Skip to content

Privacy Policy

1. Data controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is: CompeteSync UG (haftungsbeschränkt) i.G., represented by Managing Director Benjamin Thiele, Bennigsenstraße 30, 31275 Lehrte, Germany. Email: info@competesync.com. Phone: +49 5132 928 539 8. This privacy policy applies to the websites and services at competesync.com and app.competesync.com.

2. Data Protection Officer

No Data Protection Officer has been appointed. For any questions regarding data protection, please use the contact details listed above at any time.

3. General notes on data processing

We process personal data only to the extent necessary to provide our website, our app, our services, to communicate with users, to perform contracts, to secure our systems, or where required by law. Processing is based in particular on Art. 6(1)(a) GDPR where consent has been given, Art. 6(1)(b) GDPR where processing is necessary for the performance of a contract or to take steps prior to entering into a contract, Art. 6(1)(c) GDPR where we are legally obliged to process the data, and Art. 6(1)(f) GDPR where processing is necessary to safeguard our legitimate interests.

4. Hosting with Hetzner

Our website and app are hosted with Hetzner. When you access our website and app, technically necessary data is processed, which may include IP address, date and time of access, browser type and version, referrer URL, pages and files accessed, volume of data transferred, operating system and technical access data. This processing serves the secure and stable provision of the website and app. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, error-free and efficient provision of our online offering. Server log files are stored for 7 days and then deleted, unless longer storage is required for security reasons, to investigate misuse, or to pursue legal claims. A data processing agreement under Art. 28 GDPR is in place with Hetzner.

5. Cloudflare CDN and security services

We use Cloudflare as a content delivery network and for security functions, including Cloudflare Turnstile as a protection mechanism against abusive use, automated access and spam. This may involve processing IP address, browser and device information, time of access, technical usage data, interaction data used to verify human usage, and security and log data. This processing serves the secure, fast and reliable provision of our online offering and protection against attacks, spam and abusive access, on the basis of Art. 6(1)(f) GDPR. Where Cloudflare Turnstile or other Cloudflare functions store or read information on the end device, this takes place under § 25 TDDDG; where consent is required, processing is based on Art. 6(1)(a) GDPR and § 25(1) TDDDG. A data processing agreement under Art. 28 GDPR is in place with Cloudflare.

6. Cookies, local storage and consent management

Our website and app use cookies and comparable technologies, in particular local storage. We distinguish between necessary technologies required for operation and non-necessary technologies used only after prior consent. Necessary technologies, including storing your consent choice itself in your browser's local storage, are used on the basis of § 25(2) TDDDG and Art. 6(1)(f) GDPR. Non-necessary technologies — currently our self-hosted web analytics described in Section 19 — are only activated after you actively accept them via the consent banner shown on your first visit, based on § 25(1) TDDDG and Art. 6(1)(a) GDPR; nothing beyond strictly necessary technologies runs before that choice is made. You can withdraw or change your consent at any time with effect for the future via the "Cookie preferences" link in the website footer, which resets your stored choice and lets you decide again.

7. Contact

If you contact us, for example by email or through a contact form, we process the data you provide, in particular name, email address and message. This serves to handle your inquiry, based on Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the content of the inquiry. Contact inquiries are generally stored for 365 days and then deleted, unless statutory retention obligations apply or longer storage is required for contract processing, or to pursue or defend legal claims.

8. Registration and user account

Users can create an account to use certain features of our app. This processes name, email address, password and date of birth, to set up and manage the account, for authentication, and to provide the app's features, based on Art. 6(1)(b) GDPR. Passwords are not stored in plain text but protected according to the state of the art. The date of birth is processed to verify age-related access requirements and to ensure the offering is only used by users aged 16 and over, based on Art. 6(1)(b) and, where necessary, Art. 6(1)(f) GDPR.

9. Use of the app and SaaS features

When using our app and SaaS features, we process the data necessary to provide the respective features, including the user's master data, access credentials, usage data, technical log data, content entered by the user, uploaded files, and communication and interaction data within the app. This serves to provide the contractually agreed digital services, based on Art. 6(1)(b) GDPR; where processing is necessary to ensure technical stability, IT security, abuse prevention or error analysis, it is based on Art. 6(1)(f) GDPR. Customer data is generally stored for 365 days, unless longer statutory retention obligations apply or further storage is required for contract processing, or to pursue or defend legal claims.

10. Uploaded files and user data

Users can upload data and files within the app. This content is processed to provide the respective app features, based on Art. 6(1)(b) GDPR. Users are responsible for only uploading data they are authorized to process. Special categories of personal data within the meaning of Art. 9 GDPR, such as health data, biometric data, or information on political opinions, are not intended to be processed.

11. Payment processing via Stripe and Stripe Billing

We use Stripe and Stripe Billing for payments, subscriptions and billing. This may involve processing name, email address, billing details, payment data, contract and subscription data, transaction data, and IP address and technical payment information, for payment processing and contract performance, based on Art. 6(1)(b) GDPR. Where we are required to retain certain payment and billing data under tax or commercial law, processing is based on Art. 6(1)(c) GDPR. A data processing agreement under Art. 28 GDPR is in place with Stripe to the extent Stripe acts as a processor.

12. Email communication via Microsoft 365

We use Microsoft 365 for our business email communication, which may involve processing email address, name, content of communications, attachments, times of communication and technical metadata. This serves to carry out our communications, handle inquiries and process contracts, based on Art. 6(1)(b) or Art. 6(1)(f) GDPR. A data processing agreement under Art. 28 GDPR is in place with Microsoft.

13. CRM and internal organization with Airtable

We use Airtable for CRM and organizational purposes, which may involve processing name, contact details, company details, communication history, contract and project data, and internal notes, depending on the contact or customer relationship. This serves to organize customer relationships, handle inquiries, and carry out pre-contractual or contractual measures, based on Art. 6(1)(b) or Art. 6(1)(f) GDPR. Our legitimate interest lies in the efficient organization of our business processes. A data processing agreement under Art. 28 GDPR is in place with Airtable.

14. Support system Zammad

We use Zammad for support inquiries, which may involve processing name, email address, content of the support inquiry, technical information, communication history and attachments. This serves to handle support inquiries and fulfill contractual or pre-contractual obligations, based on Art. 6(1)(b) or Art. 6(1)(f) GDPR. A data processing agreement under Art. 28 GDPR is in place with Zammad.

15. Applications

Applications — including for our unpaid volunteer positions — can be submitted by email or through the application form on our careers page. We process the data submitted as part of the application, in particular name, contact details, the role applied for, application documents, links to a portfolio or profile, and other information provided by the applicant. This serves to carry out the application and selection process, based on Art. 6(1)(a) GDPR (consent, given by submitting the application) and Art. 6(1)(f) GDPR (our legitimate interest in reviewing and organizing applications); where an application concerns a paid employment relationship rather than a volunteer position, Section 26 BDSG (German Federal Data Protection Act) additionally applies. Application data is deleted once it is no longer required for the application process, unless statutory retention obligations apply or longer storage is required to defend legal claims.

16. In-app community

Our app may provide in-app community features, which may involve processing name or username, profile information, posts, comments or other content, reactions and interactions, times of publication, technical metadata, and moderation and abuse reports. This serves to provide the community features, based on Art. 6(1)(b) GDPR to the extent the features are part of the usage relationship; where we moderate content, prevent abuse or protect our platform, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in providing interactive features, enforcing our terms of use, protecting other users, and the secure operation of our platform. We reserve the right to review, moderate or remove content where necessary to comply with legal requirements, protect the rights of third parties, or enforce our terms of use.

17. Discord community

We operate or link to a community on Discord. If you join our Discord community or interact with us or other users there, this may involve processing your Discord username, profile information, messages and posts, reactions and interactions, membership in servers or channels, technical metadata, and moderation and security information. Our processing serves to provide, organize and moderate the community, based on Art. 6(1)(b) GDPR to the extent the community is part of the usage relationship, as well as Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a community, communicating with users, moderating content, and protecting against abuse. To the extent Discord independently processes personal data, this processing is Discord's own responsibility, over which we have only limited influence.

18. Social media profiles

On our website we link to our social media profiles on Instagram, X, TikTok and Discord. These are merely links; simply visiting our website does not load any social media plugins. If you click such a link, you leave our website, and the respective platform provider is generally responsible for any subsequent processing of personal data.

19. Web analytics with Umami

We use Umami, a privacy-focused, open-source web analytics tool that we operate ourselves on our own infrastructure in Germany — no analytics data is shared with Umami's maker or any other third party. Umami is only loaded after you have given consent via the banner described in Section 6; it does not run before that. Once active, it may process pageview and navigation data, referrer, approximate location derived from IP address, device and browser type, and, where enabled, session replay and heatmap data such as mouse movement, clicks, scrolling and on-page interaction. Session replay and heatmaps are configured to mask input fields and to exclude our Founding Teams application form from recording entirely, so its contents (such as team name or email address) are never captured. This processing serves to understand and improve how the website is used, based on Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can decline or withdraw consent at any time via the "Cookie preferences" link in the footer; declining does not affect your ability to use the website. We do not use Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, retargeting, remarketing or conversion tracking.

20. Google Fonts

Google Fonts are hosted locally. Visiting our website therefore does not establish a connection to Google servers to load fonts.

21. Minors

Our offering is intended for users aged 16 and over. Use by persons under the age of 16 is not intended. Where consent from a child is required for services of the information society, the requirements of Art. 8 GDPR apply.

22. International use and transfers to third countries

Our offering is aimed at users internationally. When using our services and the service providers we engage, personal data may also be processed outside the European Union and the European Economic Area, in particular in connection with Microsoft 365, Airtable, Stripe, Cloudflare, Zammad, Discord and other linked social media platforms. Where personal data is transferred to countries outside the EU or EEA, this only takes place if the requirements of Art. 44 et seq. GDPR are met, based in particular on an adequacy decision, standard contractual clauses, additional safeguards, explicit consent, or another exception provided for by law.

23. Processors and service providers

We engage service providers who may process personal data on our behalf, including hosting providers, CDN and security services, email service providers, CRM service providers, support service providers, payment service providers, and technical IT service providers. Data processing agreements under Art. 28 GDPR are in place with all necessary service providers.

24. Retention period

We store personal data only for as long as necessary for the respective purposes. Contact inquiries and customer data are generally stored for 365 days, and server log files for 7 days. Longer storage may take place where statutory retention obligations apply, or storage is required to assert, exercise or defend legal claims. Business and tax-relevant documents may be subject to statutory retention obligations, in which case processing is based on Art. 6(1)(c) GDPR.

25. Data security

We take technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure. These measures are taken in accordance with the state of the art, the cost of implementation, and the nature, scope, circumstances and purposes of the processing, taking into account the risks to the rights and freedoms of natural persons, in line with Art. 32 GDPR.

26. Rights of data subjects

Under the GDPR, data subjects have the right of access (Art. 15), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction of processing (Art. 18), the right to data portability (Art. 20), the right to object (Art. 21), the right to withdraw consent given (Art. 7(3)), and the right to lodge a complaint with a supervisory authority (Art. 77).

27. Withdrawal of consent

Where processing is based on consent, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out until the withdrawal remains unaffected.

28. Right to object

To the extent we process personal data on the basis of Art. 6(1)(f) GDPR, data subjects have the right to object to the processing at any time for reasons arising from their particular situation.

29. Right to lodge a complaint with a supervisory authority

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they consider that the processing of their personal data violates data protection law.

30. Changes to this privacy policy

We may amend this privacy policy if our data processing, our services, or legal requirements change.