Privacy Policy

Last updated: July 2026 · Applies to this website and the Compliance Concierge application. Subject to change.

1. Controller

Kristian Hoffmann, Karl-Kraut-Straße 15, 30177 Hannover, Germany is the controller responsible for the processing of personal data described in this policy. Contact: moin@kristianhoffmann.de. No Data Protection Officer has been appointed. As a sole proprietorship, Kristian Hoffmann is not required to appoint one.

2. Processing purposes and legal bases

We process personal data for the following purposes:

  • Visiting the website: technical server logs (IP address, browser user agent, timestamp) are processed on our Hostinger server in Frankfurt, Germany, to keep the service secure. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
  • Account and sign-in: for email magic-link sign-in or OAuth sign-in (Google, GitHub, or Apple) we process your email address and, depending on the provider, your name as profile data supplied by that provider. Legal basis: Art. 6(1)(b) GDPR (contract performance).
  • Core service: documents and questionnaires you upload are stored on our own infrastructure in Frankfurt am Main. Relevant content is sent to Mistral AI (Paris, France; EU-hosted inference, not used for model training) to draft AI-assisted answers. Legal basis: Art. 6(1)(b) GDPR (contract performance).
  • Payment: subscription payments are handled by Stripe. Your name, email address, and payment details are processed directly by Stripe — we do not store full payment data ourselves. Legal basis: Art. 6(1)(b) GDPR (contract performance).
  • Email delivery: sign-in and product notifications (e.g. magic links, status updates) are sent via our email provider, Brevo (Sendinblue GmbH / Sendinblue SAS, EU). Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in reliable delivery).
  • Trust Center document requests: when you request access to a document through a Trust Center, we store your name, email address, company, and stated purpose, and forward that information to the relevant Trust Center operator so they can decide on access. Legal basis: Art. 6(1)(b) and (f) GDPR.
  • NIS2 readiness check: the NIS2 self-assessment tool runs entirely in your browser; no input is sent to or stored on our servers.

3. Recipients and processors

The following providers process personal data on our behalf, or receive data from us as part of the processing activities described above:

  • Hostinger — server hosting for our self-hosted database, authentication, and file storage stack, Frankfurt am Main (Germany).
  • Mistral AI — evidence search and draft assistance, an EU company (Paris, France) with EU-hosted inference. Content is not used for model training.
  • Hostinger International Ltd. — server hosting for the Node.js web application and API in Frankfurt am Main (Germany).
  • Stripe — payment processing for subscriptions; Stripe does not receive your document or questionnaire data. Stripe group companies based in the US process data under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).
  • Brevo (Sendinblue GmbH / Sendinblue SAS) — sends account and product-related emails; an EU company.
  • Google LLC, GitHub Inc. (Microsoft) and Apple Inc. — only if you choose OAuth sign-in: your email address and, depending on the provider, your name are exchanged with the provider you select, for authentication. These are US-based companies; transfers are safeguarded under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).

For transfers to the US you can request a copy of the applicable safeguards (Standard Contractual Clauses) or details of the relevant Data Privacy Framework certification by email: moin@kristianhoffmann.de.

Data processing agreements (DPAs) are in place with the providers listed above. Our own DPA is public and applies to every plan — no request needed: moin@kristianhoffmann.de.

4. Retention

Account and document data is kept for as long as the account, or the respective documents, exist; deleting a document removes its source file and all embeddings generated from it via cascade delete. Server logs are kept only briefly and then deleted automatically. Statutory retention obligations, in particular for invoices (§147 German Fiscal Code, §257 German Commercial Code), remain unaffected.

5. Cookies

We use only strictly necessary cookies (e.g. for the login session and the language setting). These are required to operate the website, so no consent banner is needed (Art. 6(1)(f) GDPR, §25(2) TDDDG — German Telecommunications-Digital-Services-Data-Protection Act). We do not use tracking, analytics tools, or advertising.

6. Your rights

Under the GDPR you have the right to access, rectify, erase, and port your personal data, and to restrict or object to certain processing. Any consent you have given can be withdrawn at any time with effect for the future. To exercise any of these rights, email moin@kristianhoffmann.de. You also have the right to lodge a complaint with a supervisory authority; the competent authority is Die Landesbeauftragte für den Datenschutz Niedersachsen (lfd.niedersachsen.de).

7. No automated decision-making

We do not use automated decision-making within the meaning of Art. 22 GDPR. AI-drafted answers are always reviewed by a human before they are exported.

8. Contact

Questions about this policy or a Data Processing Agreement request: moin@kristianhoffmann.de.