Zum Hauptinhalt springen
Privacy Policy

Version 1.3 – effective 10 June 2025 · KontoCSV – https://kontocsv.de

This notice informs you pursuant to Art. 12 – 14 GDPR and § 25 TTDSG about the type, scope and purpose of processing personal data when using KontoCSV.

1 Controller

Hermann Hampel

Kreuzäckerstr. 7 · 85055 Ingolstadt · Germany

Email support@kontocsv.de

(Fewer than 20 people regularly process personal data – no data protection officer is required under Sec. 38 BDSG. Please contact the controller directly if you have questions.)

2 Definitions

The definitions of Art. 4 GDPR apply (e.g. "processing", "personal data").

3 Hosting & Infrastructure

ServiceLocationPurposeLegal basisAgreement / Safeguard
Google Cloud Run (Google Ireland Ltd.)Region europe-west3 (Frankfurt)Serving website / APIArt. 6 (1) fCloud DPA incl. SCC, accepted 10 · 06 · 2025
Supabase (Supabase Inc.)eu-central-1Authentication, database, object storageArt. 6 (1) bDPA + SCC
Supabaseeu-west3 / eu-west1Realtime DB, storage, auth, pushArt. 6 (1) b / Art. 6 (1) fSupabase Data Processing Terms + SCC, accepted 10 · 06 · 2025
OpenAI (OpenAI Ireland Ltd. / OpenAI LLC)Ireland · USAAI-powered PDF analysisArt. 6 (1) bDPA 07 · 06 · 2025 incl. SCC & EU-US DPF
Stripe (Stripe Payments Europe Ltd.)IrelandPayment processingArt. 6 (1) bIndependent controller

4 Purposes of Processing & Legal Bases

ProcessingDataPurposeLegal basis
Website visitIP address, user agent, timestamp, referrerTechnical delivery & security logsArt. 6 (1) f
Registration / loginEmail, password hash, session tokenPerformance of the contractArt. 6 (1) b
PDF upload & AI analysisPDF content, metadataConversion to CSV / XLSXArt. 6 (1) b
PaymentName, email, card dataPerformance of the contractArt. 6 (1) b
Realtime sync / auth (Supabase)Device token, app ID, event dataLive status & push notificationsArt. 6 (1) f
Support contactEmail, messageHandling your requestArt. 6 (1) f
Cookies / local storageSession & CSRF tokensLogin persistence§ 25 (2) No. 2 TTDSG in conjunction with Art. 6 (1) f

No analytics or marketing cookies are set – a consent banner is therefore not required. If analytics or similar tools are added in the future, a consent banner will appear.

5 AI Processing & Third-Country Transfers

Uploaded PDF pages are transmitted to OpenAI in encrypted form so the Vision model can extract text and structure.

  • Legal framework: Standard Contractual Clauses (SCC) + EU-US Data Privacy Framework, DPA 07 · 06 · 2025.
  • Storage period at OpenAI: max. 30 days (API retention).
  • Training: API data is not used for model training.
  • Automated decisions: no decisions within the meaning of Art. 22 GDPR, only rule-based extraction.

Supabase runs in EU data centers. Processing is fully GDPR-compliant with additional technical safeguards (TLS 1.3, access controls).

6 Retention Periods

Data typeDeletion / retention
Server logs30 days
PDF files & intermediate resultsAutomatic hard delete ≤ 24 h
Contract & invoice data10 years (HGB, AO)
Support emails≤ 1 year after completion
Session tokensDeleted when the account is removed or user opts out

7 Technical & Organisational Measures (TOM)

TLS 1.3 end-to-end · AES-256 at rest

Optional CMEK encryption in Cloud Run & Supabase

Role & rights concept, MFA for admin accounts

In-memory processing + 24-hour deletion routine

Pen tests & vulnerability scans at least annually

Subprocessor monitoring (15 days prior notice)

8 Your Rights (Art. 15 – 22 GDPR)

You may request access, rectification, erasure, restriction, data portability or object at any time. Contact: support@kontocsv.de.

You also have the right to lodge a complaint with a supervisory authority (e.g. BayLDA, Promenade 27, 91522 Ansbach).

9 Withdrawal of Consent

Processing activities based on your consent can be withdrawn at any time without formal requirements. The lawfulness of processing carried out before the withdrawal remains unaffected.

10 Obligation to Provide Data

Email, password and payment details are required for registration, PDF upload and payment. Without this data, the paid services cannot be provided.

11 Changes to this Notice

We update this privacy notice whenever processes, service providers or legal requirements change. Current version: https://kontocsv.de/datenschutz · Effective 10 · 06 · 2025.