Privacy policy

Last updated: 22 September 2026

This is an English courtesy translation. The German version is legally authoritative.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Christoph Klett
Tilman-Riemenschneider-Straße 35
97204 Höchberg
Germany
Email: hallo@bricksta.com
Phone: +49 172 3654426

2. Your rights as a data subject

With regard to your personal data, you have in particular the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)

You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR).

3. Data collected when visiting the website (server log files)

When you access this website, the hosting provider automatically processes information in server log files that your browser transmits. This usually includes: IP address, date and time of access, page/file requested, amount of data transferred, referrer URL, and browser and operating system information.

The legal basis is our legitimate interest in providing the website securely and stably (Art. 6 (1) (f) GDPR). Our hosting provider retains these log entries for one day; after that they are no longer available to us either.

4. Hosting and delivery (Vercel)

This website is hosted by Vercel and delivered via its content delivery network. Personal data (in particular access data) may be processed in the process. Server-side processing takes place in the Frankfurt am Main region. The page content itself is delivered via a worldwide network of edge nodes — when accessed from outside Europe, your request may therefore be handled at a node outside the EU. A data processing agreement is in place; for transfers to third countries, appropriate safeguards (EU standard contractual clauses) are used.

Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA.

5. Application and user accounts (Supabase)

For the logged-in application area (registration, sign-in, operation of the software) we use Supabase as a backend and authentication service. Account and usage data are processed insofar as this is necessary to provide the application (Art. 6 (1) (b) GDPR). The database is located in Frankfurt am Main, so your account and usage data are stored within the European Union. A data processing agreement is in place; as the operating company is based outside the EU, EU standard contractual clauses apply to access from there.

Provider: Supabase Pte. Ltd, 65 Chulia Street #38‑02/03, OCBC Centre, 049513, Singapore.

6. Contacting us

If you contact us by email, we process your details to handle the enquiry. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures/contract) or Art. 6 (1) (f) GDPR (legitimate interest in responding). The data are deleted once they are no longer required to achieve the purpose and no statutory retention obligations conflict with deletion.

7. Cookies and reach measurement

The public marketing pages of this website set no tracking or analytics cookies and embed no third-party web analytics services. In the logged-in application area, we store technically necessary information in your browser’s local storage — your login session and display preferences such as chosen views and expanded sections. We do not use cookies there. This information is required for operation (Art. 6 (1) (f) GDPR or § 25 (2) TDDDG).

We operate our own reach measurement on our servers in Frankfurt am Main. Per page view we record: the page requested, the time, the referring domain (not its full address), campaign identifiers from the link, the type of access (human, search engine, AI service), the country, the device type (phone, tablet, computer), the organisation the internet connection is registered to, as well as scroll depth, time on page and clicks on marked buttons. The legal basis is our legitimate interest in designing our offering to meet demand (Art. 6 (1) (f) GDPR).

To determine the organisation we query two public sources and transmit your IP address in the clear to do so: the registration data held by the European internet registry RIPE NCC (Amsterdam, Netherlands) and the reverse lookup of the connection name via a DNS resolver. Both queries run only after the page has reached you. Access providers are discarded — a name is stored only if it points to an organisation rather than to a connectivity provider.

With a single exception, no access to your device takes place (§ 25 TDDDG): we neither store nor read cookies or any other information there — except for the marker recording your objection, described below. Several page views are linked to one visit via a random identifier that, on your device, exists solely in the memory of the open page and expires on reload. Recognition beyond the individual visit is therefore impossible. Your IP address is not stored: it enters our measurement data only as an irreversible, salted hash that allows abusive access to be limited. To determine the organisation, however, it is transmitted in the clear to RIPE NCC and to a DNS resolver, as described in the paragraph above, without being kept in that form by us.

Retention: The data collected is retained indefinitely; it serves the long-term comparison of how our offering develops across several years. It contains no IP address, no recognition beyond the individual visit and no device identifier. An entry does, however, name the organisation behind the connection — for a visit from a corporate network, therefore, the name of the company, not of a person. Attribution to individual persons is thus neither possible for us nor intended.

Objection: You may object to the measurement at any time by visiting bricksta.com/?no-tracking. Your browser remembers this choice and your visits will no longer be recorded. This is the only information stored on your device in this context; it serves solely to implement your objection. You can reverse it via bricksta.com/?track-me.

8. Email delivery (Resend)

For sending and, where applicable, receiving emails, we use the Resend service. The data required for delivery (e.g. email address, content) are processed. The legal basis is Art. 6 (1) (b) or (f) GDPR. A data processing agreement is in place; EU standard contractual clauses apply to the transfer to the USA.

Provider: Plus Five Five, Inc. (“Resend” service), 2261 Market Street #5039, San Francisco, CA 94114, USA.

9. Public intake forms and spam protection (Cloudflare Turnstile)

Organisations can publish intake forms in Bricksta that anyone may use without an account. We process the entries you make in the form and your email address for confirmation; the legal basis is Art. 6 (1) (b) or (f) GDPR.

To protect against automated submissions, these form pages use Cloudflare Turnstile. A verification component provided by Cloudflare is loaded in your browser — this alone transmits your IP address and technical details about your browser and device to Cloudflare. When you submit the form, we additionally transmit the component’s verification token and your IP address in the clear to Cloudflare for checking. The legal basis is our legitimate interest in preventing abuse (Art. 6 (1) (f) GDPR). A data processing agreement is in place; EU standard contractual clauses apply to the transfer to the USA.

This transfer differs from what we store ourselves: in our own database your IP address is never kept in the clear, only as a non-reversible, salted hash used solely to limit the number of submissions per connection. Cloudflare, by contrast, receives the address itself.

Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.

10. AI-assisted features

Parts of the application work with an AI language model — for example when a runnable template is built from your description, an incoming email is matched to a case, or details are taken from an attachment. For these features the content concerned is transmitted to the language model provider and processed there. The legal basis is Art. 6 (1) (b) GDPR.

The default provider is Anthropic. For customers in the European Economic Area the contracting party is a company based in Ireland. Under Anthropic’s terms, the transmitted content is not used to train models.

An organisation may instead configure its own provider for its own area (currently OpenAI, Azure OpenAI, Google or its own OpenAI-compatible endpoint). In that case the content is transmitted to the provider chosen by that organisation, on its instruction, and the terms agreed between the organisation and that provider apply.

Default provider: Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland.

11. Connections to your organisation’s own systems

An organisation can connect Bricksta to its own systems — for example a Microsoft 365 account, in order to process emails from a mailbox or send notifications to Microsoft Teams. The connection is set up and expressly authorised by the organisation itself.

With these connections the data does not flow to a service provider of ours, but into your own organisation’s account. We access that organisation’s Microsoft environment with the permissions granted in the process; processing within that environment is governed by the contract the organisation itself has with Microsoft. The legal basis for our access is Art. 6 (1) (b) GDPR.

12. Transfers to third countries

The database holding your account and usage data, and the server-side processing, are located in Frankfurt am Main and therefore within the European Union; only the delivery of page content runs via a worldwide network of edge nodes. The companies operating these services, however, are based outside the EU: Vercel Inc. and Plus Five Five, Inc. in the USA, Supabase Pte. Ltd in Singapore. Access from those countries — for maintenance and support, for example — constitutes a transfer to a third country.

None of these countries is covered by an adequacy decision of the European Commission that would cover all of the transfers named here. As an appropriate safeguard within the meaning of Art. 46 (2) (c) GDPR, EU standard contractual clauses are agreed with all three providers; they form part of the respective data processing agreement. You may request a copy at the address given above.

Two further recipients concern specific features only and therefore need separate consideration:

  • Cloudflare, Inc. (USA) receives your IP address when a public intake form is opened and submitted (section 9). Here too EU standard contractual clauses are agreed; they form part of the data processing agreement.
  • Anthropic Ireland, Limited is the default provider for the AI features (section 10) and is based in Ireland, and therefore within the EU. Processing by sub-processors outside the EU is not ruled out; for that case, EU standard contractual clauses likewise form part of the agreement.

13. Encryption (SSL/TLS)

For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” in your browser’s address bar.

14. Changes to this privacy policy

We adjust this privacy policy as soon as changes to the data processing we carry out make it necessary. The current version available on this page applies in each case.