Privacy Policy for Albrecht Apps GmbH

Version 2026-07-16 · Effective July 16, 2026

The German version is the legally controlling version. The English text in the PDF is a convenience translation only.

Open PDF (DE/EN)

1. Controller

This English text is provided for convenience only. The German version is the legally controlling version. In case of discrepancies or questions of interpretation, the German version prevails.

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Albrecht Apps GmbH
Falkenstraße 9
49610 Quakenbrück
Germany

Represented by the managing director: Andrej Albrecht

Email: contact@albrecht-apps.com
Phone: +49 5431 9567802

No data protection officer has been appointed.

2. General information on data processing

2.1 Scope of processing
We process personal data only to the extent necessary to provide our website and services, to communicate, to carry out pre-contractual measures and contracts, to fulfil legal obligations, to secure our systems, or where you have given consent.

2.2 Legal bases
Depending on the processing activity, we rely in particular on:

  • Art. 6(1)(a) GDPR where you have given voluntary consent;
  • Art. 6(1)(b) GDPR for pre-contractual measures and contract performance;
  • Art. 6(1)(c) GDPR to fulfil legal obligations;
  • Art. 6(1)(f) GDPR to pursue legitimate interests, unless your interests or fundamental rights override ours.

Access to information on a terminal device or its storage is additionally governed by Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act). Where strictly necessary, access occurs under Section 25(2) TDDDG; otherwise only with consent under Section 25(1) TDDDG.

2.3 Recipients and processors
We use carefully selected service providers. Where they process personal data on our behalf, we conclude the legally required data processing agreements. We disclose data to other recipients only where necessary for contract performance, a legal basis exists, or you have consented.

2.4 Transfers to third countries
Individual providers may process data outside the European Union or European Economic Area. In such cases we ensure that the requirements of Arts. 44 ff. GDPR are met, in particular through an adequacy decision of the European Commission, valid certification under the EU-US Data Privacy Framework, or appropriate safeguards such as the European Commission’s standard contractual clauses. Residual risks may arise in particular from access rights of foreign authorities.

2.5 Storage periods
We store personal data only as long as necessary for the respective purpose. Thereafter data is deleted or anonymised unless legal retention obligations, assertion or defence of legal claims, or documented security reasons require further storage. Specific periods are stated in the respective processing descriptions. The stated retention periods are enforced through automated daily deletion jobs.

3. Hosting and provision of the website

We host our website and central application data with Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Under our configuration, the web servers, databases, load balancing, and monitoring infrastructure used are predominantly located in Nuremberg, Germany.

Each time the website is accessed, technically necessary data is processed, in particular:

  • IP address;
  • date and time of access;
  • URL accessed and amount of data transferred;
  • referrer URL;
  • browser, operating system, and device information;
  • HTTP status and technical error data.

This processing is necessary to deliver, stabilise, analyse errors in, and secure the website. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our digital offerings.

Server and access logs are generally stored for 14 days. Security-relevant extracts may be stored longer in individual cases until an incident is clarified and defended against and until claims are enforced or defended.

4. Security measures and abuse prevention

To protect our website and user accounts we process technical security data. This includes IP address, user agent, login identifier or partially masked email hint, timestamp, failed login attempts, rate-limit counters, block reason, and technical session and security tokens.

We use in particular HTTPS/HSTS, CSRF protection, access restrictions, firewalls, rate limits, honeypots, time-based checks, and temporary lockout after repeated failed logins. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is preventing abuse, fraud, spam, and attacks and protecting our users and systems.

Rate-limit data is stored for a short period. Application and security logs are generally stored for 30 days unless a specific security incident requires longer retention.

5. Strictly necessary cookies and storage technologies

We use strictly necessary cookies and comparable storage technologies so that the website and user accounts function. These include in particular:

Where these storages are strictly necessary for the explicitly requested service, the legal basis is Section 25(2) TDDDG. Subsequent processing depends on purpose under Art. 6(1)(b) or (f) GDPR. These technologies are first-party (Albrecht Apps).

Storing your consent decision also serves to evidence and manage your choice. Server-side consent records may include session identifier, IP address, user agent, selection, and timestamp. Legal bases are Art. 6(1)(c) and (f) GDPR. Records are generally stored for up to three years after replacement or withdrawal of the choice where required to meet accountability obligations.

Optional cookies (analytics and similar) are set only after your consent; see Sections 16–20. A continuously updated overview of cookies and browser storage—including provider, category, retention, and first-/third-party classification—is available under Cookie Settings.

6. User accounts and registration

When setting up and managing a user account we process in particular:

  • email address and encrypted password;
  • verification status and verification timestamps;
  • time zone and communication settings;
  • required confirmations and voluntary consents with timestamps;
  • security-relevant login and account data.

The email address is verified through a confirmation link. The legal basis is Art. 6(1)(b) GDPR for establishing and performing the user relationship and Art. 6(1)(f) GDPR for security and prevention of abusive accounts.

During registration you confirm that you have read the privacy policy. This acknowledgment is not a data protection consent. Voluntary consents, in particular for newsletter, analytics, or marketing, are requested separately and may be withdrawn at any time with future effect.

Account data is stored for the duration of the user relationship. After account deletion, productive content is generally deleted or anonymised within 30 days unless legal retention obligations, open claims, or security reasons prevent this. Data in backups is overwritten in the regular cycle within at most 90 days.

7. Waiting list and access invitations

If you register for a waiting list we process your email address, language, signup source, and confirmation and timestamp data. This serves to manage the waiting list and send requested access information.

The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw this at any time. Unconfirmed signups and unused invitation tokens are generally deleted after 7 days. Confirmed waiting-list data is stored until withdrawal, purpose ceases, or regular cleanup.

8. Newsletter and free PDF and scorecard offers

Certain free resources are expressly offered as part of our newsletter. If you select this offer, you consent to receive the requested resource and the newsletter by email with information on product architecture, BLE, launch guides, engineering insights, and simulator updates.

We process in particular:

  • email address;
  • selected topics, language, and signup source;
  • consent text, timestamp, and confirmation status;
  • delivery, unsubscribe, bounce, and complaint information.

Signup uses a double opt-in procedure. Only after you confirm the link in the confirmation email are the resource and newsletter sent. Confirmation evidences that the address provided is controlled by the person signing up.

The legal basis is Art. 6(1)(a) GDPR. Proof of signup and abuse prevention additionally rely on Art. 6(1)(f) GDPR. Our legitimate interest is legally secure proof of signup and prevention of foreign or abusive registrations.

You may withdraw consent at any time via the unsubscribe link in any newsletter email or by message to contact@albrecht-apps.com. After withdrawal the address is blocked for marketing sends. A minimal suppression record may be stored for up to three years to evidence withdrawal and prevent further sends. Unconfirmed signups are deleted after 7 days.

Some free PDF documents contain first-party redirect links on our website (paths under /go/). When you click such a link we perform an immediate redirect to the destination and may record an anonymous measurement event (document edition, link key or destination, language, and timestamp). We do not set analytics cookies on this hop and do not join the event to a newsletter subscriber or user account. To limit repeat counts we briefly process a truncated network address into a short-lived cryptographic hash (typically 24 hours) and do not store the raw IP address or browser user-agent on the click record. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is understanding which document links are used so we can improve our materials. You may object on grounds relating to your particular situation. Raw click events are generally deleted after 90 days.

9. Measurement of email opens and link clicks

If you have separately and voluntarily consented to performance measurement, our newsletters may contain a tracking pixel and personalised redirect links. When an email is opened or a link clicked, this may process in particular email address or recipient identifier, IP address, user agent, timestamp, and destination URL. Evaluation serves to measure reach and relevance of our content.

The legal basis is exclusively your voluntary consent under Art. 6(1)(a) GDPR and, where terminal-device access occurs, Section 25(1) TDDDG. Consent is not required to receive the newsletter and may be withdrawn at any time with future effect.

Raw tracking data is generally deleted or aggregated after 90 days. Without tracking consent you technically receive a variant without an open pixel and without personalised click measurement; neither tracking pixels nor personalised redirect links are generated.

10. Email delivery via Mailgun

We use Mailgun, a service of Mailgun Technologies, Inc., USA, to send confirmations, transactional messages, free resources, and newsletters. Production is configured for the EU API and EU data region. This processes in particular email address, message content, delivery status, technical send data, and bounce, unsubscribe, and complaint information.

The legal basis depends on the send purpose: Art. 6(1)(b) GDPR for contract- or account-related messages, Art. 6(1)(a) GDPR for newsletters, and Art. 6(1)(f) GDPR for delivery reliability, suppression lists, and abuse prevention.

Despite the chosen EU region, Mailgun as a US provider may be subject to third-country access possibilities. Transfer occurs on the basis of applicable safeguards of the provider, in particular possible certification under the EU-US Data Privacy Framework and/or standard contractual clauses.

Full sent email content is generally stored in our system for at most 90 days unless longer storage is required for contract performance, consent documentation, or defence of claims. Delivery and suppression information is stored longer according to the respective purpose.

11. Email address verification via Mailboxlayer/APILayer

To safeguard delivery quality and prevent spam, fraud, and abusive signups we verify newly entered email addresses with Mailboxlayer, a service of Apilayer Data Products GmbH, Oppolzergasse 6/1/4, 1010 Vienna, Austria.

The email address and technical verification data are transmitted to the provider. We receive among other things information on format, domain, MX/SMTP reachability, disposable, role, or freemail properties, and a scoring value. The verification result and technical provider response may be stored.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is preventing abusive signups, protecting sending reputation, and avoiding undeliverable messages. Data subjects may object on grounds relating to their particular situation.

Verification results are generally deleted after 90 days. Provably undeliverable, abusive, or complaint-related addresses may be stored longer on a suppression list where necessary to prevent further messages.

12. Launch Readiness Score and browser storage

With the Launch Readiness Score, answers may initially be stored in your browser’s local storage under a language-dependent key so you can continue the questionnaire. This data remains on your device until deleted by the application, your browser, or yourself.

If you request the result by email we process your email address, questionnaire answers, calculated scores, language, consent, and delivery information. The legal basis is Art. 6(1)(a) GDPR if you voluntarily request the send.

Submitted scorecard answers are generally stored for 12 months and then automatically deleted or anonymised unless longer storage is required due to a contract, renewed consent, or legal obligations. On newsletter unsubscribe, stored answers are deleted before this period expires.

13. Product and SaaS data

When using our authenticated products we may process depending on function:

  • company name, website, and country;
  • information on brand, target audience, and business;
  • freely entered texts and configurations;
  • generated content and results;
  • landing page content, subdomains, and optional custom domains;
  • usage, status, and technical log data.

Processing occurs to provide the selected functions on the basis of Art. 6(1)(b) GDPR. Voluntary content is required for the respective output; without it the relevant function cannot be executed.

Product content is stored for the account duration and generally removed from active systems within 30 days after account or content deletion. Backups are overwritten in the regular cycle within at most 90 days.

Please do not enter special categories of personal data under Art. 9 GDPR, health data, passwords, payment data, confidential third-party data, or other personal data unless expressly required and agreed with us.

14. AI functions and OpenAI API

For certain optimisation and generation functions we transmit business texts entered by the user and necessary instructions to the OpenAI API. For users in the European Economic Area the provider under the applicable contract terms is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland; affiliated companies and subprocessors may also process data in third countries.

Input texts, technical metadata, and generated outputs may be processed. The purpose is solely the generation or optimisation requested by the user. The legal basis is Art. 6(1)(b) GDPR.

We use an OpenAI business/API account. Under settings applicable to business services, API inputs and outputs are by default not used to train models unless we expressly consent to data sharing.

For necessary third-country transfers the safeguards described in Section 2.4 apply. Users must not enter special categories of personal data, confidential third-party data, or other personal content unless expressly agreed and secured under data protection law.

15. Error monitoring with self-hosted Sentry

To detect and analyse technical errors we use a self-hosted Sentry installation on our Hetzner infrastructure. Both backend and browser errors may be captured. This may process technical error details, timestamp, affected URL or function, browser/device information, IP address, and technical identifiers. Transmission of standard personal user information to Sentry is disabled.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is stability, security, and remediation of our services. Error data is generally deleted after 30 days unless needed longer to analyse a specific incident.

16. Consent management and Google Tag Manager

We use Google Tag Manager only after your consent to manage analytics and marketing technologies technically. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is not loaded when you first access our website. A connection to Google is established and Google Tag Manager is loaded only after you have consented to the “Analytics & Performance” category. Without this consent, no analytics or marketing tags are activated through Google Tag Manager and no Consent Mode or comparable analytics requests are transmitted to Google.

The legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with future effect through the cookie settings.

17. Google Analytics 4

After your consent we use Google Analytics 4, a web analytics service of Google Ireland Limited. Google Analytics processes in particular pages visited, events, approximate location and device information, referrer, technical identifiers, IP address, and usage timestamps. IP anonymisation is enabled; Google may nevertheless process data in third countries.

After consent, Google may set third-party cookies such as _ga, _gid and _gat (or comparable identifiers) via Google Tag Manager. Their storage duration follows Google’s policies.

Processing serves reach measurement and improvement of our website. Legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw consent at any time via cookie settings.

User-related event data in Google Analytics is stored for at most 14 months.

18. Meta Pixel

After your consent we use the Meta Pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This may transmit in particular visited pages, interactions, referrer, browser and device data, IP address, timestamp, and cookie or advertising identifiers to Meta. Meta may link this information to an existing Meta account and use it for measurement, audience building, and advertising.

For collection and transmission of certain event data Meta and we may be joint controllers; for subsequent processing Meta is independently responsible under its terms.

After consent, Meta may set third-party cookies or advertising identifiers. Specific names and retention periods follow Meta’s policies.

Legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. The pixel is activated only after consent. You may withdraw consent at any time via cookie settings.

19. LinkedIn Insight Tag

After your consent we use the LinkedIn Insight Tag of LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn may process URL, referrer, IP address, device and browser properties, and timestamps. Data serves conversion measurement, reach analysis, and where applicable audience building.

According to LinkedIn, directly identifying characteristics are removed within seven days and remaining pseudonymised data is deleted within 180 days.

After consent, LinkedIn may set third-party cookies or identifiers. Specific names and retention periods follow LinkedIn’s policies.

Legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. The tag is activated only after consent. You may withdraw consent at any time via cookie settings.

20. YouTube videos

We embed videos in enhanced privacy mode via youtube-nocookie.com. The provider is Google Ireland Limited. When an embedded player loads, IP address, browser and device data, referrer, page visited, and further technical data may nevertheless be transmitted to Google/YouTube. If you are logged in to Google, Google may associate the view with your account.

YouTube videos are not loaded on page view. Instead we initially show a local preview image with a two-click solution. The player loads only after you allow external media in cookie settings and actively start the video in a second step. Until then no connection to YouTube is established and YouTube does not set cookies through our embeds.

Processing occurs on the basis of your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be withdrawn via cookie settings.

21. Self-hosted fonts and icons

Fonts and icons are delivered from our own servers on Hetzner infrastructure. We use in particular Inter as the main typeface, Font Awesome for symbols, and IBM Plex Mono for code display in the blog.

No fonts or icons are loaded from Google Fonts, Font Awesome CDNs, or comparable external providers. On normal page views no IP addresses are therefore transmitted to such third parties.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is uniform and privacy-conscious presentation of our website without unnecessary third-party connections.

22. Contact by email, phone, and WhatsApp link

Our website has no contact form. You can reach us by email or phone; a WhatsApp link is also available.

When you contact us by email or phone we process the information you provide, in particular contact details, content, and timestamp, to handle your enquiry.

The legal basis is Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is handling business communication.

The website contains an external link to WhatsApp. Only when you click this link are you redirected to WhatsApp. The respective WhatsApp provider is responsible for processing there under its terms. Please do not transmit confidential or sensitive data via WhatsApp.

Contact enquiries are generally deleted once the enquiry is finally handled and no contractual, legal, or evidential reasons prevent deletion. Business correspondence may be subject to statutory retention obligations.

23. External links and social media presence

Our website contains links to LinkedIn, X, Instagram, Facebook, Threads, YouTube, Pinterest, and other external offerings. Merely displaying our website does not transmit data to these providers through plain links. Only when you click do you leave our website. The respective provider’s privacy information applies to subsequent processing.

Where you interact with our social media profiles we process visible profile, message, and interaction data for communication and public relations. The legal basis depending on content is Art. 6(1)(b) or (f) GDPR. For individual platform functions joint responsibility with the platform provider may exist.

24. Payment services

Stripe is technically prepared but is not currently used as an active payment service on the website. Before activation these privacy notices, data processing agreements, the order process, and concrete data flows will be updated. Until then no payment data is transmitted to Stripe via the website.

25. Automated decision-making

We currently do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Scores and AI outputs serve orientation and are not used for such decisions.

26. Obligation to provide data

Providing data is generally neither legally nor contractually required. However, certain information is necessary to set up an account, provide a requested service, deliver an email, or perform a contract. Without this data the relevant function or service cannot be offered.

27. Rights of data subjects

Subject to statutory requirements you have in particular the right:

  • of access under Art. 15 GDPR;
  • to rectification under Art. 16 GDPR;
  • to erasure under Art. 17 GDPR;
  • to restriction of processing under Art. 18 GDPR;
  • to data portability under Art. 20 GDPR;
  • to object under Art. 21 GDPR;
  • to withdraw consent under Art. 7(3) GDPR with future effect;
  • to lodge a complaint with a supervisory authority under Art. 77 GDPR.

To exercise your rights contact contact@albrecht-apps.com. We may require reasonable proof of identity to prevent unauthorised disclosure.

Special note on the right to object
Where we process data on the basis of Art. 6(1)(f) GDPR you may object at any time on grounds relating to your particular situation. For direct marketing you may object at any time without giving specific reasons.

28. Right to lodge a complaint

You may lodge a complaint with a supervisory authority. The authority responsible for our registered office is:

The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hannover
Germany

Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de

29. Updates to this privacy policy

We update this privacy policy when our processing, services used, or legal requirements change. The version published on this website applies. Where material changes require renewed consent we obtain this separately.