This is a translation for your convenience. The German version is the legally binding one.
NewEase AG
Bahnhofstrasse 1, 47574 Goch, Germany
info@newease.ag
Freyberg Consulting
Felix Freyberg
Mandrellaplatz 3
12555 Berlin, Germany
Email: kontakt@felix-freyberg.de
This policy covers two different things, and our position differs between them:
Our own pages and our contract with you. When you visit claritos.io, fill in a form, place an order or create a user account, we decide what happens to your data. We are the controller within the meaning of the GDPR. Sections 4 to 13 and 17 to 25 cover this.
Our customers' content inside the application. When a business uses claritos for its tasks, documents, bookkeeping, contacts or records, that business decides which data it processes there and why. We merely carry it out on their instructions (Art. 28 GDPR). If you are a customer, patient or business partner of such a business and want to know what happens to your data, that business is your point of contact, not us. Section 14 covers this.
We process personal data only to the extent necessary for the respective purpose. The legal bases are Art. 6(1)(b) GDPR (initiation and performance of a contract), Art. 6(1)(c) GDPR (legal obligations, such as retention for tax purposes), Art. 6(1)(f) GDPR (legitimate interest in secure operation) and, where we ask you expressly, Art. 6(1)(a) GDPR (consent).
When you visit our pages, we process the data your browser transmits and that is technically necessary for delivery: IP address, date and time, the address requested, the volume of data transferred, the status message, browser type and version, operating system and the referring page, if your browser sends it. This data is recorded in the logs of our hosting provider, serves secure operation (Art. 6(1)(f) GDPR), is not merged with other records and is deleted after a short period.
We measure the use of our pages with our own count, operated on our own servers. We record page views, clicks, scroll depth and time spent. This data does not leave our infrastructure; we pass it to no one and do not combine it with data from other providers.
So that we do not count returning visits twice and can show you the same page variant, we store a random identifier in your browser. This only happens if you have consented. The identifier is then kept for up to one year. Without your consent we use an identifier that ends when you close your browser — it merely holds the current page delivery together and does not recognise you on a later visit.
The legal basis is your consent (Art. 6(1)(a) GDPR together with § 25(1) TDDDG). You may withdraw it at any time — via the round symbol at the bottom left of every page. Withdrawal takes effect immediately and deletes the stored identifier; the lawfulness of processing up to that point is unaffected.
We record your decision itself because we must be able to prove it (Art. 7(1) GDPR). Stored are: the time, the purposes you chose, the wording shown to you, the page you were on, the language, and a shortened note of browser and operating system. We do not store your IP address. Instead we keep an irreversible check value with which, in a dispute, it can only be verified whether a particular address consented on that day. We delete these records after three years.
Necessary, without consent: cookies for signing in and for the basket during an order — they are protected by the server (httpOnly) and end with the session. In addition, the record of your privacy decision itself, because without it we would have to ask you again on every visit. The legal basis is § 25(2) no. 2 TDDDG: without this storage the service you requested could not be provided.
Only with your consent: the audience-measurement identifier from section 6, stored for up to one year.
We set no advertising cookies on these pages, and no third-party services are embedded that report your behaviour to themselves. Customers may embed an advertising measurement tool in pages built with claritos; where that happens, it is named explicitly in that page's consent dialog — together with the recipient of the data — and likewise runs only after consent.
When you fill in a form, we process the data you provide in order to handle your enquiry and to contact you (Art. 6(1)(b) GDPR). Mandatory fields are marked as such; everything else is voluntary. A one-time code may be sent to confirm your email address.
For orders we process your order and invoicing data to perform the contract (Art. 6(1)(b) GDPR) and retain the records to the extent required by law (Art. 6(1)(c) GDPR, sections 147 AO and 257 HGB — as a rule ten years).
Payments are handled by Stripe Payments Europe, Ltd. (Ireland). You enter your payment details — card or account data — directly there; they do not reach our servers. From Stripe we receive only the information whether and how payment was made.
We use an electronic signature for contracts and agreements. For evidentiary purposes we record who signed when and from which IP address, and we send a confirmation code to your email address — at a higher level of assurance additionally by SMS to your mobile number. These details become part of the audit trail of the signed document (Art. 6(1)(b) and (f) GDPR).
The SMS code is generated and sent by Twilio Inc. on our behalf. For signatures with a seal, a certification authority (SSL.com) is additionally involved, which issues the seal; it acts as an independent controller for that purpose.
If you apply as a sales partner, we process your application and contract data in order to review and carry out the cooperation (Art. 6(1)(b) GDPR). In the partner area you sign in with a code that we send to your email address. Commission statements are subject to statutory retention periods.
For payouts we transmit the details required — name, address, bank details and the amount — to our payment service providers Qonto (Olinda SAS, France) and Wise Europe SA (Belgium). Which route is used depends on the destination country and the currency.
To use claritos we create an account. We process your name, email address, a password hash (we do not know the password itself), optionally a profile picture, your language preference and your membership of one or more organisations including your role there (Art. 6(1)(b) GDPR).
We set a session cookie for signing in. To protect access, we store when you signed in.
You can delete your account yourself in your profile settings. Section 21 explains what is deleted and what has to remain for legal reasons.
You can sign in to claritos with your Google account and connect your Gmail mailbox to claritos. Both are voluntary; claritos can be used in full without a Google account.
Signing in with Google. If you sign in with Google, we receive your identifier, your email address, your name and, if stored, your profile picture from Google. We use this information solely to create your user account and to recognise you (Art. 6(1)(b) GDPR).
Sending from your mailbox. If you connect your Gmail mailbox, you can send emails — invoices, quotes or letters, for instance — directly from your own mailbox instead of through a third-party sender address. For this we request the permission to send only. We have no read access to your mailbox: we do not retrieve your messages, do not search them and do not analyse them. The only thing transmitted to Google is the message whose sending you initiate in claritos, together with its attachments.
What we store. For the connection we store the access credentials issued by Google in encrypted form, along with the address of the connected mailbox. If you disconnect, we delete these credentials.
How to end the connection. You can disconnect at any time in the claritos settings. Independently of that, you can withdraw access at any time in the security settings of your Google account (google.com/account → Security → Third-party apps with account access).
Limited use of Google user data. claritos' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In detail: we use this information solely for the features you visibly use in claritos. We do not pass it on to third parties, except where necessary for the feature you requested, for security reasons — such as investigating abuse — or to comply with a legal obligation. We do not use it for advertising and we do not sell it. We do not allow humans to read it, unless you have expressly consented, it is necessary for security or to comply with a legal obligation, or the data is aggregated and anonymised.
Inside claritos, our customers process their own data: tasks, projects, times, contacts, documents, bookkeeping entries, invoices, reminders, correspondence, forms, contracts and — depending on the business — client or patient records containing health data.
For this content the respective customer is the controller. We process it solely on their behalf and on their instructions (Art. 28 GDPR), on the basis of a data processing agreement that we make available to every customer.
We do not analyse this content for our own purposes, in particular not for advertising, and we do not pass it on to third parties unless a legal obligation applies or the customer requests it.
If you are a customer, patient or business partner of a business that uses claritos, please address requests for access, rectification or erasure to that business. If your request reaches us directly, we forward it to them and inform you accordingly; we are not permitted to decide on it.
Some features work by machine: text and document recognition, suggestions for assigning bookkeeping entries, translations, drafting assistance and the reading of laboratory reports. For this, the content concerned is transmitted to a language-model service and processed there.
We use the Vercel AI Gateway for this, through which requests go to Anthropic PBC (USA) and Google. The transmitted content is not used there to train models.
What is generated by machine are suggestions. They are reviewed by a human before being adopted; no automated decision within the meaning of Art. 22 GDPR takes place.
For converting Office files to PDF we use CloudConvert (EU region).
claritos can be connected to further services. The customer establishes these connections themselves by granting the respective access — usually under their own contract with the provider. Only then is data transmitted there, and only the data the respective feature requires:
Google — sign-in and sending from your own mailbox (section 13).
Zoom Video Communications — import of meetings and their summaries.
Pingen AG (Switzerland) and LetterXpress (Germany) — sending physical letters and registered mail. The recipient's address and the content of the letter are transmitted, because that is precisely what is printed and delivered.
MailCheap (Cyberlabs, Inc., Delaware, USA — data held in Germany) — mailboxes in the partner area. The emails are transmitted together with sender, recipient and content, because the service delivers and stores them.
GoHighLevel — handover of contacts and triggers to an account held there.
Meta Platforms — measurement of advertising performance, if the customer provides an advertising account.
The respective provider's own privacy policy applies to processing on their side. We store the access credentials in encrypted form and delete them when the connection is ended.
An organisation can download its data as an archive — tables as CSV, documents in their original form, plus a part that can be evaluated for tax purposes. This serves the fulfilment of its own retention obligations and a change of provider (Art. 6(1)(b) and (c) GDPR).
What you should know about this:
Such an archive contains personal data of the organisation's contacts, clients and business partners — depending on the business, health data as well.
Only whoever administers the organisation may start it. Every run and every later download is logged.
Access credentials are not included. Passwords, keys and tokens for connected services are expressly left out.
The download link is sent by email to the addresses the organisation enters for this purpose — which may include people outside it, such as their tax advisers. Whoever holds the link can reach the archive; the organisation decides who receives it.
The archive can be encrypted with a password. The organisation sets the password itself; it never appears in the delivery email.
After 30 days the link expires, and we delete the archive from our storage.
This is to be distinguished from our own operational backup: we back up the entire platform in encrypted form with a provider-independent storage service (Backblaze) so that we can restore it after an outage. This backup is not accessible to anyone and serves solely secure operation (Art. 6(1)(f) GDPR).
In addition to the logs of our hosting provider (section 5), claritos keeps its own event log: errors and security-relevant events — incoming interface calls, triggered backups or failed background processing, for instance. It contains as little personal information as possible, as a rule only internal identifiers. These entries are deleted after 90 days. The legal basis is our legitimate interest in secure and traceable operation (Art. 6(1)(f) GDPR).
We use service providers who process data solely on our behalf and on our instructions (processing on behalf of a controller pursuant to Art. 28 GDPR):
Vercel Inc. (USA), execution in the EU — operation and delivery of the pages. The server functions run exclusively in European data centres (Frankfurt, Paris, Dublin). Delivery of the pages themselves runs over a worldwide network; the log data named in section 5 arises in the process, depending on your location also outside the EU.
Supabase Inc. (USA), data held in Frankfurt am Main — database.
Cloudflare, Inc. (USA), storage jurisdiction European Union — storage and delivery of images, videos and documents. When a file is retrieved, your IP address is transmitted to this service for technical reasons.
Railway Corp. (USA), execution in Amsterdam — background processing, such as generating PDF documents, text recognition and backups.
Inngest, Inc. (USA) — orchestration of recurring jobs. Only internal identifiers are transmitted.
Plus Five Five, Inc. ("Resend", USA), sending from Ireland — sending our emails.
Backblaze, Inc. (USA), storage in the EU region (EU Central) — encrypted backups.
CloudConvert (EU region) — conversion of Office files to PDF.
Anthropic PBC (USA) and Google, via the Vercel AI Gateway — machine processing pursuant to section 15.
Twilio Inc. (USA) — sending the SMS code at a higher level of assurance for the electronic signature.
Google Ireland Limited (Ireland) — signing in with Google and sending emails from the user's mailbox, where the user has established the connection. See section 13.
Acting as independent controllers, that is, not on our behalf:
Stripe Payments Europe, Ltd. (Ireland) — payment processing.
SSL.com — issuing the seal for the electronic signature.
Qonto (Olinda SAS, France) and Wise Europe SA (Belgium) — payouts in the partner programme (section 11).
Only if a customer connects them themselves do the following come into play (section 16): Zoom Video Communications, Pingen AG (Switzerland), LetterXpress (Germany), MailCheap (Cyberlabs, Inc.), GoHighLevel and Meta Platforms. Without such a connection, no data flows to them.
Corresponding agreements are in place with all processors.
Where service providers process data outside the European Union, this takes place on the basis of the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) with supplementary safeguards, or on the basis of an adequacy decision.
Every provider that stores your data processes it in the EU — including those whose company is based in the USA:
Vercel — server functions in Frankfurt, Paris and Dublin.
Supabase — database in Frankfurt am Main.
Cloudflare R2 — file storage with the jurisdiction "European Union".
Railway — background processing in Amsterdam.
MailCheap/Cyberlabs — mailboxes in Germany.
Resend — email sending from Ireland.
Backblaze — encrypted operational backups in the EU region.
Your content — documents, bookkeeping entries, contacts, records, files — is therefore stored exclusively in the EU, backup copies included. For the event of access under US law, the standard contractual clauses apply in addition.
Three routes do leave the EU, and we name them expressly:
Delivery of the pages runs over a worldwide network so that pages appear quickly everywhere. The log data from section 5 arises in the process — essentially your IP address and the address requested — at a node outside the EU depending on your location. No content is involved.
Machine processing (section 15) transmits the content concerned to Anthropic PBC and Google in the USA. This concerns actual content — the text of a document to be read, for instance. It happens only for the features named there and only with what the respective feature requires.
The SMS code at a higher level of assurance for the electronic signature (section 10) goes via Twilio in the USA; your mobile number is transmitted in the process.
For Switzerland, where the letter-sending provider Pingen is based, an adequacy decision of the European Commission exists; a transfer there therefore requires no additional safeguards.
We store personal data only for as long as is necessary for the respective purpose. It is then deleted, unless a statutory retention obligation applies. In detail:
Event log of the application: 90 days (section 18).
Backup archives: 30 days (section 17).
Documents, bookkeeping entries and invoices: according to commercial and tax retention obligations, as a rule ten years (sections 147 AO, 257 HGB).
User account and content: until deleted by you or until the end of the contract with the business they belong to.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interests (Art. 21). You may withdraw consent at any time with effect for the future.
Where your rights concern content that a business processes in claritos, that business is your point of contact (section 14).
You may lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf, Germany
Phone: +49 (0)211 / 38424 - 0
Our pages may refer to third-party websites. The respective providers are solely responsible for their content and data processing.
We adapt this policy when the processing described here changes. Last updated: September 12, 2026.
