Privacy Policy
Last updated: July 29, 2026
This Privacy Policy explains how Jennifer Dumler, Timo Fallert GbR (“SocialEdge”, “we”, “us” or “our”) processes personal data. It applies to our websites at www.socialedge.ai and socialedge-saas.webflow.io, our web application at app.socialedge.ai, as well as communication and support provided in connection with our services.
Personal data means any information relating to an identified or identifiable natural person. This may include, in particular, names, contact details, online identifiers, communication content, user account data and data processed in connection with the management of a Google Business Profile.
The specific data processed in each case depends on whether you merely visit our website, contact us, book an appointment, enter into a contract with us, use our app or engage us to manage a Google Business Profile.
1. Controller and Your Rights
Controller
The Controller within the meaning of the General Data Protection Regulation (GDPR) is:
Jennifer Dumler, Timo Fallert GbR (SocialEdge)
Schugshofweg 1
77815 Bühl
Germany
Phone: 01567 9617691
Email: verwaltung@socialedge.ai
No Data Protection Officer has been appointed. You may send all data protection inquiries directly to the contact details above.
Legal Bases
We process personal data in particular on the following legal bases:
- Art. 6(1)(a) GDPR where you have given us your consent;
- Art. 6(1)(b) GDPR where processing is necessary to take steps prior to entering into a contract or to perform a contract;
- Art. 6(1)(c) GDPR where we are subject to a legal obligation;
- Art. 6(1)(f) GDPR where processing is necessary for the purposes of our legitimate interests or those of a third party and such interests are not overridden by the interests or fundamental rights and freedoms of the data subject;
- Section 25(1) TDDDG for storing information on your device or accessing information stored on your device where consent is required;
- Section 25(2) TDDDG where access to the device is strictly necessary for transmitting a communication or for providing a digital service expressly requested by you.
Recipients and Processors
We only disclose personal data where this is necessary for the purposes described, where a legal basis exists or where we are legally required to do so. Recipients may in particular include hosting, cloud, communication, CRM, analytics, payment, AI and platform providers, as well as tax advisors, legal advisors and public authorities.
Where a service provider processes personal data on our behalf, we enter into a data processing agreement pursuant to Art. 28 GDPR before the relevant processing begins. Where we ourselves act as a processor on behalf of a customer, the data processing agreements between SocialEdge and the respective customer shall additionally apply.
Your Data Protection Rights
Subject to the applicable statutory requirements, you have in particular the following rights:
- the right of access to your personal data pursuant to Art. 15 GDPR;
- the right to rectification of inaccurate data pursuant to Art. 16 GDPR;
- the right to erasure pursuant to Art. 17 GDPR;
- the right to restriction of processing pursuant to Art. 18 GDPR;
- the right to data portability pursuant to Art. 20 GDPR;
- the right to object to processing based on Art. 6(1)(e) or (f) GDPR pursuant to Art. 21 GDPR;
- the right to withdraw consent at any time with effect for the future;
- the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.
The supervisory authority generally responsible for SocialEdge is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg. You may also contact any other supervisory authority competent pursuant to Art. 77 GDPR.
Right to Object to Direct Marketing
If your personal data is processed for direct marketing purposes, you may object to such processing at any time. Following your objection, we will no longer use the relevant data for direct marketing purposes.
No Solely Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. AI-assisted results, analyses and recommendations are used to support our services and are not used as automated legally binding decisions concerning an individual.
Encryption
Our website and app use SSL or TLS encryption. This protects transmitted content against unauthorized interception during transmission.
2. Hosting and Technical Provision
Webflow – Hosting of Our Website
Our website is created with Webflow and provided by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. When you access the website, Webflow processes in particular your IP address, date and time of access, the page or file requested, referrer URL, browser and device information, as well as technical log data. This processing is necessary to deliver the website securely, reliably and without errors.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our website. Where access to your device is strictly necessary for providing the website, Section 25(2) TDDDG additionally applies.
Transfers to the USA are, where applicable, based on certification under the EU-US Data Privacy Framework and, additionally, on the European Commission's Standard Contractual Clauses. Further information can be found in Webflow's Privacy Policy.
Vercel – Hosting of Our Web Application
Our web application at app.socialedge.ai is hosted on the Pro plan by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When delivering the app, Vercel processes in particular IP addresses, timestamps, requested resources, browser and device information, as well as security- and error-related log data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, high-performance and stable operation of the app. Transfers to third countries are safeguarded in accordance with the Vercel DPA, in particular on the basis of the EU-US Data Privacy Framework or the Standard Contractual Clauses.
Further information: Vercel Privacy Notice and Vercel Data Processing Addendum.
Content Delivery Networks and Software Libraries
To ensure the fast and secure delivery of individual software libraries, our website uses cdnjs or Cloudflare and jsDelivr in addition to Webflow's networks. In this context, your IP address, browser information, requested file, referrer, and the date and time of access may be transmitted to the respective CDN providers.
Providers include in particular Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, as well as the jsDelivr network, which uses various CDN subprocessors. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the fast, secure and technically reliable delivery of our website.
Further information: Cloudflare Privacy Policy and jsDelivr Subprocessors.
Server Log Data
Technical log data is generally stored only for as long as necessary for operation, troubleshooting, prevention of misuse and IT security. Unless a security incident or statutory retention requirement applies, log data controlled by us is regularly deleted or anonymized no later than after 30 days. Any different technically necessary retention periods applied by the hosting providers are set out in their respective privacy information.
Google Fonts
The fonts used on our website are provided locally or through the hosting infrastructure used by us. Therefore, no separate connection to Google Fonts is established when you access the website.
3. Cookies, Consent Management and Local Storage
Cookies and Similar Technologies
Our website and app may use cookies and comparable storage and access technologies. Cookies are small data records that are stored on or read from your device. They may be technically necessary or, with your consent, used for analytics, convenience or communication purposes.
Technically necessary access takes place on the basis of Section 25(2) TDDDG. Any subsequent processing of personal data is based on Art. 6(1)(b) or (f) GDPR. Non-essential cookies and comparable technologies are only activated after you have given your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
CCM19 Consent Management
We use CCM19 to manage your consent preferences. The provider is Papoo Software & Media GmbH, Auguststraße 4, 53229 Bonn, Germany.
CCM19 processes in particular your consent decision, the time and scope of your consent, a pseudonymous consent identifier, browser and device information and, where applicable, your IP address. This processing is necessary to control services according to your preferences and to provide evidence of consent given.
The legal bases are Art. 6(1)(c) and (f) GDPR as well as Section 25(2) TDDDG. Our legitimate interest lies in the legally compliant and verifiable management of the services used.
You can change or withdraw your choices at any time via the cookie settings available on the website. Any withdrawal of consent applies with effect for the future.
Further information can be found in the CCM19 Privacy Policy.
Management of Consent-Based Services
Services requiring consent, such as Ahrefs Web Analytics, Crisp, Calendly and embedded YouTube content, are controlled through our consent management system and are only activated after you have made the corresponding selection. External social media profiles, by contrast, are only linked. Data is only transmitted to the respective social network when you click the corresponding link.
Local Storage and Growth Calculator
Our website may use your browser's local storage to save settings selected by you, in particular display or color preferences. This storage takes place on the basis of Section 25(2) TDDDG where it is necessary to provide the function selected by you.
Our Growth Calculator processes the values you enter directly in your browser in order to calculate an estimated investment and potential contribution margin. According to the current technical configuration, these entries are not automatically transmitted to us. If you close or refresh the page, the entries may be lost.
The results of the Growth Calculator are non-binding model calculations. They do not constitute an individual offer or a guarantee of any specific revenue, contribution margin, ranking or other business result.
4. Analytics, Live Chat, Appointment Booking and Embedded Media
Ahrefs Web Analytics
We use Ahrefs Web Analytics to statistically evaluate the use of our website and to improve our offering from both a technical and content perspective. The provider is Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581.
Depending on the configuration, this may include the collection of page views, referrers, approximate location, browser, operating system, device type, screen size, language, timestamps and shortened or technically processed IP information. Ahrefs is only activated through CCM19 after you have given your consent.
The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future via the cookie settings.
Further information can be found in the Ahrefs Privacy Policy.
Crisp Live Chat
We use Crisp for communication via live chat. The provider is Crisp IM SAS, 2 Boulevard de Launay, 44100 Nantes, France.
When the chat is activated, the data processed may include in particular your IP address, browser and device information, pages visited, time and duration of the visit, chat content, name, email address and any other information you voluntarily provide. Crisp is only activated through CCM19 after you have given your consent.
The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Where you use the chat for a specific pre-contractual or contractual inquiry, the subsequent processing of your message is additionally based on Art. 6(1)(b) GDPR.
Further information: Crisp Privacy Policy.
Calendly Appointment Booking
We use Calendly to schedule consultation appointments. The provider is Calendly LLC, 271 17th Street NW, 10th Floor, Atlanta, Georgia 30363, USA.
When you activate the appointment booking function, the data processed may include in particular your name, email address, phone number, company, preferred appointment time, time zone, answers to appointment questions and technical connection data. The data is used to schedule, conduct and follow up on the requested appointment.
The Calendly embed is only loaded after you have given your consent. The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. The subsequent processing of your appointment booking is based on Art. 6(1)(b) GDPR.
Transfers to third countries may be based on the EU-US Data Privacy Framework or Standard Contractual Clauses. Further information: Calendly Privacy Notice and Calendly DPA.
YouTube in Privacy-Enhanced Mode
Our website may contain embedded videos from YouTube. For users in the European Economic Area, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, USA.
The videos are embedded via the youtube-nocookie.com domain and are only activated after you have given your consent. When a video is loaded or played, the data transmitted to Google or YouTube may include in particular your IP address, browser and device information, the page accessed, referrer, timestamp and interactions with the video. If you are signed in to your Google account, your use may be associated with your account.
The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Transfers to third countries may be based on the EU-US Data Privacy Framework or Standard Contractual Clauses.
Further information can be found in the Google Privacy Policy.
No Use of Google Analytics
At present, we do not use Google Analytics on this website. If Google Analytics is activated in the future, we will update this Privacy Policy before activation and manage the service through our consent management system.
5. Contact by Email, Phone and WhatsApp
Contact by Email
If you contact us by email, we process in particular your email address, your name, the content of your message, any attachments transmitted, as well as the date and time of the communication. The processing is carried out in order to handle your inquiry and for subsequent communication.
Our business customer communication by email is handled via IONOS. The provider is IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. IONOS may process connection, communication and log data required for sending, receiving, storing and securing emails.
The legal basis is Art. 6(1)(b) GDPR where your inquiry relates to entering into or performing a contract. In other cases, the processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in handling business inquiries.
Further information can be found in the IONOS Privacy Policy.
Gmail Accounts for Google Business Profiles
For the management of Google Business Profiles entrusted to us, we use separate Google or Gmail accounts. These accounts are used to access and manage Google Business Profiles and are not used for our general customer communication by email.
When these accounts are used, Google processes in particular account, login, security, access and activity data. Further details regarding the management of Google Business Profiles can be found in the section “Management of Google Business Profiles”.
Contact by Phone
If you contact us by phone, we process in particular your phone number, your name, the time and duration of the call, as well as the information you provide to us. The processing is carried out in order to handle your inquiry on the basis of Art. 6(1)(b) or (f) GDPR.
WhatsApp Business
Our website contains an external link that allows you to voluntarily start a conversation with our WhatsApp Business account. No data is transmitted to WhatsApp via this link before you click it.
After clicking the link, you will be redirected to WhatsApp. In this context and during the subsequent communication, WhatsApp may process in particular your phone number, profile name, profile picture, message content, attachments, communication times and technical metadata. For users in the European Economic Area, the provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; the parent company is Meta Platforms, Inc., USA.
We process WhatsApp communications received by us in order to handle your inquiry. The legal basis is Art. 6(1)(b) GDPR where the communication serves to initiate or perform a contract, and otherwise Art. 6(1)(f) GDPR. Our legitimate interest lies in offering the communication channel selected by you.
Use of WhatsApp is voluntary. You may contact us by email or phone instead at any time. Please do not send passwords, verification codes, payment data or other unnecessary highly confidential information via WhatsApp.
We have only limited influence over the independent processing of data by WhatsApp and Meta. Further information: WhatsApp Privacy Policy.
6. External Links to Social Networks
Our website contains a link to our WhatsApp Business account as well as icons or links to our profiles on Instagram, Threads, Facebook, YouTube, TikTok, LinkedIn and X. These are standard external links and not automatically loading social media plugins, embedded feeds or tracking pixels. Contact via WhatsApp is additionally explained in the section “Contact by Email, Phone and WhatsApp”.
As long as you do not click such a link, no connection to the respective social network is established solely because of the link. Only when you click the link do you leave our website and access the platform of the respective provider. The provider will generally receive your IP address, browser and device information, referrer, date and time of access and, where applicable, information about your user account on that platform. If you are logged in to the respective network, your visit may be associated with your account.
Instagram, Threads and Facebook
For users in the European Economic Area, the provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; the parent company is Meta Platforms, Inc., USA.
Further information can be found in the privacy information of Instagram and Threads as well as Facebook.
YouTube
For users in the European Economic Area, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, USA.
Further information can be found in the Google and YouTube Privacy Policy.
TikTok
For users in the European Economic Area, according to TikTok, TikTok Technology Limited, The Sorting Office, Ropemaker Place, Dublin 2, D02 HD23, Ireland, and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London EC1A 9HP, United Kingdom, are jointly responsible for the processing.
Further information can be found in the TikTok Privacy Policy.
The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; the parent company is LinkedIn Corporation, USA.
Further information can be found in the LinkedIn Privacy Policy.
X
For users in the European Economic Area, the provider is X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland; the parent company is X Corp., USA.
Further information can be found in the X Privacy Policy.
Legal Basis for External Links
Redirecting you to a social network only takes place as a result of your explicit action. The legal basis for providing the external links is Art. 6(1)(f) GDPR. Our legitimate interest lies in making our social media profiles accessible. The respective platform provider is generally responsible for the processing that takes place after you access the relevant platform.
If we use social media plugins, feeds or tracking pixels in the future that transmit data as soon as the page is loaded, we will only activate them after obtaining any required consent and will update this Privacy Policy accordingly before activation.
7. Customer, Contract and Payment Data
Contract Initiation and Performance
If you request an offer, enter into a contract with us or use our services, we process in particular master data, contact data, business data, location data, offer data, contract data, communication data, service data, billing data and payment data.
This may include in particular your name, business name, address, email address, phone number, Google Business Profile, selected plan, contract term, scope of services, investment amount, invoice information, payment status and the communication required to provide the agreed services.
The legal basis is Art. 6(1)(b) GDPR. Where we comply with statutory retention and documentation obligations, processing is based on Art. 6(1)(c) GDPR. Processing may additionally be based on Art. 6(1)(f) GDPR for the establishment, exercise or defense of legal claims.
Accounting and Professional Advisors
Billing, contract and booking data may be disclosed to tax advisors, accounting service providers, banks, payment providers or public authorities where this is necessary to process the contractual relationship, comply with legal obligations or protect our legal claims.
Stripe
We use Stripe to process investments and recurring payments. For customers in the European Economic Area, the provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Stripe may process in particular your name, email address, billing address, business, investment amount, currency, payment status, transaction identifiers and the data required for the selected payment method. Full credit card or bank account details are generally processed directly by Stripe and are not stored by us in full.
The legal basis is Art. 6(1)(b) GDPR. Where Stripe processes data under its own responsibility for fraud prevention, security or compliance with its own legal obligations, Stripe's privacy terms additionally apply.
Transfers to third countries are safeguarded in accordance with Stripe's contractual documentation, in particular on the basis of the EU-US Data Privacy Framework or Standard Contractual Clauses.
Further information can be found in the Stripe Privacy Policy.
8. SocialEdge App, User Accounts and Firebase
Provision of the SocialEdge App
Our customers can access the SocialEdge app at app.socialedge.ai. Within the app, we provide functions for managing accounts, business and location data, Google Business Profiles, rankings, reviews, activities, notifications and support cases.
The processing is carried out on the basis of Art. 6(1)(b) GDPR in order to provide the contractually agreed app and support services. Security and log data may additionally be processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of the app.
Firebase and Google Cloud
We use Firebase services provided by Google for essential functions of the app. For users in the European Economic Area, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, USA.
Depending on the app function used, Google or Firebase may process in particular user account, authentication, business, location, profile, communication, support, review, ranking, file, log, device and security data.
Firebase Authentication
We use Firebase Authentication for registration, login and management of user accounts. The data processed may include in particular your name, email address, login identifier, encrypted or hashed authentication information, verification status, login times, IP address, as well as security and device information.
According to Google, Firebase Authentication is provided as a global service and data processing may therefore also take place in the USA. Authentication data is consequently not processed exclusively in the Frankfurt region.
Cloud Firestore
We use Cloud Firestore to store operational app data. The database region configured by us is europe-west3 in Frankfurt. Depending on how the app is used, the data processed may include in particular account and contact data, business and location data, Google Business Profile data, support messages, activities, notifications, ranking and review data, as well as settings and preferences.
The selected region describes the primary storage location of the relevant Firestore data. Technical support, security, metadata or subprocessing activities may nevertheless also take place outside Germany or the European Economic Area.
Firebase Storage
Files uploaded through the app, in particular screenshots, images and evidence relating to support cases, are processed via Firebase Storage. The location configured by us is in the europe-west3 region in Frankfurt.
If you upload files, they should contain only the information necessary for the relevant support or service purpose. Unnecessary passwords, verification codes, payment data or particularly sensitive information should be removed or redacted before upload.
Log and Security Data
To detect errors, misuse, unauthorized access and technical disruptions, we may process IP addresses, timestamps, device and browser information, functions accessed, error messages and security-related events.
Third-Country Transfers and Further Information
Transfers to Google companies or subprocessors outside the European Economic Area are safeguarded in accordance with Google's contractual documentation, in particular on the basis of the EU-US Data Privacy Framework and Standard Contractual Clauses.
Further information can be found in the Google Privacy Policy, the Firebase Privacy Information and the Google Cloud Data Processing Addendum.
9. Management of Google Business Profiles
Manager Access and Managed Profile Data
As part of our services, our customers grant us manager access to their Google Business Profile. The customer or existing profile owner remains the owner of the profile. Manager access allows us to read, maintain and modify the agreed content and settings within the scope of the customer's instructions.
Depending on the scope of the engagement, we process in particular business and location data, contact details, opening hours, categories, service descriptions, posts, images, videos, links, statistics, ranking information, publicly visible reviews, responses to reviews, as well as support and verification information.
The legal basis is Art. 6(1)(b) GDPR. Where personal data is processed on behalf of the customer, SocialEdge acts as a Processor. Where required, a Data Processing Agreement pursuant to Art. 28 GDPR is concluded for this purpose.
Review Management
SocialEdge does not create, purchase, sell, falsify or manipulate customer reviews. We do not publish reviews under the identity of actual or fictitious customers and do not promise any specific number of positive reviews.
As part of the agreed services, we may analyze publicly visible reviews, prepare draft responses, support the customer in responding appropriately and assist with lawful measures aimed at generating authentic customer reviews.
Review of Reputation-Damaging Reviews in Plan 3
As part of Plan 3, we support customers in reviewing and reporting reviews that, in the customer's assessment, contain demonstrably false or reputation-damaging factual claims or may violate platform policies.
For this purpose, we may process publicly visible reviews, reviewer names, the date and time of the review, review content, internal information concerning the underlying circumstances, screenshots, supporting evidence and communication with the customer or Google. We coordinate the assessment of the circumstances and the required evidence closely with the customer.
SocialEdge cannot delete reviews itself. Whether Google reviews, restricts or removes a review is decided exclusively by Google. No specific review outcome or removal is guaranteed.
Suspensions, Restrictions and Video Verifications
The paid plans include support with suspensions, restrictions and video verifications of Google Business Profiles. Depending on the individual case, we review the possible cause, explain the required steps to the customer, assist with compiling supporting evidence or communicate directly with Google.
In this context, business, location, contact, profile, support, verification, image, video and supporting evidence data may be processed. Video recordings may show individuals, business premises, vehicles, work equipment, signage or other information required for verification.
The final verification, approval or reinstatement of a profile is decided exclusively by Google and cannot be guaranteed by SocialEdge.
Communication with Google
Where necessary to perform the engagement, we transmit the required profile, business, support and supporting evidence data to Google and communicate with the platform operator. For users in the European Economic Area, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, USA.
Google may process data under its own responsibility in accordance with its platform terms and privacy policies. Further information can be found in the Google Privacy Policy.
Planned Google Business Profile API Integration
In the future, our app may be connected to Google Business Profiles authorized by the customer through the Google Business Profile API. According to the current technical status, the API integration has not yet been activated.
Once activated, the app may, depending on the permissions actually requested and confirmed by the customer, read and modify profile, location, post, image, review, statistics and administration data.
Access takes place only after the customer's express authorization. The customer may revoke granted Google permissions through their Google account settings. Following revocation or termination of the contract, access tokens and operational copies that are no longer required shall be deleted or restricted in accordance with applicable statutory and contractual requirements.
Before the API is activated, this section will be updated based on the OAuth permissions, data fields, retention periods, deletion options and revocation options actually used.
Information received through Google APIs is used in accordance with the Google API Services User Data Policy.
10. Ranking and Competitor Analysis
Local Dominator
We use Local Dominator to analyze the local visibility of Google Business Profiles. The service enables, in particular, location-based ranking queries, grid analyses, competitor comparisons and documentation of ranking developments.
In this context, business name, location, address, Google Maps or profile identifier, categories, search terms, geographic coordinates, ranking positions, publicly visible competitor data, timestamps and technical usage information may be processed.
The processing is carried out for the provision of the contractually agreed Local SEO and Google Maps services on the basis of Art. 6(1)(b) GDPR. Where publicly available competitor information is analyzed, the processing may additionally be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in measuring and improving local visibility.
A Data Processing Agreement is in place with the provider, including the required provisions for possible transfers to third countries. Where data is processed outside the European Economic Area, such transfers are safeguarded in particular through Standard Contractual Clauses.
Ranking Reports and Forecasts
Ranking data represents a snapshot and may vary depending on search location, device, personalization, competition, Google updates and other factors. The analyses do not constitute a guarantee of any specific ranking position, visibility, number of inquiries or particular economic result.
11. CRM, System Emails and Newsletters
Brevo as CRM and Email Service
We use Brevo to manage prospect and customer contacts, to send transactional or system-related emails and to distribute newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Depending on how the service is used, Brevo processes in particular name, email address, phone number, company, customer status, communication history, consent status, list and segment assignments, sending and delivery status, as well as technical information relating to the use of emails.
CRM and Customer Communication
We use the CRM to process inquiries, document customer contacts, carry out pre-contractual measures and support existing customers. The legal basis is Art. 6(1)(b) GDPR. Where data is processed for the organization and improvement of our business processes, the processing may additionally be based on Art. 6(1)(f) GDPR.
Transactional and System-Related Emails
Brevo may be used to send necessary emails, for example account, security, support, appointment, contract or service-related information. The legal basis is Art. 6(1)(b) GDPR where the message is necessary for the performance of a contract. Security-related messages may additionally be based on Art. 6(1)(f) GDPR.
Newsletters and Double Opt-In
We only send promotional newsletters with your consent. We generally use a double opt-in procedure for newsletter registration. This means that you receive an email in which you must confirm your subscription. To document your consent, we may store in particular your email address, the time of registration and confirmation, your IP address and the registration text used.
The legal basis for sending newsletters is Art. 6(1)(a) GDPR. You may withdraw your consent at any time via the unsubscribe link included in the respective message or by contacting us. The withdrawal applies with effect for the future.
Open and Click Tracking
With your consent, our newsletters may contain tracking pixels and individualized links. This allows us to determine whether a message was delivered and opened and which links were clicked. The time, IP address, browser and device information may also be processed.
The analysis is used to measure the reach and relevance of our messages and to improve their content. The legal basis is Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.
Further Information
Where required, a Data Processing Agreement is in place with Brevo. Further information can be found in the Brevo Privacy Policy.
12. Use of Artificial Intelligence
Purposes and Categories of Data
We use AI-assisted services to provide our services efficiently. This includes in particular the creation and optimization of texts, images, posts, draft responses and recommendations, the analysis of Google Business Profiles, reviews, rankings and competitor data, as well as support for internal workflows and support processes.
Where required for the respective engagement, this may involve the processing of business, location, contact, profile, review, communication, image, support, ranking and analytics data. This may also include personal data, in particular names, publicly visible information relating to reviewers, review texts, contact person details, images and content from support cases.
We limit inputs to the information necessary for the respective purpose. Passwords, verification codes, full payment details, identification numbers, tax identification numbers and other unnecessary highly confidential data must not be entered into AI services. Where source data contains sensitive information that is not required, such information should be removed, redacted or pseudonymized before transmission.
Customer emails are not automatically read or autonomously answered by our AI services. AI-generated results are not used for decisions based solely on automated processing that produce legal effects or similarly significantly affect an individual.
Legal Bases and Roles
Processing is based on Art. 6(1)(b) GDPR where the use of AI is necessary to provide the contractually agreed service. For internal quality, efficiency and security purposes, processing may additionally be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the efficient and high-quality provision of our services.
Where SocialEdge processes data on behalf of a customer, AI providers are used only as contractually engaged subprocessors. For personal customer data, we exclusively use the business API or enterprise offerings described below. Consumer services are used only for general content that does not contain personal or confidential customer data.
OpenAI API
We use the OpenAI API to process personal customer data. The contracting entity for customers in the European Economic Area is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. Depending on the technical provision of the service, affiliated OpenAI entities and subprocessors, particularly in the USA, may be involved.
OpenAI processes inputs, uploaded content, technical metadata and generated outputs for the provision, security and abuse prevention of the API. According to OpenAI, data submitted through the API is not used by default to train or improve its models. ChatGPT Plus is used exclusively for general content that does not contain personal or confidential customer data.
Further information: OpenAI Privacy Policy, Business Data Privacy and OpenAI Data Processing Addendum.
Anthropic API
We use the API of Anthropic's Claude AI service to process personal customer data. The provider is Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA.
Anthropic processes inputs, uploaded content, technical metadata and outputs for the provision and security of the API. The Data Processing Addendum, including Standard Contractual Clauses, forms part of the commercial terms. Claude Pro is used exclusively for general content that does not contain personal or confidential customer data.
Further information: Anthropic Privacy Policy and Information about the Anthropic DPA.
Business Gemini Solution
For personal customer data, we exclusively use a business-grade and contractually safeguarded Gemini solution or a paid Gemini API provided by Google. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, USA.
Google processes inputs, uploaded content, technical metadata and outputs for the provision and security of the service. According to Google, content submitted through paid Gemini API services is not used to improve Google products. The free Gemini app is used exclusively for general content that does not contain personal or confidential customer data.
Further information: Google Privacy Policy, Information on Gemini API Data Retention and Google Cloud Data Processing Addendum.
Figma AI and Nano Banana
For AI-assisted image and design editing, we use Figma's native AI functionality, including the Google image model Nano Banana made available through it. The provider is Figma, Inc., 760 Market Street, Floor 10, San Francisco, CA 94102, USA.
Figma processes in particular uploaded images and designs, prompts, technical metadata and generated outputs. Figma may use subprocessors for this purpose. For Figma AI, Figma identifies, among others, Google LLC or Google Vertex as AI model providers; prompt inputs and outputs are processed. The setting allowing the use of our content for “Content Training” is disabled.
Transfers to third countries are safeguarded in particular through the EU-US Data Privacy Framework and the Standard Contractual Clauses contained in Figma's DPA.
Further information: Figma Privacy Policy, Figma Data Processing Addendum and Figma Subprocessors.
Responsibility for AI-Generated Results
AI-generated results may be inaccurate, incomplete or incorrect. They are therefore not used as a guarantee of any specific ranking, removal, verification or other decision by Google. Where results are published or used for customer-related measures, SocialEdge and the respective customer remain responsible, within their respective areas of responsibility, for reviewing the results and ensuring their lawful use.
13. Transfers to Third Countries
Some of the service providers we use are based outside the European Union or the European Economic Area, or use affiliated companies and subprocessors located there. As a result, personal data may in particular be transferred to or processed from the USA, the United Kingdom, Singapore or other third countries.
Depending on the specific function used, this includes in particular Webflow, Vercel, Google and Firebase, Stripe, Calendly, OpenAI, Anthropic, Figma, Ahrefs, Local Dominator, Meta, TikTok, X, LinkedIn and CDN providers.
Transfers to third countries only take place where the applicable legal requirements are met. Where the European Commission has adopted an adequacy decision for the relevant country, the transfer may be based on Art. 45 GDPR. For certified US companies, this may in particular include the EU-US Data Privacy Framework.
Where no applicable adequacy decision exists, we use appropriate safeguards pursuant to Art. 46 GDPR where required. These include in particular the European Commission's Standard Contractual Clauses as well as supplementary technical, contractual and organizational safeguards.
In exceptional cases, a transfer may be based on one of the conditions set out in Art. 49 GDPR, for example where the transfer is expressly necessary for the performance of a contract or where the data subject has expressly consented after having been informed in advance.
When selecting and using service providers, we take into account in particular the purpose of processing, categories of data, access possibilities, storage locations, subprocessors, contractual terms and available safeguards. Further details can be found in the relevant sections of this Privacy Policy and in the provider information linked there.
14. Retention Periods and Deletion
We store personal data only for as long as necessary for the respective purpose, for the performance of a contract, to protect legitimate interests or to comply with legal obligations. The data is then deleted or anonymized. Where data must continue to be retained as evidence, we restrict or limit its processing to the extent technically and organizationally possible.
The following standard retention periods apply in particular:
- Server and security logs: generally no longer than 30 days, unless a security incident or another legitimate retention reason exists;
- Consent records: for the duration of the consent and subsequently for up to three years in order to comply with statutory documentation obligations;
- General contact inquiries without a contract: up to three years after the last substantive communication;
- Business email and contract correspondence: up to six years where it is subject to statutory retention requirements as commercial or business correspondence;
- Prospect data in the CRM: up to three years after the last relevant contact, unless an earlier objection or other ground for deletion applies;
- Contract and customer data: for the duration of the contract and subsequently for the regular civil-law limitation period of up to three years; longer statutory retention periods remain unaffected;
- Operational app, ranking, review and Google Business Profile data: for the duration of the contract; after termination of the contract, operational copies that are no longer required are generally deleted or anonymized within 90 days. Data required as evidence of performance or claims may remain stored in restricted form for up to three years;
- Support messages: generally for up to three years after completion of the relevant matter or termination of the contract;
- Support uploads, screenshots and evidence: generally for up to 90 days after final completion of the relevant matter; evidence required for ongoing Google, legal or support proceedings is retained until completion and, where applicable, subsequently in restricted form for the applicable limitation period;
- Appointment booking data: generally for up to three years after the appointment; where a contractual relationship is established, the applicable contract retention periods shall apply;
- Newsletter data: until consent is withdrawn. Any required suppression record and evidence of consent may subsequently be retained for up to three years;
- Invoices and accounting records: generally eight years;
- Books, annual financial statements and certain tax-relevant documents: generally ten years;
- Backups: deleted operational data may remain in access-restricted backup copies until their regular overwrite cycle, generally for no longer than 90 days.
Where required by law, these periods begin only at the end of the calendar year in which the relevant event occurred or the document was created. Special statutory provisions may require longer retention, for example in the case of ongoing legal disputes, administrative proceedings, tax audits or other statutory retention restrictions.
If consent is withdrawn or a legitimate deletion request is submitted, we delete the affected data unless a prevailing statutory obligation or another legal basis requires continued restricted storage.
15. Changes to This Privacy Policy
We may update this Privacy Policy if our services, technical systems, service providers, legal requirements or data processing activities change. The version published on our website at the relevant time shall apply.
If changes affect an existing consent, we will obtain renewed consent where required by law. Changes to tools, service plans, API permissions, storage locations or data flows are reviewed before they are used in production and are reflected in this Privacy Policy accordingly.
Last updated: July 29, 2026