Legal
Privacy Policy
Effective: May 2026
1. Data Controller
The party responsible for data processing is:
Alexandi Software Solutions
Owner: Emin Alexandi
Rigaer Str. 37d
10247 Berlin
Germany
Email: [email protected]
2. Scope of this Privacy Policy
This privacy policy informs about the processing of personal data in connection with the use of the SaaS platform "zeig" at the domain zeig.app.
The service is intended exclusively for businesses.
3. Categories of Processed Data
Depending on usage, the following data may be processed:
- Master data (name, email address)
- Contract and billing data
- Usage data (access logs, timestamps, truncated IP addresses)
- Uploaded content (e.g., PDFs, preview images)
- Metadata of shared content
4. Purpose of Processing
Processing is carried out for the following purposes:
- Provision of the platform
- Storage and delivery of content
- Management of user accounts
- Ensuring security and stability
- Error analysis and product improvement
5. Legal Basis
Processing is based on:
- Art. 6(1)(b) GDPR (contract performance)
- Art. 6(1)(f) GDPR (legitimate interest in security and operation)
- Art. 6(1)(c) GDPR (legal obligations)
6. Data Processing by Sub-processors
To provide the service, we use the following sub-processors:
- Railway (Application and database hosting, EU)
- Cloudflare R2 (Object storage for uploaded files, EU)
- Cloudflare (CDN & Security, EU)
- Google LLC (Google Sign-In, Gmail API; optional, USA / global)
- DodoPayments (Payment processing for subscriptions, USA)
- Umami Analytics (Web analytics for marketing pages, self-hosted on Railway in the EU; no separate third-party data transfer)
Application and database hosting as well as storage of uploaded files take place exclusively within the European Union. Where individual sub-processors (in particular Google APIs and DodoPayments) process data in third countries, transfers are based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR, along with additional technical safeguards.
7. Shared Content & External Recipients
Users can share content with external recipients via access-restricted links.
The following applies:
- The respective user is responsible for selecting recipients
- Password protection and expiration dates can optionally be set
- External recipients do not need a user account
The provider has no control over the forwarding of links by the user.
8. Storage Duration
Personal data is only stored for as long as necessary for contract fulfillment.
After termination of the contract, data will be deleted after 30 days, unless legal retention obligations require otherwise.
9. Backups
For recovery in case of errors, database contents can be restored to any point within the last 7 days. Backups are used exclusively for system security.
10. Rights of Data Subjects
Data subjects have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
Requests should be directed to: [email protected]
11. Data Security
We implement appropriate technical and organizational measures to protect personal data against loss, misuse, and unauthorized access.
12. Google Services
Google Sign-In (Login/Registration)
We enable login and registration via "Google Sign-In". In doing so, we receive from Google the basic data required for authentication (in particular email address, name, and optionally profile picture and Google Account ID). The purpose is the creation and management of your user account and secure login.
Google Workspace / Gmail: Send Emails from zeig (optional)
If you connect zeig with your Google account, zeig can send emails on your behalf via the Gmail API. For this, we only request permissions that are necessary for this function (e.g., "Send messages only" / gmail.send). zeig does not read any contents of your mailbox without additional permissions.
In this process, zeig processes the email content you create (subject, body, attachments) as well as recipient addresses exclusively for sending the message and providing the function.
OAuth Access Tokens / Revocation
To use the Google integration, we store access data (e.g., refresh tokens) in a secured form to maintain the connection. You can disconnect the connection at any time in zeig or revoke it in your Google account; tokens may also become invalid through Google (e.g., through revocation or expiration).
Use of Google Data (Limited Use)
Data we receive through Google APIs is used only to provide or improve user-facing features that you use (e.g., login, email sending). We do not use this data for advertising/profiling and do not share it with third parties for advertising purposes. Human access occurs only to the extent necessary for security/support reasons and within the applicable rules.
13. Cookies and Sessions
We use only strictly necessary cookies to enable login and session management. After successful login, we store a session cookie with a validity of seven days. Session data is stored in our database (PostgreSQL on Railway, EU) and deleted upon logout or expiration.
No consent is required for this (Section 25(2)(2) TTDSG), as the cookies are strictly necessary to provide the service expressly requested by the user. We do not use tracking or marketing cookies within the application.
14. Payment Processing (DodoPayments)
For processing paid subscriptions we use the payment service provider DodoPayments. When you subscribe to a paid plan, your name, email address, billing address, and the payment information required for the transaction are transmitted directly to and processed by DodoPayments. We do not store complete payment data (in particular no card data).
DodoPayments processes this data partly as a processor on behalf of the provider, and partly as an independent controller where necessary to complete the payment and comply with statutory obligations (e.g., anti-money-laundering, accounting). The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligations). Transfer to the USA is based on EU Standard Contractual Clauses (SCCs).
15. Salesforce Integration (optional)
Users may connect their Salesforce account to zeig at their own initiative in order to display contact suggestions (Leads and Contacts) from their own Salesforce account when creating folders. The connection is established via OAuth; zeig only reads the fields required for the suggestion feature (e.g., name, email address) from the user's Salesforce account.
This data is not transferred to third parties. The user remains the data controller for the data processed in their Salesforce account. The connection can be disconnected at any time in the profile settings or revoked from the Salesforce account.
16. Custom Domains (Whitelabel)
Customers can serve their content under their own domain (whitelabel). To do so, they set up a CNAME record pointing to our proxy domain (proxy.zeig.app). Requests to the customer's domain are routed via a Cloudflare Worker reverse proxy to our application, with the original Host header forwarded so the correct content is served.
Cloudflare acts as a processor in this regard (see section 6). No content analysis of the requests takes place beyond this routing.
17. Changes to this Privacy Policy
We reserve the right to modify this privacy policy if necessary due to technical, legal, or organizational changes.