Privacy notice

As of 31 August 2026

1. Scope

This notice covers the Implisense Platform at app.implisense.com — the website, the signed-in area and the API reachable through it. Our marketing site implisense.com has its own privacy notice.

2. Controller

Implisense GmbH, Spiekermannstraße 31a, 13189 Berlin, Germany
Phone: +49 30 44719759
E-mail: info@implisense.com

Represented by the Managing Directors Dr. Andreas Schäfer and Dr. André Bergholz. Further details in our legal notice.

3. Processing at a glance

PurposeDataLegal basis
Account and sign-inname, e-mail address, sign-in timesArt. 6(1)(b) GDPR
Organisation, licence, creditscompany name, billing address, VAT ID, payment statusArt. 6(1)(b) and (c) GDPR
Use of the research featuressearches, company profiles opened, lists, notes, credit entriesArt. 6(1)(b) GDPR
Product analytics (section 5)pseudonymous usage eventsArt. 6(1)(f) GDPR
Customer outreach (section 9)activity metrics of the organisation, contact addressArt. 6(1)(f) GDPR
Audience measurement (section 10)anonymous page viewsArt. 6(1)(f) GDPR
Operation and securityserver logsArt. 6(1)(f) GDPR

4. Account, organisation and billing

Sign-in

User accounts are managed by Clerk. Registration collects your e-mail address, first and last name and the sign-in method you chose; if you accept our terms and this notice during registration, the time of that acceptance is stored as well. Our own database keeps a copy of name, e-mail address and the time of the last sign-in. Passwords never reach our systems.

Payment

Payments — the Plus licence and credit top-ups — are handled by Stripe. Payment data, card details in particular, are collected and processed by Stripe and never reach our servers. We store the billing address, the VAT identification number, the Stripe customer number and the status of the licence.

Abandoned payments

If someone starts a purchase and does not complete it, we record that a purchase was started and not completed, with the time and the organisation. We use this solely to find obstacles in the checkout and delete these records automatically after 90 days. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a working checkout.

5. Product analytics in the signed-in area

To understand which features of the platform are used and where they fail, we record a limited, conclusively defined list of events in the signed-in area: running a search, opening a company profile, meeting a paywall, running out of credits, and creating or editing lists, notes and uploads. For each event we store the time, the user account, the organisation, the name of the event and a few technical details.

We do not store search terms. All that is derived from the search text is a classification into one of a few categories — such as “hit”, “no hit”, “person”, “foreign” or “too short”. The text you entered is not stored.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is designing and debugging our own product. There is no advertising profiling, no cross-site tracking and no disclosure to third parties.

Retention 90 days. After that the individual events are deleted automatically; only aggregated figures without any personal reference remain. You may object to this processing at any time under Art. 21(1) GDPR — an informal e-mail is enough.

6. History of companies you viewed

We store the company profiles you opened most recently against your account so that you can find them again. The history is visible only to you. Under Settings → Profile you can pause it and delete it entirely at any time.

7. Research in company data

When you use the platform we retrieve data on German companies from our own database. That data comes from public sources — the commercial and company registers, the Bundesanzeiger and company websites among them — and contains personal data of directors and shareholders. We process it on the basis of Art. 6(1)(f) GDPR; the legitimate interest is economic information about companies and who represents them, which is the very purpose the legislator pursues with register publicity. Separate information of the data subjects under Art. 14 GDPR is dispensable under Art. 14(5)(b) GDPR where it would involve disproportionate effort; data subjects receive information on request to info@implisense.com and may object to the processing.

Uploaded lists

When you upload a table for matching, the file is processed in memory only and never stored. Columns that map to no search field are discarded immediately. Only the companies you then add to a list are stored permanently.

Shareholder lists

When you order a shareholder list, we instruct a retrieval service we operate ourselves to fetch it from the register portal. Only the details of the company sought are transmitted, no data about you.

8. AI-assisted features

Three features of the platform put a language model by OpenAI to work. Your identity is never transmitted — no name, no e-mail address, no account or organisation identifier. What is transmitted differs by feature:

FeatureWhat is transmittedWeb search
Summary of a listonly figures about your list (count, industries, size classes, legal forms, federal states, founding decades) — no company namesno
News overview for a companypublic master data of the companyyes
Contact research for a companymaster data of the company plus the names and roles of known directors, with the task of finding publicly available business contact detailsyes

Contact research is therefore processing of third parties’ personal data: names of directors are transmitted to OpenAI, and the result may contain business phone numbers, e-mail addresses and profiles on professional networks. The legal basis is Art. 6(1)(f) GDPR; our customers’ legitimate interest is getting in touch with a business. Only business contact details are sought, never private ones. Data subjects may object at info@implisense.com. The data is not used to train models.

9. Customer outreach

At regular intervals we evaluate how intensively an organisation uses the platform — as a figure over the past 28 days, without individual events. On that basis we choose which customers to approach, for instance with a pointer to a feature or with the question what is getting in the way. We record who was approached, through which channel, and whether the message arrived; part of the selected organisations is deliberately not approached, so that we can tell whether an approach achieves anything at all.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is supporting existing customers and improving the product. You may object at any time under Art. 21(2) GDPR; you will then receive no further messages of this kind. An informal e-mail is enough.

10. Audience measurement

We count page views with Umami, which we run on our own infrastructure at umami.implisense.com. It sets no cookies, stores no IP addresses and builds no cross-device identifiers; the data never leaves our infrastructure. The legal basis is Art. 6(1)(f) GDPR.

Alongside page views we count anonymous interaction events there: that a button was pressed, a filter opened, a dialogue abandoned or a step of a wizard reached. Only the name of the event and a few fixed details about it are transmitted — which button it was, which step, and whether the access is a free or a paid one. No personal reference and no free text: neither your account nor your email address, nor any search terms or company names you typed, are sent with it. No cookies are set for this either.

11. Cookies and local storage

The platform sets two cookies, both technically necessary:

  • a session cookie from Clerk that carries your sign-in for the duration of the session — without it there could be no signed-in area;
  • a language cookie that remembers whether you use the platform in German or English.

In addition, some features keep intermediate results in the memory of your browser tab so that an analysis already computed need not be fetched again when you navigate back. That storage is cleared when the tab is closed.

All three fall under § 25(2) no. 2 TDDDG: they are strictly necessary for the service you expressly requested. We therefore ask for no consent and show no cookie banner. We set no advertising or tracking cookies, neither our own nor those of others.

12. Server logs

When the platform is accessed, our ingress server processes the IP address, the time, the address requested, the status code and the browser identification in order to keep the service running and to detect abuse. The legal basis is Art. 6(1)(f) GDPR. The logs are used for that purpose only, are not combined with other data and are deleted automatically.

13. Recipients and transfers to third countries

ServicePurposeProvider and location
Clerkuser accounts, sign-inClerk, Inc., USA
Stripepayment processingStripe Payments Europe Ltd., Ireland
NeondatabaseNeon, data centre Frankfurt am Main
OpenAIAI features (section 8)OpenAI Ireland Ltd., Ireland
Hostingoperation of the platformHetzner Online GmbH, Germany

Data processing agreements under Art. 28 GDPR are in place with all of the providers named. Clerk involves a transfer to the USA, safeguarded by the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR. Umami, our shareholder-list retrieval service and our company database run on our own infrastructure; no transfer to third parties takes place there. The platform’s fonts are served from our own servers — there is no connection to a third-party font service.

14. Retention periods

DataPeriod
Account and organisation datauntil the account is deleted
Usage events (product analytics)90 days
Abandoned payments90 days
History of companies vieweduntil you delete it, or the account is deleted
Lists and notesuntil you delete them, or the account is deleted
Credit and invoice datastatutory retention periods (§ 147 AO, § 257 HGB)

15. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). The right to object covers the product analytics in section 5, the customer outreach in section 9 and the audience measurement in section 10 in particular.

You can delete the history of companies you viewed yourself (section 6). To delete your account and all remaining data stored about you, an informal message to info@implisense.com is enough; we act on it without undue delay.

You may also lodge a complaint with a supervisory authority. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin, Germany.

16. What we do not do

We do not sell usage data, we build no advertising profiles, we set no third-party advertising or tracking cookies, and we do not follow you across other websites.

Privacy notice | Implisense