Informational translation. The German version (link in the footer) is binding under GDPR and German law.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Sole Proprietorship
Owner: Justus Langowsky
Nicodéstraße 13
01465 Dresden
Germany
Email: contact@dailypitch.io
2. General notes on data processing
We generally process personal data of our users only insofar as this is necessary to provide a functional website and our content and services. Processing of personal data of our users is regularly carried out only with the consent of the user.
An exception applies in cases where prior consent cannot be obtained for factual reasons and the processing of the data is permitted by law.
3. Which data we process
3.1 When visiting the website (server logs)
When you visit our website, our hosting provider (Vercel Inc.) automatically collects information that your browser transmits:
- IP address (truncated / anonymised)
- Date and time of the request
- Content of the request (the specific page)
- Access status / HTTP status code
- Referrer URL
- Browser, operating system and its surface, language and version of the browser software
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure and stable provision of the website).
Storage period: 14 days, then automatic deletion.
3.2 On registration and use of the tool
For the use of the pitch-deck generator we process the following data:
- Email address (for magic-link login)
- Company name, branding details, contact email, booking URL
- Briefings entered and decks generated
- Uploaded files (reference decks, logos)
Legal basis: Art. 6 (1) lit. b GDPR (performance of contract).
Storage period: Until deletion of the user account. Generated decks and related data are permanently deleted 30 days after account deletion.
3.3 When opening a shared deck
When you open a share link to a deck, we collect, aggregated and without plain-text IP:
- Salted hash of the IP address (SHA-256 with rotating server-side salt, truncated to 16 characters, not reversible to the original IP, used solely for deduplication of views within a 24-hour window)
- User agent
- Referrer (where the access came from)
- Which sections of the deck were viewed, dwell time, scroll depth
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest of the deck author in engagement analytics). The recipient cannot disable this function as it is an integral part of the product; however, no identifying data is stored.
Storage period: 12 months, then automatic aggregation at daily level.
4. Recipients of the data
We pass on data only to the following processors:
- Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA: hosting of the website and application. We have entered into a data-processing agreement (DPA) with Vercel. Data transfer to the US is based on the EU Commission's standard contractual clauses. Server region: Frankfurt (fra1).
- Anthropic, PBC, 548 Market St PMB 90375, San Francisco, CA 94104, USA: AI-powered generation of deck content. Submitted briefings are transmitted to Anthropic for generation and are not used for training purposes (Anthropic's API customer terms).
- Resend, Inc., 2261 Market Street #4990, San Francisco, CA 94114, USA: delivery of magic-link login emails.
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland: processing of payment transactions for paid plans. We have entered into a data processing agreement (DPA) with Stripe. The data transmitted includes: name, email address, billing address, payment data (card or account details are collected directly by Stripe and are not visible to us).
5. Cookies and similar technologies
We use only technically necessary cookies (session cookies for login functionality). These are permitted under § 25 (2) no. 2 TTDSG without consent.
We use no tracking, no analytics tools (e.g. Google Analytics), no advertising cookies and no social-media pixels.
6. Your rights
You have the following rights vis-à-vis us at any time:
- Information about the data stored about your person (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR): “right to be forgotten”
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR): export of your data in a structured format
- Objection to processing (Art. 21 GDPR)
- Withdrawal of consent already given, with effect for the future (Art. 7 (3) GDPR)
To exercise these rights, an informal email to contact@dailypitch.io is sufficient. We respond within 30 days.
7. Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with a data-protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The competent authority is the supervisory authority of your habitual place of residence or the authority responsible for our registered office:
Devrientstraße 1
01067 Dresden
Phone: +49 351 85471 101
Email: saechsdsb@slt.sachsen.de
Web: www.saechsdsb.de
8. Data security
We use exclusively encrypted connections (HTTPS / TLS 1.3) for the secure transmission of your data. Databases are protected by strong authentication. Processors are carefully selected and contractually obliged to comply with the GDPR.
9. Changes to this privacy policy
We reserve the right to adapt this privacy policy if legal requirements or our data processing change. The current version is always available on this page.