Last updated: July 30, 2026
This policy explains which personal data we process when you visit our websites at saasflow.com (the "Websites") or use the SaaSFlow application at app.saasflow.com (the "Services"), why we process it, who receives it, and which rights you have. We have tried to write it so you can actually read it.
Who is responsible
The controller for the processing described here is:
Walletguide GmbH
Rüggeberger Str. 94
58256 Ennepetal
Germany
Represented by Alexander Peiniger (CEO and Managing Director)
[email protected]
When we act as a processor instead
SaaSFlow analyzes the financial data of your company: transactions, customers, subscriptions, bank accounts and the people appearing in that data. For this data, your company is the controller and we are the processor under Art. 28 GDPR. That processing is governed by our Data Processing Agreement, including its annexes on security measures and sub-processors. The rest of this policy describes the processing for which we ourselves are the controller.
What we process, why, and on which legal basis
Account and profile data
When you sign up or are invited to a company workspace, we process your name, email address, role and sign-in data to create and secure your account and provide the Services. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Payment data
For paid plans, you provide payment information to us and our payment provider Stripe (see our sub-processor list), which lets us charge recurring fees. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Support and communication
When you contact us by email or through the support chat, we process the content of the conversation and your contact details to resolve your request. Legal basis: performance of a contract and our legitimate interest in good support (Art. 6(1)(b) and (f) GDPR).
Website visits
When you visit the Websites, our servers process technical connection data (IP address, requested pages, browser type) to deliver the pages and keep them secure. Our web analytics are cookie-less and aggregate page views without identifying you. Legal basis: our legitimate interest in operating and securing the Websites (Art. 6(1)(f) GDPR).
Ad measurement
We advertise on platforms such as Google Ads. If you arrive through one of our ads, we store the ad click identifier in a first-party cookie and, if you later sign up, report the conversion back to the advertising platform from our servers. We do not embed advertising pixels or third-party tracking scripts, and we do not build remarketing audiences from your browsing behavior. Details are in our cookie policy. Legal basis: our legitimate interest in measuring whether our advertising works (Art. 6(1)(f) GDPR).
Newsletter
If you subscribe to our newsletter, we use your email address to send it until you unsubscribe. Every newsletter contains an unsubscribe link. Legal basis: consent (Art. 6(1)(a) GDPR).
Error monitoring
Inside the Services, we use Sentry to diagnose errors. It only runs after you have accepted the corresponding category in the consent dialog of the Services, and it is listed in our sub-processor list. Legal basis: consent (Art. 6(1)(a) GDPR), revocable at any time in the cookie settings of the Services.
AI processing
Some features of the Services use large language models to analyze your company data: the monthly performance report, the report chat, and categorization suggestions. These features never run on their own. Someone in your company has to approve each AI provider inside the product first, in a dialog that names the provider, the model, where the data is processed, and which data categories are shared. When a run starts, the financial data the feature analyzes (for example transactions, customers, subscriptions, and account balances) is sent to that provider and processed there. We currently work with Anthropic (US) and Cursor/xAI (US) for these features; both are included in our sub-processor list with further details. An approval can be withdrawn at any time in the product settings, which blocks new runs.
Who receives your data
We use service providers for hosting, banking connectivity, payments, email delivery, support and the features described above. Every provider that processes personal data for us is bound by a data processing agreement, and all of them are published with purpose, location and transfer safeguards in our sub-processor list. We do not sell personal data.
Beyond that, we only share personal data if a merger, acquisition or financing of the SaaSFlow business requires it (we would notify you), or if we are legally obliged to, for example by a court order or a lawful request from an authority.
International transfers
Our application data is hosted in the EU. Some of our providers are US companies; for them we rely on their certification under the EU-US Data Privacy Framework where it exists, and additionally on the EU Commission's Standard Contractual Clauses, so that a valid transfer mechanism remains in place either way. The safeguard per provider is stated in the sub-processor list.
How we secure your data
We protect your data with technical and organizational measures appropriate to the risk: encrypted transmission, encryption at rest, strict access controls, tenant separation and regular reviews. The full set is published as Annex 2 of our Data Processing Agreement.
How long we keep your data
We keep personal data only as long as we need it for the purpose it was collected for; the retention period therefore differs by use case. Where possible, we apply a general rule: personal data is deleted or anonymized if you have not used our Websites and Services for more than 9 months. Exceptions apply where technical limitations prevent this or where laws require longer storage, for example tax rules for retaining documents. Deletion after the end of a company contract follows § 9 of the Data Processing Agreement.
Your rights
You have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict its processing, and to receive it in a machine-readable format. If processing is based on your consent, you can withdraw the consent at any time with effect for the future.
Where processing is based on our legitimate interest, you can object at any time for reasons arising from your particular situation (Art. 21 GDPR).
Much of this you can do yourself in the account settings of the Services. For everything else, email [email protected]; we answer as soon as possible after verifying your identity. In some cases we may be limited in what we can disclose, for example where a request would reveal information about another person.
You also have the right to complain to a data protection supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen; you can also contact the authority of your own EU member state.
Minors
The Websites and Services are not directed at individuals under 16, and we do not knowingly collect their data. If you become aware that someone under 16 has provided us with personal data, please contact us and we will delete it.
Changes to this policy
If we materially change this policy, we will announce it on our website at least 30 days before the change takes effect. Continued use of the Websites and Services after that date means the new version applies.
Contact
Walletguide GmbH
Rüggeberger Str. 94
58256 Ennepetal
Germany
Represented by Alexander Peiniger
CEO and Managing Director
[email protected]