Legal

Privacy Policy

Last updated: July 22, 2026

1. Controller

The controller for this website, public access-request flow, beta onboarding, and the DeinHans product is Ariel Ben Shushan ERP Consultant, Frankfurter Allee 108a/Fabrikgebäude 2. Hof, 10247 Berlin, Germany. You can reach us at hello@deinhans.de.

2. Scope of this policy

This policy explains how we process personal data when you visit public DeinHans pages, submit an access request, book a call, communicate with us, or use the product after we accept and onboard you. If a signed data processing agreement or customer agreement applies, that agreement may add product-specific processing terms.

3. Data protection contact

No separate data protection officer contact is published at this time. Privacy requests can be sent to the controller contact above. If a separate data protection officer contact is appointed or legally required, we will update this page. We route requests internally and respond according to applicable data protection law.

4. Data we process

Depending on your interaction with DeinHans, we may process the following categories of personal data.

  • Contact and request data: name, email, phone number, company name, role, message, selected path, source volume, accountant status, urgency, and selected package.
  • Business and bookkeeping context: company profile, bank and payment context, documents, invoices, receipts, contracts, payout reports, comments, tasks, exceptions, and monthly bookkeeping status shared after onboarding.
  • Scheduling data: selected meeting type, time, timezone, booking status, rescheduling/cancellation data, meeting link, Cal.com identifiers, and booking webhook payloads.
  • Account and authentication data: sign-in identifiers, invitation status, organization relationship, role, access state, and security events where product access is granted.
  • Attribution data: landing path, referrer where available, UTM source, medium, campaign, content, term, date submitted, and lead/request identifiers.
  • Communications data: emails, support messages, meeting notes, internal CRM notes, related email-send status, and follow-up history.
  • Technical and security data: IP address, user agent, device/browser information, logs, Cloudflare Turnstile verification result, basic request metadata, and abuse-prevention signals.
  • Optional analytics and campaign data: page and landing views, CTA clicks, form starts, lead and booked-consultation events, plus standard device, browser, and campaign metadata sent by the direct Google tag after consent.
  • Third-party personal data contained in customer materials, such as names, contact details, invoice references, employee/vendor/customer data, or transaction counterparties that customers upload or connect.

5. Sources of data

Most data comes directly from you or your organization. Some data is created by providers and integrations needed to operate the workflow.

  • You provide data through public forms, email, meetings, product input, uploads, and support communication.
  • Your organization, accountant, tax advisor, or invited users may provide context or documents related to the same bookkeeping workflow.
  • Cal.com, Notion, Supabase, email providers, analytics tools, and security providers generate operational status, identifiers, logs, and webhook events.
  • Ad platforms and UTM links may provide campaign context only where the relevant tag or link is used and consent requirements are met.

6. Purposes

We use personal data for defined operational purposes connected to website, beta onboarding, customer support, and the product.

  • Operate public pages, language selection, cookie choices, security checks, and request forms.
  • Check whether a requested bookkeeping month or accountant workflow fits the current beta package and decide whether to accept, defer, or reject access.
  • Send request confirmations, booking links, beta onboarding information, service notices, and follow-up messages.
  • Schedule calls, update booking status, and connect request IDs with meetings and CRM status.
  • Provide, secure, support, debug, and improve the DeinHans product after onboarding.
  • Prepare bookkeeping work, separate open business questions, produce handover state, and support accountant or customer review.
  • Measure public campaign quality only when analytics or marketing consent has been given.
  • Comply with legal, tax, commercial, accounting, security, and dispute-resolution obligations.

7. Legal bases

Where the GDPR applies, we rely on the following legal bases depending on the processing activity.

  • Art. 6(1)(b) GDPR for pre-contract steps, access requests, access calls, onboarding, customer agreements, support, and product delivery.
  • Art. 6(1)(f) GDPR for legitimate interests such as B2B communication, product security, fraud prevention, service reliability, internal workflow control, CRM follow-up, and improvement of beta operations.
  • Art. 6(1)(a) GDPR for optional analytics, marketing tags, and consent-based communications where required. You can withdraw consent at any time with effect for the future.
  • Art. 6(1)(c) GDPR for legal obligations, including tax, commercial, accounting, regulatory, security, and statutory retention duties.
  • Art. 6(1)(f) GDPR or Art. 6(1)(c) GDPR for establishing, exercising, or defending legal claims, depending on the context.

8. Required and voluntary data

Some information is necessary to evaluate and provide the service. Optional information is marked by context or can be omitted unless needed for the requested workflow.

  • Required public-request data includes at least contact details, company, selected path, privacy acknowledgement, and security verification where enabled.
  • If required data is missing, we may be unable to process the request, book a call, accept you into beta, or provide the product.
  • Optional analytics and marketing consent is not required to use the website or submit a request.

9. Recipients and processors

We share data only where necessary for the stated purposes, where a provider processes data for us, where a professional participant is involved, or where required by law.

  • Supabase for database, authentication, storage, and backend infrastructure.
  • Vercel for hosting and deployment infrastructure.
  • Cloudflare Turnstile for bot protection and abuse prevention on public request forms.
  • Cal.com for fit-call scheduling, calendar embeds, booking metadata, and webhook updates.
  • Notion for internal CRM and access-request tracking when the integration is configured.
  • Resend for request confirmations, booking links, invitations, account emails, and service notices.
  • Google Analytics and Google Ads through the direct Google tag, only for consented measurement.
  • Accountants, tax advisors, bookkeepers, or professional partners where they are part of the customer-selected review, sign-off, filing, or onboarding workflow.
  • Authorities, courts, advisors, or counterparties where disclosure is legally required or necessary to enforce rights, defend claims, prevent abuse, or protect security.

10. Cookies, local storage, and campaign tags

Essential storage is used for site operation, language, security, sign-in, and consent records. Optional analytics and marketing tags run only after consent. Further details and controls are available in the Cookie Policy.

  • Essential storage is necessary for the website and product to work and cannot be switched off through the cookie panel.
  • Analytics storage helps us understand performance and page behavior after consent.
  • Google Ads campaign and conversion tags load only after marketing consent.
  • You can change or withdraw optional consent at any time in the Cookie Policy.

11. Automation, AI, and no solely automated decisions

After onboarding, DeinHans may use automated extraction, matching, classification, anomaly detection, and AI-assisted preparation to process bookkeeping evidence. These outputs prepare work for human review and do not create legally binding decisions, tax advice, legal advice, accountant sign-off, filings, or decisions based solely on automated processing within the meaning of Art. 22 GDPR. Customer content is not used to train shared, public, or general-purpose models unless the customer separately and expressly opts in.

12. Customer-provided data and roles

Customers remain responsible for having a lawful basis to upload, connect, or otherwise provide third-party personal data contained in bookkeeping materials. Article 28 GDPR is handled through customer and provider processing agreements; it is not an Article 6 lawful basis. The role depends on the data flow and must be confirmed before live customer materials are processed.

  • Website visitors, access requests, scheduling, CRM, billing, security, and campaign records are generally processed by DeinHans as controller.
  • Customer bookkeeping documents processed according to customer instructions are generally processed by DeinHans as processor under a data processing agreement.
  • Security logs needed to protect DeinHans systems may be processed by DeinHans as controller for that limited purpose.
  • A tax advisor or professional firm involved under its own mandate generally acts as an independent controller for its professional files and duties.
  • Before live uploads, the customer agreement must include or be accompanied by an Article 28 data processing agreement and a TOM/security schedule.
  • Public request forms are for fit information only; do not submit invoices, receipts, bank exports, employee/customer data, or confidential bookkeeping documents through them.

13. International transfers

Some infrastructure, analytics, email, scheduling, support, AI/OCR, and campaign providers may process data outside the European Economic Area. Where required, we rely on appropriate safeguards such as EU standard contractual clauses, adequacy decisions, EU-US Data Privacy Framework participation where applicable, data processing agreements, transfer impact assessments, and provider privacy terms. A customer DPA or subprocessor register should identify the active providers, regions, and available safeguard copies for product processing.

14. Retention

We keep access-request and CRM data while the request is active and for follow-up, audit, beta-selection, and commercial documentation. Public request data is not a place for source documents. Product, accounting, communication, and billing records may be retained for statutory commercial, tax, accounting, contractual, limitation, and evidence periods once a customer agreement applies. Optional analytics and marketing data is kept according to the relevant provider settings and consent state, and consent can be changed at any time.

15. Security

We use technical and organizational measures designed to protect personal data, including access controls, transport encryption, restricted service credentials, provider controls, logs, role separation, and operational review. No internet service can be guaranteed risk-free, so access is limited to people and systems that need it.

16. Your rights

Where the GDPR applies, you may request access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also object to processing based on legitimate interests. We respond to data-subject requests within the statutory period, usually one month, unless an extension or lawful refusal applies. You may lodge a complaint with a competent data protection authority, including the Berlin Commissioner for Data Protection and Freedom of Information where applicable.

17. Contact

For privacy questions, data-subject requests, or withdrawal of consent, contact:

hello@deinhans.de