Skip to content
PRIVACY DRAFT

Privacy policy

Legal review required

Privacy draft - review against the actual providers, contracts and configuration before publication.

1. Controller

Stabilitätswerk AI. Legal form, service address and authorised representation still need to be completed before launch.

2. Privacy contact

Contact for privacy matters: kontakt@stabilitaetswerk.de. Additional contact channels and mailing address still need validation.

3. Cloudflare hosting

The website is intended to be delivered through Cloudflare Pages. Cloudflare receives technical request data such as IP address, headers and timestamps.

4. Supabase Auth

Supabase processes signup, login, password-recovery and session data needed for authentication and invitation acceptance.

5. Supabase database

Supabase stores organisation, company, assessment and role data where this is required for the product to function.

6. Registration and user account

Name, business email and authentication data are processed to create and operate a user account.

7. Organisation and team data

Organisation names, memberships, roles, invitations and suspension markers are processed to support collaborative access.

8. Company and financial data

Only the financial inputs required by the documented scoring formula and its derived metrics are requested.

9. Business Health Assessments

Each assessment stores inputs, derived metrics, formula version, score values, data-quality warnings and triggered recommendations.

10. Stripe Checkout and billing

Stripe receives billing, address and tax-ID-related data to support checkout, subscription management and invoicing.

11. Stripe Customer Portal

The customer portal allows payment methods, invoices and subscription settings to be managed through Stripe.

12. Contact by email

If you contact the provider by email, the submitted data is processed to handle the request. Exact retention periods still need to be defined.

13. Technical server logs

Cloudflare, Supabase and infrastructure providers may process technical log data. Exact contents and retention windows require final review.

14. Local storage required for authentication

The application uses browser storage for session persistence. No marketing trackers or advertising cookies are used in the initial version.

15. No marketing analytics in the initial version

The initial release uses no marketing trackers, no advertising cookies, no remote fonts and no embedded social feeds.

16. No generative-AI processing of assessment inputs

Financial assessment inputs are not sent to generative AI systems for scoring or recommendation generation.

17. Recipients and processors

At minimum, recipients/processors include Cloudflare, Supabase and Stripe. Additional processors must not be invented.

18. International data transfers

Cross-border transfers need to be reviewed against the actual infrastructure, contractual safeguards and provider setup before launch.

19. Retention periods

Exact retention periods must be defined from legal, contractual and operational requirements and should not be guessed.

20. Account and data deletion

A final account and organisation deletion process still needs to be defined. The current product avoids unsafe partial deletion.

21. Rights of data subjects

Data subjects may exercise access, rectification, deletion, restriction, portability and objection rights within the applicable legal framework.

22. Right to complain

Data subjects may lodge a complaint with a competent supervisory authority.

23. Security measures

The product relies on HTTPS, role-based access, Supabase RLS, minimal privileged functions and conservative logging rules.

24. Changes to the privacy policy

This policy is a draft and must be completed, reviewed and updated whenever the product setup materially changes.