Privacy Policy
Last updated 2026-06-24
This policy explains what personal data Benjamin Hellmich (getAdvantage)(“getAdvantage”, “we”) processes when you use getadvantage.app, why, the legal basis for each use, and the rights you have under the EU General Data Protection Regulation (GDPR). We aim to be precise and honest: getAdvantage measures how AI reads a website at the moment of a scan — the resulting scores are measurements, never guarantees.
Who is responsible
The data controller is Benjamin Hellmich (getAdvantage). Contact for any data request: legal@getadvantage.app. The full Impressum (§ 5 DDG) is at /impressum.
Deployment enquiries and letters of intent
If you request a deployment review, we collect your name, work email, company and any optional context you choose to include. We retain the wording of your non-binding letter of intent, your authority acknowledgement and the submission and email confirmation times. We use these details to verify your request, assess fit and follow up with you. Email confirmation establishes access to the mailbox, not independent proof of corporate signing authority.
Records are stored in our managed database and confirmation emails are delivered through Resend. Submitting an enquiry does not subscribe you to marketing or permit us to publish your company name. Please do not include confidential operational data. We retain enquiry records while considering and following up on your request, and remove them when no longer needed unless retention is legally required. To withdraw interest or request deletion, contact ben@getadvantage.app.
The optional AI use-case assistant sends the message you enter and any previous draft in the current session to OpenAI to generate a starting point for discussion. Your name, email and company fields are not sent to the assistant. We do not save the assistant conversation in our database. If you choose to send a deployment request, your last message is shown as optional context; you can remove it before submitting. Do not enter confidential, personal or safety-critical operational details.
Our on-site booking form uses Cal.com to check availability and reserve your meeting. Booking details are processed by Cal.com and the connected calendar and Google Meet services to arrange the call. You choose whether to provide details there. See Google’s privacy policy.
WhatsApp links open a direct chat with our founder through WhatsApp. No message is sent until you send it yourself. WhatsApp processes any details you share there under its own privacy terms.
What we collect and why
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account email & bcrypt-hashed password | Create, secure and operate your account | Contract — Art. 6(1)(b) |
| Email submitted to the report unlock (“email gate”) | Unlock your full report and, where you ask, email it to you | Consent — Art. 6(1)(a) |
| Feedback you submit in the in-app feedback widget (your message + an optional email) | Improve the product and, where you leave an email, reply to you | Consent — Art. 6(1)(a) |
| Sites/URLs you scan and the resulting scores | Provide the scan, history and benchmark features (facts observed on public pages) | Contract — Art. 6(1)(b) |
| Billing data (handled by Stripe — your card never touches our servers) | Process subscriptions and invoices | Contract — Art. 6(1)(b) |
| First-party, server-side funnel events (no cookie, no device storage, no PII in the event) | Understand and improve the product funnel | Legitimate interest — Art. 6(1)(f) (improving and securing the Service) |
The session cookie aboard_session (one cookie; a signed JWT carrying your account id + email) | Keep you logged in — strictly necessary, no tracking or ad cookies | Contract — Art. 6(1)(b) |
| Your client IP address (processed transiently in memory, never written to storage) | Rate-limiting and abuse/fraud prevention | Legitimate interest — Art. 6(1)(f) (preventing abuse and protecting the Service) |
We do not sell your data, run advertising trackers, or build cross-site profiles. We confirmed by code audit that the site loads no third-party trackers of any kind. Scan results contain only publicly-observable facts about the pages you submit.
Cookies and consent
We set exactly one cookie — aboard_session — which is strictly necessary to keep you logged in (httpOnly, Secure in production,SameSite=Lax, 30-day lifetime). Our analytics are cookieless and server-side: we measure funnel events on our own servers without storing or reading any information on your device. Because we store no non-essential information on your device and access none, the device-access consent requirement of § 25 TDDDG is not triggered, so no cookie consent banner is required.
Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The AI-readability score is a measurement of how AI assistants may read a public page at scan time — it has no legal or similarly significant effect on any data subject.
Is providing data mandatory?
Providing your email address is a contractual requirement to create an account: without it we cannot establish the account or provide the Service. All other processing is either necessary to deliver a feature you request or based on your consent, which you can withdraw at any time.
Sub-processors
We share data only with the processors required to run the Service. Each acts under a GDPR Art. 28 data-processing agreement. The current list is also maintained at /subprocessors, and our processor terms (DPA) are at /dpa.
| Processor | Purpose | Region | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting & content delivery | USA (EU region pinned: fra1) | EU Standard Contractual Clauses / EU-US Data Privacy Framework where certified |
| Neon Inc. | Managed PostgreSQL database (accounts, scans, billing mirror) | EU (Frankfurt) | EU — no third-country transfer |
| Stripe Payments Europe, Ltd. (with Stripe, Inc., USA) | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses / EU-US Data Privacy Framework |
| OpenAI, L.L.C. | AI perception & copy generation on scanned content (API; not used to train models) | USA | EU Standard Contractual Clauses |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | USA | EU Standard Contractual Clauses |
| Cloudflare, Inc. | Authoritative DNS and inbound email routing / forwarding for getadvantage.app and plusxplus.de | USA (global anycast edge) | EU Standard Contractual Clauses / EU-US Data Privacy Framework |
| Advantage Studio (Mission Control) | Internal operations console operated by the platform operator — receives a captured lead email + domain for founder operations | EU / USA | Intra-operator; EU Standard Contractual Clauses where applicable |
When you submit an email through the report unlock, that lead email and the scanned domain are also forwarded to our internal operations console (Advantage Studio / Mission Control), operated by the getAdvantage operator, so we can follow up on founder enquiries. No other personal data is sent there.
International transfers
Our database (Neon, Frankfurt) keeps account, scan and billing-mirror data in the EU. Some processors are based in the United States — in particular Vercel (hosting, EU region pinned), OpenAI(AI perception & copy generation; the API is not used to train models), Resend (transactional email) and Stripe’s US entity. Where data is transferred outside the EU/EEA it is protected by EU Standard Contractual Clauses (2021/914) and, where a provider is certified, the EU-US Data Privacy Framework. A copy of the relevant safeguards is available on request.
Retention
We keep account and scan data while your account is active. After you close your account we delete account and scan data within about 30 days, except where a longer period is legally required. Billing records are retained for the statutory period under German tax and commercial law (§ 147 AO / § 257 HGB — generally 8–10 years). Gate-capture (lead) emails are kept until you ask us to remove them. The client IP used for rate-limiting exists only transiently in memory (a window of minutes) and is never persisted.
Security
We apply appropriate technical and organisational measures under Art. 32 GDPR: bcrypt (cost-12) password hashing; signed JWT sessions in httpOnly+Secure cookies; strict tenant isolation (every database query is scoped to your account id); TLS in transit; a Postgres database hosted in the EU (Neon, Frankfurt); SSRF-guarded outbound fetches that re-validate DNS/IP and block private ranges; a global Content-Security-Policy, HSTS and security headers; per-IP rate limiting; secrets kept only in environment variables (never in the repository); and signature verification on billing webhooks. The same measures are summarised in our DPA.
Your rights
You have the right to access, rectify, export (data portability), restrict, object to and erase your personal data, and to withdraw any consent at any time without affecting prior processing. To exercise any of these, email us. You may also lodge a complaint with your competent data-protection supervisory authority.
Children
getAdvantage is a tool for builders and is not directed to children under 16. We do not knowingly collect personal data from children.
Withdrawal & consumer rights
If you are a consumer, you may have a statutory right of withdrawal for paid subscriptions. How that right works, and the official model withdrawal form, are set out at /widerruf.
Changes
We may update this policy as the Service evolves; the “last updated” date above always reflects the current version.