Privacy Policy / Datenschutzerklärung
Last updated: August 2026
1. Controller (Verantwortlicher)
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other data protection legislation is:
[COMPANY_NAME][STREET_ADDRESS]
[POSTAL_CODE] [CITY], [COUNTRY]
Represented by: [GESCHÄFTSFÜHRER_NAME]
Email: [CONTACT_EMAIL]
Phone: [PHONE_NUMBER]
2. Data Protection Officer (Datenschutzbeauftragter)
If you have questions about data protection, please contact our Data Protection Officer:
[DPO_NAME]Email: [DPO_EMAIL]
3. Overview of Data Processing
3.1 Categories of Data We Process
- Account data: Name, email address, organization name, password (hashed)
- Contact/CRM data: Contact names, email addresses, company information, job titles — imported or entered by you for your outreach campaigns
- Email content: Templates, email bodies, subjects you compose in the platform
- Mailbox connection data: OAuth tokens (encrypted at rest with AES-256-GCM), email provider metadata
- Usage data: Campaign analytics, open/click tracking data, login timestamps
- Technical data: IP address, browser type, device information (collected automatically via server logs)
3.2 Purposes of Processing
- Providing and operating the OSENBOLT platform (Art. 6(1)(b) GDPR — contract performance)
- User authentication and account security (Art. 6(1)(b) GDPR)
- Sending emails on behalf of our users via connected mailboxes (Art. 6(1)(b) GDPR)
- Campaign analytics and performance reporting (Art. 6(1)(f) GDPR — legitimate interest)
- Preventing abuse, fraud detection, and platform security (Art. 6(1)(f) GDPR)
- Legal compliance and responding to lawful requests (Art. 6(1)(c) GDPR)
4. Legal Basis for Processing (Art. 6 GDPR)
| Processing Activity | Legal Basis |
|---|---|
| Account registration & authentication | Art. 6(1)(b) — Performance of contract |
| Sending campaign emails on your behalf | Art. 6(1)(b) — Performance of contract |
| Email open/click tracking | Art. 6(1)(f) — Legitimate interest (campaign performance analytics) |
| Security measures (rate limiting, logging) | Art. 6(1)(f) — Legitimate interest (platform security) |
| Cookie-based session management | Art. 6(1)(b) — Necessary for service provision |
| Processing payment information | Art. 6(1)(b) — Performance of contract |
5. Data Recipients & Sub-processors
We use the following third-party service providers (sub-processors) to operate OSENBOLT:
| Provider | Purpose | Data Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | [DATA_REGION — e.g., EU (Frankfurt) / US East] |
| Vercel Inc. | Application hosting, serverless functions | [VERCEL_REGION — e.g., US East (iad1)] |
| Google LLC (Gmail API) | Email sending on behalf of users who connect Gmail | USA (Standard Contractual Clauses apply) |
| Microsoft Corp. (Graph API) | Email sending on behalf of users who connect Outlook | USA/EU (Standard Contractual Clauses apply) |
| [ADDITIONAL_PROCESSOR] | [PURPOSE] | [LOCATION] |
All sub-processors are bound by Data Processing Agreements (Auftragsverarbeitungsverträge, Art. 28 GDPR). For transfers to the USA, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, and/or the EU-US Data Privacy Framework where applicable.
6. International Data Transfers
Some of our sub-processors are located in the United States or other countries outside the European Economic Area (EEA). We ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR
- EU-US Data Privacy Framework certification (where applicable)
- Technical measures including encryption in transit (TLS 1.3) and at rest (AES-256)
7. Data Retention
- Account data: Retained for the duration of your active account. Deleted within 30 days of account closure, unless legal retention periods apply.
- Campaign & email data: Retained for 12 months after campaign completion. You may request earlier deletion.
- Contact/CRM data: Retained until you delete it or close your account.
- Server logs (IP, access): Automatically deleted after 90 days.
- OAuth tokens: Deleted immediately when a mailbox is disconnected.
German commercial and tax law (HGB, AO) may require retention of certain business records for 6-10 years. In such cases, data is restricted from further processing and deleted after the statutory period expires.
8. Your Rights (Betroffenenrechte)
Under the GDPR, you have the following rights:
- Right of access (Art. 15): Obtain confirmation of whether we process your personal data and request a copy.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data ("right to be forgotten").
- Right to restriction (Art. 18): Request limitation of processing.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)): Withdraw consent at any time without affecting prior lawfulness.
- Right to lodge a complaint (Art. 77): File a complaint with a supervisory authority.
To exercise your rights, contact us at [CONTACT_EMAIL]. We will respond within 30 days as required by Art. 12(3) GDPR.
9. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for our company is:
[SUPERVISORY_AUTHORITY_NAME][SUPERVISORY_AUTHORITY_ADDRESS]
Website: [SUPERVISORY_AUTHORITY_URL]
For companies registered in Germany, the relevant authority depends on the Bundesland. For example, for North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW.
10. Cookies & Tracking Technologies
10.1 Essential Cookies
We use strictly necessary cookies for authentication session management. These cookies are required for the platform to function and cannot be disabled. Legal basis: Art. 6(1)(b) GDPR, § 25(2) TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz).
| Cookie Name | Purpose | Duration |
|---|---|---|
| sb-*-auth-token | Supabase authentication session | Session / 7 days |
10.2 Email Open/Click Tracking
When you send campaigns through OSENBOLT, emails may contain a tracking pixel (1×1 transparent image) and redirected links to measure open and click rates. This tracking applies only to the recipients of campaigns you send — not to your own usage of the OSENBOLT platform.
As the sender of these campaigns, you are the data controller for your recipients' data. You are responsible for ensuring a valid legal basis (e.g., legitimate interest under Art. 6(1)(f) GDPR for B2B cold outreach, or consent where required).
11. Technical & Organizational Security Measures
- All data transmitted via TLS 1.2+ encryption
- OAuth tokens and credentials encrypted at rest using AES-256-GCM
- Row-Level Security (RLS) enforced at the database level — users can only access their own organization's data
- Rate limiting on authentication and API endpoints to prevent brute-force attacks
- Automatic session expiry after 15 minutes of inactivity
- Service-role keys isolated to server-side code only — never exposed to browsers
- Regular security updates and dependency audits
12. Data Processing Agreement (Auftragsverarbeitung)
When you use OSENBOLT to manage contacts and send campaigns, we act as a data processor (Auftragsverarbeiter) on your behalf under Art. 28 GDPR. You remain the data controller for the personal data of your contacts.
A Data Processing Agreement (DPA/AVV) is available upon request at [CONTACT_EMAIL]. Our DPA covers:
- Subject matter and duration of processing
- Nature and purpose of processing
- Categories of data subjects and personal data
- Obligations of the processor (confidentiality, security, sub-processor management)
- Assistance with data subject requests
- Audit rights
- Data return and deletion upon termination
13. B2B Cold Outreach & Anti-Spam Compliance
OSENBOLT is designed for B2B sales outreach. As a user, you are responsible for ensuring your campaigns comply with applicable laws including:
- GDPR (EU): Legitimate interest (Art. 6(1)(f)) may serve as a legal basis for B2B contact where the outreach is relevant to the recipient's professional role.
- UWG (Germany): § 7 UWG requires that commercial email to businesses is permissible if there is a presumed interest. Unsolicited email to individuals (B2C) generally requires prior consent.
- CAN-SPAM (USA): All emails must include a valid physical postal address and an unsubscribe mechanism.
- CASL (Canada): Express or implied consent is required for commercial electronic messages.
OSENBOLT includes built-in compliance features:
- Automatic
List-Unsubscribeheader on all campaign emails - Bounce detection and automatic contact invalidation
- Daily sending limits to prevent spam behavior
- Sending window restrictions to respect business hours
14. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in our data practices or legal requirements. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top indicates the most recent revision.
15. Contact
For privacy-related inquiries, data subject requests, or to request our DPA:
Email: [CONTACT_EMAIL]Postal: [COMPANY_NAME], [STREET_ADDRESS], [POSTAL_CODE] [CITY]
