Legal details are not configured.
This page is incomplete until the operator sets: LEGAL_DPO, LEGAL_SUPERVISORY_AUTHORITY, LEGAL_GOVERNING_LAW, LEGAL_VENUE, LEGAL_DPA_URL.
Privacy Policy
Version 2026-10-04.2
1. Who is responsible (controller)
The controller for the processing described here (Art. 4(7) GDPR) is:
BizBrew UG (haftungsbeschränkt) i.G.
Mittenwalder Str. 10
12629 Berlin
Germany
Email: [email protected]
Phone: +49 176 26086067
Data protection officer: NOT CONFIGURED: LEGAL_DPO
This policy covers the website bizbrew.org and the accounts of businesses that sign up for BizBrew. When a business (a "tenant") uses BizBrew to manage its own customers, staff, bookings or payments, that business is the controller for its customers' data and we process it on its behalf under a data processing agreement. If you are a customer of such a business, please contact that business about your data; its own privacy notice applies.
2. What we process, why, and on what legal basis
Visiting the website
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in delivering and securing the website.
Website statistics
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding how the website is used.
Creating a business account
Legal basis: Art. 6(1)(b) GDPR — taking steps to enter into, and performing, the contract; Art. 6(1)(f) for bot and abuse protection.
Using BizBrew as a business
Legal basis: Art. 6(1)(b) GDPR — performing the contract; Art. 6(1)(c) for statutory retention of billing records.
Contact form and e-mails to us
Legal basis: Art. 6(1)(b) GDPR where your request concerns a contract, otherwise Art. 6(1)(f) — our interest in answering you.
Error monitoring and security
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, working service.
Providing the account data marked as required is necessary to conclude the contract; without it we cannot create an account. We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. We do not sell personal data or use it for advertising.
3. Recipients
We use the following service providers, bound by data processing agreements. Purpose, data, location and transfer safeguard of each are listed on our sub-processor page.
- Hetzner Online — Server hosting for the application, database (self-hosted Supabase/PostgreSQL), file storage and cache
- Cloudflare — DNS, CDN and TLS proxy, Turnstile bot protection, Web Analytics (cookieless) on the marketing site, R2 storage for database backups
- Stripe — Payment processing for subscriptions and for tenants' customer payments (Stripe Connect)
- Resend — Transactional e-mail to business account holders (sign-up, verification, billing)
- Hostinger — SMTP e-mail delivery to tenants' customers (booking confirmations, reminders, portal e-mails)
- Bird (MessageBird) — SMS and WhatsApp messages (phone verification, portal sign-in codes, reminders) (Only when SMS/WhatsApp messaging is used)
- Sentry (Functional Software) — Error monitoring for the marketing website and the admin and customer portal applications
- Google (Firebase Cloud Messaging, Google Calendar API) — Push notifications to the mobile apps; Google sign-in (OAuth) when a business connects a Google Calendar (Only when push notifications or a Google Calendar connection are used)
We also disclose data to authorities where we are legally obliged to.
4. Transfers outside the EU/EEA
Some of these providers, or their group companies, are located in or can access data from countries outside the EU/EEA, in particular the United States. Such transfers take place only on the basis of an adequacy decision (including the EU–U.S. Data Privacy Framework for certified companies) or the European Commission's standard contractual clauses (Art. 45, 46(2)(c) GDPR). The safeguard used for each provider is shown on the sub-processor page; you can request a copy of the safeguards from us.
5. How long we keep data
- Account data: for as long as your account exists. When you ask us to delete your account, we delete or anonymise the data unless we must keep it by law.
- Billing records and invoices: for the statutory retention periods under commercial and tax law, after which they are deleted.
- Contact requests: until your request is resolved, unless they become part of a contract.
- Server and security logs: only as long as needed to investigate errors and attacks.
- Database backups: deleted data can remain in off-site backups for up to 30 days before the backup itself is deleted.
6. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- have processing restricted (Art. 18);
- receive your data in a machine-readable format (Art. 20);
- object at any time, on grounds relating to your situation, to processing based on Art. 6(1)(f), and without giving reasons to direct marketing (Art. 21);
- withdraw any consent you gave, with effect for the future (Art. 7(3));
- lodge a complaint with a data protection supervisory authority (Art. 77), in particular in the EU member state of your residence, place of work or the place of the alleged infringement. The authority responsible for us is: NOT CONFIGURED: LEGAL_SUPERVISORY_AUTHORITY.
To exercise your rights, e-mail [email protected] or use our contact page.
7. Cookies and similar technologies
The marketing website sets no tracking or advertising cookies. If you choose a language with the language switcher, a cookie (bb_mkt_locale) remembers your choice for one year. Cloudflare may set strictly necessary security cookies to protect the site against attacks. Cloudflare Turnstile on the sign-up and contact forms evaluates technical browser signals to tell humans from bots.
The BizBrew application (your business workspace and customer portals) uses strictly necessary cookies to keep you signed in.
8. Changes to this policy
We update this policy when our processing changes. The current version and a history of changes are shown below. Where a change affects you materially, we inform account holders by e-mail.
Change history
- 4 October 2026 (2026-10-04.2) — Website statistics now run only with consent (banner and cookie settings); added the consent cookie, Sentry error monitoring on the website, and German, Spanish and French versions.
- 4 October 2026 (2026-10-04) — Restructured for GDPR Art. 13: controller and contact details, legal basis per purpose, full recipient list with transfer safeguards, retention, all data subject rights including complaint to a supervisory authority. Removed consent-by-use, the unbacked encryption and fixed-deletion-period statements, and the third-party country lookups on the signup page.
- 1 February 2026 (2026-02) — First published version.