Scope:
This part applies exclusively to our web application at app.supapresence.com. For our public website, please refer to the "Website" section; the tracking and marketing services described there (PostHog, Google Tag Manager, HubSpot) are not used in the app.
1. Controller and Our Role
The app is operated by:
SupaPresence
Daniel Zamojski, Michael Helcig
(Complete contact details can be found in our Imprint)
For user account data (e.g. registration, login, billing, support) we are the controller within the meaning of Art. 4(7) GDPR.
For the content our customers (restaurant businesses) process in the app, in particular reviews and the information about their authors contained therein, we act as a processor pursuant to Art. 28 GDPR. In that case the respective customer is the controller, and we have concluded a data processing agreement with them. Data subjects should address their requests primarily to the business concerned; we will of course forward any requests we receive.
2. Data We Collect
- Account data: name, email address, password (stored exclusively as a cryptographic hash), language preference, time of acceptance of the terms of use; if you sign in with Google, additionally your Google identifier and profile picture
- Business data: information about your business as well as team and role assignments
- Connected platforms: subject to your authorisation, the access credentials (OAuth tokens) and identifiers of your Google Business Profile, plus the reviews retrieved from it including the publicly displayed author name, review text and star rating
- Content you provide: e.g. menus, documents, website content and content instructions for reply generation
- Usage and log data: session data (IP address, browser identifier), activity logs within the app and server log data
We do not use any cookies for marketing or tracking purposes in the app. Only technically necessary cookies for login and session security are used.
3. Hosting and Content Delivery Network (Hetzner, Cloudflare)
The SupaPresence app is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers used are located exclusively in data centres in Germany; no transfer to a third country takes place in the context of hosting. Hetzner processes the data solely on our instructions, and we have concluded a data processing agreement pursuant to Art. 28 GDPR with Hetzner. Processing covers all data required to operate the app, in particular the categories listed under section 2 including server log data (IP address, time of access, browser type, resource requested). Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in secure and reliable operation (Art. 6(1)(f) GDPR). Further information is available in Hetzner's privacy policy.
Cloudflare (CDN, DNS and security): Our servers sit behind the network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, acting as a reverse proxy. Every request to the app therefore passes through Cloudflare first. Cloudflare handles name resolution, delivery of static content, TLS encryption, and defence against attacks (including bot and DDoS protection). In doing so, Cloudflare processes IP address, date and time of access, requested URL, volume of data transferred, browser identification, referrer URL, and security-related events. Because Cloudflare terminates the TLS connection, it is technically also able to process the content of requests, including the technically necessary session cookie. Cloudflare may set technically necessary cookies to detect malicious requests. We have concluded a data processing agreement pursuant to Art. 28 GDPR with Cloudflare. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in the availability, performance, and security of the app (Art. 6(1)(f) GDPR).
Transfer to a third country: Cloudflare operates a global network. Requests from Austria are usually served via European locations, but processing outside the EU, in particular in the USA, is possible. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework; the European Commission's standard contractual clauses apply in addition (Art. 46(2)(c) GDPR). Further information is available in Cloudflare's privacy policy.
4. AI Features (OpenAI)
For the AI-powered features of the app we use large language models (LLMs) provided by OpenAI. For users in the European Economic Area, the provider is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. We use these services for the following purposes:
- Generating and improving suggested texts, in particular replies to customer reviews
- Language detection and translation of content within the app
- Analysing the business information you provide in order to adapt the content and tone of the generated texts to your business
- Comparable text-based features within the app
Only the content required for the respective feature is transmitted, in particular the text of the review including the publicly displayed information about its author (e.g. display name, star rating), information about your business, and your own content instructions. Account and payment data are not transmitted to OpenAI.
We use the OpenAI API exclusively, on the basis of a Data Processing Addendum pursuant to Art. 28 GDPR. According to OpenAI, data submitted via the API is not used to train its models and is retained only for a limited period (generally up to 30 days) for abuse and security monitoring, after which it is deleted.
Transfer to a third country: Processing by OpenAI may also take place on servers in the USA. Such transfers are based on the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR), including supplementary safeguards, which form part of the data processing agreement concluded with OpenAI. Please note that despite these safeguards, access by US government authorities cannot be entirely ruled out and the level of data protection in the USA is not equivalent to that in the EU.
No automated decision-making: The AI produces suggestions that are reviewed and approved by a human before publication. Customers may optionally enable automatic publication for positively rated reviews; even in that case, no decision producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR is made.
5. Other Recipients and Service Providers
- Hetzner Online GmbH (Germany) - hosting and operation of the app
- Cloudflare, Inc. (USA) - CDN, DNS, and security/attack mitigation (EU-US Data Privacy Framework)
- OpenAI Ireland Limited (Ireland) - AI/LLM features
- Zoho Corporation B.V. (EU data centres) - delivery of system and notification emails
- Google Ireland Limited - connection to your Google Business Profile. Retrieving reviews and publishing replies involves an exchange of data between the app and Google. Google is responsible for the processing that takes place on its own platform.
We do not sell your data or share it for advertising purposes.
6. Purpose of Processing
- Providing, operating and improving the app
- Registration, login and management of user accounts
- Retrieving, managing and replying to reviews on behalf of our customers
- Generating AI-assisted text suggestions
- Security, abuse prevention and error analysis
- Communicating with you regarding system notifications and support
7. Legal Basis
- Performance of a contract (Art. 6(1)(b) GDPR) for the account, provision and billing of the app
- Legitimate interest (Art. 6(1)(f) GDPR) for security, abuse prevention, error analysis and the efficient handling of customer feedback
- Consent (Art. 6(1)(a) GDPR) where you grant it separately, for example when connecting your Google account
- Legal obligation (Art. 6(1)(c) GDPR), for example for commercial and tax retention requirements
8. Data Storage and Retention
- Account and business data are stored for the duration of the contractual relationship and deleted afterwards, unless statutory retention periods apply
- Reviews and replies are stored for as long as the platform connection exists, at the latest until the end of the contractual relationship
- Server and session logs are stored for up to 30 days
- Content transmitted to OpenAI is deleted there after 30 days at the latest, according to the provider
Where we act as a processor, we delete or return the data in accordance with the instructions of the respective customer.
9. Your Rights
You have the following rights under the GDPR:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing and to data portability
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time with effect for the future
- Right to lodge a complaint with the competent supervisory authority (in Austria: Austrian Data Protection Authority)
To exercise these rights, please contact us at: [email protected]
10. Updates to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be published on this page.