GDPR · BriefSignal

Privacy Notice

Effective 30 August 2026 · Our own business processing is separated from processing carried out for travel-agency customers.

1. Controller

Trevion UG (haftungsbeschränkt)
Blenzerweg 19, 53426 Dedenbach, Germany
Amtsgericht Koblenz, HRB 30487
Email: privacy@brief-signal.com

We review regularly whether a statutory data protection officer must be appointed. If appointed, contact details will be published here.

2. Who controls traveller data?

The partner travel agency determines why and how traveller data in its forms, CRM, proposals and communications is used. The agency is therefore controller and Trevion UG is processor. Travellers should primarily consult the agency’s own privacy notice. Detailed duties are set out in the DPA.

3. Our processing activities

ActivityDataPurposeLegal basisRetention
Website and server logsIP address, time, URL, browser/device and error dataSecure operation, troubleshooting and abuse preventionGDPR Art. 6(1)(f)Usually 30–90 days; longer for a security investigation or legal claim
Contact and demo requestName, company, email, phone, message, source and timeAnswering requests, arranging demos and pre-contract stepsGDPR Art. 6(1)(b), (f)Usually 3 years after closure; contract retention if converted
Partner account and teamName, business contact, company, role, login and security dataAccount, permissions, 2FA and service deliveryGDPR Art. 6(1)(b), (f)Contract term plus usually 3 years; mandatory records longer
Contract acceptanceAcceptance, time, IP, document version and immutable snapshotContract performance, evidence and legal claimsGDPR Art. 6(1)(b), (c), (f)Applicable contract, limitation and commercial retention periods
Payment and invoicingCompany/billing data, VAT ID, amount, currency, transaction/invoice ID and statusPayment, recurring charge, VIES validation, accounting and invoiceGDPR Art. 6(1)(b), (c)Invoices/accounting records generally 8 years; business letters 6 years
Support and ticketsContact data, ticket, screenshot/attachment and technical metadataSupport, troubleshooting, security and qualityGDPR Art. 6(1)(b), (f)Usually 3 years after closure; longer for disputes/security incidents
Newsletter and marketingName, email, consent and opt-out dataNews, product information and proof of consentGDPR Art. 6(1)(a), or permitted legitimate interest for customersUntil withdrawal; minimal suppression data may remain

4. AI processing

When AI assistance is enabled, the form, conversation, CRM, proposal or document excerpt necessary for the task may be sent to the OpenAI API. We minimise data and customers should avoid unnecessary special-category data. API data is not used for model training by default; abuse-monitoring logs may normally be retained for up to 30 days. AI may prepare recommendations, but no final decision producing legal effects is made solely by automated means.

5. Recipients and providers

Contabo GmbH, Germany

German/EU hosting and server infrastructure; processor under a GDPR Article 28 agreement.

OpenAI Ireland Limited

AI API and image generation; processor/subprocessor under business terms and DPA.

Applicable Revolut merchant entity

Payment and recurring charges; independent controller for its own regulatory duties.

Haufe-Lexware GmbH & Co. KG

Contact, invoice and accounting data in Lexware Office.

European Commission VIES

EU VAT-number validation and evidence of the validation.

Email and integration providers

Platform email, partner-configured SMTP and integrations activated by the partner.

6. International transfers

We primarily select EU/EEA providers and regions. If personal data is transferred outside the EEA, we rely on an adequacy decision, EU Standard Contractual Clauses and supplementary safeguards where required. OpenAI Ireland Limited contracts for EEA business API data and applies safeguards to group transfers.

7. Cookies

Strictly necessary session, CSRF, security, language and consent cookies are used to provide the requested service (TDDDG §25(2), GDPR Art. 6(1)(b), (f)). Optional analytics or marketing technology is enabled only after prior, revocable consent. Refusal must not block core features. Settings can be changed through the cookie controls.

8. Your rights

You may request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting prior lawful processing. Send requests to the email above; we may verify identity.

You may complain to any competent supervisory authority, particularly where you live or work. Our lead authority is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz; poststelle@datenschutz.rlp.de.

9. Security and changes

We use access controls, encrypted transmission, tenant separation, logging, backups and incident response. We update this Notice for legal, technical or provider changes and notify material changes through an appropriate channel.

2026-08-30