Privacy notice
Deutsche Fassung: Datenschutzerklärung
Trade Fair Follow-up turns an exhibitor's own follow-up texts into one e-mail per trade-fair lead, for the exhibitor to send. Two kinds of personal data pass through it: the details of the people who use an exhibitor's account, and the leads the exhibitor uploads.
Who is responsible
For account data the controller is Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. Questions about your data: privacy@vitersoft.com. We have not appointed a representative in the EU.
For leads, the exhibitor who uploaded them is the controller, and we process them on its documented instructions as its processor (Art. 28 GDPR, see our processing terms). If you were a visitor at a stand and want to know what happens to your data, ask the exhibitor; we will help them answer. We never e-mail leads.
What is processed, why, on what basis
- Order and account: company, country, your name and work e-mail, the fair you order for — to run the order and your account (Art. 6(1)(b) GDPR).
- Your texts: sender name and address, the consent wording used at your stand, topics, products and e-mail texts — to make the e-mails you asked for (Art. 6(1)(b) GDPR).
- Leads (as your processor): name, e-mail, company, job title, country, language, consent record, notes, topic and product — read from your export in your browser; the original file is kept in private storage.
- Usage statistics: counts and categories, never a lead and never a name (Art. 6(1)(f) GDPR, our interest in knowing whether the service works).
We do not store IP addresses. No automated decision about anyone is made. We do not sell or share personal data.
How long
The uploaded original export is deleted automatically 30 days after upload. Leads and the translations made for them are deleted automatically 90 days after the fair ends, or earlier when the exhibitor removes them. Orders, texts and the accepted terms stay until the account is deleted. The owner can delete the account in settings at any time: that removes everything at once, and we count each of our tables and the storage afterwards to confirm nothing is left. An account nobody ever signed in to is removed after 30 days. Sign-in links are stored only as a hash and removed within a day of expiring.
Who else receives it
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA — runs the application. Function logs (time, address, status, errors — no form content) are kept for up to 7 days. For transfers to the USA, Cloudflare states that it relies on its certification under the EU-U.S. Data Privacy Framework and, as a fallback, the EU Standard Contractual Clauses.
- Supabase (database and private file storage in Frankfurt, EU). Only our server can read them.
- Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (Paris trade register 498 019 298, trading as Brevo), as processor — sends the account's sign-in links and reminders to the exhibitor only; no message carries a lead. Brevo's sub-processors may process data outside the EEA, including the USA, Canada, Serbia and India, on Standard Contractual Clauses, the Data Privacy Framework or an adequacy decision. Brevo puts an invisible image in every letter, so it registers when a letter is opened; we cannot switch that off per message.
- OpenRouter, Inc. (USA) — only when the exhibitor asks for a translation: the exhibitor's own texts with their placeholders, nothing about any lead. Requests are routed only to model providers that retain nothing (zero data retention). We have no separate data processing agreement with OpenRouter; an exhibitor who does not want its texts to go there writes the translation by hand.
- PostHog (EU cloud, Germany) — the usage counts above, without cookies or profiles.
Cookies
One: the sign-in cookie, which holds the account and the person and nothing else. The statistics run without cookies and without local storage.
Your rights
You may ask for access, correction, deletion, restriction, portability and object to processing (Art. 15–21 GDPR); deletion you can do yourself in settings. Write to privacy@vitersoft.com or tradefair@vitersoft.com. You may complain to any data protection supervisory authority (Art. 77 GDPR), for example the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Datenschutzerklärung
1. Verantwortlicher
Für Kontodaten: Armen Sarkisian, Komitas 57, 0032 Yerevan, Armenia. E-Mail: privacy@vitersoft.com. Ein Vertreter in der EU (Art. 27 DSGVO) ist nicht benannt. Für die hochgeladenen Leads ist der Aussteller Verantwortlicher; wir verarbeiten sie als Auftragsverarbeiter nach seinen dokumentierten Weisungen (Art. 28 DSGVO). Wir schreiben Leads nie an.
2. Verarbeitete Daten, Zwecke, Rechtsgrundlagen
Für Bestellung und Konto: Firma, Land, Ihr Name, Ihre geschäftliche E-Mail-Adresse und die Messe (Art. 6 Abs. 1 lit. b DSGVO). Ihre Texte: Absender, Wortlaut der Einwilligung am Stand, Themen, Produkte, E-Mail-Texte (Art. 6 Abs. 1 lit. b DSGVO). Leads im Auftrag: Name, E-Mail, Firma, Funktion, Land, Sprache, Einwilligungsnachweis, Notizen, Thema und Produkt — im Browser gelesen, die Originaldatei privat gespeichert. Nutzungsstatistik ohne Cookies, ohne Profile und ohne Lead-Daten (Art. 6 Abs. 1 lit. f DSGVO). IP-Adressen speichern wir nicht. Eine automatisierte Entscheidung findet nicht statt. Wir verkaufen keine Daten.
3. Speicherdauer
Die hochgeladene Originaldatei wird 30 Tage nach dem Hochladen automatisch gelöscht, Leads und ihre Übersetzungen 90 Tage nach Messeende oder früher durch den Aussteller. Bestellungen, Texte und akzeptierte Bedingungen bleiben bis zur Löschung des Kontos, die die Inhaberin oder der Inhaber jederzeit in den Einstellungen vornehmen kann. Konten ohne Anmeldung löschen wir nach 30 Tagen; Anmeldelinks speichern wir nur als Hashwert und löschen sie spätestens einen Tag nach Ablauf.
4. Empfänger
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Betrieb der Anwendung; Funktionsprotokolle ohne Formularinhalte bis zu 7 Tage). Für Übermittlungen in die USA stützt sich Cloudflare nach eigenen Angaben auf das EU-U.S. Data Privacy Framework und ergänzend auf die EU-Standardvertragsklauseln.
- Supabase (Datenbank und privater Dateispeicher in Frankfurt, EU).
- Sendinblue, vereinfachte Aktiengesellschaft französischen Rechts, 9-17 rue Salneuve, 75017 Paris, Frankreich, Handels- und Gesellschaftsregister Paris Nr. 498 019 298 (Brevo), als Auftragsverarbeiter für Anmeldelinks und Erinnerungen an den Aussteller — nie an Leads. Unterauftragsverarbeiter können Daten auch außerhalb des EWR verarbeiten, u. a. in den USA, Kanada, Serbien und Indien; Grundlage sind Standardvertragsklauseln, das Data Privacy Framework oder ein Angemessenheitsbeschluss. Brevo registriert über ein unsichtbares Bild, wann eine E-Mail geöffnet wird.
- OpenRouter, Inc. (USA), nur wenn der Aussteller eine Übersetzung anfordert: seine eigenen Texte mit Platzhaltern, keine Lead-Daten; nur an Anbieter ohne Datenspeicherung. Ein gesonderter Auftragsverarbeitungsvertrag mit OpenRouter besteht nicht; wer das nicht möchte, übersetzt von Hand.
- PostHog (EU-Cloud, Deutschland), Nutzungsstatistik ohne Cookies und Profile.
5. Cookies
Nur das Anmelde-Cookie mit Konto und Person. Die Statistik nutzt weder Cookies noch lokalen Speicher.
6. Ihre Rechte
Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch (Art. 15–21 DSGVO); die Löschung können Sie selbst in den Einstellungen vornehmen. Anfragen an privacy@vitersoft.com. Beschwerde bei einer Datenschutz-Aufsichtsbehörde (Art. 77 DSGVO), etwa der Berliner Beauftragten für Datenschutz und Informationsfreiheit. Keine Rechtsberatung.