Template — pending legal review. This text is a DSGVO baseline for the Xboard pilot. Replace bracketed placeholders and have a qualified German data-protection counsel sign off before public launch.
Privacy policy
1. Controller
The controller responsible for the processing of your personal data on Xboard is:
[Operator legal name][Operator street address]
[Operator city, postal code, country]
Email: [Operator contact email]
Data Protection Officer: [DPO contact]
2. Purposes and lawful bases
Xboard is a lead-to-deposit and growth operating system positioned “Deep in the appointment-based service / creative-professional segment, with a capability-broad engine underneath — sold WORLDWIDE” (product definition §3). Craft is optional personalization, never identity — any business can use the engine with no craft declared. Personal data is processed for the following purposes:
- Booking operations — receiving inquiries, confirming appointments, taking deposits. Lawful basis: Art. 6(1)(b) GDPR (performance of a contract).
- Marketing communications — only on explicit opt-in. Lawful basis: Art. 6(1)(a) GDPR (consent), withdrawable at any time.
- Ad measurement and retargeting — only on explicit tracking-and-ad-data opt-in. Lawful basis: Art. 6(1)(a) GDPR.
- Service security and fraud prevention. Lawful basis: Art. 6(1)(f) GDPR (legitimate interest).
- Compliance with legal obligations (tax records, data-subject-rights handling). Lawful basis: Art. 6(1)(c) GDPR.
3. Categories of data
- Contact data (name, email, WhatsApp number, location).
- Project briefs (free-text descriptions of the work requested).
- Booking and payment data (Stripe Connect references, deposit amounts, currency).
- Communication content (drafted emails / WhatsApp / IG DMs that the studio approves).
- Tracking and ad-measurement events when explicitly consented.
- Audit-log metadata for security and compliance.
4. Data we receive from connected platform APIs
When a studio connects a third-party account, Xboard receives the following from that platform's API — only for that studio, and only to provide the features the studio has enabled:
Meta (Facebook & Instagram) — Graph API & Conversions API:
- Facebook Pages data (page identifiers, names, the connected Page's posts).
- Page Insights data (post-level and page-level performance metrics).
- Instagram Business account data (account identifiers, published media).
- Instagram Insights data (media and account performance metrics).
- Ads data and Ads Insights data (performance for boosts you approve).
- Lead Ads data (contact details a person submits in a Meta Lead Ad to the studio).
- Messaging content (Instagram Direct and WhatsApp messages between the studio and its clients, when connected).
- Conversions API: hashed identifiers (e.g. SHA-256 email/phone) for ad measurement, only with the visitor's explicit tracking consent.
TikTok — Content Posting & Marketing APIs:
- TikTok account profile information, the account's post list and post analytics, and follower count.
Google / YouTube — YouTube Data API & Google Ads API:
- YouTube channel data and video analytics; Google Ads campaign and performance data.
Xboard's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We receive this data only after the studio explicitly connects the account via that platform's OAuth flow, and use it solely for the publishing, measurement, and inbox features in Xboard. We do not sell it or use it for advertising unrelated to the studio's own campaigns.
5. Data subject rights
You have the right to:
- Access (Art. 15) — request a copy of all personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate data.
- Erasure (Art. 17) — request deletion (subject to retention obligations).
- Restriction (Art. 18) — limit further processing.
- Portability (Art. 20) — receive your data in a machine-readable format.
- Object (Art. 21) — object to processing based on legitimate interest.
- Withdraw consent (Art. 7) — at any time, with no effect on prior lawful processing.
- Lodge a complaint with the competent German supervisory authority — the data-protection authority of the operator's Bundesland (state) of establishment. [Operator/counsel: confirm the competent authority for the operator's registered seat — e.g. the Berliner Beauftragte für Datenschutz und Informationsfreiheit for a Berlin establishment.]
To exercise these rights, contact [Operator contact email]. We respond within 30 days as required by Art. 12(3). To request erasure specifically, see data deletion.
6. Retention
Personal data is retained only as long as necessary for the purpose it was collected. Default retention windows:
- Incomplete inquiries that never became a booking: up to 12 months.
- Inactive leads: up to 24 months, to allow follow-up.
- Client records: 6 years (German commercial and contract obligations).
- Invoices and payment records: 10 years (§147 AO tax retention).
- Consent records: up to 10 years, for the defense of potential legal claims.
- Raw tracking events: approximately 13 months at the row level, plus aggregated reports.
- AI run logs: 180 days.
- Audit logs: 12 months (security and compliance).
Per-tenant retention rules can override these defaults. The current rules for your studio are visible inside the Compliance dashboard. [Operator/counsel: confirm these windows match the deployed retention configuration before removing the warning banner.]
7. Recipients and sub-processors
Personal data is shared with the following categories of recipients under Art. 28 data-processing agreements:
- Hosting — Render Services, Inc. (application + database; target region Frankfurt/EU — migration in progress, currently US (Oregon)).
- Object storage — Cloudflare, Inc. (R2), encrypted media and document storage.
- Authentication — Clerk, Inc. (sign-in and identity; processes your account email and authentication identifiers) under a data-processing agreement.
- Payment processor — Stripe Payments Europe Ltd. (Ireland) under Stripe Connect.
- Email delivery — Resend (USA) under EU Standard Contractual Clauses.
- AI inference — the configured AI provider for the assistant feature: Anthropic PBC (USA, under EU Standard Contractual Clauses) or AWS Bedrock (EU region), per deployment configuration.
- Error monitoring — Sentry.
- Meta Platforms Ireland Ltd. — only when the studio explicitly connects a Meta account for Lead Ads + CAPI.
Where data is transferred outside the EEA, we rely on the EU Commission's adequacy decisions or Standard Contractual Clauses. The full, current list of sub-processors is published at our sub-processor list.
8. Security
Xboard uses industry-standard transport encryption (TLS 1.2+) and at-rest encryption for sensitive material such as access tokens. Access to production data is restricted to the operator and audited.
9. Cookies and similar
The application uses strictly necessary cookies for session authentication. Tracking cookies for ad measurement are only set when the studio's visitor explicitly consents on the public booking form. There is no third-party advertising network embedded in the dashboard.
10. Changes
We may update this policy. Material changes will be notified at least 30 days before they take effect, via the dashboard.