1. Controller
The controller within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR) is:
Lars Eppendahl, sole proprietor, trading as saasvisionary.com
Wasserstr. 496 (Bürocenter am Schlosspark)
44795 Bochum, Germany
Email: privacy@saasvisionary.com
Phone: +49 234 95313930
In this policy, “SaaSVisionary”, “we”, “us” and “our” refer to this controller. Further company details are available in our Imprint.
Data protection officer
We have not appointed a data protection officer. We are not legally required to do so, because fewer than 20 people are regularly engaged in the automated processing of personal data. For all data protection questions, please contact us directly using the details above.
2. Scope of this policy
This policy covers:
- Our website at saasvisionary.com, including its subpages;
- Our customer relationship: sign-up, trial, subscription, billing, support and communication with our business customers and their authorized users;
- Our software at app.saasvisionary.com, as far as we decide on the purposes and means of processing (for example, account administration, security and billing).
It does not cover the personal data that our customers store and process in the app about their own contacts, leads and clients (“customer content”). For customer content, the respective customer is the controller and we act as its processor (see section 5). If a business contacted you using SaaSVisionary, please direct your requests to that business first.
SaaSVisionary is offered exclusively to businesses. Nevertheless, the individual people who act for our customers (for example, account owners and team members) have all rights described in this policy.
3. Our website (saasvisionary.com)
3.1 Hosting and server log files
Our website is a static website hosted by an external hosting provider whose servers for our hosting package are located in the United Kingdom. Pages are delivered through the host’s content delivery network (CDN), which serves each visitor from a nearby node; visitors from outside the EU may therefore be served by nodes outside the EU. When you open a page, your browser automatically transmits information that the server records in log files.
- Data categories: IP address, date and time of the request, requested URL, referrer URL (the page you came from), user agent (browser type and version, operating system), HTTP status code and transferred data volume.
- Purposes: delivering the website to your device, ensuring its stability and security, detecting and defending against attacks and misuse, and analyzing technical errors.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a secure and functioning website.
- Recipients: our hosting provider as our processor under a data processing agreement pursuant to Art. 28 GDPR.
- Third-country transfer: The United Kingdom is covered by an adequacy decision of the European Commission (Art. 45 GDPR).
- Retention: Load balancer logs are deleted after 48 hours, and access and error logs after 4 days, unless a specific security incident requires us to keep individual entries longer for its investigation; in that case we keep them only until the incident has been resolved.
3.2 Bot protection
Our host uses a bot-protection service that automatically evaluates incoming requests (in particular IP address, user agent and request pattern) to detect and block automated attacks, spam and excessive traffic. In rare cases, you may be shown a short verification step (captcha) before the page loads. In that case, the service sets a strictly necessary cookie named __Host-stackprotect_state that holds a random ID for the verification, so that you are not asked again straight away. It expires after 10 minutes. The service also adds a technical response header (x-stackprotect-id) that does not store anything on your device.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website and our visitors against misuse. Storing the verification cookie is strictly necessary for this security function and does not require consent (§ 25(2) no. 2 TDDDG).
- Recipients: our hosting provider as our processor.
- Retention: verification cookie 10 minutes; log data as for server log files (section 3.1).
3.3 Website analytics (only with your consent)
We use the website analytics of our own SaaSVisionary platform (app.saasvisionary.com) to understand how our website is used, to improve it and to follow up on enquiries and orders. This happens only if you consent in the banner that appears when you first visit our website. Until you decide, and if you reject, nothing is recorded and nothing is stored on your device except your choice itself.
- What is processed: pages viewed, the referring page and campaign parameters (such as utm_source), time of the visit, device and browser type, approximate location derived from your IP address, clicks and scroll depth for aggregated heat maps (counts only, no recording of what you type), and the entries you submit in forms on our website (for example name, email address and company in the order form). Passwords, card numbers and hidden form fields are never read. We do not use session recordings. If your browser sends a “Do Not Track” signal, no analytics take place.
- Linking to your contact record: if you submit a form, your visit history can be linked to the contact record in our CRM that matches your email address or phone number, or a new contact is created, so that we can handle your enquiry or order with the relevant context.
- Storage on your device: a pseudonymous visitor ID, session and campaign-attribution information in your browser’s local storage and, if you arrive through a partner link, a referral cookie. Details are listed in our Cookie Policy.
- Legal basis: your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). Storing your consent decision itself is strictly necessary (§ 25(2) no. 2 TDDDG).
- Withdrawal: you can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer of every page. The banner then appears again.
- Recipient: our platform provider (USA) as our processor (see section 4.5, including third-country transfers).
- Retention: visit data linked to a contact record is deleted together with that record; other analytics data is kept only as long as needed for the purposes above. We ask for your consent again after six months at the latest.
3.4 Self-hosted fonts and video
All fonts and our product video are stored on our own web server and delivered from there. When you visit our website, no connection is made to font services or video platforms (such as Google Fonts or YouTube), and no data is transmitted to such providers.
4. Contact, customer relationship and app
4.1 Contact by email or phone
If you contact us by email or phone, we process the data you provide.
- Data categories: name, email address, phone number, company, content of your request and, if applicable, attachments and the time of contact.
- Purposes: answering your request and any follow-up communication.
- Legal basis: Art. 6(1)(b) GDPR, where your request relates to an existing contract or the conclusion of a contract; otherwise Art. 6(1)(f) GDPR, based on our legitimate interest in responding to inquiries addressed to us.
- Recipients: our email and telephony service providers as processors, where applicable.
- Retention: We delete your data once your request has been fully dealt with and there is no reason to expect further communication on it, usually no later than 12 months after the last contact. Messages that constitute business correspondence are retained in accordance with section 4.10.
4.2 Contact form
Our website offers a contact form. When you send it, your entries are received by our web server (hosting provider, see section 3.1) and forwarded directly and encrypted to our customer relationship management (CRM) system, where a contact record is created or updated so that we can handle and answer your request. Our web server does not store the entries; to prevent abuse it keeps a pseudonymised (hashed) form of your IP address with the time of submission for 10 minutes.
- Data categories: company, first and last name, email address, phone number (optional), topic and message, the time of submission and, if you tick it, your optional newsletter consent (see section 4.11).
- Purposes: handling and answering your request, and documenting the communication.
- Legal basis: Art. 6(1)(b) GDPR, where your request is aimed at concluding or performing a contract; otherwise Art. 6(1)(f) GDPR, based on our legitimate interest in answering inquiries.
- Recipients: the operator of our CRM system as our processor. Our CRM runs on our own SaaSVisionary platform, so the recipients listed in section 4.5 apply accordingly.
- Retention: as in section 4.1.
Fields marked as required are needed to process your request. Without them we cannot respond.
4.3 Sign-up and customer account
To use SaaSVisionary, you must create a customer account at app.saasvisionary.com.
- Data categories: name, business email address, phone number, company name, billing address, VAT ID, password (stored in hashed form only), selected plan, the confirmation that you act in a commercial or professional capacity, and the date and time of sign-up and of that confirmation. For team members invited by a customer: name, email address, role and permissions.
- Purposes: concluding and performing the subscription contract, providing the account, administering users and permissions, and verifying that we only contract with businesses.
- Legal basis: Art. 6(1)(b) GDPR (contract and pre-contractual measures). For team members invited by the customer: Art. 6(1)(f) GDPR, based on our and our customer’s legitimate interest in enabling the customer’s team to use the service.
- Recipients: our platform provider (USA) as processor (see section 4.5); Stripe for billing (see section 4.4).
- Retention: for the duration of the contract. After the end of the contract, account data is deleted or anonymised within 90 days, and backups age out on a rolling basis (recovery window of about 7 days), subject to the statutory retention obligations described in section 4.10.
Providing this data is required to conclude the contract. Without it, we cannot provide the service.
4.4 Free trial and payments via Stripe
We offer a 14-day free trial on every plan. A payment method is required to start the trial; the trial converts to a paid subscription to the plan and billing period you selected at checkout unless you cancel before it ends. We process your selected plan, trial status and start and end dates to provide the trial, to remind you where applicable, and to prevent misuse of repeated trials.
Payments are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland (“Stripe”).
- Data categories: name, email address, billing address, company name, VAT ID, payment card details (entered directly with Stripe; we do not receive or store your full card number), transaction data (amount, currency, date, plan, payment status) and technical data used by Stripe for fraud prevention (such as IP address and device information).
- Purposes: processing payments, managing subscriptions and invoices, collecting VAT correctly, and preventing fraud.
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(c) GDPR (tax and accounting obligations); Art. 6(1)(f) GDPR for fraud prevention, based on our and Stripe’s legitimate interest in secure payment transactions. For the trial, Art. 6(1)(b) GDPR, and for misuse prevention Art. 6(1)(f) GDPR.
- Role of Stripe: Stripe acts as our processor for some processing operations. For other operations, in particular fraud prevention, compliance with financial and anti-money-laundering regulations and its own payment network obligations, Stripe acts as an independent controller. For those operations, Stripe’s own privacy notice applies, which is available on Stripe’s website.
- Third-country transfer: Stripe may transfer data to Stripe, Inc. in the USA and to other group companies. Stripe bases such transfers on the EU Standard Contractual Clauses and, where applicable, its certification under the EU-U.S. Data Privacy Framework.
- Retention: as long as required for the contract; invoices and accounting records are retained in accordance with section 4.10.
4.5 Operation of the app by our platform provider (USA)
Our software at app.saasvisionary.com is technically operated by our platform provider, a company based in the United States. The provider hosts the application, stores its data and provides the technical infrastructure.
- Data categories: all data processed in the app, in particular account data (section 4.3), usage and log data (for example, login times, IP address, browser information, actions performed in the app, error logs) and customer content (section 5).
- Purposes: providing, operating, securing and maintaining the app; detecting and correcting errors; preventing misuse.
- Legal basis: for account and usage data, Art. 6(1)(b) GDPR (providing the contractual service) and Art. 6(1)(f) GDPR (security and stability of the service, based on our legitimate interest in a secure, error-free platform). For customer content, the customer’s own legal basis applies (see section 5).
- Recipient: our platform provider (USA) as our processor or, for customer content, as our sub-processor, under a data processing agreement pursuant to Art. 28 GDPR.
- Third-country transfer: Transfers to the USA are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), together with the UK Addendum for UK data; the platform provider is not certified under the EU-U.S. Data Privacy Framework. The platform provider uses further sub-processors, which are listed on our sub-processor page. The name of the platform provider is available on request.
- Retention: The account’s audit history (which user did what and when) is kept for as long as the account exists. Crash reports keep only the most recent occurrences of each error. Account data and customer content are deleted as described in sections 4.3 and 5.
4.6 Transactional emails
We send you emails that are necessary for the contract, such as sign-up confirmations, password resets, trial and payment notifications, invoices, security alerts and notices of changes to the service or prices.
- Data categories: email address, name, company and the content of the respective message; where applicable, technical delivery data (time of delivery, delivery status).
- Legal basis: Art. 6(1)(b) GDPR; for security alerts additionally Art. 6(1)(f) GDPR.
- Recipients: these emails are sent via the email infrastructure of our platform provider (USA) or email delivery services used within the platform, acting as processors. See section 4.5 regarding third-country transfers.
- Retention: delivery data is deleted together with the log data of the app; the messages themselves form part of business correspondence (section 4.10) where applicable.
4.7 Third-party services connected by the customer
Within the app, customers can connect their own accounts with third-party services, for example Twilio (telephony and SMS), Mailgun (email delivery), AI model providers or their own Stripe account. When a customer does this, data is exchanged between the app and that service on the customer’s instructions.
The customer decides whether to connect such services and concludes its own contract with the respective provider. For this processing the customer is the controller, and the provider’s terms and privacy policies apply between the customer and that provider. We act only as the customer’s processor in transmitting the data. Customers are responsible for ensuring a legal basis and, where required, for concluding their own data processing agreements and providing information to their contacts.
4.8 Customer support
When you contact our support team, we process the data you provide and, to the extent necessary to solve your issue, the data in your account.
- Legal basis: Art. 6(1)(b) GDPR; for requests not related to a contract, Art. 6(1)(f) GDPR (our legitimate interest in answering inquiries).
- Access to account data: We access customer content only to the extent necessary to answer your request and only on your instruction or with your permission, in line with our Data Processing Agreement.
- Retention: support requests are deleted no later than 12 months after the issue is closed, unless they constitute business correspondence to be retained under section 4.10.
4.9 Information about our services by email (existing customers)
If you are a customer and have given us your email address in connection with the purchase of our service, we may send you information about our own similar products and services by email (for example, new features or plan upgrades).
- Legal basis: Art. 6(1)(f) GDPR in conjunction with § 7(3) of the German Act against Unfair Competition (UWG). Our legitimate interest lies in informing our customers about our own offerings.
- Right to object: You can object to this use at any time, free of charge (apart from the basic transmission costs), for example by clicking the unsubscribe link contained in every such email or by sending an email to privacy@saasvisionary.com. We pointed this out when collecting your email address.
- Retention: until you object or the customer relationship ends. After an objection, we keep your email address on a block list solely to ensure that we do not contact you again (Art. 6(1)(c) and (f) GDPR).
We do not send marketing emails to anyone else without their prior express consent (see section 4.11).
4.10 Statutory retention obligations
We are subject to German commercial and tax law retention obligations. In particular, invoices, accounting vouchers and records are retained for up to 10 years, and commercial and business correspondence for up to 6 years (§ 147 of the German Fiscal Code (AO), § 257 of the German Commercial Code (HGB)). The period begins at the end of the calendar year in which the document was created.
- Legal basis: Art. 6(1)(c) GDPR.
- During this period, the data is restricted and used only to comply with these obligations (for example, tax audits). It is deleted when the period expires.
We may also retain data where it is required to establish, exercise or defend legal claims, on the basis of Art. 6(1)(f) GDPR, for as long as the respective claim can be asserted.
4.11 Newsletter (with your consent)
In our contact form you can optionally tick a separate box to receive occasional news and offers from SaaSVisionary by email. Ticking it is voluntary and is not required to send your request.
- Double opt-in: after you subscribe, we send you a confirmation email. You are only added to the newsletter once you click the confirmation link. The link is valid for 7 days; without confirmation you do not receive newsletters.
- Data categories: your email address and, if provided, your name and company; the time of subscription and confirmation and the exact wording of the consent you gave, so that we can prove your consent.
- Content and frequency: news about SaaSVisionary, new features, guides and offers, usually no more than a few times per month.
- Evaluation: our email system can record whether a newsletter was delivered, opened and which links were clicked, so that we can improve our content. This evaluation is part of your consent.
- Legal basis: your consent (Art. 6(1)(a) GDPR and § 7(2) no. 2 UWG). Storing the proof of consent is based on Art. 6(1)(c) and (f) GDPR.
- Withdrawal: you can unsubscribe at any time with effect for the future via the link in every newsletter or by emailing privacy@saasvisionary.com. Sending a contact request later without ticking the box does not unsubscribe you.
- Recipients: our platform provider (USA) as our processor (see section 4.5), including the email delivery services used within the platform.
- Retention: until you unsubscribe. After that, we keep your email address on a block list so that you are not contacted again, and we keep the proof of your consent for up to 3 years to be able to demonstrate it (Art. 6(1)(c) and (f) GDPR).
5. Customer content: we act as processor
Customers use SaaSVisionary to store and process data about their own contacts, leads and clients, for example contact details, messages, call recordings and transcripts (if enabled by the customer) and files. For this customer content:
- the customer is the controller and decides why and how the data is processed;
- SaaSVisionary acts as a processor on behalf of the customer and processes the data only on the customer’s documented instructions, as set out in our Data Processing Agreement;
- our sub-processors are listed on our Sub-processors page.
If you are a contact of one of our customers and want to exercise your rights, please contact that business directly. If you contact us, we will forward your request to the customer where we can identify it, and support the customer in responding.
6. Recipients overview
We share personal data only where this is necessary for the purposes described above. Categories of recipients are:
- our platform provider (USA) for the operation of the app and, with your consent, website analytics;
- our hosting provider (servers in the United Kingdom) for website hosting;
- Stripe for payment processing;
- email, telephony and CRM service providers used to communicate with you;
- tax advisors and auditors, who are bound by professional secrecy, for accounting and tax purposes;
- public authorities (for example, tax authorities or courts) where we are legally obliged to disclose data.
A current list of our sub-processors is available on our Sub-processors page. We do not sell personal data.
7. International data transfers
Some of our service providers are located outside the European Union and the European Economic Area, or may access data from there. We transfer personal data to such countries only where the requirements of Art. 44 et seq. GDPR are met, in particular:
- United Kingdom: adequacy decision of the European Commission (Art. 45 GDPR);
- USA: the EU Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR) and, for recipients certified under it (for example Stripe), the EU-U.S. Data Privacy Framework (Art. 45 GDPR), together with supplementary measures where necessary.
You can request a copy of the relevant safeguards by contacting us at privacy@saasvisionary.com.
8. Your rights
Under the GDPR, you have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR): to obtain confirmation whether we process your data and, if so, information about it and a copy.
- Right to rectification (Art. 16 GDPR): to have inaccurate data corrected or incomplete data completed.
- Right to erasure (Art. 17 GDPR): to have your data deleted, unless we are required or entitled to retain it.
- Right to restriction of processing (Art. 18 GDPR): to have the processing of your data restricted in certain cases.
- Right to data portability (Art. 20 GDPR): to receive data you have provided to us, based on consent or a contract, in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Right to withdraw consent (Art. 7(3) GDPR): where processing is based on your consent, you can withdraw it at any time with effect for the future. The lawfulness of processing before the withdrawal remains unaffected.
To exercise your rights, simply contact us at privacy@saasvisionary.com. We may ask you to verify your identity. We respond within one month; in complex cases this period can be extended by two further months, in which case we will inform you. How to export and delete account data is also explained on our Data Deletion page.
Right to object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(f) GDPR (legitimate interests). In that case, we will no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
Where we process your personal data for direct marketing purposes, you have the right to object at any time to such processing, without having to give reasons. After an objection, we will no longer use your data for direct marketing.
To object, a short message to privacy@saasvisionary.com is sufficient.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestr. 2–4
40213 Düsseldorf, Germany
We would appreciate it if you contacted us first, so that we can try to resolve your concern directly.
10. No automated decision-making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).
11. Obligation to provide data
You are not legally obliged to provide personal data. However, some data is required to conclude and perform a contract with us (for example, the data required for sign-up and billing), or to answer your request. Without this data, we cannot conclude the contract or respond to you.
12. Data security
We take appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access, taking into account the state of the art, the costs of implementation and the risks involved. These include encrypted transmission using TLS on our website and in the app, access controls and the principle of least privilege. More information is available on our Security page.
13. Changes to this policy
We update this policy when our services or processing activities change or when the law requires it. The current version is always available on this page, with the date of the last update shown at the top. Where changes significantly affect customers, we will inform them by email in advance.