Last updated: 30. Juli 2026

Privacy policy

This notice explains how Emptera processes personal data under the General Data Protection Regulation (GDPR) and German data-protection law.

01Data controller under GDPR

Controller for data processing on this website and in the Emptera product:

Loistava Holding UG (haftungsbeschränkt)
Asternring 9, 15732 Schulzendorf, Germany
Represented by managing director Antti Savolainen
E-mail: [email protected]

No data protection officer is required by law. Please direct all data-protection enquiries to the address above.

02Categories of data and purposes

We process personal data for the following purposes:

Account creation and sign-in
E-mail, optional Google account ID + display name, password hash only, IP, sign-in timestamp. Basis: Art. 6 (1) (b) GDPR (contract performance).
Organisation and role management
Basis: Art. 6 (1) (b) GDPR.
Buyer profiles and saved searches
Free-form target description, derived attributes, vector embeddings for similarity search. Used only to deliver the matching service. Basis: Art. 6 (1) (b) GDPR.
Notifications and e-mail alerts
Basis: Art. 6 (1) (b) GDPR.
Billing and payments
Basis: Art. 6 (1) (b) + (c) GDPR (tax retention).
Product analytics and session replay
PostHog (EU-hosted, Frankfurt), two-tier: a basic, anonymous, cookieless reach measurement (page views, visitor count) runs without consent — nothing is stored on or read from your device (§ 25 TTDSG not triggered), basis Art. 6 (1) (f) GDPR (legitimate interest in data-minimal reach measurement). Anything further (persistent cookies for cross-session insights, session recordings with sensitive-input masking) happens only after explicit consent via the banner, basis Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. “Decline” disables all analytics.
Server logs and security
IP, user agent, URL, timestamp, HTTP status. Retained ≤30 days.

On register data: Public pages of Empteradisplay data about insolvent legal entities (company names, commercial-register extracts, insolvency announcements, administrator information). These are not personal data of the platform's users but public records published by the responsible registers. The legal basis is generally Art. 6 (1) (f) GDPR (legitimate interest in providing a research tool for business acquisitions and succession); German proceedings are additionally mandated by statute (§ 9 InsO, § 10 HGB, §§ 2 ff. HRV — Art. 6 (1) (c) GDPR). For Emptera's other live markets, register data comes from each country's own official register: France (BODACC (DILA)), Belgium (Kruispuntbank van Ondernemingen (BCE/KBO)), Spain (BORME / Registro Mercantil (BOE)), Ireland (CRO open data (CC BY 4.0)), Slovakia (Register právnických osôb (CC BY 4.0)), Romania (Registrul Comerțului / ONRC (CC BY 4.0)), Croatia (e-Oglasna ploča sudova (stečaj)), Finland (Kaupparekisteri / PRH (konkurssit)), Estonia (Äriregister / RIK (pankrot)), Latvia (Maksātnespējas reģistrs (UR, CC0)), Lithuania (Juridinių asmenų registras (CC BY 4.0)), Norway (Enhetsregisteret / Brønnøysund (konkurs)), United Kingdom (The Gazette / Companies House) and Switzerland (SHAB / SOGC (Konkurspublikationen)). Where natural persons (directors, shareholders, insolvency administrators) are exceptionally named, processing rests on the same Art. 6 (1) (f) balancing test (plus (c) for Germany).

Company database (all companies, not only insolvent ones)

Emptera additionally maintains a database of European companies, including companies about which no insolvency or sale notice exists. It is built exclusively from official company registers published as open data by the member states, in particular under Implementing Regulation (EU) 2023/138 on high-value datasets.

Companies are not natural persons. Under Recital 14 GDPR the Regulation does not cover the processing of data concerning legal persons. Company name, register number, legal form, registered office, activity, status and filed accounts are therefore not personal data.

A personal-data dimension exists only where natural persons are linked to a company (directors, beneficial owners) or where the legal form itself is a natural person (e.g. sole trader). For those cases:

  • Legal basis: Art. 6 (1) (f) GDPR. The legitimate interest is providing a research tool for company acquisitions and business succession. The balancing test favours the data subject as regards public visibility, which is why personal data never appears on public, indexable pages and is shown only to signed-in, paying users.
  • Ages as bands only. Where a register publishes a year of birth, we derive and store only an age band (e.g. "60–69"), never the date itself — a deliberate data minimisation under Art. 5 (1) (c) GDPR. We do not process inferred or estimated age or gender.
  • No contact data held in reserve. We do not store email addresses or telephone numbers of company officers for stockpiling purposes.
  • No creditworthiness or person-level scores. Indicators always relate to the company, never to a person, and are contractually barred from use in credit, insurance, employment or tenancy decisions.
  • Retention: register-derived personal data is not retained longer than the source register publishes it (CJEU, 7 Dec 2023, C-26/22 and C-64/22).

Information where data is obtained from public registers (Art. 14 GDPR). This data is not collected from the data subject but from official registers, and this privacy notice constitutes the information required by Art. 14 GDPR. Notifying each data subject individually would involve disproportionate effort (Art. 14 (5) (b) GDPR), precisely because we hold no contact details for those persons and do not collect any. Where we do contact someone in an individual case, the Art. 14 information is provided no later than that first communication.

Sources and licences. We use official registers under their own licence terms, including: UK Companies House (Open Government Licence v3.0), INSEE Sirene (Licence Ouverte 2.0), Irish CRO (CC BY 4.0), Belgian KBO/BCE, Romanian Registrul Comerțului (CC BY 4.0), Norwegian Brønnøysund (NLOD), Finnish PRH (CC BY 4.0), Estonian Äriregister, Lithuanian JAR (CC BY 4.0), Slovak RPO (CC BY 4.0), Latvian Uzņēmumu reģistrs (CC0 1.0), and the respective national insolvency registers. The source is named on every view.

Objection and erasure. You may object at any time to the processing of your personal data under Art. 21 GDPR — simply write to [email protected]. We then remove that person from every view, export and API response, and a suppression list prevents them being re-added at the next register refresh. The company record is unaffected, because it contains no personal data.

03Cookies and local storage

Strictly necessary cookies (session, language is_lang, active-org is_active_org, and the consent cookie ur_consent that stores your cookie choice) fall under § 25 (2) No. 2 TTDSG and require no consent.

Analytics cookies (PostHog) are not strictly necessary and, under § 25 (1) TTDSG, are set only after you have explicitly consented via our cookie banner ("Accept"). Without consent no analytics cookies are set and nothing is stored on your device; all essential site functions work unchanged. The basic, anonymous, cookieless reach measurement (page views, visitor count) runs independently, because it neither stores nor reads anything on your device and therefore falls outside § 25 TTDSG — choosing "Decline" switches that off too. You can withdraw consent at any time by deleting the ur_consent cookie. Where PostHog captures data after consent, the IP address is truncated before storage on EU servers.

04Recipients and processors

The following processors receive data on our behalf under Art. 28 GDPR data-processing agreements. Third-country transfers are covered by EU Standard Contractual Clauses (SCC).

RecipientPurposeRegionLegal basis
Supabase, Inc. (400 Alabama Street, San Francisco, CA 94110, USA) — ehemaliger Auftragsverarbeiter, bis 31.08.2026Until 31 Aug 2026: database hosting, authentication and session management. Since the migration on 31 Aug 2026 both the database AND authentication (a self-operated GoTrue service) run exclusively on our own Hetzner infrastructure in Germany. Supabase, Inc. no longer receives any data at all; this row remains for transparency about the past period.Keine Datenübermittlung mehr (vormals USA)Art. 6 (1) (b) GDPR (contract performance); SCC — no longer applicable
Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) — ehemaliger Auftragsverarbeiter, bis 31.08.2026Until 31 Aug 2026: web-application hosting. Since the migration on 31 Aug 2026 the application is served entirely from our own Hetzner infrastructure in Germany. Vercel Inc. no longer receives any data at all; this row remains for transparency about the past period.Keine Datenübermittlung mehr (vormals EU-Frankfurt + globales CDN)Art. 6 (1) (b) GDPR; SCC — no longer applicable
Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA)DNS resolution, DDoS protection, reverse-proxy CDN. Server logs (IP, timestamp, requested resource, referrer, user agent) retained for up to 24 hours.Global (EU-Edge in Frankfurt)Art. 6 (1) (f) GDPR (security of processing); SCC
PostHog Inc. (2261 Market Street #4008, San Francisco, CA 94114, USA)Product analytics, web analytics and session replay (visual recording of interactions for troubleshooting and UX improvement). Inputs in password fields are automatically masked.EU-Rechenzentrum (Frankfurt) — eu.i.posthog.comAnonymous, cookieless basic reach measurement (page views, visitors): Art. 6 (1) (f) GDPR (legitimate interest) — no information is stored on or read from the device, so § 25 TTDSG does not apply. Persistent cookies and session replay only after explicit consent via the banner: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG. “Decline” disables all analytics. SCC.
Resend, Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA)Delivery of transactional e-mails (sign-up confirmations, password reset, match notifications).USA / EU-EdgeArt. 6 (1) (b) GDPR; SCC
Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Irland)Payment processing, invoicing, subscription management. Payment card data are processed exclusively within Stripe's PCI-DSS-certified environment.EU (Irland) mit Verarbeitung auch in den USAArt. 6 (1) (b) GDPR; SCC
Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Deutschland)The entire server infrastructure since 31 Aug 2026: web-application hosting, primary PostgreSQL database hosting (account, organisation and subscription data), authentication and session management (a self-operated GoTrue service; magic link and the Google OAuth callback) as well as self-hosted background-job orchestration (enrichment pipelines, alert matching, cron schedules; self-run Inngest OSS).EU (Deutschland) — kein DrittlandtransferArt. 6 (1) (b) GDPR; Art. 28 GDPR (DPA)
Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (Hangzhou, VR China) — DeepSeek-APIPrimary language model in the LLM router for deep-research dossier generation. Transmits public company + register data and generated summaries. Names and dates of birth of directors/shareholders, private addresses, and third parties named in free text (§9 summary, website) are stripped/redacted server-side before transmission. NOT removed: the debtor's registered commercial name — transmitted as the business identifier, which for sole traders (e.K.) may include the merchant's surname.VR China — kein Angemessenheitsbeschluss (siehe Abschnitt Drittlandtransfer)Art. 6 (1) (f) GDPR; transfer without an adequacy decision, mitigated by data minimisation (no personal user data, no director/shareholder names)
OpenAI, L.L.C. (3180 18th Street, San Francisco, CA 94110, USA)LLM inference for deep research (fallback), translation (DE↔EN), text embeddings and Deal-Playbook generation. As with DeepSeek, director/shareholder names, dates of birth and free-text third parties are removed first. Additionally processed: for the playbook, the insolvency administrator's professional name (to prepare the outreach the user requested) and the user's own buyer-profile text (for semantic matching).USA (API-Rechenzentrum)Art. 6 (1) (f) GDPR; SCC; OpenAI Business DPA (no training-data use)
Anthropic PBC (548 Market Street PMB 90375, San Francisco, CA 94104, USA)LLM inference as an alternative to OpenAI for deep research and analysis. Used via the LLM router as described above.USAArt. 6 (1) (f) GDPR; SCC; Anthropic Commercial Terms (no training-data use)
Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Irland) — Gemini-APIGemini LLM inference as an automatic fallback in the LLM router — used when the upstream providers are unavailable. Same data minimisation as DeepSeek/OpenAI.EU (Irland); Verarbeitung ggf. auch USAArt. 6 (1) (f) GDPR; SCC where applicable
Web-Recherche- und Anreicherungsdienste (u. a. Serper/Google, Brave Search, Mojeek, DuckDuckGo, archive.org/Wayback, Trustpilot, Google News, RDAP/WHOIS, IndexNow/Bing) — EU/USA/UKTo resolve the company website and enrich public company data, queries containing the debtor company's name and/or domain are sent to web-search and archive services. Only legal-entity data (company name, domain) is transmitted — no personal user data.EU / USA (DPF) / UK (Angemessenheitsbeschluss)Art. 6 (1) (f) GDPR (legitimate interest in data enrichment)
GitHub, Inc. (88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA)Code repository and CI/CD pipelines (GitHub Actions) for deployment. Does not process end-user data directly.USAArt. 6 (1) (f) GDPR; SCC

05Transfers to third countries

Several processors are US-based. An adequacy decision exists under the EU-US Data Privacy Framework (2023) where the provider is certified. Additionally, SCC under Art. 46 (2) (c) GDPR have been concluded with the US providers.

For deep research our primary language model is the DeepSeek API (provider based in the People's Republic of China). There is no adequacy decision for China. We safeguard this transfer through data minimisation: before every request, names and dates of birth of representatives and shareholders, private addresses, and third parties named in free text are stripped or redacted server-side. Public company + register data and factual summaries derived from it are transmitted. The only item not removed is the debtor company's registered commercial name, which serves as the business identifier and — for sole traders (e.K.) — may contain the merchant's surname. No personal account data is sent to DeepSeek. If you wish to exclude this transfer entirely, contact us at [email protected] and we will process the relevant research via EU/US models only.

Since 31 Aug 2026 the web application, the database, authentication and background orchestration are all hosted exclusively at Hetzner in Germany. Copies of the relevant agreements are available on request.

06Retention periods

Account data
Up to 30 days after cancellation, then anonymised or deleted. Exception: statutory retention (up to 10 years for invoices under § 147 AO).
Buyer profiles and alerts
Until deleted by the user or on account closure.
Server logs
Up to 30 days.
PostHog events and session recordings
12 months by default.
Invoice and payment data
10 years under § 147 AO.

07Data-subject rights

Under GDPR you have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure — the „right to be forgotten" (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw a consent (Art. 7 (3) GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR). Competent authority: Landesbeauftragte für den Datenschutz Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow.

An informal e-mail to [email protected] or our contact form is sufficient to exercise these rights.

08Automated decision-making and profiling

Emptera computes a personalised „match score" between your buyer profile and public company records. This is a decision aid; it does not replace human review and produces no legal effect or similarly significant effect on you within the meaning of Art. 22 GDPR. You may inspect, change or delete the underlying attributes at any time.

09E-mail delivery and alerts

After sign-up you receive transactional e-mails (confirmation, password reset) and match notifications per your alert configuration, delivered via Resend. You can unsubscribe from match notifications through the link in every e-mail or in your account settings.

10Session replay (PostHog)

To improve usability and diagnose errors, we record sessions via PostHog session replay (mouse movements, clicks, page changes, form interactions). Sensitive inputs (passwords, card fields) are masked automatically.

Session recording starts only after your explicit consent via the cookie banner ("Accept") and does not run without it (basis: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG). You may withdraw consent at any time by choosing "Decline", deleting the ur_consent cookie, or e-mailing [email protected].

11Technical and organisational measures

  • Encrypted transport (TLS 1.2/1.3)
  • Encrypted off-site backups (age-encrypted daily database dumps, off-site copy held in the EU)
  • Passwordless authentication (magic link, Google OAuth)
  • Tenant isolation enforced server-side in the application/query layer on every database access; direct database API access (PostgREST) to the public schema is disabled
  • Two-factor authentication for admin accounts
  • Regular backups with restore testing
  • Access logging and periodic access review

12Changes to this notice

We update this privacy notice as regulations or our processing activities change. The current version is always available at emptera.com/privacy. Material changes are additionally communicated by e-mail to registered users.

Privacy policy — Emptera