Privacy Policy
Bickel Capital GmbH · Im Waldfeld 38, 60488 Frankfurt am Main · Version: March 2026
Note: This English version is provided for convenience only. The German version is the legally binding version in all cases.
We are delighted by your interest in our company. The protection of your personal data is of particular importance to the management of Bickel Capital GmbH, operating under the brand Kenkon. This Privacy Policy informs you about the nature, scope, and purpose of the personal data we collect, use, and process, and about the rights available to you.
1. Controller and Contact
The controller within the meaning of the GDPR is:
Bickel Capital GmbH (Brand: Kenkon)
Im Waldfeld 38
60488 Frankfurt am Main
Germany
For data protection enquiries, please contact us at the email address above.
2. Definitions
a) Personal Data
Any information relating to an identified or identifiable natural person.
b) Processing
Any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure, or erasure.
c) Controller
The natural or legal person which determines the purposes and means of the processing of personal data.
d) Consent
Any freely given, specific, informed, and unambiguous indication of the data subject's wishes signifying agreement to the processing of their personal data.
3. Collection of General Data (Server Log Files)
Our website collects general data each time it is accessed, stored in server log files:
•
Browser types and versions
•
Operating system of the accessing device
•
Referring website (referrer)
•
Date, time, and IP address of access
•
Internet service provider
This data is not attributed to specific persons and is deleted after 90 days. Legal basis: Art. 6(1)(f) GDPR.
4. Contact Form and Email Contact
When you use our contact form or send us an email, the personal data you transmit (name, email address, message content) is automatically stored. This data is used exclusively to process your enquiry and is deleted after 12 months at the latest. Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR.
For sending email notifications regarding incoming contact form submissions, we use Brevo (Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France) as a data processor pursuant to Art. 28 GDPR. Data submitted via the contact form is forwarded to Brevo solely for the purpose of delivering the notification email. Brevo processes this data exclusively on our behalf and according to our instructions. Brevo's privacy policy: https://www.brevo.com/en/legal/privacypolicy/
5. Cookies
Strictly Necessary Cookies
Essential for website operation and cannot be disabled. Legal basis: Art. 6(1)(f) GDPR.
Analytics Cookies (with consent only)
Set only with your express consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time via our cookie banner.
6. Web Analytics – Google Analytics
We use Google Analytics (with IP anonymisation) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. Used only with your consent (Art. 6(1)(a) GDPR). Opt-out: https://tools.google.com/dlpage/gaoptout
Further information: https://policies.google.com/privacy
7. LinkedIn
Our website may contain components of the social network LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland). If you visit a page containing a LinkedIn component while logged in, LinkedIn will receive information about your visit. Legal basis: Art. 6(1)(a) or Art. 6(1)(f) GDPR.
LinkedIn's Privacy Policy: https://www.linkedin.com/legal/privacy-policy
8. Use of AI Tools
Kenkon uses artificial intelligence (AI) tools to support internal processes and client communication. Personal data may be processed in this context. Legal basis: Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR.
We ensure that no sensitive personal data is entered into external AI systems without explicit consent, that we use only AI providers offering adequate data protection guarantees, and that no automated decisions with legally significant effects are made without human review.
We do not engage in automated decision-making or profiling with legally significant effects within the meaning of Art. 22 GDPR.
9. International Data Transfers
Our business operations may require transferring personal data to third countries outside the EEA. We ensure an adequate level of protection through Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and Transfer Impact Assessments (TIA) for relevant transfers.
10. Job Applications
We process personal data of applicants to conduct the application process. Legal basis: Art. 6(1)(b) GDPR. Application documents are deleted two months after the rejection decision, unless other legitimate interests apply.
11. Retention and Deletion
Personal data is stored only as long as necessary for the respective processing purpose or as required by statutory retention periods (up to 10 years). Data is routinely deleted after the applicable period.
12. Your Rights
a) Right of Access (Art. 15 GDPR)
You have the right to obtain information about the personal data we process concerning you.
b) Right to Rectification (Art. 16 GDPR)
You have the right to request correction of inaccurate or incomplete data.
c) Right to Erasure (Art. 17 GDPR)
You have the right to request erasure of your personal data.
d) Right to Restriction (Art. 18 GDPR)
You have the right to request restriction of processing.
e) Right to Data Portability (Art. 20 GDPR)
You have the right to receive your data in a structured, machine-readable format.
f) Right to Object (Art. 21 GDPR)
You have the right to object to processing based on Art. 6(1)(e) or (f) GDPR.
g) Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time with future effect.
h) Right to Lodge a Complaint (Art. 77 GDPR)
Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
Postfach 3163, 65021 Wiesbaden, Germany
https://datenschutz.hessen.de
13. Legal Bases for Processing
•
Art. 6(1)(a) GDPR – Consent (e.g., analytics cookies)
•
Art. 6(1)(b) GDPR – Contract performance or pre-contractual measures
•
Art. 6(1)(c) GDPR – Legal obligations
•
Art. 6(1)(f) GDPR – Legitimate interests (e.g., website operation, IT security)
14. Automated Decision-Making
We do not engage in automated decision-making or profiling with legally significant effects within the meaning of Art. 22 GDPR. All material decisions are made by human employees.
15. Changes to this Privacy Policy
This Privacy Policy is valid as of March 2026. The current version is always available on our website.