Privacy notice
Deutsche Fassung: Datenschutzerklärung
Forschungszulage Evidence prepares the technical project description for a German R&D tax allowance application. Personal data passing through it: the name, role and work e-mail of the people who use an account; the roles, months of work, part-time share and pay of the staff the client enters for the projects (we ask for roles, not names); and whatever an uploaded export of commits or tickets contains — we ask for exports without author names.
Who is responsible
Controller: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com. We have not appointed a representative in the EU.
What is processed, why, on what basis
- The estimator runs in your browser. Nothing you type into it is sent to us unless you ask for an assessment call; then your answers and the estimated total go with the request.
- Assessment request and account: company name and size band, your name, role and work e-mail — to arrange the call and run your account (Art. 6(1)(b) GDPR).
- Intake and engagement: your projects in your words, staff by role with months, part-time share and pay per year, the terms you accepted — to prepare the draft you engaged us for (Art. 6(1)(b) GDPR). For the staff figures your company is the controller and we process them on its instructions.
- Exports of commits or tickets: dates, short texts and keys, read in your browser, the original kept in private storage — to build the evidence list (Art. 6(1)(b) GDPR).
- Usage statistics: counts and categories, no names, no amounts tied to a company (Art. 6(1)(f) GDPR, our interest in knowing whether the service works).
We do not store IP addresses. No automated decision about you is made.
How long
Uploaded exports — the original and the rows read from it — are deleted automatically 30 days after upload. The intake, the German drafts, the published draft with its evidence list, the assessment request and the engagement stay until the account is deleted, because you need them for the tax office step months later. The owner can delete the account in settings at any time: that removes everything at once, and we count each of our tables and the storage afterwards to confirm nothing is left. An account nobody ever signed in to is deleted after 30 days. Sign-in links are stored only as a hash and removed within a day of expiring.
Who else receives it
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA — runs the application. Function logs (time, address, status, errors — no form content) are kept for up to 7 days. For transfers to the USA, Cloudflare states that it relies on its certification under the EU-U.S. Data Privacy Framework and, as a fallback, the EU Standard Contractual Clauses.
- Supabase (database and private file storage in Frankfurt, EU). Only our server can read them.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (Paris trade register 498 019 298, trading as Brevo), as processor — sends sign-in links and the message that a draft is ready; no message carries anything from your intake. Brevo's sub-processors may process data outside the EEA, including the USA, Canada, Serbia and India, on Standard Contractual Clauses, the Data Privacy Framework or an adequacy decision. Brevo puts an invisible image in every letter, so it registers when a letter is opened; we cannot switch that off per message.
- OpenRouter, Inc. (USA) — only when our operator has a field of your project description translated into German: the text you wrote for that field and the form's question, nothing else — no names, no e-mail, no staff table. Requests are routed only to model providers that retain nothing (zero data retention). We have no separate data processing agreement with OpenRouter; if you do not want your project texts to go to it, tell us and the German is written by hand.
- PostHog (EU cloud, Germany) — the usage counts above, without cookies or profiles.
- Our operator — a person working for us who reads your intake and writes or checks the German.
Cookies
One: the sign-in cookie, which holds the account and the person and nothing else. The statistics run without cookies and without local storage.
Your rights
You may ask for access, correction, deletion, restriction, portability and object to processing (Art. 15–21 GDPR); deletion you can do yourself in settings. Write to privacy@vitersoft.com or forschungszulage@vitersoft.com. You may complain to any data protection supervisory authority (Art. 77 GDPR), for example the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Datenschutzerklärung
1. Verantwortlicher
Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. E-Mail: privacy@vitersoft.com. Ein Vertreter in der EU (Art. 27 DSGVO) ist nicht benannt.
2. Verarbeitete Daten, Zwecke, Rechtsgrundlagen
Der Rechner läuft in Ihrem Browser; Eingaben erreichen uns nur, wenn Sie ein Erstgespräch anfragen, dann zusammen mit der Anfrage. Für Anfrage und Konto verarbeiten wir Firmenname, Größenklasse, Ihren Namen, Ihre Funktion und geschäftliche E-Mail-Adresse (Art. 6 Abs. 1 lit. b DSGVO). Für den Auftrag verarbeiten wir Ihre Projektangaben, Mitarbeitende nach Funktion (nicht nach Namen) mit Monaten, Teilzeitanteil und Personalkosten je Jahr sowie die akzeptierten Bedingungen (Art. 6 Abs. 1 lit. b DSGVO); für die Personaldaten ist Ihr Unternehmen Verantwortlicher und wir verarbeiten sie nach seinen Weisungen. Hochgeladene Exporte von Commits oder Tickets (Datum, Kurztext, Schlüssel) werden im Browser gelesen, das Original privat gespeichert. Nutzungsstatistik ohne Cookies und ohne Profile (Art. 6 Abs. 1 lit. f DSGVO). IP-Adressen speichern wir nicht. Eine automatisierte Entscheidung findet nicht statt.
3. Speicherdauer
Exporte (Original und gelesene Zeilen) werden 30 Tage nach dem Hochladen automatisch gelöscht. Angaben, Entwürfe, veröffentlichter Entwurf mit Belegliste, Anfrage und Auftrag bleiben bis zur Löschung des Kontos, die die Inhaberin oder der Inhaber jederzeit in den Einstellungen vornehmen kann. Konten ohne Anmeldung löschen wir nach 30 Tagen; Anmeldelinks speichern wir nur als Hashwert und löschen sie spätestens einen Tag nach Ablauf.
4. Empfänger
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Betrieb der Anwendung; Funktionsprotokolle ohne Formularinhalte bis zu 7 Tage). Für Übermittlungen in die USA stützt sich Cloudflare nach eigenen Angaben auf das EU-U.S. Data Privacy Framework und ergänzend auf die EU-Standardvertragsklauseln.
- Supabase (Datenbank und privater Dateispeicher in Frankfurt, EU).
- Sendinblue, vereinfachte Aktiengesellschaft französischen Rechts, 9-17 rue Salneuve, 75017 Paris, Frankreich, Handels- und Gesellschaftsregister Paris Nr. 498 019 298 (Brevo), als Auftragsverarbeiter für Anmeldelinks und Benachrichtigungen. Unterauftragsverarbeiter können Daten auch außerhalb des EWR verarbeiten, u. a. in den USA, Kanada, Serbien und Indien; Grundlage sind Standardvertragsklauseln, das Data Privacy Framework oder ein Angemessenheitsbeschluss. Brevo registriert über ein unsichtbares Bild, wann eine E-Mail geöffnet wird.
- OpenRouter, Inc. (USA), nur wenn unser Bearbeiter ein Feld Ihrer Vorhabenbeschreibung übersetzen lässt: der von Ihnen geschriebene Text dieses Feldes und die Frage des Formulars, keine Namen, keine E-Mail-Adresse, keine Personaltabelle; nur an Anbieter ohne Datenspeicherung. Ein gesonderter Auftragsverarbeitungsvertrag mit OpenRouter besteht nicht; auf Wunsch schreiben wir den deutschen Text von Hand.
- PostHog (EU-Cloud, Deutschland), Nutzungsstatistik ohne Cookies und Profile.
- Unser Bearbeiter, der Ihre Angaben liest und den deutschen Text schreibt oder prüft.
5. Cookies
Nur das Anmelde-Cookie mit Konto und Person. Die Statistik nutzt weder Cookies noch lokalen Speicher.
6. Ihre Rechte
Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch (Art. 15–21 DSGVO); die Löschung können Sie selbst in den Einstellungen vornehmen. Anfragen an privacy@vitersoft.com. Beschwerde bei einer Datenschutz-Aufsichtsbehörde (Art. 77 DSGVO), etwa der Berliner Beauftragten für Datenschutz und Informationsfreiheit.