Privacy Policy

Read our privacy policy

This English text is a convenience translation. The legally binding version is the German one (Deutsch), reachable via the language switch below.

Last updated: 2026-06-25

This Privacy Policy is published in English and German. The German version (Datenschutzerklärung) is the binding version; the English text is a convenience translation. In case of conflict, the German version prevails.

This Privacy Policy explains how Finalform GmbH ("Finalform", "we", "us") processes personal data in its role as data controller. It applies to visitors of our websites at autopage.dev and app.autopage.dev, to account holders and their authorized users, to billing and payment data, and to marketing communications.

This policy does not govern the visitor behavioral data that Autopage processes on the landing pages of our business customers. For that processing Finalform acts as a processoron the customer's behalf. That relationship is governed by the Data Processing Agreement and Section 8 of the Terms of Service. See Section 12 below for the full controller and processor split.

We collect personal data directly from you (Article 13 GDPR applies; we do not source your data from third-party brokers or data-enrichment vendors). We process no special categories of personal datawithin the meaning of Article 9 GDPR. Where Autopage performs cross-tenant "enrichment", that is non-personal, aggregated industry-benchmark data and is not personal data about you.

Autopage is a business-to-business (B2B) service. We contract only with businesses and entrepreneurs (Unternehmer within the meaning of Section 14 BGB). We do not knowingly serve consumers.

Contents

  • 1. Controller identity and contact
  • 2. Data Protection Officer (Datenschutzbeauftragter)
  • 3. Categories of personal data we collect
  • 4. Purposes of processing and legal bases (Article 6 GDPR)
  • 5. Recipients and sub-processors
  • 6. International transfers and US data residency
  • 7. Retention periods
  • 8. Your rights as a data subject
  • 9. Right to lodge a complaint
  • 10. Is provision of data required?
  • 11. Automated decision-making and profiling
  • 12. Controller and processor split: visitor data on customer pages
  • 13. Changes to this policy

1. Controller identity and contact

The controller responsible for the data processing described in this policy is:

Finalform GmbH
Theodor-Heuss-Str. 106
26129 Oldenburg
Germany

  • Managing Director (Geschäftsführer): Robin Schröder
  • Register court: Amtsgericht Oldenburg, HRB 222780
  • VAT identification number (USt-IdNr.): DE457693089
  • Email: support@autopage.dev

For full provider identification details, see the Impressum.

2. Data Protection Officer (Datenschutzbeauftragter)

Finalform is appointing an external Data Protection Officer (DPO) before go-live. The appointed DPO's name and contact details (email and postal address) will be published here, and notified to the supervisory authority (LfD Niedersachsen), before the service goes live.

Until the appointment is published, data protection enquiries can be directed to the controller contact in Section 1.

We expect to be legally required to appoint a DPO. A Data Protection Impact Assessment (DPIA) under Article 35 GDPR is very likely mandatory for Autopage given the combination of visitor behavioral measurement and AI-driven content optimization. Under Section 38(1) BDSG, a controller that is required to carry out a DPIA must appoint a Data Protection Officer regardless of headcount. We appoint an external DPO on that basis.

3. Categories of personal data we collect

We collect the following categories of personal data, in each case directly from you or generated by your use of the service. We collect only what we need for the stated purpose.

3.1 Website and application visitors (autopage.dev and app.autopage.dev)

  • A small set of strictly necessary and functional cookies and two Web-Storage keys on our own sites. These are first-party only. We set no analytics or marketing cookie, no third-party tracker or pixel, and no consent-management banner on our own properties. The full inventory is disclosed in the Cookie Policy.
  • We do not operate web analytics on our own sites. We collect no IP-based visitor log, no user-agent profile, no referrer history, and no device fingerprint for our own website visitors.

3.2 Account registration and use of the application

  • Account identity data: name, business email address, and account credentials.
  • Company name and, for EU customers, an EU VAT identification number, collected at billing via our payment processor (see Section 3.3). Collecting and validating the company name and EU VAT-ID at signup, as a condition of B2B onboarding, is planned and not yet active.
  • Account and configuration data you enter while using Autopage, and metadata about your use of the application (for example, login timestamps and the pages and experiments you configure).

3.3 Billing and payments (via Stripe)

  • Billing contact details, company name, billing address, and VAT identification number.
  • Subscription, plan, invoice, and transaction records.
  • Payment is handled by our payment processor, Stripe. Stripe collects and processes your payment instrument data (for example, card details) directly on its own hosted pages. Finalform stores no full payment card number. Stripe is our payment processor; Finalform is the legal seller and issues the invoice.

3.4 Support and communications

  • The content of your enquiries and our correspondence when you contact us by email or through a support channel, including any data you choose to include.

3.5 Marketing email (planned, not yet active)

  • Email address and, where applicable, name and company.
  • Consent records, including the time, source, and scope of consent, and engagement metadata for emails we send.

This describes a planned capability; Autopage does not currently send marketing email, so the email recipient in Section 5 is transactional only.

4. Purposes of processing and legal bases (Article 6 GDPR)

We process the personal data above for the purposes and on the legal bases set out below. Where we rely on legitimate interests under Art 6(1)(f), the interest pursued is named (Art 13(1)(d)).

Purposes of processing, categories of data, and legal basis under Article 6 GDPR
PurposeCategories of dataLegal basis (Art 6 GDPR)
Provide and operate the Autopage application (authentication, dashboard, optimization runs)Account data, configuration and usage dataPerformance of a contract, Art 6(1)(b)
Operate and secure our public websiteFunctional cookie and storage dataOur legitimate interest in operating and securing the website, Art 6(1)(f)
Create and administer your account and authenticate usersAccount identity and credentialsPerformance of a contract, Art 6(1)(b)
Validate B2B status and EU VAT identification number (planned, not yet active)Company name, VAT-IDPerformance of a contract and pre-contractual steps, Art 6(1)(b), and compliance with our tax and invoicing obligations, Art 6(1)(c)
Process subscriptions, payments, and invoicing via StripeBilling data, transaction recordsPerformance of a contract, Art 6(1)(b), and compliance with a legal obligation for invoicing, Art 6(1)(c)
Keep accounting and tax recordsInvoices and related recordsCompliance with a legal obligation, Art 6(1)(c), in particular Section 14b UStG and German commercial and tax retention duties
Send transactional email (verification, magic-link sign-in, notifications)Email address, email contentPerformance of a contract, Art 6(1)(b)
Provide customer support and respond to enquiriesSupport correspondencePerformance of a contract, Art 6(1)(b), or our legitimate interest in answering enquiries from prospects, Art 6(1)(f)
Secure our systems, prevent abuse and fraud, rate-limit requests, and ensure availabilityService-integrity data (including the transient rate-limit key described in the Data Retention and Minimisation Policy)Our legitimate interest in the security and integrity of our service, Art 6(1)(f)
Optional preference cookies on our own sitePreference storageOur legitimate interest in honoring your settings, Art 6(1)(f), or consent under Art 6(1)(a) if reclassified, together with Section 25(1) TDDDG for storing or reading data on your device
Send product-marketing email to existing customers (planned, not yet active)Email address, consent and engagement recordsOur legitimate interest in direct marketing to existing customers, Art 6(1)(f), subject to Section 7(3) UWG, or consent under Art 6(1)(a)
Comply with legal requests and defend legal claimsAny relevant dataCompliance with a legal obligation, Art 6(1)(c), and legitimate interest in establishing or defending legal claims, Art 6(1)(f)

Where we rely on consent under Art 6(1)(a), you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

The legal basis for the visitor data Finalform processes on a customer's behalfis determined by that customer (the controller), together with the Section 25(1) TDDDG opt-in the customer obtains on its own pages. Finalform processes that data only on the customer's documented instructions (Art 28(3)(a)). See Section 12 and the Data Processing Agreement.

5. Recipients and sub-processors

We share personal data only with service providers and recipients who help us deliver and operate the service, and only as needed. Where these providers process personal data on our behalf, they act as our processors (sub-processors) under Article 28 GDPR contracts. Each sub-processor is bound by data-protection obligations equivalent to those we owe you, and Finalform remains liable for each sub-processor's performance.

Recipients, service or role, data received, region, and transfer mechanism
Recipient (legal entity)Service / roleData it receivesRegionTransfer mechanism
Railway Corporation (Delaware, US)Application hosting, compute, and managed PostgreSQL databaseAll account, configuration, and billing data we control, and the visitor data we process on customers' behalfUS default; EU residency configurable per serviceUS recipient → EU-US DPF adequacy if certified, else SCC + TIA
Anthropic, PBC (Delaware, US)Large language model that generates and rewrites landing-page copyTenant brief, baseline page copy, and population-level aggregate metrics only; no per-visitor data, no account dataUS (api.anthropic.com)US recipient → DPF adequacy if certified, else SCC + TIA; no-training / zero-retention tier
Cloudflare, Inc. (Delaware, US)Browser Rendering API that renders a customer's landing page during baseline scrapeThe customer's public landing-page URL only; no visitor data, no account dataUS (api.cloudflare.com)US recipient → DPF adequacy if certified, else SCC + TIA
Stripe (Stripe Payments Europe, Ltd. (Ireland) or Stripe, Inc. (US))Payment processing and billingCompany name, billing address, EU VAT-ID, account-holder billing email and name, organization-id metadata, subscription and transaction data; no card number stored by usEU and US per accountIf Stripe Payments Europe Ltd (IE): intra-EEA for the EU leg; if Stripe, Inc. (US): DPF adequacy if certified, else SCC + TIA
Resend (Plus Five Five, Inc., US)Transactional email delivery (verification, magic-link, password reset, invitations, notifications)Recipient email address, email content (subject and HTML body), and the recipient name in templatesUS (api.resend.com)US recipient → DPF adequacy if certified, else SCC + TIA

We may also disclose personal data to professional advisers (for example, our tax adviser or lawyers) and to public authorities or courts where required by law.

For the current, complete, and dated list of sub-processors, including each provider's location and the data categories it processes, see the Sub-processor List. We maintain that list with a visible effective date and version, and provide advance notice of changes as described there.

6. International transfers and US data residency

Some of the processing described above involves transferring personal data to recipients outside the European Economic Area (EEA), in particular to providers in the United States. We disclose this plainly rather than implying EU-only processing:

  • Our primary hosting and database provider (Railway) defaults to US infrastructure, with EU data residency configurable per service.
  • The AI provider (Anthropic), the page-render API (Cloudflare), and the email provider (Resend) process data in the United States.
  • Stripe processes in the EU and the US depending on the contracting entity.

For each transfer to a third country we rely on an appropriate safeguard under Chapter V GDPR (Art 13(1)(f)):

  • EU-US Data Privacy Framework (DPF) adequacywhere the specific recipient entity is certified under the DPF. Where a recipient is DPF-certified, the transfer relies on the European Commission's adequacy decision for the DPF.
  • Standard Contractual Clauses (SCCs) plus a transfer impact assessment (TIA) where the recipient is not DPF-certified.

The current transfer mechanism for each recipient is recorded, per recipient, in the Sub-processor List. A copy of the relevant safeguards, including the Standard Contractual Clauses, is available on request via the contact in Section 1.

7. Retention periods

We keep personal data only as long as necessary for the purposes for which it was collected, or as required by law, then delete or aggregate it. The full schedule, with a start trigger (Startzeitpunkt) for each category, is set out in the Data Retention and Minimisation Policy, which this policy incorporates by reference. The summary below states at least one concrete period per category and must not contradict that policy.

  • Account and tenant data: retained for the life of the account. On a deletion request or account closure, account and tenant data is deleted immediately and completely, with no grace tail.
  • Visitor interaction data(processed on customers' behalf): a target of 90 days for raw events, then aggregate-only metrics that carry no identifier.
  • Operational telemetry (LLM call telemetry, namely token counts and call duration, with no prompt or response content): a target of 90 days.
  • Security and access logs: a target of 30 days.
  • Notifications: 30 days.
  • Support correspondence: kept as long as needed to handle the matter and for a reasonable period afterwards to address follow-ups.
  • Marketing data: until you withdraw consent or object, after which we suppress your address as needed to honor your choice.
  • Invoices and accounting records: retained for the statutory period. German tax and commercial law requires retention of invoices (Buchungsbelege) for 8 years(Section 147 AO as amended by the Bürokratieentlastungsgesetz IV, effective 2025-01-01) and of business correspondence for 6 years (Section 257 HGB, Section 147 AO). These records live in our payment and external accounting systems. During the retention period the data is restricted to that purpose rather than actively used.

An erasure request does not override a statutory retention obligation. During such a hold the data is restricted, not deleted, and is erased once the statutory period ends.

8. Your rights as a data subject

Subject to the conditions and limits in the GDPR, you have the following rights regarding your personal data:

  • Access (Art 15): to obtain confirmation of whether we process your data and a copy of it.
  • Rectification (Art 16): to have inaccurate data corrected and incomplete data completed.
  • Erasure (Art 17): to have your data deleted where one of the grounds applies.
  • Restriction (Art 18): to have processing restricted in certain cases.
  • Data portability (Art 20): to receive data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection (Art 21): to object, on grounds relating to your particular situation, to processing based on legitimate interests, and to object at any time to processing for direct marketing.
  • Automated decision-making (Art 22): see Section 11.

Where processing is based on consent, you also have the right to withdraw consent at any time with effect for the future (Section 4).

To exercise any of these rights, contact us using the details in Section 1 (or the DPO once appointed, Section 2). We will respond without undue delay and in any event within one month of receiving the request. We may extend this by two further months for complex or numerous requests and will tell you if we do. We may need to verify your identity before acting.

9. Right to lodge a complaint

If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, place of work, or the place of the alleged infringement.

Our competent supervisory authority is:

Der Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen)
Prinzenstraße 5, 30159 Hannover, Germany

Exercising this right does not affect any other administrative or judicial remedy.

10. Is provision of data required?

Providing personal data is not a general legal requirement. However, certain data is necessary to enter into and perform our contract with you.

  • To create and operate an account, you must provide account identity data. As a B2B customer, your company name and (for EU customers) a valid EU VAT identification number are required for billing and invoicing (see Section 3.3); signup-time collection of these is planned and not yet active.
  • To purchase a paid plan, you must provide billing data so that we and our payment processor can process payment and so that we can issue a legally compliant invoice.

If you do not provide the account identity data, we cannot create your account or provide the service. The company name and EU VAT identification number are needed only for billing and invoicing on a paid plan; without them we cannot process payment or issue a compliant invoice. Provision of optional data (for example, consent to marketing) is voluntary, and declining has no effect on the core service.

11. Automated decision-making and profiling

Finalform does not make decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR, in respect of the data covered by this policy.

Autopage's optimization works by population-level A/B experimentation. Visitors are assigned to a page variant at the level of the group, not the individual: the system serves different variants to groups of visitors, measures aggregate performance such as conversion rates across the whole group, and decides which variant performs better for the population. It does not build a profile of an identified individual and does not make a solely-automated decision that has legal or similarly significant effects on any one person. The AI component, a large language model supplied by Anthropic, PBC, generates and rewrites copy at the level of the page and its variants, not at the level of an individual visitor.

12. Controller and processor split: visitor data on customer pages

It is important to distinguish two different roles Finalform plays.

  • As controller (this policy): Finalform determines the purposes and means of processing for its own website visitors, account holders, billing, support, and marketing. That is what this Privacy Policy covers.
  • As processor(not this policy): When a business customer installs the Autopage JavaScript snippet on landing pages it owns or controls, Autopage processes the behavioral data of that customer's website visitors on the customer's behalf and on the customer's documented instructions. For that processing the customer is the controller and Finalform is the processor under Article 28 GDPR. That data is limited to a pseudonymous visitor session identifier and coarse, bucketed behavioral signals; Finalform persists no visitor IP address, user-agent string, precise geolocation, device fingerprint, or form input; a visitor IP address reaches our servers with every request as a technical necessity, is used only transiently in server memory (roughly 60 seconds) for rate limiting, and is never written to our database or application logs.

That processor relationship is governed by the Data Processing Agreement between Finalform and the customer, and by Section 8 of the Terms of Service, not by this Privacy Policy. Among other things, the customer is responsible for obtaining any visitor consent required under Section 25(1) TDDDG before the snippet stores or reads information on a visitor's device, and for the lawfulness of the processing it instructs.

If you are a visitor to a landing page operated by one of our customers and you have questions about how your data is used there, please contact that customer (the controller). We will assist the customer in responding as required by the Data Processing Agreement.

13. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing, our service, or the law. The date of the current version is shown in the "Last updated" line above. Where a change is material, we will take reasonable steps to inform affected account holders in advance, for example by email or an in-app notice. The version in force is the dated version published on our site at the relevant time.