Privacy
Information on the processing of your data pursuant to Art. 13/14 GDPR.
1. Controller
The controller within the meaning of the GDPR is: [Company name], [Address]. Email: support@life-scale.de
Data Protection Officer: [if appointed: enter name and contact, otherwise remove]
2. What Data We Process
We process personal data only insofar as it is necessary to provide our services:
- Master data: name, email address, password (encrypted)
- Profile data: profession, budget, lifestyle, languages, target regions and other preferences provided during onboarding
- Contract and billing data: billing address, plan, payment status (payment data itself is processed exclusively by Stripe)
- Usage data: pages visited, time spent, click events (only with consent, see section 7)
- Support data: content of support requests and tickets
3. Purposes and Legal Bases
- Provision of the platform and personalised recommendations — Art. 6 (1) (b) GDPR (performance of contract)
- Payment processing and invoicing — Art. 6 (1) (b) and (c) GDPR (legal obligation)
- Analytics, reach measurement and marketing — Art. 6 (1) (a) GDPR (consent), § 25 (1) TDDDG
- Security, abuse and fraud prevention — Art. 6 (1) (f) GDPR (legitimate interest)
- Compliance with statutory retention obligations — Art. 6 (1) (c) GDPR
4. Processors and Recipients
To provide our services, we use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR are in place. Transfer takes place only insofar as it is necessary for the respective purpose:
| Service Provider | Purpose | Location / Third-Country Transfer |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing, invoicing | EU/Ireland; possibly USA – safeguarded via EU Standard Contractual Clauses (SCC) & EU-US Data Privacy Framework |
| HubSpot, Inc. | CRM, contact and sales management | USA – EU Standard Contractual Clauses (SCC) & EU-US Data Privacy Framework |
| Microsoft (Outlook / Microsoft 365) | Sending and receiving emails (support) | EU/USA – EU Standard Contractual Clauses (SCC) & EU-US Data Privacy Framework |
Disclosure to other third parties occurs only if there is a legal obligation or you have expressly consented.
5. Third-Country Transfer
Where data is transferred to countries outside the EU/EEA (in particular to the USA), we ensure an adequate level of data protection — via an adequacy decision of the EU Commission (EU-US Data Privacy Framework) and/or by concluding the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) with supplementary protective measures. Despite these measures, it cannot be entirely ruled out, particularly with US providers, that authorities there may access data.
6. Retention Period per Data Category
| Data Category | Retention Period |
|---|---|
| Account and profile data | Until deletion of the account; after a deletion request, final removal occurs after 30 days |
| Contract and invoice data | 10 years (commercial and tax retention obligation, § 257 HGB, § 147 AO) |
| Support tickets / communication | Up to 3 years after completion of the case |
| Analytics/usage data (with consent) | Anonymous visitor ID up to 90 days; session events 90 days |
| Cookie consent record | Up to 12 months |
7. Cookies & First-Party Analytics
We use technically necessary cookies for session management. Optional analytics and marketing cookies are set exclusively after your express consent via our cookie banner (Art. 6 (1) (a) GDPR; § 25 (1) TDDDG).
| Category | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Necessary | Login session, security, storing cookie consent | § 25 (2) TDDDG (technically required) | Session up to max. 12 months |
| Analytics | First-party usage measurement in our own database (no third parties, no Google Analytics) | Art. 6 (1) (a) GDPR | up to 90 days |
| Marketing | UTM campaign parameters for evaluating advertising channels | Art. 6 (1) (a) GDPR | up to 90 days |
For analytics we do not record IP addresses or browser fingerprints; only a rough country estimate is derived from the time zone. You can withdraw your consent at any time via the “Cookies” link in the footer or by deleting our cookies.
8. Session Recordings (Session Replay)
As part of our first-party analytics, administrators can trace usage sessions based on event metadata (pages visited, click element labels without input values, scroll depth, time spent, device type, browser language, rough country estimate, consent level). No DOM snapshots, screenshots, mouse movements, keystrokes or form contents and no IP addresses are recorded.
The legal basis is your consent (Art. 6 (1) (a) GDPR; § 25 (1) TDDDG) and, for logged-in users, additionally the legitimate interest in ensuring functionality and security (Art. 6 (1) (f) GDPR). Session events are automatically deleted after 90 days.
You can withdraw your consent at any time via the “Cookies” link in the footer; data already stored will be removed at the latest after the 90-day period expires.
9. Your Rights as a Data Subject
You have the right at any time to:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)
To exercise these rights, a message to support@life-scale.de is sufficient.
10. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU Member State of your residence, place of work or the place of the alleged infringement.
The supervisory authority responsible for us is: [enter the competent state data protection authority based on the company’s registered office]
11. Obligation to Provide Data & Automated Decisions
Providing master and contract data is necessary for the conclusion of the contract; without it we cannot provide the service. Profile data is voluntary but influences the quality of the recommendations.
No automated decision with legal effect within the meaning of Art. 22 GDPR takes place. Our recommendations are non-binding suggestions.
12. Data Security
We take technical and organisational measures (Art. 32 GDPR) to protect your data against loss, manipulation and unauthorised access, including transport encryption (TLS), access restrictions and — optionally — two-factor authentication.
