Privacy Notice
Last updated: March 20, 2026
1. Data Controller
The controller responsible for the processing of your personal data under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:
Postera Capital GmbH
Wilhelm-Tell-Str. 26
40219 Dusseldorf, Germany
Email: [email protected]
1a. Data Protection Officer
Postera Capital GmbH is not required to appoint a Data Protection Officer under Art. 37 GDPR and § 38 BDSG. Data protection inquiries can be directed to [email protected].
2. Processing Purposes, Legal Basis and Retention Periods
a) Server Log Files
When you visit our website, we automatically collect technical access data including browser type and version, operating system, referrer URL, pages accessed, date and time of access, and your IP address. This processing is necessary for the security and technical operation of the website.
Legal basis: Art. 6(1)(f) GDPR — legitimate interests in ensuring website functionality and cybersecurity. You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR); please contact [email protected]. Augmento has carried out a balancing test; further information is available on request.
Retention: Server log files are automatically deleted after 14 days unless a specific incident requires longer retention for security investigation purposes.
b) Contact via Email and Contact Forms
Personal data submitted through contact forms or direct email (name, email address, and the content of your message) is stored and processed for the purpose of responding to your inquiry.
Legal basis: Art. 6(1)(f) GDPR — legitimate interests in responding to business communications. You have the right to object to this processing at any time (Art. 21 GDPR); contact [email protected]. Augmento has carried out a balancing test; information is available on request.
Retention: Contact data is deleted within 6 months of the inquiry being resolved, unless a longer statutory retention period applies (e.g., under commercial or tax law) or the contact relates to a contractual relationship, in which case § 2(c) below applies.
c) User Accounts and Subscription Data
When you register for an account, we collect your email address and a hashed version of your password. If you purchase a Subscription, we additionally process your subscription tier, billing status, and Paddle customer ID. This data is required to provide and manage your access to the Service.
Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of a contract to which you are party, or in order to take steps at your request prior to entering into a contract.
Retention: Account data is retained for the duration of your account. Upon account deletion, personal data is deleted within 30 days, subject to any statutory retention obligations under commercial law (§ 257 HGB: 6 years for correspondence; 10 years for accounting records under § 147 AO). API keys are revoked immediately upon account deletion and associated log entries are anonymised within 90 days.
d) API Usage Data
When you use the Augmento API, we automatically process API request logs, including your IP address, the endpoint called, query parameters (excluding your credentials), timestamp, and HTTP response codes. This data is processed to ensure the technical operation of the API, monitor compliance with rate limits, and investigate security incidents.
Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of the subscription contract; and Art. 6(1)(f) GDPR — legitimate interests in service security and abuse prevention. You have the right to object to processing under Art. 6(1)(f) at any time on grounds relating to your particular situation (Art. 21 GDPR). Augmento has carried out a balancing test; information is available on request.
Retention: API usage logs are retained for 90 days and then automatically deleted or anonymised.
e) Payment Processing
Paid subscriptions are processed through Paddle.com Market Ltd (UK/Ireland), who acts as our Merchant of Record. We do not collect or store your payment card details. Paddle processes your payment data as an independent controller under their own privacy policy (available at paddle.com/legal/privacy). We store only your Paddle customer ID and subscription status.
Legal basis: Art. 6(1)(b) GDPR — necessary for contract performance. Billing-related data (e.g., invoice records) is additionally retained under Art. 6(1)(c) GDPR to comply with commercial and tax law retention obligations.
Retention: Paddle customer ID and subscription status are retained for the duration of the contractual relationship and for 10 years thereafter in accordance with § 147 AO (German Fiscal Code) for tax record-keeping purposes.
f) Customer Support (Freshdesk)
We use Freshdesk, a customer support platform provided by Freshworks, Inc. (USA), to manage support tickets. When you create a support ticket, your name (if provided), email address and the content of your messages are transmitted to and stored by Freshworks on our behalf.
Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of a contract; Art. 6(1)(f) GDPR — legitimate interests in providing customer support. You have the right to object to processing under Art. 6(1)(f) at any time (Art. 21 GDPR); contact [email protected]. Augmento has carried out a balancing test; information is available on request.
Retention: Support tickets and associated personal data are retained for 3 years after the ticket is resolved, after which they are deleted or anonymised.
Data transfers to the USA: Freshworks, Inc. participates in the EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are additionally in place.
g) Cookies and Local Storage
This website uses only technically necessary cookies and local storage (e.g., for authentication session tokens). No tracking or marketing cookies are used. Technically necessary cookies are exempt from the consent requirement under § 25 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz).
h) Web Analytics (Plausible)
We use Plausible Analytics, a privacy-focused analytics service provided by Plausible Insights OU (Estonia). Plausible does not use cookies, does not collect personal data, and does not track individual users across websites. All data is aggregated and no individual visitor can be identified.
Legal basis: Art. 6(1)(f) GDPR — legitimate interests in understanding aggregate website usage patterns. As no personal data is processed, your right to object under Art. 21 GDPR does not apply to this processing activity.
For more information, see: plausible.io/data-policy
i) Content Delivery Network and Security (Cloudflare)
Our website is served through the content delivery network and reverse proxy of Cloudflare, Inc. (USA). Your connection is routed through Cloudflare servers, which may process your IP address, HTTP request headers and connection metadata for the purposes of content delivery, DDoS protection and website availability. Cloudflare may set technically necessary cookies for security purposes (e.g., bot detection).
Legal basis: Art. 6(1)(f) GDPR — legitimate interests in website security and performance. You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR); contact [email protected]. Augmento has carried out a balancing test; information is available on request.
Data transfers to the USA: Cloudflare, Inc. is certified under the EU-US Data Privacy Framework (DPF). Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are additionally in place. For details, see Cloudflare’s Data Processing Addendum at cloudflare.com/privacypolicy.
j) Bot Protection (Cloudflare Turnstile)
We use Cloudflare Turnstile (Cloudflare, Inc., USA) to protect registration and authentication forms from automated abuse. Turnstile may process browser characteristics, interaction patterns and your IP address to distinguish legitimate users from bots. No tracking cookies are set.
Legal basis: Art. 6(1)(f) GDPR — legitimate interests in preventing automated abuse and ensuring service integrity. You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR); contact [email protected]. Augmento has carried out a balancing test; information is available on request.
Data transfers to the USA: As described in § 2(i) above for Cloudflare.
k) Transactional Emails (Resend)
We use Resend, Inc. (USA) to deliver transactional emails (e.g., password reset emails, account verification, subscription notifications). Your email address and the content of the transactional message are transmitted to Resend for this purpose.
Legal basis: Art. 6(1)(b) GDPR — necessary for contract performance (account management).
Data transfers to the USA: Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are in place. Resend, Inc. is certified under the EU-US Data Privacy Framework (DPF).
Retention: Resend retains email delivery logs for 30 days.
l) B2B Contact and Institutional Subscriber Data
Where you access the Service on behalf of a business or organisation (e.g., as an employee, analyst or authorised representative), we process the personal data necessary to manage the institutional subscription account: email addresses, names, job titles (if provided), and communication history.
Legal basis: Art. 6(1)(b) GDPR — necessary for the performance of the subscription contract with your organisation; Art. 6(1)(f) GDPR — legitimate interests in maintaining the business relationship. You have the right to object to processing under Art. 6(1)(f) at any time (Art. 21 GDPR); contact [email protected].
Retention: Business contact data is retained for the duration of the subscription and for 3 years after contract termination for correspondence purposes, subject to commercial law retention obligations.
3. Recipients and Third-Party Processors
Your data may be transferred to or processed by the following third-party service providers, with whom we have concluded Data Processing Agreements (DPAs) pursuant to Art. 28 GDPR where applicable:
| Provider | Location | Purpose | Transfer Safeguard |
|---|---|---|---|
| Paddle.com Market Ltd | UK / Ireland | Payment processing / Merchant of Record | Adequacy decision (UK) / SCCs (Ireland, EEA) |
| Freshworks, Inc. (Freshdesk) | USA | Customer support ticket management | EU-US DPF + SCCs (Art. 46(2)(c) GDPR) |
| Resend, Inc. | USA | Transactional email delivery | EU-US DPF + SCCs (Art. 46(2)(c) GDPR) |
| Cloudflare, Inc. | USA | CDN, DDoS protection, bot detection (Turnstile) | EU-US DPF + SCCs (Art. 46(2)(c) GDPR) |
| Plausible Insights OU | Estonia (EEA) | Privacy-preserving web analytics | No personal data processed; no transfer safeguard required |
We do not sell personal data to third parties and do not transfer personal data for marketing purposes.
4. Automated Decision-Making
We do not engage in automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects or similarly significant effects on you.
5. Your Rights
Under the GDPR, you have the following rights with respect to your personal data:
- Right of access — to obtain confirmation and a copy of your personal data (Art. 15 GDPR)
- Right to rectification — to have inaccurate data corrected (Art. 16 GDPR)
- Right to erasure (‘right to be forgotten’) — to request deletion of your data in certain circumstances (Art. 17 GDPR)
- Right to restriction of processing — to limit how we use your data in certain circumstances (Art. 18 GDPR)
- Right to data portability — to receive your data in a machine-readable format (Art. 20 GDPR)
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3) GDPR)
Right to Object (Art. 21 GDPR) — Important: Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims. To exercise your right to object, please contact [email protected].
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt. This period may be extended by a further two months where necessary due to the complexity or volume of requests, in which case we will notify you within the first month.
6. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your personal data violates the GDPR. The supervisory authority responsible for Postera Capital GmbH is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Postfach 20 04 44
40102 Dusseldorf
Tel.: 0211 / 38424-0
Email: [email protected]
Website: www.ldi.nrw.de
7. Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our processing activities or applicable law. Material changes will be communicated to registered Users by email at least 30 days before they take effect. The current version is always available at augmento.ai/privacy. The ‘Last updated’ date at the top of this Notice reflects the date of the most recent revision.