All Products at a Glance
Select a product for detailed information on privacy, security and compliance.
Infrastructure & Data Center Partners
All PCM Group products rely on two audited, ISO-certified partners – exclusively in Germany/EU.
www.hetzner.com
Hauptstraße 68 · 02742 Friedersdorf · Deutschland
all-inkl.com/datenschutzinformationen
Global Security Standards
These measures apply to all PCM Group products and platforms.
All data transmissions are made exclusively via encrypted HTTPS connections with TLS 1.2 or higher. Sensitive data (patient data, health data, GPS data) are additionally encrypted at rest with AES-256.
All servers and databases are located in data centers within the European Union – operated by Hetzner Online GmbH (Nuremberg/Falkenstein) and ALL-INKL.COM (Friedersdorf). No data transfer to third countries without an explicit legal basis.
All products and processes are aligned with the requirements of the General Data Protection Regulation (EU) 2016/679. Data processing is carried out exclusively on a proven legal basis (Art. 6 GDPR), for health data pursuant to Art. 9 GDPR.
For all SaaS products (Wellpoint, Lyvio/Unifyr, PHE Buddy) we provide a DPA pursuant to Art. 28 GDPR. Requests to datenschutz@pcm-group.at.
In the event of data breaches we notify affected users and the Austrian Data Protection Authority within the statutory 72-hour deadline (Art. 33 GDPR). All products have 24/7 monitoring and documented incident response processes.
PCM Group
Parent organization for management consulting (PCM Solution), software development (PCM Technology) and strategic investments. Headquarters: Eben im Pongau, Austria.
- HTTPS/TLS 1.2+ on all connections
- Firewall & DDoS protection (ALL-INKL)
- Regular security updates
- Access on a need-to-know basis
- Cookie consent management
- Logging of all system accesses
We use Unifyr Analytics (analytics.agentur-circle.com) for privacy-friendly website statistics. No tracking without cookie consent. No sharing with third parties. No cross-site tracking.
- Access (Art. 15 GDPR)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
Requests to datenschutz@pcm-group.at – response within 30 days.
| Provider | Purpose | Location | Basis |
|---|---|---|---|
| ALL-INKL.COM | Website hosting | Germany (EU) | Art. 6 (1) f · DPA |
| Unifyr Analytics | Website statistics | EU | Art. 6 (1) a GDPR |
| PCM DWP | Contact form/CRM | EU | Art. 6 (1) f GDPR |
| Google Fonts | Fonts (locally embedded) | EU (local) | Legitimate interest |
| Agentur Circle GmbH | Web development, design, marketing, Unifyr Analytics | Austria (EU) | Art. 28 GDPR · DPA |
| Finanzbuchhaltung Monuth KG | Accounting, tax consulting, payroll | Austria (EU) | Art. 6 (1) c GDPR · WTBG |
| ↳ BMD NTCS | Accounting & payroll software (sub-processor Monuth) | Austria (EU) | Via Finanzbuchhaltung Monuth KG |
| ↳ Finmatics | AI document processing & booking suggestions (sub-processor Monuth) | Austria / EU | Via Finanzbuchhaltung Monuth KG |
- Development & maintenance of all PCM Group websites and product landing pages
- Graphics, UI/UX design and corporate identity
- Online marketing, SEO and performance optimization
- Operation of Unifyr Analytics (privacy-friendly website statistics)
- Technical implementation of marketing campaigns
- Financial data and business documents (receipts, invoices, accounts)
- Employee data for payroll (name, social security number, salary)
- Customer data within the scope of accounting (invoice recipients)
- Tax data for tax authority filings
| Software / Service | Provider | Purpose | Location |
|---|---|---|---|
| BMD NTCS | BMD Systemhaus GmbH | Accounting, payroll & tax advisory software | Austria (EU) |
| Finmatics | Finmatics GmbH | AI-assisted document processing & automatic booking suggestions | Austria / EU |
For questions on data protection, DPA requests or data subject rights.
Wellpoint
All-in-one practice software for therapists. Processing of sensitive patient data to the highest data protection standards.
Wellpoint processes patient data (health data) pursuant to Art. 9 GDPR. Processing only on explicit consent (Art. 9 para. 2 lit. a). All data is stored and transmitted AES-256 encrypted.
- TLS 1.2+ transport encryption
- AES-256 at-rest encryption
- Two-factor authentication
- Role-based access control
- Automatic session timeouts
- Complete audit log
- Penetration tests (annual)
- 24/7 system monitoring
Wellpoint provides each customer with a DPA pursuant to Art. 28 GDPR. As a therapist you are the data controller – Wellpoint is the processor. DPA available by email or via the customer portal.
| Provider | Purpose | Location | Basis |
|---|---|---|---|
| Hetzner Online GmbH | Server & database | Germany (EU) | Art. 28 GDPR · DPA |
| GoCardless Ltd. | Payment processing | United Kingdom / EU | Art. 6 (1) b GDPR |
| Unifyr Analytics | Marketing website statistics | EU | Art. 6 (1) a GDPR |
| Agentur Circle GmbH | Web development, design, marketing website wellpoint.at | Austria (EU) | Art. 28 GDPR · DPA |
| Finanzbuchhaltung Monuth KG | Accounting, invoicing, tax consulting | Austria (EU) | Art. 6 (1) c GDPR · WTBG |
| ↳ BMD NTCS | Accounting & payroll software (sub-processor Monuth) | Austria (EU) | Via Finanzbuchhaltung Monuth KG |
| ↳ Finmatics | AI document processing & booking suggestions (sub-processor Monuth) | Austria / EU | Via Finanzbuchhaltung Monuth KG |
In the event of data breaches, affected therapists and the supervisory authority are notified within 72 hours. 24/7 security monitoring through Hetzner infrastructure. Dedicated incident response process documented and tested.
Request a DPA, ask data protection questions or exercise data subject rights.
PHE Buddy
Mobile app for PKU patients. Processing of sensitive health data with the highest protection pursuant to Art. 9 GDPR.
PHE Buddy processes health data (phenylalanine values, dietary diary) pursuant to Art. 9 GDPR. Processing only on explicit consent. No data sharing with third parties without explicit consent. AES-256 encryption at rest.
- Encrypted device storage
- Optional PIN/biometric protection
- No advertising, no profiling
- Offline functionality available
Privacy policy available in German and English. All international users (DACH + EU) are treated equally – GDPR applies to all.
| Provider | Purpose | Location | Basis |
|---|---|---|---|
| ALL-INKL.COM | Website hosting | Germany (EU) | Art. 28 GDPR · DPA |
| Hetzner Online GmbH | App backend & data | Germany (EU) | Art. 28 GDPR · DPA |
| Apple App Store | App distribution (iOS) | USA (SCC) | Art. 6 (1) b GDPR |
| Google Play Store | App distribution (Android) | USA (SCC) | Art. 6 (1) b GDPR |
| Agentur Circle GmbH | Web development, design, marketing website phe-buddy.at | Austria (EU) | Art. 28 GDPR · DPA |
| Finanzbuchhaltung Monuth KG | Accounting, invoicing, tax consulting | Austria (EU) | Art. 6 (1) c GDPR · WTBG |
| ↳ BMD NTCS | Accounting & payroll software (sub-processor Monuth) | Austria (EU) | Via Finanzbuchhaltung Monuth KG |
| ↳ Finmatics | AI document processing & booking suggestions (sub-processor Monuth) | Austria / EU | Via Finanzbuchhaltung Monuth KG |
Questions about health data or data subject rights.
Unifyr
Marketing platform with website analytics, central inbox, AI-powered post scheduling, and proprietary tracking pixel – developed by PCM Group & Agentur Circle GmbH, exclusively EU-hosted.
| Module | Function | Legal basis |
|---|---|---|
| 📊 Analytics | Privacy-friendly website statistics, consent-controlled, IP-anonymized | Art. 6 (1) a GDPR |
| 📥 Central Inbox | Consolidated communication overview for customer inquiries & messages | Art. 6 (1) b GDPR |
| 📅 Post Scheduling | AI-powered planning & scheduling of social media content | Art. 6 (1) b GDPR |
| 🤖 AI Marketing | AI models for content generation & campaign optimization (EU-side) | Art. 6 (1) b GDPR |
| 📡 Unifyr Pixel | Proprietary tracking pixel for technical analysis – active before cookie banner, no sharing with third parties | Art. 6 (1) f GDPR |
Unifyr Pixel
This website uses the Unifyr Pixel, a technical analysis tool by Agentur Circle GmbH, Austria. The pixel is required for the basic technical functionality of the website and collects exclusively anonymized technical data (page views, load times, error detection). No prior cookie consent is required for this.
The collected data is not shared with third parties, advertising networks, or any other external entities. All data is processed exclusively on EU servers (Germany) and is not used for profiling or personal evaluation.
Legal basis: Art. 6 para. 1 lit. f GDPR (Legitimate interest – technical analysis) · Operator: Agentur Circle GmbH · datenschutz@pcm-group.at
No customer content flows into external AI services. All AI functions in Unifyr run on EU-hosted models or are operated by instructed processors.
- No tracking without active cookie consent
- No cross-site tracking – data is not linked across products
- No sharing with advertising networks or third parties
- No personal user profiles
- IP anonymization active in analytics & pixel
- Data remains exclusively within EU jurisdiction
- Opt-out possible at any time via cookie settings
- Inbox data visible only to the respective website operator
| Provider | Purpose | Location | Basis |
|---|---|---|---|
| PCM Group / PCM Technology | Software development of the Unifyr platform | Austria (EU) | Internal · Art. 6 (1) b GDPR |
| Agentur Circle GmbH | Operations, hosting, pixel, inbox, post scheduling | Austria (EU) | Art. 28 GDPR · DPA |
| Hetzner Online GmbH | Server infrastructure, app backend, pixel tracking | Germany (EU) | Art. 28 GDPR · DPA · ISO 27001 |
| ALL-INKL.COM | Website hosting, e-mail infrastructure | Germany (EU) | Art. 28 GDPR · DPA · ISO 27001 |
Lyvio is integrated as a media module into the Unifyr platform. Hosting, data protection architecture and security measures follow the same standards as the entire Unifyr platform.
- Encrypted media storage
- HTTPS/TLS for all transmissions
- Secure authentication
- Automatic EU backups
- Complete access logs
- Privacy by Design (Art. 25 GDPR)
Questions about tracking, consent, pixel integration, media sharing or data deletion.
AI & Privacy
PCM Group uses AI tools in a differentiated and purpose-bound manner: local models for everything involving personal data, external cloud services exclusively for internal tasks without customer data.
- AI requests are processed locally on Mittwald servers in Germany
- No forwarding to OpenAI, Anthropic, Google or other external AI services
- Full control over prompts and responses – no external logging
- User data is not used for model improvement
- GDPR-compliant DPA concluded with Mittwald
- Fully air-gapped from the public internet (internal API only)
- No external model logging, no telemetry back-channel
- Access only via authenticated internal services
- Regular model review for security vulnerabilities
- HTTPS/TLS also on internal API endpoints
| Tool | Provider / Hosting | Use case | Personal data | Assessment |
|---|---|---|---|---|
| Claude.ai | Anthropic (USA) Cloud service |
Marketing texts, campaign planning, software development (test scenarios, code review, development tasks) | No customer data – internal content only | ⚠️ Internally permitted no personal reference |
| ChatGPT / GPT-4o | OpenAI (USA) Cloud service |
Marketing activities, copywriting, internal ticket system analysis (anonymized ticket categories, no customer names) | No customer data – anonymized | ⚠️ Internally permitted no personal reference |
| Higgsfield AI | Higgsfield (USA) Cloud service |
AI video & image generation for marketing campaigns, social media content, advertising materials | No personal reference – purely creative content | ⚠️ Internally permitted Marketing only |
| Ollama (self-hosted) | PCM Group (EU) Hetzner dedicated |
Internal documentation, analysis, draft texts – wherever internal data is processed | Fully controlled | ✅ Primary maximum control |
| Mittwald mStudio AI | Mittwald (DE) EU data center |
AI-powered product features, managed local inference | EU-only, DPA concluded | ✅ Permitted ISO 27001, DPA |
The following data categories are under no circumstances entered into external cloud AI services (Claude.ai, ChatGPT, Higgsfield or others):
Inquiries about AI infrastructure, models used, or data protection in AI functions.
Technical & Organizational Measures
Complete documentation of TOM pursuant to Art. 32 GDPR for all products and systems of PCM Group. These measures apply as the minimum standard for all service providers and sub-processors used.
Measures that deny unauthorized persons physical access to data processing facilities used to process personal data.
- Server infrastructure exclusively in certified data centers (Hetzner Nuremberg/Falkenstein, ALL-INKL Friedersdorf)
- Access to data center locations only for authorized personnel (biometrics/chip card at Hetzner, 24/7 access control at ALL-INKL)
- Video surveillance of all access areas in the data centers
- No own physical servers – exclusively ISO-27001-certified service providers
- PCM Group office premises: key card/system, alarm system outside business hours
- Clean desk policy for all employees with access to personal data
Measures that prevent data processing systems from being used by unauthorized persons.
- Password policy: minimum length 12 characters, upper/lowercase letters, special characters, numbers
- Two-factor authentication (2FA) for all administrative access and cloud services
- Automatic screen lock after 5 minutes of inactivity
- Automatic session timeout for all web applications
- Password manager mandatory for all employees (no reuse)
- Immediate account deactivation upon employee departure
- Regular review of active user accounts (quarterly)
- VPN mandatory for access to internal systems from home office
Ensuring that authorized users of a data processing system can only access the data covered by their access authorization.
- Role-based access control (RBAC) in all product systems
- Principle of least privilege – each employee receives only the rights necessary for their role
- Separation of development, test, and production environments
- No direct database access for end users – exclusively via API layer
- Database access only for administrators with documented justification
- Logging of all privileged access (audit log)
- Regular review of access rights (annually, immediately upon role change)
Ensuring that personal data cannot be read, copied, altered, or removed without authorization during electronic transmission or transport.
- Transmission exclusively over encrypted connections (HTTPS/TLS 1.2+)
- HSTS (HTTP Strict Transport Security) on all product domains
- No sending of personal data via unencrypted e-mail
- File transfers exclusively via secured, authenticated channels
- No transfer of personal data to insecure third countries
- Logging of data disclosures to sub-processors
- API communication exclusively via authenticated endpoints (Bearer Token / API Key)
Ensuring that it can subsequently be checked and determined whether and by whom personal data has been entered, modified, or removed from data processing systems.
- Complete audit log for all data changes in product systems (Wellpoint)
- Timestamps for creation, modification, and deletion of all records
- Immutable log files (append-only logs)
- User ID is stored with every data change
- Form validation and input sanitizing to protect against manipulation
- Logs retained for at least 90 days
Ensuring that personal data processed on behalf of the controller can only be processed in accordance with the controller's instructions.
- DPA (Data Processing Agreement) with all sub-processors pursuant to Art. 28 GDPR
- Written instructions to all processors before processing begins
- Regular review of sub-processors (at least annually)
- Register of all sub-processors used is kept up to date
- Sub-processors may not engage further sub-processors without authorization
- Contractual obligation of all employees to confidentiality (§ 6 DSG)
- Data protection training for all employees with access to personal data
Ensuring that personal data is protected against accidental destruction or loss.
- Daily automatic backups of all databases (encrypted, EU-internal)
- Backup retention: 30 days rolling
- Redundant server infrastructure (Hetzner: multiple locations)
- UPS (uninterruptible power supply) and emergency generators at data center locations
- 99.9% availability SLA at ALL-INKL, guaranteed uptime at Hetzner
- 24/7 monitoring of all production systems with automatic alerting
- Disaster recovery plan documented and tested annually
- Recovery Time Objective (RTO) < 4 hours for critical systems
- Recovery Point Objective (RPO) < 24 hours
Ensuring that data collected for different purposes can be processed separately.
- Logical tenant separation: customer data from different clients is stored in isolation
- Strict separation of development, test, and production data
- No use of real data in test/development environments
- Separate databases per product (Wellpoint, etc. do not share a database)
- Marketing data and operational customer data in separate systems
- Accounting data (Finanzbuchhaltung Monuth KG) separated from operational CRM data
- Dedicated data protection officer / contact person designated internally
- Incident response contact: datenschutz@pcm-group.at
- Register of all data protection breaches maintained internally
- Data protection considered from the beginning of product development (Privacy by Design)
- Most privacy-friendly settings by default (Privacy by Default)
- Data Minimization: collect only data strictly necessary for the purpose
- Storage limitation: deletion concepts defined for all data categories
- Cookie consent required before tracking (no pre-ticking)
- New features checked for data protection compliance before launch
- Data Protection Impact Assessment (DPIA) for high-risk processing
Complete TOM documentation available on request for DPA purposes.
EU AI Act Assessment
Classification of all AI systems of PCM Group pursuant to Regulation (EU) 2024/1689 (EU AI Act), in force since August 2024, progressively applicable from 2025–2027.
| AI tool / use case | Risk level | Rationale | Requirements |
|---|---|---|---|
| Claude.ai – Marketing & development | ▶️ Low | Internal use, no customer data input, human reviews output | Internal transparency obligation |
| ChatGPT – Marketing & ticket analysis | ▶️ Low | Anonymized content, no personal data, no customer contact | Internal transparency obligation |
| Higgsfield AI – Video/image marketing | ⬇️ Minimal | Purely generative creative content, no personal reference | Labeling as AI content |
| Ollama – Self-hosted, internal | ⬇️ Minimal | Fully internal, no external data transfer, no user contact | None specific |
| Mittwald mStudio AI – Product features | ▶️ Low | EU hosting, user interaction possible, no high-risk area | Transparency obligation |
| Claude – Software development & tests | ⬇️ Minimal | Code & test scenarios, no personal reference, developer reviews everything | None specific |
Pursuant to Art. 5 EU AI Act, the following AI practices are prohibited. PCM Group confirms that none of these systems are in use:
| Prohibited practice | PCM Group status |
|---|---|
| Subliminal manipulation of persons | ✅ Not in use |
| Exploitation of vulnerabilities/age/disability | ✅ Not in use |
| Social scoring by public authorities | ✅ Not in use (private company) |
| Real-time biometrics in public spaces | ✅ Not in use |
| Emotion recognition in the workplace/education | ✅ Not in use |
| Biometric categorization by sensitive characteristics | ✅ Not in use |
| Scraping biometric data from social media | ✅ Not in use |
- AI-generated text drafts are labeled as such internally and reviewed by a human before sending
- No use of AI chatbots that pretend to be human
- No deepfakes or AI-generated media without labeling
- Users are informed when AI systems are used in the product context
- AI-supported decision assistance is communicated as such – final decision always rests with the human
- All AI systems are used as assistive tools – no autonomous decision-making without human approval
- AI outputs are reviewed by an employee before use
- No AI system has direct write access to production databases
- Kill switch: all AI services can be deactivated immediately
- No AI system makes decisions that have legal or significant financial consequences for individuals
Inquiries about AI classification or the use of AI in our products.