Last updated: 20. Juli 2026
Privacy policy
This notice explains how Übernahme-Radar processes personal data under the General Data Protection Regulation (GDPR) and German data-protection law.
01Data controller under GDPR
Controller for data processing on this website and in the Übernahme-Radar product:
Loistava Holding UG (haftungsbeschränkt)
Asternring 9, 15732 Schulzendorf, Germany
Represented by managing director Antti Savolainen
E-mail: info@uebernahmeradar.de
No data protection officer is required by law. Please direct all data-protection enquiries to the address above.
02Categories of data and purposes
We process personal data for the following purposes:
- Account creation and sign-in
- E-mail, optional Google account ID + display name, password hash only, IP, sign-in timestamp. Basis: Art. 6 (1) (b) GDPR (contract performance).
- Organisation and role management
- Basis: Art. 6 (1) (b) GDPR.
- Buyer profiles and saved searches
- Free-form target description, derived attributes, vector embeddings for similarity search. Used only to deliver the matching service. Basis: Art. 6 (1) (b) GDPR.
- Notifications and e-mail alerts
- Basis: Art. 6 (1) (b) GDPR.
- Billing and payments
- Basis: Art. 6 (1) (b) + (c) GDPR (tax retention).
- Product analytics and session replay
- PostHog (EU-hosted, Frankfurt), two-tier: a basic, anonymous, cookieless reach measurement (page views, visitor count) runs without consent — nothing is stored on or read from your device (§ 25 TTDSG not triggered), basis Art. 6 (1) (f) GDPR (legitimate interest in data-minimal reach measurement). Anything further (persistent cookies for cross-session insights, session recordings with sensitive-input masking) happens only after explicit consent via the banner, basis Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. “Decline” disables all analytics.
- Server logs and security
- IP, user agent, URL, timestamp, HTTP status. Retained ≤30 days.
On register data: Public pages of Übernahme-Radar display data about insolvent legal entities (company names, commercial-register extracts, § 9 InsO announcements, administrator information). These are not personal data of the platform's users but public records mandated by German law (§ 9 InsO, § 10 HGB).
04Recipients and processors
The following processors receive data on our behalf under Art. 28 GDPR data-processing agreements. Third-country transfers are covered by EU Standard Contractual Clauses (SCC).
| Recipient | Purpose | Region | Legal basis |
|---|---|---|---|
| Supabase, Inc. (400 Alabama Street, San Francisco, CA 94110, USA) | Authentication (magic link, Google OAuth), user + session management, PostgreSQL database hosting in the EU region (Frankfurt). | EU (Frankfurt) für Datenbank; USA für Steuerung | Art. 6 (1) (b) GDPR (contract performance); SCC |
| Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) | Web-application hosting; server-side functions run in the EU region (Frankfurt, fra1/dub1). Static assets delivered via CDN. | EU (Frankfurt) für Funktionen; global für CDN-Edge | Art. 6 (1) (b) + (f) GDPR; SCC |
| Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) | DNS resolution, DDoS protection, reverse-proxy CDN. Server logs (IP, timestamp, requested resource, referrer, user agent) retained for up to 24 hours. | Global (EU-Edge in Frankfurt) | Art. 6 (1) (f) GDPR (security of processing); SCC |
| PostHog Inc. (2261 Market Street #4008, San Francisco, CA 94114, USA) | Product analytics, web analytics and session replay (visual recording of interactions for troubleshooting and UX improvement). Inputs in password fields are automatically masked. | EU-Rechenzentrum (Frankfurt) — eu.i.posthog.com | Anonymous, cookieless basic reach measurement (page views, visitors): Art. 6 (1) (f) GDPR (legitimate interest) — no information is stored on or read from the device, so § 25 TTDSG does not apply. Persistent cookies and session replay only after explicit consent via the banner: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. “Decline” disables all analytics. SCC. |
| Resend, Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA) | Delivery of transactional e-mails (sign-up confirmations, password reset, match notifications). | USA / EU-Edge | Art. 6 (1) (b) GDPR; SCC |
| Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Irland) | Payment processing, invoicing, subscription management. Payment card data are processed exclusively within Stripe's PCI-DSS-certified environment. | EU (Irland) mit Verarbeitung auch in den USA | Art. 6 (1) (b) GDPR; SCC |
| Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Deutschland) | Server infrastructure for our self-hosted background-job orchestration (enrichment pipelines, alert matching, cron schedules; self-run Inngest OSS). Payload data typically contain record IDs, not personal user data. | EU (Deutschland) — kein Drittlandtransfer | Art. 6 (1) (b) GDPR; Art. 28 GDPR (DPA) |
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (Hangzhou, VR China) — DeepSeek-API | Primary language model in the LLM router for deep-research dossier generation. Transmits public company + register data and generated summaries. Names and dates of birth of directors/shareholders, private addresses, and third parties named in free text (§9 summary, website) are stripped/redacted server-side before transmission. NOT removed: the debtor's registered commercial name — transmitted as the business identifier, which for sole traders (e.K.) may include the merchant's surname. | VR China — kein Angemessenheitsbeschluss (siehe Abschnitt Drittlandtransfer) | Art. 6 (1) (f) GDPR; transfer without an adequacy decision, mitigated by data minimisation (no personal user data, no director/shareholder names) |
| OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA) | LLM inference for deep research (fallback), translation (DE↔EN), text embeddings and Deal-Playbook generation. As with DeepSeek, director/shareholder names, dates of birth and free-text third parties are removed first. Additionally processed: for the playbook, the insolvency administrator's professional name (to prepare the outreach the user requested) and the user's own buyer-profile text (for semantic matching). | USA (API-Rechenzentrum) | Art. 6 (1) (f) GDPR; SCC; OpenAI Business DPA (no training-data use) |
| Anthropic PBC (548 Market Street PMB 90375, San Francisco, CA 94104, USA) | LLM inference as an alternative to OpenAI for deep research and analysis. Used via the LLM router as described above. | USA | Art. 6 (1) (f) GDPR; SCC; Anthropic Commercial Terms (no training-data use) |
| Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Irland) — Gemini-API | Gemini LLM inference as an automatic fallback in the LLM router — used when the upstream providers are unavailable. Same data minimisation as DeepSeek/OpenAI. | EU (Irland); Verarbeitung ggf. auch USA | Art. 6 (1) (f) GDPR; SCC where applicable |
| Web-Recherche- und Anreicherungsdienste (u. a. Serper/Google, Brave Search, Mojeek, DuckDuckGo, archive.org/Wayback, Trustpilot, Google News, RDAP/WHOIS, IndexNow/Bing) — EU/USA/UK | To resolve the company website and enrich public company data, queries containing the debtor company's name and/or domain are sent to web-search and archive services. Only legal-entity data (company name, domain) is transmitted — no personal user data. | EU / USA (DPF) / UK (Angemessenheitsbeschluss) | Art. 6 (1) (f) GDPR (legitimate interest in data enrichment) |
| GitHub, Inc. (88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA) | Code repository and CI/CD pipelines (GitHub Actions) for deployment. Does not process end-user data directly. | USA | Art. 6 (1) (f) GDPR; SCC |
05Transfers to third countries
Several processors are US-based. An adequacy decision exists under the EU-US Data Privacy Framework (2023) where the provider is certified. Additionally, SCC under Art. 46 (2) (c) GDPR have been concluded with the US providers.
For deep research our primary language model is the DeepSeek API (provider based in the People's Republic of China). There is no adequacy decision for China. We safeguard this transfer through data minimisation: before every request, names and dates of birth of representatives and shareholders, private addresses, and third parties named in free text are stripped or redacted server-side. Public company + register data and factual summaries derived from it are transmitted. The only item not removed is the debtor company's registered commercial name, which serves as the business identifier and — for sole traders (e.K.) — may contain the merchant's surname. No personal account data is sent to DeepSeek. If you wish to exclude this transfer entirely, contact us at info@uebernahmeradar.de and we will process the relevant research via EU/US models only.
Database hosting (Supabase, Frankfurt), server functions (Vercel, Frankfurt) and background orchestration (Hetzner, Germany) run inside the EU. Copies of the relevant agreements are available on request.
06Retention periods
- Account data
- Up to 30 days after cancellation, then anonymised or deleted. Exception: statutory retention (up to 10 years for invoices under § 147 AO).
- Buyer profiles and alerts
- Until deleted by the user or on account closure.
- Server logs
- Up to 30 days.
- PostHog events and session recordings
- 12 months by default.
- Invoice and payment data
- 10 years under § 147 AO.
07Data-subject rights
Under GDPR you have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure — the „right to be forgotten" (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on legitimate interests (Art. 21 GDPR)
- Withdraw a consent (Art. 7 (3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR). Competent authority: Landesbeauftragte für den Datenschutz Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow.
An informal e-mail to info@uebernahmeradar.de is sufficient to exercise these rights.
08Automated decision-making and profiling
Übernahme-Radar computes a personalised „match score" between your buyer profile and public company records. This is a decision aid; it does not replace human review and produces no legal effect or similarly significant effect on you within the meaning of Art. 22 GDPR. You may inspect, change or delete the underlying attributes at any time.
09E-mail delivery and alerts
After sign-up you receive transactional e-mails (confirmation, password reset) and match notifications per your alert configuration, delivered via Resend. You can unsubscribe from match notifications through the link in every e-mail or in your account settings.
10Session replay (PostHog)
To improve usability and diagnose errors, we record sessions via PostHog session replay (mouse movements, clicks, page changes, form interactions). Sensitive inputs (passwords, card fields) are masked automatically.
Session recording starts only after your explicit consent via the cookie banner ("Accept") and does not run without it (basis: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG). You may withdraw consent at any time by choosing "Decline", deleting the ur_consent cookie, or e-mailing info@uebernahmeradar.de.
11Technical and organisational measures
- Encrypted transport (TLS 1.2/1.3)
- Encryption at rest (Supabase, Postgres)
- Passwordless authentication (magic link, Google OAuth)
- Postgres Row-Level Security for strict tenant isolation
- Two-factor authentication for admin accounts
- Regular backups with restore testing
- Access logging and periodic access review
12Changes to this notice
We update this privacy notice as regulations or our processing activities change. The current version is always available at uebernahmeradar.de/datenschutz. Material changes are additionally communicated by e-mail to registered users.