This English text is a convenience translation. The legally binding version is the German one (Deutsch), reachable via the language switch below.
Last updated: 2026-06-25
This Privacy Policy is published in English and German. The German version (Datenschutzerklärung) is the binding version; the English text is a convenience translation. In case of conflict, the German version prevails.
This Privacy Policy explains how Finalform GmbH ("Finalform", "we", "us") processes personal data in its role as data controller. It applies to visitors of our websites at autopage.dev and app.autopage.dev, to account holders and their authorized users, to billing and payment data, and to marketing communications.
This policy does not govern the visitor behavioral data that Autopage processes on the landing pages of our business customers. For that processing Finalform acts as a processoron the customer's behalf. That relationship is governed by the Data Processing Agreement and Section 8 of the Terms of Service. See Section 12 below for the full controller and processor split.
We collect personal data directly from you (Article 13 GDPR applies; we do not source your data from third-party brokers or data-enrichment vendors). We process no special categories of personal datawithin the meaning of Article 9 GDPR. Where Autopage performs cross-tenant "enrichment", that is non-personal, aggregated industry-benchmark data and is not personal data about you.
Autopage is a business-to-business (B2B) service. We contract only with businesses and entrepreneurs (Unternehmer within the meaning of Section 14 BGB). We do not knowingly serve consumers.
The controller responsible for the data processing described in this policy is:
Finalform GmbH
Theodor-Heuss-Str. 106
26129 Oldenburg
Germany
For full provider identification details, see the Impressum.
Finalform is appointing an external Data Protection Officer (DPO) before go-live. The appointed DPO's name and contact details (email and postal address) will be published here, and notified to the supervisory authority (LfD Niedersachsen), before the service goes live.
Until the appointment is published, data protection enquiries can be directed to the controller contact in Section 1.
We expect to be legally required to appoint a DPO. A Data Protection Impact Assessment (DPIA) under Article 35 GDPR is very likely mandatory for Autopage given the combination of visitor behavioral measurement and AI-driven content optimization. Under Section 38(1) BDSG, a controller that is required to carry out a DPIA must appoint a Data Protection Officer regardless of headcount. We appoint an external DPO on that basis.
We collect the following categories of personal data, in each case directly from you or generated by your use of the service. We collect only what we need for the stated purpose.
This describes a planned capability; Autopage does not currently send marketing email, so the email recipient in Section 5 is transactional only.
We process the personal data above for the purposes and on the legal bases set out below. Where we rely on legitimate interests under Art 6(1)(f), the interest pursued is named (Art 13(1)(d)).
| Purpose | Categories of data | Legal basis (Art 6 GDPR) |
|---|---|---|
| Provide and operate the Autopage application (authentication, dashboard, optimization runs) | Account data, configuration and usage data | Performance of a contract, Art 6(1)(b) |
| Operate and secure our public website | Functional cookie and storage data | Our legitimate interest in operating and securing the website, Art 6(1)(f) |
| Create and administer your account and authenticate users | Account identity and credentials | Performance of a contract, Art 6(1)(b) |
| Validate B2B status and EU VAT identification number (planned, not yet active) | Company name, VAT-ID | Performance of a contract and pre-contractual steps, Art 6(1)(b), and compliance with our tax and invoicing obligations, Art 6(1)(c) |
| Process subscriptions, payments, and invoicing via Stripe | Billing data, transaction records | Performance of a contract, Art 6(1)(b), and compliance with a legal obligation for invoicing, Art 6(1)(c) |
| Keep accounting and tax records | Invoices and related records | Compliance with a legal obligation, Art 6(1)(c), in particular Section 14b UStG and German commercial and tax retention duties |
| Send transactional email (verification, magic-link sign-in, notifications) | Email address, email content | Performance of a contract, Art 6(1)(b) |
| Provide customer support and respond to enquiries | Support correspondence | Performance of a contract, Art 6(1)(b), or our legitimate interest in answering enquiries from prospects, Art 6(1)(f) |
| Secure our systems, prevent abuse and fraud, rate-limit requests, and ensure availability | Service-integrity data (including the transient rate-limit key described in the Data Retention and Minimisation Policy) | Our legitimate interest in the security and integrity of our service, Art 6(1)(f) |
| Optional preference cookies on our own site | Preference storage | Our legitimate interest in honoring your settings, Art 6(1)(f), or consent under Art 6(1)(a) if reclassified, together with Section 25(1) TDDDG for storing or reading data on your device |
| Send product-marketing email to existing customers (planned, not yet active) | Email address, consent and engagement records | Our legitimate interest in direct marketing to existing customers, Art 6(1)(f), subject to Section 7(3) UWG, or consent under Art 6(1)(a) |
| Comply with legal requests and defend legal claims | Any relevant data | Compliance with a legal obligation, Art 6(1)(c), and legitimate interest in establishing or defending legal claims, Art 6(1)(f) |
Where we rely on consent under Art 6(1)(a), you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the visitor data Finalform processes on a customer's behalfis determined by that customer (the controller), together with the Section 25(1) TDDDG opt-in the customer obtains on its own pages. Finalform processes that data only on the customer's documented instructions (Art 28(3)(a)). See Section 12 and the Data Processing Agreement.
We share personal data only with service providers and recipients who help us deliver and operate the service, and only as needed. Where these providers process personal data on our behalf, they act as our processors (sub-processors) under Article 28 GDPR contracts. Each sub-processor is bound by data-protection obligations equivalent to those we owe you, and Finalform remains liable for each sub-processor's performance.
| Recipient (legal entity) | Service / role | Data it receives | Region | Transfer mechanism |
|---|---|---|---|---|
| Railway Corporation (Delaware, US) | Application hosting, compute, and managed PostgreSQL database | All account, configuration, and billing data we control, and the visitor data we process on customers' behalf | US default; EU residency configurable per service | US recipient → EU-US DPF adequacy if certified, else SCC + TIA |
| Anthropic, PBC (Delaware, US) | Large language model that generates and rewrites landing-page copy | Tenant brief, baseline page copy, and population-level aggregate metrics only; no per-visitor data, no account data | US (api.anthropic.com) | US recipient → DPF adequacy if certified, else SCC + TIA; no-training / zero-retention tier |
| Cloudflare, Inc. (Delaware, US) | Browser Rendering API that renders a customer's landing page during baseline scrape | The customer's public landing-page URL only; no visitor data, no account data | US (api.cloudflare.com) | US recipient → DPF adequacy if certified, else SCC + TIA |
| Stripe (Stripe Payments Europe, Ltd. (Ireland) or Stripe, Inc. (US)) | Payment processing and billing | Company name, billing address, EU VAT-ID, account-holder billing email and name, organization-id metadata, subscription and transaction data; no card number stored by us | EU and US per account | If Stripe Payments Europe Ltd (IE): intra-EEA for the EU leg; if Stripe, Inc. (US): DPF adequacy if certified, else SCC + TIA |
| Resend (Plus Five Five, Inc., US) | Transactional email delivery (verification, magic-link, password reset, invitations, notifications) | Recipient email address, email content (subject and HTML body), and the recipient name in templates | US (api.resend.com) | US recipient → DPF adequacy if certified, else SCC + TIA |
We may also disclose personal data to professional advisers (for example, our tax adviser or lawyers) and to public authorities or courts where required by law.
For the current, complete, and dated list of sub-processors, including each provider's location and the data categories it processes, see the Sub-processor List. We maintain that list with a visible effective date and version, and provide advance notice of changes as described there.
Some of the processing described above involves transferring personal data to recipients outside the European Economic Area (EEA), in particular to providers in the United States. We disclose this plainly rather than implying EU-only processing:
For each transfer to a third country we rely on an appropriate safeguard under Chapter V GDPR (Art 13(1)(f)):
The current transfer mechanism for each recipient is recorded, per recipient, in the Sub-processor List. A copy of the relevant safeguards, including the Standard Contractual Clauses, is available on request via the contact in Section 1.
We keep personal data only as long as necessary for the purposes for which it was collected, or as required by law, then delete or aggregate it. The full schedule, with a start trigger (Startzeitpunkt) for each category, is set out in the Data Retention and Minimisation Policy, which this policy incorporates by reference. The summary below states at least one concrete period per category and must not contradict that policy.
An erasure request does not override a statutory retention obligation. During such a hold the data is restricted, not deleted, and is erased once the statutory period ends.
Subject to the conditions and limits in the GDPR, you have the following rights regarding your personal data:
Where processing is based on consent, you also have the right to withdraw consent at any time with effect for the future (Section 4).
To exercise any of these rights, contact us using the details in Section 1 (or the DPO once appointed, Section 2). We will respond without undue delay and in any event within one month of receiving the request. We may extend this by two further months for complex or numerous requests and will tell you if we do. We may need to verify your identity before acting.
If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, place of work, or the place of the alleged infringement.
Our competent supervisory authority is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen)
Prinzenstraße 5, 30159 Hannover, Germany
Exercising this right does not affect any other administrative or judicial remedy.
Providing personal data is not a general legal requirement. However, certain data is necessary to enter into and perform our contract with you.
If you do not provide the account identity data, we cannot create your account or provide the service. The company name and EU VAT identification number are needed only for billing and invoicing on a paid plan; without them we cannot process payment or issue a compliant invoice. Provision of optional data (for example, consent to marketing) is voluntary, and declining has no effect on the core service.
Finalform does not make decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR, in respect of the data covered by this policy.
Autopage's optimization works by population-level A/B experimentation. Visitors are assigned to a page variant at the level of the group, not the individual: the system serves different variants to groups of visitors, measures aggregate performance such as conversion rates across the whole group, and decides which variant performs better for the population. It does not build a profile of an identified individual and does not make a solely-automated decision that has legal or similarly significant effects on any one person. The AI component, a large language model supplied by Anthropic, PBC, generates and rewrites copy at the level of the page and its variants, not at the level of an individual visitor.
It is important to distinguish two different roles Finalform plays.
That processor relationship is governed by the Data Processing Agreement between Finalform and the customer, and by Section 8 of the Terms of Service, not by this Privacy Policy. Among other things, the customer is responsible for obtaining any visitor consent required under Section 25(1) TDDDG before the snippet stores or reads information on a visitor's device, and for the lawfulness of the processing it instructs.
If you are a visitor to a landing page operated by one of our customers and you have questions about how your data is used there, please contact that customer (the controller). We will assist the customer in responding as required by the Data Processing Agreement.
We may update this Privacy Policy to reflect changes in our processing, our service, or the law. The date of the current version is shown in the "Last updated" line above. Where a change is material, we will take reasonable steps to inform affected account holders in advance, for example by email or an in-app notice. The version in force is the dated version published on our site at the relevant time.