Privacy policy
Information on the processing of personal data when using re:one
As of: July 15, 2026
1. Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Maik Masur, acting under the business name „Valend", Spohrstraße 61, 60318 Frankfurt am Main, Germany. Email: contact@valend.de
2. Scope
This privacy policy informs you about the processing of personal data when using Valend's websites, mobile applications, software solutions, platforms and other digital services, including re:one and future products.
It applies to all visitors of our websites as well as to registered users of our services.
3. General information on data processing
The protection of your personal data is of high importance to Valend.
We process personal data exclusively in accordance with applicable data protection regulations, in particular the GDPR, the Federal Data Protection Act (BDSG) and other applicable data protection provisions.
Personal data is any information relating to an identified or identifiable natural person.
We process personal data only insofar as this is necessary to provide our services, to fulfill contractual obligations, due to legal requirements or on the basis of consent.
4. Hosting and technical infrastructure
Our services are provided via the technical infrastructure of external service providers.
The following data may be processed in particular:
- IP address
- Date and time of access
- Browser type
- Operating system
- Device information
- Referrer URL
- Hostname
- Technical error logs
This processing serves to securely provide our services, for error analysis and to ensure the stability and security of our systems.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
5. Use of Base44
For the development, provision, hosting and technical operation of re:one, Valend uses the Base44 platform.
The provider of the platform is: Base44, Inc.
When using Base44, personal data may be processed insofar as this is necessary for the provision and operation of re:one.
This may include in particular the following data:
- Registration and user account data
- Contact data
- Technical usage and log data
- IP addresses and device information
- Content entered by the user
- Uploaded files and documents
- Data from connected Google or Microsoft services
- Communication, calendar and organization data
- Content processed within AI functions
- Error and security logs
Base44 processes personal data on behalf of Valend and in accordance with Valend's instructions. The processing is based on Base44's Data Processing Addendum as a data processing agreement in accordance with Art. 28 GDPR.
Base44's Data Processing Addendum is available at: https://base44.com/dpa
Base44 may use further sub-processors for the technical provision of its services.
If personal data is processed by Base44 or its sub-processors outside the EU or EEA, the data transfer takes place in compliance with the legal requirements of Art. 44 et seq. GDPR.
Transfer grounds that may be used in particular include:
- an adequacy decision of the European Commission
- the EU-US Data Privacy Framework, provided the respective recipient is effectively certified
- the standard contractual clauses of the European Commission
- or another legally permissible transfer ground
The legal basis for processing is Art. 6 para. 1 lit. b GDPR insofar as the processing is necessary for the provision of re:one.
Insofar as the processing serves the secure, stable and economic provision of re:one, it is based on Art. 6 para. 1 lit. f GDPR.
After termination of the contractual relationship or deletion of the user account, the personal data stored at Base44 will be deleted in accordance with contractual and statutory requirements.
6. Server log files
When visiting our websites, information is automatically stored in so-called server log files.
This includes in particular:
- IP address
- Date and time
- Browser information
- Operating system
- Page accessed
- HTTP status code
- Amount of data transferred
- Referrer URL
This data serves exclusively for technical provision, error analysis, abuse detection and IT security.
This data is generally not merged with other data sources.
The log data is regularly deleted unless statutory retention obligations or security incidents require longer storage.
7. Cookies and consent management
Our websites use cookies and comparable technologies.
Technically necessary cookies serve to securely provide our services and to store your privacy settings.
Analytics and convenience functions are activated only after your explicit consent.
The legal bases for this are:
- § 25 para. 2 TDDDG for technically necessary cookies
- § 25 para. 1 TDDDG for consent-based cookies
- Art. 6 para. 1 lit. a GDPR (consent)
- Art. 6 para. 1 lit. f GDPR (legitimate interest)
You can revoke your consent at any time with effect for the future.
8. Analytics and usage statistics
To improve our services, we may use analytics functions.
The following information may be processed in particular:
- Page views
- Session duration
- Click behavior
- Browser information
- Device information
- Approximate geographic region
- Anonymized or truncated IP address
Analytics functions are activated only if you have previously given your consent.
Individual users are generally not identified.
9. Registration and user account
For certain services – in particular re:one – creating a user account is required.
The following data may be processed in particular:
- Name
- Email address
- Encrypted password
- Profile information
- Language settings
- Time zone
- Account settings
This data serves exclusively to provide the user account, for authentication and for the security of our services.
Legal basis is Art. 6 para. 1 lit. b GDPR.
10. Contact
If you contact us by email or via a contact form, we process your information exclusively to handle your request.
This concerns in particular:
- Name
- Email address
- Content of your message
- Voluntarily provided information
Legal basis is Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
The data will be deleted as soon as it is no longer required for the respective purpose and no statutory retention obligations conflict.
11. Data security
Valend employs appropriate technical and organizational measures to protect personal data from loss, misuse, manipulation, unauthorized access, alteration, disclosure or other unlawful processing.
This includes in particular:
- Encrypted data transmissions using TLS/SSL
- Role-based access and permission concepts
- Access restrictions
- Regular security updates and reviews
- Logging of security-relevant events
- Measures to secure and restore data availability
The security measures are regularly reviewed and developed in line with technological progress.
Despite appropriate technical and organizational measures, complete security during data transmission over the internet cannot be guaranteed.
12. Login via Google (Google OAuth)
For logging into our services, authentication via a Google account can be used.
The provider of Google services for users within the European Economic Area is: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Access is via the OAuth 2.0 process. re:one does not receive the Google account password, but only the authentication information and permissions released by the user.
The following data may be processed in particular – depending on the permissions you have granted:
- Name
- Email address
- Google account ID
- Profile picture (optional)
- Authentication information
The login serves exclusively for the purpose of authentication and providing your user account.
Legal basis is Art. 6 para. 1 lit. b GDPR.
Further information can be found in Google's privacy policy: https://policies.google.com/privacy
13. Login via Microsoft
Alternatively, login via a Microsoft account is possible.
The provider of Microsoft services for users within the European Economic Area is: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Access is via the OAuth 2.0 or OpenID Connect process.
The following data may be processed in particular:
- Name
- Email address
- Microsoft account ID
- Profile information
- Authentication information
Processing serves exclusively for login and management of your user account.
Legal basis is Art. 6 para. 1 lit. b GDPR.
Further information can be found in Microsoft's privacy policy: https://privacy.microsoft.com/
14. Google Drive
If you connect Google Drive with re:one, Valend processes only the data necessary for the functions you have expressly requested.
Depending on usage, this may include in particular:
- File names
- Folder structure
- Metadata
- Document content
- Sharing settings
Access is granted only after your explicit consent.
Valend processes this data exclusively to provide the desired functions.
Legal basis is Art. 6 para. 1 lit. b GDPR.
15. Gmail
If you connect your Gmail account, re:one may process email data – depending on the permissions you have granted.
This may include in particular:
- Sender
- Recipient
- Subject
- Time of sending
- Message body
- Attachments
- Labels and markers
This data is processed exclusively to provide the functions you want.
Valend does not use Gmail data for advertising purposes and does not sell it to third parties.
Legal basis is Art. 6 para. 1 lit. b GDPR.
16. Google Calendar
If you connect Google Calendar, the following data may be processed in particular:
- Appointments
- Start and end
- Participants
- Locations
- Descriptions
- Reminders
Processing serves exclusively to provide the desired functions within re:one.
Legal basis is Art. 6 para. 1 lit. b GDPR.
17. Microsoft 365
If you connect Microsoft services with re:one, the following data may be processed – depending on the permissions you have granted:
- Outlook emails
- Calendar
- Contacts
- OneDrive files
- Microsoft Teams information
Processing takes place exclusively within the framework of the functions you use.
Legal basis is Art. 6 para. 1 lit. b GDPR.
18. APIs and third parties
Our services can be connected with third-party applications and services.
Which data is processed depends on the respective integrations and the permissions you have granted.
Processing serves exclusively to provide the desired functions.
The respective data protection provisions of third parties apply additionally to the processing of personal data by third parties.
19. Permissions and revocation
You decide which integrations to connect with your user account.
Permissions already granted can be revoked at any time via the settings of the respective third-party provider or within the corresponding application.
After revocation, no new data will be processed via the relevant integration. Already stored data will be deleted or anonymized in accordance with statutory requirements.
Users can disconnect their Google or Microsoft connection at any time within re:one or via the security and permission settings of their respective account.
Use of Google user data
The use and transfer of information that re:one receives via Google APIs is in accordance with the Google API Services User Data Policy and the Limited Use requirements therein.
Google user data is used exclusively to provide or improve the functions expressly requested by the user and visible within re:one.
Google user data is in particular not:
- sold
- used for personalized advertising or retargeting
- passed on to data brokers or advertising platforms
- used to assess creditworthiness
- or used to train or improve general AI or machine learning models
Access by humans occurs only if the user has expressly consented, if this is necessary for security reasons, or if there is a legal obligation.
20. Data minimization
Valend processes only the personal data necessary to provide the respectively used functions.
We orient ourselves on the principle of data minimization in accordance with Art. 5 para. 1 lit. c GDPR and limit access to the necessary extent.
Where technically possible, data is processed in pseudonymized or anonymized form.
21. Artificial intelligence (AI)
Individual services of Valend, in particular re:one, use artificial intelligence (AI) functions to support users in organizing, processing and analyzing information.
Depending on the function used, the following data may be processed in particular:
- Text inputs
- Documents
- Notes
- Emails
- Contacts
- Calendar information
- Tasks
- Metadata
- Other content provided by the user
Processing serves exclusively to provide the functions requested by the user.
Personal data is not used to train our own AI models, unless this is expressly stated and separately approved by the user.
Legal basis is Art. 6 para. 1 lit. b GDPR and – if required – Art. 6 para. 1 lit. a GDPR.
22. Uploaded files and documents
Users can store or process documents, files, images and other content in re:one.
This data is processed exclusively to provide the desired functions, to store and synchronize content, and to make it accessible to the user within their account.
Valend does not claim any ownership rights to the content uploaded by the user.
23. Contacts, calendar and tasks
If users use corresponding functions or activate integrations, contacts, appointments, tasks and other organizational data may be processed.
This processing serves exclusively to provide the functions desired by the user.
This data is not passed on to third parties unless this is technically necessary or legally required.
24. Communication within the services
If our services provide communication functions, messages, comments, file shares and similar content may be processed.
Processing serves exclusively to provide the respective function and to ensure the security of our services.
25. Processors
Valend uses carefully selected service providers who process personal data exclusively on our behalf and according to our instructions.
Where legally required, data processing agreements in accordance with Art. 28 GDPR are concluded with these service providers.
26. Recipients of personal data
Personal data is generally not sold to third parties or passed on for advertising purposes.
A transfer takes place exclusively,
- when this is necessary for contract fulfillment
- when you have expressly consented
- when we are legally obliged to do so
- or when service providers process personal data as part of data processing.
27. International data transfers
If personal data is processed outside the EU or EEA, this takes place exclusively in compliance with the legal requirements of the GDPR.
This is done in particular on the basis of
- an adequacy decision of the European Commission
- the standard contractual clauses of the European Commission
- or another legally permissible basis in accordance with Art. 44 et seq. GDPR.
28. Storage duration
Personal data is stored only as long as is necessary to fulfill the respective processing purpose or as long as statutory retention obligations exist.
After the respective purpose ceases to apply, personal data is deleted or anonymized unless legal obligations conflict with deletion.
29. Your rights as a data subject
Under the GDPR, you have the following rights:
- Right to access in accordance with Art. 15 GDPR
- Right to rectification in accordance with Art. 16 GDPR
- Right to erasure in accordance with Art. 17 GDPR
- Right to restriction of processing in accordance with Art. 18 GDPR
- Right to data portability in accordance with Art. 20 GDPR
- Right to object to processing in accordance with Art. 21 GDPR
- Right to withdraw consent given in accordance with Art. 7 para. 3 GDPR with effect for the future
To exercise your rights, an informal notification to: Email: contact@valend.de is sufficient.
30. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.
The data protection supervisory authority responsible for Valend is: The Hessian Commissioner for Data Protection and Freedom of Information, Wilhelmstraße 7, 65185 Wiesbaden, Germany
Email: poststelle@datenschutz.hessen.de · Website: https://datenschutz.hessen.de
31. Data protection officer
Currently, there is no legal obligation for Valend to appoint a data protection officer.
If a legal obligation arises in the future or a data protection officer is voluntarily appointed, the corresponding contact details will be published in this privacy policy.
32. Automated decisions
A decision based solely on automated processing within the meaning of Art. 22 GDPR does not generally take place.
If individual functions include automated decisions or profiling in the future, affected users will be informed separately.
33. Changes to this privacy policy
Valend reserves the right to adapt this privacy policy if this becomes necessary due to legal changes, technical developments, new functions or changed processing processes.
The version published at the time of your visit applies in each case.
Registered users will be informed of significant changes in an appropriate manner.
34. Contact
If you have questions about data protection, the processing of your personal data or the exercise of your data protection rights, you can contact the controller named in section 1 at any time.