Privacy

What this site stores about you.

Information pursuant to Articles 13 and 14 GDPR.

The German version of this notice prevails. The English version is a courtesy translation.

1. Controller

upsmart GmbH, Fährstr. 217, 40221 Düsseldorf, Germany
Managing director: Jerome Burmeister
Email: info@upsmart.team

Data protection contact

For any matter concerning data processing, exercising your rights as a data subject or withdrawing consent: info@upsmart.team.

Under § 38 (1) BDSG there is currently no obligation to appoint a data protection officer, as none of the thresholds is met (at least 20 people permanently engaged in automated processing, large-scale processing of special categories, commercial transfer of data). This page will be updated as soon as an obligation arises.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "recipient", "third party" and "consent" used in this notice are to be understood within the meaning of Article 4 GDPR.

3. Data subject rights

You have the right at any time:

  • to access the data processed about you (Article 15 GDPR)
  • to rectification of inaccurate data (Article 16 GDPR)
  • to erasure (Article 17 GDPR), unless retention obligations apply
  • to restriction of processing (Article 18 GDPR)
  • to data portability (Article 20 GDPR). You receive your data in a structured, commonly used and machine-readable format
  • to object to processing based on legitimate interests (Article 21 GDPR), and in particular to object to direct marketing at any time and without giving reasons
  • to withdraw consent with effect for the future (Article 7 (3) GDPR)
  • to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for upsmart is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de

4. Processing when you simply visit the site

When you access the website, the hosting provider processes technically necessary connection and log data in order to deliver the content and to defend against attacks: server log data (IP address, user agent, referrer, time of the request, status code). The legal basis is Article 6 (1) (f) GDPR, the legitimate interest in secure operation.

This website is operated by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel is certified under the EU-U.S. Data Privacy Framework. The infrastructure runs on Amazon Web Services, Microsoft Azure and Google Cloud, which thereby act as sub-processors.

the statement on the Article 28 GDPR processing agreement with Vercel, once the version that applies to our plan is documented

Retention period of the server logs, once confirmed by the provider

5. External services

On a plain page view, this website loads no content from third-party servers. Fonts, images, scripts and stylesheets sit on the same server as the page itself. No analytics services and no embedded maps, videos or third-party font services are loaded.

Only when you press a booking button does the scheduling calendar of Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA, open in a new window. No data is transmitted to Calendly before that click. On their page Calendly's own privacy notice applies; the company is certified under the EU-U.S. Data Privacy Framework and has designated a representative in the Union.

6. Getting in touch

If you contact us by email or telephone, we process your details in order to handle the enquiry on the basis of Article 6 (1) (b) or (f) GDPR.

Sign-up and funding letter

When you sign up for the platform or subscribe to the funding letter, we process your email address on the basis of your consent under Article 6(1)(a) GDPR. Sign-up uses a confirmation procedure: you receive an email with a confirmation link, that link leads to a page with a confirmation button, and only that button adds you. If it is never pressed, we do not add you to our list. The sending of the confirmation email itself is recorded in our mail provider's log.

The time of confirmation and the wording you agreed to are logged. This serves solely as the record of consent that we are required to keep under section 7(2)(3) of the German Act Against Unfair Competition.

For sending and managing addresses we use Resend, Inc., San Francisco, USA, as a processor. The agreement under Article 28 GDPR incorporates the EU standard contractual clauses. You may withdraw your consent at any time, informally to info@upsmart.team; and once we start sending letters, every letter will also carry an unsubscribe link. After withdrawal the address is deleted.

To protect both steps against abuse, we process the IP address of your connection: when the form is submitted and again when it is confirmed. It is held in memory only and serves solely to limit the number of operations per connection. After ten minutes at the latest it is no longer taken into account and is discarded on the next access; it never outlives the runtime of the function instance. No storage beyond that, no combination with other data and no profiling takes place. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in preventing confirmation messages from being sent to third-party addresses and in protecting the confirmation step against bulk requests.

Once you have confirmed, the same function remembers the confirmation link you redeemed, so that the same click does not count twice. The link contains your email address, and to that extent it too is held in memory: for at most 24 hours, because that is how long the link is valid at all. After that the entry is discarded on the next access, and it never outlives the runtime of the function instance. Here too there is no storage beyond that, no combination with other data and no profiling. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in a confirmation that takes effect only once.

7. No cookies for recognition

upsmart sets no cookies for advertising or tracking. This website sets no cookies at all. Your answer to the notice below is stored only locally in your browser (localStorage) under the key upsmart-keks and is not transmitted to any server.

8. No automated decision-making

No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place on this website. AI features of the upsmart platform itself are unaffected and are governed separately in the relevant product contract.

9. Security of processing

upsmart implements technical and organisational measures pursuant to Article 32 GDPR: TLS encryption of all connections, encrypted data storage, access logging and role-based permissions.

10. Minors

This website is addressed exclusively to business users. We do not knowingly process personal data of anyone under the age of 16.

11. Notes on AI-assisted articles

Articles on this website may be produced with the support of generative AI systems. Where they are, we mark them as AI-assisted and name the person who reviewed and cleared them before publication, together with the date of that review. The marking implements Article 50 of Regulation (EU) 2024/1689 on artificial intelligence.

Only the primary sources of the respective funding bodies are binding. Statements on deadlines, funding rates and procedures reflect the state of the review and do not replace legal, tax or funding advice.

12. Changes to this privacy notice

Changes in the legal or technical framework may make it necessary to adapt this notice. The current version applies from the moment it is published on this page.

As at: September 2026