StrategyFrame® Privacy Policy

Effective date: September 25, 2026

This Privacy Policy explains how StrategyFrame® GmbH ("StrategyFrame®", "we", "us") collects, uses and shares personal information when you visit our US website strategyframe.us, enter into a subscription for or use the StrategyFrame® AI platform (the "Service"), or otherwise interact with us.

1. Who we are

The controller responsible for your personal information is StrategyFrame® GmbH, Düsseldorfer Strasse 181, 40545 Düsseldorf, Germany, info@strategy-frame.com. Our Data Protection Officer can be reached through heyData GmbH, Schützenstrasse 5, 10117 Berlin, Germany, datenschutz@heydata.eu.

Because we are established in Germany, we process all personal information in accordance with the EU General Data Protection Regulation (GDPR), regardless of where you are located. Section 9 describes additional rights under US state law.

Customer Data in the Service. When a business customer uploads content to the Service, we process personal information in that content on the customer's behalf as its processor. The customer's own privacy notice governs that processing. Please contact the customer with requests about it. The sub-processors we use for Customer Data, including providers of AI models, are listed in our Data Processing Addendum, which customers receive with their contract.

2. Information we collect

Category

Examples

Source

Identifiers and contact details

Name, business email, phone number, company, job title

You

Account information

Login credentials, user settings, single sign-on data

You, your SSO provider

Billing information

Billing contact and address, invoices, records of bank transfers

You, your bank

Usage and device information

IP address, browser, device, pages visited, features used, timestamps

Automatically

Communications

Messages to support, chat, meeting bookings, newsletter interactions

You

Marketing and advertising data

Cookie identifiers, ad interactions, conversion events

Cookies and similar technologies

We do not knowingly collect sensitive personal information as defined by US state law, and we ask you not to submit it.

3. How we use information and our legal bases

Purpose

Legal basis under GDPR

Providing the Service, managing accounts, billing and support

Performance of a contract (Art. 6(1)(b))

Securing our website and Service, preventing fraud

Legitimate interests (Art. 6(1)(f))

Improving the Service and understanding usage

Legitimate interests (Art. 6(1)(f)) or consent where cookies are involved (Art. 6(1)(a))

Analytics and advertising cookies

Consent (Art. 6(1)(a))

Newsletter and marketing emails

Consent (Art. 6(1)(a)); for existing customers, legitimate interests in direct marketing (Art. 6(1)(f))

Complying with tax and legal obligations

Legal obligation (Art. 6(1)(c))

We do not use automated decision-making that produces legal or similarly significant effects on you.

4. Service providers we share information with

We share personal information only with service providers who process it on our behalf under written contracts, or as described below.

Purpose

Providers

Hosting and content delivery

Vercel Inc. (USA)

Authentication

Okta, Inc. / Auth0 (USA)

CRM, forms, meeting booking, newsletter and live chat

HubSpot Germany GmbH

Analytics and tag management

Google Analytics, Google Tag Manager, Microsoft Clarity

Advertising and conversion tracking

Google Ads (incl. Conversion Tag and Customer Match), LinkedIn Ads, Meta Ads, Meta Pixel, Meta Conversions API

Customer reviews

Google Business Profile, Google Customer Reviews

Embedded media

YouTube, Spotify

Spam and bot protection

Google reCAPTCHA

Workflow automation

Zapier, Inc. (USA)

Privacy seal

heyData GmbH

We may also disclose information to authorities where required by law, to protect our rights, or to a successor in a merger or acquisition.

5. International transfers

We are based in Germany and host our Service primarily in the European Union. If you are in the United States, your information is transferred to and processed in the EU. Where we transfer personal information from the EU to countries outside the European Economic Area, we rely on an adequacy decision, such as the EU–US Data Privacy Framework for certified US companies, or on the European Commission's Standard Contractual Clauses.

6. Retention

We keep personal information only as long as needed for the purposes above. Account data is deleted after your account ends, subject to a 30-day export period. Billing records are retained for up to 10 years to meet German tax and commercial law requirements. Server logs are deleted after 14 days.

7. Cookies and similar technologies

We use strictly necessary cookies to operate the website and Service. We use analytics and advertising cookies only with your consent, which you can give or withdraw at any time through Cookie Settings. Our website honors Global Privacy Control (GPC) signals as an opt-out of analytics and advertising cookies. Because we rely on consent and GPC, we do not respond separately to "Do Not Track" browser signals.

8. Your rights under the GDPR

You have the right to access, correct or delete your personal information, to restrict or object to its processing, to data portability, and to withdraw consent at any time without affecting prior processing. You may also lodge a complaint with a data protection supervisory authority, such as the State Commissioner for Data Protection of North Rhine-Westphalia (LDI NRW).

9. Your US state privacy rights

Depending on your state of residence, including California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws, you may have the right to: know what personal information we collect and how we use and disclose it; access a copy of it; correct it; delete it; and opt out of the sale of personal information, the sharing of personal information for cross-context behavioral advertising, and targeted advertising.

We do not sell personal information for money. Our use of advertising cookies may be considered "sharing" or "targeted advertising" under some state laws. You can opt out at any time through Your Privacy Choices or by enabling Global Privacy Control in your browser.

To exercise your rights, email info@strategy-frame.com. We will verify your request by matching information you provide with information we hold. You may use an authorized agent. We will not discriminate against you for exercising your rights. If we deny your request, you may appeal by replying to our decision.

In the past 12 months we have collected the categories of personal information listed in Section 2, for the purposes listed in Section 3, and disclosed them to the categories of recipients listed in Section 4.

10. Children

The Service is intended for business users. It is not directed to children under 16, and we do not knowingly collect personal information from them.

11. Security

We use technical and organizational measures to protect personal information, including encryption in transit and access controls. We are working toward ISO/IEC 27001 certification. No method of transmission or storage is completely secure.

12. Reviewing and updating your information

You can review and update your account information in your account settings or by contacting us.

13. Changes to this policy

We will post any changes on this page and update the effective date. For material changes, we will notify account holders by email before the change takes effect.

14. Contact

StrategyFrame® GmbH, Düsseldorfer Strasse 181, 40545 Düsseldorf, Germany. Email: info@strategy-frame.com. Data Protection Officer: heyData GmbH, datenschutz@heydata.eu.