Scripe 4.0 is here!

|

Read the update

Privacy Notice pursuant to Art. 13, 14 GDPR

Version: July 2026

We, Scripe GmbH, (hereinafter: "the Company", "we" or "us") would like to inform you here about data protection in our company.

Within the scope of our responsibility under data protection law, the entry into force of the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter: "GDPR") has imposed additional obligations on us to ensure the protection of the personal data of the person affected by a processing operation (in the following, we also address you as the data subject using the terms "customer", "user", "you" or "data subject"*).

*The German version of this notice refrains from the simultaneous use of the male, female and diverse (m/f/d) language forms for reasons of better readability. All personal designations apply equally to all genders.

To the extent that we decide, either alone or jointly with others, on the purposes and means of data processing, this includes above all the obligation to inform you transparently about the nature, scope, purpose, duration and legal basis of the processing (cf. Art. 13 and 14 GDPR). With this statement (hereinafter: "Privacy Notice" or "Privacy Notices"), we inform you about the manner in which your personal data are processed by us.

Our Privacy Notices are structured in a modular fashion. They consist of a general part applying to any processing of personal data and any processing situations by us, and of specific parts whose content relates in each case only to the processing situation specified there, naming the respective offering or product.

To be able to find the parts relevant to you, please note the following overview of the structure of these Privacy Notices:

A. General Information

I. Definitions

Modelled on Art. 4 GDPR, these Privacy Notices are based in particular on the following definitions:

"Personal data" (Art. 4 No. 1 GDPR) means any information relating to an identified or identifiable natural person ("data subject"). A person is identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data or by means of information on his or her physical, physiological, genetic, mental, economic, cultural or social identity. Identifiability may also be given by means of a combination of such information or other additional knowledge. The manner in which the information came about, its form or its embodiment is irrelevant (photographs, video or audio recordings may also contain personal data).

"Processing" (Art. 4 No. 2 GDPR) means any operation involving the handling of personal data, whether or not by automated (i.e. technology-supported) means. This includes in particular the collection (i.e. the procurement), recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction of personal data, as well as the change of an objective or purpose on which a data processing operation was originally based.

"Controller" (Art. 4 No. 7 GDPR) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

"Third party" (Art. 4 No. 10 GDPR) means any natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or processor, are authorised to process the personal data; this also includes other legal persons belonging to the same group of companies.

"Processor" (Art. 4 No. 8 GDPR) means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller, in particular in accordance with the controller's instructions (e.g. IT service providers). Within the meaning of data protection law, a processor is in particular not a third party.

"Consent" (Art. 4 No. 11 GDPR) of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes in the form of a statement or of another clear affirmative action by which the data subject signifies agreement to the processing of personal data relating to him or her.

II. Controller

The controller under data protection law within the meaning of Art. 4 No. 7 GDPR for the processing of personal data on https://scripe.io/ (in short, the "Website") is us, i.e.

Scripe GmbH Bismarckstraße 68a 12157 Berlin E-mail: hello@scripe.io

For further details about our company, please refer to the imprint information on our website https://scripe.io/imprint.

For matters relating to data protection, you can reach us by post at the above address with the addition "– Data Protection –" or by e-mail at privacy@scripe.io.

II.a Our Roles: Controller and Processor

Depending on the processing situation, we act either as controller (Art. 4 No. 7 GDPR) or as processor (Art. 4 No. 8, Art. 28 GDPR):

1. Scripe as controller. For the following processing operations, we determine the purposes and means ourselves and are therefore the controller; these Privacy Notices relate to these processing operations:

  • operation of our Website and our social media profiles;
  • registration, administration and authentication of user accounts;
  • contract administration, billing and payment processing;
  • ensuring the security and stability of our services and preventing their misuse;
  • product analytics, error diagnostics and improvement of our services;
  • our own marketing and sales activities (e.g. newsletter, CRM);
  • compliance with our own statutory obligations (e.g. retention obligations under commercial and tax law);
  • the processing of publicly accessible LinkedIn data for the product-wide inspiration and benchmark feature described in B.II.6.m.bb.

2. Scripe as processor. To the extent that business customers (e.g. companies, agencies and their teams) use Scripe within a shared workspace, we process the workspace content arising in this context on behalf of and in accordance with the instructions of the respective customer. This concerns in particular:

  • content, drafts, media and knowledge bases that the customer and its users contribute to Scripe;
  • the LinkedIn accounts linked by the customer's users, including the profile, post and analytics data retrieved via these accounts;
  • the planning, publication and evaluation of posts as well as the engagement features configured by the customer.

In these cases, the respective customer is the controller within the meaning of the GDPR; we process the data exclusively for the provision of the contractually agreed services on the basis of our data processing agreement pursuant to Art. 28 GDPR (available at https://scripe.io/dpa; the current list of our sub-processors can be found at https://scripe.io/subprocessors). Data subjects whose data are processed in such a customer workspace (e.g. employees of a customer) should primarily contact the respective customer as controller to exercise their data subject rights; however, we will of course also be happy to assist you directly at privacy@scripe.io.

3. Joint controllership. Joint controllership (Art. 26 GDPR) exists exclusively with regard to the operation of our own social media profiles (see Section C.), in particular our LinkedIn company page, jointly with LinkedIn Ireland Unlimited Company. There is no joint controllership for the processing of data within the Scripe application — neither with our customers nor with LinkedIn; LinkedIn is an independent controller for the processing on the LinkedIn platform.

In principle, any processing of personal data is only permitted if the data processing falls under one of the following legal justifications:

Art. 6 (1) (a) GDPR ("Consent"): If the data subject has indicated, freely, in an informed manner and unambiguously, by means of a statement or another clear affirmative action, his or her agreement to the processing of personal data concerning him or her for one or more specific purposes;

Art. 6 (1) (b) GDPR: If the processing is necessary for the performance of a contract to which the data subject is party, or in order to take pre-contractual steps at the request of the data subject;

Art. 6 (1) (c) GDPR: If the processing is necessary for compliance with a legal obligation to which the controller is subject (e.g. a statutory retention obligation);

Art. 6 (1) (d) GDPR: If the processing is necessary in order to protect the vital interests of the data subject or of another natural person;

Art. 6 (1) (e) GDPR: If the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or

Art. 6 (1) (f) GDPR ("Legitimate interests"): If the processing is necessary for the purposes of the legitimate (in particular legal or economic) interests of the controller or of a third party, except where such interests are overridden by the conflicting interests or rights of the data subject (in particular where the data subject is a minor).

The storage of information in the end user's terminal equipment or access to information already stored in the terminal equipment is only permitted if covered by one of the following legal justifications:

§ 25 (1) TDDDG (German Act on Data Protection and Privacy in Telecommunications and Digital Services): If the end user has consented on the basis of clear and comprehensive information. Consent must be given in accordance with Art. 6 (1) (a) GDPR;

§ 25 (2) No. 1 TDDDG: If the sole purpose is to carry out the transmission of a communication over a public telecommunications network;

§ 25 (2) No. 2 TDDDG: If the storage or access is strictly necessary in order for the provider of a telemedia service to provide a telemedia service expressly requested by the user.

For the processing operations carried out by us, we indicate the applicable legal basis in each case below. A processing operation may also be based on several legal bases.

IV. Data Erasure and Storage Period

For the processing operations carried out by us, we indicate below in each case how long the data are stored by us and when they are erased or blocked. Unless an explicit storage period is stated below, your personal data will be erased or blocked as soon as the purpose or the legal basis for the storage ceases to apply, unless you have given us your consent to further storage.

It should be noted in this regard that our business relationships with our customers are also based on continuing obligations, which are established for an indefinite period.

However, storage may take place beyond the stated period in the event of a (threatened) legal dispute with you, for the preservation of evidence within the framework of the statute of limitations (under §§ 195 et seq. of the German Civil Code (BGB), these limitation periods can be up to 30 years, with the standard limitation period being three years) or other legal proceedings, or if storage is provided for by statutory provisions to which we are subject as controller (e.g. § 257 of the German Commercial Code (HGB), § 147 of the German Fiscal Code (AO)).

When the retention period prescribed by the statutory provisions expires, the personal data will be blocked, anonymised or erased, unless further storage by us is necessary and there is a legal basis for it.

V. Data Security

We use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties, taking into account the state of the art, the costs of implementation and the nature, scope, context and purpose of the processing as well as the existing risks of a data breach (including its likelihood and impact) for the data subject. Our security measures are continuously improved in line with technological developments.

All communication with our Website and our application is encrypted in transit using current versions of the TLS (Transport Layer Security) protocol. Data stored by us at rest is additionally encrypted at the infrastructure level by our hosting providers (managed database, object storage, backups); further technical and organisational measures are described in Annex 2 of our data processing agreement (https://scripe.io/dpa).

Unfortunately, the transmission of information via the internet is not completely secure, which is why we cannot guarantee the security of data transmitted to our Website via the internet.

VI. Cooperation with Processors and Other Service Providers

Like any larger company, we also use external domestic and foreign service providers to handle our business transactions (e.g. in the areas of IT, logistics, telecommunications, sales and marketing). These act only on our instructions and have been contractually obligated within the meaning of Art. 28 GDPR to comply with the provisions of data protection law, insofar as these service providers are not themselves controllers within the meaning of Art. 4 No. 7 GDPR.

An up-to-date overview of the sub-processors used by us can be found at https://scripe.io/subprocessors. Insofar as we act as a processor for business customers (see A.II.a), our data processing agreement pursuant to Art. 28 GDPR, available at https://scripe.io/dpa, additionally applies.

VII. Transfer of Personal Data to Third Countries

In the course of our business relationships, your personal data may be passed on or disclosed to service providers and other recipients that may also be located outside the European Economic Area (EEA), i.e. in third countries. Such processing takes place exclusively for the fulfilment of contractual and business obligations and to maintain your business relationship with us. The legal bases are in principle Art. 6 (1) (a), (b) and/or (f), in each case in conjunction with Art. 44 et seq. GDPR. We will inform you about the respective details of the transfer below at the relevant points.

The European Commission certifies, by means of so-called adequacy decisions, that some third countries provide data protection comparable to the EEA standard (a list of these countries and a copy of the adequacy decisions are available here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en.

In other third countries to which personal data may be transferred, however, there may not be a consistently high level of data protection due to a lack of legal provisions. Where this is the case, we take care to ensure that data protection is adequately guaranteed. This is possible, for example, through binding corporate rules, standard data protection clauses of the European Commission for the protection of personal data pursuant to Art. 46 (1), (2) (c) GDPR (the 2021 standard contractual clauses are available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0915&locale-en), certificates or recognised codes of conduct.

A transfer of data to third countries by us therefore only takes place,

insofar as this is necessary for the handling of your inquiry, the execution of your order and the performance of the contract existing between you and us,

if this takes place within the framework of processing on our behalf (Art. 28 GDPR),

otherwise only insofar as you have given us your consent for this or this is necessary for the fulfilment of our statutory or contractual obligations or to safeguard legitimate interests of us or of third parties.

If, under the aforementioned conditions, a data transfer is made to a third country (a country outside the EU/EEA) and, in the assessment of the European Commission, this third country ensures an adequate level of data protection (Art. 45 GDPR), the transfer of your personal data may take place on this basis.

In the case of transfers to third countries for whose level of data protection no such adequacy decision exists, the protection of your personal data is ensured as far as possible by appropriate safeguards within the meaning of Art. 46 GDPR, in particular by the standard data protection clauses adopted by the EU Commission pursuant to Art. 46 (2) (b) GDPR and any additional safeguards.

Otherwise, we will only transfer your data to a third country if the data transfer can be based on Art. 49 GDPR, i.e. in particular if

you have explicitly consented to the proposed data transfer after having been informed of the possible risks of such data transfers for you,

the transfer is necessary for the performance of a contract between you and us or for the implementation of pre-contractual measures taken at your request,

the transfer is necessary for the conclusion or performance of a contract concluded in your interest by us with another natural or legal person,

the transfer is necessary for the establishment, exercise or defence of legal claims.

VIII. Automated Decision-Making (Including Profiling)

Insofar as we have been granted consent to process personal data for advertising purposes, we carry out partially automated analyses of the communication and usage behaviour of the visitors of our Website in order to gain insights about the respective user, so that we can optimise our Website and our web application Scripe.

In principle, we do not intend to use personal data collected from you for a procedure of automated decision-making (including profiling) within the meaning of Art. 22 GDPR.

We would inform you of any exceptions to this principle at the appropriate point in the information below.

Due to statutory requirements, we are obliged to combat money laundering and fraud. In this context, data analyses (including for payment transactions) are also carried out. These measures also serve your protection at the same time. If, in individual cases, we use purely automated processing operations to bring about a decision — including profiling — we will inform you of this in connection with the respective application.

IX. Obligation to Provide Personal Data

As a matter of principle, we do not make the conclusion of contracts with us conditional on you providing us with personal data beforehand. As a customer, you are in principle also under no statutory or contractual obligation to provide us with your personal data.

However, it may be the case that we can only provide certain services to a limited extent or not at all if you do not provide the data required for this.

As a (potential) customer, you would therefore have to provide those personal data that are necessary for the establishment, performance and termination of a business relationship and the fulfilment of the associated contractual or other obligations, or which we are legally obliged to collect. So that we can meet our obligations, you must provide us with the necessary information and documents and notify us without undue delay of any changes arising in the course of the business relationship.

If you do not provide us with the necessary information, we or your other contractual partners may not be able to fulfil the obligations resulting from the business relationship. Without these data, we or your other contractual partners will therefore, as a rule, have to refuse to conclude a contract or to carry out another order, or will no longer be able to perform an existing contract.

X. Statutory Obligation to Transmit Certain Data

Under certain circumstances, we may be subject to a special statutory or legal obligation to make the lawfully processed personal data available to third parties, in particular public bodies (Art. 6 (1) (c) GDPR).

XI. Your Rights

You may assert your rights as a data subject regarding your processed personal data against us at any time. As a data subject, you have the right, subject to the statutory requirements:

pursuant to Art. 15 GDPR, to request information about your data processed by us. In particular, you may request information about the processing purposes, the category of data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if they were not collected by us, as well as the existence of automated decision-making including profiling and, where applicable, meaningful information about its details;

pursuant to Art. 16 GDPR, to request without undue delay the rectification of inaccurate data or the completion of your data stored by us;

pursuant to Art. 17 GDPR, to request the erasure of your data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;

pursuant to Art. 18 GDPR, to request the restriction of the processing of your data, insofar as the accuracy of the data is contested by you or the processing is unlawful;

pursuant to Art. 20 GDPR, to receive your data that you have provided to us in a structured, commonly used and machine-readable format, or to request their transmission to another controller ("data portability");

pursuant to Art. 21 GDPR, to object to the processing, insofar as the processing is based on Art. 6 (1) (e) or (f) GDPR. This is in particular the case if the processing is not necessary for the performance of a contract with you. Unless the objection concerns direct marketing, when exercising such an objection we ask you to set out the reasons why we should not process your data in the way we have been doing. In the event of your justified objection, we will examine the situation and will either discontinue or adapt the data processing or demonstrate to you our compelling legitimate grounds on the basis of which we will continue the processing;

pursuant to Art. 7 (3) GDPR, to withdraw from us at any time your once-given consent — i.e. your voluntary intention, made comprehensible in an informed manner and unambiguously by means of a statement or another clear affirmative action, that you agree to the processing of the personal data in question for one or more specific purposes — including consent given before the GDPR became applicable, i.e. before 25.5.2018, if you have given such consent. The consequence of this is that we may no longer continue, for the future, the data processing that was based on this consent. You may therefore withdraw your consent at any time, without any formal requirements, with effect for the future, e.g. by e-mail to privacy@scripe.io or by a notification to any of the contact points named in A.II.

pursuant to Art. 77 GDPR, to complain to a data protection supervisory authority about the processing of your personal data in our company, e.g. to the supervisory authority responsible for us: Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59-61, 10555 Berlin, Tel.: +49 30 13889-0, Fax: +49 30 215 50 50, e-mail: mailbox@datenschutz-berlin.de

XII. Changes to These Privacy Notices

In the course of the further development of data protection law as well as technological or organisational changes, our Privacy Notices are regularly reviewed to determine whether they need to be adapted or supplemented. We reserve the right to change these data protection provisions at any time with effect for the future.

You will be informed of changes in particular on our website at https://scripe.io/privacy.

B. Website

I. Function of the Website

Information about our company and the services we offer can be found in particular at https://scripe.io/ together with the associated subpages (hereinafter collectively: the "Website").

When you visit our Website, personal data relating to you are processed.

When you visit and use the Website, the following categories of personal data are collected, stored and further processed by us.

We process the personal data described in more detail below in accordance with the provisions of the GDPR, the other applicable data protection provisions and only to the extent necessary.

Insofar as the processing of the personal data is based on Art. 6 (1) (f) GDPR, the stated purposes also constitute our legitimate interests.

1. Log Data; Website Operation

a) Log Data

When you visit our Website, a so-called log record (so-called server log files) is stored temporarily and in anonymised form on our web server. This may consist of the following data:

website/application from which the Website was requested (so-called referrer URL) name and URL of the requested page date and time of your access to the Website description of the type, language and version of the web browser used IP address of your requesting internet-enabled device your internet service provider files downloaded from our Website (e.g. PDF or Word documents) amount of data transferred operating system of your requesting internet-enabled device message as to whether the access was successful (access status/HTTP status code) GMT time zone difference

The processing of the log data serves statistical purposes and the improvement of the quality of our Website, in particular the stability and security of the connection. The legal basis is Art. 6 (1) (f) GDPR.

b) Website Operation

For the operation of our Website (display of the Website, hosting), we use the services of the providers "Vercel" (Scripe infrastructure, frontend) and "Railway" (backend) of our processors Vercel Inc., 440 N Barranca Ave Suite 4133 Covina, CA 91723 United States, and Railway Corp., 2135 California St San Francisco, CA 94115 United States.

In addition to aggregated personal usage data, the aforementioned companies also collect non-identifying personal data of the visitor or user of our Website regarding device, operating system, internet browser, screen resolution, language and keyboard settings, internet service provider, referring and exit pages and date/time stamps, etc., see https://vercel.com/docs/speed-insights/privacy-policy

They also process personal data of the users of our Website (e.g. your IP address) and data that you enter, such as name, e-mail address, telephone number.

Vercel and Railway use this information to provide the Website and the associated functionalities and services to us and thus to the visitors and users of our Website as well as to our customers.

We have concluded a data processing agreement pursuant to Art. 28 GDPR with each of Vercel and Railway, see https://vercel.com/legal/dpa and https://railway.app/legal/dpa. Further information on data processing by Vercel and Railway can be found at https://vercel.com/legal/privacy-policy and https://railway.app/legal/privacy.

2. (Contact) Forms; Other Inquiries

When you use the forms available on our Website (e.g. "Scripe Community"), the "form data" apparent from the respective form, entered by you or "attached" to your message and thereby transmitted are processed (e.g. gender, first name, surname, e-mail address, address, telephone, your message, time of transmission).

In the case of inquiries or other contact by e-mail and telephone, the personal data you provide in this context (e.g. name, telephone number) are processed.

We process the data transmitted via our forms (e.g. contact and sales inquiries) within our own IT systems and, for the purpose of handling your inquiry, in our customer relationship management system (CRM) "HubSpot"; further details on HubSpot can be found under B.II.6.i). For sending the associated e-mails, we use the service "Resend" (see B.II.6.i).

The legal bases for the data processing operations are in each case Art. 6 (1) (a), (b) and/or (f) GDPR and, in the case of the storage of information in the end user's terminal equipment and access to information already stored in the terminal equipment, § 25 (1) or (2) No. 2 TDDDG (German Act on Data Protection and Privacy in Telecommunications and Digital Services).

3. Newsletter, Weekly LinkedIn Insights; Other E-Mails

With your consent, we use your data for advertising purposes, e.g. for sending advertising e-mails. In doing so, we process mandatory information such as your e-mail address, but also information that you provide to us voluntarily. We use the voluntary information to be able to address you in an individualised manner. The data processing takes place on the basis of your consent pursuant to Art. 6 (1) (a) GDPR in order to provide you with the requested advertising messages.

For example, in addition to the purely informational use of our Website, we offer a subscription to our newsletter, with which we inform you about current developments in the areas of our expertise as well as about new offers and events. If you sign up for our newsletter, the following "newsletter data" are collected, stored and further processed by us:

website/application from which the Website was requested (so-called referrer URL) date and time of your access to the Website description of the type, language and version of the web browser used IP address of your requesting internet-enabled device your e-mail address and any further data entered by you the date and time of the sign-up and confirmation

In addition, when the newsletter is sent, we evaluate your user behaviour. For this evaluation, the e-mails sent contain so-called web beacons or tracking pixels, which are one-pixel image files stored on our Website. For the evaluations, we link the aforementioned data and the web beacons with your e-mail address and an individual ID. Links contained in the newsletter also contain this ID.

The newsletter data are processed for the purpose of sending the newsletter. By signing up for our newsletter, you consent to the processing of your personal data. The legal basis is Art. 6 (1) (a) GDPR; for transfers to the USA, the safeguards described under A.VII apply, in particular the EU Standard Contractual Clauses concluded with our e-mail service provider.

Insofar as we remind you by e-mail in certain situations (e.g. if you do not complete the onboarding) of the services offered by us or of the actions still outstanding on your part, this takes place on the basis of Art. 6 (1) (a), (b) and (f) GDPR.

The storage of the newsletter data and the sending of the newsletter/e-mails take place using the service "ActiveCampaign" of the provider ActiveCampaign, LLC, 1 North Dearborn St 5th Floor Chicago, IL 60602, see https://www.activecampaign.com/de.

You can view ActiveCampaign's privacy policy on the ActiveCampaign website at https://www.activecampaign.com/legal/privacy-policy. The data processing agreement ("Data Processing Addendum") that we have concluded with ActiveCampaign is available at https://www.activecampaign.com/legal/dpa. The service providers used by ActiveCampaign in the data processing operations and further details on the data processed by them can be found here: https://www.activecampaign.com/legal/subprocessors. Should you have difficulties with the English language, please contact us.

For the sign-up to our newsletter, we use the so-called double opt-in procedure: after your sign-up, we send an e-mail to the e-mail address provided, in which we ask you to confirm that you wish to receive the newsletter. The purpose of this procedure is to be able to prove your sign-up and, if necessary, to clarify any possible misuse of your personal data.

In addition, we and ActiveCampaign each store the IP addresses used by you and the times of the sign-up and confirmation. The purpose of this procedure is to be able to prove your sign-up and, if necessary, to clarify any possible misuse of your personal data.

The only mandatory information is your name and your e-mail address. After your sign-up, these data are processed for the purpose of sending the e-mails. The provision of further, separately marked data is voluntary and is used to be able to address you personally.

We point out that ActiveCampaign may also transfer personal data to third countries with potentially inadequate levels of data protection and process them there, where far-reaching possibilities of access by authorities to (personal) data of data subjects, not limited to the extent necessary, could exist, against which sufficient legal remedies might not be available.

You may withdraw your consent to the sending of the newsletter and other e-mails at any time. You may declare the withdrawal by clicking on the link provided in every newsletter e-mail, by e-mail to hello@scripe.io or by a message to the contact details stated in A.II.

If you withdraw your consent, your personal data will be anonymised within 30 days, unless there is another legal ground for the further processing of your personal data.

The services of ActiveCampaign are used on the basis of your consent pursuant to § 25 (1) TDDDG and Art. 6 (1) (a) GDPR as well as a data processing agreement pursuant to Art. 28 GDPR including the EU Standard Contractual Clauses

4. Registration and Sign-In; Account Deletion; Clerk

On our Website, you have the option of registering (sign up, https://scripe.io/signup) and, after registration, signing in (sign in, https://scripe.io/signin).

For user management, in particular the authentication and authorisation of users, we use the service "Clerk" of Clerk, Inc., 660 King St Unit 345, San Francisco, CA 94107 US, privacy@clerk.dev, to which all data provided during registration and sign-in are transmitted and where they are further processed by Clerk.

Clerk's privacy notices are available at https://clerk.com/legal/privacy and https://clerk.com/legal/dpf, and the data processing agreement ("Data Processing Agreement") can be found at https://clerk.com/legal/terms.

As "representative of controllers or processors not established in the Union" pursuant to Art. 27 GDPR, Clerk has designated "VeraSafe", i.e. VeraSafe Ireland Ltd, Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23AT2P, Ireland. VeraSafe can also be contacted at privacy@clerk.dev or here: https://verasafe.com/public-resources/contact-data-protection-representative.

If you wish to use the functions of the Scripe service, it is necessary that you create a user account and sign in there.

Mandatory information for the registration is your first and last name as well as your e-mail address. These data are used to set up your user account, to grant access to your user account and to manage it.

Mandatory information for the sign-in is your e-mail address, to which we send you a numeric sign-in code valid for one-time use (one-time password). Providing the e-mail address is mandatory in order to be able to match you with the data in our customer database.

We process your data for the above purposes for the performance of a contract or in order to take pre-contractual steps pursuant to Art. 6 (1) (b) GDPR.

Alternatively, you can sign in via your account with Google. If you register/sign in via your Google account, Google will transmit your name, your e-mail address, your language setting and, where applicable, your profile picture to us. For the sign-in service, Google acts as an independent controller; the data processing by Google is beyond our sphere of influence, and we can assume no responsibility for compliance with data protection requirements there. Google's privacy notices can be found at https://policies.google.com/privacy.

If you choose to sign in via Google, the legal basis for the associated processing by us is Art. 6 (1) (b) GDPR (performance of the contract or pre-contractual measures at your request).

You can delete your account under "Manage Account", "Security".

5. (Trial) Orders

On our Website, you have the option of placing (trial) orders.

For this purpose, you must enter your "billing data", i.e. depending on the payment method, first name, surname, company (if applicable), e-mail address, street, house number, postcode, city, country and, where applicable, VAT ID number, your credit card number or your PayPal details.

Mandatory information necessary for the conclusion and performance of a contract is marked separately; further information is voluntary.

For the organisational execution of your order, for contract management and invoicing, we use the cloud-based SaaS (software-as-a-service) service "Stripe" of Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, California, 94080, USA, and Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, respectively.

The "billing data" to be entered by you are processed by us and Stripe for the purposes of handling your inquiry, carrying out pre-contractual measures for the use of our services and, where applicable, fulfilling one or more contracts with you in the course of the execution of your order(s); the legal basis is Art. 6 (1) (b) GDPR.

We have concluded a data processing agreement with Stripe, which you can find at https://stripe.com/de/legal/dpa. Further information on data processing by Stripe can be found at https://stripe.com/de/privacy.

6. Scripe

The "Scripe" service offered by us converts your audio files containing spoken texts, as well as other texts, using artificial intelligence ("AI"), into written texts that you can publish (possibly in modified form) on LinkedIn.

Through the consistent creation of content, personalised by means of AI on the basis of your information ("3-step onboarding" and subsequent inputs), your visibility on LinkedIn is intended to be increased.

With various functions, Scripe enables the storage of text, audio and video ("Media Library"), collaboration in teams ("Collaboration"), the creation of the texts, the planning ("Smart Calendar") and the realisation of their publication ("Posts") on LinkedIn.

Scripe enables the analysis of your data published on LinkedIn and visible to every user, as well as of the performance of your posts. The results of the analyses are visualised and stored and used, among other things, for tips to improve your visibility and the performance of your posts.

In processing the data, we cooperate with several processors and other service providers:

a) Hosting and Infrastructure (Vercel, Railway, PlanetScale, AWS)

For the operation of the application, the storage and further processing of the data transmitted by you to us, we use the following infrastructure service providers:

"Vercel" (frontend hosting) of Vercel Inc., 440 N Barranca Ave Suite 4133, Covina, CA 91723, USA, see https://vercel.com/legal/privacy-policy, data processing agreement at https://vercel.com/legal/dpa.

"Railway" (backend hosting and Redis caching) of Railway Corp., 2135 California St, San Francisco, CA 94115, USA, see https://railway.app/legal/privacy, data processing agreement at https://railway.app/legal/dpa.

"PlanetScale" (database for storing user data, recordings and posts) of PlanetScale, Inc., 535 Mission Street 14th Floor, San Francisco, California, 94105, USA, see https://planetscale.com/legal/privacy, data processing agreement at https://planetscale.com/legal/data-processing-addendum.

"AWS" (file and media storage as well as backup via Amazon Simple Storage Service – S3) of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. The storage location of your data is EU-West, Frankfurt am Main. Privacy notices at https://aws.amazon.com/de/privacy/, data processing agreement ("AWS Data Processing Addendum") at http://aws.amazon.com/agreement.

b) Deepgram

For the transcription of audio to text (speech-to-text), we use the service "Deepgram" of Deepgram, Inc., 1748 Market St, Suite 100, San Francisco, CA 94102, USA, to which the audio data transmitted by you are transferred.

Deepgram's privacy notices can be viewed at https://deepgram.com/privacy, https://developers.deepgram.com/docs/data-privacy-compliance and https://deepgram.com/privacy/subprocessors.

c) Microsoft Azure (Azure OpenAI Service; Azure AI Foundry with Claude models)

For artificial intelligence, machine learning and the associated processing of the data, we use the "Azure OpenAI Service" and "Azure AI Foundry" (see https://azure.microsoft.com/de-de/products/ai-services/openai-service) of Microsoft Corporation, 1 Microsoft Way, Redmond, WA 98052-8300, USA. Via Azure AI Foundry, in addition to OpenAI models (e.g. GPT), we also use the "Claude" AI models of Anthropic, PBC; all model requests are processed within the Microsoft Azure infrastructure — the contractual partner and processor is Microsoft; no direct transmission to Anthropic takes place. The Azure regions used by us are located in the EU (Germany, Sweden) and in the USA. The data used to create or edit your content (e.g. a publication on LinkedIn) are transferred to these services.

We use the AI models in such a way that your content is not used to train the providers' base models (Microsoft enterprise terms, no training by default).

Microsoft's privacy notices are available at https://privacy.microsoft.com/de-de/privacystatement, and the data processing agreement ("Data Processing Addendum") at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

d) Additional AI Services (fal.ai, ElevenLabs, Exa, Braintrust)

For individual AI functions, we additionally use the following services:

"fal.ai" (generation of images and other media) of Features and Labels, Inc., 1111B S Governors Ave, STE 27434, Dover, DE 19904, USA, see https://fal.ai/privacy-policy.

"ElevenLabs" (AI speech synthesis) of ElevenLabs, Inc., 169 Madison Ave #2484, New York, NY 10016, USA, see https://elevenlabs.io/de/privacy.

"Exa" (AI-supported web research) of Exa Labs, Inc., San Francisco, CA, USA, see https://exa.ai/privacy-policy.

"Braintrust" (quality assurance and observability of our AI functions; prompts and model outputs may be logged in this context) of Braintrust Data, Inc., San Francisco, CA, USA, see https://www.braintrust.dev/legal/privacy-policy.

e) Pinecone

For the storage and searching of vector representations ("embeddings") of your content (e.g. for content-related recommendations and search), we use the service "Pinecone" of Pinecone Systems, Inc., 12 E 49th St, 17th Floor, New York, NY 10017, USA.

Pinecone's privacy notices can be viewed at https://www.pinecone.io/privacy/, and the data processing agreement ("Data Processing Addendum") at https://www.pinecone.io/legal/.

f) Pusher

For real-time notifications within the application (WebSockets), we use the service "Pusher" of Pusher Ltd, 160 Old Street, London EC1V 9BW, United Kingdom.

Pusher's privacy notices can be viewed at https://pusher.com/legal/privacy/, and the data processing agreement at https://pusher.com/legal/dpa/.

g) Product Analytics and Feature Flags (Mixpanel, Statsig, Meta)

For the analysis of the use of our application, the control of features as well as reach and conversion measurement, we use:

"Mixpanel" (product analytics) of Mixpanel, Inc., One Front Street, 28th Floor, San Francisco, CA 94111, USA, see https://mixpanel.com/legal/privacy-policy/. The processing takes place via Mixpanel's EU data residency. To improve our application, interaction recordings of the use of the application (session replays, heatmaps) may also be created in this context.

"Statsig" (feature flags, A/B tests) of Statsig, Inc., Bellevue, WA, USA, see https://www.statsig.com/privacy.

We use Mixpanel and Statsig as functional product instrumentation in order to operate, secure and improve our application. The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in the functionality, stability and further development of our product — and, insofar as information is stored on or accessed in your terminal equipment for this purpose, § 25 (2) No. 2 TDDDG.

For advertising and conversion measurement, we additionally use the following services only with your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG), which you can give via the cookie banner and withdraw at any time in the cookie settings:

"Meta Pixel" and "Conversions API" (reach and conversion measurement) of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, see https://www.facebook.com/privacy/policy.

"LinkedIn Insight Tag" (reach and conversion measurement for LinkedIn campaigns) of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, see https://www.linkedin.com/legal/privacy-policy.

"FirstPromoter" (affiliate/referral attribution on our website) of FirstPromoter S.R.L., Cluj-Napoca, Romania; see B.II.6.k for further details.

h) Intercom

For the operation of our chatbot and for customer support, we use the service "Intercom" of Intercom R&D Unlimited Company, 2nd Floor, Stephen Court, 18-21 St. Stephen's Green, Dublin 2, Republic of Ireland.

Intercom's privacy notices are available at https://www.intercom.com/legal/privacy, the data processing agreement ("Data Processing Addendum") can be found at https://www.intercom.com/legal/data-processing-agreement, see also the further (data protection) information at https://www.intercom.com/legal/terms-and-policies#terms.

i) CRM and E-Mail (HubSpot, Resend, ActiveCampaign)

For customer management and the sending of e-mails, we use:

"HubSpot" (customer relationship management – CRM) of HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA, see https://legal.hubspot.com/privacy-policy, data processing agreement at https://legal.hubspot.com/dpa.

"Resend" (sending of transactional e-mails, e.g. confirmation and notification e-mails) of Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA, see https://resend.com/legal/privacy-policy, data processing agreement at https://resend.com/legal/dpa.

"ActiveCampaign" (newsletter and e-mail marketing) of ActiveCampaign, LLC, 1 North Dearborn St 5th Floor, Chicago, IL 60602, USA; further details can be found under B.II.3.

j) Churnkey

In connection with the management and cancellation of subscriptions, we use the service "Churnkey" of Churnkey, Inc., USA.

Churnkey's privacy notices can be viewed at https://www.churnkey.co/legal/privacy.

k) FirstPromoter

For the operation of our affiliate and referral programme, we use the service "FirstPromoter" of FirstPromoter S.R.L., Cluj-Napoca, Romania.

FirstPromoter's privacy notices can be viewed at https://firstpromoter.com/privacy.

l) Integrations (Slack, Notion, WhatsApp)

Insofar as you actively initiate this, you can connect Scripe with third-party services. In doing so, personal data are transmitted to the respective provider:

"Slack" (notifications and engagement features) of Slack Technologies Limited / Salesforce, Inc., see https://slack.com/intl/de-de/trust/privacy/privacy-policy.

"Notion" (integration with Notion workspaces) of Notion Labs, Inc., 2300 Harrison St, San Francisco, CA 94110, USA, see https://www.notion.so/notion/Privacy-Policy.

"WhatsApp" (transmission of audio/text messages to Scripe via the WhatsApp Business Platform) of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, see https://www.whatsapp.com/legal/privacy-policy.

m) LinkedIn

aa) Linking Your LinkedIn Account; Publication and Analytics

You can publish your posts on "LinkedIn". The LinkedIn service is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

The linking of your LinkedIn account with Scripe takes place exclusively via LinkedIn's official OAuth procedure: you sign in directly with LinkedIn and grant there the permissions that Scripe requires for publishing posts (including on company pages managed by you), for retrieving your basic profile data and for retrieving post history, follower and page statistics. Posts are published, and engagement actions you configure are performed, via LinkedIn's official APIs using the permissions you grant. In addition, we retrieve and process profile, post and performance data for your connected accounts — including publicly accessible LinkedIn content — in order to provide the analytics, post-history and content features. We store the access tokens issued in this process in order to maintain the connection; you can revoke the connection at any time in Scripe or in your LinkedIn settings. At no time do we receive your LinkedIn credentials (password).

Information on data processing by LinkedIn is available at https://www.linkedin.com/legal/privacy-policy?_l=de_DE. The data processing agreement between us and LinkedIn Ireland Unlimited Company can be viewed here: https://legal.linkedin.com/dpa/DE.

bb) Processing of Publicly Accessible LinkedIn Data (Including Data of Third Parties); Information pursuant to Art. 14 GDPR

Scripe offers an inspiration and benchmark feature that is based on a corpus of publicly accessible LinkedIn posts and associated author profiles ("viral posts corpus"). For this purpose, we also process personal data of persons who are not themselves Scripe users (external authors): name, profile headline, profile picture, profile URL, occupational and company details, follower counts as well as their publicly published posts including public interaction metrics. The source of these data is exclusively publicly accessible LinkedIn content.

The purposes of the processing are the provision of content inspiration, trend and benchmark analyses for our customers. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest and that of our customers lies in the analysis of publicly available professional content. Posts of external authors are automatically deleted after 18 months at the latest.

Please note: your own posts publicly published on LinkedIn may also — just as they are visible to everyone on LinkedIn — be displayed to other Scripe users in this feature as examples or benchmarks.

As a data subject, you may object at any time to the processing of your publicly accessible LinkedIn data in this feature (Art. 21 GDPR), e.g. by e-mail to privacy@scripe.io; we will then remove your data from the corpus. Your further rights under A.XI. remain unaffected.

n) Additional Infrastructure, Media and Notification Services

In addition, we use the following services:

"Cloudflare Images" (delivery and caching of images, e.g. post images and profile pictures) of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, see https://www.cloudflare.com/privacypolicy/, data processing agreement at https://www.cloudflare.com/cloudflare-customer-dpa/.

"Upstash" (serverless Redis for rate limiting and queues of our API) of Upstash, Inc., San Francisco, CA, USA, see https://upstash.com/trust/privacy.

"Axiom" (technical logging and web vitals measurement) of Axiom, Inc., San Francisco, CA, USA, see https://axiom.co/privacy.

"Sentry" (error monitoring and performance diagnostics) of Functional Software, Inc. (Sentry), San Francisco, CA, USA, see https://sentry.io/privacy/; processing takes place via Sentry's EU ingest.

"Sanity" (content delivery for parts of our marketing website) of Sanity AS, Oslo, Norway, see https://www.sanity.io/legal/privacy.

"Expo" (delivery of push notifications of the Scripe mobile app) of 650 Industries, Inc. (Expo), Palo Alto, CA, USA, see https://expo.dev/privacy; delivery takes place technically via the push services of Apple (APNs) and Google (FCM), respectively.

"Giphy" (GIF search in the post editor; your search queries are transmitted directly from your browser to Giphy) of Giphy, Inc. (Shutterstock, Inc.), New York, NY, USA, see https://support.giphy.com/hc/en-us/articles/360032872931-GIPHY-Privacy-Policy.

"Unsplash" (stock photo search in the post editor; search queries are forwarded via our servers) of Unsplash (Squarespace, Inc.), New York, NY, USA, see https://unsplash.com/privacy.

"Mux" (streaming of videos on our marketing website) of Mux, Inc., San Francisco, CA, USA, see https://www.mux.com/privacy.

"YouTube Data API" (retrieval of video metadata when you use YouTube links as a content source) of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, see https://policies.google.com/privacy.

III. Duration of Data Processing

Your data are only processed for as long as this is necessary to achieve the processing purposes stated above; the legal bases stated in the context of the processing purposes apply accordingly.

Regarding the use and storage duration of cookies, please note point B.V.

Third parties engaged by us will store your data on their systems for as long as is necessary in connection with the provision of the services for us in accordance with the respective assignment.

Further details on the storage period can otherwise be found under A.IV.

IV. Categories of Recipients and Transfers to Third Countries

The following (further) categories of recipients, which as a rule are processors (see A.VI. in this regard), may receive access to your personal data:

Service providers for the operation of our Website and the processing of the data stored or transmitted by the IT systems (e.g. for data centre services, customer care, payment processing, IT security). The legal basis for the transfer is Art. 6 (1) (b) or (f) GDPR (where applicable in conjunction with Art. 49 (1) (b), (c), (e) GDPR), insofar as they are not processors anyway;

State bodies/authorities, insofar as this is necessary to fulfil a legal obligation. The legal basis for the transfer is Art. 6 (1) (c) GDPR;

Persons engaged in the conduct of our business operations (e.g. auditors, banks, insurance companies, legal advisers, supervisory authorities, parties involved in company acquisitions or the formation of joint ventures). The legal basis for the transfer is Art. 6 (1) (b) or (f) GDPR.

For the safeguards ensuring an adequate level of data protection in the event of a transfer of the data to third countries, see A. VII.

Beyond this, we only pass on your personal data to third parties if you have given your explicit consent pursuant to Art. 6 (1) (a) GDPR (where applicable in conjunction with Art. 49 (1) (a) GDPR).

We have carefully selected the service providers who, as processors, process data for us on our behalf and subject to our instructions and who are thus recipients of personal data; they offer sufficient guarantees of appropriate technical and organisational measures and are contractually obligated by us in accordance with Art. 28 GDPR.

We regularly transmit your personal data to the following processors and other service providers:

Type of processing

Company

Registered office

Privacy information

Frontend hosting / web infrastructure Vercel Inc. USA https://vercel.com/legal/privacy-policy
Backend hosting, Redis caching Railway Corp. USA https://railway.app/legal/privacy
Database (user data, recordings, posts) PlanetScale, Inc. USA https://planetscale.com/legal/privacy
File/media storage and backup (S3) Amazon Web Services EMEA SARL LUX (EU-West, Frankfurt) https://aws.amazon.com/de/privacy/
User management, authentication Clerk, Inc. USA https://clerk.com/legal/privacy
Sign-in via Google Google Ireland Ltd. IRL https://policies.google.com/privacy
Payment processing, contract and invoice management Stripe, Inc. USA https://stripe.com/de/privacy
In-app purchases (iOS) Apple Inc. USA https://www.apple.com/legal/privacy/
Cancellation/retention flow Churnkey, Inc. USA https://www.churnkey.co/legal/privacy
AI / machine learning (Azure OpenAI) Microsoft Corporation USA https://privacy.microsoft.com/de-de/privacystatement
AI / machine learning (Claude models, provided via Microsoft Azure AI Foundry) Microsoft Corporation (models of Anthropic, PBC) USA / EU https://privacy.microsoft.com/de-de/privacystatement
Audio transcription (speech-to-text) Deepgram, Inc. USA https://deepgram.com/privacy
AI image/media generation Features and Labels, Inc. (fal.ai) USA https://fal.ai/privacy-policy
AI speech synthesis ElevenLabs, Inc. USA https://elevenlabs.io/de/privacy
AI-supported web research Exa Labs, Inc. USA https://exa.ai/privacy-policy
AI quality assurance / observability Braintrust Data, Inc. USA https://www.braintrust.dev/legal/privacy-policy
Vector database (embeddings of content) Pinecone Systems, Inc. USA https://www.pinecone.io/privacy/
Real-time notifications (WebSockets) Pusher Ltd UK https://pusher.com/legal/privacy/
Product analytics Mixpanel, Inc. USA https://mixpanel.com/legal/privacy-policy/
Feature flags / A/B tests Statsig, Inc. USA https://www.statsig.com/privacy
Reach/conversion measurement (Pixel, Conversions API), WhatsApp Meta Platforms Ireland Ltd. IRL https://www.facebook.com/privacy/policy
Reach/conversion measurement (LinkedIn Insight Tag) LinkedIn Ireland Unlimited Company IRL https://www.linkedin.com/legal/privacy-policy
Newsletter, e-mail marketing ActiveCampaign, LLC USA https://www.activecampaign.com/legal/privacy-policy
Transactional e-mails Plus Five Five, Inc. (Resend) USA https://resend.com/legal/privacy-policy
CRM HubSpot, Inc. USA https://legal.hubspot.com/privacy-policy
Chatbot / customer support Intercom R&D Unlimited Company IRL https://www.intercom.com/legal/privacy
Affiliate/referral programme FirstPromoter S.R.L. RO https://firstpromoter.com/privacy
Slack integration Slack Technologies Ltd. / Salesforce, Inc. USA https://slack.com/intl/de-de/trust/privacy/privacy-policy
Notion integration Notion Labs, Inc. USA https://www.notion.so/notion/Privacy-Policy
Social media / publication LinkedIn Ireland Unlimited Company IRL

https://www.linkedin.com/legal/privacy-policy?_l=de_DE https://legal.linkedin.com/dpa/DE

Image CDN (post and profile images) Cloudflare, Inc. USA https://www.cloudflare.com/privacypolicy/
Serverless Redis (API rate limiting, queues) Upstash, Inc. USA https://upstash.com/trust/privacy
Technical logging, web vitals Axiom, Inc. USA https://axiom.co/privacy
Push notifications mobile app (delivery via Apple APNs / Google FCM) 650 Industries, Inc. (Expo) USA https://expo.dev/privacy
GIF search (post editor) Giphy, Inc. (Shutterstock, Inc.) USA https://support.giphy.com/hc/en-us/articles/360032872931-GIPHY-Privacy-Policy
Stock photo search (post editor) Unsplash (Squarespace, Inc.) USA https://unsplash.com/privacy
Video streaming (marketing website) Mux, Inc. USA https://www.mux.com/privacy
Video metadata (YouTube content sources) Google Ireland Ltd. IRL https://policies.google.com/privacy

V. Use of Cookies, Other Services on Our Website

1. Cookies, Tracking

On our Website, we use cookies. Cookies are data records that are assigned to the browser you use and stored on your storage medium by means of a characteristic character string, and through which certain information flows to the entity setting the cookie. A cookie usually contains the name of the domain from which the cookie data were sent as well as information about the age of the cookie and an alphanumeric identifier.

Cookies cannot execute programs or transfer viruses to your computer (or other device, e.g. tablet, mobile phone) and therefore cannot cause any damage. They serve to recognise the user's device, to make any preferences immediately available and to make our online offering as a whole more user-friendly and effective, i.e. more pleasant for you, by enabling us to offer you a better service tailored to you.

They enable us to recognise your device when you return to our Website and thereby to store information about your preferred activities on the Website, thus aligning our Website with your individual interests. This can also speed up the processing of your requests.

Cookies may therefore contain data that make it possible to recognise the device used. In some cases, however, cookies also contain only information on certain settings that cannot be related to a specific person. However, cookies cannot directly identify a user.

A distinction is made between session cookies, which are deleted as soon as you close your browser, and persistent cookies, which are stored beyond the individual session.

Further information on the cookies used and the possibility of giving your consent, where applicable, is provided by a corresponding pop-up tool when you visit our Website.

Any use of cookies that is not strictly technically necessary constitutes data processing that is only permitted with your consent — which can be withdrawn at any time with effect for the future — pursuant to Art. 6 (1) (a) GDPR, § 25 (1) TDDDG (German Act on Data Protection and Privacy in Telecommunications and Digital Services).

Beyond this, we only pass on your personal data processed by means of cookies to third parties if you have given consent pursuant to Art. 6 (1) (a) GDPR (where applicable in conjunction with Art. 49 (1) (a) GDPR).

You can also visit our Website without cookies. If you do not wish to use cookies, you can completely deactivate or restrict them in your browser. However, this may lead to functional restrictions of our Website.

The following links provide further information on deactivating or managing your cookie settings and on deleting cookies in the browser you use:

Google Chrome: https://support.google.com/chrome/answer/95647

Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences; http://support.mozilla.com/de-de/kb/Enabling%20and%20disabling%20cookies

Internet Explorer: http://windows.microsoft.com/en-GB/windows-vista/Block-or-allow-cookies; https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies

Microsoft Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d

Safari: http://help.apple.com/safari/mac/8.0/#/sfri11471; OS X: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac; iOS: https://support.apple.com/de-de/HT201265

We process your personal and non-personal data for the technical provision of our Website on the basis of Art. 6 (1) (f) GDPR. Our legitimate interest consists in obtaining and documenting your consent to data processing.

We retain your preferences and the related consents given, where applicable, in the consent manager for 12 months.

2. Social Media

On our Website, we do not use any social media plugins. Insofar as our web pages contain icons of social media providers (e.g. of "LinkedIn" and "Instagram"), we use these only for passive linking to the pages of the respective providers.

Our Website contains the following links to websites operated jointly with or by third-party providers:

https://www.linkedin.com/company/scripe https://www.instagram.com/scripe.io/

This privacy statement applies to the processing of personal data by such third-party providers in addition to the privacy statements of these third-party providers. Please note that we can assume no responsibility for the content of third-party websites or for compliance with data protection requirements there.

We give you the opportunity to communicate directly with Instagram and LinkedIn via the links and to interact with other users, so that we can improve our offering and make it more interesting for you as a user.

The legal basis for the linking and the resulting processing of your data is Art. 6 (1) (f) GDPR. We point out that Instagram and LinkedIn may also transfer personal data to third countries with potentially inadequate levels of data protection and process them there, where far-reaching possibilities of access by authorities to (personal) data of data subjects, not limited to the extent necessary, could exist, against which sufficient legal remedies might not be available.

Only if you click on the respective link and thereby give a corresponding consent do Instagram and LinkedIn receive the information that you have accessed the corresponding website of our online offering. In addition, the log data are transmitted. By activating the link, personal data relating to you are thus transmitted to Instagram and LinkedIn and stored there. Since these third-party providers collect data in particular via cookies, we recommend that you delete all cookies via the security settings of your browser before clicking on one of the aforementioned links, unless you wish to consent to the data transfer anyway.

Further information on the purpose and scope of the data collection and its processing by these third-party providers can be found below in the information on our social media presences (C.) and in their privacy statements. There you will also find further information on your rights and setting options for protecting your privacy.

3. Data Protection and Third-Party Websites

Our Website may contain hyperlinks to and from websites of third parties. If you follow a hyperlink to one of these websites, please note that we can assume no responsibility or guarantee for third-party content or data protection conditions. Please make sure of the data protection conditions applicable in each case before you transmit personal data to these websites.

C. Social Media

I. General Information

We maintain publicly accessible profiles in various social networks (https://www.linkedin.com/company/scripe, https://www.instagram.com/scripe.io/).

Your visit to these profiles sets in motion a multitude of data processing operations. Below, we provide you with an overview of which of your personal data are collected, used and stored by us when you visit our profiles.

You are not obliged to provide us with your personal data. However, this may be necessary for individual functionalities of our profiles in social networks. These functionalities are not available to you, or only to a limited extent, if you do not provide us with your personal data.

When you visit our profiles, your personal data are collected, used and stored not only by us, but also by the operators of the respective social network. This also happens if you do not have a profile in the respective social network yourself. The individual data processing operations and their scope differ depending on the operator of the respective social network, and they are not necessarily traceable for us.

We point out that Instagram and LinkedIn may also transfer personal data to third countries with potentially inadequate levels of data protection and process them there, where far-reaching possibilities of access by authorities to (personal) data of data subjects, not limited to the extent necessary, could exist, against which sufficient legal remedies might not be available.

For instance, when you visit our web pages at the respective third-party provider, Instagram and LinkedIn place cookies on your device, which remain effective for a period of up to two years unless they are deleted beforehand. The purpose of these cookies is to store information in the web browser. Instagram and LinkedIn process the information stored in the cookies, store the data collected about you as usage profiles and use these for purposes of advertising, market research and/or the demand-oriented design of their websites. Such an evaluation takes place in particular (also for users who are not logged in) for the display of demand-oriented advertising and to inform other users of the social networks about your activities on our website.

You have a right to object to the creation of these user profiles; to exercise it, you must contact Instagram and LinkedIn.

The data transfer takes place regardless of whether you have an account with Instagram and LinkedIn and are logged in there. If you are logged in with these providers, the data collected about you on our site are directly assigned to your existing account with the respective provider.

If you use our profiles in social networks to contact us (e.g. by creating your own posts, reacting to one of our posts or by sending private messages to us), the data you provide to us are processed by us exclusively for the purpose of being able to get in contact with you. The legal bases for the data collection are therefore Art. 6 (1) (a) and (b) GDPR.

We delete stored data as soon as their storage is no longer necessary or you request us to delete them; in the case of statutory retention obligations, we restrict the processing of the stored data accordingly.

Otherwise, we have no influence on the data collected and the data processing operations, nor are we aware of the full scope of the data collection, the purposes of the processing or the storage periods. Nor do we have any binding information on the deletion of the collected data by Instagram and LinkedIn.

II. Information About the Collection of Personal Data

1. Instagram

Instagram is an online service for sharing photos and videos and for interacting with other users. The Instagram service for users in the EU is provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

We maintain a public Instagram profile at https://www.instagram.com/scripe.io/. When you visit, comment on or interact with this profile, Meta processes personal data as an independent controller under Meta's own terms and privacy policy. If you contact us via Instagram (e.g. by direct message or comment), we process the data you provide solely to respond to you. The legal bases are Art. 6 (1) (a) and (b) GDPR.

We may use aggregated insights about the use of our Instagram profile that Meta makes available to page operators. Conclusions about individual users are not possible for us on that basis. Further information on data processing by Meta/Instagram is available at https://privacycenter.instagram.com/policy/.

2. LinkedIn

LinkedIn is an internet-based social network for maintaining existing business contacts and establishing new business connections. Depending on the account type, various functions are offered, e.g. profile creation, networking with other users, search functions, messaging services, job search.

The LinkedIn service is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

We use the statistical information (the extent of interactions, statistics on the age composition and the working relationships of our visitors) about the use of our LinkedIn page, which LinkedIn makes available in anonymised form via its statistics service. Conclusions about individual users and access to individual user profiles by us are not possible.

We process the following personal data:

Your LinkedIn user name as well as comments on our LinkedIn page and messages that you send us via our LinkedIn page.

Your activity on our LinkedIn page via the LinkedIn statistics service, e.g. the extent of interactions, statistics on the age composition and the working relationships of our visitors.

Other information that is necessary to answer inquiries from our visitors or to uniquely identify our visitors in our systems.

The purpose of the data processing of our LinkedIn presence is to provide information about our company, our products and services, combined with the possibility for users to interact with us. The legal basis is Art. 6 (1) (f) GDPR and, in the case of the storage of information in the end user's terminal equipment and access to information already stored in the terminal equipment, § 25 (2) No. 2 TDDDG. Our legitimate interest is in particular our business interest in sharing information with our users and being able to communicate with them.

Through the visit to its website, LinkedIn receives the information that you have accessed the corresponding subpage of our website. In addition, the log data explained in these Privacy Notices are transmitted. This takes place regardless of whether LinkedIn provides a user account via which you are logged in, or whether no user account exists. If you are logged in to LinkedIn, your data are directly assigned to your account. If you do not wish the assignment to your profile at LinkedIn, you must log out before activating the button.

With regard to the operation of our LinkedIn presence, we are joint controllers with LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

The data processing agreement between us and LinkedIn Ireland Unlimited Company can be viewed here: https://legal.linkedin.com/dpa/DE.

It cannot be ruled out that data of LinkedIn users are also processed outside the European Union:

In this respect, LinkedIn invokes "legally provided mechanisms to lawfully transfer data across borders". Specifically, for the transfer of personal data between LinkedIn Ireland Unlimited Company or its customers and LinkedIn Corporation, reference is made to the standard contractual clauses approved by the European Commission, see https://www.linkedin.com/legal/privacy-policy?_l=de_DE under "Cross-border data transfers" and https://www.linkedin.com/help/linkedin/answer/62533?trk=microsites-frontend_legal_privacy-policy&lang=de

Further information on the purpose and scope of the data collection and its processing by LinkedIn can be found in LinkedIn's privacy policy. There you will also find further information on your rights and setting options for protecting your privacy:

LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; further information on data processing by LinkedIn https://www.linkedin.com/legal/privacy-policy?_l=de_DE.

D. (Potential) Customers

For (potential) customers, the following privacy notices additionally apply:

I. General Processing Purposes

The business purpose of Scripe GmbH is the development and marketing of "Scripe", a web application for writing and publishing LinkedIn posts, which are created by means of transcription of the spoken word or other texts of the user into written text and, using artificial intelligence, personalised for the user taking into account the user's specifications and templates. Through the consistent creation of content, personalised by means of AI on the basis of the user's information and subsequent inputs, visibility on LinkedIn is intended to be increased. Scripe enables the analysis of the data published on LinkedIn and visible to every user, as well as of the performance of the user's posts. The results of the analyses are visualised and stored and used, among other things, for tips to improve the visibility and performance of the customer's posts.

Which data are processed in detail and in what manner they are used depends largely on the contractual or other obligational relationships between you and us.

II. Sources of the Data; Processed Data (Categories)

We primarily process data that you provide to us. These are, for example,

customer data (e.g. surnames, first names, addresses, contact details, billing/payment data, account data, order data);

billing data (e.g. first name, surname, company, e-mail address, telephone number, street, house number, postcode, city, country and VAT ID number).

In addition, we process — insofar as necessary for the fulfilment of our contractual and statutory obligations — personal data that we permissibly receive from third parties, e.g. from our processors.

Furthermore, we process personal data that we may permissibly obtain and process from publicly accessible sources (e.g. commercial and association registers, internet, media).

We also process data that are processed and transmitted to us within the framework of the contracts concluded with us through products provided to you and services rendered to you. These are — usually in addition to the data mentioned above — among others

IT usage data (e.g. logging of user activities, communication processes, log files);

data constituting your already published and potential LinkedIn posts, i.e. your voice and any (audio/video/text/image) data mentioned by you in the post or otherwise transmitted.

Insofar as you give us consent to the processing of personal data for specific purposes (e.g. contact via e-mail or telephone, newsletter, advertising, customer retention, payment, transfer of your data to service providers), the lawfulness of this processing is given on the basis of your consent, Art. 6 (1) (a) GDPR (where applicable in conjunction with Art. 49 (1) (a) GDPR).

The processing of personal data also takes place in the context of pre-contractual measures carried out at the request of prospective customers, as well as in the context of the performance of contracts with you, Art. 6 (1) (b) GDPR (where applicable in conjunction with Art. 49 (1) (b), (c) GDPR). The purposes of the data processing are primarily determined by the (potential) contract. These are generally service contracts and contracts of a mixed type, so that the data processing serves in particular the handling of orders, the transmission of the data to any third-party providers, the provision of our services during the term of the contracts and payment processing.

Furthermore, the processing of your data takes place to fulfil legal obligations, Art. 6 (1) (c) GDPR, to which we are subject, for example under the statutory retention periods pursuant to § 147 AO (German Fiscal Code) and § 257 (4) HGB (German Commercial Code).

Furthermore, we process your data to safeguard legitimate interests of us or of third parties pursuant to Art. 6 (1) (f) GDPR, e.g. for the assertion of legal claims and defence in legal disputes, to ensure the IT security and IT operations of Scripe GmbH, for advertising and for our quality management, in particular by obtaining customer reviews and evaluating the results.

IV. Further Categories of Recipients; Transfers to Third Countries

Within Scripe GmbH, those persons receive access to your data who need them to fulfil our contractual and statutory obligations and to safeguard legitimate interests of us or of third parties. Processors engaged by us (Art. 28 GDPR) may also receive your data for these purposes.

Under the statutory conditions, the following (further) recipients of your personal data may, for example, come into consideration:

our processors and our other service partners and vicarious agents, e.g. service providers for IT, postal services, telecommunications, payment transactions, advertising, artificial intelligence, machine learning, web/file hosting/clouds.

your (potential) contractual partners, e.g. credit institutions, credit card companies;

public bodies and institutions, e.g. tax authorities;

LinkedIn.

A transfer of data to countries outside the European Economic Area (so-called third countries) only takes place by us under the conditions stated in A.VII.

Please contact us if anything is unclear or if you have any questions.

Your team at Scripe GmbH