Privacy Policy (Datenschutzerklärung)

This policy explains how merentum processes personal data, pursuant to Regulation (EU) 2016/679 (GDPR / DSGVO) and the Austrian Datenschutzgesetz (DSG). merentum is built to store as little personal data as possible.

Last updated: 14 September 2026.

1. Controller

Yavor Plamenov Ivanov, Gregorygasse 10B/25, 1230 Wien, Österreich — privacy@merentum.com (see Imprint).

2. What we process, why, and on which legal basis

Account (sign-in with Google)

You sign in with Google. We store your Google account ID, email address, name and avatar URL. Purpose: providing your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). We do not store your Google password, and we do not store any Google access or refresh tokens.

Business information you submit

To generate your website you provide business details — such as business name, address, contact details, opening hours, a description of your services and, optionally, a logo. We process and store this data to generate, review and publish your website. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Emails we send you

We email you about your account and your websites — a welcome message when you sign up, and updates when a website is ready for you to review, needs changes, or goes live. These are service messages required to deliver what you asked for, not marketing, so there is no newsletter and nothing to unsubscribe from. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Subscriptions and payments

Payments are processed entirely by Stripe; your card details never reach our servers. We store your subscription plan, status and billing period, and Stripe's customer and subscription identifiers. Legal basis: performance of a contract (Art. 6(1)(b)) and legal obligations regarding bookkeeping (Art. 6(1)(c) GDPR, § 132 BAO — accounting records are retained for the statutory period of 7 years).

Service telemetry

We record technical metadata about the AI processing we perform (model used, token counts, estimated cost, timing — never the content of your submission) for internal monitoring and cost accounting. Legal basis: legitimate interest in operating a reliable service (Art. 6(1)(f) GDPR).

Server logs

We keep standard server logs (e.g. IP address, browser, access times) for security and troubleshooting. Legal basis: legitimate interest in operating a secure, reliable service (Art. 6(1)(f) GDPR).

3. Cookies

Strictly necessary cookies — the session cookie that keeps you signed in and a CSRF protection cookie — are always active and require no consent (§ 165 Abs 3 TKG 2021). We use no advertising cookies.

Analytics cookies — we use Google Analytics 4 to understand how the site is used. These cookies (e.g. _ga) are set only if you accept them in the cookie banner. Until you consent, Google Consent Mode keeps analytics storage disabled, so no analytics cookies are stored. Legal basis: your consent (Art. 6(1)(a) GDPR / § 165 Abs 3 TKG 2021). You can withdraw consent at any time via the "Cookie settings" link in the footer, with effect for the future.

We have configured Google Analytics for data minimisation: Google Signals and all advertising features are switched off, IP addresses of visitors in the EU/EEA are dropped by Google before they are logged, and analytics data is retained for no longer than 2 months.

4. Recipients and processors

  • Google Ireland Ltd. / Google LLC — sign-in (Google OAuth) and Google Analytics (usage statistics — only with your consent).
  • Stripe Payments Europe Ltd. / Stripe Inc. — payment processing and subscription billing.
  • Anthropic PBC — AI generation of your website content from the business information you submit.
  • Resend, Inc. (USA) — delivery of transactional emails about your account and your websites. Transfers are covered by the EU–US Data Privacy Framework and standard contractual clauses.
  • Hetzner Online GmbH — hosting of the application and database on servers in the EU.

Where these providers process data in the United States, transfers rely on the EU–U.S. Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR).

5. Automated processing

AI models generate website content from the business information you provide. This does not produce legal effects for you and is not automated decision-making within the meaning of Art. 22 GDPR. Every generated website is reviewed by a person before publication.

6. Retention

  • Account data (email, name, avatar): until you request account deletion.
  • Business information and generated website: until you request account deletion.
  • AI processing metadata (model, token counts, cost — not content): deleted after 90 days.
  • Billing records: 7 years (statutory retention, § 132 BAO), held by Stripe.
  • Server logs: deleted on a rolling 30-day basis.

To request deletion of your account, contact support@merentum.com — this removes all data listed above (except statutory billing records) and cancels any active subscription.

7. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interest (Art. 21). Contact us at privacy@merentum.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at).