Privacy policy
Last updated: 7/25/2026
Privacy Policy
Last updated: July 2026
Controller
Campaiva, owner: Florian Bassiouni (sole proprietorship), Ricklinger Stadtweg 13, 30459 Hannover, Germany — office@campaiva.com.
Roles
We are the controller for website visitors and platform accounts (this policy). For data our customers process on the platform (CRM contacts, email recipients, landing-page visitors) we act as processor under Art. 28 GDPR based on our Data Processing Agreement; data subjects should contact the respective customer.
Processing overview
- Hosting: Hetzner (Germany/EU); server logs for security and stability (Art. 6(1)(f) GDPR), rotated regularly. Encrypted backups within the EU.
- Account: email, name, company, hashed password, double-opt-in timestamp; security audit logs with hashed IPs (Art. 6(1)(b), (f) GDPR).
- Payments: Stripe (SCCs / EU-US Data Privacy Framework); card data never touches our systems (Art. 6(1)(b) GDPR).
- Cookies: strictly necessary (auth, CSRF, session — always on); functional and first-party analytics only with consent (§ 25 TDDDG, Art. 6(1)(a) GDPR). No third-party tracking or marketing cookies. Manage anytime under Settings → Privacy.
- Error monitoring: Sentry with EU (Germany) ingest endpoint and PII scrubbing (Art. 6(1)(f) GDPR).
- Email: transactional mail via IONOS (Germany); customer campaigns are sent through the customer's own SMTP or Microsoft 365 account (we act as processor); own newsletters only with double opt-in.
- AI features: prompts and uploaded assets are sent to OpenAI, Anthropic, Google (Gemini/Veo), HeyGen and ElevenLabs (USA*) only when you use the respective feature; inputs are not persisted by default and are not used for model training under our data processing agreements. Bring-your-own-key is supported.
- Connected accounts: Meta (Facebook/Instagram/Ads), Google, LinkedIn, Microsoft 365, Shopify via OAuth — tokens stored encrypted, strictly per customer; ad audiences only as hashed identifiers; revocable at any time (tokens are then deleted).
- Landing pages & measurement: processed on behalf of the respective customer (controller); the customer must inform visitors under Art. 13 GDPR.
Google user data (Google API Services User Data Policy)
Campaiva's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: data is used only for user-facing features the user activated, is never sold, never used for third-party advertising or profiling, is not transferred except to provide or improve those features, as required by law, or with explicit consent, and no humans read it except with consent, for security/abuse, legal compliance, or in aggregated/anonymized form. Tokens are stored encrypted and can be revoked in Campaiva ("Integrations → disconnect") or at myaccount.google.com/permissions; stored tokens are then deleted.
Transfers, retention, rights
*US transfers are safeguarded by EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework; current sub-processor list at campaiva.com/trust. Retention: account data 30 days after contract end; usage/security data ~90 days; uploaded media 90 days or per plan; invoicing data 10 years (German law). You have the rights of access, rectification, erasure, restriction, portability, objection (Art. 21 GDPR — direct marketing: at any time) and consent withdrawal; contact office@campaiva.com. Supervisory authority: Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover. No automated decision-making under Art. 22 GDPR takes place.