Privacy

Privacy Policy

Information on the processing of personal data under Art. 13 GDPR.

Last updated: April 2026
A German version of this Privacy Policy is available via the language toggle above.

1. Privacy at a glance

The following provides an overview of what happens to your personal data when you visit vaytax.com or use the Vaytax service. Vaytax is an online VAT-compliance service for businesses with German tax obligations. As such, tax and financial data are also processed.

2. Controller

FRADECO GmbH
Deutsch-Französische Steuerberatungsgesellschaft
Simrockstraße 92
53619 Rheinbreitbach
Germany

E-mail: [email protected]
Website: vaytax.com

The controller is the natural or legal person who alone or jointly determines the purposes and means of processing personal data.

3. Data Protection Officer

FRADECO GmbH is currently not required to appoint a Data Protection Officer under Art. 37 GDPR in conjunction with § 38 BDSG. For data-protection enquiries, please contact us at the address above or by e-mail at [email protected].

4. Categories of data processed

In the course of using Vaytax, we process the following categories of personal data:

a) Account data

E-mail address, password (stored solely as a cryptographic hash), authentication tokens.

b) Company data

Company name, legal form, address, country, sector.

c) Tax data

Tax number (Steuernummer), VAT identification number (USt-IdNr.), competent tax office (Finanzamt), VAT preliminary return values (Kennzahlen / KZ values), VAT amounts, filing periods.

d) Financial data

IBAN, SEPA direct debit mandate, payment references.

e) Representative data

Name, date of birth, e-mail address of the legal representative or authorized agent.

f) Document data

Uploaded PDF documents, generated XLSX and CSV files, tax returns and preliminary returns.

g) Usage data

Page views, session identifiers (via sessionStorage only, not cookies), timestamps, browser and operating system, IP address (in server logs).

5. Legal basis for processing

We process your personal data on the following legal bases:

6. Recipients and processors

We engage the following service providers, with whom data-processing agreements (DPAs) under Art. 28 GDPR have been concluded where applicable:

In addition, as part of the tax-advisory work, data is transmitted to:

7. Transfer to third countries

The database and primary data processing take place in the EU (Supabase eu-central-1, Stockholm; Cloudflare EU).

Resend Inc. is based in the USA. Data transfer is on the basis of Standard Contractual Clauses (SCCs) under Art. 46 (2) (c) GDPR. Only e-mail addresses and the contents of transactional e-mails are processed via Resend.

Stripe processes payment data primarily in the EU (Stripe Payments Europe, Ltd., Ireland) but may transfer it to Stripe, Inc. (USA) for processing and fraud-prevention purposes. The transfer is on the basis of Standard Contractual Clauses and Stripe’s certification under the EU-U.S. Data Privacy Framework.

Google Fonts and Google Analytics 4 are delivered from servers of Google Ireland Limited (EU) and Google LLC (USA). Google is certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses additionally apply under Art. 46 (2) (c) GDPR.

8. Storage period

9. Cookies, tracking and consent

We distinguish between technically necessary storage mechanisms and consent-based tracking technologies:

a) Technically necessary storage (no consent needed)

For login and session management in the authenticated area we use the browser’s localStorage / sessionStorage APIs (e.g. storing the authentication token after successful login). Under § 25 (2) No. 2 TTDSG this storage is permitted without consent because it is strictly necessary to provide the service the user has expressly requested. Cookies in the classical sense are not used for this purpose.

b) Audience measurement with Google Analytics 4 (with consent only)

On the public pages of vaytax.com we use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for statistical evaluation of usage. IP anonymisation is enabled (anonymize_ip: true); no linkage with other Google services or accounts.

On first visit to our website, Google Analytics is initialised in “Consent Mode v2” with the default state “denied”. At that point no cookies are set and no personal data is transmitted to Google. Via our consent banner you can equally accept (“Accept all”) or reject (“Essential only”). Only after active consent are the following cookies set:

c) Conversion measurement via Google Ads (with consent only)

In addition to audience measurement, the publicly accessible pages of vaytax.com use Google Ads conversion tracking (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). This lets us measure how many visitors who arrived via a paid Google ad subsequently complete an action relevant to us (for example creating an account, requesting a Finanzamt letter quote, or completing a purchase).

When you click one of our Google ads, Google automatically appends a Google click identifier (URL parameter ?gclid=...) to the destination URL. This identifier is stored locally in your browser (localStorage, key vd_gclid) for a maximum of 90 days. It does not identify a person and contains no plain-text personal data; it serves solely to associate a later conversion with the original ad click.

Transmission of the identifier to Google Ads happens in one of two ways: (a) directly from your browser when the conversion-tracking cookie is active after you click “Accept all” in our consent banner; (b) from our backend via the Google Ads API on server-side events such as a confirmed payment or submitted quote request. In both cases we transmit only the click identifier, the conversion event, the conversion value in euros, and an internal order reference. We do not transmit your name, email address, or any other profile information as part of this measurement.

Before you give consent, the identifier is stored locally but is neither transmitted to Google Ads nor used for conversion measurement. Processing is based on Article 6 (1) (a) GDPR (consent), which you may withdraw at any time with effect for the future via our cookie settings. On withdrawal, identifiers already stored in your browser are deleted; conversion events already transmitted to Google can additionally be managed via the privacy settings of your Google account.

Retention period: the click identifier stored locally in your browser is automatically deleted after 90 days. Conversion events transmitted to Google Ads are retained in accordance with Google Ads retention policies; for details and objection options see the Google privacy policy.

d) Legal basis

For consent-based processing in audience measurement and Google Ads conversion measurement: Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TTDSG (consent). For technically necessary storage: Art. 6 (1) (b) GDPR in conjunction with § 25 (2) No. 2 TTDSG.

e) Withdrawal of consent

You may withdraw your consent at any time with future effect. The lawfulness of processing carried out before the withdrawal is unaffected. To withdraw, click here: Change cookie settings. Alternatively, delete the cookies via your browser settings.

f) Supplementary cookie-free audience measurement

Independent of consent, we collect aggregated, non-personal usage data (page views, time-on-page, anonymised session id) on the basis of our legitimate interest (Art. 6 (1) (f) GDPR). This data is stored exclusively on our servers (Supabase, EU), contains no IP addresses, and is deleted after 90 days.

10. SSL/TLS encryption

This website uses SSL/TLS encryption for security and to protect the transmission of all content. You can recognise an encrypted connection by the change in the browser’s address bar from “http://” to “https://” and by the lock icon.

11. Your rights as a data subject

You have the following rights regarding your personal data:

To exercise your rights, please contact: [email protected]

12. Right to lodge a complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR). Our competent authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Postfach 30 40
55020 Mainz, Germany
www.datenschutz.rlp.de

13. Hosting

This website is hosted via Cloudflare Pages. When the website is accessed, technical information is automatically stored in server log files (IP address, date and time of access, page accessed, browser type, operating system).

Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare processes data in the EU. More information: Cloudflare privacy policy.

14. Google Fonts

This site uses Google Fonts for consistent typography. When a page is loaded, your browser fetches the required fonts into its cache. To do so, your browser connects to Google’s servers; Google thereby learns that the website was accessed from your IP address.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. More information: Google privacy policy.

15. Changes to this Privacy Notice

We reserve the right to amend this Privacy Notice to keep it in line with current legal requirements or to reflect changes to our services. The new Privacy Notice will apply on your next visit.

Effective April 2026.