Legal

Privacy Policy

Version 2.2 · as of 4 September 2026. The German version is legally binding; this English translation is for convenience. For commissioned processing the DPA under Art. 28 GDPR (Annex A) applies; for AI functions the AI Usage Terms — BETA (Annex C).

1. Controller

HEINI Operations UG (haftungsbeschränkt), Wierling 19, 48301 Nottuln, Germany, Managing Director: Daniel Heinen. General email: hallo@heini.app · Privacy: datenschutz@heini.app.

Where HEINI processes data on a customer’s behalf within the contractually agreed SaaS platform, the respective customer is the controller and HEINI the processor (Art. 28 GDPR, Annex A). This policy covers the processing for which HEINI is itself the controller (website including prospect SUSI and scheduling, contract handling, billing).

2. Hosting and server location

The standard processing location for website, storage and backup is the Hetzner Online GmbH data centre in Falkenstein (FSN1), Germany — an isolated stack per customer (single-tenant). Hetzner is ISO 27001:2022 certified.

A deviating hosting region is agreed exclusively at the express request of an Enterprise customer in the individual contract (DPA no. 7.2); without such agreement all processing remains in Falkenstein/Germany.

Website hosting and self-hosted analytics are separate from the optional SUSI and Calendly services. Activating or directly opening Calendly in particular transfers data to a US provider; see the separate sections below. For use of the heini.app SaaS platform (especially AI inference) separate sub-processors based in the EU may be engaged whose parent companies may be located in third countries; this is listed in DPA no. 7.

3. Processing in detail

3.1 Website visit. Purpose: provision, security, stability. Data: IP address, time, user agent, referrer, requested URL. Legal basis: Art. 6(1)(f) GDPR. Storage: 14 days (security logs). Recipient: Hetzner (Falkenstein/DE, DPA).

3.2 Cookies (§ 25 TDDDG). Strictly necessary cookies (login session, CSRF protection, language) without consent (§ 25(2) no. 2 TDDDG). Functional/statistical/marketing cookies only after active consent; revocable any time. Web analytics via Umami (cookieless, self-hosted, no persistent identifiers, no third-country transfer).

3.3 Account and contract handling. Purpose: initiation, conclusion, performance. Data: company, name, role, business email, phone, address, VAT ID, payment data. Legal basis: Art. 6(1)(b) and (c) GDPR. Storage: contract term plus statutory retention (10 years, § 257 HGB, § 147 AO).

3.4 AI interaction (AI colleague). Purpose: providing the AI service on the customer’s behalf. Data: inputs (prompts, documents), output, technical logs. The customer acting as controller determines the legal basis for its content. Art. 28 GDPR and the DPA govern commissioned processing; they do not constitute an independent legal basis under Art. 6 GDPR. Sub-processors: see DPA no. 7 (Hetzner Falkenstein/DE; AI provider per order confirmation). Customer data is not used for model training (§ 6.2 Terms). BYOK: if the customer brings its own AI model/provider, inference runs via the provider chosen by the customer; its selection and data-protection responsibility lie with the customer (§ 6.2a Terms, DPA no. 7.3a).

3.5 Billing. Purpose: invoicing, payment, accounting. Legal basis: Art. 6(1)(b) and (c) GDPR. Storage: 10 years (§ 257 HGB, § 147 AO). Recipients: the customer’s tax advisor, payment service provider (see DPA). HEINI only prepares postings and provides no tax advice within the meaning of §§ 2–5 StBerG (§ 6.7 Terms).

3.6 Marketing/newsletter. Only with express consent (Art. 6(1)(a) GDPR, § 7(2) UWG); revocable any time via the unsubscribe link or hallo@heini.app.

SUSI on this website

SUSI is an AI text conversation for prospective customers. HEINI Operations UG (haftungsbeschränkt) is the controller for these website enquiries. The conversation explains HEINI, clarifies your needs and prepares a suitable next step. It does not provide operational access to customer accounts.

Your message, conversation reference and page context are transmitted for a response only when you choose Send. Please provide only information needed for your enquiry, without confidential customer data. We handle general business enquiries based on our legitimate interest in answering them (Art. 6(1)(f) GDPR); where you personally request steps towards a contract, Art. 6(1)(b) GDPR applies.

To continue the requested conversation, browser session storage holds only a conversation reference and timestamp, used for continuation for up to 24 hours. Message text is not stored there. Free conversation text is not sent to analytics. The reference is not anonymous when it can be linked to a conversation.

For access, erasure or an objection concerning your enquiry, contact datenschutz@heini.app. SaaS account deletion and export rules do not automatically apply to this prospect conversation.

Optional scheduling with Calendly

We offer Calendly, LLC (USA) for scheduling. The embedded calendar loads only after you activate it. Calendly then receives IP address, browser and connection data; you enter your name, email and other booking details at Calendly yourself. Activation is optional. You can contact us by email instead. The clearly labelled external direct link also opens Calendly.

The optional embed relies on your consent (Art. 6(1)(a) GDPR; where required § 25(1) TDDDG). Scheduling serves to answer your business enquiry (Art. 6(1)(f) GDPR), or to take steps towards a contract at your request (Art. 6(1)(b) GDPR). A SUSI conversation reference is shared with Calendly only if you separately choose this. We do not automatically include free conversation text or contact details in calendar links.

Calendly processes booking information as a processor for the organiser and certain data from its own website and services as a controller. Its privacy notice describes processing in the USA and other countries and cites the EU-US Data Privacy Framework and Standard Contractual Clauses as transfer mechanisms. These provider statements do not replace verification of the specific service and contractual arrangements.

You may close the embed at any time to stop further calendar requests from it. This does not automatically delete data already transmitted. Manage Calendly cookie preferences within the calendar. For access or erasure of booking details, contact datenschutz@heini.app. Booking information is handled for its stated purpose, subject to statutory retention obligations.

4. Recipients and third-country transfer

4.1 Recipients: Hetzner Online GmbH (location Falkenstein/FSN1, Germany; deviating region only at Enterprise request — DPA no. 7.2), engaged AI providers (list DPA no. 7; with BYOK the provider chosen by the customer), the customer’s tax advisor, payment service provider, authorities where legally required.

4.2 Where a third-country transfer occurs in SaaS use, it relies on the bases in DPA no. 7.5 (adequacy decision, EU Standard Contractual Clauses 2021 with TIA, DPF). Optional scheduling on this website uses Calendly and may involve transfers to the USA; it is not covered by a blanket promise of exclusively German processing.

5. Encryption and security

Customer data is protected with a per-account key (envelope encryption). On contract end the key is destroyed; the data becomes irreversibly unreadable (crypto-shredding, Art. 17 GDPR). Transport via TLS 1.3, storage encrypted (AES-256). HEINI reports personal-data breaches without undue delay, at the latest within 48 hours of becoming aware (§ 9.2 Terms).

6. Storage period

Personal data is deleted once the purpose ceases and no statutory retention obligation applies. After contract end: 30-day export window (CSV/JSON), then deletion from production systems; backups are overwritten in the rotation cycle (max. 90 days). Commercial/tax retention obligations (§ 257 HGB, § 147 AO) remain unaffected.

7. No automated individual decisions (Art. 22 GDPR)

HEINI makes no solely automated decisions with legal effect on data subjects. The AI colleague prepares and proposes — approval and decision rest with a human (human-in-the-loop).

8. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to lodge a complaint with a supervisory authority (Art. 77). Contact datenschutz@heini.app.

9. Status

Version 2.2 — as of 4 September 2026. This policy is updated when processing or the legal situation changes; the current version is available at /en/legal/privacy/.