Decidly Beta

Legal

Privacy Policy

Version 1.0 · Effective 2026-04-24

This Privacy Policy informs you about the processing of personal data in connection with the marketing website decidly.io and the use of Decidly (the “Service”), available at app.decidly.io.

1. Controller

Controller within the meaning of Art. 4 (7) GDPR:
DBBC Ventures GmbH
Platanenstr. 45, 13156 Berlin, Germany
Phone: +49 176 20908066
Email: privacy@decidly.io
Registered at Local Court Berlin (Charlottenburg), HRB 256898.

2. Data Protection Officer

We have not appointed a data protection officer because the statutory requirements for such an appointment (§ 38 BDSG) are not currently met. For any data protection questions, please contact privacy@decidly.io.

3. Roles under the GDPR

With respect to personal data that you (or your organisation) enter when using the Service – e.g. names of employees, decision content, comments – your organisation acts as the controller and we act as the processor. Processing is governed by a Data Processing Agreement (see Data Processing Agreement).

For the processing of your account data, billing data and technical logs, as well as for visits to the marketing website and the waitlist sign-up, we act as the controller. This Privacy Policy covers that processing.

4. Categories of Data Processed

5. Purposes and Legal Bases

Purpose Legal basis
Providing the Service, account managementArt. 6(1)(b) GDPR (contract)
Authentication (OAuth, Magic Link)Art. 6(1)(b) GDPR
Security, abuse prevention, log filesArt. 6(1)(f) GDPR (legitimate interests)
Evidence of consent to Terms / PrivacyArt. 6(1)(c) and Art. 7(1) GDPR
Support communicationArt. 6(1)(b)/(f) GDPR
Waitlist sign-up (one-off launch notification)Art. 6(1)(a) GDPR (consent)
Statutory retention (e.g. invoices)Art. 6(1)(c) GDPR, § 257 HGB, § 147 AO
AI assistance (Clarify / Ideate / Decide)Art. 6(1)(b) GDPR (contract performance)

6. Hosting

6.1 Marketing site (decidly.io)

The marketing site is hosted by ALL-INKL.COM – Neue Medien Münnich, Inh. René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When the site is accessed, the following data is automatically logged in server log files:

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically sound and secure operation). Logs are deleted within 14 days, unless a security incident requires longer retention. A data processing agreement pursuant to Art. 28 GDPR is in place with ALL-INKL.COM.

6.2 Application (app.decidly.io)

The application database, authentication and file storage are operated by Supabase in the EU (AWS region eu-west-1, Ireland). A data processing agreement pursuant to Art. 28 GDPR is in place. A complete list of all sub-processors can be found at Subprocessors.

6a. Email Delivery (Resend)

For service emails (password reset, invitations, notifications about pending decisions, weekly digests) we use Resend, operated by Resend.com, Inc., hosted in the EU (AWS region eu-west-1, Ireland). A data processing agreement pursuant to Art. 28 GDPR is in place.

7. AI-Assisted Features (Anthropic / Claude)

For features supporting clarification, ideation and decision-making, we use the Claude language model operated by Anthropic PBC (USA). When you actively trigger an AI feature, the input necessary for the request (e.g. your question, relevant text excerpts) is transmitted to Anthropic.

8. OAuth Sign-In (Google, Microsoft, Apple)

When you sign in via an OAuth provider, the authentication data (email address, possibly name, provider ID) is exchanged between the provider and us. The legal basis is Art. 6(1)(b) GDPR. Details on processing by the providers are available in their respective privacy policies.

9. Cookies, Local Storage and Fonts

On the marketing website (decidly.io) we set no cookies and use no comparable tracking technologies (local storage, session storage etc.) for analytics or marketing purposes.

In the application (app.decidly.io) we use only strictly necessary cookies and localStorage entries (session tokens, theme setting). These are exempt from consent under § 25(2)(2) TDDDG. We do not use marketing or analytics cookies.

Both sites use the fonts Inter and JetBrains Mono as well as Tailwind CSS. All resources are served locally from our own servers. There is no connection to Google servers or any content delivery network and no transmission of your IP address to third parties.

10. Waitlist (Early Access)

If you sign up for the waitlist on the marketing site, the email address you provide and – for technical reasons – the timestamp of registration, IP address and user agent are processed. Legal basis: your consent under Art. 6(1)(a) GDPR and the legitimate interest in protecting the form against abuse (Art. 6(1)(f) GDPR).

The data is received server-side by a PHP script on decidly.io and forwarded by email to the controller. The SMTP server of the host ALL-INKL.COM is used for delivery; receipt at the controller's mailbox is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Gmail). No further storage in a database takes place.

The email address is used solely to inform you once about the launch or availability of Decidly. There is no further disclosure to third parties.

You can withdraw your consent at any time by informal email to privacy@decidly.io. Upon withdrawal, your email address will be deleted without undue delay.

10a. Contact Form

When you submit the contact form on this site or inside the application (Settings → Help & Feedback), the following data is processed: the email address you provide and, optionally, your name; subject and message; the category you select (bug, feature, question, other); the language of the form; and a non-reversible hash of your IP address — used solely for rate-limiting and abuse protection. The original IP address is not stored. Submissions from the logged-in application additionally include the current URL, your browser's user agent and viewport, and the browser language, to help us reproduce reported issues.

Legal bases: our legitimate interest in receiving and responding to user enquiries (Art. 6(1)(f) GDPR); for contract-related queries from existing customers, the performance of a contract (Art. 6(1)(b) GDPR); for the IP hash, our legitimate interest in protecting the form against spam and automated abuse (Art. 6(1)(f) GDPR). Submission of the form requires confirmation of this privacy notice.

Submissions are stored in our Supabase database in the EU region (see § 6.2). They are visible only to authorised internal staff of the controller via an admin interface. We do not automatically forward contact-form submissions by email, and there is no transfer to third parties beyond the hosting providers listed in our Subprocessor list.

Contact-form messages are deleted automatically 90 days after we have marked them as resolved or closed. You can request earlier deletion at any time by writing to privacy@decidly.io.

11. Retention Periods

12. Recipients and Third-Country Transfers

We disclose personal data only to the processors listed in the Subprocessor list and to public authorities where legally required. Transfers to third countries currently only occur to Anthropic (USA) and Google (USA), each safeguarded by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

13. Source Code Deployment

The source code of both sites is versioned and automatically deployed via GitHub (GitHub, Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA). For visitors to these sites, this deployment process involves no data processing by GitHub; no GitHub resources are loaded in the visitor's browser.

14. Automated Decision-Making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. AI suggestions are suggestions; decisions are always made by a human.

15. Your Rights

To exercise your rights, an informal message to privacy@decidly.io is sufficient.

16. Right to Lodge a Complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority. The authority competent for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
www.datenschutz-berlin.de

17. Security

We implement technical and organisational measures to protect your data against unauthorised access, loss or alteration. These include in particular: TLS encryption, row-level security at the database layer (tenant-isolated visibility), encrypted storage of authentication data, need-to-know access controls and regular reviews. Details are set out in the TOMs annex to the DPA.

18. Changes to this Policy

We adapt this Privacy Policy if features, legal requirements or the services we use change. The current version is always available at this URL. For material changes, we additionally notify active users by email or in-app.