Decidly Beta

Legal

Privacy Policy

Version 1.1 · Effective 2026-05-04

This Privacy Policy informs you about the processing of personal data in connection with the marketing website decidly.io and the use of Decidly (the “Service”), available at app.decidly.io.

1. Controller

Controller within the meaning of Art. 4 (7) GDPR:
DBBC Ventures GmbH
Platanenstr. 45, 13156 Berlin, Germany
Phone: +49 176 20908066
Email: privacy@decidly.io
Registered at Local Court Berlin (Charlottenburg), HRB 256898.

2. Data Protection Officer

We have not appointed a data protection officer because the statutory requirements for such an appointment (§ 38 BDSG) are not currently met. For any data protection questions, please contact privacy@decidly.io.

3. Roles under the GDPR

With respect to personal data that you (or your organisation) enter when using the Service – e.g. names of employees, decision content, comments – your organisation acts as the controller and we act as the processor. Processing is governed by a Data Processing Agreement (see Data Processing Agreement).

For the processing of your account data, billing data and technical logs, as well as for visits to the marketing website, we act as the controller. This Privacy Policy covers that processing.

4. Categories of Data Processed

5. Purposes and Legal Bases

Purpose Legal basis
Providing the Service, account managementArt. 6(1)(b) GDPR (contract)
Authentication (OAuth, Magic Link)Art. 6(1)(b) GDPR
Security, abuse prevention, log filesArt. 6(1)(f) GDPR (legitimate interests)
Evidence of acceptance of Terms / Privacy / DPAArt. 6(1)(f) GDPR (documentation and legal defence); Art. 6(1)(c) where retention is legally required
Support communicationArt. 6(1)(b)/(f) GDPR
Statutory retention (e.g. invoices)Art. 6(1)(c) GDPR, § 257 HGB, § 147 AO
AI assistance (Clarify / Ideate / Decide)Art. 6(1)(b) GDPR (contract performance)

6. Hosting

6.1 Marketing site (decidly.io)

The marketing site is hosted by ALL-INKL.COM – Neue Medien Münnich, Inh. René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. When the site is accessed, the following data is automatically logged in server log files:

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically sound and secure operation). Logs are deleted within 14 days, unless a security incident requires longer retention. A data processing agreement pursuant to Art. 28 GDPR is in place with ALL-INKL.COM.

6.2 Application (app.decidly.io)

The application database, authentication and file storage are operated by Supabase in the EU (AWS region eu-west-1, Ireland). A data processing agreement pursuant to Art. 28 GDPR is in place. A complete list of all sub-processors can be found at Subprocessors.

6.3 Application-Hosting (Vercel)

The application frontend, server-side routes and the internal admin dashboard are hosted and executed on Vercel. Depending on the request, Vercel processes HTTP request metadata, technical logs and content transiently required to serve the respective request. A data processing agreement pursuant to Art. 28 GDPR and EU Standard Contractual Clauses are in place.

6a. Email Delivery (Resend)

For service emails (password reset, invitations, notifications about pending decisions, weekly digests) we use Resend, operated by Resend.com, Inc., hosted in the EU (AWS region eu-west-1, Ireland). A data processing agreement pursuant to Art. 28 GDPR is in place.

6b. Payment Processing (Stripe)

For paid tiers, AI-credit top-ups and payment status synchronisation we use Stripe Payments Europe, Limited. Stripe processes billing contact data, payment and subscription identifiers, invoice and payment metadata and payment-method details. Decidly does not store full card numbers. A data processing agreement pursuant to Art. 28 GDPR and EU Standard Contractual Clauses are in place.

7. AI-Assisted Features (Anthropic / Claude)

For features supporting clarification, ideation and decision-making, we use the Claude language model operated by Anthropic PBC (USA). When you actively trigger an AI feature, the input necessary for the request (e.g. your question, relevant text excerpts) is transmitted to Anthropic.

8. OAuth Sign-In (Google, Microsoft)

When you sign in via an OAuth provider, the authentication data (email address, possibly name, provider ID) is exchanged between the provider and us. The legal basis is Art. 6(1)(b) GDPR. Details on processing by the providers are available in their respective privacy policies.

9. Cookies, Local Storage and Fonts

On the marketing website (decidly.io) we set no cookies. We use local storage only to remember your language preference; this is not used for analytics or marketing.

In the application (app.decidly.io) we use only strictly necessary cookies and localStorage entries (session tokens, theme setting). These are exempt from consent under § 25(2)(2) TDDDG. We do not use marketing or analytics cookies.

Both sites use the fonts Inter and JetBrains Mono as well as Tailwind CSS. All resources are served locally from our own servers. There is no connection to Google servers or any content delivery network and no transmission of your IP address to third parties.

10. Contact Form

When you submit the contact form on this site or inside the application (Settings → Help & Feedback), the following data is processed: the email address you provide and, optionally, your name; subject and message; the category you select (bug, feature, question, other); the language of the form; and a non-reversible hash of your IP address — used solely for rate-limiting and abuse protection. The original IP address is not stored. Submissions from the logged-in application additionally include the current URL, your browser's user agent and viewport, and the browser language, to help us reproduce reported issues.

Legal bases: our legitimate interest in receiving and responding to user enquiries (Art. 6(1)(f) GDPR); for contract-related queries from existing customers, the performance of a contract (Art. 6(1)(b) GDPR); for the IP hash, our legitimate interest in protecting the form against spam and automated abuse (Art. 6(1)(f) GDPR). Submission of the form requires acknowledgement of this privacy notice.

Submissions are stored in our Supabase database in the EU region (see § 6.2). They are visible only to authorised internal staff of the controller via an admin interface. We do not automatically forward contact-form submissions by email, and there is no transfer to third parties beyond the hosting providers listed in our Subprocessor list.

Contact-form messages are deleted automatically 90 days after we have marked them as resolved or closed. You can request earlier deletion at any time by writing to privacy@decidly.io.

11. Retention Periods

12. Recipients and Third-Country Transfers

We disclose personal data only to the processors listed in the Subprocessor list and to public authorities where legally required. Third-country transfers may occur in particular for Anthropic, Google Workspace, Stripe, Vercel and GitHub where relevant; they are safeguarded by Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

13. Source Code Deployment

The source code of both sites is versioned and automatically deployed via GitHub (GitHub, Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA). For visitors to these sites, this deployment process involves no data processing by GitHub; no GitHub resources are loaded in the visitor's browser.

14. Automated Decision-Making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. AI suggestions are suggestions; decisions are always made by a human.

15. Your Rights

To exercise your rights, an informal message to privacy@decidly.io is sufficient.

16. Right to Lodge a Complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority. The authority competent for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
www.datenschutz-berlin.de

17. Security

We implement technical and organisational measures to protect your data against unauthorised access, loss or alteration. These include in particular: TLS encryption, row-level security at the database layer (tenant-isolated visibility), encrypted storage of authentication data, need-to-know access controls and regular reviews. Details are set out in the TOMs annex to the DPA.

18. Changes to this Policy

We adapt this Privacy Policy if features, legal requirements or the services we use change. The current version is always available at this URL. For material changes, we additionally notify active users by email or in-app.