Privacy Policy
Datenschutzerklärung - DSGVO / GDPR & US state privacy
Last updated 17 July 2026
This policy explains what personal data Avis Studio (the “Service”, workspace.avis-studio.app) processes, why, on what legal basis, and the rights you have. It reflects what the app actually does.
1. Controller
The controller responsible for processing your personal data is:
Daniel Werpel
Erlenstraße 35, 90556 Seukendorf, Germany
Privacy & data-protection requests: legal@avis-studio.app
Data protection officer
A statutory data protection officer (DPO) is not required for this operation: as a sole proprietorship we do not meet the thresholds of § 38 BDSG (we do not have 20+ persons constantly engaged in automated processing), and our core activity is not large-scale processing of special-category data or systematic monitoring under Art. 37 GDPR. You can reach us on any privacy matter at the contact address above.
2. What we process, and why
The table below lists each category of personal data, the purpose, the legal basis under Art. 6 GDPR, and how long we keep it.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data (name, email, sign-in identity) | Create and secure your account; authenticate you; contact you about the Service. | Art. 6(1)(b) - contract | For the life of the account; deleted on account deletion (see §6). |
| Workspace content (customers, finance, decisions, planner, documents you enter) | Provide the core Service - store and display the data you put in. | Art. 6(1)(b) - contract | Until you delete it or your account; backups age out on our normal cycle. |
| Usage & device data (log data, IP, basic interaction analytics) | Keep the Service secure and reliable; understand aggregate usage to improve it. | Art. 6(1)(f) - legitimate interest (secure, working Service) | Short-lived; aggregated or deleted on a rolling basis. |
| Billing data (via Merchant of Record) | Take payment for paid plans, issue invoices, handle taxes and refunds. | Art. 6(1)(b) - contract; Art. 6(1)(c) - legal (tax/records) | Held by the Merchant of Record; tax records kept as law requires. |
| Connected-integration data (Google Calendar / Contacts / Drive - only if you connect them) | Sync the calendar events, contacts or documents you choose to connect. | Art. 6(1)(a) - consent (you connect it); (b) - contract | Until you disconnect the integration or delete your account. |
| Support communications | Answer your questions and resolve issues. | Art. 6(1)(b) - contract; (f) - legitimate interest (support) | As long as needed to handle the matter, then deleted. |
| Advertising / conversion data (Meta Pixel & Conversions API) - only with consent | Measure and optimise our ads: record a single 'StartTrial' conversion when a trial starts, and attribute it to an ad click. Sent to Meta as Pixel cookies (_fbp/_fbc) and, server-side, a hashed email, IP address and user-agent. | Art. 6(1)(a) - consent (§ 25(1) TDDDG for the cookies); withdrawable anytime | Held by Meta per its retention policy; we store only the fire-once flag. |
3. Who processes data on our behalf (subprocessors)
We use a small number of vetted providers to run the Service. Each processes personal data only on our instructions under a data processing agreement. Providers in the US rely on the EU Standard Contractual Clauses and/or certification under the EU–US Data Privacy Framework as the transfer safeguard.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting/infrastructure and privacy-friendly, cookieless product analytics. | United States | SCCs / EU–US Data Privacy Framework |
| Supabase | Authentication (sessions, sign-in), primary database and file storage; sends account/auth emails. | United States / EU (project region) | SCCs / DPA |
| Google (Google Ireland Ltd / Google LLC) | Google sign-in; and - only if you connect them - Google Calendar, Contacts and Drive sync. | EU / United States | SCCs / EU–US Data Privacy Framework |
| Paddle.com Market Ltd | Merchant of Record for paid plans: payment processing, invoicing, tax and refunds. | United Kingdom | UK adequacy / SCCs; see their privacy notice |
| Meta Platforms Ireland Ltd / Meta Platforms, Inc. | Advertising measurement and optimisation (Meta Pixel + Conversions API) - only if you have consented. Receives a single trial-start conversion with pseudonymised identifiers (Pixel cookies, hashed email, IP, user-agent). | EU / United States | SCCs / EU–US Data Privacy Framework |
Paddle.com Market Ltd processes your payment data as its own controller for parts of the transaction (tax, fraud, invoicing); see their privacy notice.
Google integrations - scope
Google sign-in shares only the basic profile needed to authenticate you. The Calendar, Contacts and Drive integrations are optional and off by default; each has its own separate consent screen and requests only the access it needs (Drive access is limited to files the app creates). You can disconnect any of them at any time in Settings → Integrations, which revokes the access.
4. Cookies & tracking
Our own cookies are strictly necessary; the only non-essential cookies are Meta’s advertising cookies, which are set only with your consent (see §4a):
- Authentication cookies (via our auth provider) keep you signed in - essential; the Service cannot work without them.
- A theme preference cookie remembers light/dark - essential to your setting.
- A short-lived cookie may record how you arrived (campaign attribution) across the sign-in redirect.
- Meta advertising cookies (
_fbp, and_fbcfrom an ad click) - set by the Meta Pixel only after you consent, to measure ad conversions. Not set if you decline.
Our product analytics (Vercel Analytics) remains cookieless. We do not show a separate cookie banner in this app because your advertising consent is collected once on our marketing site (avis-studio.app) and stored for the whole avis-studio.app domain; this app inherits that choice. If you have not consented, or you withdraw consent there, no Meta pixel loads here, no Meta cookie is set, and no server-side conversion is sent.
4a. Meta Pixel & Conversions API (advertising)
With your consent, we use the Meta Pixel and the server-side Meta Conversions API (CAPI) to record a single “StartTrial” conversion when your 14-day trial starts, and to attribute it to the ad you clicked. For this we transmit to Meta:
- the Pixel cookies
_fbp/_fbc(the click identifiers set on theavis-studio.appdomain); - your email address hashed with SHA-256 (irreversibly, on our server - Meta never receives your email in the clear), used only to match the conversion; and
- your IP address and browser user-agent, as Meta requires for matching.
The legal basis is your consent (Art. 6(1)(a) GDPR; § 25(1) TDDDG for the cookie access). You can withdraw consent at any time via the cookie settings on avis-studio.app - withdrawal stops all future pixel and CAPI processing here (it does not undo processing already carried out). You can also manage ad personalisation in your Meta account settings. Meta acts as an independent controller for its own use of this data; see Meta’s Privacy Policy.
5. Fonts & third-party content
Fonts are self-hosted and served from our own infrastructure. The app makes no runtime request to Google Fonts (or any external font CDN), so your IP address is not shared with a font provider when a page loads.
6. Export & deletion of your data
You are in control of your data and can act on it yourself, at any time, from Settings:
- Export (Art. 20 - portability): Settings → Data → Export downloads everything in your workspace as a single JSON file.
- Delete your workspace: Settings → Data → Delete project removes the project and all its data while keeping your login.
- Delete your account (Art. 17 - erasure): Settings → Data → Delete account removes your account and cascades the deletion across all your data. This is irreversible.
Billing records held by the Merchant of Record and records we must keep for legal (e.g. tax) reasons are retained for the required period even after deletion; they are then removed.
7. Your rights under the GDPR
You have the right to:
- access your personal data (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest (Art. 21); and
- withdraw consent at any time, without affecting prior processing (Art. 7(3)).
To exercise any of these, contact us (see the Imprint) - or use the self-serve export and deletion tools above.
Right to complain
You may lodge a complaint with a supervisory authority. Our competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
8. US state privacy rights
This section applies if you are a resident of a US state with a consumer-privacy law, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA) and Texas (TDPSA).
Categories we collect
- identifiers (name, email, account/sign-in identity);
- customer records & commercial information (the workspace content you enter, subscription status);
- internet/usage activity (log data, basic interaction analytics);
- approximate location inferred from IP for security.
Selling & sharing
We do not sell your personal information for money. If you consent to advertising cookies (see §4a), our use of the Meta Pixel and Conversions API may qualify as “sharing” for cross-context behavioral advertising under some US state laws, because a trial-start conversion is disclosed to Meta. You can opt out at any time by withdrawing consent on avis-studio.app. Without your consent, no such sharing occurs. We do not use or disclose sensitive personal information beyond what is needed to provide the Service.
Your rights
- the right to know what we collect and how we use it (this policy);
- the right to access and to delete your personal information;
- the right to correct inaccurate information;
- the right to opt out of sale / sharing / targeted advertising - we do not sell for money; the only “sharing” is the consent-based Meta advertising in §4a, which you opt out of by withdrawing that consent; and
- the right not to receive discriminatory treatment for exercising your rights.
Exercise these the same way as the GDPR rights above - via the self-serve tools or by contacting us. We will verify your request against your account.
9. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from children under 16 (or under 13 where COPPA applies). If you believe a child has provided us data, contact us and we will delete it.
10. Security
We use appropriate technical and organisational measures - encrypted transport, access controls scoped per account, and reputable infrastructure providers - to protect your data. No method of transmission or storage is perfectly secure, but we work to protect it and to keep our providers accountable.
11. Changes to this policy
We may update this policy as the Service evolves. Material changes will be communicated in-app or by email before they take effect. The “last updated” date at the top reflects the current version.