Legal · GDPR
Privacy Policy
Last updated : 22 June 2026
1. Data Controller
Alpen Kredit Group GmbH
Maximilianstrasse 12, 80539 München, Deutschland
Email : info@alpen-kredit.com
DPO : Marie-Claire Dupont — info@alpen-kredit.com
Alpen Kredit Group GmbH processes your personal data as data controller, in accordance with Regulation (EU) 2016/679 (GDPR) and the Federal Data Protection Act (BDSG).
2. Data Collected
We collect the following categories of data depending on your interactions with the platform:
3. Purposes and Legal Bases
Each processing activity is based on an explicit legal basis:
4. Retention Periods
KYC data is retained for 5 years after the end of the business relationship (§ 8 GwG). Account data is retained for 3 years after termination. Connection logs are retained for 12 months. Marketing data (with consent) is retained until consent is withdrawn.
5. Data Transfers
Your data may be transferred to:
- Financial partner institutions to which your file is submitted (with your consent)
- Competent authorities (BaFin, ACPR, anti-money laundering FIU) where required by law
- Our technical processors (EU cloud hosting, email delivery service) under GDPR data processing agreements
No transfer outside the EU/EEA without appropriate safeguards (European Commission standard contractual clauses).
6. Your Rights
You have the following rights regarding your personal data:
Access
Obtain a copy of all your data within 30 days
Rectification
Correct any inaccurate or incomplete information
Erasure
Delete your data (subject to legal obligations)
Portability
Receive your data in a structured, readable format
Objection
Object to processing based on legitimate interests
Restriction
Suspend processing during a dispute
Notification
Be informed of any data breach within 72 hours
Auto. decision
Challenge any decision made solely by algorithm
To exercise your rights: info@alpen-kredit.com with proof of identity. Response within 30 days. If refused, you may contact the info@alpen-kredit.com ICO (UK), BfDI (Germany) or CNIL (France).
7. Data Security
We apply the following security measures: TLS 1.3 encryption in transit, AES-256 at rest, mandatory two-factor authentication, bcrypt password hashing (cost 12), logging of all sensitive actions, annual penetration tests. Any data breach is reported to the competent authority within 72 hours in accordance with Art. 33 GDPR.
8. Cookies
We use technical (strictly necessary), analytical and marketing cookies. For details and preference management, see our Cookie Policy.
9. Contact & Changes
For any questions: info@alpen-kredit.com. We reserve the right to modify this policy. In the event of a substantial change, you will be informed by email or platform notification at least 30 days in advance.