Privacy

Privacy notice

Status: draft — not yet legally reviewed.

Placeholder — fill in the real company details and have this reviewed before going live.
Data controller

[PLACEHOLDER: full legal company name, address and contact details of the data controller under the GDPR]

What data we process

Account data (name, email address) when you create an account; the deal, company and contact data your team enters into DealLoft; and technical log data (e.g. IP address, timestamps) when accessing the application.

Purposes of processing

Providing and operating the application, authentication, billing, and — where you enable it — syncing email and calendar events with Outlook or Gmail.

Legal basis

Processing is based on performance of the usage agreement (GDPR Art. 6(1)(b)) and, where applicable, consent (GDPR Art. 6(1)(a)) — for example when connecting Outlook, Gmail, or an AI assistant.

Processors & recipients

Supabase (database and auth hosting), Stripe (payment processing), and — only when you enable the integration — Microsoft (Outlook/Microsoft 365) and Google (Gmail/Google Calendar) under their respective OAuth grant.

Cookies

A session cookie for sign-in (strictly necessary) and a cookie that remembers your chosen language on this site. No tracking or advertising cookies.

Retention

Account-related data is kept for as long as the account is active, and removed after cancellation subject to statutory retention periods.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to lodge a complaint with a data protection authority.

Contact for privacy requests

hello@dealloft.app