B
BizBrew

Privacy Policy

Version 2026-10-04.2

1. Who is responsible (controller)

The controller for the processing described here (Art. 4(7) GDPR) is:

BizBrew UG (haftungsbeschränkt) i.G.
Mittenwalder Str. 10
12629 Berlin
Germany
Email: [email protected]
Phone: +49 176 26086067
Data protection officer: NOT CONFIGURED: LEGAL_DPO

This policy covers the website bizbrew.org and the accounts of businesses that sign up for BizBrew. When a business (a "tenant") uses BizBrew to manage its own customers, staff, bookings or payments, that business is the controller for its customers' data and we process it on its behalf under a data processing agreement. If you are a customer of such a business, please contact that business about your data; its own privacy notice applies.

2. What we process, why, and on what legal basis

Visiting the website

When you open a page, the servers and our CDN (Cloudflare) process your IP address, the requested URL, time, referrer, browser and device information. This is needed to deliver the page and to defend against attacks.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in delivering and securing the website.

Website statistics

If enabled, we use Cloudflare Web Analytics, which counts page views without cookies and without building visitor profiles. It is not loaded on the e-mail verification page.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding how the website is used.

Creating a business account

Business name, business type, your e-mail address, phone number, password (stored only as a hash) and country (used to set your default currency and time zone). We use your phone number to contact you about your account. Cloudflare Turnstile checks that the sign-up is made by a human, and we limit the number of sign-ups per IP address. We record which version of the Terms and this policy you accepted.

Legal basis: Art. 6(1)(b) GDPR — taking steps to enter into, and performing, the contract; Art. 6(1)(f) for bot and abuse protection.

Using BizBrew as a business

Account and login data, settings, the content you enter, subscription and billing data (payments are processed by Stripe; we receive a reference, card brand and last four digits, never the full card number), and service e-mails about your account.

Legal basis: Art. 6(1)(b) GDPR — performing the contract; Art. 6(1)(c) for statutory retention of billing records.

Contact form and e-mails to us

Name, e-mail address, company and your message, used only to answer your request.

Legal basis: Art. 6(1)(b) GDPR where your request concerns a contract, otherwise Art. 6(1)(f) — our interest in answering you.

Error monitoring and security

Technical error reports from the website and the application (which can include IP address and user ID), audit logs of significant administrative actions, and rate-limit counters.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, working service.

Providing the account data marked as required is necessary to conclude the contract; without it we cannot create an account. We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. We do not sell personal data or use it for advertising.

3. Recipients

We use the following service providers, bound by data processing agreements. Purpose, data, location and transfer safeguard of each are listed on our sub-processor page.

  • Hetzner Online — Server hosting for the application, database (self-hosted Supabase/PostgreSQL), file storage and cache
  • Cloudflare — DNS, CDN and TLS proxy, Turnstile bot protection, Web Analytics (cookieless) on the marketing site, R2 storage for database backups
  • Stripe — Payment processing for subscriptions and for tenants' customer payments (Stripe Connect)
  • Resend — Transactional e-mail to business account holders (sign-up, verification, billing)
  • Hostinger — SMTP e-mail delivery to tenants' customers (booking confirmations, reminders, portal e-mails)
  • Bird (MessageBird) — SMS and WhatsApp messages (phone verification, portal sign-in codes, reminders) (Only when SMS/WhatsApp messaging is used)
  • Sentry (Functional Software) — Error monitoring for the marketing website and the admin and customer portal applications
  • Google (Firebase Cloud Messaging, Google Calendar API) — Push notifications to the mobile apps; Google sign-in (OAuth) when a business connects a Google Calendar (Only when push notifications or a Google Calendar connection are used)

We also disclose data to authorities where we are legally obliged to.

4. Transfers outside the EU/EEA

Some of these providers, or their group companies, are located in or can access data from countries outside the EU/EEA, in particular the United States. Such transfers take place only on the basis of an adequacy decision (including the EU–U.S. Data Privacy Framework for certified companies) or the European Commission's standard contractual clauses (Art. 45, 46(2)(c) GDPR). The safeguard used for each provider is shown on the sub-processor page; you can request a copy of the safeguards from us.

5. How long we keep data

  • Account data: for as long as your account exists. When you ask us to delete your account, we delete or anonymise the data unless we must keep it by law.
  • Billing records and invoices: for the statutory retention periods under commercial and tax law, after which they are deleted.
  • Contact requests: until your request is resolved, unless they become part of a contract.
  • Server and security logs: only as long as needed to investigate errors and attacks.
  • Database backups: deleted data can remain in off-site backups for up to 30 days before the backup itself is deleted.

6. Your rights

You have the right to:

  • access the data we hold about you (Art. 15 GDPR);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17);
  • have processing restricted (Art. 18);
  • receive your data in a machine-readable format (Art. 20);
  • object at any time, on grounds relating to your situation, to processing based on Art. 6(1)(f), and without giving reasons to direct marketing (Art. 21);
  • withdraw any consent you gave, with effect for the future (Art. 7(3));
  • lodge a complaint with a data protection supervisory authority (Art. 77), in particular in the EU member state of your residence, place of work or the place of the alleged infringement. The authority responsible for us is: NOT CONFIGURED: LEGAL_SUPERVISORY_AUTHORITY.

To exercise your rights, e-mail [email protected] or use our contact page.

7. Cookies and similar technologies

The marketing website sets no tracking or advertising cookies. If you choose a language with the language switcher, a cookie (bb_mkt_locale) remembers your choice for one year. Cloudflare may set strictly necessary security cookies to protect the site against attacks. Cloudflare Turnstile on the sign-up and contact forms evaluates technical browser signals to tell humans from bots.

The BizBrew application (your business workspace and customer portals) uses strictly necessary cookies to keep you signed in.

8. Changes to this policy

We update this policy when our processing changes. The current version and a history of changes are shown below. Where a change affects you materially, we inform account holders by e-mail.

Change history

  • 4 October 2026 (2026-10-04.2) — Website statistics now run only with consent (banner and cookie settings); added the consent cookie, Sentry error monitoring on the website, and German, Spanish and French versions.
  • 4 October 2026 (2026-10-04) — Restructured for GDPR Art. 13: controller and contact details, legal basis per purpose, full recipient list with transfer safeguards, retention, all data subject rights including complaint to a supervisory authority. Removed consent-by-use, the unbacked encryption and fixed-deletion-period statements, and the third-party country lookups on the signup page.
  • 1 February 2026 (2026-02) — First published version.