Reguly

Legal

Privacy policy

Last updated: 18 June 2026

This page is a translation. Only the German version is legally binding; in case of doubt it prevails.

Privacy policy

The protection of your personal data is important to us. We process your data exclusively on the basis of the statutory provisions, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). In this policy we inform you which data we collect, for what purpose and on what legal basis we process it, and which rights you have.

Personal data is any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).

Controller

The controller responsible for data processing on this website is:

Bites GbR, Van-Douven-Straße 12, 40227 Düsseldorf, Germany. Email: info@reguly.eu

What data we process

Depending on your use, we process the following categories of personal data:

  • Account and master data: name, email address, and where applicable phone number and postal address, as well as the credentials you provide on registration.
  • Usage and content data: the product information, documents and settings you create within the platform.
  • Technical access data (server logs): IP address, date and time of access, the page requested, browser type and operating system.
  • Communication data: the content you send us by email or via contact forms.

Purposes and legal bases

We process your data to provide and operate the platform, to perform the usage contract and to respond to your enquiries.

The legal bases are in particular Art. 6(1)(b) GDPR (performance of a contract) for account and platform use, Art. 6(1)(f) GDPR (legitimate interest in secure, uninterrupted operation) for server logs, and Art. 6(1)(c) GDPR (legal obligation) for statutory retention requirements.

Hosting (Vercel)

Our website and application are hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). In doing so, Vercel processes access data (e.g. IP address and technical connection data) on our behalf as a processor (Art. 28 GDPR).

Where data is transferred to the USA, this is done on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR) to ensure an adequate level of data protection.

We operate the application backend (API) and the associated database with Render Services, Inc. (San Francisco, USA). Render processes the data stored in the platform on our behalf as a processor (Art. 28 GDPR). Where data is transferred to the USA, this is done on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR).

Payment processing (Stripe)

To process payments we use Stripe Payments Europe, Ltd. (The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland). Your payment data (e.g. card details) is processed directly by Stripe; we do not store full payment data on our servers.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Further information can be found in Stripe’s privacy policy at https://stripe.com/privacy.

Sign in with Google

You can optionally sign in via your Google account (“Sign in with Google”). In doing so, Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) transmits the profile data required for sign-in to us, in particular your name and email address.

Use is based on your consent (Art. 6(1)(a) GDPR) or on the performance of a contract (Art. 6(1)(b) GDPR). Further information can be found in Google’s privacy policy at https://policies.google.com/privacy.

Newsletter

If you subscribe to our newsletter, we process the email address you provide and, optionally, your name in order to send you regular information on the PPWR and related compliance topics. The legal basis is your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time with effect for the future via the unsubscribe link in every email or by message to info@reguly.eu; we document your consent and its withdrawal.

For dispatch we use the service provider Resend (Resend, Inc., USA) as a processor (Art. 28 GDPR). Resend processes your email address and technical dispatch data. Where data is transferred to the USA, this is done on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR).

Cookies & audience measurement

Our website uses strictly necessary cookies that are required for operation and need no consent. With your consent we run our own pseudonymous first-party usage analysis for audience measurement. We record page views, clicks, scroll depth, visible page sections, dwell time, device and screen data (e.g. browser, operating system, screen resolution), approximate country-level origin and the chronological history of a session. This data is grouped via a random session identifier; for logged-in users the session is additionally linked to the user account, so it is traceable which actions occurred in which session. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); for the account-related analysis of logged-in users we additionally rely on Art. 6(1)(b) and (f) GDPR.

We do not store any raw IP addresses, only a salted SHA-256 hash to distinguish visits. Your browser’s “Do Not Track” signal is respected. You can adjust or withdraw your consent at any time with effect for the future:

Retention period

We store personal data only for as long as is necessary for the purposes stated or as required by statutory retention periods. Account data is stored for the duration of the contractual relationship and deleted after it ends, unless statutory retention obligations apply. Server logs are generally deleted or anonymised automatically after a short period.

Your rights

You have the right at any time to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and to object to processing (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia. To exercise your rights, an informal message to info@reguly.eu is sufficient.

Data security

We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access. All transmission is SSL/TLS-encrypted throughout.

If you have any questions about data protection or wish to exercise your rights, you can reach us at any time at info@reguly.eu.