Zuletzt aktualisiert: 06. Dezember 2024 • Version 2.0
RightMoney ("us", "we", or "our") operates the RightMoney platform and provides AI-powered business management tools (the "Service").
This privacy policy informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
1Definitions
- Service: The RightMoney platform and AI-powered tools operated by RightMoney.
- Personal Data: Data about a living individual who can be identified from those data.
- Usage Data: Data automatically collected generated by the use of the Service.
- Cookies: Small files stored on your device.
- Data Controller: We are a Data Controller of your Personal Data.
- Data Processor: Service providers who process data on our behalf.
- Data Subject: Any living individual who is the subject of Personal Data.
2GDPR Principles
We commit to processing Personal Data in compliance with the General Data Protection Regulation (GDPR) principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
3Information We Collect
✓ Consent-Based Collection
We collect data only with your explicit consent. You control what data we process through opt-in mechanisms during registration and in your privacy settings.
3.1 Personal Data (Opt-In Required)
- Email address (required for account creation)
- Full name (required for account creation)
- Phone number (optional - you choose whether to provide)
- Business information (optional - only if you create a business profile)
- Profile data (optional - you control what to add)
3.2 Business Data (User-Controlled)
Your Choice: Business data is only collected when you actively upload or create it. You maintain full control.
- Financial records (invoices, expenses) - only data you upload
- Documents and contracts - only files you choose to upload
- Business communications - only messages you send
- AI chat conversations - only when you use AI features
3.3 Usage Data (Anonymized)
Privacy Protection: Usage data is anonymized before processing. We cannot identify you from this data.
- IP address (anonymized - last octet removed, e.g., 192.168.1.xxx)
- Browser type and version (aggregated, non-identifying)
- Pages visited and features used (anonymized session data)
- Timestamps and session duration (no user identification)
3.4 Cookies and Tracking (Consent Required)
We use cookies only with your explicit consent:
- Essential Cookies: Required for authentication and core functionality (cannot be disabled)
- Functional Cookies: Remember preferences (opt-in via cookie banner)
- Analytics Cookies: Help us improve the service (opt-in via cookie banner)
You can withdraw cookie consent at any time through the cookie settings in your account.
4Legal Basis for Processing (GDPR)
- Contract Performance (Art. 6(1)(b) GDPR): To provide and maintain the Service
- Consent (Art. 6(1)(a) GDPR): For AI analysis, marketing communications, and analytics
- Legal Obligation (Art. 6(1)(c) GDPR): Tax and commercial law compliance (up to 10 years retention)
- Legitimate Interest (Art. 6(1)(f) GDPR): Security, fraud prevention, service improvement
5How We Use Your Data
Data Minimization Principle
We only process data that is necessary for the specific purpose you consented to. We do not process data for purposes beyond what you agreed to.
Essential Service Provision (No Consent Needed - Contract Fulfillment)
- Provide and maintain your account and the Service
- Send account notifications and critical service updates
- Provide customer support when requested
- Detect and prevent fraud and security issues
AI Features (Explicit Opt-In Required)
- AI-powered legal, tax, and business analysis (only when you use AI features)
- Generate business insights and recommendations (only with consent)
- Document analysis and automation (only for documents you upload)
✓ You can enable/disable AI processing in your Privacy Settings at any time
Analytics & Improvement (Opt-In Required)
- Monitor usage patterns to improve the Service (anonymized data only)
- Conduct product research and development
✓ Analytics can be disabled in Privacy Settings
Legal Compliance (Legal Obligation)
- Compliance and regulatory reporting as required by law
- Tax and commercial law documentation retention (up to 10 years)
6Data Sharing and Third Parties
We share data only with:
6.1 Service Providers
- OpenAI: AI analysis (Data Processing Agreement in place)
- Supabase: Data storage in EU (GDPR compliant)
6.2 Legal Requirements
When required by law, court order, or to protect rights and safety.
7Data Retention
- Account data: Until account deletion
- Business documents: Per legal retention requirements (up to 10 years for tax/commercial law)
- Usage logs: 30 days
- AI chat history: Until deletion or 2 years of inactivity
8Your GDPR Rights
You have the right to:
Right to Access (Art. 15 GDPR)
Request a copy of your personal data
Right to Rectification (Art. 16 GDPR)
Correct inaccurate or incomplete data
Right to Erasure (Art. 17 GDPR)
"Right to be forgotten" - request deletion
Right to Restriction (Art. 18 GDPR)
Limit processing of your data
Right to Data Portability (Art. 20 GDPR)
Receive data in structured, machine-readable format
Right to Object (Art. 21 GDPR)
Object to processing of your data
Right to Withdraw Consent (Art. 7(3) GDPR)
Withdraw consent at any time
Exercise your rights: Visit the GDPR Compliance Center or email privacy@rightmoney.de
9Data Security & Anonymization
9.1 Security Measures
We implement industry-leading security measures:
- SSL/TLS encryption for all data transmission
- AES-256 encryption for sensitive data at rest
- Multi-factor authentication (MFA) available
- Access controls and role-based permissions
- Regular security audits and penetration testing
- SOC 2 Type II certified infrastructure
- 24/7 security monitoring and incident response
9.2 Data Anonymization Practices
Privacy by Design
We anonymize data wherever possible to protect your privacy. Anonymized data cannot be traced back to you.
- IP Address Anonymization: Last octet removed before storage (e.g., 192.168.1.xxx)
- Usage Analytics: All analytics data is aggregated and anonymized - no individual tracking
- Session Data: Session IDs are hashed and rotated; cannot be linked to individual users
- Error Logs: Personal data is automatically redacted from system logs
- Research Data: Any data used for research is fully anonymized and aggregated
9.3 Data Breach Protocol
In the unlikely event of a data breach:
- We will notify affected users within 72 hours as required by GDPR
- We will notify relevant supervisory authorities
- We will provide details of the breach and remediation steps
- We will offer identity protection services if applicable
Note: No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. We continuously improve our security measures to provide the highest level of protection.
10International Data Transfers
Your data is primarily stored in EU data centers. When data is transferred outside the EU, we ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements with all processors
- Compliance with GDPR requirements for third-country transfers
11Cookies and Tracking
We use three types of cookies:
- Necessary Cookies: Required for authentication and core functionality
- Functional Cookies: Remember preferences and settings
- Analytics Cookies: Understand usage patterns (requires consent)
You can manage cookie preferences through our cookie consent banner or browser settings.
12Children's Privacy
Our Service is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If we become aware of such collection, we will take steps to delete the information.
13Changes to This Privacy Policy
We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via:
- Email notification to your registered address
- Prominent notice on the platform
- In-app dialog requiring re-acceptance
The updated "Effective Date" will be shown at the top of this policy. Continued use after notification constitutes acceptance.
14Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority:
For Germany:
Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
Find all EU supervisory authorities: www.bfdi.bund.de
15Contact Information
For privacy-related inquiries or to exercise your rights: