Privacy Policy
Information about how we handle your data
Last updated: January 2026
1. Privacy at a Glance
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified.
2. Responsible Party
The responsible party for data processing on this website is:
Balane GmbH
Balanstraße 84
81541 München
Germany
Managing Director: Jonas David Höttler
E-Mail: contact@balane.tech
3. Hosting
This website is hosted by Vercel Inc. (San Francisco, USA). When using the website, technical data (IP address, browser type, access time) is recorded in server logs. Data transfer to the USA is based on the EU-US Data Privacy Framework, for which Vercel is certified.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in reliable website delivery).
Server Log Files
When you access this website, data is automatically collected that your browser transmits and stored in log files of our hosting provider (Vercel): IP address, date and time of access, name and URL of the file retrieved, amount of data transferred, HTTP status code, browser used including version, operating system, referrer URL. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in trouble-free operation and IT security). This data is not combined with other data sources. Retention: 14 days, then automatic deletion. In case of concrete indications of abusive use (e.g. brute-force, DDoS) we reserve the right to retain individual log entries longer.
SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the "https://" in your browser's address bar and by the lock icon. When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data Collection on This Website
Website Analytics (Umami)
This website uses Umami, a privacy-friendly, self-hosted analytics solution. We operate Umami on the Railway platform in the Amsterdam data center (Netherlands, EU). The tracking script is loaded only after your explicit consent via the cookie banner (§ 25 TTDSG). You can withdraw your consent at any time via the cookie banner. Umami:
- Does not collect personal data
- Does not use cookies
- Does not store IP addresses
- Is fully GDPR compliant
Registration / Contact Form
When you register with us or contact us, your information will be stored for processing the request and in case of follow-up questions. This data will not be shared without your consent.
Sign in with Apple
As an alternative to email-based registration, you can sign in using your Apple ID (Sign in with Apple). Apple authenticates you and transmits the following data to us: an anonymized Apple user identifier, your email address (or, if you selected "Hide My Email", an Apple-generated relay address in the format @privaterelay.appleid.com) and — only upon the very first sign-in — optionally your first and last name. We receive no further data from Apple; in particular, no contact details, location, or device identifiers. Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. Legal basis: Art. 6(1)(b) GDPR (contract initiation/performance) and, insofar as you consented to the sign-in, Art. 6(1)(a) GDPR. Third-country transfers are based on the EU-US Data Privacy Framework and supplementary Standard Contractual Clauses. You can revoke the connection at any time in your Apple ID settings (appleid.apple.com → "Sign in with Apple"). Details: https://www.apple.com/legal/privacy/en-ww/.
5. External Services
Supabase (Database)
For storing user data, we use Supabase. Data is stored on servers in Frankfurt, Germany (EU).
Stripe (Payment Processing)
For payment processing, we use Stripe. Stripe is PCI-DSS Level 1 certified. We do not store complete credit card data ourselves.
Zammad (Support System)
For support requests, we use Zammad, a self-hosted ticket system. The system runs on servers of Hetzner Online GmbH in Germany. No transfer to third countries takes place. When creating a support ticket, your name, email address, and message are stored.
Brevo (Email Delivery)
For sending transactional emails (e.g., registration confirmation, password reset), we use Brevo (formerly Sendinblue). Processing takes place on EU servers. Data processed: email address, name, and email content.
Odoo CRM (Lead Management)
For managing contact requests, we use Odoo CRM. The system is self-hosted on servers in Germany (Hetzner). No data is transferred to third countries.
AI Services (Text Generation)
For optional AI-assisted text generation when creating proposals, the following services may be used: OpenAI (USA), Anthropic (USA), and Mistral AI (France). Usage is voluntary and requires an active user action. Legal basis: Art. 6(1)(b) GDPR (contract performance) resp. Art. 6(1)(f) GDPR (legitimate interest in AI functionality). Data transfer to the USA is based on the EU-US Data Privacy Framework (Commission Adequacy Decision of 10 July 2023) and, additionally, EU Standard Contractual Clauses (SCC, 2021/914). Data Processing Agreements (DPA) are in place. Only content strictly necessary for the respective generation is transmitted; providers do not use the data for model training (API access).
Transfers to Third Countries
Some of the services we use (in particular the AI providers, Stripe, and Brevo) process data in the United States. Legal basis for transfer: (1) the European Commission's Adequacy Decision on the EU-US Data Privacy Framework (DPF, effective 10 July 2023) for certified providers, supplemented by (2) EU Standard Contractual Clauses (SCC) pursuant to Implementing Decision 2021/914. Data Processing Agreements (DPA) under Art. 28 GDPR are in place with all processors. Copies of the safeguards applied are available on request.
Processing of Customer Data (B2B Users as Controllers)
Insofar as you, as a business user of our software, enter data of your own customers (names, email, address, invoice items), you act as the data controller vis-à-vis these end-customers (Art. 4(7) GDPR). We process this data exclusively on your behalf and in accordance with your instructions (Art. 28 GDPR). The Data Processing Agreement (DPA) is part of our General Terms and Conditions and is automatically concluded upon acceptance of the T&Cs. The technical and organizational measures (TOMs) applied are documented there as well. A separate signature is not required; upon request we will provide a PDF copy.
No Automated Decision-Making
We do not make decisions that have legal effects on you or similarly significantly affect you, solely on the basis of automated processing — including profiling — within the meaning of Art. 22 GDPR.
Protection of Minors
Our offer is aimed at business users, self-employed persons, and companies. The website and our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has transmitted personal data to us, we will delete it without delay.
Withdrawal of Your Consent
Insofar as data processing is based on your consent (e.g., analytics via Umami, optional AI features), you may withdraw that consent at any time with effect for the future. The lawfulness of the processing carried out on the basis of consent until its withdrawal remains unaffected (Art. 7(3) GDPR). You can withdraw consent for analytics via the cookie banner; other withdrawals by email to contact@balane.tech.
6. Your Rights
You have the following rights at any time regarding your personal data:
Right to information about your stored data
Right to correct inaccurate data
Right to delete your data
Right to transfer your data (Art. 20)
Right to restriction of processing (Art. 18)
Right to object to processing (Art. 21)
To exercise your rights, please contact: contact@balane.tech
7. Right to Complain
You have the right to complain to the competent supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht
Promenade 18, 91522 Ansbach
www.lda.bayern.de
Questions? Contact us at contact@balane.tech