Legal

Privacy Policy

This policy explains how personal data is processed on hellovanta.com. The controller is VANTA LLC, operating under the brand "Vanta Services".

1. Controller

VANTA LLC
30 N Gould St Ste N
Sheridan, WY 82801
USA
Registration: 2026-002008776 (Wyoming Secretary of State)

Represented by: Managing Member of VANTA LLC
Email (privacy requests): b.buettner@itsappsy.com
Phone: +49 151 29084749

2. General Principles

We process personal data only where necessary to provide a functional website and our services. Where the GDPR applies, processing is based on one of the following legal bases:

  • Art. 6(1)(a) GDPR: your consent
  • Art. 6(1)(b) GDPR: contract or pre-contractual steps
  • Art. 6(1)(c) GDPR: legal obligation
  • Art. 6(1)(f) GDPR: legitimate interests

We apply the principles of data minimization and confidentiality and take appropriate technical and organizational measures to protect your data.

3. Hosting and Server Logs (Vercel)

This website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. The serverless functions run in the Frankfurt region (fra1). On every request your browser transmits technically necessary data that is stored in log files for a short period:

  • truncated IP address
  • date and time of access
  • requested URL and HTTP status code
  • browser type, operating system, referrer URL

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). Retention: a maximum of 14 days, then automatic deletion.

4. Cookies and Consent Management

We use a consent banner with three categories. Your choice is stored locally for one year in the entry vanta-consent-v1.

  • Necessary: always active, required for core functions such as navigation and storing your selection.
  • Statistics: anonymized measurement of site usage. Loaded only with your consent.
  • Third-party content: allows loading embedded videos, calendar scripts and marketing tags (see sections 5 and 6).

You can withdraw your consent at any time by deleting the entry in your browser or resetting your selection in the banner.

5. Appointment Booking, Google Calendar and Meet

When you book a call on this website, we process the details you enter: name, email address, phone number and the selected time slot. Purpose: scheduling, confirmation emails, reminders and preparing the conversation.

To create the appointment and the video conference link we use Google Calendar and Google Meet (Google LLC, USA / Google Ireland Limited, EU). Your name and email address are included in the calendar event so the invitation reaches you.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps taken at your request).

6. Meta Pixel and Conversions API

With your consent, we use the Meta Pixel and the Meta Conversions API (Meta Platforms Ireland Ltd., EU / Meta Platforms, Inc., USA) to measure the performance of our advertising and to send conversion events (such as a submitted form or a booked call) to Meta. Without your consent, no marketing tags are loaded and no events are sent.

Legal basis: Art. 6(1)(a) GDPR (consent), given via the consent banner and revocable at any time.

7. Payments (Stripe)

For online payments we use Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc., USA). Stripe processes the data required for the payment (such as name, email, payment method and transaction data). You enter card details exclusively with Stripe; we never store card data and only receive the status and receipt of the payment.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

8. SMS Notifications (Twilio)

For transactional text messages, for example appointment confirmations and reminders, we use Twilio (Twilio Inc., USA). Twilio processes the phone number and the message content on our behalf.

Legal basis: Art. 6(1)(b) GDPR (performance of contract or pre-contractual steps). You can opt out of SMS notifications at any time by contacting us.

9. Transactional Email (Resend)

For sending transactional emails, such as booking confirmations and signed contract documents, we use Resend (Resend, Inc., USA). The data required for delivery is processed: email address, name, subject and content, plus attachments where applicable.

Legal basis: Art. 6(1)(b) GDPR (performance and documentation of contract).

10. Internal Client Area

Database and Authentication (Supabase)

To manage our business clients we operate a password-protected internal area. Its data is stored with Supabase Inc. (USA); the database is located in the EU region Frankfurt, Germany (eu-central-1). Data is encrypted at rest and transmitted exclusively over secured connections (TLS). Technically necessary cookies secure the login session. Particularly sensitive internal records are additionally encrypted at the application level (AES-256-GCM).

AI-Assisted Research (Anthropic, USA)

To prepare introductory calls we internally create a research brief about a prospective client business using the AI model "Claude" by Anthropic, PBC (San Francisco, USA), including an integrated web search. Only the business name and location are transmitted to Anthropic (data minimization); internal notes, email, phone and revenue are not transmitted. The result is used exclusively by our staff to prepare the conversation. No automated decision-making with legal effect takes place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in well-prepared conversations). You may object to this processing and request deletion of the brief (see section 13).

11. International Data Transfers

Several of the recipients named above (including Vercel, Stripe, Twilio, Resend and Anthropic) are based in the USA. Where personal data of EU/EEA residents is transferred to countries without an adequacy decision, we rely on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with supplementary technical and organizational measures where available. Data processing agreements under Art. 28 GDPR are in place with our processors.

12. Data Retention

We store personal data only as long as necessary for the purposes stated above or as long as statutory retention obligations (for example under commercial or tax law) apply. After that, the data is deleted or anonymized.

13. Your Rights

Where the GDPR applies, you have the following rights against us at any time:

  • access to your stored data (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure of your data, unless statutory retention obligations apply (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent with effect for the future (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a data protection supervisory authority, for example in the EU member state of your habitual residence.

For residents of US states with applicable consumer privacy laws (for example the California Consumer Privacy Act, CCPA): we honor the rights granted by your state's law, including the right to know, the right to delete and the right to opt out of the sale or sharing of personal information. We do not sell personal information.

An informal email to b.buettner@itsappsy.com is sufficient to exercise any of these rights.

14. Changes to This Policy

We update this privacy policy as needed to reflect changes in the law or in our services. The current version is always available on this page.

Last updated: 7/22/2026