This English text is a convenience translation. The legally binding version is the German one (Deutsch), reachable via the language switch below.
Last updated: 2026-08-21
This Privacy Policy is published in English and German. The German version (Datenschutzerklärung) is the binding version; the English text is a convenience translation. In case of conflict, the German version prevails.
This Privacy Policy explains how Finalform GmbH ("Finalform", "we", "us") processes personal data in its role as data controller. It applies to visitors of our websites at autopage.dev and app.autopage.dev, to account holders and their authorized users, to billing and payment data, and to marketing communications.
This policy does not govern the visitor behavioral data that Autopage processes on the landing pages of our business customers. For that processing Finalform acts as a processoron the customer's behalf. That relationship is governed by the Data Processing Agreement and Section 8 of the Terms of Service. See Section 12 below for the full controller and processor split.
We collect personal data directly from you (Article 13 GDPR applies; we do not source your data from third-party brokers or data-enrichment vendors). We process no special categories of personal datawithin the meaning of Article 9 GDPR. Where Autopage performs cross-tenant "enrichment", that is non-personal, aggregated industry-benchmark data and is not personal data about you.
Autopage is a business-to-business (B2B) service. We contract only with businesses and entrepreneurs (Unternehmer within the meaning of Section 14 BGB). We do not knowingly serve consumers.
The controller responsible for the data processing described in this policy is:
Finalform GmbH
Theodor-Heuss-Str. 106
26129 Oldenburg
Germany
For full provider identification details, see the Impressum.
Finalform is appointing an external Data Protection Officer (DPO) before go-live. The appointed DPO's name and contact details (email and postal address) will be published here, and notified to the supervisory authority (LfD Niedersachsen), before the service goes live.
Until the appointment is published, data protection enquiries can be directed to the controller contact in Section 1.
We expect to be legally required to appoint a DPO. A Data Protection Impact Assessment (DPIA) under Article 35 GDPR is very likely mandatory for Autopage given the combination of visitor behavioral measurement and AI-driven content optimization. Under Section 38(1) BDSG, a controller that is required to carry out a DPIA must appoint a Data Protection Officer regardless of headcount. We appoint an external DPO on that basis.
We collect the following categories of personal data, in each case directly from you or generated by your use of the service. We collect only what we need for the stated purpose.
This describes a planned capability; Autopage does not currently send marketing email, so the email recipient in Section 5 is transactional only.
We process the personal data above for the purposes and on the legal bases set out below. Where we rely on legitimate interests under Art 6(1)(f), the interest pursued is named (Art 13(1)(d)).
| Purpose | Categories of data | Legal basis (Art 6 GDPR) |
|---|---|---|
| Provide and operate the Autopage application (authentication, dashboard, optimization runs) | Account data, configuration and usage data | Performance of a contract, Art 6(1)(b) |
| Operate and secure our public website | Functional cookie and storage data | Our legitimate interest in operating and securing the website, Art 6(1)(f) |
| Create and administer your account and authenticate users | Account identity and credentials | Performance of a contract, Art 6(1)(b) |
| Record the customer's business self-attestation at signup and check the EU VAT identification number after purchase | Company name, business confirmation record, VAT-ID and the validation status reported for it | Performance of a contract and pre-contractual steps, Art 6(1)(b), and compliance with our tax and invoicing obligations, Art 6(1)(c) |
| Process subscriptions, payments, and invoicing via Stripe | Billing data, transaction records | Performance of a contract, Art 6(1)(b), and compliance with a legal obligation for invoicing, Art 6(1)(c) |
| Keep accounting and tax records | Invoices and related records | Compliance with a legal obligation, Art 6(1)(c), in particular Section 14b UStG and German commercial and tax retention duties |
| Send transactional email (verification, magic-link sign-in, notifications) | Email address, email content | Performance of a contract, Art 6(1)(b) |
| Provide customer support and respond to enquiries | Support correspondence | Performance of a contract, Art 6(1)(b), or our legitimate interest in answering enquiries from prospects, Art 6(1)(f) |
| Secure our systems, prevent abuse and fraud, rate-limit requests, and ensure availability | Service-integrity data (including the transient rate-limit key described in the Data Retention and Minimisation Policy) | Our legitimate interest in the security and integrity of our service, Art 6(1)(f) |
| Optional preference cookies on our own site | Preference storage | Our legitimate interest in honoring your settings, Art 6(1)(f), or consent under Art 6(1)(a) if reclassified, together with Section 25(1) TDDDG for storing or reading data on your device |
| Send product-marketing email to existing customers (planned, not yet active) | Email address, consent and engagement records | Our legitimate interest in direct marketing to existing customers, Art 6(1)(f), subject to Section 7(3) UWG, or consent under Art 6(1)(a) |
| Comply with legal requests and defend legal claims | Any relevant data | Compliance with a legal obligation, Art 6(1)(c), and legitimate interest in establishing or defending legal claims, Art 6(1)(f) |
Where we rely on consent under Art 6(1)(a), you may withdraw it at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the visitor data Finalform processes on a customer's behalfis determined by that customer (the controller), together with the Section 25(1) TDDDG opt-in the customer obtains on its own pages. Finalform processes that data only on the customer's documented instructions (Art 28(3)(a)). See Section 12 and the Data Processing Agreement.
We share personal data only with service providers and recipients who help us deliver and operate the service, and only as needed. Where these providers process personal data on our behalf, they act as our processors (sub-processors) under Article 28 GDPR contracts. Each sub-processor is bound by data-protection obligations equivalent to those we owe you, and Finalform remains liable for each sub-processor's performance.
| Recipient (legal entity) | Service / role | Data it receives | Region | Transfer mechanism |
|---|---|---|---|---|
| Railway Corporation (Delaware, US) | Application hosting, compute, and managed PostgreSQL database | All account, configuration, and billing metadata we control, and the visitor data we process on customers' behalf | Amsterdam, Netherlands (europe-west4-drams3a), confirmed 2026-07-30 | EU residency at rest only. That establishes where stored data rests, not the absence of a third-country transfer of the same data. A US processing leg remains and is a third-country transfer: Railway's addendum states that its primary processing takes place in the US and that the US transfer is necessary. For that leg, DPF where the recipient is certified, else the EU SCCs, which the addendum deems entered into, with a transfer impact assessment maintained either way |
| Anthropic, PBC (Delaware, US) | Large language model that generates and rewrites landing-page copy | Tenant brief, baseline page copy, and population-level aggregate metrics only; no per-visitor data, no account data | US (api.anthropic.com), and not the US alone: Anthropic states data may also go to other countries outside the EEA and the UK | Third-country transfer → SCC + TIA. Anthropic makes no DPF claim and relies on standard contractual clauses for countries without an adequacy decision. No training on commercial API inputs or outputs, with the customer-controllable user-feedback setting off (confirmed 2026-07-30). Retention: 30 days, not zero; Anthropic may access inputs and outputs for safety and security purposes |
| Cloudflare, Inc. (Delaware, US) | Browser Rendering API that renders a customer's landing page during baseline scrape | The customer's public landing-page URL only; no visitor data, no account data | US (api.cloudflare.com) | US recipient → DPF certification (Cloudflare states it relies on its EU-U.S. DPF, Swiss-U.S. DPF and UK Extension certifications), else SCC + supplementary measures, with a transfer impact assessment maintained either way |
| Stripe Payments Europe, Limited (Ireland) | Payment processing and billing | Company name, billing address, EU VAT-ID, account-holder billing email and name, organization-id metadata, subscription and transaction data; no card number stored by us | EU for the contracting leg, with onward processing in the US | The contracting leg is intra-EEA, because the recipient is established in Ireland: the Stripe Services Agreement assigns accounts outside North and South America to Stripe Payments Europe, Limited, and we are a German GmbH. Stripe's onward processing in the US is a third-country transfer resting on Stripe's own safeguards; Stripe states it is DPF-certified |
| Resend (Plus Five Five, Inc., US) | Transactional email delivery (verification, magic-link, password reset, invitations, notifications) | Recipient email address, email content (subject and HTML body), and the recipient name in templates | US (api.resend.com) | US recipient → DPF certification (Plus Five Five, Inc. self-certified with the U.S. Department of Commerce), else SCC + TIA |
We may also disclose personal data to professional advisers (for example, our tax adviser or lawyers) and to public authorities or courts where required by law.
For the current, complete, and dated list of sub-processors, including each provider's location and the data categories it processes, see the Sub-processor List. We maintain that list with a visible effective date and version, and provide advance notice of changes as described there.
Your data is stored in the European Union. Our hosting and database provider (Railway) runs our database and every production service in Amsterdam, Netherlands (europe-west4-drams3a), confirmed on 2026-07-30. All personal data persisted by the Autopage application on Railway, including the pseudonymous visitor session identifier and behavioral events, rests in the EU. Copies held by our other providers are governed separately and are covered by the transfers described below. That establishes EU residency at rest only. It does not mean the same data undergoes no third-country transfer: Railway's separate US processing and access leg remains a third-country transfer, covered by the safeguards set out below.
We do not claim that no personal data ever leaves the EEA, because some does. We disclose this plainly rather than implying EU-only processing:
We disclose these transfers and their safeguard to you under Art 13(1)(f) GDPR. For each transfer to a third country we rely on an appropriate safeguard under Chapter V GDPR, either an adequacy decision (Art 45) or appropriate safeguards (Art 46):
The current transfer mechanism for each recipient is recorded, per recipient, in the Sub-processor List. A copy of the relevant safeguards, including the Standard Contractual Clauses, is available on request via the contact in Section 1.
We keep personal data only as long as necessary for the purposes for which it was collected, or as required by law, then delete or aggregate it. The full schedule, with a start trigger (Startzeitpunkt) for each category, is set out in the Data Retention and Minimisation Policy, which this policy incorporates by reference. The summary below states at least one concrete period per category and must not contradict that policy.
A scheduled job runs once daily and records what it deleted. It covers five of the categories above: raw visitor events with their session assignments, model-call telemetry, notifications, expired dashboard session records, and sign-in rate-limit counters. The other periods above are not on that clock; each runs on its own trigger, such as your deletion request, the end of a marketing relationship, or the statutory holds. The security and access log is the one entry that is neither: no dedicated log exists yet, so its 30-day figure is a commitment we are building to and not a description of current behaviour.
An erasure request does not override a statutory retention obligation. During such a hold the data is restricted, not deleted, and is erased once the statutory period ends.
Subject to the conditions and limits in the GDPR, you have the following rights regarding your personal data:
Where processing is based on consent, you also have the right to withdraw consent at any time with effect for the future (Section 4).
To exercise any of these rights, contact us using the details in Section 1 (or the DPO once appointed, Section 2). We will respond without undue delay and in any event within one month of receiving the request. We may extend this by two further months for complex or numerous requests and will tell you if we do. We may need to verify your identity before acting.
If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, place of work, or the place of the alleged infringement.
Our competent supervisory authority is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (LfD Niedersachsen)
Prinzenstraße 5, 30159 Hannover, Germany
Exercising this right does not affect any other administrative or judicial remedy.
Providing personal data is not a general legal requirement. However, certain data is necessary to enter into and perform our contract with you.
If you do not provide the account identity data, the company name, or the business confirmation, we cannot create your account or provide the service. The EU VAT identification number is needed for billing and invoicing on a paid plan; without it we cannot process payment or issue a compliant invoice. Provision of optional data (for example, consent to marketing) is voluntary, and declining has no effect on the core service.
Finalform does not make decisions about you that are based solely on automated processing and that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR, in respect of the data covered by this policy.
Autopage's optimization works by population-level A/B experimentation. Visitors are assigned to a page variant at the level of the group, not the individual: the system serves different variants to groups of visitors, measures aggregate performance such as conversion rates across the whole group, and decides which variant performs better for the population. It does not build a profile of an identified individual and does not make a solely-automated decision that has legal or similarly significant effects on any one person. The AI component, a large language model supplied by Anthropic, PBC, generates and rewrites copy at the level of the page and its variants, not at the level of an individual visitor.
It is important to distinguish two different roles Finalform plays.
That processor relationship is governed by the Data Processing Agreement between Finalform and the customer, and by Section 8 of the Terms of Service, not by this Privacy Policy. Among other things, the customer is responsible for obtaining any visitor consent required under Section 25(1) TDDDG before the snippet stores or reads information on a visitor's device, and for the lawfulness of the processing it instructs.
If you are a visitor to a landing page operated by one of our customers and you have questions about how your data is used there, please contact that customer (the controller). We will assist the customer in responding as required by the Data Processing Agreement.
We may update this Privacy Policy to reflect changes in our processing, our service, or the law. The date of the current version is shown in the "Last updated" line above. Where a change is material, we will take reasonable steps to inform affected account holders in advance, for example by email or an in-app notice. The version in force is the dated version published on our site at the relevant time.