Privacy Policy
This Privacy Policy explains how we process personal data when you visit our marketing website getfaind.com / www.getfaind.com and when you use our application at app.getfaind.com (together, the “Website” and the “App”). It covers our own processing as controller under the EU/UK General Data Protection Regulation (GDPR). Where we process personal data on behalf of our customers as part of the FAIND service, we act as a processor — see section 15 and the separate Data Processing Agreement. The behaviour of the customer-embedded FAIND snippet on our customers’ own websites is described separately in the Snippet Data Statement; this Policy does not restate it beyond that pointer. If you have questions, contact us at privacy@getfaind.com.
1) Controller
leif ventures UG (haftungsbeschränkt)
Karl-Marx-Str. 250, 12057 Berlin, Germany
Commercial Register: HRB 170145 B, Local Court (Amtsgericht) Charlottenburg
Represented by: Leif Pritzel
VAT ID: DE344532119
Email: privacy@getfaind.com
Data Protection Officer: Not appointed (not legally required). Contact person for privacy matters: Leif Pritzel (see above).
2) Scope
This Policy applies to personal data we process as controller through our Website and App, and to online interactions with us (e.g. requesting an audit, signing in, contacting support). It does not cover offline processing, third-party websites we link to, or the processing we perform strictly on our customers’ behalf under a data processing agreement.
- The customer-embedded snippet: If you are a visitor to a customer website that has installed FAIND, the snippet’s behaviour on that site is described in the Snippet Data Statement. In that context the customer is the controller and we act as processor.
3) What we collect
- Usage and log data: IP address, timestamps, requested URLs, referrer, user agent, response codes, error logs.
- Account and access data: email address for registration/login via magic link, session identifiers, plan/subscription status.
- Communications: messages you send us (e.g. support emails, replies to our outreach).
- Website journey data: to understand how visitors move from our marketing pages through the audit/report and sign-up flow, we set a first-party identifier cookie (
faind_vid, a random value) and associate it with the pages you view on our own site. See section 7 for details and consent classification. - Visiting-company identification: on our marketing Website we use an IP-to-company lookup to identify the organisation a visitor is likely coming from (not the individual). For this we record: a pseudonymous
ip_hashcomputed assha256(IP + a secret salt), the user agent, referrer, approximate location (country/region/city), and any UTM parameters. The raw IP address is passed to the lookup provider but is not itself retained in our analytics. Becauseip_hashis a persistent pseudonymous identifier, we treat it as personal data; it is retained no longer than 24 months (section 10) and you may object at any time (section 11). Thefaind_vidcookie is not strictly necessary and, under §25 TDDDG, is set only after your prior consent via our cookie banner; your consent choice is shared across our sites (see section 7). - Product data (when you use our services): publicly accessible content of your verified domain (e.g. HTML, structured data, meta tags), and technical measurements (e.g. status codes, response times, technical content signals) needed to generate AI-readable static copies (the “Knowledge Graph”) and visibility reports.
- Analytics (only with consent): pseudonymous usage data via our web analytics provider.
We do not collect full payment card numbers. Payments are processed by Stripe (see “Recipients and processors”).
4) Why we use your data (legal basis)
- Provide and secure the Website/App: Art. 6(1)(f) GDPR (legitimate interests).
- Account, login, subscriptions, billing, support: Art. 6(1)(b) GDPR (contract / steps prior to contract).
- Product features (Knowledge Graph / static AI-readable copies, AI Visibility Report): Art. 6(1)(b) GDPR (contract).
- Lead generation and understanding our Website audience (visiting-company identification via IP-to-company lookup; the
faind_vidjourney cookie): these technologies are not strictly necessary, so storing or reading them on your device requires your prior consent under §25 TDDDG, and the associated processing is based on Art. 6(1)(a) GDPR (consent) obtained via our cookie banner. - Compliance (tax, accounting): Art. 6(1)(c) GDPR (legal obligation).
- Analytics: Art. 6(1)(a) GDPR (consent via cookie banner).
5) How we use your data
We use the data to operate and protect the Website/App; authenticate you; manage subscriptions and billing; deliver our product (creating AI-readable static copies of publicly available pages you control and sending indexing signals); generate and send requested visibility reports; understand how visitors use our marketing Website and identify visiting companies for B2B lead generation; answer support requests and respond to your communications; and (if you consent) improve the Website/App through analytics.
6) Log files
Like most websites, we process server logs. The information may include IP address, browser, ISP, date/time, entry/exit pages and click counts. Logs are used to analyse trends, administer the site and ensure security.
7) Cookies and similar technologies
We use strictly necessary cookies for sessions and security (Art. 6(1)(f) GDPR). Optional cookies and similar technologies are used only with your prior consent via our cookie banner (Art. 6(1)(a) GDPR), and you can withdraw consent at any time in the banner settings. The main non-essential technologies on our own Website are:
- faind_vid (first-party journey cookie): a first-party cookie containing a random 32-character hexadecimal value. It stitches together a visitor’s journey across our own site (for example homepage → /offer → report → sign-up) so we can understand and improve conversion and attribute leads. It does not track you across other websites. This cookie is used for analytics / lead generation and is not strictly necessary, so under §25 TDDDG it is set only after your prior consent via our cookie banner (legal basis Art. 6(1)(a) GDPR); your consent choice is shared across www.getfaind.com and app.getfaind.com, and the cookie is retained no longer than 24 months. This is distinct from the customer-embedded FAIND snippet, which sets no cookie and stores nothing on the visitor’s device and therefore needs no consent — see the Snippet Data Statement.
- Web analytics: set only after you consent via the cookie banner (Art. 6(1)(a) GDPR).
8) Recipients and processors
We use carefully chosen service providers, engaged as processors under Art. 28 GDPR (with processor agreements and, where needed, Standard Contractual Clauses). The core recipients of personal data are:
- Hosting/Server: DigitalOcean, LLC (United States; EU hosting region Frankfurt, Germany) — entity + jurisdiction; further particulars on request.
- CDN/Security: Cloudflare, Inc. (United States) — entity + jurisdiction; further particulars on request.
- Payments: Stripe Payments Europe, Limited (Ireland) — entity + jurisdiction; further particulars on request.
- Transactional email: Brevo SAS (France) — entity + jurisdiction; further particulars on request.
- Email delivery, search indexing, and web analytics: Google Ireland Limited (Ireland) — entity + jurisdiction; further particulars on request (web analytics is consent-based).
- AI/LLM analysis of publicly available content: Providers for AI/LLM analysis of publicly available content (processing publicly available, non-personal page content).
- Company identification and business-contact enrichment: Providers for company identification and business-contact enrichment.
A current and complete list of sub-processors — including providers used solely to process publicly available, non-personal content — is available to customers and prospective customers on request.
9) International transfers
Where data is processed outside the EEA/UK (e.g. the USA), we rely on an adequacy decision where one applies (such as the EU–US Data Privacy Framework for certified recipients) or on the EU Standard Contractual Clauses plus supplementary safeguards. Copies of the relevant transfer mechanisms are available on request.
10) Retention
We keep personal data only as long as necessary for the purposes described, or as required by law. The retention policy below reflects our current practice; a purge job is being implemented to enforce the time limits on the personal-data pockets. A period stated here is our retention policy, not a contractual guarantee. A key distinction runs through it: content change-detection signals and aggregated statistics carry no visitor identifier, no raw IP and no user-agent, so they are not personal visitor data and may be kept for as long as they are useful; the time limits apply only to the personal pockets (server logs, and our own-site lead/journey data).
- Knowledge Graph / shadow-site artifacts and per-page content change-detection signals (derived from the customer’s own public pages; no visitor identifier, no raw IP, no user-agent): retained for the duration of the subscription and deleted or anonymized within 30 days after termination. For rendered page snapshots we additionally keep only the two most recent per page.
- Aggregated traffic statistics (hourly counts by page/host/source; no visitor identifier, no raw IP or user-agent): as they contain no personal data, these may be retained as long-term statistical records, including in anonymized/aggregated form.
- Server logs (may include IP address and user-agent): retained for 90 days, and longer only where needed to investigate a specific security incident.
- FAIND-website lead & visitor-journey data (the
faind_vidjourney cookie; visiting-company identification including the saltedip_hash; offer/report journey records): retained while the business relationship or lead is active, and in any case deleted or anonymized after 24 months of inactivity. - Magic-link tokens: up to 15 minutes; successful login records up to 12 months (security proof).
- Account and contract/billing records: retained per statutory rules (up to 10 years; § 147 AO / § 257 HGB).
11) Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object to processing based on Art. 6(1)(f) (Art. 21). Where processing relies on consent, you can withdraw consent at any time with future effect (Art. 7(3)). To exercise your rights, email privacy@getfaind.com. We may need to verify your identity.
12) Complaint
You can lodge a complaint with any supervisory authority. The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
13) Children’s data
Our services are directed at businesses and not at children under 16. We do not knowingly collect data from children.
14) Security
We implement appropriate technical and organisational measures per Art. 32 GDPR, including TLS encryption, access controls, logging and regular backups.
15) Processing on behalf of customers (SaaS)
When we deliver the FAIND service to a customer — building and hosting the AI-readable Knowledge Graph from the publicly accessible content of the customer’s verified domain, and processing data collected via the customer-embedded snippet — we act as a processor under Art. 28 GDPR and the customer is the controller. The terms of that processing are set out in our Data Processing Agreement, and the data the snippet handles on the customer’s own site is described in the Snippet Data Statement. The customer remains responsible for the lawfulness of the origin site’s content and robots rules and for any consent required on its own site.
16) Changes to this Policy
We may update this Policy if our services or legal requirements change. The current version is always available on this page, with the “Last updated” date above reflecting the latest revision.
Contact: leif ventures UG (haftungsbeschränkt), Karl-Marx-Str. 250, 12057 Berlin, Germany · Email: privacy@getfaind.com. See also our Imprint, Terms, Data Processing Agreement and Snippet Data Statement.