contacting operators and their contact persons to present our services and terms, and publishing their listings — Art. 6(1)(f) GDPR (interest in a complete market comparison and in business relationships); once an agreement is signed, Art. 6(1)(b) GDPR.
-   Complying with legal obligations, in particular under trade, broker (MaBV), anti-money-laundering (GwG), commercial and tax law — Art. 6(1)(c) GDPR.
-   Operating the website securely, preventing abuse and spam, analysing errors — Art. 6(1)(f) GDPR.
-   Audience and campaign measurement, where information is stored on or read from your device for it — your consent, § 25(1) TDDDG and Art. 6(1)(a) GDPR (sections 12 to 12c).
-   Establishing, exercising or defending legal claims — Art. 6(1)(f) GDPR.
-   We send newsletters or other advertising by email only with your express consent (Art. 6(1)(a) GDPR, § 7(2) no. 2 UWG); we do not currently run a newsletter.

## 6\. Storage Periods

We keep personal data only as long as the purpose requires or a statutory retention obligation applies. In detail:

-   Enquiries that do not lead to a contract: deleted no later than three years after the end of the year of the last contact (standard limitation period, §§ 195, 199 BGB), unless you ask for deletion earlier and no retention obligation prevents it.
-   Brokerage records: records and documents under § 10 MaBV are kept for five years (§ 14 MaBV); information collected under the Anti-Money Laundering Act also for five years (§ 8(4) GwG).
-   Commercial and tax records: business letters sent and received for six years, accounting vouchers such as invoices for eight years, books and annual accounts for ten years (§ 147 AO, § 257 HGB where applicable), each from the end of the calendar year.
-   Partner portal access: for the duration of the listing; the account is then deleted unless one of the periods above applies.
-   Server log files and error reports: only as long as needed for troubleshooting and preventing abuse (sections 9b and 12d).
-   Analytics data in Google Analytics: at most 14 months.
-   Cookie consents: in your browser, until you change your choice or clear your browser data (Cookie Policy).
-   Where a purpose has ended but a retention obligation has not, we restrict processing and use the data only to meet that obligation.

## 7\. Recipients

We disclose personal data only where necessary:

-   Operators: we forward your enquiry to the operator of the space you are interested in (Art. 6(1)(b) GDPR). From receipt, the operator is independently responsible for further processing.
-   Processors: service providers acting on our behalf and on our instructions under contracts pursuant to Art. 28 GDPR (section 7b).
-   Advertising and analytics providers, where you have consented (sections 12b and 12c).
-   Tax advisers, lawyers and courts, where needed to meet legal obligations or enforce claims.
-   Authorities, where we are legally required to do so.
-   We do not sell personal data.

## 7b. Service Providers and Processors

To run the website and handle enquiries we use in particular:

-   Hosting: Hostinger International Ltd., Larnaca, Cyprus — servers running the website, the content management system and our self-hosted customer relationship management (CRM) system.
-   Cloudflare, Inc., San Francisco, USA — content delivery network, attack protection and DNS. Every request to the website passes through Cloudflare, which processes in particular IP addresses and technical request data.
-   Zoho Corporation B.V., Utrecht, Netherlands — email sending and mailbox (EU data centre).
-   Discord Inc., San Francisco, USA — our team's internal notification channel. New enquiries, including contact and enquiry data, are posted there so we can respond quickly.
-   Functional Software, Inc. (Sentry), San Francisco, USA — error monitoring; data is stored in an EU data centre (Germany) (section 12d).
-   Google Ireland Limited, Dublin, Ireland — reCAPTCHA (section 11c) and the Gemini AI model for our assistant (section 11b).
-   IP-API.com (ip-api.com) — estimating approximate location from the IP address (section 11d).
-   Kickbox, Inc., USA — checking whether the domain of an email address belongs to a disposable-email provider. Only the domain (the part after the @) is sent, never the full address.

## 8\. Transfers to Third Countries

Some of the providers named are based in the USA or may transfer data there. We base transfers to the USA on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified under it — to our knowledge this applies to Google, Cloudflare, Discord, Sentry, LinkedIn and X — and otherwise on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can request a copy of the safeguards at [info@coworkingview.com](mailto:info@coworkingview.com).

## 9\. Security

We protect your data with appropriate technical and organisational measures (Art. 32 GDPR): encrypted transmission (TLS), access to servers and systems only for authorised persons bound to confidentiality and only with strong authentication, firewall rules restricting access to the server, regular security updates and daily backups. No transmission over the internet is entirely risk-free.

## 9b. Server Log Files

Each time the website is accessed, our servers and Cloudflare process technically necessary data: IP address, date and time, requested URL, amount of data transferred, status code, referrer, and browser and operating-system details. We need them to deliver the website, keep it stable and secure, and fend off attacks and abuse such as automated mass requests; for that purpose we also limit the number of requests per IP address. The legal basis is Art. 6(1)(f) GDPR. Log data is not combined with other data and is deleted as soon as it is no longer needed for these purposes; rate-limiting counters are held in memory only.

## 10\. Your Rights

You have the following rights against us:

-   Access to the data we hold about you (Art. 15 GDPR).
-   Rectification of inaccurate data (Art. 16 GDPR).
-   Erasure of your data (Art. 17 GDPR), unless a retention obligation prevents it.
-   Restriction of processing (Art. 18 GDPR).
-   Data portability (Art. 20 GDPR).
-   Objection to processing (Art. 21 GDPR) — see section 10b.
-   Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR); you withdraw cookie consent through "Cookie settings" in the footer.
-   Complaint to a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or the alleged infringement. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI), Alt-Moabit 59–61, 10555 Berlin, Germany, [mailbox@datenschutz-berlin.de](mailto:mailbox@datenschutz-berlin.de), www.datenschutz-berlin.de; in Spain, for example, the Agencia Española de Protección de Datos (www.aepd.es).

## 10b. Right to Object under Art. 21 GDPR

Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Where we process your data for direct marketing, you may object at any time without giving reasons, and we will no longer process it for that purpose. An informal objection to [info@coworkingview.com](mailto:info@coworkingview.com) is sufficient.

## 11\. Automated Decision-Making and Profiling

We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Automated tools — search filters, sorting (section 8c of the Terms), the AI assistant and automatic spam detection — help select and order spaces and filter out abusive submissions; a human decides on your enquiry itself. Should a decision within the meaning of Art. 22 GDPR ever be introduced, we will inform you in advance.

## 11b. AI Assistant (Google Gemini)

Our website offers an AI assistant that helps you search for spaces and answers general questions. It is an AI system, not a human employee, and the chat window says so (Art. 50(1) AI Act). What we process: (a) your messages, the page on which you opened the chat, and campaign information (section 12b); (b) only if you agree during the conversation, your name and email address and, optionally, phone number and company name together with your requirements. The assistant asks for your agreement before it collects contact details. Model provider: to generate replies, your messages are sent to the Gemini API of Google Ireland Limited. We use the paid tier; there, Google processes the inputs as our processor under its Data Processing Addendum and does not use them to train its models. Google may retain inputs for a limited time to detect abuse. Legal basis: operating the assistant and answering your questions — our legitimate interest in fast and efficient customer service (Art. 6(1)(f) GDPR). Collecting your contact details and handling your enquiry — Art. 6(1)(b) GDPR; where you have also given consent, Art. 6(1)(a) GDPR, which you may withdraw with effect for the future. Recipients: contact details given in the chat are handled exactly like an enquiry through the contact form (CRM, internal notification, sections 7 and 7b). Storage: we do not keep a permanent record of the conversation; it exists only in your browser for the duration of the chat. Technical error reports may contain excerpts (section 12d). Please do not enter payment or login details, special categories of personal data (Art. 9 GDPR, e.g. health data) or other people's data. We will never ask you for payment details. Accuracy: replies are generated automatically and may be wrong. Prices and availability given in the chat are non-binding indications (section 8b of the Terms). Third-country transfers: processing in the USA is possible; it is based on the EU-US Data Privacy Framework and additionally on Standard Contractual Clauses (section 8).

## 11c. Google reCAPTCHA

We use Google reCAPTCHA Enterprise to protect forms, search and the AI assistant against spam and automated abuse. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the data as our processor (Art. 28 GDPR) under the Google Cloud Terms of Service and the Cloud Data Processing Addendum. reCAPTCHA works invisibly and without puzzles: the script loads as soon as you interact with a protected form or use a protected feature, and assesses technical characteristics such as IP address, browser and device information and interaction behaviour on the page. Google sets the \_GRECAPTCHA cookie in the process. Because reCAPTCHA serves solely to protect the service you requested against abuse, we base storing and reading it on § 25(2) no. 2 TDDDG. Legal basis for the processing: our legitimate interest in protecting the website and our users' enquiries against abuse and spam (Art. 6(1)(f) GDPR). You may object under section 10b; the protected forms can then not be used, but you can always reach us by email. Third-country transfers: processing in the USA is possible (section 8).

## 11d. Location from Your IP Address

To show you nearby spaces first (section 8c of the Terms) and to assign enquiries to the right city, we derive an approximate location (city, country, approximate coordinates) from your IP address. To do so, we send the IP address to the IP-API.com service and use the country code supplied by Cloudflare. We do not store your IP address or the derived location permanently; the result is cached in memory for at most six hours. With an enquiry we store only city and country. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a relevant order of results. We never ask for your precise location through your device's location function.

## 11e. Referral Programme

If you refer someone to us, we process your name and email address and the name and email address of the person referred, to attribute the referral and to contact that person once. The legal basis is Art. 6(1)(f) GDPR. Please only name people who agree to the referral. We tell the person referred where we got their data at our first contact (Art. 14(3)(b) GDPR), send them no advertising without their consent, and delete their data if they are not interested or object.

## 11f. Operators and the Partner Portal

For operators and their contact persons we process contact and company data, property data, brokerage and billing data to perform our agreement (Art. 6(1)(b) GDPR) or, for contact persons of a company, on the basis of our legitimate interest in the business relationship (Art. 6(1)(f) GDPR). For the partner portal we additionally process login data and set a strictly necessary session cookie (partners\_jwt, 7 days) and a language cookie (partners\_locale, 1 year) (§ 25(2) no. 2 TDDDG). Changes made in the portal are notified internally with the contact person's name and email address (section 7b, Discord). Login is protected by reCAPTCHA (section 11c).

## 12\. Cookies and Similar Technologies

We store information on, or read it from, your device only where this is strictly necessary for a service you have expressly requested (§ 25(2) no. 2 TDDDG) or where you have consented (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You give and withdraw consent through the cookie banner and at any time through "Cookie settings" in the footer; "Reject all" is as easy as "Accept all". Our Cookie Policy lists the individual cookies and storage entries we use.

## 12b. Advertising and Campaign Measurement

We advertise on Google, LinkedIn and X. To see which ads lead to enquiries we use these providers' conversion tags — only if you consent in the "Marketing" category (§ 25(1) TDDDG, Art. 6(1)(a) GDPR).

-   Google Ads conversion measurement — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
-   LinkedIn Insight Tag — LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
-   X Pixel and X Conversions API — for users in the EU: Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland; parent company X Corp., USA.
-   Data processed: online identifiers (cookie IDs, click IDs such as gclid or twclid), IP address, browser and device information, the page visited and the event (e.g. page view or submitted enquiry). The providers also process this data for their own purposes; for the collection through their tags on our website we are joint controllers with them (Art. 26 GDPR). You can exercise your rights against us and against the provider concerned.
-   X Conversions API: if you have consented to "Marketing" and send an enquiry, we send X, server-side, the "enquiry" event together with the click ID, your email address and phone number in hashed (SHA-256) form, and your IP address and browser identifier, so that X can match the enquiry to the ad. Without marketing consent this transfer does not take place.
-   Campaign parameters: if you reach us through an ad or a link with campaign parameters (e.g. utm\_source, utm\_campaign, gclid, twclid), we pass this information to our CRM together with your enquiry so we know which campaign it came from (Art. 6(1)(f) GDPR). Beyond the current visit we store it in your browser only with your marketing consent.
-   Third-country transfers: transfers to the USA are possible (section 8).
-   Withdrawal: at any time through "Cookie settings" in the footer. Advertising tags are then no longer loaded and the X and LinkedIn advertising cookies we set are deleted.

## 12c. Google Analytics 4

For audience measurement we use Google Analytics 4 from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The analytics script is loaded only once you consent to "Analytics"; without consent no connection to Google Analytics is made. If you have consented only to "Marketing", the same script may be loaded because Google Ads measures enquiries through it; analytics cookies are then not set (section 12b). With your consent, Google Analytics sets the cookies \_ga and \_ga\_<ID\> (up to 2 years) to recognise visits and sessions, and processes the pages viewed, the landing page of your visit including campaign parameters, the referrer, and browser, device and approximate location information; according to Google, Google Analytics does not store IP addresses. The legal basis is your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR), which you can withdraw at any time through "Cookie settings". Analytics data is kept for at most 14 months. Google processes the data as our processor; transfer to the USA is possible (section 8).

## 12d. Error Monitoring (Sentry)

When an error occurs on the website or in our interfaces, an error report is sent to Sentry (Functional Software, Inc., USA; stored in a data centre in Germany). The report contains technical details such as the error message, requested URL, browser and device type, and campaign parameters. If handling an enquiry fails, it may also contain the email address given, so we can still reach you. In the browser, Sentry is loaded only on the first error and sets no cookies. The legal basis is our legitimate interest in a working website and in not losing any enquiry (Art. 6(1)(f) GDPR). Error reports are deleted after at most 90 days.

## 13\. Third-Party Websites and External Links

Our website contains links to third-party websites, for example operators, map services or review platforms. If you follow such a link, the privacy terms of that provider apply; we have no influence over its data processing.

## 14\. Minors

Our services are aimed at businesses and adults. We do not knowingly collect data from people under 16. If we learn that such data has been sent to us, we delete it. Please let us know at [info@coworkingview.com](mailto:info@coworkingview.com).

## 15\. Changes to this Policy

We update this Privacy Policy when our data processing or the law changes. The version published on the website applies. Where a new processing operation requires consent, we ask for it separately.

## 16\. Contact

For data protection questions and to exercise your rights: [info@coworkingview.com](mailto:info@coworkingview.com) or by post to the address in section 1. Your right to lodge a complaint with a supervisory authority (section 10) is unaffected.

Last updated: 28 September 2026