Skip to content
G GRIPRESEARCH
The Dive Reports Pricing About

LEGAL

Deutsch / English

Privacy Policy (Datenschutzerklärung)

UNREVIEWED DRAFT · NICHT GEPRÜFT

DRAFT — not final, not legal advice. Prepared 2026-09-30 as a template for https://gripresearch.fi. Items in [SQUARE BRACKETS] are placeholders. Have the page reviewed before go-live. This policy reflects the actual processing (VPS hosting, e-mail + password login, Paddle payments, no tracking, no analytics, no advertising cookies). If analytics, marketing or community functions are added later, this policy must be updated first.

[English translation — the German version governs.] This is a courtesy translation of datenschutz.de.md; the German text is the binding version.

This policy informs you under Articles 13 and 14 of the General Data Protection Regulation (GDPR) about the processing of personal data on this website.

1. Controller

[FIRST AND LAST NAME] [STREET AND HOUSE NUMBER] [POSTAL CODE CITY] [COUNTRY] E-mail: [E-MAIL ADDRESS]

No data protection officer has been appointed; appointment is not legally required (Art. 37 GDPR).

2. General purposes and legal bases

We process personal data only to the extent necessary to provide a functioning website and our content and services, and to perform contracts. Any use beyond this (in particular tracking, analytics, advertising or profiling) does not take place.

3. Hosting on a VPS (server log files)

Our website is hosted on a virtual server (VPS) rented by us from [VPS PROVIDER], [LOCATION/COUNTRY OF PROVIDER]. When you access the website, the server automatically collects information in so-called server log files that your browser transmits. These are:

  • IP address (as far as required for operation),
  • date and time of access,
  • name and URL of the retrieved resource,
  • transfer protocol / HTTP status code,
  • browser type and operating system used,
  • previously visited page (referrer), where transmitted.

Purposes: provision and delivery of the website, IT security, system security and stability, error and abuse analysis. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of our service. Data processing agreement: a processor agreement under Art. 28 GDPR is in place with the hosting provider.

4. User account, e-mail + password login and transactional e-mails

Login uses an e-mail address and password. The password is stored only as a salted hash (scrypt) and is not readable by us in plain text. In particular, the following are processed:

  • your e-mail address,
  • your password (exclusively in hashed form),
  • the time of registration, login and password reset as well as the single-use tokens created for that and technical data (e.g. IP address to prevent abuse),
  • for registered users, the account data you provide.

We also use [E-MAIL SERVICE PROVIDER], [LOCATION/COUNTRY OF PROVIDER], to send transactional e-mails (password reset links, order and payment confirmations, the confirmation under Section 312f BGB relating to the withdrawal notice).

Purposes: provision and access security of your user account, performance of the user contract, execution of the login and purchase process, transmission of contract-related confirmations. Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures). Data processing agreement: a processor agreement under Art. 28 GDPR is in place with the e-mail service provider.

5. Payment processing via Paddle

The purchase of reports and subscriptions is processed via Paddle (Paddle.com Market Ltd and/or Paddle.com Inc., depending on the contracting entity — [PADDLE ENTITY / CONTRACTING PARTY]). Paddle acts as merchant of record and, as reseller, is the contracting party to the purchase: the purchase contract is concluded between you and Paddle, not with us.

  • For the checkout, payment and billing data that Paddle collects itself (e.g. name, address, payment details), Paddle is an independent controller. In this respect, Paddle's own privacy policy applies: [PADDLE PRIVACY POLICY URL].
  • Where Paddle passes personal data on to us for fulfilment, access provision and support (e.g. e-mail address, order/entitlement data), Paddle processes this data on our behalf under the Paddle Data Processing Addendum (Art. 28 GDPR); we are the controller in this respect. We do not receive complete payment data such as card numbers.

Purposes: processing the purchase or subscription, unlocking the purchased content, bookkeeping, fraud prevention. Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for fraud prevention and our legitimate interest in correct processing, Art. 6(1)(f) GDPR. Recipients: Paddle (see above).

6. Account and entitlement data

We process the account and entitlement data belonging to your account (e.g. which reports or subscriptions are unlocked for you, validity periods, access times) in order to make the purchased content available to you and to perform the contract. Legal basis: Art. 6(1)(b) GDPR.

7. Cookies, local storage and Section 25 TDDDG

We use exclusively one technically strictly necessary session cookie (or comparable local storage) that is required for the login and session process. There is no tracking, no web analytics and no advertising tracking.

The legal basis for storing information on your device is Section 25(2) No. 2 TDDDG (strict necessity for a digital service expressly requested by the user). Consent under Section 25(1) TDDDG is therefore not required; no cookie consent banner is used.

If analytics, marketing or other non-strictly-necessary cookies are used in future, this will occur only after prior express consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR); this policy will be updated beforehand.

8. Recipients and categories of recipients

Recipients of personal data are: the hosting provider ([VPS PROVIDER]), the e-mail service provider ([E-MAIL SERVICE PROVIDER]) and Paddle (payment processing) — in each case to the extent described. No disclosure to other third parties takes place unless we are legally obliged to do so (e.g. tax and accounting obligations, information to authorities).

9. Transfers to third countries

Where the services used (e.g. Paddle or the e-mail service provider) involve a transfer to third countries outside the EU/EEA — in particular the USA — this is based on an adequacy decision of the EU Commission (e.g. the EU-US Data Privacy Framework) or on appropriate safeguards under Art. 46 GDPR (in particular EU standard contractual clauses). [IF APPLICABLE, CHECK AND ADD ADEQUACY DECISION / SCC PER SERVICE.]

10. Retention period

  • Server log files: stored for [NUMBER] days, then automatically deleted, unless security-related retention is necessary.
  • Account and entitlement data: for the duration of the account; after deletion of the account only as long as statutory retention obligations exist (in particular Sections 147 AO, 257 HGB — six or ten years depending on the record).
  • Transactional e-mails / accounting records: within the above statutory retention periods. We delete or anonymise data once the purpose of processing ceases to apply and no statutory retention obligation prevents this.

11. Your rights

You have the following rights vis-à-vis us:

  • access to the data processed (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
  • withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).

To exercise your rights, a message to [E-MAIL ADDRESS] is sufficient.

Right to complain: you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is in particular [COMPETENT SUPERVISORY AUTHORITY / STATE DATA PROTECTION AUTHORITY].

12. No automated decision-making

No decision based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR takes place.

13. Necessity of providing data

The provision of your data is neither legally nor contractually required. However, for the conclusion of a user or purchase contract, the provision of the stated data (in particular the e-mail address) is necessary, since without it a login and the provision of purchased content are not possible. For purchase processing via Paddle, the necessity additionally follows from Paddle's requirements.

14. Changes to this privacy policy

We will update this policy if the processing changes (e.g. through new services). The version available on the website applies. Status: [DATE].

← home German version (binding) →
© 2026 Grip Research gripresearch.fi
Impressum (Legal notice) Datenschutz (Privacy) AGB (Terms) Widerruf (Withdrawal)