Legal · Privacy
Privacy policy
How Transparion processes personal data when you visit the website, contact us, use analyses or an account, make payments or use optional product features.
This version reflects the features and data processing technically reviewed on September 1, 2026. Its version is recorded when an account is created; optional browser preferences are used only with consent. Before final legal approval, the authority to represent the company and the privacy contact, any appointment of a data protection officer, the Supabase project region, production providers and subprocessors, specific transfer safeguards, roles in the agency widget and the binding deletion and backup plan must be confirmed.
01
Controller
The controller within the meaning of the General Data Protection Regulation and other applicable data-protection laws is:
- Provider
- Tridots UG (haftungsbeschränkt)
- Brand
- Transparion
- Address
- Rothenbaumchaussee 31, 20148 Hamburg
- Represented by
- Michael Trippel and Lino Krumrey
- [email protected]
02
Website, hosting and server logs
When you access the website and its programming interfaces, the systems involved process, in particular, your IP address, time of access, requested address, referrer, browser and device details, volume of data transferred, and status, error and security data. The website cannot be delivered without this connection data.
The public website is delivered through Cloudflare and Vercel; the application API runs on Fly.io. These providers may process connection and security logs. The purposes are delivery, stability, error analysis, prevention of abusive access and enforcement of usage limits. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the service.
Where this involves storing or accessing information on a device, strictly necessary functions are based on Section 25(2)(2) TDDDG. The production log retention periods of the individual hosting providers and their contractual configuration still need to be formally documented before legal approval.
03
Contact form and support
When you write to us through the contact form, we process your name, email address, enquiry and message and, if voluntarily provided, your company and website. We also process the request and connection data necessary to limit abuse.
The information is sent via Resend to the contact mailbox used by Transparion. It is processed to handle pre-contractual or contractual enquiries on the basis of Article 6(1)(b) GDPR. General enquiries are processed on the basis of Article 6(1)(f) GDPR; our interest is orderly and secure communication.
Name, email address, subject and message are required fields. We cannot answer the enquiry without them. Company and website are optional.
04
Account, sign-in and recovery
During registration and account use, we process the organisation name, email address, a password stored as a hash, role and permissions, language, website where provided, creation and email verification times, and the version and time of acknowledgement of this privacy policy. Processing is necessary to set up, secure and use the account and is based on Article 6(1)(b) GDPR.
We send single-use links through Resend for email verification and password recovery. Verification links are valid for 24 hours and password reset links for 30 minutes. To prevent abuse, we also process request and security data on the basis of Article 6(1)(f) GDPR.
After successful sign-in, an authentication token is stored in Local Storage. In the default configuration, it expires after seven days and is removed at sign-out. The browser remembers the email address of a password reset in progress only for the current session.
05
Transparion Insight
For the requested free analysis, we process your business email address, domain, language, an optional content or blog URL, IP address, request time and, separately from the analysis request, an optional marketing choice. We also process publicly available content from the specified website and the prompts, AI answers, sources, mentions, assessments, scores and recommendations generated from it.
Processing is necessary to create, provide and deliver the requested analysis by email and is based on Article 6(1)(b) GDPR. Usage limits, abuse prevention and a pseudonymised security identifier are additionally based on Article 6(1)(f) GDPR. The plain-text email address is not transmitted as AI input.
The email and IP addresses in the temporary contact snapshot are automatically deleted or redacted from the result after 30 days. The analysed domain and substantive analysis results may remain without these contact details. The result is accessible through an unguessable link; anyone with the link can open it and should therefore treat it as confidential.
- Required: business email address and domain
- Optional: content or blog URL and marketing choice
- Technical data: IP address, request time and security identifier
- Result data: prompts, AI answers, sources, companies, scores, sentiment and recommendations
06
Transparion Pro Scan and technical website analysis
For a Pro Scan, we process account and contact data, delivery email address, IP address, the analysed domain, target market and region, category and specialisation, custom prompts, up to four competitor URLs and additional content URLs, scan configuration, recurring scheduling, order and payment status, provider usage and token information, and all generated results and reports. The legal basis is Article 6(1)(b) GDPR; the IP address also supports secure operation on the basis of Article 6(1)(f) GDPR.
When technical website analysis is enabled, our crawler retrieves, in particular, robots.txt, sitemaps and selected pages of the specified website. It processes addresses, HTTP status and headers, titles, metadata, headings, links, content structure and technical response measurements. Google PageSpeed Insights or CrUX measurements are also requested if configured in production.
Pro Scan analyses are generated using OpenAI, Anthropic Claude and Google Gemini. Depending on the analysis, stored data includes prompts, answers, search and citation sources, rankings, visibility, citation share, sentiment, competitor data, content assessments, recommendations, environment labels and report files. Recurring scans also store the schedule and last execution.
The configurator stores a draft in Session Storage during the browser session and, for signed-in users, also in the account. The most recently used domain is stored locally only with preference consent.
07
AI services and publicly accessible sources
Analyses are based on the domains, URLs, prompts and contextual information you provide, as well as publicly accessible websites and search results. In exceptional cases, these may contain names, business contact details or statements about identifiable employees and sole traders. Sources include the specified website, linked publicly accessible pages and web sources found by AI systems or search services.
Where publicly collected content contains personal data, we process it for the requested market, source and visibility analysis on the basis of Article 6(1)(b) GDPR in relation to the client and, additionally, Article 6(1)(f) GDPR. Our legitimate interest is analysing publicly presented business content. Data subjects can object to processing and request a review or removal.
In source and visibility features accessible exclusively to administrators, we also process publicly discoverable company names, domains, categories, prompt and citation pages, and summaries and rankings derived from them. The purposes are product quality and business market research on the basis of Article 6(1)(f) GDPR. Ordinary customer accounts cannot access this administrative dataset.
OpenAI is used for Insight, Pro Scan and content features; Anthropic Claude and Google Gemini are additionally used for Pro Scans. Prompts, publicly available website content, search context, result data and pseudonymised security or order identifiers may be transmitted to these providers. Users should not enter special categories of personal data, confidential personnel data or unnecessary personal information into free-text fields.
Transparion does not use this data to train its own general-purpose AI model. Whether and how individual providers may use data for their own purposes depends on the production API or enterprise settings and the contracts in place; this configuration must be documented for each provider before legal approval.
08
Agency widgets
Agencies can offer an embedded Transparion analysis under their own name. In this process, we handle email address, domain, IP and request context, widget and agency identifiers, referring page or approved embedding domain, analysis result, and the times of result views and booking-link clicks. Cloudflare Turnstile may be used for bot protection.
Each agency can access the scans assigned to it and can see, in particular, email address, domain, status and usage events. The agency named in the widget is generally responsible for its own sales and marketing purposes. Where Transparion provides the analysis solely on the agency’s instructions, processing on behalf of the agency is intended; the specific allocation of roles must be confirmed in the agency agreement and before legal approval.
To configure and display a widget, Transparion also processes the agency name, branding colours, support email, booking and privacy notice URLs, approved embedding domains and an optionally uploaded agency logo. The logo is stored in a publicly accessible Supabase storage area. No automatic deletion period is currently configured for branding and logos. For optional colour detection, the server may load publicly available HTML and CSS from the specified agency website.
An optional marketing choice in an agency widget applies exclusively to the agency named there. It is initially stored as pending and confirmed by opening the signed result link once the agency result has loaded successfully. It does not automatically apply to Transparion or other agencies.
09
Orders and payments
For paid services, we process order data, email address, product and scan configuration, price, currency, payment and order status, and Stripe customer, checkout, payment intent and event identifiers. The legal basis is Article 6(1)(b) GDPR. Legally required accounting and tax data is additionally processed under Article 6(1)(c) GDPR; fraud and error checks are based on Article 6(1)(f) GDPR.
Payment details are entered on pages provided by Stripe. Transparion does not receive complete credit card details. Stripe’s own cookie and privacy notices also apply when you move to Stripe.
10
Information and marketing emails
Marketing emails are sent only on the basis of voluntary consent under Article 6(1)(a) GDPR in conjunction with Section 7 UWG or another applicable statutory permission. The choice is not a prerequisite for Insight, Pro Scan or an account.
In the direct Transparion Insight form, actively selected marketing consent is stored immediately for Transparion; no additional confirmation email is sent there. The agency widget instead uses the confirmation procedure through the signed result link described in the previous section. Contacts are kept separate and deduplicated per email address and controller.
We store the email address, responsible company, source, status, wording and version of consent, and the times of request, confirmation, withdrawal and last use. Consent can be withdrawn at any time with future effect through the unsubscribe link or privacy contact. The lawfulness of processing before withdrawal is unaffected. You may object to direct marketing at any time without giving a specific reason.
11
Optional Advisory and traffic features
Where the Advisory workspace is enabled for an account, we process the entered brand voice, target audience, calls to action, approved facts and sources, statements to avoid, links, and generated and edited content drafts. Processing serves the requested content assistance and is based on Article 6(1)(b) GDPR; OpenAI is used for generation.
If a user voluntarily connects Google Analytics 4 or Google Search Console, we process encrypted OAuth refresh tokens, granted permissions, property and site identifiers, synchronisation logs and daily aggregated metrics such as sessions, users, page views, key events, organic traffic, clicks, impressions, click-through rate and position. The purpose is the traffic analysis requested by the user. The connection can be disconnected; the token must then no longer be used for new requests.
These features are still publicly marked as “coming soon”, but may be enabled for eligible test or customer accounts. This processing does not occur without enablement or an active Google connection.
13
Recipients and service providers
Only employees and commissioned service providers have access, to the extent necessary for the respective purpose. Where a provider acts as a processor, an agreement under Article 28 GDPR is required; all production contractual arrangements must be confirmed before legal approval. Individual providers, especially payment and optional content services, may also act as independent controllers for their separate purposes.
- Cloudflare, Vercel and Fly.io
- Delivery, hosting, API operation and security
- Supabase
- Database, authentication and storage infrastructure
- OpenAI
- Insight, Pro Scan analysis and content generation
- Anthropic and Google
- Claude and Gemini analysis in Pro Scan; optional PageSpeed, OAuth, Analytics and Search Console
- Resend
- Analysis, account, payment and contact emails
- Stripe
- Checkout, payment and fraud prevention
- Brandfetch and Logo.dev
- Optional or export-related company logos
- Agency partners
- Access to scans assigned to their widget according to the contractual allocation of roles
14
Processing outside the EEA
Some of the providers named above or their subprocessors are based in the USA or can access data from there. Under Articles 44 et seq. GDPR, such a transfer is permissible only on a valid transfer basis. Depending on the specific recipient, this may be an adequacy decision under Article 45 GDPR — for the USA, the EU-US Data Privacy Framework only for currently certified recipients — or the European Commission’s standard contractual clauses under Article 46 GDPR together with any required supplementary measures.
The transfer basis, subprocessor list and storage region applicable to each entity used in production will be documented from the contracts before legal approval. A copy or further information about the relevant safeguards can be requested via [email protected]; trade secrets and security information may be redacted.
15
Retention and deletion
Personal data is deleted or anonymised when its purpose no longer applies and no statutory retention, evidence, security or limitation periods prevent this. A fully binding deletion and backup plan covering all providers and all data groups listed below has not yet been implemented; this gap must be closed before legal approval.
For Insight, email and IP data in the temporary contact snapshot is automatically cleared after 30 days. The substantive results and domain currently have no separate automatic end date. Verification links expire after 24 hours, password reset links after 30 minutes and the default account session after seven days. Consent settings are renewed after 180 days; session data in the browser generally ends with the browser session.
Requests processed through the background queue may contain the order data required for Insight, Pro Scan or a PDF export. Successful queue entries are retained for 24 hours and technically deleted after no more than seven days. Stored PDF reports, however, do not yet have an automatic end date.
Account, Pro Scan, Advisory, widget and substantive result data is currently retained until deletion by the user, contract termination or a justified deletion request, unless a retention obligation prevents deletion. Deleting a Pro Scan in the account initially hides it through a deletion marker; final physical removal, including backups, still needs to be formally defined.
Marketing contacts remain active until consent is withdrawn or an objection is made. After that, only suppression and event data necessary to honour the withdrawal and provide evidence is retained for the applicable evidence and limitation periods. Contact enquiries are stored until handling is complete and afterwards only where necessary for contractual or statutory reasons or the defence of legal claims. Accounting records are generally subject to an eight-year retention period; other commercial or tax documents are subject to six- or ten-year periods depending on their type.
16
Required information and consequences of not providing it
Insight requires a domain and business email address; analysis and delivery cannot be provided without them. An account requires an organisation name, email address, password and acknowledgement of the current privacy policy. A Pro Scan requires the order, target and prompt information marked as required in the configurator and, for payment, the order details required by Stripe.
Optional information is identifiable as such, in particular additional content or competitor URLs, convenience preferences, marketing choices and optional Google connections. Not providing it prevents only the respective additional feature and has no disadvantages for other services.
17
Automated analyses
Transparion automatically generates visibility, source, sentiment and competitor metrics, as well as rankings, recommendations and content drafts. This combines, in particular, user-selected prompts, answers from the AI systems used, mentions of the analysed company and its competitors, visible or documented sources, and linguistic assessments. Results are information and working aids; they may be incomplete or incorrect and should be reviewed by a qualified person.
These analyses do not make decisions producing legal or similarly significant effects on a natural person within the meaning of Article 22 GDPR. Users decide on business actions themselves.
18
Your rights and right to lodge a complaint
Subject to the statutory requirements, data subjects have, in particular, rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on Article 6(1)(f) GDPR, an objection may be made on grounds relating to the person’s particular situation. Direct marketing may be objected to at any time without giving a specific reason.
Consent may be withdrawn at any time with future effect. This does not affect the lawfulness of processing before withdrawal. Requests can be sent to [email protected] or by post to the address stated above.
You may also lodge a complaint with a data protection supervisory authority, particularly where you live or work or where the controller is based. The Hamburg Commissioner for Data Protection and Freedom of Information is generally responsible for the company’s Hamburg registered office.
- Privacy contact
- [email protected]
- Supervisory authority
- Hamburg Commissioner for Data Protection and Freedom of Information
- Address
- Ludwig-Erhard-Straße 22, 20459 Hamburg
- [email protected]
19
Security and changes
Transparion implements appropriate technical and organisational measures. These include encrypted transmission, role-based access restrictions, hashed passwords, time-limited single-use links, protection against automated attacks and separation of public and authenticated features.
This privacy policy is updated when features, providers, data flows or legal requirements change materially. At registration, the account records the version and time of acknowledgement. AI features may additionally require notices directly at the relevant feature; this policy does not replace such contextual notices.
