Privacy Policy
Ansehn GmbH · Lessingstrasse 1f, 68723 Schwetzingen, Germany · Last updated: September 10, 2026
1. Controller
The controller responsible for the processing of personal data in connection with the website ansehn.com and the Ansehn platform is:
Ansehn GmbH
Lessingstrasse 1f
68723 Schwetzingen
Germany
Represented by the Managing Directors Kevin Katzke and Maximilian Wolf
Register court: Amtsgericht Mannheim (Mannheim Local Court), HRB 755277
VAT ID: DE456882339
Email: hello@ansehn.com
Phone: +49 176 60998014
Hereinafter referred to as “we”, “us” or “Ansehn”.
2. Data Protection Officer
Ansehn is currently not legally required to appoint a Data Protection Officer (Section 38 BDSG, Art. 37 GDPR) and has not appointed one. For all questions regarding data protection, please contact the address given above directly.
3. Principles of Data Processing
We process personal data exclusively in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications and Telemedia Data Protection Act (TTDSG). Personal data means any information relating to an identified or identifiable natural person.
For every processing activity, we require a legal basis under Art. 6 GDPR, in particular:
- Art. 6(1)(a) GDPR – you have given consent to the processing (e.g., certain cookies, newsletter).
- Art. 6(1)(b) GDPR – processing for the performance of a contract with you or to take steps prior to entering into a contract (e.g., account creation, use of the platform, billing).
- Art. 6(1)(c) GDPR – processing to comply with a legal obligation (e.g., retention obligations under tax and commercial law).
- Art. 6(1)(f) GDPR – processing to safeguard legitimate interests (e.g., IT security, fraud prevention, product improvement), provided your interests do not override these.
4. Your Rights as a Data Subject
You have the following rights against Ansehn regarding your personal data:
- Access to the data we process about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, an informal message to hello@ansehn.com is sufficient.
In addition, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for us is:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW)
Heilbronner Straße 35, 70191 Stuttgart
Phone: 0711 615541-0
Email: poststelle@lfdi.bwl.de
5. When You Visit Our Website
When you access ansehn.com, our hosting provider automatically processes technical access data (including IP address, date and time of access, page accessed, browser type, referrer URL) in what are known as server log files. This is technically necessary to deliver the website to you and to ensure its operation.
- Purpose: Provision and security of the website (e.g., detection of abuse and attacks)
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning, secure website)
- Service provider used: Vercel Inc. (USA) – web hosting of the application; data stored in the USA
If we use analytics tools on the website (see Section 9, “Cookies and Similar Technologies”), this is done only within the scope described there.
6. When You Register (Onboarding)
To use the Ansehn platform, you must create an account. In doing so, we process the data you provide during the registration process, in particular:
- Name
- business email address
- Access credentials (password or login via a single sign-on provider)
- the domain or brand you have provided for monitoring
- Purpose: Setting up and managing your user account, provision of the platform
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures)
- Service providers used: Neon, LLC – hosting of the application database (Postgres-as-a-Service), data stored in Germany (Frankfurt)
7. When You Use Our Product (Logged-in Area)
Ansehn helps companies measure and understand their visibility in AI-based search and answer systems (including ChatGPT, Claude, Gemini, Perplexity, Google AI Overviews). To provide these core functions, as part of your use of the platform we process, among other things, the domain/brand data you have provided, queries or configurations you have created, and publicly accessible search results, and pass this data on — to the extent necessary for the respective function — to the following processors:
| Service provider | Purpose | Place of processing | Data location |
|---|---|---|---|
| OpenAI, L.L.C. | Generative AI services for intelligent platform functions | USA | USA |
| Anthropic, PBC | Generative AI services for intelligent platform functions | USA | USA |
| Google LLC (Gemini API) | Generative AI services for intelligent platform functions | USA | USA |
| Perplexity AI, Inc. | Generative AI services for intelligent platform functions | USA | USA |
| DataForSEO Cyprus Ltd. | SEO and search data API for querying public search results | Limassol, Cyprus | EU/USA |
| Oxylabs UAB | Proxy services for querying publicly accessible AI search results | Vilnius, Lithuania | EU |
| API Hero Ltd. (Trigger.dev) | Processing of background jobs | USA | USA |
| LaunchDarkly (Catamorphic Co.) | Feature flag management (controlling which features are active for your account) | USA | USA |
| PostHog, Inc. | Product analytics | Europe | Europe |
| seriouscode GmbH (Vemetric) | Product analytics and event tracking | Kleinrötz, Austria | EU |
- Purpose: Provision of the platform functions you have booked, in particular analysis and simulation of your brand's AI visibility, technical operation, product improvement
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for product analytics, additionally Art. 6(1)(f) GDPR or, insofar as implemented via cookies/local storage technologies, Art. 6(1)(a) GDPR in conjunction with Section 25 TTDSG (see Section 9)
Please note: When using generative AI services (OpenAI, Anthropic, Google Gemini, Perplexity), the data necessary to provide the function (e.g., your queries, publicly accessible content) is transferred to the respective providers in the USA. Data processing agreements under Art. 28 GDPR are or will be concluded with all providers named.
8. When You Communicate With Us
8.1 Contact Form / Email Contact
If you contact us by email, sign up for product notifications, or receive transactional messages from us (e.g., password reset, invoices, system notifications), we process the data necessary for this (name, email address, content of your message).
- Purpose: Responding to your inquiries, sending operationally necessary and product-related communications
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in communicating with prospective customers); for optional marketing/newsletter content, Art. 6(1)(a) GDPR (consent, revocable at any time)
Service providers used: Plus Five Five, Inc. (Resend) and Astrodon Corporation (Loops) – sending of transactional emails, USA
8.2 Demo Booking (“Book a demo”)
For scheduling appointments, we use Calendly from the United States. The data you enter (name, business email address, company, company size, free text) is transferred to the respective provider. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measure). A data processing agreement (DPA) under Art. 28 GDPR is in place with the provider.
8.3 Free Trial Access / Sign-up
To register for a trial account, we collect at least: name, business email address, company, password (stored encrypted). This data is used to provide the trial access and to make contact as part of the contract initiation process. The legal basis is Art. 6(1)(b) GDPR.
9. Cookies and Similar Technologies
Our website and platform use cookies, local storage entries, and similar technologies to provide functionality and to analyze usage. We distinguish between the following categories:
- Technically necessary cookies (e.g., login/session cookies, security cookies): These are necessary for you to log in and use the platform. No consent is required for these under Section 25(2) No. 2 TTDSG; the legal basis is Art. 6(1)(b) GDPR. These cookies are set regardless of your consent decision.
- Analytics cookies (PostHog, Vemetric): These record your usage behavior on the website or within the platform in order to improve the product. They are only set if you have given your consent (Section 25(1) TTDSG, Art. 6(1)(a) GDPR).
On your first visit to our website, you will be asked for your consent via our cookie consent tool before any cookies that are not technically necessary are set. You can withdraw or change your consent at any time with effect for the future by reopening your cookie settings via Cookie Settings.
You can find an up-to-date overview of the individual cookies set (name, provider, purpose, storage period) at any time in this cookie consent tool.
You may also object to the use of cookies at any time via your browser settings, or delete cookies that have already been stored.
10. When You Make a Payment
- We do not offer an online payment process (e.g., by credit card or payment service provider) on our website. Instead, we send you an invoice after the contract is concluded. For invoicing and bookkeeping, we use the Lexware software from Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany. This involves processing the data required for the invoice (e.g., name, billing address, contact person, email address, scope of services, invoice amount).
- Payment of the invoice is made by you via standard bank transfer; we do not collect any payment or account data for this purpose via our website.
- The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(c) GDPR, insofar as commercial and tax law retention obligations apply (Section 147 of the German Fiscal Code (AO), Section 257 of the German Commercial Code (HGB)). As Haufe-Lexware GmbH & Co. KG is based in Germany, no data is transferred to a third country in this respect.
- We use the cloud-based version, lexoffice. A data processing agreement (DPA) under Art. 28 GDPR is in place with Haufe-Lexware GmbH & Co. KG, which ensures that the data stored there is processed only in accordance with our instructions and in compliance with the GDPR.
11. Transfers to Third Countries
Most of the service providers named above are based, or process data, in the USA, a country outside the European Economic Area (EEA) that has not been uniformly recognized by the European Commission as providing an adequate level of data protection.
We base the transfer of personal data to such third countries on appropriate safeguards within the meaning of Art. 46 GDPR — in particular the Standard Contractual Clauses (SCCs) issued by the European Commission — as well as, where the respective provider is certified accordingly, an adequacy decision of the EU Commission under the EU-U.S. Data Privacy Framework (DPF). We provide an overview of which specific safeguard applies to which provider on request at hello@ansehn.com.
Providers that process or store data within the EU (Neon – Frankfurt, PostHog – Europe, Vemetric – Austria, Oxylabs – Lithuania), as well as those with a mixed EU/USA location (DataForSEO), are partially exempt from this or only affected to a limited extent.
12. Storage Period
We store personal data only for as long as is necessary for the respective purposes:
- Account data: for the duration of your contractual relationship with us; after termination, the data is deleted unless statutory retention obligations require otherwise
- Invoice and payment data: in accordance with commercial and tax law retention periods (generally 6 or 10 years under Section 257 HGB, Section 147 AO)
- Server log files: generally for a short period, essentially for security reasons
- Communication data (e.g., email support): for as long as necessary to process your request, thereafter in accordance with statutory retention periods
13. Data Security
We take appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access (including encryption of transmission, access restrictions). Agreements under Art. 28 GDPR are in place with all processors used, which obligate them to take appropriate security measures.
14. Newsletter
If you subscribe to our newsletter, we use your email address and, where applicable, your name solely to send the content you have agreed to receive (double opt-in procedure). The legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time via the unsubscribe link in each email.
Our newsletter is sent on our behalf by Astrodon Corporation (“Loops”), 9450 SW Gemini Dr, PMB 22902, Beaverton, Oregon 97008-7105, USA, as our processor under Art. 28 GDPR — the same provider already named in Section 8 for sending transactional emails. You can find the Astrodon Corporation privacy policy at: https://loops.so/privacy.
15. When You Apply to Us
If you apply to us for a position, we process the personal data you provide to us as part of your application. This includes, in particular:
- First and last name
- Contact details (e.g., email address, phone number, address)
- Application documents (e.g., cover letter, CV, references, certificates)
- Information about your professional background, qualifications, and skills
- Salary expectations, availability, and desired start date
- Notes from interviews and other information you provide to us in the course of the application process
- Purpose: Conducting the application process, in particular assessing your suitability for the advertised position, communicating with you, and deciding whether to establish an employment relationship
- Legal basis: Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG (contract initiation)
- Recipients: Within Ansehn, access is granted exclusively to those persons involved in the application process (e.g., management, the relevant team)
If no employment relationship is established, we will delete your application documents six months after the application process has concluded. The legal basis for this retention is our legitimate interest in being able to demonstrate the proper conduct of the process in order to defend against possible claims, in particular under the General Act on Equal Treatment (AGG) (Art. 6(1)(f) GDPR). You may object to this retention at any time or request earlier deletion, provided no statutory retention obligations conflict with this.
16. Changes to This Privacy Policy
We will update this Privacy Policy whenever our data processing changes — in particular when a cookie banner or new service providers are introduced. The version published at the time of your visit to ansehn.com shall apply.