Privacy Policy

1. Data Controller

The party responsible for data processing on this website is:

Linus-Alexander Steinert
Neuhäuser Straße 66
33102 Paderborn, Germany
Email: info@immonote.app

2. Types of Data Processed

No personal data is collected via forms when simply visiting this website. Personal data is only processed when you use the account area (sign-in and subscription management, see sections 4–6). Apart from that, the following data is processed:

Automatically collected data

When visiting this website, technical access data is automatically collected by the hosting provider (Firebase Hosting), including IP address, browser type, operating system, and time of access. This is technically necessary to deliver the website. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in delivering the website).

3. Hosting (Google Firebase)

This website is hosted via Firebase Hosting, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). When accessing the website, a connection to Google's servers is established, during which technical data (in particular the IP address) is transmitted. This is necessary to deliver the website. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in reliable website delivery).

Data Processing Agreement

We have concluded a Data Processing Agreement (DPA) with Google pursuant to Art. 28 GDPR (Google Cloud Data Processing Addendum).

Data transfers to the USA

Google may transfer data to the USA. Google LLC is certified under the EU-US Data Privacy Framework, which is intended to ensure an adequate level of data protection pursuant to Art. 45 GDPR. For more information, see policies.google.com/privacy.

4. Account Area: Registration and Sign-in (Firebase Authentication)

On this website you can create an ImmoNote account and sign in to manage your subscription. We use Firebase Authentication, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). The data processed includes your email address, your password (encrypted only), your user ID and technical data (IP address, time of sign-in). During registration, your name, company name and optionally phone number and company address are also collected; to confirm your email address we send you a verification code, which is deleted after at most 5 minutes.

The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract for the ImmoNote services). The same Data Processing Agreement with Google applies as described in section 3.

5. Subscription Management (Cloud Firestore)

After signing in, the account area displays information about your company and your subscription (e.g. plan, subscription status, billing period). This data is read from the cloud database of the ImmoNote app (Google Cloud Firestore, EU region Frankfurt); the details in the ImmoNote app privacy policy below apply. The legal basis is Art. 6(1)(b) GDPR (performance of contract).

6. Payment Processing (Stripe)

We use the payment service provider Stripe to conclude and process paid subscriptions. The provider for customers in the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe"). During checkout and in the Stripe customer portal you are redirected to pages operated by Stripe.

Stripe processes in particular: name, email address, billing address, payment details (e.g. card details or bank account for SEPA direct debit), amount and time of the transaction, and technical data. Your full payment details are processed exclusively by Stripe and never reach us; we only receive information about the status of your subscription and truncated details (e.g. card type and last digits).

The legal basis is Art. 6(1)(b) GDPR (performance of contract and pre-contractual measures) and Art. 6(1)(c) GDPR with regard to statutory retention obligations under commercial and tax law. Stripe may also transfer data to Stripe, Inc. in the USA; Stripe is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). For more information, see the Stripe Privacy Policy.

7. Local Storage in Your Browser

This website does not use cookies or tracking technologies for advertising or analytics purposes. When you sign in to the account area, Firebase Authentication stores your session information locally in your browser (localStorage/IndexedDB) so that you stay signed in. This storage is technically necessary for the service you requested (Section 25(2) no. 2 of the German TDDDG) and does not require consent. The data remains on your device until you sign out or clear your browser's site data.

8. Data Security

Data transmission between your browser and our servers is encrypted via SSL/TLS. However, we note that data transmission over the internet may generally have security vulnerabilities. Complete protection of data against third-party access is not possible.

9. Storage Duration

The automatically collected technical access data is processed by Firebase Hosting in accordance with Google's policies and is not permanently stored by us. We have no control over the exact retention period of server log data at Google. For more information, see the Firebase Privacy Policy.

Billing and invoice data related to paid subscriptions is retained by us or by Stripe for as long as statutory retention obligations exist (generally up to ten years under German tax and commercial law, Section 147 AO, Section 257 HGB).

10. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) – information about your stored data
  • Right to rectification (Art. 16 GDPR) – correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) – deletion of your data
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to object (Art. 21 GDPR) – object to the processing of your data based on legitimate interests

To exercise your rights, please contact: info@immonote.app

11. Right to Lodge a Complaint with a Supervisory Authority

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent supervisory authority for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf, Germany
www.ldi.nrw.de

Privacy Policy – ImmoNote App

Applies to the iOS and Android app "ImmoNote"

1. Data Controller

Linus-Alexander Steinert
Email: info@immonote.app

2. What Data Is Collected?

Authentication data

  • Email address (registration and login)
  • User ID (automatically generated)

Protocol data

  • Personal data (names, addresses, contact details of tenants and inspectors)
  • Bank data (IBAN/BIC) – if voluntarily provided
  • Signatures of the parties involved
  • Property data (address, apartment number)
  • Room descriptions, photos, and condition information
  • Meter readings and key information

Company data

  • Company name, address, email, logo

Usage data

  • Login timestamps (for security and analysis)

3. Special Categories of Personal Data

Signatures qualify as biometric data within the meaning of Art. 9 GDPR and are treated as a special category of personal data. Processing is based solely on your explicit consent (Art. 9(2)(a) GDPR). You may withdraw this consent at any time. Signatures are used exclusively to document the handover report and are stored within the EU.

4. Purpose of Data Processing

  • Creation, storage, and management of handover reports
  • Secure login and access control
  • PDF generation of printable reports
  • Cloud-based storage for cross-device use
  • Email delivery of reports to involved parties
  • Address auto-completion during data entry

5. Legal Basis

Art. 6(1)(b) GDPR (Contract performance)
Provision of app services, creation of reports, email delivery.

Art. 6(1)(a) GDPR (Consent)
Collection of photos, signatures, and optional bank data (IBAN/BIC).

Art. 6(1)(f) GDPR (Legitimate interest)
Login tracking for security, address auto-completion.

Art. 9(2)(a) GDPR (Explicit consent)
Processing of biometric data (signatures).

6. Data Storage and Security

Storage location

All data is stored on Google Firebase servers (Cloud Firestore and Firebase Storage) in the EU region (eur3/Frankfurt). Cloud Functions run in the europe-west1 region.

Security measures

  • Encrypted data transmission (TLS/SSL)
  • Server-side encryption by Google Firebase
  • Company-based access control (data isolation between organizations)
  • User-based authentication via Firebase Auth
  • Role-based permissions

Retention periods

  • Protocol data: Until you delete it
  • Account data: Until account deletion
  • Login history: 90 days
  • Signature tokens: 15 minutes (automatic deletion)

7. Data Sharing

Your data is only shared with the following recipients:

Google Firebase (Google Ireland Ltd.)

As technical service provider for cloud infrastructure, authentication, and data storage. Data location: EU (Frankfurt). Firebase Privacy Policy

Komoot GmbH (Photon API)

For address auto-completion, search terms are transmitted to photon.komoot.io. Komoot is headquartered in Berlin, Germany.

Email recipients

When sending reports by email, the recipients you specify receive a PDF version of the report. Each recipient only receives the data relevant to them.

No further disclosure to third parties takes place unless we are legally obliged to do so.

8. No Transfers to Third Countries

Your data is stored and processed exclusively on EU servers of Google Firebase (region eur3/Frankfurt). Cloud Functions run in the europe-west1 region.

For postal code validation, the service zippopotam.us is used. Only postal codes (no personal data) are transmitted to this service.

9. Camera and Photo Library

The app optionally requires access to:

  • Camera: To photograph rooms, keys, and meters
  • Photo library: To select existing images

These permissions are only used when you explicitly want to add photos to reports. Photos are only stored in the cloud when you save a report.

10. Your Rights

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR) – You can delete individual reports directly in the app. For complete account deletion, please contact us.
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR) – at any time with effect for the future

To exercise your rights, please contact: info@immonote.app

11. No Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

12. Children

This app is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you discover that a child has submitted personal data to us, please contact us.

13. Changes to This Privacy Policy

We reserve the right to update this privacy policy. The current version is always available in the app under Settings and on this website.