Privacy notice

This notice explains which personal data SmallBiz Guide GmbH processes as the operator of PayLens, for which purposes, and what rights you have under the GDPR. Not legal advice.

1. Controller

The controller is SmallBiz Guide GmbH, Nachtigallenweg 17, 65779 Kelkheim, Germany, registered with the commercial register of Königstein local court under HRB 11926, represented by its managing director Robert Hoffmann. Please send privacy requests to info@smallbizguide.de.

We are not required to appoint a data protection officer (§ 38 (1) BDSG); requests are answered by the management.

2. What we process, and why

  • Email address — for passwordless sign-in (magic link) and to send the notifications you asked for (alert digest).
  • Profile & preferences — language and default market, to personalise the interface.
  • Alert rules & events, saved views — content you create, so we can deliver the notifications that match it.
  • Newsletter (“PayLens Radar”) — email address and chosen language when you subscribe to the free newsletter. Sign-up uses double opt-in: we only send after you confirm via the link we email you, and the times of sign-up and confirmation are logged. Every issue carries a one-click unsubscribe link (no account needed).
  • Contact requests: name, company (optional), email address and your message when you use the contact form; to handle your request. Deleted once the request is closed and no statutory retention duties apply.
  • Access requests: name, email address, company (optional), your message (optional) and language when you ask for dashboard access via “Request access”; to decide on the request. The admins receive the request by email, and you get a confirmation of receipt that repeats none of it. Stored with the request are also its status (pending, approved or declined), when and by whom it was decided, and an internal note on the decision.
  • Bot protection on forms: on the contact, access request and newsletter forms, Cloudflare Turnstile checks that a submission comes from a person (section 4).
  • Usage data: page views, clicks, search queries and session recordings inside the signed-in app, plus anonymous visit statistics for the public pages; to see which parts get used (section 7).
  • Technical server and access logs — for operation, security and error analysis.

3. Legal bases

Art. 6(1)(b) GDPR (providing the services you requested: sign-in, notifications; for access requests, steps taken at your request before entering into a contract), Art. 6(1)(a) GDPR (consent: newsletter; revocable at any time via the unsubscribe link) and Art. 6(1)(f) GDPR (legitimate interest in security and operation, in particular server log files and protecting the forms against bots and abuse, and in the usage analytics described in section 7).

4. Processors / recipients

We have concluded data processing agreements pursuant to Art. 28 GDPR with the following providers:

  • Supabase Inc. — authentication, application database and encrypted file storage. Seat: San Francisco, USA · processing in the EU region Frankfurt · SCCs + EU-US Data Privacy Framework.
  • Resend Inc.: delivery of transactional email (sign-in, digest, access requests); the email address is transmitted for delivery. Seat: San Francisco, USA · SCCs + EU-US Data Privacy Framework.
  • PostHog Inc.: usage analytics (section 7). Seat: San Francisco, USA · processing in the EU region Frankfurt · SCCs.
  • Google Ireland Ltd. — application hosting (Firebase App Hosting), server logs. Seat: Dublin, Ireland · processing in the EU.
  • Cloudflare, Inc.: bot protection on the contact, access request and newsletter forms (Cloudflare Turnstile). When one of these forms loads and is submitted, your IP address and technical characteristics of your browser and device are sent to Cloudflare to detect automated submissions. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the forms against spam and abuse). Seat: San Francisco, USA · processing on Cloudflare’s global network · EU-US Data Privacy Framework + SCCs.

5. Transfers to third countries

Supabase Inc. and Resend Inc. are headquartered in the USA. Both are certified under the EU-US Data Privacy Framework, recognised by the European Commission’s adequacy decision of 10 July 2023; standard contractual clauses (module 2) have been concluded in addition. PostHog Inc. is also headquartered in the USA; the usage analytics run in its EU cloud in Frankfurt, and standard contractual clauses cover any support access from the USA. The processing itself takes place in the EU (Supabase region Frankfurt, PostHog region Frankfurt). Cloudflare, Inc. is also headquartered in the USA and certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. Turnstile runs on Cloudflare’s global network, so the data from the bot check may also be processed outside the EU. Beyond this, no data is transferred to third countries.

6. Cookies

We only use strictly necessary cookies (sign-in session, language preference). Under § 25 (2) no. 2 TDDDG these require no consent. No advertising or analytics cookies; section 7 explains how the usage analytics work without them.

7. Usage analytics (PostHog)

To see which parts of PayLens are used and where people get stuck, we use PostHog (PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA), run in its EU cloud in Frankfurt; the data never leaves the EU.

Public pages: page views, clicks, device type, browser and referring page are collected without cookies and without storing anything on your device. Visitors are counted by a daily-rotating hash computed server-side from IP address and browser signature; the IP address itself is not stored, and recognising a visitor beyond that day is not possible.

Signed-in app: page views, clicks, search queries and the use of individual features are linked to your account (user id, email address), so we can improve features where it matters and ask you about them if needed. We also record sessions (movements and clicks in the interface); form inputs are masked. An identifier is stored in the localStorage of your browser.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in developing the product). You can object to the usage analytics at any time: inside the app under Settings › Account › Usage analytics (applies to that browser), or informally via info@smallbizguide.de. A data processing agreement under Art. 28 GDPR is in place with PostHog. Event data and session recordings are deleted automatically once the retention period configured at PostHog ends, and are never kept longer than the analysis requires.

8. Retention

Profile, preference and alert data are stored for as long as your account exists or as long as needed for the purposes above; afterwards they are deleted or anonymised. Newsletter data are stored until you unsubscribe; proof of consent is retained to the extent legally required. Access requests are kept after the decision, so that a later request from the same address can be matched to it, until you ask for their deletion (section 9). Technical server log files are deleted automatically after at most 14 days.

9. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), as well as to withdraw consent you have given (Art. 7(3) GDPR). An informal message to info@smallbizguide.de is enough.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 31 63, 65021 Wiesbaden, Germany.

This is a translation for convenience. In case of doubt, the German version prevails.

Legal notice