
Privacy Policy
Last updated: 03.08.2025
We take the protection of your personal data seriously. This notice explains what data we process, for what purposes, on which legal bases, and what rights you have under the EU General Data Protection Regulation (GDPR) and German law.
1. Controller and Contact
Controller (Art. 4(7) GDPR):
REICHARDT UG
Zeppelinstraße 61, 70193 Stuttgart, Germany
Email: privacy@skivive.com
2. What data we process
- Account / contact data: name, email address, perdonal preferences and user-entered data.
- Usage data (analytics): events such as page views, feature usage, device/browser information, approximate location derived from IP (city-level), referrer/UTM parameters.
- Server logs: IP address, timestamp, request details, error logs (short-term).
We do not intentionally process special categories of data (Art. 9 GDPR) and do not conduct profiling producing legal effects (Art. 22 GDPR).
3. Purposes and legal bases (Art. 6 GDPR)
-
Provide our service & customer support (account creation, authentication, responding to requests)
Legal basis: performance of a contract or steps prior to entering into a contract (Art. 6(1)(b) GDPR). -
Security, fraud prevention, reliability (e.g., logs, rate limiting, backups)
Legal basis: legitimate interests in secure and reliable operation (Art. 6(1)(f) GDPR). Our interests are balanced against your interests and rights. -
Analytics & product improvement (PostHog)
Legal basis: consent (Art. 6(1)(a) GDPR). Where cookies or similar technologies are used, consent is also obtained under § 25(1) TTDSG.
You can withdraw consent at any time via {{“Privacy settings” link}}. -
Legal obligations (tax/compliance, requests from authorities)
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
4. Cookies and similar technologies
We use cookies or similar technologies only with your consent where they are not strictly necessary. Details are provided in our Cookie banner. You can change your choices anytime.
5. Recipients and processors (Art. 28 GDPR)
We use carefully selected service providers bound by data processing agreements:
-
Supabase (EU-hosted): database, authentication, storage, and email delivery.
Role: processor for account, contact, and usage-related data needed to run the service. -
PostHog (EU-hosted): product analytics and event tracking (activated only after consent).
Role: processor for usage/analytics data. -
Infrastructure/ops (e.g., hosting, CDN, monitoring, email gateway)
Role: processor as needed to deliver the service.
We do not sell personal data. Access to data is limited to personnel and providers who need it to perform their tasks and are bound by confidentiality.
6. International transfers (Art. 44 et seq. GDPR)
Our primary processing and storage are located in the European Union. Where an exceptional transfer outside the EU/EEA occurs (e.g., support by an EU-hosted provider’s non-EU staff), we use appropriate safeguards such as EU Standard Contractual Clauses, and implement additional measures where necessary. You can request a copy of relevant safeguards.
7. Retention
We retain personal data only as long as necessary for the stated purposes:
- Account data: for the life of the account and for 3 months after deletion (for dispute handling/backups), unless legal retention duties require longer.
- Support communications: 12 months.
- Analytics data (PostHog): 12 months after collection or until you withdraw consent.
- Server logs: typically 30 days, unless needed to investigate incidents.
When retention periods expire, data are deleted or anonymized.
8. Your rights (Art. 12–22, 77 GDPR)
You have the right to:
- Access your data and obtain a copy (Art. 15),
- Rectification (Art. 16),
- Erasure (“right to be forgotten”, Art. 17),
- Restriction of processing (Art. 18),
- Data portability (Art. 20),
- Object to processing based on legitimate interests (Art. 21),
- Withdraw consent at any time (Art. 7(3)) with effect for the future.
To exercise your rights, contact us at privacy@skivive.com.
You also have the right to lodge a complaint with a supervisory authority (Art. 77), in particular in your habitual residence, place of work, or the place of the alleged infringement.
Lead supervisory authority:
State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW)
House address: Lautenschlagerstraße 20, 70173 Stuttgart, Germany
Postal address: P.O. Box 10 29 32, 70025 Stuttgart, Germany
Phone: +49 711 61 55 41-0
Email: poststelle@lfdi.bwl.de
Website: https://www.baden-wuerttemberg.datenschutz.de
9. How to control analytics (PostHog)
- Use the Privacy settings link to grant or withdraw consent.
- Some browsers offer “Do Not Track” or tracking prevention features; if enabled and supported by our site, we respect these settings.
- If you opt out, PostHog will not be loaded (or will operate in a mode without personal identifiers, where configured).
10. Security
We implement appropriate technical and organizational measures to protect your data (e.g., encryption in transit, access controls, regular backups, least-privilege access, and supplier due diligence). No method of transmission or storage is 100% secure, but we work to continuously improve our safeguards.
11. Children
Our service is not directed to children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us to arrange deletion.
12. Changes to this notice
We may update this policy from time to time. Material changes will be highlighted on this page and, where appropriate, notified to you by email or in-app. The version is indicated by the “Last updated” date above.
Short service-specific notes
- Supabase (EU): acts as our database/auth platform and processes account and operational data strictly under our instructions.
- PostHog (EU): used for analytics only after your consent. Events may include button clicks, page views, session duration, and device/browser info. We configure PostHog to minimize identifiers and respect DNT, as applicable.
If you have any questions about this notice, please contact us at privacy@skivive.com.