Trust Centre · As of: September 2026
Trust Centre: data protection, security and AI in the PBM Campaign Platform
The PBM Campaign Platform is GDPR-compliant software for hyper-personalised, automated customer communication via email, letter, landing page and SMS – for banks, insurers, energy suppliers and SMEs. The provider is PBM Personal Business Machine AG from Cologne.
Every customer receives their own, isolated installation. Standard hosting is in Germany. On this page, we answer the questions your data protection, security and outsourcing team will ask – with mechanisms instead of promises, with an as-of date and with sources.
- Single-tenantYour own installation
- Hosting in Germanyoptionally AWS, Azure and others
- Consent checkbefore every send
- Audit logfor humans, service accounts and AI
The legal and regulatory information on this page is as of September 2026 and does not replace legal advice.
On this page
Operations & infrastructure
Where is the PBM Campaign Platform operated – and who do you share the installation with?
No one. The PBM Campaign Platform runs as single-tenant: every customer receives their own, fully isolated installation with its own Kubernetes cluster. There is no database shared with other companies and therefore no risk of data leaking between customers. Standard hosting is in Germany.
Definition
Single-tenant is an operating model in which every customer receives their own, isolated installation of the software. Unlike multi-tenant operation, customers share neither a database nor a runtime environment.
| Option | Location | What changes |
|---|---|---|
| Standard | Data centres in Germany, provider Hetzner | nothing – standard operation |
| Amazon Web Services (AWS) | EU region, by arrangement | Hosting provider becomes a subcontractor; installation remains single-tenant |
| Microsoft Azure | EU region, by arrangement | as for AWS |
| Other environments | by arrangement | We clarify the requirements in the project |
| Object storage (S3) | with the chosen hosting provider | optionally your own S3 storage – files such as letters and images are then stored in your account |
What isolation means in practice
- Separate installation per customer, deployed automatically.
- The same tested code base for all installations – only the configuration differs.
- Data storage in the EU.
- Encryption of data at rest and in transit (TLS).
Within your installation, you separate brands, branches or locations using a hard brand boundary – more on this under “Roles & visibility rights” and on the Brands & locations page.
Contract documents
Which contract documents does PBM provide for review?
PBM provides a data processing agreement (DPA) under Art. 28 GDPR, a description of the technical and organisational measures (TOMs) under Art. 32 GDPR and a current list of subcontractors. We send you the documents on request – for your review, before any contract is signed.
Data processing agreement (DPA)
Stipulates that PBM processes your data only on your instructions.
Request DPATechnical and organisational measures (TOMs)
Describes how the data in your installation is protected.
Request TOMsList of subcontractors
Shows who is involved in providing the service.
Request listWhat do the technical and organisational measures contain?
The TOMs follow the protection goals of Art. 32 GDPR. The overview shows which platform mechanism covers which goal; the full document contains the details for each hosting option.
| Category | Mechanism in the PBM Campaign Platform |
|---|---|
| Separation | Separate installation per customer (single-tenant); hard brand boundary within the installation |
| Physical access control | Login with password, optionally passkeys, or single sign-on via OIDC (e.g. Microsoft); no self-registration |
| Access control | Roles with additive permissions; visibility across three layers (list access, brand boundary, responsibility) |
| Input and change control | Audit log: who did what and when, and which personal data they accessed |
| Transfer control | TLS in transit; letter data via SFTP to the print service provider; identifiers for advertising platforms hashed before transfer |
| Encryption | Data encrypted at rest and in transit |
| End-customer access | Personal landing pages behind a lock page with at least two factors for financial and insurance data, attempts limited and logged |
| Availability & recovery | [OPEN – technical concept: backup, RPO/RTO, availability target] |
| Regular review | [OPEN – review procedures, penetration tests, CERTIFICATION – if available] |
Which subcontractors does PBM use?
Which subcontractors are involved depends on your hosting option and your channels. You choose the email and SMS providers as well as the print service provider yourself – PBM is not tied to any particular one here.
| Service | Subcontractor | Location | Note |
|---|---|---|---|
| Hosting (default) | [NAME – e.g. Hetzner Online GmbH] | Germany | [CHECK] |
| Hosting (optional) | [AWS / Microsoft Azure / others] | EU region | only if this option is chosen |
| AI model provider | [OPEN – technical concept] | [OPEN] | only with AI features activated |
| Email/SMS delivery | chosen by you | [per provider] | freely selectable, per brand or channel |
| Letter printing & dispatch | lettershop chosen by you | [per provider] | Handover via SFTP |
| Support/operations | [IF APPLICABLE] | [OPEN] | [OPEN] |
Traceability
How does the PBM Campaign Platform demonstrate who did what?
Through a comprehensive audit log. It records who did what and when, and which personal data they accessed – whether a human, a service account of a connected application or an AI agent. Approvals, imports, access denials and processed withdrawals of consent are recorded in the same log.
- Actors distinguishable: human, service account, AI agent – filterable.
- Approvals documented: who approved which content in which language version?
- Every AI action logged: suggestions, review notes and reports from the AI agents.
- Access explainable: at the push of a button, the access diagnosis shows who may see a record – and why.
- Human
- Service account
- AI agent
| Time | Actor | Type | Action |
|---|---|---|---|
| 10:42 | C. Reuter | Human | Content approved (four-eyes) · Wiederanlage/DE |
| 10:40 | ‘Compliance check’ | AI agent | Tone notice generated |
| 10:31 | “Core banking system” | Service account | 1,204 contacts imported (upsert) |
| 09:58 | J. Becker | Human | Access denied (brand boundary) |
| 09:12 | System | Service account | Withdrawal processed · journey stopped |
This helps with accountability under Art. 5(2) GDPR: you can not only claim compliance with the principles but demonstrate it.
Role & authorisation concept
Who may see which customer data – and what may they do with it?
The PBM Campaign Platform strictly separates two questions: what someone sees and what someone may do. Both are checked on every access. A contact is only visible if all three visibility layers apply – what counts is the intersection, never the sum.
The three visibility layers
- List access: access to a customer list is granted explicitly to each person.
- Brand boundary: every contact belongs to exactly one brand. Staff at one bank never see customers of another – not even if data is maintained incorrectly elsewhere.
- Responsibility: Attributes such as region, team or territory narrow the view further.
Roles bundle permissions, for example Super Admin, Admin, Campaign Manager, Adviser, Insights Viewer, Support, Service Account and AI Agent. Permissions are additive; anything not permitted is hidden. Campaign launches and content can be tied to a four-eyes principle. User accounts are created only by invitation or via the API; sign-in is by password, optionally with passkeys, or by single sign-on via OIDC, for example with Microsoft.
The adviser who appears as the sender of the letter does not gain any access to data as a result. Personalisation and access rights are kept separate.
| Campaign Mgr | Advisers | |
|---|---|---|
| approve | permitted | not permitted |
| launch | permitted | not permitted |
- List access
- 2 lists
- Brands
- 1 · Volksbank Beispieltal eG
- Access tags
- Region North · Private Customers team
Question: Why can’t Jan Becker see the contact Marlene Hoffmann?
Explanation generated- 1 · List access List “Life Reinvestment 2026” – access (met)
- 2 · Brand boundary Brand “Regionalbank Musterstadt” – not enabled ← this is where it fails (not met)
- 3 · Responsibility no longer checked (no longer checked)
Personalisation with limits
Which data may be used for personalisation – and who controls this?
“Individual for every recipient – but only with data approved for that purpose.” You, as the controller, decide which attributes enter the PBM Campaign Platform and which rules turn them into content. Before every send, a compliance gate that cannot be switched off checks consent for each channel.
Five control points
- You determine the data basis. Attributes are created only through your import or your interface. A repeat import updates; it never deletes.
- Rules instead of a black box. Traceable rules determine which text variant or which argument a customer receives – drawn from a pool of approved arguments.
- Approval before use. Every language version is approved, by default under the four-eyes principle. An automatic compliance and tone-of-voice check runs beforehand and blocks anything that raises concerns.
- Consent per channel. The compliance gate checks before every send. If email consent is missing, a letter remains possible. A withdrawal stops running journeys immediately and blocks re-entry.
- Limits on contacts. Cross-channel caps and minimum intervals protect against too many contacts.
- letter only permitted → letter fallback 2,604
- Withdrawal → stopped 41
- Frequency limit reached → postponed 523
This gate cannot be deactivated.
Customers reach personal landing pages via a signed token, never via customer or contract numbers in the link. Measurement takes place without third-party cookies. Audiences for advertising platforms are created only from contacts with advertising consent; identifiers are hashed before transfer.
Recommendation
Special categories of personal data under Art. 9 GDPR – such as health data – require their own legal basis, usually explicit consent. We recommend using such data as a personalisation attribute only after review by your data protection officer.
AI with approval
How do the AI functions of the PBM Campaign Platform handle customer data?
“The AI drafts. You decide.”
The AI functions make suggestions – for texts, translations, rules or analyses. Sending takes place exclusively via a verified, rule-based execution. No language model makes decisions in the sending path.
AI suggestion · not yet accepted
Ms Hoffmann, your fixed-term deposit matures on 31 March – act now, before it is too late.
- no promises of returns
- Mandatory notice
- Tone: ‘too urgent’
Approval · four-eyesJ. NeumanntoC. ReuterApproved
logged · 25 September 2026 10:42
-
Can be switched off.
The AI layer is optional. The platform works fully without it.
-
Suggestion, not execution.
AI results are labelled as suggestions and take effect only after human approval. Acting AI agents run only behind human approval.
-
No live generation.
Personalised content is generated in advance in batches, checked and cached – not when the customer opens the page.
-
Every AI action in the audit log.
What the AI suggested, checked or reported is traceable.
For AI functions that make predictions – such as a lead score forecast or a recommendation for send time and channel – the platform ensures transparency, human oversight and an opt-out option (Art. 22 GDPR).
Model and data processing
- Models and providers used: [OPEN – technical concept]
- Processing location of AI requests: [OPEN – technical concept]
- Use of your data to train AI models: [OPEN – clarify before publication; only state if evidenced: “Your data is not used to train AI models.”]
Law & regulation · As of: September 2026
Which rules apply to hyper-personalised campaigns – and how does the platform help?
Responsibility for your campaigns remains with you as the controller. The PBM Campaign Platform makes the rules technically implementable and demonstrable. The following sections reflect the position as of September 2026 and do not replace legal advice.
GDPR · Art. 5, 6, 9, 21, 22, 28, 32
What does the GDPR require of personalised customer communication?
The GDPR requires a legal basis for every processing operation, purpose limitation and data minimisation – and that you can demonstrate compliance with these (Art. 5, Art. 6 GDPR). According to Recital 47, direct marketing may be based on a legitimate interest (Art. 6(1)(f)). If a person objects to direct marketing, their data may no longer be processed for that purpose (Art. 21(2) and (3)). The stricter rules of Art. 9 apply to health data and other special categories. Art. 22 governs automated individual decisions with legal or similarly significant effects. PBM processes your data as a processor on the basis of a DPA (Art. 28); the security measures are described in the TOMs (Art. 32).
Platform mechanisms
Consent and objection documented, withdrawal stops immediately, access, rectification, erasure and data portability as guided processes, automatic deletion periods, anonymisation instead of deletion where retention obligations apply, audit log.
UWG · Section 7
When is advertising by email or SMS permitted under the UWG?
Under Section 7(2) no. 2 UWG, advertising by electronic mail is generally permitted only with prior express consent. For existing customers, an exception applies under Section 7(3) UWG if all four conditions are met: you obtained the email address in connection with a sale, you are advertising your own similar goods or services, the customer has not objected, and they are clearly informed of their right to object at any time, both when the address is collected and each time it is used. Advertising by letter is not permitted if it is apparent that the recipient does not want it (Section 7(1) UWG).
Platform mechanisms
Consent per channel as an attribute, check at the compliance gate before every send, channel fallback to letter, objection stops immediately.
EU AI Act · Regulation (EU) 2024/1689 · Regulation (EU) 2026/1744
Does AI in campaign management fall under the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) applies in stages. Since 2 February 2025, the prohibitions of certain AI practices and the obligation to promote AI literacy (Art. 4) have applied. Since 2 August 2025, obligations for providers of general-purpose AI models have applied. Since 2 August 2026, the transparency obligations under Art. 50, among others, have applied. Under the amending Regulation (EU) 2026/1744 (“Digital Omnibus on AI”), the obligations for high-risk AI systems under Annex III apply from 2 December 2027, and for high-risk systems in regulated products under Annex I from 2 August 2028. Annex III lists as high-risk, for example, creditworthiness assessment as well as risk assessment and pricing in life and health insurance – these are not functions of the PBM Campaign Platform. As the deployer, you classify your specific use.
Platform mechanisms
AI can be switched off, suggestions labelled, human approval, every AI action logged.
- Entry into force of the EU AI Act (completed)
- Prohibited practices, AI literacy (Art. 4) (completed)
- Obligations for general-purpose AI models, governance, penalties (completed)
- General application, including transparency obligations (Art. 50) (current)
- High-risk AI under Annex III (new under Regulation (EU) 2026/1744) (planned)
- High-risk AI in products under Annex I (new under Regulation (EU) 2026/1744) (planned)
DORA · Art. 28, 30 · Implementing Regulation (EU) 2024/2956
What does DORA require of banks and insurers that use a campaign platform?
Since 17 January 2025, the Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied to financial entities. Anyone using software as a service such as the PBM Campaign Platform is obtaining an ICT service from an ICT third-party service provider. The financial entity must keep all such contracts in a register of information (Art. 28(3) DORA); BaFin requests the register annually and requires the LEI or EUID to identify the service provider (Implementing Regulation (EU) 2024/2956). Art. 30 DORA prescribes key contractual provisions, such as the description of the service, the locations where the service is provided and data is processed, rules on availability, integrity and security of data, assistance with ICT incidents and termination rights. If the service supports a critical or important function, further obligations apply, including rights of access, inspection and audit as well as exit strategies (Art. 28(8), Art. 30(3)). You assess for yourself whether this is the case for your campaign platform.
Platform mechanisms
Single-tenant, choice of location and hosting provider, data storage in the EU, data export at any time, audit log. DORA contract annex: [OPEN – in preparation].
BFSG
Does the Barrierefreiheitsstärkungsgesetz (Accessibility Strengthening Act) apply to your campaigns?
Since 28 June 2025, the Barrierefreiheitsstärkungsgesetz (BFSG) has applied to certain products and services for consumers, including banking services and e-commerce services. The PBM Campaign Platform itself is a business-to-business offering. As their provider, you check whether your landing pages or emails form part of a covered consumer service.
Platform mechanisms
[OPEN – technical concept: accessibility of the landing page and email templates]
For your review
Which questions will your outsourcing and data protection team ask – and where is the answer?
This table summarises the most common review questions. Each answer refers to the evidence you need for your documentation.
| Question | Answer | Evidence / document |
|---|---|---|
| Who is the provider and contracting party? | PBM Personal Business Machine AG, Wilhelm-Mauser-Str. 14-16, 50827 Köln, Amtsgericht Köln HRB 89856 | Legal notice · LEI/EUID: [IF AVAILABLE] |
| Where is the data processed? | Germany by default (Hetzner); optionally AWS, Microsoft Azure or other environments; data storage in the EU | DPA, list of subprocessors |
| Do we share the environment with other customers? | No. A dedicated, isolated installation with its own Kubernetes cluster | TOMs (separation) |
| How is the data encrypted? | At rest and in transit (TLS) | TOMs (encryption) |
| Can we use our own storage? | Yes, optionally your own S3 storage | Service description [DOCUMENT] |
| Who can see our customer data? | Only authorised users, according to three visibility layers; every access logged | TOMs (access control), audit log export [CHECK] |
| How does sign-in work? | Password, optionally passkeys, or single sign-on via OIDC (e.g. Microsoft) | TOMs (system access control) |
| How do we get our data back? | Export and data portability at any time | Service description, exit arrangements [DOCUMENT] |
| Which subprocessors are involved? | Depends on the hosting option and the channel providers selected | List of subcontractors |
| Does the platform use AI with our data? | Only if activated; suggestions with human approval, every action logged | AI section of this page, DPA [CHECK] |
| Does PBM support our DORA obligations? | Information for the register of information and the contract under Art. 30 DORA: [OPEN – DORA contract annex] | [DOCUMENT] |
| How is a security incident handled? | Notification and support under the DPA: [OPEN – process, deadlines] | DPA, incident process [DOCUMENT] |
| Which certifications are in place? | [CERTIFICATION – if available] | [EVIDENCE] |
| How long are audit logs retained? | [OPEN – technical concept] | TOMs |
Security contact
How do you report a security vulnerability to PBM?
Write to [security@personal-business-machine.com – CONFIRM ADDRESS]. Please describe the vulnerability, the affected location and the steps to reproduce it. We will confirm receipt within [DEADLINE] and keep you informed about the fix.
Please note
- Do not access third-party data and do not modify any data.
- Publish details only after agreeing this with us.
- Encrypted communication: [PGP KEY / FINGERPRINT – if available]
Frequently asked questions
Frequently asked questions on data protection, security and AI
Is the PBM Campaign Platform GDPR-compliant?
The PBM Campaign Platform is built for GDPR-compliant use: a dedicated, isolated installation per customer, hosting in Germany as standard, consent check per channel before every send, audit log and guided processes for data subject rights. Whether your campaigns are lawful also depends on your legal basis and your consents.
Where is our data stored?
By default in data centres in Germany operated by the provider Hetzner. Optionally, we run your installation on AWS, Microsoft Azure or in other environments by arrangement. Data is stored in the EU. You can optionally store files in your own S3 storage.
What does single-tenant mean for the PBM Campaign Platform?
Single-tenant means that each customer receives their own, fully isolated installation with its own Kubernetes cluster. There is no database shared with other companies. Within your installation, you separate brands, branches or locations by means of a hard brand boundary.
Do we get a data processing agreement?
Yes. PBM provides a data processing agreement under Art. 28 GDPR, the technical and organisational measures under Art. 32 GDPR and a list of subprocessors. You receive the documents for your review before the contract is concluded.
Can the AI send campaigns without human approval?
No. The AI of the PBM Campaign Platform makes suggestions that take effect only after human approval. Sending takes place exclusively via a verified, rule-based execution with a compliance gate. The AI layer can be switched off, and every AI action is logged in the audit log.
Can we demonstrate who has accessed customer data?
Yes. The audit log of the PBM Campaign Platform records who did what and when, and which personal data they accessed – people, service accounts and AI agents. In addition, the access diagnosis explains at the click of a button who may see a record and why.
Is the PBM Campaign Platform an ICT third-party service provider within the meaning of DORA?
For financial entities, PBM, as a provider of software as a service, is an ICT third-party service provider. The contract therefore belongs in your register of information under Art. 28(3) DORA. You assess for yourself whether the platform supports a critical or important function in your organisation; additional contractual obligations under Art. 30(3) DORA depend on this.
May we email existing customers without consent?
Only under the four conditions of Section 7(3) UWG: the address was obtained through a sale, you are advertising your own similar offerings, the customer has not objected, and they are informed of their right to object when the address is collected and each time it is used. The PBM Campaign Platform checks the stored consent per channel before every send. This answer does not replace legal advice.
Does the EU AI Act apply to the platform’s AI functions?
The EU AI Act applies in stages; since 2 August 2026, the transparency obligations under Art. 50, among others, have applied. The obligations for high-risk AI under Annex III apply from 2 December 2027. Creditworthiness assessment or pricing in life and health insurance are not among the functions of the PBM Campaign Platform. As of: September 2026.
Can we export our data at any time?
Yes. The PBM Campaign Platform offers export and data portability. Access, rectification, erasure and data portability for data subjects run as guided processes; where retention obligations exist, data is anonymised instead of deleted.
Sources · As of: September 2026
Which sources is this page based on?
- Regulation (EU) 2016/679 (General Data Protection Regulation), Art. 5, 6, 9, 21, 22, 28, 32, Recital 47 – EUR-Lex: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Gesetz gegen den unlauteren Wettbewerb (UWG, Act against Unfair Competition), Section 7 – gesetze-im-internet.de: https://www.gesetze-im-internet.de/uwg_2004/__7.html
- Regulation (EU) 2024/1689 (AI Regulation, EU AI Act), Art. 4, 50, 113, Annex III – EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Regulation (EU) 2026/1744 (“Digital Omnibus on AI”) of 8 July 2026, in force since 27 July 2026 – EUR-Lex: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA), Art. 3, 28, 30, 64 – EUR-Lex: https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Implementing Regulation (EU) 2024/2956 (standard templates for the register of information) – EUR-Lex: https://eur-lex.europa.eu/eli/reg_impl/2024/2956/oj
- BaFin: DORA – register of information and notification requirements – https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Fachartikel/2025/fa_250115_DORA_Informationsregister_und_Anzeigepflichten.html
- Barrierefreiheitsstärkungsgesetz (BFSG) – gesetze-im-internet.de: https://www.gesetze-im-internet.de/bfsg/
This page does not replace legal advice. As of: September 2026. We update it when the legal situation or the platform changes.