1. Controller
Stabilitätswerk AI. Legal form, service address and authorised representation still need to be completed before launch.
Legal review required
Privacy draft - review against the actual providers, contracts and configuration before publication.
Stabilitätswerk AI. Legal form, service address and authorised representation still need to be completed before launch.
Contact for privacy matters: kontakt@stabilitaetswerk.de. Additional contact channels and mailing address still need validation.
The website is intended to be delivered through Cloudflare Pages. Cloudflare receives technical request data such as IP address, headers and timestamps.
Supabase processes signup, login, password-recovery and session data needed for authentication and invitation acceptance.
Supabase stores organisation, company, assessment and role data where this is required for the product to function.
Name, business email and authentication data are processed to create and operate a user account.
Organisation names, memberships, roles, invitations and suspension markers are processed to support collaborative access.
Only the financial inputs required by the documented scoring formula and its derived metrics are requested.
Each assessment stores inputs, derived metrics, formula version, score values, data-quality warnings and triggered recommendations.
Stripe receives billing, address and tax-ID-related data to support checkout, subscription management and invoicing.
The customer portal allows payment methods, invoices and subscription settings to be managed through Stripe.
If you contact the provider by email, the submitted data is processed to handle the request. Exact retention periods still need to be defined.
Cloudflare, Supabase and infrastructure providers may process technical log data. Exact contents and retention windows require final review.
The application uses browser storage for session persistence. No marketing trackers or advertising cookies are used in the initial version.
The initial release uses no marketing trackers, no advertising cookies, no remote fonts and no embedded social feeds.
Financial assessment inputs are not sent to generative AI systems for scoring or recommendation generation.
At minimum, recipients/processors include Cloudflare, Supabase and Stripe. Additional processors must not be invented.
Cross-border transfers need to be reviewed against the actual infrastructure, contractual safeguards and provider setup before launch.
Exact retention periods must be defined from legal, contractual and operational requirements and should not be guessed.
A final account and organisation deletion process still needs to be defined. The current product avoids unsafe partial deletion.
Data subjects may exercise access, rectification, deletion, restriction, portability and objection rights within the applicable legal framework.
Data subjects may lodge a complaint with a competent supervisory authority.
The product relies on HTTPS, role-based access, Supabase RLS, minimal privileged functions and conservative logging rules.
This policy is a draft and must be completed, reviewed and updated whenever the product setup materially changes.