briven startet bald — jetzt unverbindlich vormerken →

Privacy policy

Version: 11 September 2026

With this privacy policy we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR; in Germany DSGVO), about the processing of your personal data when you use briven — a service for the automated technical analysis of buildings. Personal data means any information relating to an identified or identifiable natural person.

1. Controller & data protection officer

The controller within the meaning of Article 4(7) GDPR is:

briven UG (haftungsbeschränkt)
represented by its managing director Ayosha Aghazadeh
Overbergstraße 87
45663 Recklinghausen
Germany
Email: kontakt@briven.de

Data protection officer

We have not yet appointed a data protection officer; that is the factual position, not the legal one — the duty to appoint one already exists, see below. The service is not in regular operation — the checkout is switched off and registrations are closed — which limits the scale of the processing, but does not defer the duty. Of the statutory conditions that trigger a duty to appoint (§ 38(1) BDSG, the German federal act implementing the GDPR, and Article 37(1) GDPR), the following are not met: our company does not permanently employ at least twenty people on the automated processing of personal data (§ 38(1) sentence 1 BDSG); we are not a public authority (Article 37(1)(a) GDPR); and our core activity consists neither in regular and systematic monitoring of individuals on a large scale (Article 37(1)(b) GDPR) nor in large-scale processing of special categories of data (Article 37(1)(c) GDPR).

The remaining condition is § 38(1) sentence 2 BDSG. It has two limbs. The first: processing operations subject to a data protection impact assessment under Article 35 GDPR. We carried out a documented threshold assessment for this; it concludes that our building analysis is subject to one. The second: processing on a commercial basis for the purpose of transmitting personal data, including in anonymised form, or for the purpose of market or opinion research on the internet — that case does not arise here; our transfers go to processors bound by a data processing agreement and to payment service providers, as the means of carrying out the payment. The full reasoning is set out in our documented threshold assessment.

With that outcome, the duty to appoint under § 38(1) sentence 2 BDSG has already arisen; it attaches to the processing we carry out, not to the start of any particular state of operation. The choice has been made, the appointment follows without undue delay; we will publish the contact details at this point. The impact assessment itself exists in draft and is not complete: it still lacks the advice of the data protection officer required by Article 35(2) GDPR. Until those contact details are published, please address any data protection question to us at kontakt@briven.de.

2. Overview of processing activities

The following table summarises the main processing activities, their purposes and the corresponding legal basis. The detail is set out in the sections that follow.

ProcessingPurposeLegal basis
Building analysis (address, documents, photos)Carrying out the analysis you orderedArticle 6(1)(b)
User accountRegistration, login, administrationArticle 6(1)(b)
Payment & performance of the contractInvoicing, order confirmation, accountingArticle 6(1)(b) and (c)
Server logs, security, abuse preventionStable and secure operationArticle 6(1)(f)
Audience measurement (Plausible)Anonymous, cookie-free statistical analysis of usageArticle 6(1)(f) (legitimate interest)

3. Legal bases

We process personal data on the following legal bases: consent (Article 6(1)(a) GDPR), performance of a contract and pre-contractual measures (Article 6(1)(b) GDPR), legal obligation (Article 6(1)(c) GDPR, for example retention duties under commercial and tax law) as well as legitimate interests (Article 6(1)(f) GDPR).

Where we base processing on legitimate interests (Article 6(1)(f) GDPR), we name the specific interest in the relevant section. Our legitimate interest lies in particular in the secure, stable and abuse-free operation of the application, in defending against attacks and in developing the service in line with actual needs. In the balancing exercise, your interests meriting protection do not prevail, because we use the data exclusively for these narrowly defined purposes and not for advertising or extensive profiling.

4. Hosting and infrastructure

The web application, our own processing services (in particular the anonymisation services, see section 6) and the object storage for the files you upload and those produced in the course of the analysis (photos, documents, 3D building models) run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in German data centres. A data processing agreement within the meaning of Article 28 GDPR is in place — see section 12.

The database and authentication have been operated by us ourselves since 02/09/2026 — on a server of our own at Hetzner Online GmbH, the same provider as above, in Germany (Falkenstein site). The software used (Supabase) runs there under our own responsibility; no contracting provider established outside the European Union is therefore involved any longer in the day-to-day operation of the database and the login. The data processing agreement under Article 28 GDPR concluded with Hetzner Online GmbH also covers this server — see section 12. The storage medium is encrypted; the connection to it is encrypted and, where it links our own servers, runs through a private tunnel. Only the secure programming interface of our database service is publicly reachable — that is what your browser connects to and retrieves your data from; every access is tied to your login, the database additionally applies row-level access rules whose completeness we check regularly, and we limit the number of login attempts per sender. Direct access to the database from the internet is not possible. The data held up to the move at the previous provider (Supabase Pte. Ltd, registered office in Singapore) has since been deleted.

This database is backed up in encrypted form, updated daily and kept for 28 days. The backups are stored in two locations independent of one another: at our hosting provider in Germany and — as a second, provider-independent storage location — in the object storage of Scaleway SAS in Paris, France (EU). The second copy serves solely to preserve the backup should the first location or its provider fail; an overview is set out in section 12.

5. Server logs and IP addresses

When the application is called up, technically necessary connection data is automatically processed in server logs: IP address, date and time of access, the resource requested, the HTTP status code, the volume of data transferred, the referring URL and the type of browser or device used (user agent).

Purpose: provision of the application, safeguarding system security, detecting and defending against attacks and abuse, and limiting the frequency of requests (rate limiting). The legal basis is our legitimate interest in secure and stable operation (Article 6(1)(f) GDPR); the legitimate interest consists in defending against attacks and preventing abuse. This data is used neither for advertising nor for profiling. Rate-limiting counters are deleted after 24 hours at the latest; technical access logs are deleted after seven days at the latest.

6. Data collected when you use the web application

a) Building address

To carry out the building analysis, you enter the address of a property. It is processed on our infrastructure in Germany and linked to your user account in the analysis database. The address is the very subject matter of the analysis contract. How an address is converted into coordinates (geocoding) is described in section 10.

Important: the full address is not passed to the AI component (see section 8). For spatial location, the AI receives only the postcode, town, federal state and country; street and house number are removed before every transfer to the AI. The coordinates used for the map display are processed separately (see section 11). Legal basis: performance of the contract (Article 6(1)(b) GDPR).

b) Uploaded documents and photos

You may optionally upload documents (for example sales particulars, energy performance certificates, plans) and photos. Before the AI analysis, all uploads automatically pass through a multi-stage pseudonymisation and redaction chain: faces and people are detected and made unrecognisable, number plates, doorbell, letterbox and door signs are redacted, text contained in images is read by optical character recognition (OCR) and personal passages are redacted, and personal references in the text of documents are blacked out (pattern recognition together with name recognition operated on our own infrastructure). From uploaded PDF documents we remove the document metadata (author, creator, title) before storage. From photos we remove the capture metadata (in particular GPS position, device data, date taken) before they enter the analysis; the original file you uploaded is kept unchanged until the period stated in section 15 expires. This processing takes place entirely on our servers in Germany.

Despite these far-reaching measures, a residual risk that individual people may be recognised cannot be entirely excluded. The content transferred to the AI therefore remains personal data in law; it is processed on the basis of performance of the contract (Article 6(1)(b) GDPR) and within the framework of processing on behalf of a controller (Article 28 GDPR) — see section 8.

Your contribution & data minimisation (Article 5(1)(c) GDPR): as far as possible, please do not upload photos showing recognisable people, doorbell signs, letterboxes, door signs, number plates or reflections. Our processing chain does not replace the principle of minimisation. By uploading, you warrant that you are entitled to have the content in question processed (see section 9).

c) User account and login

On registration we process: your email address, your name (optional) and a password chosen by you (which we store exclusively as a cryptographic hash, never in plain text). We do not offer login via external providers such as Google, Microsoft or Apple — no transfer of your login data to an identity provider therefore takes place. Since 02/09/2026 your login data has been processed on our own infrastructure operated in Germany (sections 4 and 12); since that date no new login data has been transferred to a third country. The data held up to then — including login data — at the previous provider of our database (Supabase Pte. Ltd, registered office in Singapore) has since been deleted. Legal basis: performance of the contract (Article 6(1)(b) GDPR).

d) Waiting list / pre-registration

While briven is not yet generally available, you can sign up to a waiting list using a form in order to be notified at launch. In doing so we process your email address and — if you entered an address beforehand — optionally the property address you provided, which we keep solely as a note for your notification (no geocoding and no analysis take place on that occasion). The processing is based on your consent(Article 6(1)(a) GDPR). You give it by signing up and make it effective by clicking the confirmation link in the email that follows (double opt-in); without that click the sign-up is automatically discarded — after seven days at the latest.

We additionally record which of our pages you came to us from and — if you were logged in at the time — the link to your user account.

If you sign up from one of our non-German-language pages — such as this English one — two further items are added: the language of your sign-up and the country whose launch this page concerns. Both follow from the page you were viewing; there is no input field for them. The language determines the one we write to you in — including the unsubscribe link. The country tells us which launch you are interested in, so that we do not write to you when a different country launches. The legal basis for all of this is the same consent (Article 6(1)(a) GDPR); these items share the fate of your sign-up and are deleted with it.

The sign-up serves solely for a single notification at launch; no regular newsletter is associated with it. You can withdraw your consent at any time with effect for the future — via the unsubscribe link in our emails or informally by email to kontakt@briven.de; we will then send you no further notification and will not use your address for any other purpose, in particular not for advertising. After withdrawal we immediately delete the property address stored in your sign-up. Your email address then remains for only three years in our unsubscribe register, solely for evidential purposes (that consent existed and was withdrawn, Article 7 GDPR), after which it is deleted. The launch notification is sent via our email provider Scaleway TEM (see section 12).

e) Contact form & enquiries by email

When you use our contact form or write to us by email, we process the data you provide (name, email address and your message) in order to deal with and respond to your enquiry. The legal basis is — depending on the subject matter — the conclusion or performance of a contract (Article 6(1)(b) GDPR) or our legitimate interest in responding to your enquiry (Article 6(1)(f) GDPR). These details are optional; without a name, email address and message, however, we cannot deal with your enquiry.

The delivery of the form message to our mailbox runs via our email provider Scaleway TEM (see section 12). We keep your enquiry only for as long as is necessary to deal with it and delete it afterwards, unless a statutory retention duty provides otherwise.

f) Enterprise enquiry

If you use our Enterprise form (for portfolios of 100 properties and above), we process, in addition to your name, your email address and your optional message, also your company and the number of properties in your portfolio, in order to qualify your commercial enquiry and to offer you individual terms. The legal basis is the conclusion of a contract (Article 6(1)(b) GDPR) or our legitimate interest in initiating a business relationship (Article 6(1)(f) GDPR). The enquiry reaches our internal sales mailbox, not that of the general contact form. Sending, storage period and provider (Scaleway TEM) correspond to point e).

7. Payment and performance of the contract

Payment processing is carried out by the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. Mollie processes your payment data as an independent controller(Article 4(7) GDPR), in particular for the purposes of executing the payment, preventing fraud and complying with its own legal obligations. We ourselves store no complete card or account data; what remains with us is a payment or customer reference, the payment status and — in the case of a subscription — the subscription administration data (identifier, status, end of the period).

Subscriptions (recurring payment): for monthly plans you give a recurring payment mandate (in the case of SEPA direct debit, a SEPA mandate); the monthly collection is then carried out automatically via Mollie. The mandate and creditor data are held at Mollie; we do not store your IBAN. The legal basis for the contractual subscription data is performance of the contract (Article 6(1)(b) GDPR).

Providers specific to the payment method: depending on the method chosen (for example PayPal, Klarna, card payment), further providers may be involved who act as independent controllers and may carry out their own identity or credit checks (in particular Klarna and PayPal). Details are set out in the data protection information of the provider concerned and in Mollie’s privacy policy. Mollie has its registered office in the European Union; depending on the payment method, downstream payment networks (for example card schemes) may process data outside the Union as well (see section 14).

Order confirmation & invoice: after the contract is concluded you receive a confirmation by email on a durable medium (§ 312f BGB, the German civil code). The creation and audit-proof archiving of your invoice are carried out by our accounting provider acting as a processor (BuchhaltungsButler GmbH, servers in Germany — see section 12); what is transferred on that occasion is the invoice recipient data (name or company name, address, VAT number where applicable), your email address and the invoice amount. We retain invoicing and accounting data on account of commercial and tax obligations (Article 6(1)(c) GDPR; § 147(3) AO, the German fiscal code, and § 257(4) HGB, the German commercial code). Details of the contract and the right of withdrawal are set out in our terms and conditions (in German) and in the withdrawal information (in German).

8. AI-assisted analysis

The building analysis uses AI models operated on European cloud infrastructure. The following providers are used — depending on availability and in order to keep the service running (the specific choice may vary):

  • OVHcloud (OVH SAS), France — EU
  • Scaleway (Scaleway SAS), France — EU
  • Mistral AI (Mistral AI SAS), Paris, France — EU

What is transferred to the AI: the spatial location (postcode, town, federal state and country only — see section 6 a), the public geographic and factual data (see section 10) and the uploaded documents and photos, exclusively in pseudonymised and redacted form (see section 6 b). Since a residual risk of re-identification cannot be entirely excluded, we continue to treat this data as personal data. Legal basis: performance of the contract (Article 6(1)(b) GDPR) in conjunction with processing on behalf of a controller (Article 28 GDPR).

The providers named process the data on instruction, as processors. Under the contractual terms, the data transferred is not used to train the AI models and is not retained beyond the processing (zero retention). The corresponding data processing agreements under Article 28 GDPR are concluded with all of the providers named. The zero-retention commitment rests on different foundations depending on the provider: for one on a contractual term, for another on a privacy policy published for the service concerned, and for the third on a setting requested specifically for our account and confirmed by the provider. We hold all three items of evidence and present them on request. An overview of recipients is set out in section 12.

The AI analysis is produced in an automated manner and serves solely as a technical basis for your decision. It is diagnostic in character, does not constitute a legally binding inspection and does not replace an on-site inspection by a professional. On the question of automated decision-making, see section 18.

9. Data about people who do not use briven (Article 14 GDPR)

In the course of a building analysis we regularly also process personal data about people who do not themselves use briven and who are unaware of the analysis. This section is addressed to you if you are one of those people. It is deliberately written so as to be comprehensible without the rest of the text.

Who is responsible for this processing. briven UG (haftungsbeschränkt), represented by its managing director Ayosha Aghazadeh, Overbergstraße 87, 45663 Recklinghausen, Germany, email kontakt@briven.de. We have not yet appointed a data protection officer; as soon as we have, you will find the contact details in section 1.

Which data is affected and where it comes from. On the one hand, from documents that our users upload: owners and encumbrances in land register extracts, co-owners in declarations of division and meeting minutes, tenants in leases and service charge statements, trade businesses on invoices, and people, number plates and doorbell, letterbox or door signs in photos. On the other hand, from official public sources that we consult ourselves: the official 3D building models, from which we use the geometry of immediately adjoining neighbouring buildings in order to detect party walls, and the official aerial imagery, on which neighbouring plots may be shown.

For what purposes we process it. Exclusively in order to carry out the technical assessment of the condition of the building ordered by our user — and to redact beforehand the personal references contained in the material. We do not evaluate this data as personal data, we do not create profiles and we do not use it for advertising. The final report contains no personal names.

What we combine — and what we do not. For the assessment we combine information from several sources into a picture of the building: official cadastral data, 3D building models, aerial imagery and documents uploaded by our users. What is combined in doing so are building characteristics only — year of construction, geometry, materials, condition. Information relating to individuals is neither combined, nor enriched, nor attributed to a person; it is redacted before the analysis.

On what basis. On the basis of our legitimate interests and those of our users under Article 6(1)(f) GDPR. The interest consists in being able to assess the technical condition of a building reliably before a significant economic decision. We have balanced the opposing interests of the data subjects and documented that balancing exercise; we will provide you with the outcome on request. For people who have provided us with their documents themselves, performance of the contract additionally applies (Article 6(1)(b) GDPR).

How we protect your data. Before the uploaded documents and photos are transferred to our AI providers, they pass on our servers in Germany through multi-stage redaction: faces, people, number plates and doorbell, letterbox and door signs are covered, text present in images is read and personal passages redacted, personal references in the text of documents are blacked out, and all address details are removed. This step is mandatory: if it fails, no analysis starts. Complete anonymisation cannot be guaranteed technically; we therefore continue to treat this data as personal data.

We treat official aerial imagery differently — and we tell you openly why. Aerial imagery from the official cadastral authorities does not pass through this redaction. We have checked and measured this: at the actual ground resolution of about twelve centimetres per pixel, people appear as three to five pixels with no recognisable feature; during the measurement the redaction technology detected no people at all, but covered up to 13 per cent of the image area, including, on one occasion, an entire residential building. It would therefore be ineffective here and harmful at the same time. What we do instead is to limit the image extract we request to the plot being assessed, so that neighbouring plots are kept out as far as possible (data minimisation, Article 5(1)(c) GDPR).

Who receives it. Our processors, in particular our hosting provider in Germany and our AI providers in the European Union. They process the data on instruction, do not use it to train their models and do not retain it beyond the processing. You will find the complete and current list at briven.eu/subprozessoren (in German) and in section 12.

How long we keep it. Documents and photos that may contain information about you are deleted 18 months after the last use of the corresponding analysis. Those 18 months are an inactivity period, not a maximum storage period: if the analysis is used again, the period starts afresh. The total storage period of a file therefore depends on how long the corresponding analysis continues to be used. Deletion occurs earlier as soon as the analysis or the user’s account is deleted — which as a rule happens well before the period expires. You will find the same information in the table in section 15; the maximum periods for all other data categories are set out there as well. In the final report we reproduce images only in their redacted form, and we do not evaluate information about you as personal data. As complete anonymisation is not technically guaranteed, we cannot exclude that an indirect link to a person might be established from the report.

If your data reaches a third country. The uploaded documents and photos themselves are stored exclusively in Germany (Hetzner, see section 4), the database has since 02/09/2026 likewise been operated on our own servers in Germany, and the AI analysis takes place exclusively within the European Union. Since 02/09/2026 there is therefore no new transfer of this data to a third country. Previously there was one, because the contracting provider of our database had its registered office in Singapore — the processing itself already took place within the Union. The data held up to the move at that provider (Supabase Pte. Ltd, registered office in Singapore) has since been deleted. The complete account of all cases — including those that do not concern your data — is set out in section 14.

Why we do not inform you individually. Article 14 GDPR obliges us in principle to inform you where we obtain data about you from a source other than yourself. Article 14(5)(b) GDPR provides an exception on which we rely here — for two reasons. As regards people whose details appear in uploaded documents or photos, we do not know your identity and we do not deliberately seek it: we redact those details instead of evaluating them. Informing you would first require identifying you — that is, carrying out precisely the processing we avoid. As regards the owner of a property examined at the request of a prospective buyer, prior information would seriously impair the purpose of the processing, because a neutral and uninfluenced assessment of the condition would then no longer be possible. What we do instead is make this information available to you here, publicly and permanently.

Your rights — even without an account with us. You have the same rights as our users: access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18) and objection (Article 21). As we rely on legitimate interests, you may object to the processing at any time on grounds relating to your particular situation. Please contact us informally at kontakt@briven.de; please tell us the property address so that we can locate your data. We respond within one month. For the protection of all parties, we may request information confirming your identity (Article 12(6) GDPR). You may also lodge a complaint with a data protection supervisory authority at any time — that of your habitual residence, your place of work or the place of the alleged infringement (Article 77(1) GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (the supervisory authority of the German state of North Rhine-Westphalia), Kavalleriestraße 2–4, 40213 Düsseldorf (postal address: Postfach 20 04 44, 40102 Düsseldorf; www.ldi.nrw.de). The same information is set out in section 17.

10. Public data sources

For the analysis we consult publicly accessible geographic and factual data, in particular: the official cadastre (ALKIS WFS), OpenStreetMap (ODbL licence, via an Overpass interface), official aerial imagery from the cadastral authorities of the federal states (WMS), and data on flooding, heavy rainfall, radon, earthquakes, noise, listed buildings and mining activity published by the competent bodies. These queries are made without exception from our servers; what is transmitted is the building coordinate, not your IP address.

For the conversion of an address into coordinates (geocoding) we currently operate no service of our own; the public services that would come into question are switched off here. As soon as we put a geocoding service into operation, we will state it here and in the overview of recipients in section 12 — that is the only place to which the full address would be transmitted.

We process official orthophotos at a ground resolution of about 10 to 20 centimetres per pixel. On such vertical images, individual people may be represented as objects a few pixels in size; facial features and number plates are not recognisable on them. For the transfer of these images to our AI processors, the bases and protective measures described in section 8 apply. The source of this data are the respective public bodies named (Article 14(2)(f) GDPR).

11. Map display

The aerial map in the analysis view shows official digital orthophotos from the cadastral authorities of the federal state concerned. It is the same image source from which the analysis and the PDF report are derived.

The map tiles are delivered by our own server. In doing so your browser establishes no connection to the geographic services of the federal states; your IP address is not transmitted to them when the tiles are retrieved. What is transmitted are only the coordinates of the map extract displayed, and that from our server to the competent public body in Germany — no link to you as a person results from this.

No transfer to a third country takes place for the map display. Legal basis: performance of the contract or legitimate interest in a functioning map display (Article 6(1)(b) or (f) GDPR).

12. Recipients and processors

To provide the service we use processors (Article 28 GDPR) and transfer data to other recipients, some of whom are independent controllers. A detailed description of the procedures is set out in our internal record of processing activities (Article 30 GDPR), which we make available to the supervisory authority on request.

a) Processors (Article 28 GDPR)

ProviderLocation / regionPurposeProcessing
Hetzner Online GmbHGermanyServer hosting; self-operated database and authentication (Falkenstein site; the software used is called Supabase, we operate it ourselves); object storage for the files you upload and those produced by the analysis (photos, documents, 3D building models)EU; data processing agreement concluded
AppSignal B.V.Netherlands (EU)Error tracking and performance monitoring (APM)EU; data processing agreement concluded
OVHcloud (OVH SAS)France (EU)AI processing of pseudonymised input dataEU; data processing agreement concluded
Scaleway SASFrance (EU)AI processing of pseudonymised input dataEU; data processing agreement concluded
Mistral AI SASFrance (EU)AI processing of pseudonymised input dataEU; data processing agreement concluded
Scaleway TEMFrance (EU)Transactional emails (confirmations, notifications)EU; data processing agreement concluded
Scaleway Object StorageFrance (EU), ParisObject storage — second location for the database backup, independent of the hosting provider (since 03/09/2026)EU; data processing agreement in place, its scope for this service not yet conclusively assessed
BuchhaltungsButler GmbHGermany (Berlin)Invoicing and audit-proof archiving (accounting)EU; data processing agreement concluded
IONOS SEGermanyEmail mailbox kontakt@briven.deEU; data processing agreement concluded

b) Independent controllers / other recipients

RecipientLocation / regionPurposeBasis
Mollie B.V. (inkl. PayPal, Klarna)Netherlands (EU); third countries where applicablePayment processing; identity or credit checks where applicableIndependent controller

Categories of recipients: Hosting and IT service providers, error tracking and monitoring providers, AI service providers, payment service providers, accounting and invoicing providers, email service providers. This list is updated whenever anything changes; the list published at the relevant time is authoritative. A compact overview is also available at briven.eu/subprozessoren (in German).

13. Cookies and audience measurement

We use technically necessary cookies for authentication (the session cookie of our own login service, cookies with the prefix sb-) and one cookie that records your preference regarding statistics — in particular an objection to audience measurement (briven_consent, one year, renewed on each visit so that your objection does not expire silently). These cookies are necessary to provide the service you have expressly requested or to give effect to your data protection decision and do not require consent (§ 25(2) no. 2 TDDDG, the German act on data protection in telecommunications and digital services).

For audience measurement we use Plausible Analytics on our own infrastructure (self-hosted). Plausible works without cookies, stores nothing on your device and does not actively read anything from it; consent under § 25 TDDDG is therefore not required. There is no fingerprinting, no cross-device or cross-site tracking and no transfer to third parties. Only aggregated measurements are collected (for example page views, referral source, approximate region); your IP address is processed solely for the purpose of counting unique visits, by means of an irreversible procedure that changes daily, and is not stored.

The legal basis is our legitimate interest in an anonymous analysis of reach and usage with a view to developing the service in line with actual needs (Article 6(1)(f) GDPR); since the processing is anonymised and purely statistical, your interests meriting protection do not prevail. You have the right to object to this processing at any time (Article 21 GDPR); the objection takes effect immediately and for the future, as the statistics are then no longer loaded. Please use the Cookie settings link in the footer or go straight there: .

For error tracking and performance monitoring (APM) we use AppSignal (AppSignal B.V., Netherlands). AppSignal sets no cookies and does not access information on your device; consent under § 25 TDDDG is therefore not required and the use is independent of your cookie decision. The personal data processed in this context (in particular your IP address) is processed on the basis of our legitimate interest in the technical stability and error correction of our service (Article 6(1)(f) GDPR); the processing takes place for the duration of our contractual relationship with AppSignal or in accordance with AppSignal’s own product-specific storage periods. For further details on processing and location, see section 12.

No marketing or advertising cookies are used.

14. Transfers to third countries

Our server infrastructure is located in Germany: the database, authentication and the storage of your files run on servers in German data centres, and the AI processing takes place within the European Union. The encrypted database backups are additionally kept in a second, provider-independent location in Paris (France) — a recipient within the Union (see section 4). In one case a transfer to a third country may nevertheless take place — permanently, because the processing itself takes place there:

  • Payment processing (permanent) — depending on the payment method, downstream payment networks may process data outside the European Union (see section 7). These networks sit behind our payment service provider and are independently responsible for that processing; they are not among our processors.

Database and authentication: since 02/09/2026 there is no longer any transfer to a third country. Until 02/09/2026 the database and authentication were provided by Supabase Pte. Ltd, whose registered office is in Singapore; the processing did already take place within the Union, but on account of the contracting provider’s registered office we based the transfer on the standard contractual clauses (Article 46(2)(c) GDPR). Since the move to our own infrastructure at a processor in Germany (section 4), no further data has been added there. The data held up to the move was kept only as a way back should the move have to be reversed; we gave up that way back on 03/09/2026 and deleted the data the same day. With that deletion, Supabase Pte. Ltd is no longer a recipient of our data, and the standard contractual clauses relating to that data have become devoid of purpose.

Should a recipient in future be established in the United States, we would base the transfer, recipient by recipient, on a certification under the EU–US Data Privacy Framework (adequacy decision of the European Commission) or, in the absence of certification, on the standard contractual clauses (Article 46(2)(c) GDPR) together with supplementary measures. For recipients in other third countries without an adequacy decision, we likewise base the transfer on the standard contractual clauses (Article 46(2)(c) GDPR) together with supplementary measures. We check and document the specific mechanism for each recipient, and its certification status, in our internal record of processing activities (Article 30 GDPR). You may request a copy of the appropriate safeguards (for example standard contractual clauses) at kontakt@briven.de.

15. Storage periods

We store personal data only for as long as is necessary for the purposes concerned or as long as statutory retention duties exist. Where no fixed period is stated below, the duration is governed by the purpose of the processing; once the purpose ceases to apply, the data is deleted or anonymised.

Data categoryStorage period (cap)
User account, analyses, results, corrections entered by youfor the duration of the contractual relationship or until the account is deleted; in addition a maximum of 24 months without any activity on your account (login, new analysis, purchase, message in the re-analysis dialogue) — we announce the automatic deletion by two prior emails. If an active subscription is running, this inactivity period does not apply
Original files uploaded by you (photos, PDF documents)18 months without further use of the corresponding analysis — the period starts afresh with each use; at the latest until the account is deleted
Official aerial imagery relating to your analysis (including older vintages for comparing the condition of the building stock)18 months without further use of the corresponding analysis — the period starts afresh with each use; at the latest until the account is deleted. The cover image of your report is unaffected: it is retrieved from the official bodies again if needed
Anonymised thumbnails from clarification requests (storage)up to 7 days after the decision
Open clarification requests (no response)up to 30 days, then discarded
Discarded clarification records; unused plain-text detailsup to 90 days
Anonymisation cache (text / image)up to 30 days
Cache of the official 3D building models (geometry by tile, with no link to a property or address)up to 12 months after the last retrieval
Dialogue histories and session data from the re-analysisup to 30 days
Incomplete re-analysis draftsup to 90 days after the last change
Rate-limiting countersup to 24 hours
Processing and billing logs (technical logs)for the duration of the account or as required; the fixed periods for the logs listed separately are set out in the rows below
Email dispatch log (delivery status, no content)up to 90 days
Invoicing and accounting data8 years (§ 147(3) AO, the German fiscal code; § 257(4) HGB, the German commercial code)
Evidence of your cookie consent (Article 7(1) GDPR)up to 4 years from the decision concerned — a cap deliberately set beyond the three-year limitation period; the preference cookie itself is extended on a rolling basis with each visit (section 13), whereas the evidential record is capped; if the account is deleted we additionally delete the link to your account immediately, after which the remaining record no longer has any link to a person
Withdrawal and cancellation confirmations (evidential register)up to 4 years from receipt of your declaration — duty of proof arising from § 356a(4) or § 312k(4) BGB (the German civil code), limitation period included; survives deletion of the account
Unconfirmed waiting-list sign-ups (confirmation link not clicked)up to 7 days, then automatically discarded — consent takes effect only with the click on the confirmation link
Unsubscribed waiting-list sign-ups (email address)up to 3 years from unsubscribing — evidence of your consent and its withdrawal (Article 7 GDPR); the stored property address is deleted immediately on unsubscribing
Confirmed waiting-list sign-ups (without withdrawal)up to 3 years from confirmation — evidence of your consent (Article 7 GDPR); once the launch notification has been delivered, the purpose ceases to apply; in no case does storage exceed this period
Administrator access log (who accessed which data and when)up to 3 years from the entry (accountability, Article 5(2) GDPR); survives deletion of the account

Regarding the period applicable to your original files: only the uploaded originals are deleted when it expires. Your report, the analyses derived from it and the redacted versions of the images are retained — so you keep your result, while the raw material that may contain information about people who are not involved disappears. We flag this in the analysis as soon as it has happened; a fresh analysis can then no longer take those documents into account.

If the account is deleted, the corresponding data is removed from the live database within 30 days, unless a statutory retention duty or an evidential or logging purpose with its own period, stated in the table, applies. A deleted copy may additionally remain for up to 56 days in our encrypted database backups — 28 days of backup retention plus up to 28 days before the server-side versioning of the second storage location finally removes non-current copies — after which it is permanently and automatically deleted; this period serves solely for restoration in the event of an incident and is neither searched nor analysed.

16. Your rights

You have the following rights in respect of your personal data:

access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR), objection to processing (Article 21 GDPR) and withdrawal of a consent given (Article 7(3) GDPR) with effect for the future.

The right to data portability (Article 20 GDPR) relates to the data you have provided (for example address, uploaded files, account data), not to the analysis results we calculate (for example assessments, cost estimates).

Right to object (Article 21 GDPR): in so far as we process data on the basis of legitimate interests (Article 6(1)(f) GDPR), you have the right to object to that processing at any time on grounds relating to your particular situation.

To exercise your rights, please contact kontakt@briven.de. We respond to requests without undue delay, at the latest within one month of receipt; where matters are complex, this period may be extended by a further two months (Article 12(3) GDPR), of which we will inform you. For the protection of your data, we may request further information confirming your identity (Article 12(6) GDPR).

17. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority. The authority responsible for us (registered office in North Rhine-Westphalia) is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
(postal address: Postfach 20 04 44, 40102 Düsseldorf)
www.ldi.nrw.de

You may also turn to the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement (Article 77(1) GDPR). Which authority that is depends on where you are; this page is written in English and is read from many countries, so we do not name a single national authority here. The European Data Protection Board publishes the current list of all supervisory authorities in the European Economic Area at edpb.europa.eu. You may lodge your complaint with the authority you choose; the supervisory authorities then cooperate under the procedure provided for by the GDPR, and the authority you approached informs you of the progress and the outcome (Article 77(2) GDPR).

18. Automated decision-making

The subject of the AI analysis is the technical assessment of a building, not an assessment of you as a person; no scoring of individuals (for example as to creditworthiness or conduct) takes place. The AI-assisted assessment is indeed produced in an automated manner, but it serves solely to inform your technical decision; evaluating and using the results is a matter for you. On request, we will explain how the diagnostic models used work in principle.

Two processes we disclose nonetheless. If you abort an analysis in progress, an automated process decides whether you receive a refund, a credit or neither. What is decisive on that occasion are exclusively technical parameters — how far the processing had progressed at the moment of the abort — and the number of such aborts within 90 days, a number capped for economic reasons. No characteristic of you as a person enters into these processes, no profile is created, and no assessment of your conduct beyond that purpose takes place. We do not regard this as a decision within the meaning of Article 22(1) GDPR; were it to be judged otherwise, it would be necessary for the performance of the contract (Article 22(2)(a) GDPR). In any event: you may ask us to review each of these decisions. Write to us, and a natural person will look at the case.

19. Obligation to provide data and changes to this policy

Providing certain data is necessary for the performance of the contract: without the building address the analysis cannot be carried out; without account and payment data the contract cannot be performed. If you do not provide this data, the contract cannot be performed, or can be performed only in part. Providing further details (for example additional documents and photos) is optional and merely improves the scope of the analysis.

We reserve the right to adapt this privacy policy so that it meets the applicable legal requirements at all times or in order to reflect changes to our services. On your next visit, the version then in force applies.

About this language version. This privacy policy is the English version of our Datenschutzerklärung in German. Both versions describe the same processing activities, the same legal bases, the same recipients and the same periods, and carry the same version date. What you find only in this version is linguistic in nature and changes nothing about your rights or our obligations: a brief explanation of the German legal designations, the pointer to the European register of supervisory authorities alongside the right of choice under Article 77(1) GDPR, and the marking of pages that exist only in German. If you notice a substantive divergence, please let us know at kontakt@briven.de.