Skip to content

Legal · GDPR

Privacy Policy

Last updated : 22 June 2026

1. Data Controller

Alpen Kredit Group GmbH

Maximilianstrasse 12, 80539 München, Deutschland

Email : info@alpen-kredit.com

DPO : Marie-Claire Dupont — info@alpen-kredit.com

Alpen Kredit Group GmbH processes your personal data as data controller, in accordance with Regulation (EU) 2016/679 (GDPR) and the Federal Data Protection Act (BDSG).

2. Data Collected

We collect the following categories of data depending on your interactions with the platform:

Identity data : First name, last name, date of birth, nationality, ID number
Contact data : Email address, phone number, postal address
Financial data : Income, expenses, assets, bank statements for the last 3 months
KYC documents : Identity document, proof of address, pay slips, financial statements
Connection data : IP address, timestamps, platform navigation path, device fingerprint
Communication data : Content of your exchanges with our support team

3. Purposes and Legal Bases

Each processing activity is based on an explicit legal basis:

Processing your financing fileContract performance (Art. 6.1.b GDPR)
KYC identity verificationLegal obligation (Art. 6.1.c GDPR / AMLD5)
Account security (2FA, logs)Legitimate interest (Art. 6.1.f GDPR)
Sending account notificationsContract performance (Art. 6.1.b GDPR)
Service improvement (aggregated analytics)Legitimate interest (Art. 6.1.f GDPR)
Marketing communications (newsletter)Consent (Art. 6.1.a GDPR — revocable)

4. Retention Periods

KYC data is retained for 5 years after the end of the business relationship (§ 8 GwG). Account data is retained for 3 years after termination. Connection logs are retained for 12 months. Marketing data (with consent) is retained until consent is withdrawn.

5. Data Transfers

Your data may be transferred to:

  • Financial partner institutions to which your file is submitted (with your consent)
  • Competent authorities (BaFin, ACPR, anti-money laundering FIU) where required by law
  • Our technical processors (EU cloud hosting, email delivery service) under GDPR data processing agreements

No transfer outside the EU/EEA without appropriate safeguards (European Commission standard contractual clauses).

6. Your Rights

You have the following rights regarding your personal data:

Access

Obtain a copy of all your data within 30 days

Rectification

Correct any inaccurate or incomplete information

Erasure

Delete your data (subject to legal obligations)

Portability

Receive your data in a structured, readable format

Objection

Object to processing based on legitimate interests

Restriction

Suspend processing during a dispute

Notification

Be informed of any data breach within 72 hours

Auto. decision

Challenge any decision made solely by algorithm

To exercise your rights: info@alpen-kredit.com with proof of identity. Response within 30 days. If refused, you may contact the info@alpen-kredit.com ICO (UK), BfDI (Germany) or CNIL (France).

7. Data Security

We apply the following security measures: TLS 1.3 encryption in transit, AES-256 at rest, mandatory two-factor authentication, bcrypt password hashing (cost 12), logging of all sensitive actions, annual penetration tests. Any data breach is reported to the competent authority within 72 hours in accordance with Art. 33 GDPR.

8. Cookies

We use technical (strictly necessary), analytical and marketing cookies. For details and preference management, see our Cookie Policy.

9. Contact & Changes

For any questions: info@alpen-kredit.com. We reserve the right to modify this policy. In the event of a substantial change, you will be informed by email or platform notification at least 30 days in advance.