Last updated: 20. Juli 2026

Privacy policy

This notice explains how Übernahme-Radar processes personal data under the General Data Protection Regulation (GDPR) and German data-protection law.

01Data controller under GDPR

Controller for data processing on this website and in the Übernahme-Radar product:

Loistava Holding UG (haftungsbeschränkt)
Asternring 9, 15732 Schulzendorf, Germany
Represented by managing director Antti Savolainen
E-mail: info@uebernahmeradar.de

No data protection officer is required by law. Please direct all data-protection enquiries to the address above.

02Categories of data and purposes

We process personal data for the following purposes:

Account creation and sign-in
E-mail, optional Google account ID + display name, password hash only, IP, sign-in timestamp. Basis: Art. 6 (1) (b) GDPR (contract performance).
Organisation and role management
Basis: Art. 6 (1) (b) GDPR.
Buyer profiles and saved searches
Free-form target description, derived attributes, vector embeddings for similarity search. Used only to deliver the matching service. Basis: Art. 6 (1) (b) GDPR.
Notifications and e-mail alerts
Basis: Art. 6 (1) (b) GDPR.
Billing and payments
Basis: Art. 6 (1) (b) + (c) GDPR (tax retention).
Product analytics and session replay
PostHog (EU-hosted, Frankfurt), two-tier: a basic, anonymous, cookieless reach measurement (page views, visitor count) runs without consent — nothing is stored on or read from your device (§ 25 TTDSG not triggered), basis Art. 6 (1) (f) GDPR (legitimate interest in data-minimal reach measurement). Anything further (persistent cookies for cross-session insights, session recordings with sensitive-input masking) happens only after explicit consent via the banner, basis Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. “Decline” disables all analytics.
Server logs and security
IP, user agent, URL, timestamp, HTTP status. Retained ≤30 days.

On register data: Public pages of Übernahme-Radar display data about insolvent legal entities (company names, commercial-register extracts, § 9 InsO announcements, administrator information). These are not personal data of the platform's users but public records mandated by German law (§ 9 InsO, § 10 HGB).

03Cookies and local storage

Strictly necessary cookies (session, language is_lang, active-org is_active_org, and the consent cookie ur_consent that stores your cookie choice) fall under § 25 (2) No. 2 TTDSG and require no consent.

Analytics cookies (PostHog) are not strictly necessary and, under § 25 (1) TTDSG, are set only after you have explicitly consented via our cookie banner ("Accept"). Without consent no analytics cookies are set and nothing is stored on your device; all essential site functions work unchanged. The basic, anonymous, cookieless reach measurement (page views, visitor count) runs independently, because it neither stores nor reads anything on your device and therefore falls outside § 25 TTDSG — choosing "Decline" switches that off too. You can withdraw consent at any time by deleting the ur_consent cookie. Where PostHog captures data after consent, the IP address is truncated before storage on EU servers.

04Recipients and processors

The following processors receive data on our behalf under Art. 28 GDPR data-processing agreements. Third-country transfers are covered by EU Standard Contractual Clauses (SCC).

RecipientPurposeRegionLegal basis
Supabase, Inc. (400 Alabama Street, San Francisco, CA 94110, USA)Authentication (magic link, Google OAuth), user + session management, PostgreSQL database hosting in the EU region (Frankfurt).EU (Frankfurt) für Datenbank; USA für SteuerungArt. 6 (1) (b) GDPR (contract performance); SCC
Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA)Web-application hosting; server-side functions run in the EU region (Frankfurt, fra1/dub1). Static assets delivered via CDN.EU (Frankfurt) für Funktionen; global für CDN-EdgeArt. 6 (1) (b) + (f) GDPR; SCC
Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA)DNS resolution, DDoS protection, reverse-proxy CDN. Server logs (IP, timestamp, requested resource, referrer, user agent) retained for up to 24 hours.Global (EU-Edge in Frankfurt)Art. 6 (1) (f) GDPR (security of processing); SCC
PostHog Inc. (2261 Market Street #4008, San Francisco, CA 94114, USA)Product analytics, web analytics and session replay (visual recording of interactions for troubleshooting and UX improvement). Inputs in password fields are automatically masked.EU-Rechenzentrum (Frankfurt) — eu.i.posthog.comAnonymous, cookieless basic reach measurement (page views, visitors): Art. 6 (1) (f) GDPR (legitimate interest) — no information is stored on or read from the device, so § 25 TTDSG does not apply. Persistent cookies and session replay only after explicit consent via the banner: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. “Decline” disables all analytics. SCC.
Resend, Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA)Delivery of transactional e-mails (sign-up confirmations, password reset, match notifications).USA / EU-EdgeArt. 6 (1) (b) GDPR; SCC
Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Irland)Payment processing, invoicing, subscription management. Payment card data are processed exclusively within Stripe's PCI-DSS-certified environment.EU (Irland) mit Verarbeitung auch in den USAArt. 6 (1) (b) GDPR; SCC
Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Deutschland)Server infrastructure for our self-hosted background-job orchestration (enrichment pipelines, alert matching, cron schedules; self-run Inngest OSS). Payload data typically contain record IDs, not personal user data.EU (Deutschland) — kein DrittlandtransferArt. 6 (1) (b) GDPR; Art. 28 GDPR (DPA)
Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (Hangzhou, VR China) — DeepSeek-APIPrimary language model in the LLM router for deep-research dossier generation. Transmits public company + register data and generated summaries. Names and dates of birth of directors/shareholders, private addresses, and third parties named in free text (§9 summary, website) are stripped/redacted server-side before transmission. NOT removed: the debtor's registered commercial name — transmitted as the business identifier, which for sole traders (e.K.) may include the merchant's surname.VR China — kein Angemessenheitsbeschluss (siehe Abschnitt Drittlandtransfer)Art. 6 (1) (f) GDPR; transfer without an adequacy decision, mitigated by data minimisation (no personal user data, no director/shareholder names)
OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA)LLM inference for deep research (fallback), translation (DE↔EN), text embeddings and Deal-Playbook generation. As with DeepSeek, director/shareholder names, dates of birth and free-text third parties are removed first. Additionally processed: for the playbook, the insolvency administrator's professional name (to prepare the outreach the user requested) and the user's own buyer-profile text (for semantic matching).USA (API-Rechenzentrum)Art. 6 (1) (f) GDPR; SCC; OpenAI Business DPA (no training-data use)
Anthropic PBC (548 Market Street PMB 90375, San Francisco, CA 94104, USA)LLM inference as an alternative to OpenAI for deep research and analysis. Used via the LLM router as described above.USAArt. 6 (1) (f) GDPR; SCC; Anthropic Commercial Terms (no training-data use)
Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Irland) — Gemini-APIGemini LLM inference as an automatic fallback in the LLM router — used when the upstream providers are unavailable. Same data minimisation as DeepSeek/OpenAI.EU (Irland); Verarbeitung ggf. auch USAArt. 6 (1) (f) GDPR; SCC where applicable
Web-Recherche- und Anreicherungsdienste (u. a. Serper/Google, Brave Search, Mojeek, DuckDuckGo, archive.org/Wayback, Trustpilot, Google News, RDAP/WHOIS, IndexNow/Bing) — EU/USA/UKTo resolve the company website and enrich public company data, queries containing the debtor company's name and/or domain are sent to web-search and archive services. Only legal-entity data (company name, domain) is transmitted — no personal user data.EU / USA (DPF) / UK (Angemessenheitsbeschluss)Art. 6 (1) (f) GDPR (legitimate interest in data enrichment)
GitHub, Inc. (88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA)Code repository and CI/CD pipelines (GitHub Actions) for deployment. Does not process end-user data directly.USAArt. 6 (1) (f) GDPR; SCC

05Transfers to third countries

Several processors are US-based. An adequacy decision exists under the EU-US Data Privacy Framework (2023) where the provider is certified. Additionally, SCC under Art. 46 (2) (c) GDPR have been concluded with the US providers.

For deep research our primary language model is the DeepSeek API (provider based in the People's Republic of China). There is no adequacy decision for China. We safeguard this transfer through data minimisation: before every request, names and dates of birth of representatives and shareholders, private addresses, and third parties named in free text are stripped or redacted server-side. Public company + register data and factual summaries derived from it are transmitted. The only item not removed is the debtor company's registered commercial name, which serves as the business identifier and — for sole traders (e.K.) — may contain the merchant's surname. No personal account data is sent to DeepSeek. If you wish to exclude this transfer entirely, contact us at info@uebernahmeradar.de and we will process the relevant research via EU/US models only.

Database hosting (Supabase, Frankfurt), server functions (Vercel, Frankfurt) and background orchestration (Hetzner, Germany) run inside the EU. Copies of the relevant agreements are available on request.

06Retention periods

Account data
Up to 30 days after cancellation, then anonymised or deleted. Exception: statutory retention (up to 10 years for invoices under § 147 AO).
Buyer profiles and alerts
Until deleted by the user or on account closure.
Server logs
Up to 30 days.
PostHog events and session recordings
12 months by default.
Invoice and payment data
10 years under § 147 AO.

07Data-subject rights

Under GDPR you have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure — the „right to be forgotten" (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw a consent (Art. 7 (3) GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR). Competent authority: Landesbeauftragte für den Datenschutz Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow.

An informal e-mail to info@uebernahmeradar.de is sufficient to exercise these rights.

08Automated decision-making and profiling

Übernahme-Radar computes a personalised „match score" between your buyer profile and public company records. This is a decision aid; it does not replace human review and produces no legal effect or similarly significant effect on you within the meaning of Art. 22 GDPR. You may inspect, change or delete the underlying attributes at any time.

09E-mail delivery and alerts

After sign-up you receive transactional e-mails (confirmation, password reset) and match notifications per your alert configuration, delivered via Resend. You can unsubscribe from match notifications through the link in every e-mail or in your account settings.

10Session replay (PostHog)

To improve usability and diagnose errors, we record sessions via PostHog session replay (mouse movements, clicks, page changes, form interactions). Sensitive inputs (passwords, card fields) are masked automatically.

Session recording starts only after your explicit consent via the cookie banner ("Accept") and does not run without it (basis: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG). You may withdraw consent at any time by choosing "Decline", deleting the ur_consent cookie, or e-mailing info@uebernahmeradar.de.

11Technical and organisational measures

  • Encrypted transport (TLS 1.2/1.3)
  • Encryption at rest (Supabase, Postgres)
  • Passwordless authentication (magic link, Google OAuth)
  • Postgres Row-Level Security for strict tenant isolation
  • Two-factor authentication for admin accounts
  • Regular backups with restore testing
  • Access logging and periodic access review

12Changes to this notice

We update this privacy notice as regulations or our processing activities change. The current version is always available at uebernahmeradar.de/datenschutz. Material changes are additionally communicated by e-mail to registered users.

Datenschutzerklärung — Übernahme-Radar