Privacy Policy

Last updated: 2. Juli 2026

This privacy policy explains how personal data is processed when you use Vistova (vistova.de).

1. Controller

Timm Ehlbeck, Willy-Brandt-Allee 31, 23554 Lübeck, Germany.

Email: info@timmehlbeck.de · Phone: +49 15120137619.

2. General

We process personal data only in accordance with the GDPR. Depending on the purpose, the legal basis is Art. 6(1)(a) (consent), (b) (contract) or (f) (legitimate interest).

3. Hosting

Vistova runs on servers located within the EU (Germany). When you access the service, technically necessary server logs (IP address, timestamp, requested resource, user agent) are processed for delivery and IT security (Art. 6(1)(f)).

4. Account and contract data

To provide the service we process registration and account data (name, email, organization, role) as well as the projects, brands and prompts you create. The legal basis is performance of the contract (Art. 6(1)(b)).

5. Web analytics (own, cookieless tracking)

On our public pages we use our own privacy-friendly analytics. We record page views, referrer and a pseudonymous visitor/session identifier stored in your browser's local storage. We do not build cross-site profiles and do not sell data. The legal basis is our legitimate interest in measuring reach (Art. 6(1)(f)).

6. Cookies and local storage

We use:

  • a technically necessary session cookie for login,
  • a token cookie for API access when Google Search Console is connected,
  • browser local storage for settings (e.g. active project) and the pseudonymous analytics IDs.

7. Processing of content for SEO/AI features

For the SEO and GEO features, content you enter (e.g. domains, keywords, prompts) is transmitted to external services to deliver the respective feature: OpenAI, Perplexity, Google (Gemini) and Serper (SERP data). The legal basis is performance of the contract (Art. 6(1)(b)).

8. Google user data (Google Search Console)

If you connect your Google Search Console, Vistova accesses your Search Console performance data read-only (scope "webmasters.readonly") with your explicit authorization via OAuth 2.0, solely to display it to you within Vistova.

Vistova's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This data is not used for advertising, not sold to third parties, and processed only to provide the feature.

You can revoke the connection at any time — in Vistova by disconnecting the integration and in your Google account under "Security → Third-party access".

9. Payments

For paid plans we use Stripe. Payment data is processed directly by Stripe; we do not store full payment credentials. The legal basis is performance of the contract (Art. 6(1)(b)).

10. Email communication

We send system- and contract-related emails (e.g. invitations, notifications, digests). The legal basis is performance of the contract or our legitimate interest (Art. 6(1)(b)/(f)).

11. Recipients / processors

To provide the service we use carefully selected providers, including: hosting (EU), OpenAI, Perplexity, Google, Serper, Stripe and our email delivery provider. Data processing agreements are in place where required.

12. Transfers to third countries

Some services (e.g. OpenAI, Google) also process data in the USA. Transfers are based on appropriate safeguards (EU Standard Contractual Clauses) or an adequacy decision.

13. Retention

We retain personal data only as long as necessary for the stated purposes or as required by law. Raw analytics data is deleted after at most 365 days.

14. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority (Art. 77).

To exercise your rights, simply email info@timmehlbeck.de.