Data protection
Data protection declaration
Information about the processing of personal data by Spectre.
1. Accountable person
The person responsible within the meaning of Art. 4 No. 7 GDPR is:
| Operator / Company | ALB Digital Diensliestungen |
|---|---|
| Legal form | ALB Digital Diensliestungen |
| Address | Mainzer Strasse, 53179 Bonn, Deutschland |
| E-mail data protection | privacy@agentspectre.eu |
| E-mail in general | legal@agentspectre.eu |
| Telephone | +49 1556 528 3042 |
| Data Protection Officer | A data protection officer is not separately named in the imprint information provided. Please address data protection requests to: privacy@agentspectre.eu. |
| EU representatives according to Art. 27 GDPR | Not applicable, as the operator is resident in Germany according to the information provided. |
2. Short review
- Spectre does not read email passwoerters. The connection takes place via OAuth or provider-related interfaces.
- Mailbox scans can process senders, subject lines, data and snippets. Relevant signals can be transmitted to backend and AI services; processing is not exclusively local.
- Response and organization functions can also process message content. Stored process data supports, among other things, the request history and the processing of requests.
- Loeshan questions are only created or sent after user action. Organizations can refuse or arrest deletions if there are legal retention requirements or exceptions.
- Payment data is processed by Stripe; Spectre receives payment status, tariff and billing references, but no full card data.
3. Processing claims, purposes and legal bases
| Process | Data categories | Purpose | Legal basis |
|---|---|---|---|
| Website provision | IP address, time, URL, user agent, technical log data | Delivery, security, error analysis, anti-abuse | Art. 6 para 1 lit. f GDPR (legitimate interest in secure operation) |
| Account and login | Name, e-mail address, provider ID, profile picture if provided by the provider, tariff, user number | Investment, authentication, tariff management, provision of booked functions | Art. 6 para 1 lit. b GDPR (contract / pre-contractual measures) |
| OAuth connection to mail providers | OAuth tokens, provider ID, e-mail address, permissions, token expiration data | Authorized access to mailbox metadata and authorized sending of requests | Art. 6 para 1 lit. b GDPR; insofar as consent for access/final processing is required: Art. 6 para 1 lit. a GDPR and § 25 TDDDG |
| Mailbox scan | sender, subject, date, provider metadata, if applicable. Snippets if technically delivered, recognized organizations, confidence, category | Identification of possible accounts, providers and data protection contacts | Art. 6 para 1 lit. b GDPR; for optional AI support if applicable. Art. 6 para 1 lit. a GDPR |
| AI-backed identification and design | Minimized account signals, organization name, domain, sender address, language, draft text, references | Recognition of data holders, formulation of Art. 17 / DSAR-oriented requests, DPO contact search | Art. 6 para 1 lit. b GDPR; with optional use of external AI services depending on the configuration Art. 6 para 1 lit. a or lit. f GDPR |
| Send requests | Name, e-mail address, target organization, recipient address, subject, request content, sending time, status, protocol ID | Exercise of data protection rights against third parties and proof for users | Art. 6 para 1 lit. b GDPR |
| Payments | Stripe customer ID, checkout ID, payment status, tariff, invoice data if submitted | Payment processing, fraud prevention, accounting | Art. 6 para 1 lit. b GDPR; Art. 6 para 1 lit. c GDPR for legal storage obligations |
| Support and Legal Requests | Contact details, communication content, technical diagnostic information, processing status | Replying to requests, correcting errors, exercising rights | Art. 6 para 1 lit. b, lit. c or lit. f GDPR depending on request |
| B2B / DPO agent functions | Organization account, domain, DPO mailbox data, incoming requests, SLA status, audit and Witness logs, API locket metadata | Data protection workflow, DSAR/Loeschqueue, audit proof, API integration | Art. 6 para 1 lit. b GDPR; Art. 6 para 1 lit. f GDPR for security and proof functions |
4. Mailbox and OAuth data
Spectre only requests the permissions required for each function. Depending on the provider, the following scopes or equivalent rights can be used:
- Gmail:
gmail.readonlyfor header-oriented analysis,gmail.sendfor user authorized shipping. - Microsoft / Outlook:
Mail.ReadandMail.Send. - Yahoo, GMX, Web.de, iCloud or other IMAP-/SMTP-based providers: provider-dependent read and broadcast rights.
If providers technically provide snippets or subject lines, they can be processed for recognition and prioritization. In response and organization functions, message content can also be processed. Stored process data is used, among other things, to process and document requests.
Users can revoke OAuth accesses at any time at the respective provider. After that, affected functions can no longer be executed until a new authorization takes place.
5. AI support
Spectre can use AI services to identify organizations, research DPO or privacy contacts, create language and jurisdiction, and prepare for privacy requests.
Data is minimized. No full mailbox dumps, e-mail passwoerters or attachments to AI services should be submitted. Depending on the function, however, sender address, domain, subject, date, organization name, category, language, draft content and source URLs can be processed.
AI results are operational propositions, not legal advice. Users check recipients, content and shipping themselves.
6. Recipients and processors
Personal data may be transmitted to the following categories of recipients, insofar as this is necessary for the respective function:
| Recipient/Service | Role | Purpose | Status |
|---|---|---|---|
| Static hosting / serverless functions | Processors | Provision of the website, OAuth callbacks, checkout functions, API routes, security protocols and protection against abuse | The live configuration must comply with this declaration and the respective processing contracts. |
| Appwriter | Processors | Account, database, user, request history, if applicable. DPO queue | Provided in the application code for account, database and queue functions; region and contract must conform to the productive configuration. |
| Stripe | Own controller or processor depending on the payment transaction | Payment processing, fraud prevention, settlement, payment status | Only for paid plates / checkout. |
| Google APIs / Gmail | Own provider of the user account | OAuth, mailbox access, shipping | Provider data protection notices apply additionally |
| Microsoft Graph / Outlook | Own provider of the user account | OAuth, mailbox access, shipping | Provider data protection notices apply additionally |
| Yahoo / GMX / Web.de / iCloud or other mail providers | Own account providers | OAuth, IMAP/SMTP or provider-related mail functions | Provider data protection notices apply additionally |
| AI service, if activated | Processor or own provider depending on the contract setup | Minimized mailbox signals for identification, contact search, voice and design support | Only if the respective function is activated in the productive environment. |
| Target organizations / DPO contacts | Own responsible persons | Reception and processing of the request sent by the user | Only after user approval / shipping action |
7. Third country transfers
Some service providers may process personal data outside the EU/EEA, especially in the USA. Where necessary, we base such transfers on adequacy decisions, the EU-U.S. Data Privacy Framework, standard contractual clauses according to Art. 46 GDPR or express consent. The productive provider and region configuration must match this explanation.
8. Browser storage, cookies and TDDDG
Spectre can use technically necessary inputs into local storage, session storage or comparable end-devices, for example for login status, OAuth-State/PKCE, language setting, tariff status, security recommendations and temporary storage of running scans.
Access to final information takes place for absolutely necessary functions on the basis of § 25 para 2 TDDDG. For non-necessary storage, analysis or marketing cookies, a prior consent according to § 25 para 1 TDDDG and Art. 6 para 1 lit. a DSGVO must be obtained. This page assumes that no unnecessary marketing or tracking cookies are currently used. If such tools are added, this explanation and consensus mechanism must be updated.
9. Storage periods
| Data | Standard period |
|---|---|
| Server and security logs | Up to 30 days, longer only in case of security or legal enforcement. |
| Account and tariff data | As long as the account exists; thereafter deletion or blocking, insofar as no legal obligations conflict. |
| OAuth tokens | As long as the mailbox is connected or until revocation, logout, token expiration or account deletion. |
| Scan results and identified data holders | As long as they are required for the user review or request history; cancellable via account/support process. |
| Transit logs and request history | As long as required for proof, performance of the contract or legal defence; regular verification after 24 months. |
| Payment and billing data | After legal trading and tax periods, regularly up to 10 years. |
| Support communications | Up to 24 months after conclusion, longer for ongoing legal or security cases. |
10. Data subject rights
In accordance with the GDPR, affected persons have the following rights in particular:
- Information according to Art. 15 GDPR
- Correction according to Art. 16 GDPR
- Deletion according to Art. 17 GDPR
- Limitation of processing according to Art. 18 GDPR
- Data transferability according to Art. 20 GDPR
- Objection according to Art. 21 GDPR
- Revocation of granted consents with effect for the future according to Art. 7 para 3 GDPR
- Complaint to a data protection supervisory authority according to Art. 77 GDPR
Please address requests to: privacy@agentspectre.eu. The supervisory authority responsible for Bonn / North Rhine-Westphalia is particularly relevant for complaints: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.
11. Security
We use technical and organizational measures to protect personal data against loss, misuse, unauthorized access and unauthorized disclosure. This includes transport closure, OAuth-based authorization, access restrictions, server-side secret management, protocol minimization and role-based access controls for organization functions.
No Internet service can guarantee absolute security. Security issues are assessed and reported in accordance with Art. 33 and 34 GDPR.
12. Changes
This data protection declaration is adapted when functions, service providers, legal bases or legal requirements change. The current version is under /datenschutz.html retrievable.