Privacy Policy

This policy describes the processing of personal data when operating the Offervity web application.

1. Controller

The controller under the GDPR is Jonas Scheffner, provider of Offervity. Full provider details and contact options are set out in the legal notice.

For data about your own customers that you enter into Offervity, we act on your documented instructions as a processor (Art. 28 GDPR); you are the controller for that data.

2. Contact

For privacy questions and to exercise your rights, contact contact@offervity.com. We are currently not legally required to appoint a data protection officer.

3. Hosting and provision of Offervity

Offervity is provided as a web application on cloud infrastructure (application hosting plus managed database, authentication and server-function services from our platform provider). Technically necessary connection data is processed when the application is accessed (see section 10). All traffic is encrypted via TLS. These providers act as processors for us.

4. Registration and user account

An account is required. We process your email address, a cryptographic password hash (never the plaintext password), registration and sign-in timestamps and session data. Passwords are additionally checked against known breaches; only an anonymised prefix of the password hash is sent to the “Have I Been Pwned” service – the password itself never leaves the application.

5. Company, customer, inquiry and quote data

We process the company data you enter (company name, address, contact details, logo, pricing rules) and content data: customer records, inquiries, quotes and line items, leads and follow-ups. This data is stored with tenant separation and is restricted to your company account through row level security.

Entering the names of your end customers is optional; you may use initials instead for data minimisation.

6. AI analysis

To analyse inquiries and draft texts, we send the inquiry text and relevant quote and company parameters via the Lovable AI Gateway to a language model (currently Google Gemini). This only happens when you explicitly start an analysis. Please do not enter special categories of personal data (Art. 9 GDPR). Results are suggestions and must be reviewed by you before commercial use.

7. Quote and PDF generation

Quote PDFs are generated directly in your browser. Quote content is not transmitted to an additional external service for this purpose; the quote data itself is stored in your tenant’s database.

8. Payments and subscriptions via Paddle

Paid subscriptions are processed by Paddle.com Market Ltd. Paddle is the Merchant of Record and an independent controller for payment processing, invoicing, tax determination and fraud prevention. The checkout is loaded as a Paddle overlay; Paddle processes the data you enter there as well as technical connection data. We do not receive payment instrument data.

Via webhooks we receive billing status data from Paddle (subscription status, plan, period end, subscription and customer identifiers) which we map to your account to unlock the purchased feature set. Paddle’s own privacy policy applies in addition.

9. Authentication and application emails

We send transactional emails (sign-up confirmation, password reset, security notices) through the email delivery of our platform/authentication provider. We process the email address, send time and delivery status. We do not send marketing newsletters.

10. Server and security logs

Operating the service generates technical log data: IP address, timestamp, requested function or URL, status codes, error messages and browser/device information. It is used for secure and stable operation, troubleshooting and abuse and fraud prevention.

11. Cookies, local storage and technically necessary storage

We only use technically necessary storage: the sign-in session (token in your browser’s local storage), security-related values and short-lived status information about subscription activation after a payment. The Paddle checkout may set additional strictly necessary cookies. We do not use tracking, analytics or marketing cookies, so consent under § 25 (1) TDDDG is not required (§ 25 (2) no. 2 TDDDG). You can clear browser storage; sign-in may then no longer work.

12. Purposes and legal bases

  • Account, company data, content and quote data, AI analysis, PDF generation: performance of contract, Art. 6(1)(b) GDPR.
  • Billing and subscription management: Art. 6(1)(b) GDPR; tax and commercial law obligations: Art. 6(1)(c) GDPR.
  • Transactional emails: Art. 6(1)(b) GDPR.
  • Logs, security, abuse and fraud prevention, troubleshooting: legitimate interests, Art. 6(1)(f) GDPR.
  • Support communication: Art. 6(1)(b) or (f) GDPR.

Providing account and company data is required to use the service; without it the contract cannot be performed.

13. Recipients and categories of recipients

  • Platform/hosting provider for application operation, database, authentication, server functions and email delivery (processor).
  • Lovable AI Gateway and the connected Google Gemini model for AI analysis (processing).
  • Paddle.com Market Ltd. as Merchant of Record and payment processor (independent controller).
  • “Have I Been Pwned” for anonymised password checks (hash prefix only).
  • Tax and legal advisors as well as authorities and courts where legally required.

We do not share data with third parties for advertising purposes.

14. Transfers to third countries

Some of the providers named above – in particular the AI and payment providers – may process data outside the EU/EEA. Such transfers rely on an EU Commission adequacy decision or the EU standard contractual clauses together with supplementary measures. We will provide information about the processing regions actually used and the applicable safeguards on request at contact@offervity.com.

15. Retention and erasure

  • Account, company and content data: for the duration of the contract; you can delete it in the application at any time.
  • After account deletion the associated data in the application database is deleted immediately; it may persist in infrastructure backups until the end of the backup cycle operated by the infrastructure provider and is overwritten automatically thereafter.
  • Log and error data: only as long as required for operation and security; in case of security incidents until resolved.
  • Invoice and tax-relevant records: statutory retention periods under § 147 AO and § 257 HGB (generally 10 or 6 years); these records are largely kept by Paddle as Merchant of Record.
  • Support communication: until the matter is resolved and beyond where record-keeping duties apply.

After these periods data is deleted or anonymised.

16. Rights of data subjects

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). Consent given can be withdrawn at any time with effect for the future. Please send requests to contact@offervity.com.

17. Right to lodge a complaint

Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement.

18. Changes to this privacy policy

We update this policy when the application, the providers used or the legal situation change. The version published on this page applies.