Privacy Policy

For the SafePrompt website · Last updated: 14 September 2026

1. Controller

SchweitzerTech GmbH
Kärcherstr. 14
76185 Karlsruhe
Germany

Managing Director: Constantin Schweitzer
Email: privacy@safeprompt.eu

2. Scope

This policy applies to the public product, information, purchase and support pages at safeprompt.eu. The SafePrompt applications have additional product-specific notices:

3. Hosting and server logs

This website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. When a page is requested, the server processes connection data required for delivery, in particular the IP address, date and time, requested address, HTTP status, amount of data transferred, referrer, browser and operating-system details.

We process this data to deliver the website securely and reliably, prevent misuse and diagnose errors. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is secure and reliable operation. Server logs are deleted once no longer required for these purposes unless a legal obligation or specific security incident requires longer retention. STRATO acts as our processor.

4. Server-side audience statistics only

We count page views solely on our server. We process the requested page, date and hour, a coarse device and region category, and the referring domain. The IP address, user agent and language preference are processed with a secret key into a pseudonymous identifier that changes daily. The source values are not stored in the statistics database. The identifier cannot be linked across different days. Identifiers from earlier calendar days are deleted with the next page request. Aggregate counts may be retained for longer.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is privacy-conscious assessment of website use and reliability. We do not use a JavaScript tracker, analytics cookies, browser fingerprinting or a persistent visitor identifier for this purpose.

5. Technically necessary session

The website uses the PHPSESSID session cookie, in particular to retain the selected language and necessary navigation state during your visit. It is limited to the session, inaccessible to JavaScript and deleted when you close the browser. It is necessary to provide the function you requested (section 25(2)(2) TDDDG).

6. Locally hosted web resources

System fonts, Bootstrap and the Bootstrap Icons font are served directly from our server. A normal visit to the marketing pages therefore does not contact Google Fonts, jsDelivr, jQuery CDNs or an advertising network. No advertisements are embedded on the marketing pages.

7. Purchases through Paddle

When you open a purchase or checkout page, we integrate Paddle as payment provider and merchant of record. Paddle processes connection, device, payment, billing and transaction data and may set technically necessary cookies. The legal basis is Article 6(1)(b) GDPR and section 25(2)(2) TDDDG. Further information: Paddle Privacy Policy.

8. Licence and purchase data

To provide purchased licences, we process your email address, optional name, transaction identifier, licence key and technical licence-activation details. During checkout, these details may be stored temporarily in browser local storage so the licence and confirmation page can be matched reliably. They are removed there after the process is completed, or can be deleted at any time through your browser’s website-data controls. The legal basis is Article 6(1)(b) GDPR and section 25(2)(2) TDDDG.

Documents, text and anonymisation content are not processed through the marketing website. The product-specific notices linked above apply to processing within the applications.

9. Contact and support

If you contact us, we process your contact details and message to answer your enquiry. The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a contract or steps before entering into one, and otherwise Article 6(1)(f) GDPR. We delete the data once the matter is complete unless legal retention duties or legitimate reasons require longer storage.

10. Recipients and international transfers

Recipients are limited to providers who need data for the purposes described above, in particular hosting, email and payment providers. Where a provider processes data outside the European Economic Area, the transfer is based on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses.

11. Your rights and right to object

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction of processing and data portability. Where processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.

12. Right to lodge a complaint

You may lodge a complaint with a data-protection supervisory authority. Our competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany: baden-wuerttemberg.datenschutz.de.

13. Encryption

Transmission between your browser and this website is encrypted using TLS.