Privacy Policy
1. Introduction
Designation of the Responsible Party
saferspaces GmbH, c/o 105 VIERTEL GmbH & Ko. KG., Gänsemarkt 33, 20354 Hamburg.
The responsible party decides alone or jointly with others on the purposes and means of processing personal data (e.g., names, contact details, etc.).
If you have any questions about data protection, you can contact us at any time at support@saferspaces.io.
Revocation of Your Consent to Data Processing
Some data processing operations are only possible with your express consent. A revocation of your already given consent is possible at any time. An informal notification by e-mail to support@saferspaces.io is sufficient for the revocation. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Complain to the Competent Supervisory Authority
As a data subject, you have the right to complain to the competent supervisory authority in the event of a data protection violation. The competent supervisory authority regarding data protection questions is the state data protection officer of the federal state in which our company is located.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to third parties. The provision is made in a machine-readable format. If you request the direct transfer of the data to another responsible party, this will only be done insofar as it is technically feasible.
Right to Information, Correction, Blocking, Deletion
You have the right at any time within the framework of the applicable legal provisions to free information about your stored personal data, origin of the data, their recipients and the purpose of data processing and, if applicable, a right to correction, blocking or deletion of this data. For this purpose and for further questions on the subject of personal data, you can contact support@saferspaces.io at any time.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content that you send to us as site operator, our website uses SSL or TLS encryption. This means that data that you transmit via this website cannot be read by third parties. You can recognize an encrypted connection by the "https://" address line of your browser and the lock symbol in the browser line.
2. Which Data Do We Process?
Hosting & Provisioning of the Application (Heroku)
Our application is operated on the Platform-as-a-Service infrastructure of Heroku (Heroku / Salesforce, Inc.). The primary processing and storage takes place in EU regions. In this context, technical data that is required for the operation, security and provision of the application is automatically processed, e.g.:
- IP address of the requesting device (shortened or technically necessary header information)
- Date and time of access
- Browser type, operating system and browser version
- Server and system logs (including technically required HTTP headers)
- Error messages
- Amount of data transferred
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in operation, security and functionality).
Data processing agreement: Heroku processes personal data exclusively on our behalf and according to documented instructions. Where required, a data processing agreement pursuant to Art. 28 GDPR has been concluded with Heroku.
Technical third-country references: In the context of global infrastructure components, certain technically necessary processing operations such as routing, TLS termination processes or DDoS protection may run via non-European systems. These operations exclusively concern minimized, encrypted metadata (e.g., IP/HTTP headers) and are secured by appropriate safeguards.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Our Configuration & Protective Measures:
- Use exclusively of European Heroku regions
- Add-ons are deliberately chosen to ensure EU processing remains guaranteed
- No storage of personal data in build artifacts or technical logs
Storage period: Log data is used exclusively for operation and security and is generally deleted within a few weeks, unless there is a legitimate interest in longer storage (e.g., for investigating security-related incidents).
Hosting & Provisioning of the Website (Vercel)
Our website is hosted by Vercel (Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA). Vercel provides both the hosting environment and serverless/edge functions, CDN, routing and security mechanisms. The primary processing takes place in European regions (including Frankfurt, Stockholm, Paris).
In the course of operation, Vercel automatically processes technical data that is required for the execution of the application, the provision of server-side functions, security and performance optimization, including in particular:
- The page from which the page was requested (so-called referrer URL)
- Name and URL of the accessed page
- Date and time of access
- Browser type, browser version and browser language
- IP address of the requesting computer (shortened so that it no longer has a direct personal reference)
- Amount of data transferred
- Operating system
- Message whether the access was successful (access status/HTTP status code)
- GMT time zone difference
This data is technically necessary to ensure the functionality, security and stability of the application. No profiling or merging with other data takes place.
Technical third-country references: Vercel operates a global edge and CDN network. Therefore, individual technically necessary operations such as:
- Routing and load balancing,
- DDoS/attack protection,
- TLS termination,
- Edge caching,
- Logging and monitoring processes
may occur via non-European systems. These processes exclusively concern minimized, encrypted metadata (particularly IP address, User-Agent, HTTP headers). Personal content or functional data is executed exclusively in EU regions.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in operation, security, stability and efficient provision of a server-based web application).
Data processing agreement: Vercel processes personal data exclusively on our behalf and according to documented instructions. Where required, a data processing agreement pursuant to Art. 28 GDPR has been concluded with Vercel.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Our Configuration & Protective Measures:
- Execution of all serverless functions exclusively in European regions (europe-*)
- Caching exclusively of static assets in the CDN (no personal content in the cache)
- Exclusion of personal data (PII) from query parameters so that no PII enters CDN or edge caching
- Log processing exclusively in EU regions with short retention period (only technically necessary log data)
Storage period: Vercel typically stores technical logs only for short periods (typically 24 hours to 7 days). They are used exclusively for operation, debugging, security and stability purposes. Longer storage only occurs if there is a legitimate interest, e.g., for investigating security-related incidents.
Infrastructure, Storage and Messaging Services (Google Cloud EMEA Limited)
We use Google Cloud EMEA Limited for infrastructure, storage and messaging services (e.g., hosting, chat data, push notifications). The primary processing takes place on servers in Frankfurt (Germany).
Legal basis: Art. 6 para. 1 lit. f GDPR - legitimate interest in the operation, security and reliable provision of infrastructure, storage and messaging services for our application.
Data processing agreement: Google processes personal data on our behalf as a data processor. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google Cloud EMEA Limited.
Technical third-country references: Some processing operations - particularly those executed by services of the parent company Google LLC in the USA - may involve third-country references. According to Google Cloud's terms of use, "Customer Data" may generally be processed in any country where Google or its sub-processors maintain facilities.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Our Configuration & Protective Measures:
- Processing primarily in European regions (Frankfurt, EU), where technically possible
- Logs are stored exclusively in EU regions
- Minimization of personal data (PII) to the required minimum
- Short log retention: Logs and temporary data are only stored for as long as technically necessary
- Access control via roles (RBAC) and multi-factor authentication (MFA)
- No additional tracking or analysis functions beyond the actual services
Storage period: Storage is carried out in accordance with Google Cloud's specifications. Technical logs and temporary data are only stored for as long as they are required for operation, debugging, security and functionality.
Chat and Location Data
We process the following personal data in connection with chat and location functions:
When the chat function is enabled, messages are stored for a maximum of 7 days and then automatically deleted. When location sharing is enabled, the geocoordinates are stored to display the location of both the app user and the web app user on a map, so that the persons can find each other.
Chat and location data are stored in Google Cloud EMEA Limited and processed through our Heroku infrastructure.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent) for location sharing, Art. 6 para. 1 lit. f GDPR (legitimate interest in providing chat and location functions) for chat data.
Storage period: Chat messages are stored for a maximum of 7 days and then automatically deleted. Location data is stored for a maximum of 1 hour or immediately deleted after location sharing is ended.
3. Use of External Services
Maps and Location Services (Google Maps)
We integrate Google Maps (Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland) to provide interactive map functions and location information on our website. In this context, IP addresses, location data and search queries may be processed.
Data processing is generally carried out within the European Union or the European Economic Area (EEA). However, it cannot be ruled out that data may also be transmitted to third countries (e.g., the USA) in the context of certain services or technical support services.
Legal basis: Art. 6 para. 1 lit. f GDPR - consent of users to process their location data in order to display their own position and, if applicable, that of third parties on an interactive map.
Data processing agreement: Google processes personal data on our behalf as a data processor. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google Cloud EMEA Limited.
Technical third-country references: Individual processing operations may take place outside the EU/EEA, particularly on servers of Google LLC in the USA. These transfers are carried out on the basis of appropriate safeguards pursuant to Art. 46 GDPR.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Our Configuration & Protective Measures:
- Use of Google Maps exclusively for displaying necessary map and location information
- No use of additional tracking or analysis functions
- Integration only after prior information to users
Storage period: The storage period is determined by Google's specifications. We have no direct influence on the specific duration of storage. Further information can be found in Google's privacy policy.
Email Services (Resend)
For sending emails, e.g., for notifications, we use Resend (Resend, Inc., USA). In this context, the content of the communication provided by you is processed.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent) or lit. b (fulfillment of a contract).
Data processing agreement: Resend processes personal data exclusively on our behalf and according to documented instructions. Where required, a data processing agreement pursuant to Art. 28 GDPR has been concluded with Resend.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Storage period: Email data is only stored for as long as is necessary for sending, or as long as legal retention periods exist.
Error and Performance Monitoring (Sentry)
We use Sentry (Functional Software, Inc. d/b/a Sentry — 45 Fremont St, 8th Floor, San Francisco, CA 94105, USA) to monitor errors and performance data of our application and to improve stability and user-friendliness. In this context, technical information such as browser type, operating system, IP address (anonymized) and error logs are processed.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in optimizing and securing our application).
Data processing agreement: Sentry processes personal data exclusively on our behalf and according to documented instructions. Where required, a data processing agreement pursuant to Art. 28 GDPR has been concluded with Sentry.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Our Configuration & Protective Measures:
- Use of an EU organization or EU server locations.
- PII scrubbing and SDK filters to anonymize personal data before processing.
- IP addresses are not stored.
- Processing only of metadata required for error analysis.
Storage period: Data is stored for the duration of analysis and optimization, but at most 90 days.
Error and Performance Monitoring (New Relic)
We use New Relic (New Relic, Inc., 188 Spear St, San Francisco, CA 94105, USA) to monitor errors and performance data of our application and to improve stability and user-friendliness. In this context, technical information such as browser type, operating system, IP address (anonymized) and error logs are processed.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in optimizing and securing our application).
Data processing agreement: New Relic processes personal data exclusively on our behalf and according to documented instructions. Where required, a data processing agreement pursuant to Art. 28 GDPR has been concluded with New Relic.
Data transfers to third countries: Transfers are secured by:
- the EU-US Data Privacy Framework,
- as well as supplementary Standard Contractual Clauses (SCC) of the EU Commission.
Transport routes are consistently TLS-encrypted, and the processed technical data is minimized to what is necessary.
Our Configuration & Protective Measures:
- Activation of EU regions for data processing.
- Deactivation of sensitive attributes to minimize personal data.
- Sampling and reduction of collected data to the technically necessary extent.
- Access control via RBAC (Role-Based Access Control) and MFA (Multi-Factor Authentication).
Storage period: Data is stored for the duration of analysis and optimization, but at most 90 days.