1. Controller
iantix UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany, registered at Amtsgericht Charlottenburg under HRB 284619 and represented by managing director Jannik Janket, is controller for Speartip. Contact: hello@speartip.eu. Privacy requests: legal@speartip.eu.
2. Scope
This notice covers speartip.eu and related account, listing, launch, claim, verification, buyer-request, watchlist, communication, payment and analytics functions. A linked external service is governed by its own notice unless we state otherwise.
3. Processing principles and legal bases
We process only data needed for specified purposes and apply data minimisation, purpose limitation, accuracy, storage limitation, integrity and confidentiality. Depending on the activity, our bases are consent under Article 6(1)(a) GDPR, contract or pre-contractual steps under Article 6(1)(b), legal obligations under Article 6(1)(c), and the legitimate interests described below under Article 6(1)(f). Where Section 25 TDDDG applies to accessing or storing information on a device, we request consent unless the operation is strictly necessary for a service expressly requested by you.
4. Hosting and delivery
Hetzner Online GmbH provides EU hosting, storage and infrastructure as our processor. To deliver and secure requests, we process IP address, timestamp, requested host and path, request method, status, referrer, browser or user-agent information and transferred volume. The basis is Article 6(1)(f) GDPR; our interests are reliable delivery, diagnosis, capacity management, abuse detection and defence. Operational access logs are normally deleted after seven days unless a security event requires evidence to be retained longer.
5. Server-side operational statistics
We use GoAccess on our infrastructure for operational traffic reports. Query strings are excluded and IP addresses are anonymised for this analysis. It does not set an analytics cookie. Aggregated reports may be retained for capacity, security and service trend analysis where they no longer identify a person. The basis is Article 6(1)(f) GDPR and our interest in operating and improving a reliable service.
6. Accounts and registration
For native accounts we process name, email, professional role, organization, password hash, selected language, verification status and timestamps. We also process login, refresh and revocation data, security timestamps, failed attempts, truncated or recorded network and user-agent evidence where needed, and account state. The basis is Article 6(1)(b) GDPR and, for fraud and account security, Article 6(1)(f). Required fields are necessary to create and secure the account.
7. Google and LinkedIn sign-in
If you deliberately choose Google or LinkedIn, we redirect you to that provider and receive the provider identifier, verified email and the profile fields shown in the authorization flow. Google Ireland Limited or LinkedIn Ireland Unlimited Company independently processes the sign-in interaction under its own notice. We validate short-lived tokens and do not persist provider access or ID tokens. The bases are Article 6(1)(b) GDPR and your requested sign-in action; strictly necessary transaction storage is used for security.
8. Legal acceptance evidence
When you accept our Terms, we retain the accepted version, timestamp, Privacy Notice version, selected locale and, for vendor services, the business-user confirmation. This establishes contract formation and accountability. The bases are Article 6(1)(b), 6(1)(c) and 6(1)(f) GDPR; our legitimate interest is proving the applicable agreement and defending legal claims.
9. Listings, launches and vendor operations
We process submitter and business contact details; product, company, pricing, market, hosting, compliance and trust information; submission and review history; and submitted logos, files and technical metadata. During submission, ownership claims and listing management, the basis is Article 6(1)(b) GDPR and, for fraud prevention, provenance, editorial quality and legal evidence, Article 6(1)(f). Once approved information is published, the product or company record also forms part of Speartip’s independently maintained directory. Ending the account relationship removes the personal account link and management authority but does not by itself remove that public record.
10. Continued editorial listings and public sources
We maintain company and product facts, business domains, published listing statements, source references and limited professional information needed for an accurate and trustworthy European software directory. Information may originate from approved vendor submissions and may be checked, supplemented or updated from company websites, public registers, official social or professional profiles, press materials and other publicly accessible sources. The basis for personal data in the editorial record is Article 6(1)(f) GDPR; our interests are freedom of information, directory completeness and accuracy, prevention of duplicate or deceptive claims, provenance and platform integrity. We primarily retain data about legal entities and products, limit natural-person data to relevant professional context, exclude private-context and special-category data, distinguish vendor-supplied from independently reviewed information, mark listings as unclaimed when management ends, and provide free correction, claim, objection and rights routes. We assess source context, reasonable expectations, necessity, sensitivity, age, accuracy and impact. This basis is not used for unsolicited promotional email where consent is required.
11. Information under Article 14 GDPR
If we did not obtain your data from you, this notice supplies the source categories, purposes, legal bases, recipients, retention and rights information. Where required, we provide the information directly within one month, at first communication, or before first disclosure. Statutory exceptions remain applicable. You can request the specific source of your data at legal@speartip.eu.
12. Claims, verification and trust evidence
We process claimed domains, professional email targets, verification codes, DNS or email proof, evidence files, review notes, status and audit history. Public listing information is separated from confidential evidence. The bases are Article 6(1)(b) GDPR and Article 6(1)(f), with our interests in preventing impersonation and keeping trust statements supportable.
13. Buyer Requests and matching
We process contact and organization data, professional role, requirements, categories, budget range, timeframe, hosting and compliance preferences, notes, selected products, matching and handling status to process the request and, where requested, introduce suitable vendors. The basis is Article 6(1)(b) GDPR and Article 6(1)(f) for fraud prevention and auditable handling. We disclose request information to vendors only as described when you submit the request or with a separate choice.
14. Watchlists and service notifications
We process account or email details, selected objects, language, verification and delivery status to provide a watchlist or notification you request. The basis is Article 6(1)(b) GDPR. Security, contract and service messages are not marketing and may be required to operate your account.
15. Newsletters and promotional email
We send newsletters or promotional email only with prior consent under Article 6(1)(a) GDPR and Section 7 UWG, or under the narrow existing-customer exception where all statutory requirements are met. We retain address, scope, wording/version, timestamp and double-opt-in evidence. Consent is voluntary and can be withdrawn at any time through the message link or at legal@speartip.eu without affecting prior lawful processing. Delivery providers act under appropriate terms.
16. Communications and legal cases
When you contact us, we process contact, content, attachments, routing, status and correspondence history to answer and document the matter. The basis is Article 6(1)(b) GDPR for contract-related matters and otherwise Article 6(1)(f), with interests in effective communication and legal defence; legal retention may rely on Article 6(1)(c).
17. Billing and Stripe
For a paid EU business order we send Stripe Payments Europe, Limited and relevant Stripe group entities the customer and billing details, plan, price, country, business and tax identifiers, and transaction metadata required for VAT-ID verification, hosted checkout, payment processing, tax calculation, invoicing, fraud prevention and the customer portal. Outside Germany, we store the Stripe Tax ID reference, verification status and timestamps and recheck eligibility before checkout and renewal. iantix UG remains the seller and tax-liable merchant. Stripe acts as our processor for services performed on our instructions and as an independent controller where Stripe determines processing for its own fraud, security, regulatory and legal obligations, as described in Stripe’s Privacy Policy and our data-processing terms. We receive customer, Tax ID, Checkout Session, PaymentIntent, subscription, invoice, refund, dispute and status identifiers and signed webhook events. We remove detailed raw webhook payloads 30 days after successful processing or intentional ignoring while retaining event hashes, identifiers, outcomes, VAT-verification evidence and legally required billing records. Our basis is Article 6(1)(b) and 6(1)(c) GDPR and, for fraud, security and reconciliation, Article 6(1)(f). Speartip does not receive full payment-card credentials.
18. Consent manager
We store the categories you choose, notice version and choice time locally in your browser so that optional services remain disabled unless accepted and your decision can be demonstrated on that device. This storage is strictly necessary to implement your privacy choice. You can reopen the settings at any time. Optional consent is separate from account and contract acceptance.
19. Microsoft Clarity
On public pages only, and only after analytics consent, Microsoft Clarity records interaction and diagnostic information such as clicks, scrolls, mouse movement, page and DOM state, visited URLs, device and browser details, performance and error information, cookie identifiers and approximate location derived from IP. Microsoft Ireland Operations Limited is an independent controller for its processing. We use the information to detect usability problems and improve public pages. The bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Clarity is not loaded in vendor or admin workspaces. You can withdraw consent at any time in Privacy settings.
20. Clarity retention and transfers
According to Microsoft, session recordings are retained for 30 days and certain click, heatmap and favourited-session data for up to 13 months. Microsoft may process data outside the EEA. Depending on the recipient and transfer, safeguards include an applicable adequacy decision such as the EU-US Data Privacy Framework and the European Commission standard contractual clauses. Microsoft’s current terms and privacy documentation govern its independent processing.
21. First-party performance measurement
We count selected page deliveries and business events for aggregate vendor statistics. The dedicated event contains no IP address, user-agent, cookie, account, visitor or session identifier and is not linked to Clarity. Raw events are deleted after 35 days and daily aggregates after 25 months. No information is stored on or read from your device for this measurement. To the extent an event could still be personal in context, the basis is Article 6(1)(f) GDPR and our interests in service quality, fraud-resistant reporting and providing vendors with proportionate aggregate performance information.
22. Recipients
Access is limited by role and need. Recipient categories are hosting, storage and email infrastructure; identity providers chosen by you; payment and tax infrastructure used for your order; optional analytics chosen by you; professional advisers, auditors and insurers bound by confidentiality; and courts or authorities where legally required. Current named providers relevant to the public service are Hetzner Online GmbH, Google Ireland Limited, LinkedIn Ireland Unlimited Company, Microsoft Ireland Operations Limited and Stripe Payments Europe, Limited with relevant Stripe group entities and subprocessors. We do not sell personal data.
23. International transfers
Our core hosting is in the EU. Google, LinkedIn, Microsoft and Stripe may use group companies or subprocessors outside the EEA. We rely, as applicable, on an adequacy decision, EU-US Data Privacy Framework certification covering the recipient and data, or standard contractual clauses plus supplementary measures. Copies or information about the relevant safeguard are available from legal@speartip.eu, subject to protection of confidential terms.
24. General retention and account closure
We keep identifiable data only for the purpose-specific period, then delete or irreversibly anonymise it unless law or a documented legal-defence need requires longer storage. On an approved account erasure, active credentials, external identities, subscriptions and account-linked activity are removed and personal fields in necessary account or review records are deleted or de-identified. A vendor workspace is deactivated when no active account remains; its public products and company are detached from that workspace and marked unclaimed rather than automatically deleted. Account and service evidence needed for legal claims is restricted through the applicable limitation period. Pending registrations expire after 24 hours, short-lived sign-in transactions after approximately ten minutes, access sessions normally after 15 minutes and refresh sessions after 30 days unless revoked sooner.
25. Specific retention
Operational access logs are normally kept seven days. First-party measurement follows Section 21 and Clarity follows Section 20. Public company and product records are retained while they remain current and relevant to the directory; inaccurate, outdated, unlawful or no-longer-necessary personal elements are corrected, restricted or removed following review. Published non-personal business facts and content may therefore outlast an account relationship. Private drafts and confidential verification evidence do not become editorial listing content and are deleted when the relevant review, security, legal-evidence and backup periods end. Upvote and follow change events are deleted after 90 days; the current signal remains until it is removed or the account is erased. Unconfirmed newsletter and watchlist records are deleted within 24 hours after becoming stale or expired. Newsletter data is kept until withdrawal; withdrawal and consent evidence is deleted after three years. Expired claim-verification challenges are deleted after a further 30 days, and closed Buyer Requests after 24 months. An expired unpaid checkout draft is stripped of staged contact and product-form data by the retention sweep; a successfully submitted launch draft is stripped immediately. Confirmed moderation and security evidence may be kept through the relevant relationship and limitation period where proportionate.
26. Statutory records and backups
Commercial books and core accounting records may be retained for ten years, accounting vouchers and invoices generally eight years, and business correspondence generally six years under applicable German law. Periods begin and may be suspended as provided by law. Encrypted backups follow a rolling operational schedule; deletion takes effect in production first and in remaining backups when they expire, unless a backup must be isolated for a documented incident or legal hold.
27. Requirement to provide data
There is generally no statutory obligation to give us data. Fields marked or functionally required are necessary to register, authenticate, contract, bill, verify a claim or process your request; without them, we cannot provide that function. Optional fields can be omitted.
28. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Fraud and ranking signals may support human or rules-based operational decisions as described in the Terms.
29. Your rights
Subject to statutory conditions, you may request access, correction, erasure, restriction, data portability and a copy of provided data, and may withdraw consent at any time for the future. You may object under Article 21 GDPR to processing based on legitimate interests for reasons arising from your situation; while an objection is assessed, disputed personal data is restricted where required. We stop direct marketing upon objection without a balancing test. Contact legal@speartip.eu. We may verify identity and normally respond within one month. Account closure and removal of an editorial listing are distinct: approved account erasure removes account links and personal operational data as described in Section 24, while company and product records may remain unclaimed. A separate correction, objection, intellectual-property or removal request is reviewed free of charge; personal data is removed unless a continuing lawful basis or an applicable Article 17 exception supports the necessary processing. Statutory billing records and proportionate legal evidence are restricted rather than used operationally. Required processor or recipient notifications are handled as part of the request.
30. Complaints
You may complain to any competent supervisory authority, particularly in your place of residence, workplace or the alleged infringement. Our lead local authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, mailbox@datenschutz-berlin.de, https://www.datenschutz-berlin.de.
31. Security
We use risk-appropriate technical and organizational measures, including transport encryption, access control, environment separation, least-privilege operation, credential hashing, signed and expiring sessions, audit-relevant records, backups and security monitoring. No internet service is risk-free; please report suspected incidents to legal@speartip.eu.
32. Children
Business account and submission services are not directed to children. We do not knowingly request children’s data for these services. If you believe a child has provided data improperly, contact us for review.
33. Changes
We update this notice when processing or law materially changes. The current version and date are published here. Where a change materially affects an existing processing choice, we provide an appropriate notice and request renewed consent where required.
