Privacy notice
As of 31 August 2026
1. Scope
This notice covers the Implisense Platform at app.implisense.com — the website, the signed-in area and the API reachable through it. Our marketing site implisense.com has its own privacy notice.
2. Controller
Implisense GmbH, Spiekermannstraße 31a, 13189 Berlin, Germany
Phone: +49 30 44719759
E-mail: info@implisense.com
Represented by the Managing Directors Dr. Andreas Schäfer and Dr. André Bergholz. Further details in our legal notice.
3. Processing at a glance
| Purpose | Data | Legal basis |
|---|---|---|
| Account and sign-in | name, e-mail address, sign-in times | Art. 6(1)(b) GDPR |
| Organisation, licence, credits | company name, billing address, VAT ID, payment status | Art. 6(1)(b) and (c) GDPR |
| Use of the research features | searches, company profiles opened, lists, notes, credit entries | Art. 6(1)(b) GDPR |
| Product analytics (section 5) | pseudonymous usage events | Art. 6(1)(f) GDPR |
| Customer outreach (section 9) | activity metrics of the organisation, contact address | Art. 6(1)(f) GDPR |
| Audience measurement (section 10) | anonymous page views | Art. 6(1)(f) GDPR |
| Operation and security | server logs | Art. 6(1)(f) GDPR |
4. Account, organisation and billing
Sign-in
User accounts are managed by Clerk. Registration collects your e-mail address, first and last name and the sign-in method you chose; if you accept our terms and this notice during registration, the time of that acceptance is stored as well. Our own database keeps a copy of name, e-mail address and the time of the last sign-in. Passwords never reach our systems.
Payment
Payments — the Plus licence and credit top-ups — are handled by Stripe. Payment data, card details in particular, are collected and processed by Stripe and never reach our servers. We store the billing address, the VAT identification number, the Stripe customer number and the status of the licence.
Abandoned payments
If someone starts a purchase and does not complete it, we record that a purchase was started and not completed, with the time and the organisation. We use this solely to find obstacles in the checkout and delete these records automatically after 90 days. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a working checkout.
5. Product analytics in the signed-in area
To understand which features of the platform are used and where they fail, we record a limited, conclusively defined list of events in the signed-in area: running a search, opening a company profile, meeting a paywall, running out of credits, and creating or editing lists, notes and uploads. For each event we store the time, the user account, the organisation, the name of the event and a few technical details.
We do not store search terms. All that is derived from the search text is a classification into one of a few categories — such as “hit”, “no hit”, “person”, “foreign” or “too short”. The text you entered is not stored.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is designing and debugging our own product. There is no advertising profiling, no cross-site tracking and no disclosure to third parties.
Retention 90 days. After that the individual events are deleted automatically; only aggregated figures without any personal reference remain. You may object to this processing at any time under Art. 21(1) GDPR — an informal e-mail is enough.
6. History of companies you viewed
We store the company profiles you opened most recently against your account so that you can find them again. The history is visible only to you. Under Settings → Profile you can pause it and delete it entirely at any time.
7. Research in company data
When you use the platform we retrieve data on German companies from our own database. That data comes from public sources — the commercial and company registers, the Bundesanzeiger and company websites among them — and contains personal data of directors and shareholders. We process it on the basis of Art. 6(1)(f) GDPR; the legitimate interest is economic information about companies and who represents them, which is the very purpose the legislator pursues with register publicity. Separate information of the data subjects under Art. 14 GDPR is dispensable under Art. 14(5)(b) GDPR where it would involve disproportionate effort; data subjects receive information on request to info@implisense.com and may object to the processing.
Uploaded lists
When you upload a table for matching, the file is processed in memory only and never stored. Columns that map to no search field are discarded immediately. Only the companies you then add to a list are stored permanently.
Shareholder lists
When you order a shareholder list, we instruct a retrieval service we operate ourselves to fetch it from the register portal. Only the details of the company sought are transmitted, no data about you.
8. AI-assisted features
Three features of the platform put a language model by OpenAI to work. Your identity is never transmitted — no name, no e-mail address, no account or organisation identifier. What is transmitted differs by feature:
| Feature | What is transmitted | Web search |
|---|---|---|
| Summary of a list | only figures about your list (count, industries, size classes, legal forms, federal states, founding decades) — no company names | no |
| News overview for a company | public master data of the company | yes |
| Contact research for a company | master data of the company plus the names and roles of known directors, with the task of finding publicly available business contact details | yes |
Contact research is therefore processing of third parties’ personal data: names of directors are transmitted to OpenAI, and the result may contain business phone numbers, e-mail addresses and profiles on professional networks. The legal basis is Art. 6(1)(f) GDPR; our customers’ legitimate interest is getting in touch with a business. Only business contact details are sought, never private ones. Data subjects may object at info@implisense.com. The data is not used to train models.
9. Customer outreach
At regular intervals we evaluate how intensively an organisation uses the platform — as a figure over the past 28 days, without individual events. On that basis we choose which customers to approach, for instance with a pointer to a feature or with the question what is getting in the way. We record who was approached, through which channel, and whether the message arrived; part of the selected organisations is deliberately not approached, so that we can tell whether an approach achieves anything at all.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is supporting existing customers and improving the product. You may object at any time under Art. 21(2) GDPR; you will then receive no further messages of this kind. An informal e-mail is enough.
10. Audience measurement
We count page views with Umami, which we run on our own infrastructure at umami.implisense.com. It sets no cookies, stores no IP addresses and builds no cross-device identifiers; the data never leaves our infrastructure. The legal basis is Art. 6(1)(f) GDPR.
Alongside page views we count anonymous interaction events there: that a button was pressed, a filter opened, a dialogue abandoned or a step of a wizard reached. Only the name of the event and a few fixed details about it are transmitted — which button it was, which step, and whether the access is a free or a paid one. No personal reference and no free text: neither your account nor your email address, nor any search terms or company names you typed, are sent with it. No cookies are set for this either.
11. Cookies and local storage
The platform sets two cookies, both technically necessary:
- a session cookie from Clerk that carries your sign-in for the duration of the session — without it there could be no signed-in area;
- a language cookie that remembers whether you use the platform in German or English.
In addition, some features keep intermediate results in the memory of your browser tab so that an analysis already computed need not be fetched again when you navigate back. That storage is cleared when the tab is closed.
All three fall under § 25(2) no. 2 TDDDG: they are strictly necessary for the service you expressly requested. We therefore ask for no consent and show no cookie banner. We set no advertising or tracking cookies, neither our own nor those of others.
12. Server logs
When the platform is accessed, our ingress server processes the IP address, the time, the address requested, the status code and the browser identification in order to keep the service running and to detect abuse. The legal basis is Art. 6(1)(f) GDPR. The logs are used for that purpose only, are not combined with other data and are deleted automatically.
13. Recipients and transfers to third countries
| Service | Purpose | Provider and location |
|---|---|---|
| Clerk | user accounts, sign-in | Clerk, Inc., USA |
| Stripe | payment processing | Stripe Payments Europe Ltd., Ireland |
| Neon | database | Neon, data centre Frankfurt am Main |
| OpenAI | AI features (section 8) | OpenAI Ireland Ltd., Ireland |
| Hosting | operation of the platform | Hetzner Online GmbH, Germany |
Data processing agreements under Art. 28 GDPR are in place with all of the providers named. Clerk involves a transfer to the USA, safeguarded by the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR. Umami, our shareholder-list retrieval service and our company database run on our own infrastructure; no transfer to third parties takes place there. The platform’s fonts are served from our own servers — there is no connection to a third-party font service.
14. Retention periods
| Data | Period |
|---|---|
| Account and organisation data | until the account is deleted |
| Usage events (product analytics) | 90 days |
| Abandoned payments | 90 days |
| History of companies viewed | until you delete it, or the account is deleted |
| Lists and notes | until you delete them, or the account is deleted |
| Credit and invoice data | statutory retention periods (§ 147 AO, § 257 HGB) |
15. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). The right to object covers the product analytics in section 5, the customer outreach in section 9 and the audience measurement in section 10 in particular.
You can delete the history of companies you viewed yourself (section 6). To delete your account and all remaining data stored about you, an informal message to info@implisense.com is enough; we act on it without undue delay.
You may also lodge a complaint with a supervisory authority. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin, Germany.
16. What we do not do
We do not sell usage data, we build no advertising profiles, we set no third-party advertising or tracking cookies, and we do not follow you across other websites.