Privacy Notice · Version 1.0
Privacy & Support
FeldmannCyber Assistant is a professional, account-based service for existing FeldmannCyber customers and authorized FeldmannCyber personnel. This notice explains what personal data the iOS app and its server-side services process, on what legal basis, who receives it, and how long it is kept.
Support
For help with the app, questions about your account, bug reports, feature suggestions, or security concerns, contact us at contact@feldmanncyber.com or +49 (0)151 6275 6121.
Accounts cannot be created in the app. If you need access, a password reset, a role change, or account closure, please contact your organization administrator or use the support address above. We aim to respond to support and data-protection requests promptly.
Please report suspected unauthorized access to your account immediately using the contact details above.
1. Who we are
FeldmannCyber GmbH, Bessunger Str. 175, 64347 Griesheim, Germany (“FeldmannCyber”, “we”, “us”) provides FeldmannCyber Assistant, a mobile application and associated assistant service. You can contact us at contact@feldmanncyber.com or +49 (0)151 6275 6121.
Data-protection contact: contact@feldmanncyber.com.
2. Scope and allocation of responsibilities
This notice applies to the iOS app and the server-side services it uses. It does not replace a customer organization’s own employee or user privacy information.
FeldmannCyber acts as controller for its own account administration, platform security, service operation, app communication, and internal LeadIntel activities. Where a customer organization decides why and how its workspace content is used — for example its messages, agenda items, attachments or compliance workflow data — the customer organization may be the controller and FeldmannCyber may process that content on its documented instructions. Questions about customer-controlled content may therefore be referred to the relevant organization.
3. Who can use the app
The app is a professional, account-based service for existing FeldmannCyber customers and authorized FeldmannCyber personnel. Users cannot create an account in the app. Accounts are provisioned in advance by FeldmannCyber or an authorized organization administrator. LeadIntel is available only to authorized FeldmannCyber personnel.
4. Personal data we process
- Account and profile data
- Name, business email address, account and user identifiers, role, organization, profile image, language and preferences.
- Authentication and security data
- Password-derived authentication records, MFA status and verification events, session/token metadata, access and audit records, and security-relevant events. The app stores its bearer token in secure device storage.
- Device and notification data
- Push token, device platform and limited device/build identifiers used to deliver and troubleshoot notifications, plus notification preferences and delivery state.
- Messages and collaboration data
- Conversation subject and text, participants, drafts, mentions, reactions, read status, voice notes, uploaded photos, videos and documents, file metadata, comments and message actions.
- Agenda and workflow data
- Work packages, activities, assignments, descriptions, comments, work logs, reminders, milestones, dependencies, sign-offs, departments and attachments.
- Catalogue contributions
- Funding suggestions, vendor suggestions, saved comparisons, reviews, ratings, notes and reports submitted by users.
- Search and interaction data
- Saved vendor queries, searches recorded for audit/security purposes, and feature actions such as read receipts or workflow status changes where retained by the service.
- LeadIntel data
- Company-level business-intent and job-posting signals, company watchlists, internal notes and stages. The service is not designed to build candidate or personal recruiter profiles or to automate outreach.
- Technical data
- Server requests and operational logs necessary to provide, secure and diagnose the service. Our reverse proxy writes standard web-server access log entries, which include the requesting IP address, timestamp, requested path, response status and user agent. In addition, security and audit records may store the IP address and user agent associated with a security-relevant action, such as a sign-in, a document upload or an administrative change. The app does not integrate a crash-reporting or performance-analytics SDK, and no crash or performance telemetry is collected by us or sent to a third-party analytics provider.
The current app does not request precise or approximate device location, address-book contacts, health data or payment information, and it does not use an advertising identifier for cross-company tracking.
5. How we obtain data
We obtain data directly from users when they sign in, edit a profile, communicate, upload content, create workflow records, configure notifications, search or submit catalogue content. Organization administrators may provide account, role and organizational data. The app and our servers create security, audit, notification and interaction records when the service is used.
Funding and vendor catalogue information and company-level LeadIntel signals may come from official publications, public company sources, licensed APIs/feeds, or authorized user submissions. We do not intentionally create personal lead profiles from public sources. Where indirectly obtained personal data is retained, we assess and fulfil the information duties and exceptions under Article 14 GDPR.
6. Purposes and legal bases
Scroll the table horizontally to see all columns.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide account access and app functions | Account/profile, messages, workflow, attachments, preferences | Contract performance (Art. 6(1)(b)) where the user is party; otherwise legitimate interests or customer instructions (Art. 6(1)(f) / processor role). |
| Authenticate users and protect the service | MFA, session data, security and audit events | Legitimate interests in secure and accountable service operation (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)). |
| Deliver notifications and communications | Push token, email, reminder/message metadata | App/service functionality; legitimate interests and, where required, consent. Device permissions remain revocable. |
| Operate catalogues and review submissions | Funding/vendor suggestions, reviews, notes, saved queries | Contract performance and/or legitimate interests in providing and improving the requested service. |
| Operate internal company intelligence | Company-level signals, staff notes and watchlists | Legitimate interests in B2B business development, subject to necessity, balancing and data-minimization assessment. |
| Comply with law and defend rights | Relevant account, audit and content records | Legal obligation (Art. 6(1)(c)) and legitimate interests in establishing, exercising or defending legal claims (Art. 6(1)(f)). |
7. Device permissions
- Camera and photo library: used only when a user chooses to attach an image or photo to a message or other supported record.
- Microphone: used only when a user chooses to record a voice message.
- Notifications: used to deliver requested reminders and alerts. Notifications are not required for core app access and can be disabled in the app’s preferences and iOS Settings.
Permission can be withdrawn in iOS Settings. Withdrawing a permission stops the related device function but does not automatically erase content already uploaded; deletion can be requested as described below.
8. Recipients and service providers
Authorized personnel and authorized users of the relevant customer organization can access data according to role and tenant permissions. Core application data is stored and processed in GDPR-compliant datacenters within the European Union. Expo is used as a subprocessor only for push-notification delivery, and Apple Push Notification service (APNs) completes delivery to iOS devices. Service providers may process data only for the contracted purpose and must protect it consistently with this notice and applicable law.
For push delivery, Expo processes the user’s push token and the notification payload only as needed to deliver the notification. Notification payloads are limited to generic, non-confidential text. Apart from this delivery flow and disclosures required by law, app data is not shared with advertising networks, analytics providers, data brokers or other independent recipients. No app data is sent to an AI provider.
9. International data transfers
Core application data is stored and processed within the European Union. Push delivery is the limited exception: Expo states that end-user push tokens may be transferred to the United States, and Expo passes iOS notifications to Apple Push Notification service. Where this processing involves a transfer outside the European Economic Area, the transfer is covered by the provider’s applicable EU-U.S. Data Privacy Framework participation and/or appropriate contractual safeguards, such as the European Commission’s Standard Contractual Clauses. Copies or descriptions of the applicable safeguards can be requested using the contact details above.
10. Retention and deletion
- Access tokens stored by the app expire after approximately 24 hours unless refreshed or replaced. Secure-device tokens are removed from the device on sign-out.
- Push tokens are retained while notification delivery is enabled and the account/device registration remains valid; invalid or stale tokens are removed.
- Drafts are retained to synchronize across devices until the user sends or deletes them or the applicable workspace retention rule removes them.
- Messages, agenda records, attachments and customer workspace content are retained while the user wishes to keep using the application. They are deleted following a verified deletion request, subject to customer-controller instructions and any mandatory legal retention. Soft-deleted files are permanently removed through the production purge process.
- Audit and security records are kept while the user uses the application and only for any additional period necessary to investigate security events or meet mandatory contractual or legal obligations. They are deleted upon a verified request where no overriding requirement applies.
- Deleted data may remain in restricted backups until the normal backup rotation completes. Backups are used only for recovery and are not restored to avoid an approved deletion request.
- Account and profile data is retained while the user wishes to use the application and is deleted after a verified account or deletion request, except where continued retention is legally required.
- LeadIntel observations and internal notes are retained only while required for authorized company use and are deleted upon an applicable verified request or when they are no longer needed.
Deletion requests are evaluated against the controller/processor role, customer instructions, legal duties and the rights of other participants in shared records. If immediate deletion is not permitted, access is restricted and the reason is explained where legally required.
11. Security
We use role-based access, tenant separation, encrypted HTTPS transport, secure device token storage, MFA, restricted infrastructure, audit logging, backup controls and other technical and organizational measures appropriate to the risk. No method of storage or transmission is completely risk-free. Users should protect their credentials and report suspected unauthorized access promptly.
12. Automated decision-making and AI
The shipped modules do not make decisions producing legal or similarly significant effects about app users solely by automated means. LeadIntel supports human evaluation of company-level business signals and does not perform automatic outreach. No app data or customer content is processed by AI or sent to an external AI provider.
13. Your rights and choices
Subject to applicable conditions, you may request access, rectification, erasure, restriction, data portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing. You may disable notifications and protected-resource permissions in the app or iOS Settings.
Because accounts are provisioned rather than self-created, request access removal or account closure through your organization administrator or contact@feldmanncyber.com. We may ask for information needed to verify your identity. Where your organization controls workspace content, we may forward or coordinate your request with that organization.
You may lodge a complaint with a competent supervisory authority. FeldmannCyber’s lead supervisory authority is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Postfach 3163, 65021 Wiesbaden, Germany, telephone +49 611 1408-0, poststelle@datenschutz.hessen.de.
14. Children
The app is intended for professional users of customer organizations and authorized FeldmannCyber personnel. It is not directed to children and accounts are not offered through public self-registration.
15. Changes to this notice
We may update this notice when features, providers or legal requirements change. The current version and effective date will be published at this URL. Material changes will be communicated through an appropriate in-app, email or organizational notice where required.
16. Contact
FeldmannCyber GmbHBessunger Str. 175
64347 Griesheim, Germany
Email: contact@feldmanncyber.com
Telephone: +49 (0)151 6275 6121