Privacy Policy

This policy explains what personal data we process — both when you simply visit our website and when you sign in and use the MSA Factory application — the legal bases for that processing, and the processors we rely on.

Controller

The controller responsible for processing your personal data is the provider named in our Imprint (betaITS GmbH).

Data protection officer

We have appointed an external data protection officer, whom you can reach at:

Winona Wenning

Althammer & Kill GmbH & Co. KGRoscherstraße 730161 HannoverDeutschland

Email: kontakt-dsb@althammer-kill.de

When you visit our website

You can browse our public pages without creating an account. Each time a page is requested, our hosting infrastructure automatically records standard server log data:

  • the page accessed and the date and time of access
  • the amount of data transferred
  • the website you came from (referrer)
  • your browser type and version
  • your operating system
  • your IP address

This processing is based on our legitimate interest in operating a secure and stable service (Art. 6(1)(f) GDPR).

Server logs are stored for a maximum of 14 days and then deleted, unless they are needed longer to investigate a specific security incident.

When you use the application

To sign up and sign in you provide account data (such as your name and email address), which is processed on our behalf by our authentication provider Clerk.

Within the app you enter business data to manage your contracts — for example customer details, products, packages and contract terms. You decide what data to enter; where it concerns your own customers, you act as the controller and we process it on your behalf.

We process this data to provide the service you have requested (Art. 6(1)(b) GDPR).

Error monitoring and analytics

We use Sentry to detect and diagnose technical errors and performance issues. Basic error and crash capture is always on to keep the service stable and secure, based on our legitimate interest (Art. 6(1)(f) GDPR). The additional session replay and performance tracing are non-essential and are activated only after you consent via the cookie banner (the “Error monitoring” category); without consent they stay off, and you can withdraw a given consent at any time with effect for the future (Art. 6(1)(a) GDPR). Session replays are captured masked — all text and form inputs are hidden and media is blocked — and we additionally scrub known personal data before it is sent.

We use PostHog (hosted in the EU) for product analytics, with automatic capture and session recording switched off. Analytics are disabled by default and run only after you consent via the cookie banner; we also honour your browser's “Do Not Track” signal (Art. 6(1)(a) GDPR).

Processors

We use the following service providers (processors under Art. 28 GDPR) to operate the service:

  • ClerkAuthentication, sign-up and organization managementProcessing location: USA (EU Standard Contractual Clauses)
  • SentryError and performance monitoring; session replay (masked, consent-gated)Processing location: USA (EU Standard Contractual Clauses)
  • PostHogProduct analytics (consent-gated)Processing location: European Union
  • Hosting & infrastructureApplication hosting, infrastructure and server logsProcessing location: Germany

International data transfers

Some processors (in particular Clerk and Sentry) may process data on servers outside the EU/EEA, including in the USA. Such transfers are safeguarded by the European Commission's Standard Contractual Clauses together with additional technical measures.

Cookies and consent

We only set essential cookies by default. Non-essential services — product analytics (PostHog) and session replay and performance tracing (Sentry) — load only after you consent via the cookie banner, where you can select them individually. You can change or withdraw your choice at any time through the cookie preferences.

Data retention

We keep personal data only as long as necessary for the purposes described above or as required by law. Server logs are deleted after at most 14 days; account and contract data are deleted when you close your account, subject to statutory retention periods.

Your rights

You have the right to access, rectify, erase and port your data, to restrict or object to processing, and — where processing is based on consent — to withdraw that consent at any time.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen

Prinzenstraße 530159 HannoverDeutschland

Contact

To exercise your rights or for any privacy question, contact us using the details in our Imprint or our data protection officer named above.