StrategyFrame® Privacy Policy
Effective date: September 25, 2026
This Privacy Policy explains how StrategyFrame® GmbH ("StrategyFrame®", "we", "us") collects, uses and shares personal information when you visit our US website strategyframe.us, enter into a subscription for or use the StrategyFrame® AI platform (the "Service"), or otherwise interact with us.
1. Who we are
The controller responsible for your personal information is StrategyFrame® GmbH, Düsseldorfer Strasse 181, 40545 Düsseldorf, Germany, info@strategy-frame.com. Our Data Protection Officer can be reached through heyData GmbH, Schützenstrasse 5, 10117 Berlin, Germany, datenschutz@heydata.eu.
Because we are established in Germany, we process all personal information in accordance with the EU General Data Protection Regulation (GDPR), regardless of where you are located. Section 9 describes additional rights under US state law.
Customer Data in the Service. When a business customer uploads content to the Service, we process personal information in that content on the customer's behalf as its processor. The customer's own privacy notice governs that processing. Please contact the customer with requests about it. The sub-processors we use for Customer Data, including providers of AI models, are listed in our Data Processing Addendum, which customers receive with their contract.
2. Information we collect
Category | Examples | Source |
|---|---|---|
Identifiers and contact details | Name, business email, phone number, company, job title | You |
Account information | Login credentials, user settings, single sign-on data | You, your SSO provider |
Billing information | Billing contact and address, invoices, records of bank transfers | You, your bank |
Usage and device information | IP address, browser, device, pages visited, features used, timestamps | Automatically |
Communications | Messages to support, chat, meeting bookings, newsletter interactions | You |
Marketing and advertising data | Cookie identifiers, ad interactions, conversion events | Cookies and similar technologies |
We do not knowingly collect sensitive personal information as defined by US state law, and we ask you not to submit it.
3. How we use information and our legal bases
Purpose | Legal basis under GDPR |
|---|---|
Providing the Service, managing accounts, billing and support | Performance of a contract (Art. 6(1)(b)) |
Securing our website and Service, preventing fraud | Legitimate interests (Art. 6(1)(f)) |
Improving the Service and understanding usage | Legitimate interests (Art. 6(1)(f)) or consent where cookies are involved (Art. 6(1)(a)) |
Analytics and advertising cookies | Consent (Art. 6(1)(a)) |
Newsletter and marketing emails | Consent (Art. 6(1)(a)); for existing customers, legitimate interests in direct marketing (Art. 6(1)(f)) |
Complying with tax and legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not use automated decision-making that produces legal or similarly significant effects on you.
4. Service providers we share information with
We share personal information only with service providers who process it on our behalf under written contracts, or as described below.
Purpose | Providers |
|---|---|
Hosting and content delivery | Vercel Inc. (USA) |
Authentication | Okta, Inc. / Auth0 (USA) |
CRM, forms, meeting booking, newsletter and live chat | HubSpot Germany GmbH |
Analytics and tag management | Google Analytics, Google Tag Manager, Microsoft Clarity |
Advertising and conversion tracking | Google Ads (incl. Conversion Tag and Customer Match), LinkedIn Ads, Meta Ads, Meta Pixel, Meta Conversions API |
Customer reviews | Google Business Profile, Google Customer Reviews |
Embedded media | YouTube, Spotify |
Spam and bot protection | Google reCAPTCHA |
Workflow automation | Zapier, Inc. (USA) |
Privacy seal | heyData GmbH |
We may also disclose information to authorities where required by law, to protect our rights, or to a successor in a merger or acquisition.
5. International transfers
We are based in Germany and host our Service primarily in the European Union. If you are in the United States, your information is transferred to and processed in the EU. Where we transfer personal information from the EU to countries outside the European Economic Area, we rely on an adequacy decision, such as the EU–US Data Privacy Framework for certified US companies, or on the European Commission's Standard Contractual Clauses.
6. Retention
We keep personal information only as long as needed for the purposes above. Account data is deleted after your account ends, subject to a 30-day export period. Billing records are retained for up to 10 years to meet German tax and commercial law requirements. Server logs are deleted after 14 days.
7. Cookies and similar technologies
We use strictly necessary cookies to operate the website and Service. We use analytics and advertising cookies only with your consent, which you can give or withdraw at any time through Cookie Settings. Our website honors Global Privacy Control (GPC) signals as an opt-out of analytics and advertising cookies. Because we rely on consent and GPC, we do not respond separately to "Do Not Track" browser signals.
8. Your rights under the GDPR
You have the right to access, correct or delete your personal information, to restrict or object to its processing, to data portability, and to withdraw consent at any time without affecting prior processing. You may also lodge a complaint with a data protection supervisory authority, such as the State Commissioner for Data Protection of North Rhine-Westphalia (LDI NRW).
9. Your US state privacy rights
Depending on your state of residence, including California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws, you may have the right to: know what personal information we collect and how we use and disclose it; access a copy of it; correct it; delete it; and opt out of the sale of personal information, the sharing of personal information for cross-context behavioral advertising, and targeted advertising.
We do not sell personal information for money. Our use of advertising cookies may be considered "sharing" or "targeted advertising" under some state laws. You can opt out at any time through Your Privacy Choices or by enabling Global Privacy Control in your browser.
To exercise your rights, email info@strategy-frame.com. We will verify your request by matching information you provide with information we hold. You may use an authorized agent. We will not discriminate against you for exercising your rights. If we deny your request, you may appeal by replying to our decision.
In the past 12 months we have collected the categories of personal information listed in Section 2, for the purposes listed in Section 3, and disclosed them to the categories of recipients listed in Section 4.
10. Children
The Service is intended for business users. It is not directed to children under 16, and we do not knowingly collect personal information from them.
11. Security
We use technical and organizational measures to protect personal information, including encryption in transit and access controls. We are working toward ISO/IEC 27001 certification. No method of transmission or storage is completely secure.
12. Reviewing and updating your information
You can review and update your account information in your account settings or by contacting us.
13. Changes to this policy
We will post any changes on this page and update the effective date. For material changes, we will notify account holders by email before the change takes effect.
14. Contact
StrategyFrame® GmbH, Düsseldorfer Strasse 181, 40545 Düsseldorf, Germany. Email: info@strategy-frame.com. Data Protection Officer: heyData GmbH, datenschutz@heydata.eu.