Skip to main content
Privacy Policy

Version 1.5, effective 23 July 2026 · KontoCSV · https://kontocsv.de

This notice informs you pursuant to Art. 12 – 14 GDPR and § 25 TDDDG about the type, scope and purpose of processing personal data when using KontoCSV.

1 Controller

Tom Abraham

Riemekestraße 118 · 33102 Paderborn · Germany

Email support@kontocsv.de

(Fewer than 20 people regularly process personal data – no data protection officer is required under Sec. 38 BDSG. Please contact the controller directly if you have questions.)

2 Definitions

The definitions of Art. 4 GDPR apply (e.g. "processing", "personal data").

3 Hosting & Infrastructure

ServiceLocationPurposeLegal basisAgreement / Safeguard
Supabase (Supabase Inc.)eu-central-1 (Frankfurt)Authentication, database, jobs, and private object storageArt. 6 (1) lit. b or Art. 6 (1) lit. f GDPRSupabase Data Processing Terms including Standard Contractual Clauses
Google Cloud Storage (Google Ireland Ltd.)Region europe-west3, Frankfurt am MainTemporary encrypted provision of PDF files, document chunks, and technically required intermediate formats for AI-assisted document processing; no permanent document repositoryArt. 6 (1) b GDPRGoogle Cloud Data Processing Addendum including Standard Contractual Clauses
Google Vertex AI / Gemini (Google Ireland Ltd.)Region europe-west3, Frankfurt am MainAI-assisted extraction and structuring of uploaded PDF documentsArt. 6 (1) b GDPRGoogle Cloud Data Processing Addendum including Standard Contractual Clauses
Render (Render Inc.)FrankfurtOperation of the Python backend and document processingArt. 6 (1) f GDPRData Processing Agreement and Standard Contractual Clauses
Stripe (Stripe Payments Europe Ltd.)IrelandPayment processingArt. 6 (1) bIndependent controller
Vercel Inc.Frankfurt, function region fra1Frontend hosting and server-side functionsArt. 6 (1) f GDPRData Processing Agreement, Standard Contractual Clauses, and EU-US Data Privacy Framework
Resend Inc.Ireland (eu-west-1)Transactional emails (registration, password reset)Art. 6 (1) bDPA + SCC
PostHog Inc.EU (Frankfurt, AWS eu-central-1)Web analytics, page views, clicksArt. 6 (1) fDPA + SCC
Sentry (Functional Software Inc.)EU (Frankfurt)Error logging and technical stability analysis of the platformArt. 6 (1) fData Processing Agreement (DPA) + SCC

Web analytics is cookieless, without cookies or local storage (PostHog cookieless_mode). No analytics cookies are set, so no consent banner is required.

Google Cloud Storage is used only in the processing path, especially for temporary uploads, chunking large files, and required intermediate formats. Automatic hard deletion takes place no later than within seven days; deletion may occur earlier in the normal processing path.

4 Purposes of Processing & Legal Bases

ProcessingDataPurposeLegal basis
Website visitIP address, user agent, timestamp, referrerTechnical delivery & security logsArt. 6 (1) f
Registration / loginEmail, password hash, session tokenPerformance of the contractArt. 6 (1) b
PDF upload & AI analysisPDF content, metadata, temporary chunks, and required intermediate formatsEncrypted temporary transmission and processing to perform the contract; no permanent storage in Google Cloud Storage, automatic hard deletion no later than within seven daysArt. 6 (1) b
PaymentName, email, card dataPerformance of the contractArt. 6 (1) b
Realtime sync / auth (Supabase)Device token, app ID, event dataLive status & push notificationsArt. 6 (1) f
Support contactEmail, messageHandling your requestArt. 6 (1) f
Web analytics (PostHog, cookieless)Anonymized user hash, page views, clicksProduct improvement & conversion optimizationArt. 6 (1) f
Error logs (Sentry)technical error metadata, browser type, anonymized IPStability, error analysis and technical improvement of the platformArt. 6 (1) f
Cookies / local storageSession & CSRF tokensLogin persistence§ 25 (2) No. 2 TDDDG in conjunction with Art. 6 (1) f

Sentry is used exclusively for technical error analysis. Personal data is not actively transmitted.

Error monitoring does not store uploaded document contents. Financial data, PDF content, and transaction data are never transmitted to error monitoring services. Only technical error metadata is processed.

No analytics or marketing cookies are set. Web analytics runs cookieless (PostHog cookieless_mode) without cookies or local storage, so a consent banner is not required.

5 AI Processing & Third-Country Transfers

Uploaded PDF files are processed in encrypted form within the configured EU regions. The Python backend processes jobs on Render in Frankfurt.

  • Google Cloud Storage: For the Gemini processing path, PDF files or chunks generated from them are temporarily provided in Google Cloud Storage in region europe-west3, Frankfurt am Main. Google Cloud Storage is used only for temporary processing, chunking large files, and required intermediate formats.
  • Google Gemini / Vertex AI: AI-assisted extraction and structuring takes place via Vertex AI or Gemini in region europe-west3, Frankfurt am Main, based on the Google Cloud Data Processing Addendum including Standard Contractual Clauses.
  • Other AI providers: Other AI providers are used for customer documents only if they are enabled in the production customer path and documented in the subprocessor list.

The following applies to all AI services:

  • Storage period: Original files, chunks, and intermediate formats are automatically and permanently deleted no later than within seven days; Google Cloud Storage is not used for permanent archiving of customer documents.
  • Automated decisions: no decisions within the meaning of Art. 22 GDPR; extraction is technically validated and must be reviewed by the user.

Supabase is used for authentication, database, jobs, and private object storage in region eu-central-1 (Frankfurt).

6 Retention Periods

Data typeDeletion / retention
Server logs30 days
PDF files, temporary GCS uploads, document chunks, and intermediate formatsAutomatic hard deletion no later than within seven days, regularly earlier after processing is complete
Contract & invoice data10 years (HGB, AO)
Support emails≤ 1 year after completion
Session tokensDeleted when the account is removed or user opts out

7 Technical & Organisational Measures (TOM)

Encryption in transit and at rest according to provider standards

Role-based access restrictions for administration and support processes

Temporary processing and automatic deletion routines

Regular technical security checks and dependency scans

Subprocessor monitoring (15 days prior notice)

8 Your Rights (Art. 15 – 22 GDPR)

You may request access, rectification, erasure, restriction, data portability or object at any time.

Self-service in Dashboard:

  • Export data (Art. 20): Under Settings → "Export my data" you can download all your data as a JSON file.
  • Delete account (Art. 17): Under Settings → "Delete account" you can permanently delete your account and all associated data.

Alternatively, contact us via email: support@kontocsv.de

You also have the right to lodge a complaint with the competent supervisory authority in North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf.

9 Withdrawal of Consent

Processing activities based on your consent can be withdrawn at any time without formal requirements. The lawfulness of processing carried out before the withdrawal remains unaffected.

10 Obligation to Provide Data

Email, password and payment details are required for registration, PDF upload and payment. Without this data, the paid services cannot be provided.

11 Changes to this Notice

We update this privacy notice whenever processes, service providers or legal requirements change. Current version: https://kontocsv.de/en/privacy · Version 1.5, effective 23 July 2026.