Skip to main content
Back

How Achtung.app processes data

This page explains, in plain English, what Achtung.app does with personal data when you use the service: what we receive, who else sees it, where it is stored, how long we keep it, and what we have deliberately not done.

It is an overview, not a contract. The binding agreement is the German Auftragsverarbeitungsvertrag (data processing agreement under Art. 28 GDPR). It is published in full and takes precedence over anything summarised here.


Who is responsible for what

For the data you put into the service — your brands, keywords, competitors, reports and the user accounts on your team — you are the controller and we act as your processor. We use that data only to run the service and only on your instructions.

For a smaller set of processing we are the controller in our own right, and it sits outside the data processing agreement: billing and tax records, our own server and security logs, defending legal claims, and the aggregated, anonymised industry benchmarks described in our terms.

If you are an agency using Achtung.app for a client, you can enter into the agreement as a processor yourself; the contract covers that case explicitly.

What we process for you

Category Examples
Account details of your users Name, email address, role, language, team membership
Credentials Password hash, session identifier, linked SSO identity
Usage data in your account Audit log entries with timestamp, IP address and user agent
Your content Brand name, domain, keywords, competitors, notes, description fields, generated reports
Linked accounts OAuth tokens and metrics from Google Search Console and Google Analytics 4, if you connect them

Special categories of data under Art. 9 GDPR and criminal-offence data under Art. 10 must not be entered into the service.

Who else receives it

To measure how AI assistants and search engines talk about a brand, we send the brand name, domain, keywords, competitor names and any free-text details you store to the providers below. We never send them your contact details, credentials, IP addresses or payment data.

Company Service Role Safeguard
OpenAI Ireland Ltd., Ireland OpenAI API Processor DPA for API customers; onward transfers on SCCs or an adequacy decision. We set store: false, so no retrievable application state is kept
Google Cloud EMEA Limited, Dublin, Ireland Gemini Developer API Processor Google-as-processor DPA; prompts and responses are not used to improve the product
Anthropic Ireland, Limited, Ireland Anthropic Messages API Processor DPA incorporated into the commercial terms, with SCCs, under Irish law
Perplexity AI, Inc., USA Perplexity API Processor DPA part of the API terms; certified under the EU-US Data Privacy Framework, with SCCs as a fallback
X.AI LLC, USA xAI API (Pro and Enterprise plans only) Processor DPA incorporating SCCs, under Irish law
Mistral AI SAS, France Mistral API (Pro and Enterprise plans only) Processor GDPR-based DPA; stored in the EU by default, with temporary third-country transfers not ruled out depending on the feature
Brave Software, Inc., USA Brave Search API See the note below DPA available; Brave does not treat search queries as processed on our behalf
STRATO AG, Berlin Servers and data centre Processor Processing in Germany
Hetzner Online GmbH, Germany Storage for the encrypted backups Processor Processing in Germany
HeiGIT gGmbH, Heidelberg openrouteservice, catchment-area calculation Independent controller We send only a coordinate pair, travel mode and time span — no name, no identifier. Processing in Germany

Payments run through Stripe Technology Company Limited, Dublin. That is our own contractual relationship rather than processing of your content, so it sits outside the agreement.

We use no external provider for sending email, for file storage during operation, or for web analytics. Those all run on our own infrastructure.

Where it is stored

Your account and measurement data is stored primarily with us in Germany, on servers operated by STRATO AG. The daily backup is encrypted and held at Hetzner Online GmbH, also in Germany, physically separate from the production system. The providers listed above process what we send them under their own terms, in some cases outside Germany.

How long we keep it

Data Retention
Account details For the life of the account plus 30 days
Audit log For the life of the account; deleted with the team
Visibility scores, sources and reports For the life of the account plus 90 days
Backups Two months

Billing records, server logs and support correspondence fall under our own controllership and are covered by the privacy policy, not by the agreement.

How it is protected

Access to the application requires a personal login; passwords are stored only as bcrypt hashes and sessions are encrypted. SSO can be enforced for your team. Administrative server access uses key authentication only, restricted to a fixed list of IP addresses. Data for different customers is separated by tenant, enforced in the application and covered by automated tests. All traffic runs over TLS with HSTS and a content security policy; the database, queue and cache are reachable only from the server itself.

OAuth tokens for the accounts you connect are encrypted with AES-256 at application level, so read access to the database alone does not expose them.

For development and maintenance we use an AI coding tool whose database access is restricted column by column: personal fields are withheld by the database itself, and a filter rejects queries touching them.

Backups are taken daily and kept for two months. A full restore from the offsite encrypted backup was tested on 18 August 2026 and completed in 35 minutes with the data intact. The test is repeated quarterly and each run is recorded in the agreement.

What we have deliberately not done

We publish two decisions rather than leaving them implied.

No disk encryption at rest. The production disk is not encrypted at operating-system level. The disk sits in an access-controlled data centre, the database and cache are reachable only locally, and administrative access is key-based from fixed addresses. Full-disk encryption mainly defends against physical access to the disk while the key is in memory during operation anyway; against the realistic attack paths it does nothing. We judged the remaining risk acceptable and are telling you rather than staying silent about it.

Search queries at Brave. Brave provides a DPA but does not treat search queries as data processed on our behalf, and on standard plans it retains queries for up to 90 days. Zero Data Retention exists only on a custom enterprise plan. We considered both that and switching search provider and judged them out of proportion: only the query itself goes to Brave, with no account, contact or payment data and no identifier, so Brave cannot connect a query to a person. Where a brand is named after a person, that name remains personal data — but searching a name its owner published for exactly that purpose is the point of the service. What must not go into a keyword is anything beyond it: details about private individuals unrelated to the brand, contact details, addresses, identification numbers.

Getting the agreement

The full agreement, including the technical and organisational measures and the complete list of processors, is published in German and can be downloaded as a PDF. It forms part of our terms of service and is concluded together with them, so there is nothing to sign; we record which version was in force when your contract was concluded. If you need a countersigned copy, or if your data protection team needs changes to the wording, write to daten@martinkulawik.de.