Legal

Privacy Policy

Last updated: 2026-07-05

1.Controller

The controller for the processing of personal data within the meaning of Art. 4 No. 7 GDPR is:

Company
Deal Pipe UG (haftungsbeschränkt)
Address
Zeppelinstraße 51, 14471 Potsdam, Germany

Further contact details can be found in the Imprint.

2.Data protection officer

Due to our company size, we are not legally required to appoint a data protection officer (§ 38 BDSG). For data protection enquiries please contact kontakt@deal-pipe.de.

3.General principles

Personal data means any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR). We process personal data exclusively on the basis of statutory provisions (GDPR, German Federal Data Protection Act, TTDSG).

This policy applies both to the website at deal-pipe.de and to the SaaS product available at app.deal-pipe.de (the "Service").

Legal bases referenced below include in particular:

  • Art. 6(1)(a) GDPR — consent
  • Art. 6(1)(b) GDPR — contract / pre-contractual measures
  • Art. 6(1)(c) GDPR — legal obligation
  • Art. 6(1)(f) GDPR — legitimate interest

4.Hosting (Vercel)

Our website and the Service are hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Server-side processing occurs primarily in the Frankfurt region (fra1).

When you visit the site, Vercel automatically processes the following server log data:

  • IP address
  • Date and time of the request
  • Requested URL and HTTP status code
  • User agent (browser, operating system)
  • Referrer URL

Legal basis: Art. 6(1)(f) GDPR (provision of a functional website, IT security).

Retention: server logs are deleted or anonymised within 30 days.

International transfers: Vercel is certified under the EU–US Data Privacy Framework. A data processing agreement including EU Standard Contractual Clauses is in place.

5.Processing within the Service

5.1 Account and authentication (Supabase)

We use Supabase (Supabase Inc., Singapore) for authentication and account storage. Database and storage are operated in the EU (Frankfurt) region.

Data processed: email, name, hashed password or OAuth tokens, organisation/role membership, login timestamps.

Legal basis: Art. 6(1)(b) GDPR. DPA with SCCs in place.

5.2 Customer data inside the product

Data you create inside the product (projects, properties, clients, reservations, tickets, files etc.) is strictly partitioned per organisation via database-level row-level security.

Legal basis: Art. 6(1)(b) GDPR; Art. 28 GDPR where you upload data of your own data subjects (we sign a DPA with you on request — contact kontakt@deal-pipe.de).

5.3 File storage (Supabase Storage)

Uploaded files are stored in Supabase Storage in the EU (Frankfurt) region. Access is restricted to members of the respective organisation and protected via row-level security.

5.4 AI features

Certain features use AI models for document analysis (extraction, classification, summaries, ticket triage). Document content is sent to the following providers:

  • Google (Gemini models) via Vertex AI — the contracting entity is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Model inference runs on Google Vertex AI in the europe-west4 (Netherlands) region; processing takes place entirely within the EU.
  • Google Cloud Storage (EU) — larger documents are briefly staged in an EU bucket for AI processing and deleted immediately afterwards.

Inputs are used solely to answer the request. We have contractually ensured that providers do not use submitted data to train their models.

Legal basis: Art. 6(1)(b) and (f) GDPR. Transfers: AI processing takes place entirely in the EU (Google Vertex AI, Netherlands region); no third-country transfer occurs.

5.5 Transactional email (Resend)

We use Resend (Resend, Inc., San Francisco, USA) for notifications, invitations, magic links and other transactional mail. Resend processes your email, message content and delivery metadata. DPA with SCCs in place.

5.6 Error and performance monitoring (Sentry)

We use Sentry (Functional Software, Inc. d/b/a Sentry, San Francisco, USA) for stability and error monitoring. On error, technical data is sent to Sentry — browser, OS, screen resolution, URL, timestamp, stack trace, optionally an anonymised user id.

Legal basis: Art. 6(1)(f) GDPR. DPA with SCCs in place.

5.7 Notifications (Knock)

We use Knock Labs, Inc. (New York, USA) for in-app and cross-channel notifications. Data processed: user id, recipient data, message content. DPA with SCCs in place.

5.8 Bot protection (Vercel BotID)

On the login page and selected endpoints we use Vercel BotID to mitigate automated abuse. Technical device signals are evaluated; no personalised profiling takes place. Legal basis: Art. 6(1)(f) GDPR (IT security).

5.9 Payment processing (Stripe)

We use Stripe to process paid subscriptions. The contracting entity for EEA customers is Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Technical processing is supported by the parent company Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA.

Data transmitted to Stripe:

  • name and billing address
  • email address
  • VAT ID (if provided)
  • payment method tokens (card or SEPA data is collected directly by Stripe and not transmitted to us — we receive only a token and the last 4 digits / expiry for display)
  • invoice and subscription metadata (plan, term, amount)

Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (compliance with statutory tax and commercial retention obligations).

Retention: invoice and payment data is retained in line with statutory retention periods (typically 10 years under § 147 AO).

International transfers: Stripe Inc. (US) is certified under the EU–US Data Privacy Framework. A data processing agreement including EU Standard Contractual Clauses is in place. Details: stripe.com/privacy.

5.10 Maps (Google Maps)

To display property locations we embed Google Maps (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; technical processing possibly by Google LLC, US). The coordinates / addresses of the displayed properties and technical connection data (including your IP address) are transmitted to Google.

Legal basis: Art. 6(1)(f) GDPR (functional presentation of property data). Transfers: EU–US DPF / SCCs.

5.11 Abuse protection / rate-limiting (Upstash)

We use Upstash (Upstash, Inc., US) for rate limiting and caching. Technical data such as IP address or user id is processed briefly as a counter; this data is ephemeral and automatically deleted after a short time.

Legal basis: Art. 6(1)(f) GDPR (IT security, protection against abuse and overload).

5.12 Optional email integration (Google / Microsoft)

You can optionally connect your Google (Gmail) or Microsoft (Outlook / Microsoft 365) mailbox to send and receive email directly from the Service. Only after your explicit authorisation (OAuth) does the Service access the required mailbox functions; access tokens are stored encrypted in our infrastructure (Supabase).

Providers: Google Ireland Limited (Gmail API) and Microsoft Ireland Operations Limited (Microsoft Graph). Legal basis: Art. 6(1)(b) GDPR (performing the feature you requested). The integration is optional and can be revoked at any time.

5.13 AI observability and quality assurance (Langfuse)

To ensure the quality and reliability of the AI features (section 5.4), to trace errors and to monitor the associated cost, we log the requests sent to the AI models and their responses using Langfuse.

Provider: Langfuse GmbH, Gethsemanestr. 4, 10437 Berlin, Germany. Processing and storage take place in the EU (Frankfurt data centre).

Data processed:

  • the inputs sent to the AI models (including document content)
  • the responses generated by the models
  • technical metadata (model used, timestamp, token and cost metrics, organisation id)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in quality assurance, error analysis and cost control of the AI features).

International transfers: the contracting entity is a German company and data is processed exclusively within the EU; no third-country transfer occurs. An Art. 28 GDPR data processing agreement with Langfuse is in place.

6.Cookies, local storage and analytics

6.1 Strictly necessary cookies

We use strictly necessary cookies and local storage to keep the Service functional — in particular for:

  • authentication and session management (login)
  • protection against cross-site request forgery (CSRF)
  • locale and theme selection
  • persisting your in-app preferences

Under § 25(2)(2) TTDSG these do not require consent because they are strictly necessary for the service explicitly requested by the user. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a functional service).

6.2 Audience measurement (Vercel Web Analytics)

We use Vercel Web Analytics, a service of Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA, to measure usage of our website. Vercel Web Analytics operates without cookies and without persistent tracking of individual users.

Data processed:

  • requested URL and timestamp
  • referrer URL
  • user agent (browser, OS, device category)
  • screen resolution
  • country (derived from the IP address; the IP is discarded immediately and not stored)
  • a daily-rotating hashed salt to distinguish returning visitors (no persistent identifier)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in needs-based design of the website).

International transfers: Vercel Inc. is certified under the EU–US Data Privacy Framework; a data processing agreement including EU Standard Contractual Clauses is in place. Details: vercel.com/docs/analytics/privacy-policy.

6.3 Performance measurement (Vercel Speed Insights)

We use Vercel Speed Insights to measure real-user load times and Web Vitals (LCP, FID/INP, CLS etc.). Operated by Vercel Inc. (address as above). The service operates without cookies and without persistent identification of users.

Data processed: technical performance metrics (render timings, interaction latency, layout shifts), requested URL, user agent, and connection quality — no personal content and no IP address in clear text.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical optimisation).

Details: vercel.com/docs/speed-insights/privacy-policy.

6.4 Product analytics and session recording (PostHog)

Within the application at app.deal-pipe.de we use PostHog for product analytics — only with your consent — to understand how the Service is used and thereby improve it.

Provider: PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. Processing and storage take place in PostHog's EU cloud (Frankfurt data centre, AWS eu-central-1).

Data processed:

  • page views and navigation paths within the application
  • technical data (browser, operating system, device category, load times / Web Vitals)
  • session recordings (session replay): a recording of your interactions (mouse movements, clicks, page changes) to analyse the user journey. All input fields are automatically masked; keystrokes and field contents are not recorded
  • a pseudonymous user identifier (an internal, randomly assigned id — no clear-text identification such as name or email)

PostHog uses cookies or comparable storage techniques (localStorage) for this. Automatic capture of all click events ("autocapture") is disabled.

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TTDSG (consent). PostHog is not loaded without your consent. You can withdraw your consent at any time with effect for the future via the cookie settings.

Retention: session recordings are automatically deleted after one month. Event and usage data is stored pseudonymously and retained only for as long as necessary for the purposes described above; you may additionally request its deletion at any time (section 10).

International transfers: data is hosted in the EU (Frankfurt). The contracting entity is PostHog Inc. (US); a data processing agreement including EU Standard Contractual Clauses is in place. Details: posthog.com/privacy.

6.5 Marketing and tracking cookies

We use no marketing, advertising or profiling cookies. We do not engage in cross-site user tracking, nor do we share usage data with advertising networks.

7.Contacting us

If you contact us by email, contact form or phone, we store your data (name, contact details, request) to process your enquiry. Legal basis: Art. 6(1)(b) or (f) GDPR. We retain such messages until your enquiry is resolved and afterwards as required by statutory retention obligations (typically 6 or 10 years under German law).

8.Recipients / processors

A full list of processors acting on our behalf is provided in sections 4 and 5. Each processor is bound by an Art. 28 GDPR agreement and, where applicable, EU Standard Contractual Clauses.

9.Retention

We retain personal data only as long as required for the relevant purpose, you have consented or statutory retention applies (6 or 10 years under German commercial / tax law).

Account data is deleted or anonymised within 30 days after contract termination, unless statutory retention applies. Customer data inside the Service can be exported and deleted on request at any time.

10.Your rights

You have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object (Art. 21 GDPR)
  • withdraw consent (Art. 7(3) GDPR) — effective only going forward

To exercise your rights, an informal message to kontakt@deal-pipe.de is sufficient.

You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). For us this is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, www.lda.brandenburg.de.

11.Automated decision-making

Solely automated decisions producing legal effects (Art. 22 GDPR) do not take place. AI-assisted suggestions are decision support only; a human always makes the final decision.

12.Data security

We implement state-of-the-art technical and organisational measures to protect your data: TLS for all connections, at-rest encryption at the database and storage layer, row-level security, role-based access control, regular audits. See the Security page for details.

13.Changes to this policy

We may update this policy to reflect changes in legal requirements or to the Service. The most recent version applies to each new visit.