Privacy Policy / Datenschutzerklärung

Last updated: 2026-08-30 — applies to the marketing site at findig.app. The application at dashboard.findig.app has its own, more detailed privacy policy.

1. Controller / Verantwortlicher

Johannes Tebbert
Auwaldstraße 7
79110 Freiburg im Breisgau
Germany
E-Mail: [email protected]

No Data Protection Officer (DPO) is required or appointed (§38 BDSG — threshold of 20 persons not reached).

2. Scope

This policy covers data processing on the public marketing site findig.app. Account-related processing inside the Findig application (at dashboard.findig.app) is governed by the application's own privacy policy, presented at registration.

3. Data Processed on This Site

3.1 Server logs

Data: IP address, timestamp, requested URL, HTTP referrer, user-agent string.

Purpose: Operating and securing the site (rate limiting, abuse prevention).

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in keeping the site available and secure.

Retention: Up to 14 days, then deleted.

3.2 Contact form

Data: Name, e-mail address, subject, message — only what you submit. We additionally store the timestamp of submission and the IP address from which it was sent (the latter solely for abuse prevention).

Purpose: Replying to your inquiry.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual) or Art. 6(1)(f) GDPR (legitimate interest in answering your question).

Storage: Submissions are stored in an encrypted-at-rest local database, accessible only to the controller. They are not synced to any third-party CRM or analytics provider.

Retention: Submissions are automatically deleted 180 days (≈ 6 months) after they were received, unless statutory retention obligations apply or you have explicitly asked us to keep the conversation open longer. You may request earlier erasure at any time — see section 6.

Sharing: Submissions trigger an e-mail to the controller above. No third-party processors beyond the e-mail provider listed in section 4.

3.3 Analytics (Cloudflare Web Analytics, if enabled)

Data: Aggregated, anonymous page-view counts. No cookies, no fingerprinting, no IP storage. Cloudflare Web Analytics is privacy-friendly and does not require consent under GDPR/TTDSG, since it stores no information on your device.

Purpose: Understanding which pages are visited.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding aggregate site usage.

3.4 Page-engagement measurement (first-party, no cookies)

Data: When you leave a page, your browser sends us four things: the page address, how many seconds the page was visible on your screen, how far down the page you scrolled (as a percentage), and where you arrived from — one of our own page addresses if you clicked a link on our site, otherwise only the bare domain name of the site that sent you (e.g. google.com), never the full address or any search terms. Nothing else — no cookie, no browser storage, no IP address, no device fingerprint, and no identifier that survives the page you were on. These measurements cannot be linked to you, to each other, or to any visit before or after.

Purpose: Finding out which pages people actually read and which ones they leave immediately, so we can fix the bad ones.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in knowing whether our own pages are useful. §25 TDDDG (consent for accessing your device) does not apply, because nothing is read from or written to your device.

Storage: On our own server in Germany. Not shared with anyone, and never sent to a third party. Automatically deleted after 90 days.

3.5 Visit journeys — only if you accept (first-party)

Data: If — and only if — you click "Accept" in the cookie banner, your browser additionally stores a random ID for the current browser tab and sends it with the measurements described in 3.4. That lets us see that one visit went, say, from the homepage to the fee calculator to the about page, instead of three unconnected page views. The ID is a random string with no meaning: it contains nothing about you or your device, is not linked to your name, e-mail or account, is never sent to any third party, and a new one is generated for every new visit.

Purpose: Understanding how people move through the site — which page leads people onward and which one is a dead end.

Legal basis: Art. 6(1)(a) GDPR and §25(1) TDDDG — your consent. If you click "Decline", or simply do not answer, no ID is stored and no ID is sent; you are still measured under 3.4, anonymously, like everyone else.

Withdrawal: The ID is deleted from your browser as soon as your consent is not "accepted" — that includes closing the tab, which ends the visit and the ID with it.

Storage: On our own server in Germany. The ID is stripped from our records after 30 days, after which those records are the anonymous ones described in 3.4 and are deleted at 90 days like the rest.

4. Processors

5. Cookies

Strictly necessary cookies may be set for security (e.g. Cloudflare's __cf_bm bot-management cookie). These do not require consent under §25 TDDDG.

Marketing cookies — only with your consent. If you click "Accept" in the cookie banner, we set two first-party cookies on .findig.app (so they are also readable on dashboard.findig.app) and load the Google Ads tag:

Browser storage — also only with your consent. After you accept, we keep one entry in your browser's session storage (not a cookie, and gone when you close the tab):

Google Ads: after consent we load gtag.js from Google (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) to measure ad conversions. This transfers your IP address and browser data to Google and may involve a transfer to the USA under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(a) GDPR / §25(1) TDDDG — your consent. If you click "Decline", nothing from Google is loaded at all.

Withdrawing consent: delete the findig_consent cookie in your browser (site settings → cookies) and the banner will ask again. Withdrawal has no effect on processing that already took place.

6. Your Rights (Art. 15–22 GDPR)

To exercise any of these, e-mail the controller at the address in section 1 from (or referencing) the e-mail address you used in the contact form, so we can identify the record. Erasure requests are actioned within 30 days, typically within one business day. You will receive written confirmation once your data has been deleted.

You also have the right to lodge a complaint with a supervisory authority — for Baden-Württemberg this is the LfDI Baden-Württemberg.

7. International Transfers

The site is hosted in Germany. Cloudflare may route traffic via servers outside the EU; standard contractual clauses (SCC) are in place for any such transfers.

If you accept marketing cookies, the Google Ads tag transfers data to Google, which may process it in the USA. Google is certified under the EU-US Data Privacy Framework, and standard contractual clauses apply in addition. This transfer happens on the basis of your consent (Art. 49(1)(a) GDPR) and stops as soon as you withdraw it — see section 5.

8. Changes

We may update this policy from time to time. Material changes are announced on this page with an updated "Last updated" date.

← Back to home