Privacy Policy

Read our privacy policy

This English text is a convenience translation. The legally binding version is the German one (Deutsch), reachable via the language switch below.

Last updated: 2026-08-21

This Privacy Policy is published in English and German. The German version (Datenschutzerklärung) is the binding version; the English text is a convenience translation. In case of conflict, the German version prevails.

This Privacy Policy explains how Finalform GmbH ("Finalform", "we", "us") processes personal data in its role as data controller. It applies to visitors of our websites at autopage.dev and app.autopage.dev, to account holders and their authorized users, to billing and payment data, and to marketing communications.

This policy does not govern the visitor behavioral data that Autopage processes on the landing pages of our business customers. For that processing Finalform acts as a processoron the customer's behalf. That relationship is governed by the Data Processing Agreement and Section 8 of the Terms of Service. See Section 12 below for the full controller and processor split.

We collect personal data directly from you (Article 13 GDPR applies; we do not source your data from third-party brokers or data-enrichment vendors). We process no special categories of personal datawithin the meaning of Article 9 GDPR. Where Autopage performs cross-tenant "enrichment", that is non-personal, aggregated industry-benchmark data and is not personal data about you.

Autopage is a business-to-business (B2B) service. We contract only with businesses and entrepreneurs (Unternehmer within the meaning of Section 14 BGB). We do not knowingly serve consumers.

Contents

  • 1. Controller identity and contact
  • 2. Data Protection Officer (Datenschutzbeauftragter)
  • 3. Categories of personal data we collect
  • 4. Purposes of processing and legal bases (Article 6 GDPR)
  • 5. Recipients and sub-processors
  • 6. International transfers and data residency
  • 7. Retention periods
  • 8. Your rights as a data subject
  • 9. Right to lodge a complaint
  • 10. Is provision of data required?
  • 11. Automated decision-making and profiling
  • 12. Controller and processor split: visitor data on customer pages
  • 13. Changes to this policy

1. Controller identity and contact

The controller responsible for the data processing described in this policy is:

Finalform GmbH
Theodor-Heuss-Str. 106
26129 Oldenburg
Germany

  • Managing Director (Geschäftsführer): Robin Schröder
  • Register court: Amtsgericht Oldenburg, HRB 222780
  • VAT identification number (USt-IdNr.): DE457693089
  • Email: support@autopage.dev

For full provider identification details, see the Impressum.

2. Data Protection Officer (Datenschutzbeauftragter)

Finalform is appointing an external Data Protection Officer (DPO) before go-live. The appointed DPO's name and contact details (email and postal address) will be published here, and notified to the supervisory authority (LfD Niedersachsen), before the service goes live.

Until the appointment is published, data protection enquiries can be directed to the controller contact in Section 1.

We expect to be legally required to appoint a DPO. A Data Protection Impact Assessment (DPIA) under Article 35 GDPR is very likely mandatory for Autopage given the combination of visitor behavioral measurement and AI-driven content optimization. Under Section 38(1) BDSG, a controller that is required to carry out a DPIA must appoint a Data Protection Officer regardless of headcount. We appoint an external DPO on that basis.

3. Categories of personal data we collect

We collect the following categories of personal data, in each case directly from you or generated by your use of the service. We collect only what we need for the stated purpose.

3.1 Website and application visitors (autopage.dev and app.autopage.dev)

  • A small set of strictly necessary and functional cookies and two Web-Storage keys on our own sites. These are first-party only. We set no analytics or marketing cookie, no third-party tracker or pixel, and no consent-management banner on our own properties. The full inventory is disclosed in the Cookie Policy.
  • We do not operate web analytics on our own sites. We collect no IP-based visitor log, no user-agent profile, no referrer history, and no device fingerprint for our own website visitors.

3.2 Account registration and use of the application

  • Account identity data: name, business email address, and account credentials.
  • Company name and your business confirmation, collected at signup as a condition of B2B onboarding. We record the company name you declare, the time you confirmed that you act as a business (Unternehmer, Section 14 BGB), and the version of the confirmation wording you were shown. The confirmation is your own declaration; we do not check it against a public register.
  • For EU customers, an EU VAT identification number, collected at checkout via our payment processor (see Section 3.3). The payment processor validates it against the EU VIES service where that service is reachable, and we record the validation status it reports so we can follow up on a number that does not validate.
  • Account and configuration data you enter while using Autopage, and metadata about your use of the application (for example, login timestamps and the pages and experiments you configure).

3.3 Billing and payments (via Stripe)

  • Billing contact details, company name, billing address, and VAT identification number.
  • Subscription, plan, invoice, and transaction records.
  • Payment is handled by our payment processor, Stripe. Stripe collects and processes your payment instrument data (for example, card details) directly on its own hosted pages. Finalform stores no full payment card number. Stripe is our payment processor; Finalform is the legal seller and issues the invoice.

3.4 Support and communications

  • The content of your enquiries and our correspondence when you contact us by email or through a support channel, including any data you choose to include.

3.5 Marketing email (planned, not yet active)

  • Email address and, where applicable, name and company.
  • Consent records, including the time, source, and scope of consent, and engagement metadata for emails we send.

This describes a planned capability; Autopage does not currently send marketing email, so the email recipient in Section 5 is transactional only.

4. Purposes of processing and legal bases (Article 6 GDPR)

We process the personal data above for the purposes and on the legal bases set out below. Where we rely on legitimate interests under Art 6(1)(f), the interest pursued is named (Art 13(1)(d)).

Purposes of processing, categories of data, and legal basis under Article 6 GDPR
PurposeCategories of dataLegal basis (Art 6 GDPR)
Provide and operate the Autopage application (authentication, dashboard, optimization runs)Account data, configuration and usage dataPerformance of a contract, Art 6(1)(b)
Operate and secure our public websiteFunctional cookie and storage dataOur legitimate interest in operating and securing the website, Art 6(1)(f)
Create and administer your account and authenticate usersAccount identity and credentialsPerformance of a contract, Art 6(1)(b)
Record the customer's business self-attestation at signup and check the EU VAT identification number after purchaseCompany name, business confirmation record, VAT-ID and the validation status reported for itPerformance of a contract and pre-contractual steps, Art 6(1)(b), and compliance with our tax and invoicing obligations, Art 6(1)(c)
Process subscriptions, payments, and invoicing via StripeBilling data, transaction recordsPerformance of a contract, Art 6(1)(b), and compliance with a legal obligation for invoicing, Art 6(1)(c)
Keep accounting and tax recordsInvoices and related recordsCompliance with a legal obligation, Art 6(1)(c), in particular Section 14b UStG and German commercial and tax retention duties
Send transactional email (verification, magic-link sign-in, notifications)Email address, email contentPerformance of a contract, Art 6(1)(b)
Provide customer support and respond to enquiriesSupport correspondencePerformance of a contract, Art 6(1)(b), or our legitimate interest in answering enquiries from prospects, Art 6(1)(f)
Secure our systems, prevent abuse and fraud, rate-limit requests, and ensure availabilityService-integrity data (including the transient rate-limit key described in the Data Retention and Minimisation Policy)Our legitimate interest in the security and integrity of our service, Art 6(1)(f)
Optional preference cookies on our own sitePreference storageOur legitimate interest in honoring your settings, Art 6(1)(f), or consent under Art 6(1)(a) if reclassified, together with Section 25(1) TDDDG for storing or reading data on your device
Send product-marketing email to existing customers (planned, not yet active)Email address, consent and engagement recordsOur legitimate interest in direct marketing to existing customers, Art 6(1)(f), subject to Section 7(3) UWG, or consent under Art 6(1)(a)
Comply with legal requests and defend legal claimsAny relevant dataCompliance with a legal obligation, Art 6(1)(c), and legitimate interest in establishing or defending legal claims, Art 6(1)(f)

Where we rely on consent under Art 6(1)(a), you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

The legal basis for the visitor data Finalform processes on a customer's behalfis determined by that customer (the controller), together with the Section 25(1) TDDDG opt-in the customer obtains on its own pages. Finalform processes that data only on the customer's documented instructions (Art 28(3)(a)). See Section 12 and the Data Processing Agreement.

5. Recipients and sub-processors

We share personal data only with service providers and recipients who help us deliver and operate the service, and only as needed. Where these providers process personal data on our behalf, they act as our processors (sub-processors) under Article 28 GDPR contracts. Each sub-processor is bound by data-protection obligations equivalent to those we owe you, and Finalform remains liable for each sub-processor's performance.

Recipients, service or role, data received, region, and transfer mechanism
Recipient (legal entity)Service / roleData it receivesRegionTransfer mechanism
Railway Corporation (Delaware, US)Application hosting, compute, and managed PostgreSQL databaseAll account, configuration, and billing metadata we control, and the visitor data we process on customers' behalfAmsterdam, Netherlands (europe-west4-drams3a), confirmed 2026-07-30EU residency at rest only. That establishes where stored data rests, not the absence of a third-country transfer of the same data. A US processing leg remains and is a third-country transfer: Railway's addendum states that its primary processing takes place in the US and that the US transfer is necessary. For that leg, DPF where the recipient is certified, else the EU SCCs, which the addendum deems entered into, with a transfer impact assessment maintained either way
Anthropic, PBC (Delaware, US)Large language model that generates and rewrites landing-page copyTenant brief, baseline page copy, and population-level aggregate metrics only; no per-visitor data, no account dataUS (api.anthropic.com), and not the US alone: Anthropic states data may also go to other countries outside the EEA and the UKThird-country transfer → SCC + TIA. Anthropic makes no DPF claim and relies on standard contractual clauses for countries without an adequacy decision. No training on commercial API inputs or outputs, with the customer-controllable user-feedback setting off (confirmed 2026-07-30). Retention: 30 days, not zero; Anthropic may access inputs and outputs for safety and security purposes
Cloudflare, Inc. (Delaware, US)Browser Rendering API that renders a customer's landing page during baseline scrapeThe customer's public landing-page URL only; no visitor data, no account dataUS (api.cloudflare.com)US recipient → DPF certification (Cloudflare states it relies on its EU-U.S. DPF, Swiss-U.S. DPF and UK Extension certifications), else SCC + supplementary measures, with a transfer impact assessment maintained either way
Stripe Payments Europe, Limited (Ireland)Payment processing and billingCompany name, billing address, EU VAT-ID, account-holder billing email and name, organization-id metadata, subscription and transaction data; no card number stored by usEU for the contracting leg, with onward processing in the USThe contracting leg is intra-EEA, because the recipient is established in Ireland: the Stripe Services Agreement assigns accounts outside North and South America to Stripe Payments Europe, Limited, and we are a German GmbH. Stripe's onward processing in the US is a third-country transfer resting on Stripe's own safeguards; Stripe states it is DPF-certified
Resend (Plus Five Five, Inc., US)Transactional email delivery (verification, magic-link, password reset, invitations, notifications)Recipient email address, email content (subject and HTML body), and the recipient name in templatesUS (api.resend.com)US recipient → DPF certification (Plus Five Five, Inc. self-certified with the U.S. Department of Commerce), else SCC + TIA

We may also disclose personal data to professional advisers (for example, our tax adviser or lawyers) and to public authorities or courts where required by law.

For the current, complete, and dated list of sub-processors, including each provider's location and the data categories it processes, see the Sub-processor List. We maintain that list with a visible effective date and version, and provide advance notice of changes as described there.

6. International transfers and data residency

Your data is stored in the European Union. Our hosting and database provider (Railway) runs our database and every production service in Amsterdam, Netherlands (europe-west4-drams3a), confirmed on 2026-07-30. All personal data persisted by the Autopage application on Railway, including the pseudonymous visitor session identifier and behavioral events, rests in the EU. Copies held by our other providers are governed separately and are covered by the transfers described below. That establishes EU residency at rest only. It does not mean the same data undergoes no third-country transfer: Railway's separate US processing and access leg remains a third-country transfer, covered by the safeguards set out below.

We do not claim that no personal data ever leaves the EEA, because some does. We disclose this plainly rather than implying EU-only processing:

  • Railway Corporation is a US company. Its data processing addendum states that its primary processing operations take place in the United States and that transferring personal data to the United States is necessary to provide the services, so a US processing leg remainsalongside the EU storage location. A visitor's IP address also transits Railway's edge and proxy layer.
  • The AI provider (Anthropic) processes outside the EEA. Anthropic does not limit this to the United States: it states that data goes to its servers in the US, or to other countries outside the EEA and the UK.
  • The page-render API (Cloudflare) and the email provider (Resend) process data in the United States.
  • Stripe: our contracting entity is Stripe Payments Europe, Limited (Ireland), so the billing leg stays inside the EEA. Stripe's own onward processing may reach the US under Stripe's safeguards.

We disclose these transfers and their safeguard to you under Art 13(1)(f) GDPR. For each transfer to a third country we rely on an appropriate safeguard under Chapter V GDPR, either an adequacy decision (Art 45) or appropriate safeguards (Art 46):

  • EU-US Data Privacy Framework (DPF) adequacywhere the specific recipient entity is certified under the DPF. Where a recipient is DPF-certified, the transfer relies on the European Commission's adequacy decision for the DPF. This is the position for Cloudflare and Resend, and for Railway's residual US leg where the recipient is certified. Stripe also states it is DPF-certified, which is what its onward US processing rests on; the leg between us and Stripe is intra-EEA, because the recipient entity is established in Ireland.
  • Standard Contractual Clauses (SCCs) plus a transfer impact assessment (TIA), and supplementary measures where the assessment calls for them, wherever the recipient is not DPF-certified or makes no DPF claim. This is the position for Anthropic, which relies on standard contractual clauses for countries without an adequacy decision, and it is the fallback for every other recipient, including Cloudflare if its certification lapses.

The current transfer mechanism for each recipient is recorded, per recipient, in the Sub-processor List. A copy of the relevant safeguards, including the Standard Contractual Clauses, is available on request via the contact in Section 1.

7. Retention periods

We keep personal data only as long as necessary for the purposes for which it was collected, or as required by law, then delete or aggregate it. The full schedule, with a start trigger (Startzeitpunkt) for each category, is set out in the Data Retention and Minimisation Policy, which this policy incorporates by reference. The summary below states at least one concrete period per category and must not contradict that policy.

  • Account and tenant data: retained for the life of the account. On a deletion request or account closure, account and tenant data is deleted immediately and completely, with no grace tail.
  • Visitor interaction data(processed on customers' behalf): 90 days for raw events, after which they are deleted and only population-level counts that carry no identifier remain. Events belonging to an experiment that has not yet concluded are kept until it concludes, so that a running test is not decided on incomplete data. That hold currently has no outer limit, which means an experiment left paused or awaiting approval keeps its events for as long as it stays in that state; we are defining a maximum age after which they are deleted regardless.
  • Operational telemetry (LLM call telemetry, namely token counts and call duration, with no prompt or response content): 90 days.
  • Security and access logs: a target of 30 days, which applies once the dedicated log exists. No dedicated log exists yet, so this is a commitment we are building to and not a description of current behaviour.
  • Notifications: 30 days.
  • Sign-in security data (the login IP address and browser user agent stored in your dashboard session record, and the request counters our sign-in rate limiter keeps against an IP address): session records are deleted once they expire, which is 30 days after sign-in, and rate-limit counters are deleted after 30 days. This concerns account holders signing in to the dashboard, not visitors to our customers' pages.
  • Support correspondence: kept as long as needed to handle the matter and for a reasonable period afterwards to address follow-ups.
  • Marketing data: until you withdraw consent or object, after which we suppress your address as needed to honor your choice.
  • Invoices and accounting records: retained for the statutory period. German tax and commercial law requires retention of invoices (Buchungsbelege) for 8 years(Section 147 AO as amended by the Bürokratieentlastungsgesetz IV, effective 2025-01-01) and of business correspondence for 6 years (Section 257 HGB, Section 147 AO). These records live in our payment and external accounting systems. During the retention period the data is restricted to that purpose rather than actively used.

A scheduled job runs once daily and records what it deleted. It covers five of the categories above: raw visitor events with their session assignments, model-call telemetry, notifications, expired dashboard session records, and sign-in rate-limit counters. The other periods above are not on that clock; each runs on its own trigger, such as your deletion request, the end of a marketing relationship, or the statutory holds. The security and access log is the one entry that is neither: no dedicated log exists yet, so its 30-day figure is a commitment we are building to and not a description of current behaviour.

An erasure request does not override a statutory retention obligation. During such a hold the data is restricted, not deleted, and is erased once the statutory period ends.

8. Your rights as a data subject

Subject to the conditions and limits in the GDPR, you have the following rights regarding your personal data:

  • Access (Art 15): to obtain confirmation of whether we process your data and a copy of it.
  • Rectification (Art 16): to have inaccurate data corrected and incomplete data completed.
  • Erasure (Art 17): to have your data deleted where one of the grounds applies.
  • Restriction (Art 18): to have processing restricted in certain cases.
  • Data portability (Art 20): to receive data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection (Art 21): to object, on grounds relating to your particular situation, to processing based on legitimate interests, and to object at any time to processing for direct marketing.
  • Automated decision-making (Art 22): see Section 11.

Where processing is based on consent, you also have the right to withdraw consent at any time with effect for the future (Section 4).

To exercise any of these rights, contact us using the details in Section 1 (or the DPO once appointed, Section 2). We will respond without undue delay and in any event within one month of receiving the request. We may extend this by two further months for complex or numerous requests and will tell you if we do. We may need to verify your identity before acting.

9. Right to lodge a complaint

If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, place of work, or the place of the alleged infringement.

Our competent supervisory authority is:

Der Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen)
Prinzenstraße 5, 30159 Hannover, Germany

Exercising this right does not affect any other administrative or judicial remedy.

10. Is provision of data required?

Providing personal data is not a general legal requirement. However, certain data is necessary to enter into and perform our contract with you.

  • To create and operate an account, you must provide account identity data, your company name, and your confirmation that you are acting as a business. All three are required at signup: without them no account is created.
  • To purchase a paid plan, you must provide billing data so that we and our payment processor can process payment and so that we can issue a legally compliant invoice. If you are established in the EU, that includes a valid EU VAT identification number (see Section 3.3), collected at checkout rather than at signup.

If you do not provide the account identity data, the company name, or the business confirmation, we cannot create your account or provide the service. The EU VAT identification number is needed for billing and invoicing on a paid plan; without it we cannot process payment or issue a compliant invoice. Provision of optional data (for example, consent to marketing) is voluntary, and declining has no effect on the core service.

11. Automated decision-making and profiling

Finalform does not make decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR, in respect of the data covered by this policy.

Autopage's optimization works by population-level A/B experimentation. Visitors are assigned to a page variant at the level of the group, not the individual: the system serves different variants to groups of visitors, measures aggregate performance such as conversion rates across the whole group, and decides which variant performs better for the population. It does not build a profile of an identified individual and does not make a solely-automated decision that has legal or similarly significant effects on any one person. The AI component, a large language model supplied by Anthropic, PBC, generates and rewrites copy at the level of the page and its variants, not at the level of an individual visitor.

12. Controller and processor split: visitor data on customer pages

It is important to distinguish two different roles Finalform plays.

  • As controller (this policy): Finalform determines the purposes and means of processing for its own website visitors, account holders, billing, support, and marketing. That is what this Privacy Policy covers.
  • As processor(not this policy): When a business customer installs the Autopage JavaScript snippet on landing pages it owns or controls, Autopage processes the behavioral data of that customer's website visitors on the customer's behalf and on the customer's documented instructions. For that processing the customer is the controller and Finalform is the processor under Article 28 GDPR. That data is limited to a pseudonymous visitor session identifier and coarse, bucketed behavioral signals; Finalform persists no visitor IP address, user-agent string, precise geolocation, device fingerprint, or form input; a visitor IP address reaches our servers with every request as a technical necessity, is used only transiently in server memory (roughly 60 seconds) for rate limiting, and is never written to our database or application logs.

That processor relationship is governed by the Data Processing Agreement between Finalform and the customer, and by Section 8 of the Terms of Service, not by this Privacy Policy. Among other things, the customer is responsible for obtaining any visitor consent required under Section 25(1) TDDDG before the snippet stores or reads information on a visitor's device, and for the lawfulness of the processing it instructs.

If you are a visitor to a landing page operated by one of our customers and you have questions about how your data is used there, please contact that customer (the controller). We will assist the customer in responding as required by the Data Processing Agreement.

13. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing, our service, or the law. The date of the current version is shown in the "Last updated" line above. Where a change is material, we will take reasonable steps to inform affected account holders in advance, for example by email or an in-app notice. The version in force is the dated version published on our site at the relevant time.