Privacy Policy
As of July 15, 2026
1. Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is: Maik Masur acting under the business name "Valend" Spohrstraße 61 60318 Frankfurt am Main Germany Email: contact@valend.de
2. Scope
This privacy policy informs you about the processing of personal data when using Valend's websites, mobile applications, software solutions, platforms, and other digital services, including re:one and future products. It applies to all visitors of our websites as well as to registered users of our Services.
3. General Information on Data Processing
The protection of your personal data is of great importance to Valend. We process personal data exclusively in accordance with applicable data protection provisions, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and other applicable data protection regulations. Personal data is any information relating to an identified or identifiable natural person. We process personal data exclusively where this is necessary to provide our Services, to fulfill contractual obligations, based on legal requirements, or on the basis of consent.
4. Hosting and Technical Infrastructure
Our Services are provided via technical infrastructure of external service providers. In particular, the following data may be processed: • IP address • Date and time of access • Browser type • Operating system • Device information • Referrer URL • Hostname • technical error logs This processing serves to securely provide our Services, for error analysis, and to ensure the stability and security of our systems. Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
5. Use of Base44
For the development, provision, hosting, and technical operation of re:one, Valend uses the Base44 platform. The provider of the platform is: Base44, Inc. As part of the use of Base44, personal data may be processed insofar as this is necessary for the provision and operation of re:one. This may include in particular: • registration and user account data, • contact data, • technical usage and log data, • IP addresses and device information, • content entered by the user, • uploaded files and documents, • data from connected Google or Microsoft services, • communication, calendar, and organizational data, • content processed as part of AI functions, • error and security logs. Base44 processes personal data on behalf of Valend and in accordance with Valend's instructions. The processing is carried out on the basis of Base44's Data Processing Addendum as a data processing agreement in accordance with Art. 28 GDPR. Base44's Data Processing Addendum is available at the following address: https://base44.com/dpa Base44 may engage further sub-processors for the technical provision of its services. The currently applicable sub-processors are listed by Base44 in its Data Processing Addendum or in the sub-processor list linked therein. Where personal data is processed by Base44 or its sub-processors outside the European Union or the European Economic Area, the data transfer is carried out in compliance with the statutory requirements of Art. 44 et seq. GDPR. The following transfer mechanisms may be used in particular: • an adequacy decision by the European Commission, • the EU-US Data Privacy Framework, insofar as the respective recipient is effectively certified, • the Standard Contractual Clauses of the European Commission, • or another legally permissible transfer mechanism. The legal basis for the processing is Art. 6(1)(b) GDPR insofar as the processing is necessary for the provision of re:one and the fulfillment of the user relationship. Insofar as the processing serves the secure, stable, and economical provision of re:one, it is carried out on the basis of Art. 6(1)(f) GDPR. Valend's legitimate interest consists in the secure, functional, and efficient provision of the digital services. Upon termination of the contractual relationship or deletion of the user account, the personal data stored at Base44 will be deleted in accordance with the contractual and statutory requirements. Exceptions are data that must be temporarily stored further due to statutory obligations or within technically necessary backup copies. Further information on data processing by Base44 can be found in the Data Processing Addendum and Base44's privacy information.
6. Server Log Files
When visiting our websites, information is automatically stored in so-called server log files. This includes in particular: • IP address • Date and time • Browser information • Operating system • Page accessed • HTTP status code • Amount of data transferred • Referrer URL This data serves exclusively for technical provision, error analysis, abuse detection, and IT security. This data is generally not merged with other data sources. The log data is regularly deleted unless statutory retention obligations or security incidents require longer storage.
7. Cookies and Consent Management
Our websites use cookies and comparable technologies. Technically necessary cookies serve to securely provide our Services and to store your privacy settings. Analytics and convenience functions are activated exclusively with your express consent. The legal bases are: • Section 25(2) TDDDG for technically necessary cookies • Section 25(1) TDDDG for cookies requiring consent • Art. 6(1)(a) GDPR (consent) • Art. 6(1)(f) GDPR (legitimate interest) You can revoke your consent at any time with effect for the future.
8. Analytics and Usage Statistics
To improve our Services, we may use analytics functions. In particular, the following information may be processed: • Page views • Session duration • Click behavior • Browser information • Device information • Approximate geographic region • Anonymized or truncated IP address Analytics functions are activated exclusively if you have previously given your consent. Individual users are generally not identified in this process.
9. Registration and User Account
For certain Services – in particular re:one – creating a user account is required. In particular, the following data may be processed: • Name • Email address • Encrypted password • Profile information • Language settings • Time zone • Account settings This data serves exclusively to provide the user account, authentication, and the security of our Services. The legal basis is Art. 6(1)(b) GDPR.
10. Contact
When you contact us by email or via a contact form, we process your information exclusively to handle your inquiry. This concerns in particular: • Name • Email address • Content of your message • Voluntarily provided information The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR. The data will be deleted once it is no longer required for the respective purpose and no statutory retention obligations apply.
11. Data Security
Valend takes appropriate technical and organizational measures to protect personal data from loss, misuse, manipulation, unauthorized access, alteration, disclosure, or other unlawful processing. These include in particular: • encrypted data transmission using TLS/SSL, • role-based access and permission concepts, • access restrictions, • regular security updates and security reviews, • logging of security-relevant events, • measures to secure and restore the availability of data. The security measures are regularly reviewed and further developed in line with technological progress. Despite appropriate technical and organizational measures, complete security for data transmission over the internet cannot be guaranteed.
12. Login via Google (Google OAuth)
Authentication via a Google account can be used to log in to our Services. The provider of the Google services for users within the European Economic Area is: Google Ireland Limited Gordon House Barrow Street Dublin 4 Ireland Access is granted via the OAuth 2.0 protocol. re:one does not receive the password of the Google account, but only the authentication information and permissions released by the user. Depending on the permissions you have granted, the following data may be processed: • Name • Email address • Google account ID • Profile picture (optional) • Authentication information The login serves exclusively for authentication and the provision of your user account. The legal basis is Art. 6(1)(b) GDPR. Further information can be found in Google's privacy policy: https://policies.google.com/privacy
13. Login via Microsoft
Alternatively, login via a Microsoft account can be used. The provider of the Microsoft services for users within the European Economic Area is: Microsoft Ireland Operations Limited One Microsoft Place South County Business Park Leopardstown Dublin 18 Ireland Access is granted via the OAuth 2.0 or OpenID Connect protocol. re:one does not receive the password of the Microsoft account, but only the authentication information and permissions released by the user. In particular, the following data may be processed: • Name • Email address • Microsoft account ID • Profile information • Authentication information The processing serves exclusively for login and management of your user account. The legal basis is Art. 6(1)(b) GDPR. Further information can be found in Microsoft's privacy policy: https://privacy.microsoft.com/
14. Google Drive
When you connect Google Drive with re:one, Valend processes exclusively the data that is necessary for the functions you have expressly requested. Depending on usage, this may include in particular: • File names • Folder structure • Metadata • Document content • Sharing settings Access is granted exclusively after your express consent. Valend processes this data exclusively to provide the desired functions. The connection to Google Drive is voluntary and is only established after the user has granted the corresponding permissions. The legal basis for processing is Art. 6(1)(b) GDPR insofar as the processing is necessary to provide the functions expressly requested by the user.
15. Gmail
When you connect your Gmail account, re:one may process email data depending on the permissions you have granted. This may include in particular: • Sender • Recipient • Subject • Time of sending • Message body • Attachments • Markings and labels This data is processed exclusively to provide the functions you requested. Valend does not use Gmail data for advertising purposes and does not sell it to third parties. The connection to Gmail is voluntary and is only established after the user has granted the corresponding permissions. The legal basis for processing is Art. 6(1)(b) GDPR insofar as the processing is necessary to provide the functions expressly requested by the user.
16. Google Calendar
When you connect Google Calendar, in particular the following data may be processed: • Appointments • Start and end • Participants • Locations • Descriptions • Reminders The processing serves exclusively to provide the desired functions within re:one. The connection to Google Calendar is voluntary and is only established after the user has granted the corresponding permissions. The legal basis for processing is Art. 6(1)(b) GDPR insofar as the processing is necessary to provide the functions expressly requested by the user.
17. Microsoft 365
If you connect Microsoft services with re:one, depending on the permissions you have granted, in particular the following data may be processed: • Outlook emails • Calendar • Contacts • OneDrive files • Microsoft Teams information The processing is carried out exclusively within the framework of the functions you use. The connection to Microsoft 365 is voluntary and is only established after the user has granted the corresponding permissions. The legal basis for processing is Art. 6(1)(b) GDPR insofar as the processing is necessary to provide the functions expressly requested by the user.
18. APIs and Third Parties
Our Services can be connected to third-party applications and services. Which data is processed depends on the respective integrations and the permissions you have granted. The processing is carried out exclusively to provide the desired functions. For the processing of personal data by third-party providers, their respective privacy policies apply additionally.
19. Permissions and Revocation
You decide for yourself which integrations you connect to your user account. Permissions already granted can be revoked at any time via the settings of your respective third-party provider or within the corresponding application. After revocation, no new data will be processed via the relevant integration. Data already stored will be deleted or anonymized in accordance with statutory requirements and the retention periods described in this privacy policy. Users can disconnect their Google or Microsoft connection at any time within re:one or via the security and permission settings of their respective account. Insofar as no statutory retention obligations conflict, the personal data stored from the respective integration will be deleted or anonymized after revocation or after deletion of the user account.
Use of Google User Data
The use and transmission of information that re:one receives via Google APIs is carried out in accordance with the Google API Services User Data Policy and the Limited Use requirements contained therein. Google user data is used exclusively to provide or improve the functions expressly requested by the user and visible within re:one. Google user data is in particular not: • sold, • used for personalized advertising or retargeting, • passed on to data brokers or advertising platforms, • used to assess creditworthiness, • or used to train or improve general AI or machine learning models. Access by humans occurs only if the user has expressly consented, this is necessary for security reasons, or a statutory obligation exists.
20. Data Minimization
Valend processes exclusively the personal data that is necessary to provide the respectively used functions. We are guided by the principle of data minimization in accordance with Art. 5(1)(c) GDPR and limit access to what is necessary. Where technically possible, data is processed in pseudonymized or anonymized form.
21. Artificial Intelligence (AI)
Individual Services of Valend, in particular re:one, use artificial intelligence (AI) functions to support users in organizing, processing, and analyzing information. Depending on the function used, in particular the following data may be processed: • Text inputs • Documents • Notes • Emails • Contacts • Calendar information • Tasks • Metadata • Other content provided by the user The processing is carried out exclusively to provide the functions requested by the user. Personal data is not used to train proprietary AI models unless this is expressly stated and separately approved by the user. The legal basis is Art. 6(1)(b) GDPR and, where required, Art. 6(1)(a) GDPR.
22. Uploaded Files and Documents
Users can store or process documents, files, images, and other content in re:one. This data is processed exclusively to provide the desired functions, to store content, to synchronize it, and to make it accessible to the user within their account. Valend claims no ownership rights to the content uploaded by the user.
23. Contacts, Calendar, and Tasks
If users use corresponding functions or activate integrations, contacts, appointments, tasks, and other organizational data may be processed. This processing is carried out exclusively to provide the functions requested by the user. This data is not passed on to third parties unless this is technically necessary or legally required.
24. Communication Within the Services
Insofar as our Services provide communication functions, messages, comments, file shares, and similar content may be processed. The processing is carried out exclusively to provide the respective function and to ensure the security of our Services.
25. Data Processors
Valend uses carefully selected service providers who process personal data exclusively on our behalf and according to our instructions. Where legally required, data processing agreements in accordance with Art. 28 GDPR are concluded with these service providers.
26. Recipients of Personal Data
Personal data is generally not sold to third parties or passed on for advertising purposes. Transfer takes place exclusively • when this is necessary for the fulfillment of a contract, • when you have expressly consented, • when we are legally obliged to do so, • or when service providers process personal data as part of data processing.
27. International Data Transfers
Where personal data is processed outside the European Union or the European Economic Area, this is done exclusively in compliance with the statutory requirements of the GDPR. This is done in particular on the basis of • an adequacy decision by the European Commission, • the Standard Contractual Clauses of the European Commission, • or another legally permissible basis in accordance with Art. 44 et seq. GDPR.
28. Retention Period
Personal data is stored only for as long as is necessary to fulfill the respective processing purpose or as long as statutory retention obligations exist. Once the respective purpose no longer applies, personal data will be deleted or anonymized unless statutory obligations conflict with deletion.
29. Your Rights as a Data Subject
You have the following rights under the General Data Protection Regulation (GDPR): • Right of access in accordance with Art. 15 GDPR • Right to rectification in accordance with Art. 16 GDPR • Right to erasure in accordance with Art. 17 GDPR • Right to restriction of processing in accordance with Art. 18 GDPR • Right to data portability in accordance with Art. 20 GDPR • Right to object to processing in accordance with Art. 21 GDPR • Right to revoke consent given in accordance with Art. 7(3) GDPR with effect for the future To exercise your rights, a simple informal message to: Email: contact@valend.de is sufficient.
30. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The data protection supervisory authority responsible for Valend is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Wilhelmstraße 7 65185 Wiesbaden Germany Email: poststelle@datenschutz.hessen.de Website: https://datenschutz.hessen.de
31. Data Protection Officer
Currently, there is no legal obligation for Valend to appoint a data protection officer. If a legal obligation arises in the future or a data protection officer is appointed voluntarily, the corresponding contact details will be published in this privacy policy.
32. Automated Decisions
A decision based solely on automated processing within the meaning of Art. 22 GDPR does not generally take place. Insofar as individual functions include automated decisions or profiling in the future, affected users will be informed separately.
33. Changes to This Privacy Policy
Valend reserves the right to adapt this privacy policy if this becomes necessary due to legal changes, technical developments, new functions, or changed processing processes. The version published at the time of your visit applies in each case. Registered users will be informed of material changes in an appropriate manner.
34. Contact
If you have questions about data protection, the processing of your personal data, or the exercise of your data protection rights, you can contact the controller named in Section 1 at any time.