Privacy

The text below is an English reading version, provided for convenience only. Only the German version is legally binding.

Part 1 · What the Provider is responsible for

The controller for this website, the registration, the accounts and the subscription of the businesses, the technical operation and requests to us is Kutvention – Inh. Aykut Bicak (sole proprietorship), Seewenjestraße 175A, 28237 Bremen, email support@ventiondesk.com. No data protection officer has been appointed.

For the data in VentionDesk — customers, projects, requests, invoices of a business, including in a business’s customer portal — the respective business is the controller; we process this data on its behalf (Part 2). The distinction determines whom you contact with a request for access or erasure.

Registration, contract and subscription

For the contract on the use of VentionDesk, we process the details from the registration — name and email address of the acting person, name and business address of the business, plan, payment interval and number of users, later the company details that the business stores for its documents — as well as the record of when who agreed to which version of the general terms and conditions and of the data processing agreement and by which route, and declared at registration to act as a business, together with a checksum of the wording. If the customer is a natural person, we process the data to perform the contract (Art. 6(1)(b) GDPR). We process data of employees, representatives and contact persons of other customers on the basis of our legitimate interest in initiating, performing and managing the business relationship (Art. 6(1)(f) GDPR).

The business pays for the subscription via Stripe (Stripe Payments Europe, Limited, Dublin, Ireland). For this purpose, Stripe receives name, address and email address, plan, number of users and amounts as well as the payment data that the business enters at Stripe itself; we do not see the payment data. Content from VentionDesk is not passed to Stripe. Depending on the processing operation, Stripe processes personal data as an independent controller (for example for fraud prevention and to comply with legal obligations) or on our behalf; it may also process data in the USA, based on the EU-US Data Privacy Framework and standard contractual clauses.

We store this data for the duration of the contract. After it ends, it remains available for export for 30 days and is then deleted together with the business, earlier at the request of the business. Exempt from this are accounting records, which we keep under § 147 AO (German Fiscal Code) and § 257 HGB (German Commercial Code) until the retention period expires, and the record of consent: name of the business, document, version, checksum, decision, time and route, as well as name and email address of the person who decided. On deletion we transfer it into a separate archive without the other data of the business, keep it for 3 years from the end of the calendar year in which the contract ends (§§ 195, 199 BGB, German Civil Code), and delete it afterwards.

Sign-in

Sign-in takes place without a password via a code or link sent to the account’s email address. Where the sign-in page offers it, the person can instead sign in with a passkey; for this, its public key, the chosen name and the times of creation and last use are stored with the sign-in service until it is removed. Anyone who wishes can additionally set up a second factor, a one-time code from an authenticator app; for this, its secret key is stored with the sign-in service until it is removed. The only exception to signing in without a password are reviewer accounts that we provide to the reviewers of app directories for reviewing our integration: they sign in with email address and password, which the sign-in service stores only as a hash. The legal basis is Art. 6(1)(b) GDPR; for accounts that a business creates for its staff members and customers, we process the sign-in data on its behalf.

Contact form and email to us

If you write to us via the contact form or by email, we process name, email address, message and the page visited in order to handle your request. The legal basis is Art. 6(1)(b) GDPR insofar as the request concerns a contract, otherwise our legitimate interest in answering it (Art. 6(1)(f) GDPR). The request is handled in our own VentionDesk. For rate limiting, the server briefly counts the requests per IP address in memory; our application does not store the address. It may be contained in the logs of the service providers through which the request passes (Cloudflare, Vercel, Render) for their retention period (see “Technical operation”). We store the request until it has been dealt with and thereafter until the end of the regular limitation period.

Reports of illegal content

If you report content to us as illegal (Art. 16 of the Digital Services Act, reporting route in the legal notice), we process your name and email address, your reasoning, the location and the reported content in order to confirm receipt, review the report and inform you and, where applicable, the business concerned of the decision (Art. 16 and 17 DSA). The legal basis is compliance with this legal obligation (Art. 6(1)(c) GDPR). If the reported content is part of a business’s data, we look at it for the review and record this access. The report is handled like a request in our own VentionDesk and stored for the same period.

Protection of the forms (Cloudflare Turnstile)

To protect the contact form and the registration against automated submissions, we use Cloudflare Turnstile (Cloudflare, Inc., San Francisco, USA). The check script is loaded only when you start filling in one of these forms, not when the page is opened. It then reads technical characteristics of your browser and your connection, such as IP address, browser identifier and connection characteristics, and transmits them to Cloudflare. Access to your device is strictly necessary for the submission you requested (§ 25(2) no. 2 TDDDG, German Telecommunications Digital Services Data Protection Act); the legal basis for the processing is our legitimate interest in protection against misuse (Art. 6(1)(f) GDPR).

Cloudflare processes this data on our behalf and also uses it as an independent controller to improve bot detection; details are set out in Cloudflare’s Turnstile privacy addendum, which also governs the storage period at Cloudflare. When you submit, our server asks Cloudflare, using the check token and your IP address, whether the check has been passed; our application stores neither the characteristics nor the IP address. The IP address may be contained in the logs of the service providers (Cloudflare, Render, Vercel) for their retention period (see “Technical operation”). The transfer to the USA is based on the adequacy decision for the EU-US Data Privacy Framework, supplemented by standard contractual clauses. If a submission is rejected, email remains available as an alternative.

Technical operation

Operation produces delivery logs at Vercel, runtime logs at Render and error reports at Sentry. The logs at Vercel and Render may contain the IP address of a request; our application itself does not write IP addresses to its logs. Error reports contain the error message, code location, page address and the previously visited addresses, each without query parameters, and the browser identifier; we do not include cookies, IP address or request content, and we do not set an identifier of the signed-in person. If an error report comes from your browser, Sentry nevertheless sees the IP address of the connection when receiving it. The legal basis is our legitimate interest in secure and error-free operation (Art. 6(1)(f) GDPR). The delivery logs at Vercel are deleted after one day at the latest, the runtime logs at Render after 14 days at the latest and error reports at Sentry after 30 days at the latest. If a log contains data of a business, we process it on that business’s behalf.

Cookies and storage in the browser

  • “sb-…-auth-token” — Cookie of the sign-in service (Supabase), for long values in the parts “.0” and “.1”. Keeps you signed in; set only on sign-in, “Secure” and “SameSite=Lax”, deleted on sign-out. After 30 days without use, the sign-in ends (setting at the sign-in service) and the cookie is removed on the next visit; its technical lifetime is up to 400 days.
  • “sb-…-auth-token-code-verifier” — Cookie of the sign-in service. When signing in via a link, holds the one-time secret with which the link is redeemed; set when you request a sign-in link, deleted after redemption. If the link is not redeemed, it remains until the next sign-in, technically for at most 400 days.
  • “NEXT_LOCALE” — Cookie with the selected language of the interface; set when you choose a language, and after sign-in if a different language is stored in your account. Lifetime one year, “SameSite=Lax”.
  • “ventiondesk:farbschema” — Browser storage (localStorage): light, dark or as the system; set when you choose the display, until you clear the storage.
  • “ventiondesk:ansicht” — localStorage: normal or desktop view; set when you choose the view, until you clear the storage.
  • “ventiondesk:fenster:…” — localStorage: position, size and address of the open windows in the desktop view, per account (the colon is followed by the account ID); set while you use the desktop view, deleted on sign-out.
  • “ventiondesk.projekte.ansicht, ventiondesk.projekte.sortierung, ventiondesk.ideen.ansicht” — localStorage: selected view and sorting of the project list and view of the ideas; set when you choose them, until you clear the storage.
  • “vd.rechtstext.spaeter” — localStorage: your choice “Decide later” in the notice about a new version of the general terms and conditions or the data processing agreement, so that it does not reappear during this sign-in; deleted on sign-out.
  • “Cloudflare Turnstile” — Check script, only when you fill in the contact form or the registration; it reads characteristics of your browser (see “Protection of the forms”), duration according to Cloudflare’s rules.

Each of these accesses to your device is strictly necessary for us to provide the service you requested — sign-in, language, display and view that you choose yourself, and the protection of the forms — and therefore does not require consent (§ 25(2) no. 2 TDDDG). We do not use advertising, analytics or audience measurement tools; we do not measure any interactions in the browser.

AI tools

VentionDesk does not, on its own initiative, transmit any data to providers of AI models. A business can connect AI tools — with a key for the programming interface or as an AI app such as Claude, ChatGPT or Cursor via the VentionDesk sign-in (OAuth, see Part 2 “Connected AI apps”). This is done under its own contract with the provider and at its own responsibility.

A connected tool acts only within the rights that the business grants. It can then, for example, read and edit tasks and requests and create drafts of invoices and quotes; it cannot finalise, send or record payments. It can reply to customers on a request by email only with the separately enabled right “Reply to customers on tickets by email”; every such reply carries a fixed notice that an AI assistant wrote it.

Recipients

  • Supabase (Supabase Pte. Ltd., Singapore) — database, sign-in and file storage, stored in Frankfurt am Main (eu-central-1)
  • Vercel (Vercel Inc., USA) — delivery of the website, server functions in Frankfurt am Main (fra1)
  • Render (Render Services, Inc., USA) — programming interface and background services in Frankfurt am Main
  • Resend (Plus Five Five, Inc., USA) — sending of emails from Ireland; Resend stores messages and delivery logs in the USA and deletes them after 30 days
  • Sentry (Functional Software, Inc., USA) — error reports, stored in the EU
  • Cloudflare (Cloudflare, Inc., USA) — bot check on public forms, network service in front of the programming interface and daily backup of the stored files in the EU (R2), encrypted only; deleted files disappear there after 30 days
  • Stripe (Stripe Payments Europe, Limited, Ireland) — payment of the subscription

Data processing agreements under Art. 28 GDPR are in place with Supabase, Vercel, Render, Resend, Sentry and Cloudflare. A transfer to the USA is based on the adequacy decision for the EU-US Data Privacy Framework and additionally on the standard contractual clauses of the European Commission, in the case of Supabase on the standard contractual clauses. The corporate groups are headquartered in the USA; authorities there may demand access under the law applicable there.

Part 2 · The data of the businesses

The data that a business keeps in VentionDesk — its customers and their contact persons, projects, tasks, requests from its forms, apps and mailboxes, times, quotes, invoices and documents, plus its customer portal — is the responsibility of this business. It decides on purposes and legal bases; we process the data on its behalf under the data processing agreement (Art. 28 GDPR) and not for our own purposes.

If you have sent a request to a business or use its customer portal, please contact this business with questions about your data; its details can be found in its messages to you and in its portal. If such a request reaches us, we forward it to the business.

Separation of the businesses

Each business has its own workspace. Every row and every file carries the identifier of its business, and the database itself enforces the separation (row-level security) — not just the user interface. Within a business, the role also applies: only the owner sees hourly rates and budgets, and customers in the portal see only what their business releases.

Periods set by the Software

The following are deleted or cleared automatically:

  • the raw data with which connected services deliver something (such as the notification of an email to a mailbox including its text) after 90 days — the text of the email remains as a message in the request; deliveries with an invalid signature are deleted entirely after just 7 days;
  • the technical metadata of a request (browser, page address, app version) after 90 days — the request itself remains;
  • screenshots received with a request via form, app or email after 90 days — files that a customer attaches in the customer portal remain, like the request itself;
  • availability checks after 30 days;
  • errors from connected error-tracking services, once they are resolved or ignored, 30 days thereafter;
  • entries in the change log 3 years after the end of the calendar year in which they were created — entries on invoices and payments (finalising, cancellation, sending, payment reminder and dunning notice, booking and refund of a payment) only after 10 years;
  • the entire workspace of a business 30 days after the end of its contract;
  • the copy of a deleted or replaced file in the daily, encrypted backup of the files (Cloudflare R2, EU) 30 days after the deletion.

The other logs — the activity history, the runs of AI agents, the details of connections of AI apps and the records of accesses by the Provider — are not deleted by the Software after a set period: they remain as a record until the business’s workspace is deleted; entries in the activity history of a project or customer go with it already.

The remaining data — requests, projects, times, invoices — is deleted by the business as soon as its retention obligations permit; for example, it retains invoices for eight years under § 147 AO (German Fiscal Code). The Software presents cases without a customer that have been dormant for a long time to the business for review.

Service providers

We use the following to operate the Software:

  • Supabase Pte. Ltd., Singapore — database, file storage and sign-in; storage in Frankfurt am Main (EU); access for maintenance and support also possible from countries outside the EU, including the USA
  • Render Services, Inc., San Francisco, USA — operation of the programming interface, the intakes and the scheduled jobs; Frankfurt am Main (EU)
  • Vercel Inc., Covina, USA — delivery of the web interface and the customer portal; server functions in Frankfurt am Main (EU); delivery via locations worldwide
  • Plus Five Five, Inc. (Resend), San Francisco, USA — sending and receiving email; sending from Ireland (EU); messages and delivery logs in the USA
  • Functional Software, Inc. (Sentry), San Francisco, USA — error reports and availability monitoring; storage in the EU
  • Cloudflare, Inc., San Francisco, USA — bot check (Turnstile) on public forms, network service in front of the programming interface and encrypted backup of the files (R2, EU); bot check and network service worldwide (location close to the requesting person); backup in the EU (R2 storage with EU jurisdiction), encrypted only, the key held solely by the Provider

Services that a business connects itself — an AI tool, its own email, hosting, error-tracking or payment service such as Stripe — are its recipients; its own privacy information applies to them.

Connected AI apps

Owners and staff members of a business can connect AI apps such as Claude, ChatGPT or Cursor to their business’s workspace via the VentionDesk sign-in (OAuth). The owner of the business determines which rights staff members may grant in the process. When connecting, the person selects the business, rights and projects; the app then reads and writes only within this scope, and what it reads goes to its provider (such as Anthropic, OpenAI or Anysphere). These providers are recipients of the business; the business, not we, decides on the transfer. Customer accounts of the customer portal cannot connect an AI app.

The app, person, rights, projects and the times of connection, last use and disconnection are stored; the app’s sign-in runs via Supabase (see service providers). A connection can be disconnected at any time under “Settings › My AI apps” — by the person themselves and by the owner for every connection of their business —, and it ends after 90 days without use. The details of an ended connection remain in the business’s workspace as a record until the workspace or the person’s account is deleted.

Obligation to provide data and automated decision-making

The details provided at registration — name and business address of the company, your name and your email address — are required to conclude the contract. You are not legally obliged to provide them; without them, however, we cannot create an account or conclude a contract.

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place — neither at registration nor during processing in VentionDesk.

Your rights

You have the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object, on grounds relating to your particular situation, to processing based on legitimate interest (Arts. 15 to 21 GDPR). Statutory retention obligations may take precedence over erasure.

Please send requests concerning Part 1 to support@ventiondesk.com; we reply within one month and ask further questions if there is doubt as to whether the request comes from you. Please send requests concerning Part 2 to the business that keeps your data.

Right to lodge a complaint

You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for Part 1 is the State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen (Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen), Georgstraße 122–124, 27570 Bremerhaven. For Part 2, the competent authority depends on the registered office of the business.

Last updated

This statement is current as of 2026-10-04.

Privacy | VentionDesk