Privacy Policy
Last updated: 1 August 2026
1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) and other data protection provisions is:
Maximilian Gürke
Oberdorf 31
99947 Bad Langensalza
Germany
Email: kontakt@maximilian-guerke.de
2. Scope
This privacy policy applies to the marketing website at https://cadruno.com and the application at https://app.cadruno.com (together, “Cadruno”).
3. Hosting (website)
The marketing website is hosted by:
Unesty
Geschwister-Scholl-Platz 5
09648 Mittweida
Germany
Unless stated otherwise, user data is processed in Germany / the European Economic Area.
4. Application infrastructure
The Cadruno application uses Supabase (database, authentication, storage) with project infrastructure in the EU. Payment processing is handled by Stripe. Where processors act as processors under Art. 28 GDPR, processing is based on data processing agreements and, where required, appropriate transfer safeguards.
5. Data processed when you visit the website
When you access the website, your browser automatically sends information to the server. The following data may be stored temporarily in server log files: IP address of the requesting device; date and time of access; name and URL of the retrieved file; referrer URL; browser and operating system; name of your access provider.
Processing is based on Art. 6 (1) lit. f GDPR (legitimate interest in the secure, stable, and optimized operation of the website). These data are not merged with other data sources for profiling.
6. Reach measurement (Plausible)
The marketing website uses Plausible Analytics, a cookieless analytics service that does not build personal profiles. Individual persons are not tracked. Processing is based on Art. 6 (1) lit. f GDPR (legitimate interest in understanding aggregated usage of the site).
7. Cookies
The marketing website does not use cookies for advertising or behavioural profiling. The application may set strictly necessary cookies or local storage entries for authentication, session security, and essential preferences. Where non-essential cookies would be used, we ask for consent under Art. 6 (1) lit. a GDPR.
8. Account, analyses, and contact
If you create an account or save analyses, we process account data (email address, authentication identifiers), usage and plan data, and the property and calculation inputs you submit, in order to provide the service (Art. 6 (1) lit. b GDPR).
If you contact us by email, we process the data you send (email address, name if provided, message content) to handle your request (Art. 6 (1) lit. b or lit. f GDPR; where consent is required, Art. 6 (1) lit. a GDPR). You may withdraw consent at any time with effect for the future.
9. Payments
Paid plans are billed via Stripe. Card and billing data are processed by Stripe as an independent controller or processor according to Stripe’s terms. We receive payment status, customer and subscription identifiers, and invoice-related data needed for contract performance and bookkeeping (Art. 6 (1) lit. b and lit. c GDPR; VAT obligations under the UStG).
10. Retention
Server logs are kept only as long as needed for security and operations, then deleted or anonymised. Account and analysis data are retained for the duration of the contract and deleted or anonymised after account closure, unless longer retention is required by law (for example commercial and tax retention under the German Fiscal Code, AO, and related commercial rules). Contact emails are kept until the request is resolved and for a short follow-up period, unless longer retention is required.
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and to object to processing based on legitimate interests (Art. 21 GDPR). Where processing is based on consent, you may withdraw that consent at any time (Art. 7 (3) GDPR).
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For Thuringia, Germany, this is the Thüringer Landesbeauftragte für den Datenschutz und die Informationsfreiheit.
12. Security
Cadruno uses TLS/SSL encryption in transit. You can recognise an encrypted connection by “https://” in the browser address bar.
13. No automated decisions with legal effect
Cadruno does not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. Analysis outputs are decision aids; you remain responsible for your own investment and tax decisions.