Legal Information
Privacy Policy
How SpreeHavel Digital Solutions UG handles your personal data on this website.
The statutory provisions on the protection of your data can be found in the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). Below we inform you which personal data – i.e. all data that identifies you or makes you identifiable, such as name, address, email address or usage behaviour – we collect during your visit to this website and how it is used.
1. Responsible Party
The party responsible within the meaning of data protection law is:
SpreeHavel Digital Solutions UG (haftungsbeschränkt)
c/o Reaktor Wildau
Schmiedestraße 2a
15745 Wildau, Germany
Phone: +49 173 2700423
Email: hey@spreehavel.com
Represented by: Heiko Armando Guksch
For any questions about data protection, you can reach us at hey@spreehavel.com.
2. Hosting and Server Logs
Our website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA ("Vercel"). Vercel is certified under the EU-US Data Privacy Framework. We have concluded a data processing agreement with Vercel.
When you visit our site, various server statistics that your browser transmits to our provider's server are stored automatically:
- IP address
- Browser type and version
- Operating system
- Referrer URL
- Time of access
- Pages visited
These data serve the statistical evaluation of visits to our site and cannot be attributed by us to specific persons. The IP address is anonymised; the data are not combined with other data sources. Server logs are deleted after 30 days.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in optimising our offering, preventing access from malicious sites and technically enabling delivery of the site.
3. Security of Data Transmission
We use a secure server with SSL technology (Secure Socket Layer) with 256-bit encryption to transmit your data. This means your data are transmitted to us securely and unreadable for unauthorised parties.
4. Transfers to Third Countries
In the course of accessing and using our website, data may be transferred to third countries via subcontractors or companies affiliated with them. Potential risks include unenforceable data-subject rights and a lower level of data protection. By concluding data processing agreements and standard contractual clauses, including effective supplements required by the supervisory authorities, we minimise the risk as far as possible. Transfers to the USA take place on the basis of the EU-US Data Privacy Framework (Art. 44 et seq. GDPR).
5. Cookies and Consent
Our website uses cookies. A cookie is a piece of text that our website places on your device via the web browser. Most of the cookies we use are "session cookies" that are deleted automatically at the end of your visit. Our cookie consent tool additionally sets a cookie that stores your consent choices so you do not have to repeat them on future visits. We only use analytics cookies with your consent (see section 9).
Legal basis: For technically necessary cookies Art. 6 (1) (f) GDPR — they are required for the operation of the website and no tracking data are collected.
6. Contact, Demo and Consultation Requests
When you request a demo or consultation through our forms or contact us by email, we collect and store your email address, company, position/role, the competitors you name (optional), your phone number (optional) and the text you enter, for the purpose of answering your request. Form data is stored in our database at Supabase (see section 12) and delivered to us by email through the service Resend (see section 12). We only use a phone number you have provided voluntarily, to call you back about your request.
Legal basis: If a contractual relationship develops from the request or the request relates to an existing one, the legal basis is Art. 6 (1) (b) GDPR. We also have a legitimate interest under Art. 6 (1) (f) GDPR in processing the data for the purpose of communication and answering your requests.
Retention: Deletion takes place 12 months after the last interaction or after the request has been dealt with, with an additional archiving period of 6 months. In the case of a contractual relationship, the statutory retention periods apply.
Market report downloads (e.g. the Q4 guide): When you request a market report through our forms, we collect your name, email address, company, role and, optionally, your phone number. With your consent (Art. 6 (1) (a) GDPR) we send you the report and further market reports by email, add you to our newsletter tool Brevo for this purpose (see section 8) and may contact you about the report you requested. You can withdraw your consent at any time with effect for the future, for example via the unsubscribe link in every email or by writing to hello@reyo.ai.
Abuse protection: To prevent automated submissions and misuse of our forms, we process a hidden control field, the time between opening and submitting the form, and your IP address in a shortened, hashed (pseudonymised) form that we evaluate briefly to limit the number of requests per period. We also check via a DNS query whether the domain of your email address can receive mail and compare it against a list of known disposable email providers; only the domain part, never your full address, is transmitted for this. The legal basis is our legitimate interest in the security and proper functioning of our forms (Art. 6 (1) (f) GDPR).
7. Job Applications
When you apply through our careers page, we collect your name and email address, your LinkedIn profile, and the job ID and title. These data are processed solely to evaluate your application and are deleted 6 months after the application process is completed.
Legal basis: Pre-contractual measures according to Art. 6 (1) (b) GDPR, Sec. 26 BDSG.
8. Newsletter (Brevo)
Our newsletter keeps you informed about product updates, best practices for marketing analytics, industry trends and usage tips. To sign up we require a valid email address. We send you a confirmation email (double opt-in) to verify your sign-up. For legally compliant proof, we store the IP address at sign-up and at activation of the confirmation link, together with the date and time of both events.
We use the newsletter tool "Brevo" of Brevo GmbH (formerly Sendinblue GmbH), Köpenicker Straße 126, 10179 Berlin, Germany. An invisible graphic is embedded in the newsletter to track open rates; to measure click rates, links are routed via a tracking domain of the provider. We have concluded a data processing agreement with Brevo. Details on how Brevo stores and processes data can be found in Brevo's privacy policy.
You can unsubscribe at any time via the link at the end of every newsletter or by emailing hey@spreehavel.com. The data are deleted immediately after you unsubscribe.
Legal basis: Your express consent, Art. 6 (1) (a) GDPR, Sec. 25 (1) TDDDG; conditions for consent and its withdrawal: Art. 7 GDPR.
9. Web Analytics
PostHog (EU Cloud)
We use the analytics tool PostHog in its EU cloud variant to analyse usage behaviour on our website. The provider is PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. When using the EU cloud, the data are processed and stored exclusively on servers within the European Union (Frankfurt am Main, Germany); no transfer of the analytics data to the USA takes place. We have concluded a data processing agreement with PostHog.
With your consent, PostHog collects, among other things, pages visited, clicks and interactions, device and browser information, the referrer URL and a pseudonymous user ID. The data serve exclusively the statistical evaluation and improvement of our online offering; they are not combined with other data sources or passed on to third parties.
Legal basis: Your consent, Art. 6 (1) (a) GDPR, Sec. 25 (1) TDDDG, given via our cookie consent tool. You can withdraw your consent at any time with effect for the future via the cookie settings in the footer.
Vercel Web Analytics
We use Vercel Web Analytics by Vercel Inc. (address see section 2) to measure website reach. The tool is only loaded after you have consented to analytics cookies via our cookie consent tool; it does not set cookies and does not recognise visitors across sites.
Data that may be collected includes:
- Page views and navigation patterns
- User interactions (clicks, form submissions)
- Device and browser information
- Anonymous user identifiers
Legal basis: Your consent according to Art. 6 (1) (a) GDPR, Sec. 25 (1) TDDDG. You can withdraw your consent at any time via the cookie settings in the footer.
10. Embedded Third-Party Content (Two-Click Solution)
In two places we embed content served from other companies' servers. Both work the same way: when the page loads you only see a preview image hosted by us, and no data are sent to the provider. The connection is established only once you start playback by clicking.
If you allowed the "External media" category in the cookie banner, that single click is enough. If you declined it or have not decided yet, we ask again explicitly before loading and name who receives the data. Loading through that prompt applies to the single item only and does not change your stored decision.
Spotify (podcast)
On our podcast page we embed individual episodes via the Spotify embed player (Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden). Only when you activate the player by clicking it is a connection to Spotify established; Spotify then receives, among other things, your IP address and may set its own cookies. If you are logged in to Spotify, Spotify can attribute the playback to your account. For details, see Spotify's privacy policy.
YouTube (demo video)
On our demo page we embed a product video via YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We use the extended privacy mode (youtube-nocookie.com), in which YouTube sets cookies only on playback. Here too the video loads only after your click; before that, no request from you reaches YouTube. On start, YouTube receives among other things your IP address and information about your browser. If you are logged in to Google, Google can attribute the playback to your account. A transfer to the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework. For details, see Google's privacy policy.
Legal basis: Your consent given by actively clicking, Art. 6 (1) (a) GDPR, Sec. 25 (1) TDDDG.
11. Our Social Media Profiles
We operate company profiles on the platforms listed below. If you open a profile via the icons on our website while logged in to the respective platform, the provider can attribute the visit to your account. If you do not want this, log out of the platform before opening the profile. When you use interactive features (liking, commenting, sharing, following), you are identifiable to the provider as a user. As operators of the profiles, we do not collect or process any further data.
- LinkedIn — LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
- Instagram — Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (Meta Platforms Inc. is certified under the EU-US Data Privacy Framework)
- TikTok — TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland
- YouTube — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Spotify (podcast "360 Marketing & CRM") — Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden
For details, please refer to the privacy policies of the respective providers.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in enabling a direct exchange with customers and interested parties – including for complaints – via these services and in providing content that may be of interest to you.
12. Third-Party Services
Supabase
We use Supabase (Supabase Inc., 3500 S Dupont Hwy, Dover, DE 19901, USA) for data storage and processing, for example for requests submitted via forms. The server location is Frankfurt am Main, Germany; no third-country transfer of the content data takes place. We have concluded a data processing agreement with Supabase. Further information can be found in Supabase's privacy policy.
Resend
To send us notification emails about incoming form requests we use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). The data you entered in the form is processed in the notification to our mailbox. We have concluded a data processing agreement with Resend; the transfer to the USA is based on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR). Further information can be found in Resend's privacy policy.
13. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Employee training on data protection
14. Retention Periods
We retain your personal data only for as long as necessary for the purposes for which we collected it, including compliance with statutory retention obligations.
- Server logs: 30 days
- Newsletter subscriptions: until you unsubscribe
- Contact, demo and consultation requests: 12 months after the last interaction (+ 6 months archive) or statutory periods in the case of a contractual relationship
- Market report requests: until consent is withdrawn, at most 24 months after the last interaction
- Pseudonymised IP address from the form abuse protection: 30 days
- Job applications: 6 months after completion of the application process
- Analytics data: according to the analytics provider's retention policy
15. Your Rights under the GDPR
- Right of access (Art. 15 GDPR): You have the right to request information about the personal data we process and copies of these data.
- Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate data or the completion of incomplete data.
- Right to erasure (Art. 17 GDPR): You can request the immediate deletion of your data if one of the grounds stated there applies.
- Right to restriction of processing (Art. 18 GDPR): You can request the restriction of processing if one of the conditions stated there is met.
- Right to data portability (Art. 20 GDPR): You can request to receive the data you provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you can object for reasons arising from your particular situation. If you object to processing for direct marketing purposes, we will no longer process your data for that purpose.
- Right to withdraw consent (Art. 7 (3) GDPR): You can withdraw any consent given at any time with effect for the future; the lawfulness of processing carried out before the withdrawal remains unaffected.
To exercise any of these rights, please contact us at hey@spreehavel.com.
Right to lodge a complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority, e.g. the State Commissioner for Data Protection and Access to Information of Brandenburg, Germany.
16. Contact for Privacy Questions
SpreeHavel Digital Solutions UG (haftungsbeschränkt)
c/o Reaktor Wildau
Schmiedestraße 2a
15745 Wildau, Germany
Email: hey@spreehavel.com
Phone: +49 173 2700423
Last updated: September 2026