Privacy

Privacy Policy

Information about the processing of your personal data on the Begehung.pro website and in the Begehung.pro platform.

Last updated: August 2026


1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website or use the Begehung.pro platform. Personal data is any data that can be used to personally identify you.

Legal Basis

Data processing is carried out on the basis of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications-Digital Services Data Protection Act (TDDDG).

2. Responsible Party

Responsible for data processing on this website and for the account and contract data of platform users:

Tobias Boehm Softwareentwicklung

Am Kapellenhof 11, 24576 Bad Bramstedt, Germany

kontakt@begehung.pro

+49 162 1565538

VAT ID: DE326224880

For the content a customer enters into the platform, i.e. inspections, photos, notes, and reports, the customer is the controller within the meaning of the GDPR. The provider processes this content as a processor acting on instructions (§ 5(4) and § 9(1) of the Terms and Conditions, § 1(2) of the DPA).

Data Protection Officer

We are not legally required to appoint a data protection officer.

3. Hosting and Technical Infrastructure

The application servers of this website and of the Begehung.pro web app run on Google Cloud Run in Belgium. The platform’s database, authentication and file storage are hosted by Supabase in Frankfurt am Main, Germany. Processing takes place within the European Union. Which providers are involved, where they are established and where they process data is set out in our subprocessor list.

Email Services

Our email hosting is provided by united-domains AG, Germany. The email servers are located in Germany.

Media Content Storage

Photos, audio files, signatures, company logos, profile pictures, and uploaded import documents are stored in Supabase file storage (Frankfurt am Main, Germany). The storage buckets are private and separated by tenant. Transmission occurs via TLS, storage uses AES-256 encryption.

4. Data Processing on the Website

Contact and Appointment Booking

This website does not contain a contact form. Contact is established in three ways: through the embedded Calendly booking window, by email to the address stated in the legal notice, and by phone. When booking an appointment, you enter your name and email address directly with Calendly (see section 9). For inquiries by email or phone, we process the information you provide to us.

Processing is based on Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient processing of inquiries).

Email inquiries remain in our mailbox until the matter is concluded. Retention afterwards is determined by commercial and tax law retention periods.

Replies to Inquiries

We send replies to your inquiries from our mailbox at united-domains AG, Germany. The website itself does not send any emails. Your email address is used exclusively for processing your inquiry and not for marketing purposes unless you have provided separate consent.

5. Data Processing in the Begehung.pro Platform

The Begehung.pro platform (web app and mobile app) processes extensive data as part of on-site documentation. For the content a customer enters into the platform, the customer is the controller; the provider processes it as a processor acting on instructions. The following overview explains what data is collected, how it is processed, and how long it is stored.

Types of Data Collected

  • Photos: Images that users upload to an inspection in the web app. During upload, the capture time, device type, and dimensions are taken from the file metadata and stored, as are location coordinates and bearing where the image contains them. The uploaded image retains its metadata.
  • Audio files: Sound files that users upload to an inspection, for example recordings from a dictation device. Transmission and storage are encrypted. The application itself does not make any recordings.
  • Text notes and assessments: Manual entries such as condition assessments, defect descriptions, meter readings, and free-text comments.
  • Generated reports: Expert opinions, protocols, and reports (PDF, DOCX) created from captured data.
  • Account data: Name, email address, company affiliation, and login credentials (passwords are stored exclusively as hashes).

AI-Powered Processing

Begehung.pro uses Artificial Intelligence (AI) for checklist import, report import, and text suggestions on note and comment fields. The following processing takes place:

  • Checklist and report import: Users upload a document (PDF, DOCX, or XLSX; up to 20 MB for checklist import, up to 50 MB for report import). The complete document is sent to the language model, including any photos embedded in it in the case of report import. The uploaded file is held in file storage and removed after 30 days together with the job.
  • Text suggestions on note and comment fields: The user triggers the suggestion themselves. The content of the field is then sent to the language model. The result is a suggestion that the user either accepts or discards.
  • AI telemetry: Each model call creates an entry containing user and tenant ID, job type, model and region, token count, cost, queue and run time, outcome, and the size and type of the source file. The prompt, the content of the document, and the model’s response are not recorded. These entries are retained indefinitely and evaluated exclusively by the provider.

The recipient of the AI processing is Google Cloud EMEA Limited (Google Vertex AI). Processing runs in the Frankfurt am Main region, Germany.

No automated decision-making within the meaning of Art. 22 GDPR takes place. All AI-generated content consists of suggestions that must be reviewed and confirmed by the user.

AI-powered processing is based on Art. 6(1)(b) GDPR (contract fulfillment, as import and text suggestions are part of the agreed scope of services) and Art. 6(1)(f) GDPR (legitimate interest in providing efficient documentation tools). No further AI-powered processing takes place.

Error Diagnostics, Session Replay, and Error Reports

For troubleshooting, the platform uses the service Sentry (Functional Software, Inc., USA). The organization is located in the EU region, where processing takes place. This website does not embed any error diagnostics service. From the web app, reports travel via a route of the application itself, which forwards them unchanged; the recipient is Sentry in every case. Three data flows occur:

  • Automatic error events (web app, Android, iOS): error message and stack trace, user and tenant ID, application version, the route accessed, and browser or device details.
  • Session replay (web app only): an event-driven excerpt of the session that is transmitted only when a report is submitted. Visible text is included in plain form, which also covers the names of customers and contacts as well as property addresses. Entries in form fields are masked and images and media are blocked.
  • Error report (web app only): an image of the visible area, which the reporter can review and redact before submitting, the console buffer as a file, user and tenant ID, the reporter’s email address, the route accessed, application version, device details, and the description and category of the report.

The legal basis is consent pursuant to Art. 6(1)(a) GDPR. Automatic error events and session replay are tied to the telemetry switch in the profile, which is off by default; consent is withdrawn via the same switch. The error report has its own consent path: the act of submitting plus a mandatory confirmation in the form. An error report is therefore sent even when the telemetry switch is off; a session replay only when it is on.

Sentry retains events, replays, and attachments for 30 days.

Signing in with Google

In addition to signing in with an email address and password, the sign-in screens of the web app and the mobile app offer signing in with a Google account. If you use it, your sign-in request goes to Google. Google then transmits the Google account ID, the email address, the display name, and the profile picture where one is set to the platform; the provider does not receive a password. The legal basis is Art. 6(1)(b) GDPR, as signing in is a prerequisite for using the platform. The choice of this sign-in path is made by the user.

Offline Storage on the Device

The Begehung.pro mobile app works offline. It holds inspection data, i.e. master data, inspections, areas, defects, notes, and the details of photos and audio files, in an encrypted database on your device. The photos and audio files themselves are not stored on the device. Synchronization with the server occurs automatically once an internet connection is available. The local database is cleared when you sign out. The web app does not store any inspection data on your device.

Retention Period and Deletion

Inspection data (photos, audio files, text notes, reports) is stored for the duration of the contractual relationship. After the contract ends, user data remains available for export for 90 days and is deleted after that period, unless statutory retention obligations apply. For a free trial run, the contractual relationship ends upon sealing of the inspection, and at the latest after twelve months without any use of the Platform. During the contract period, you can delete individual inspections and their data at any time. Account data is deleted after the export period and any applicable retention periods have expired. Exempt from the deletion periods above are the operational records of AI calls: they contain no content but carry user and tenant IDs and are retained indefinitely.

6. Your Rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

To exercise your rights, please contact: kontakt@begehung.pro

Right to complain to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:

Independent State Center for Data Protection Schleswig-Holstein (ULD)

Holstenstraße 98, 24103 Kiel

https://www.datenschutzzentrum.de

7. Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and version, operating system used, referrer URL, hostname of the accessing computer, time of server request, and IP address. This data is not merged with other data sources.

Server log files are automatically deleted after 30 days.

The legal basis for temporary storage of data is Art. 6(1)(f) GDPR. The collection of data is essential for providing the website.

8. Cookies and Analytics Tools

This website uses technically necessary cookies for language selection and consent management.

The use of technically necessary cookies is based on Art. 6(1)(f) GDPR. We have a legitimate interest in the technically error-free provision of our services.

Google Analytics

This website uses Google Analytics (Google Ireland Limited), a web analytics service. Google Analytics is only activated when you give your explicit consent via the cookie banner (Art. 6(1)(a) GDPR). Data collected: page views, time on page, device type, operating system, browser, approximate location (country/city), referrer URL. We use IP anonymization so that your IP address is truncated within the EU. You can revoke your consent at any time via the cookie banner.

9. Calendly

For appointment booking, we use the service Calendly (Calendly LLC, USA). The booking window is embedded in this website. When you book an appointment in it, you enter your name and email address directly with Calendly; this data is transmitted to Calendly. Details can be found in Calendly’s privacy policy: https://calendly.com/privacy

The use of Calendly is based on Art. 6(1)(b) GDPR (contract fulfillment or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient appointment scheduling).

10. Google Fonts

This page uses so-called Google Fonts for uniform font display, provided by Google. The platform’s web app also loads its fonts from Google servers. When you access a page, your browser loads the required fonts directly from Google servers (possibly in the USA). Your IP address is transmitted to Google. More information can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy

The use of Google Fonts is based on Art. 6(1)(f) GDPR. We have a legitimate interest in uniform font display on our website.

11. International Data Transfers

As part of our data processing, data is transferred to the following countries:

  • Belgium: Operation of the application servers of the website and the web app via Google Cloud Run. Subject to the GDPR.
  • Germany (Frankfurt am Main): Database, authentication, and media storage via Supabase. Subject to the GDPR.
  • European Union: Synchronization of the mobile app via PowerSync Cloud, AI processing via Google Vertex AI (Frankfurt am Main), and error diagnostics via Sentry. Subject to the GDPR.
  • Germany: Email hosting via united-domains AG. Subject to the GDPR.
  • USA: This website embeds Calendly, Google Fonts, and Google Analytics (with consent only); data may be transferred to the USA in the process. The fonts are additionally loaded by the platform’s web app. Transfers are based on Standard Contractual Clauses (Art. 46(2)(c) GDPR) or the EU-US Data Privacy Framework.

12. Data Processing Agreements

For the use of the Begehung.pro platform in a business context, a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR applies. It is particularly relevant when captured inspection data contains personal data of third parties (e.g., photos of occupied rooms, protocols with tenant data). Under its § 1(3), the DPA is concluded upon conclusion of the main contract together with the first processing of personal data, at the latest upon express consent in text form, and can be viewed at Data Processing Agreement. The engaged subprocessors are listed in the subprocessor list.

13. Automated Decision-Making

No automated decision-making including profiling pursuant to Art. 22 GDPR takes place. The AI-powered functions of Begehung.pro (checklist import, report import, and text suggestions on note and comment fields) create suggestions that must be reviewed and confirmed by the user. No legally binding or similarly significant decisions are made automatically.

14. Provision of Data

The provision of personal data is not required for using the website. Booking an appointment requires your name and email address; you enter these in the Calendly booking window. Using the Begehung.pro platform requires a user account with name and email address. Capturing inspection data, i.e. photos, audio files, and text, is necessary for the platform’s core functionality.

15. Contact

For questions about data protection, you can contact us at any time:

Email: kontakt@begehung.pro

Phone: +49 162 1565538