Privacy Policy
Last updated: 22 August 2026
1. Who is responsible
This person is responsible for the processing described here:
Tommy FrieseRosenthaler Weg 17C
13127 Berlin
Germany
Write to privacy@achordia.com about anything in this policy. Write to legal@achordia.com about other legal matters. You can also use our contact form.
2. Data protection officer
We have not appointed a data protection officer. We do not have to appoint one.
Article 37 GDPR requires one for large-scale monitoring. It also requires one for large-scale processing of special categories of data. We do neither. Section 38 BDSG requires one when at least 20 people work regularly on automated processing of personal data. We have no employees.
Write to privacy@achordia.com. You reach the person responsible directly.
3. What this policy covers, and what it does not
This policy covers your visit to this website. It covers the pages you are reading now and the contact routes on them.
It does not cover the Achordia application. A customer enters content into the product. We process that content on the instructions of that customer, under a separate agreement. There we act as a processor, not as the controller.
A second part of this policy will describe that processing. We will publish it before the product opens to external customers.
If you are an employee of a customer, ask your employer what happens to your workspace data. Your employer decides it, and we do not.
4. Visiting this website
Firebase Hosting serves this site. Firebase Hosting is a service of Google.
To send you a page, the Google infrastructure must process the technical data that your browser sends. That data is your IP address, the time of the request, the page you asked for, and which browser you use.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to run a website that works and that nobody abuses.
We keep no log of these page visits. Reading a page here leaves no access log in our systems. We therefore hold no record of who read which page, or when. Sending the contact form is different, because it reaches a server of ours. Section 5 explains what that records.
Google keeps its own operational logs of the infrastructure that it runs. Our data processing terms with Google cover those logs. We do not receive them and we do not control them.
5. Contacting us
If you use the contact form, we process the name, the email address and the message that you enter. If you write to us by email, we process what your message contains. That includes your address and any signature.
We use this only to read your enquiry and to answer it.
If your message concerns a possible business relationship, the legal basis is Article 6(1)(b) GDPR. Otherwise the basis is Article 6(1)(f). Our legitimate interest is to answer people who write to us.
No law and no contract requires you to give us this data. But we cannot reply without an address to reply to.
We keep contact enquiries for 12 months. Then we delete them. We keep one longer only in two cases. The exchange has become part of an ongoing matter, or a law requires us to keep it.
When you send the form, your browser makes a request to a server of ours. A technical request log in our cloud project keeps that request for 30 days. The entry includes an IP address. This is ordinary infrastructure logging, and we do not read it in normal operation.
Our server also writes short technical notes about each submission, for example that a message went out or that an automated check blocked it. These notes contain a shortened form of your email address. We delete them after 30 days.
We also stop people from using the form for bulk or automated messages. To do that, we store two short-lived scrambled values. We make one from your email address and one from the network address of the request. We do not store either address itself in these records. We use the values only to count the messages from one source in the last hour. The system then deletes them automatically.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to keep a public form usable. There is no CAPTCHA, and we store nothing on your device.
Two processors help us with this. Both act only on our instructions.
- Microsoft operates the mailbox that receives your message. Microsoft holds the mailbox data in its German data region.
- Resend delivers messages from the contact form into that mailbox. Resend keeps a copy of the delivery for 30 days.
Section 8 explains what this means for transfers outside the EU.
6. Cookies, local storage and tracking
This website sets no cookies. It writes nothing to the local storage or the session storage of your device.
There is no analytics, no tracking, no advertising and no profiling. There is no third-party content of any kind. No web fonts, no maps, no embedded video, no external scripts. Every file that these pages load comes from this domain.
Your device stores nothing beyond what we need to send you the page you asked for. Section 25 TDDDG therefore requires no consent. There is no cookie banner to click away.
This describes how we built the site today. It is not a promise about the future. If this changes, we change this section first, before the change goes live.
7. No automated decision-making
We make no decisions about you by automated means, and we do not profile you. Article 22 GDPR is the relevant provision.
The contact form does use an automated check to block bulk and machine-generated submissions. That check decides one thing only: whether a single message goes through. It does not evaluate you, and you can always email us directly instead.
8. Transfers outside the EU
Sections 4 and 5 name three providers: Google, Microsoft and Resend. Each one has a parent company in the United States. That is true even where the data itself stays in Europe.
Microsoft holds the mailbox in its German region. Google serves this website from its worldwide network of servers. We cannot rule out access from outside the EU for support and maintenance.
We rely on the safeguards in Article 46 GDPR. The data processing terms that apply to these services include the Standard Contractual Clauses that the European Commission has approved. Some of these providers are also certified under the EU-US Data Privacy Framework. Where that applies, the framework covers the transfer as well.
We tell you one more thing, because no contract can remove it. Authorities in the United States have legal powers to demand data from companies based there. Standard Contractual Clauses cannot switch off that law. This is why we keep the data these providers can see as small as we can. We hold no visit log for this website. We delete contact enquiries after 12 months.
Write to privacy@achordia.com if you want to know which safeguard applies to a specific provider. We will tell you, and we will send you a copy of the relevant clauses.
9. Your rights
The GDPR gives you the right to:
- ask what data we hold about you, and get a copy of it (Article 15)
- have us correct data that is wrong (Article 16)
- have us erase data (Article 17)
- have us restrict processing (Article 18)
- receive your data in a portable form (Article 20)
- object to processing that we base on our legitimate interest, on grounds that relate to your situation (Article 21)
Write to privacy@achordia.com. We answer within one month. If a request is complex, we may take up to two more months. We will tell you inside the first month if we do. These rights cost you nothing.
10. Complaining to a supervisory authority
You can complain to a data protection supervisory authority about how we handle your data. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
You can also complain to the authority where you live, where you work, or where you believe the problem happened. The choice is yours.
11. Changes to this policy
We update this policy when what we do changes. The date at the top tells you which version you are reading.
We already expect two changes. A second part will cover the Achordia application. The controller will change when we incorporate the business, and a company will then replace the person named in section 1.