Privacy Policy

Last updated: January 2025

This Privacy Policy complies with the General Data Protection Regulation (GDPR) and German data protection laws.

1. Responsible Entity (Controller)

Karsten Schwarzkopf
Brodauer Weg 33
04129 Leipzig, Germany
Email: egohead.deluxe+exposecompare@gmail.com

2. Data Processing Purposes

We process your personal data for the following purposes:

Beta Registration

Collection of email addresses for early access and product updates

PDF Analysis

Upload and AI-powered analysis of real estate PDF files

Technical Operations

Hosting, error logging, and system analytics for service improvement

User Analytics

Understanding user behavior to optimize the application

3. Legal Bases (GDPR Articles)

We process your data based on the following legal grounds under the GDPR:

Art. 6(1)(b) – Performance of Contract

Processing necessary for using ExposéCompare's core functionality and services

Art. 6(1)(f) – Legitimate Interest

Improving system stability, security, and user experience through analytics

Art. 6(1)(a) – Consent

Marketing communications, newsletter, and optional cookie tracking

4. Third-Party Processors

We work with the following trusted service providers to deliver our services:

OpenAI (via API)

AI-powered PDF analysis and data extraction

Data processing location: EU data centers only

Vercel (v0.dev Infrastructure)

Application hosting and deployment platform

Includes subprocessors: Vercel, potential database providers

Email Service Provider

Delivery of transactional and marketing emails

GDPR-compliant EU-based email services only

Analytics Tools

Privacy-focused analytics (e.g., Plausible, PostHog)

Only activated with explicit user consent

5. Data Retention

We retain your data only as long as necessary for the specified purposes:

Data TypeRetention PeriodPurpose
Email addressesMax. 3 years from last activityBeta access and updates
Uploaded PDF filesDeleted after processingAnalysis only, no permanent storage
System logsMax. 30-90 daysError tracking and security
Billing data10 years (if applicable)Legal requirements for invoicing

6. Your Rights (Data Subject Rights)

Under the GDPR, you have the following rights regarding your personal data:

Right of Access (Art. 15)

Request information about your stored data

Right of Rectification (Art. 16)

Correct inaccurate personal data

Right of Erasure (Art. 17)

Request deletion of your data

Right of Restriction (Art. 18)

Limit processing of your data

Right of Portability (Art. 20)

Receive your data in a structured format

Right to Object (Art. 21)

Object to processing based on legitimate interest

Withdraw Consent (Art. 7(3))

Revoke consent for marketing/analytics

Right to Complain

Lodge complaint with Saxony DPA

To exercise your rights: Contact us at egohead.deluxe+exposecompare@gmail.com with your request and proof of identity.

7. Cookies & Consent

We use cookies and similar technologies in compliance with GDPR requirements:

✓ Essential Cookies

Required for basic functionality - no consent needed

⚠ Analytics & Marketing Cookies

Require explicit opt-in consent via cookie banner

🔧 Cookie Management

You can withdraw consent and manage cookie preferences at any time

8. International Data Transfers

We ensure all data transfers comply with GDPR requirements:

OpenAI and other processors use EU data centers exclusively

EU Standard Contractual Clauses (SCC) implemented where applicable

No data transfers to countries without adequate protection level

9. Security Measures (TOMs)

We implement appropriate technical and organizational measures to protect your data:

HTTPS encryption for all connections
Strict access controls and authentication
Regular security updates and monitoring
Data pseudonymization where applicable

10. Contact & Complaints

Data Protection Contact

For privacy-related questions or to exercise your rights:

egohead.deluxe+exposecompare@gmail.com

Supervisory Authority

You can lodge a complaint with:

Saxon Data Protection Authority
Devrientstraße 5
01067 Dresden, Germany

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date at the top. For significant changes, we may also send you a direct notification.

This Privacy Policy is effective as of January 2025.

This policy has been designed to comply with GDPR and German data protection laws. For questions about compliance or to report privacy concerns, please contact us using the information above.