Privacy policy
As of: May 2026
As of: May 2026 · Version 1.0 · GDPR- and BDSG-compliant
We are pleased about your visit to rentprime.de and your interest in our offering. The protection of your personal data is an important concern to us. In this privacy policy, we inform you comprehensively about the processing of your personal data when using our website and our software-as-a-service offering „Rentprime".
1. Verantwortlicher
Responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the Member States is the entity named in the imprint.
KRUPKA Concept GmbH
Grabenstraße 18
40789 Monheim am Rhein
Germany
E-Mail: contact@rentprime.de
2. Data protection officer
Since there is currently no statutory obligation under § 38 BDSG to appoint a data protection officer, we have not yet formally appointed one. However you can contact us at any time with data protection concerns by email to datenschutz@rentprime.de.
Sicherheitsvorfälle und mutmaßliche Datenschutzverletzungen melden Sie bitte an security@rentprime.de. Wir behandeln Meldungen vertraulich und reagieren innerhalb eines Werktages.
2a. Competent supervisory authority of your country
You have the right to lodge a complaint with a data protection supervisory authority of your member state (Art. 77 GDPR or Art. 77 UK GDPR). The authorities primarily competent for your place of residence are:
- DE: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) — ldi.nrw.de
- AT: Datenschutzbehörde (DSB) — dsb.gv.at
- CH: Eidg. Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), DSG/revDSG anwendbar — edoeb.admin.ch
- FR: Commission nationale de l’informatique et des libertés (CNIL) — cnil.fr
- IT: Garante per la protezione dei dati personali (GPDP) — garanteprivacy.it
- ES: Agencia Española de Protección de Datos (AEPD) — aepd.es
- PT: Comissão Nacional de Proteção de Dados (CNPD) — cnpd.pt
- NL: Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl
- BE: Gegevensbeschermingsautoriteit / Autorité de protection des données (APD/GBA) — autoriteprotectiondonnees.be
- LU: Commission nationale pour la protection des données (CNPD) — cnpd.public.lu
- GB: Information Commissioner’s Office (ICO), UK GDPR + Data Protection Act 2018 — ico.org.uk
- DK: Datatilsynet — datatilsynet.dk
- SE: Integritetsskyddsmyndigheten (IMY) — imy.se
- CZ: Úřad pro ochranu osobních údajů (ÚOOÚ) — uoou.cz
- PL: Urząd Ochrony Danych Osobowych (UODO) — uodo.gov.pl
2b. Representative in the Union & the United Kingdom
EU representative (GDPR Art. 27): Da unsere Niederlassung in Deutschland (EU) ist, ist gemäß Art. 27 Abs. 1 UK GDPR + DPA 2018 kein zusätzlicher Vertreter erforderlich. Verantwortliche und Kontaktstelle für EU-Datenschutzanfragen sind die unter Punkt 1 genannten Daten (KRUPKA Concept GmbH, contact@rentprime.de).
UK representative (UK GDPR Art. 27): Since we also actively offer services into the United Kingdom (rentprime.co.uk), we shall appoint a UK representative prior to the public UK launch (July 2026). Until the formal appointment, persons resident in the UK may contact us directly atuk-privacy@rentprime.dewith requests under the UK GDPR (in particular Art. 15–22); we will respond within the statutory period of one month.
Note CH: persons resident in Switzerland are covered by the revised Data Protection Act (revDSG, in force since 01.09.2023). We accept requests under Art. 25 ff. revDSG at the same contact details. Under EU law, Switzerland is regarded as a safe third country (adequacy decision).
3. General information on data processing
3.1 Scope of processing of personal data
We generally only process our users' personal data insofar as this is necessary for the provision of a functional website and our content and services. The processing of personal data of our users regularly takes place only after the user's consent or where another legal basis allows the processing.
3.2 Legal basis for processing of personal data
- Art. 6 Abs. 1 lit. a GDPR — consent of the data subject
- Art. 6(1)(b) GDPR — contract performance or pre-contractual measures
- Art. 6(1)(c) GDPR — legal obligation (e.g. tax/commercial code)
- Art. 6 Abs. 1 lit. f UK GDPR + DPA 2018 — Berechtigtes Interesse
3.3 Data deletion and storage period
The data subject's personal data is deleted or blocked as soon as the storage purpose ceases. Further storage may take place if provided for by EU or national legislation in regulations, laws or other rules to which the controller is subject — in particular tax and commercial law retention periods of up to 10 years.
4. Provision of the website and creation of log files
4.1 Description of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the calling device. The following data is collected:
- IP-Adresse des Nutzers (anonymisiert)
- Date and time of access
- Browser and operating system used
- Page accessed and referrer URL
- Volume of data transferred
The data is stored in our system's log files. This data is not stored together with other personal user data. Retention is 7 days.
4.2 Rechtsgrundlage
Legal basis for the temporary storage of data and log files is Art. 6 (1) (f) GDPR. Our legitimate interest follows from the purposes for data collection mentioned above.
4.3 Speicherdauer
Log file data is deleted or anonymized after a maximum of 14 days.
5. Hosting
Our website and our SaaS offering are processed in the EU (database region Sweden/Stockholm, compute regions Frankfurt and Stockholm) with providers certified to ISO 27001; some of these providers are US companies, for which we apply the EU-US Data Privacy Framework (DPF) and/or EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018). Specifically, we use: Vercel Inc. (USA; frontend and serverless function hosting, compute in Frankfurt/fra1 — DPF + SCC), Fly, Inc. (USA; operation of the application API api.rentprime.de, compute in Frankfurt/fra — SCC), Supabase Inc. (USA; application database in the EU region Stockholm/eu-north-1 — DPF + SCC) as well as Cloudflare Inc. (USA; CDN, DDoS and WAF protection — DPF + SCC). All providers were carefully selected and contractually obliged to comply with the UK GDPR + DPA 2018 (data processing agreement pursuant to Art. 28 UK GDPR + DPA 2018).
Core and tenant data are processed encrypted within the European Union (database in Stockholm/Sweden). Individual AI functions are processed via Anthropic or Google in the USA; this third-country transfer is safeguarded by the EU-US Data Privacy Framework and EU-Standardvertragsklauseln (Art. 46 UK GDPR + DPA 2018) (see section 12a).
For the AI-supported functions (Lou assistant, receipt recognition) we carry out data protection impact assessments pursuant to Art. 35 UK GDPR + DPA 2018 and transfer impact assessments for the third-country processors (Anthropic, Google, Stripe) in accordance with EDPB Recommendation 01/2020. We provide these documents as well as our incident response playbook (Art. 33/34 UK GDPR + DPA 2018) to supervisory authorities and data subjects on request at datenschutz@rentprime.de zur Verfügung.
6. Registration and user account
You can register on our website by providing personal data. During registration the following data is transmitted to us: email address, first and last name, company name and time of registration.
- First and last name
- Email address
- Password (stored encrypted with bcrypt, no plain text)
- Telefonnummer (optional)
- Firmendaten (bei gewerblicher Nutzung)
Legal basis for processing is Art. 6 (1) (b) GDPR (contract performance). Data is stored for the duration of your usage relationship and archived after termination per tax and commercial law retention obligations (10 years).
7. Contract processing — software usage data
When using Rentprime you will process your tenants' personal data as the responsible body under GDPR. We are processor under Art. 28 GDPR. To fulfill the legal requirements we conclude a data processing agreement (DPA) with you, available on request. /av-vertrag available or will be sent on request.
The following data categories are processed in the scope of software use:
- Tenant data (name, address, contact details, IBAN, marital status for calculating occupancy)
- Tenancy agreement data (commencement of tenancy, end of tenancy, rent, service-charge advance payment)
- Consumption data (heating, water, other consumption-dependent costs)
- Receipts and invoices (supplier data, cost types, amounts)
- Payment and communication history between landlord and tenant
8. Cookies and comparable technologies
Our website uses cookies and comparable technologies. Detailed information can be found in our cookie banner and in the sections below.
8.1 Technisch notwendige Cookies
We use technically necessary cookies to ensure the functionality of our website (e.g. session cookies to maintain login status, language preference). These cookies are essential and cannot be deselected.
8.2 Functional cookies
Functional cookies serve to improve the user experience (e.g. storing filter settings, language preference). These are only set with your consent and can be deactivated at any time.
8.3 Statistics cookies
We currently do not use any statistics or marketing cookies. Should we integrate such services in future (e.g. Plausible Analytics or Matomo), we will obtain user consent in advance via a consent banner.
9. Kontaktaufnahme
9.1 Contact form and email
If you contact us via contact form or email, your details from the inquiry form including the contact data you provided there are stored with us for the purpose of processing the inquiry and for follow-up questions.
Processing of this data is based on Art. 6 (1) (b) GDPR insofar as your inquiry relates to performance of a contract or is necessary for pre-contractual steps. In all other cases processing is based on Art. 6 (1) (f) GDPR (legitimate interest in effective inquiry handling).
9.2 KI-basierter Chatbot (Lou)
On our contact page we operate an AI-based chatbot called "Lou". When you use the chatbot, your requests are processed in order to generate a corresponding response. For this purpose we use the language model services of Anthropic PBC (USA); in doing so, a transfer to the USA takes place. Anthropic is DPF-certified (EU-US Data Privacy Framework, adequacy decision of the EU Commission of 10.07.2023); in addition, EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018) apply. Anthropic is listed as a processor in the AVV. Processing takes place exclusively to answer your request. Your inputs are contractually guaranteed not to be used for training the language models (zero retention/no training according to the AVV).
Please do not enter any particularly sensitive personal data (Art. 9 GDPR) in the chatbot. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in effective support).
10. Zahlungsabwicklung
For payment processing we use Stripe Payments Europe Ltd., Ireland. For credit card payments your payment data is transmitted exclusively to Stripe and stored there per PCI-DSS Level 1 standards. We ourselves do not store credit card data. stripe.com/de/privacy.
11. E-Mail- und Nachrichtenversand
For transactional email delivery (e.g. password reset, contract confirmations) we primarily use Resend, Inc. (San Francisco, USA) and, as a fallback, Postmark by ActiveCampaign LLC (Chicago, USA). Both providers are DPF-certified (EU-US Data Privacy Framework); additionally, EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018) apply. Legal basis: Art. 6 Abs. 1 lit. b und f UK GDPR + DPA 2018.
For managing the newsletter and lead form we use Brevo (Sendinblue SAS, Paris, France). The processing takes place within the EU; there is no third-country connection. Legal basis: Art. 6 Abs. 1 lit. a UK GDPR + DPA 2018 (consent); you can withdraw your consent at any time via the unsubscribe link in every email.
For the optional SMS and WhatsApp dispatch (tenant communication) we use Twilio Inc. (San Francisco, USA). Twilio is DPF-certified; additionally, EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018) apply. Legal basis: Art. 6 Abs. 1 lit. f UK GDPR + DPA 2018 (legitimate interest in efficient tenant communication) — only when tenant communication is activated.
12. Recipients of your personal data
Your data is only transferred to the processors listed below, insofar as this is necessary to perform their tasks, as well as to bodies under a legal obligation or with your consent. The following processors are granted access to your data:
- Vercel Inc. (340 S Lemon Ave #4133, Walnut CA 91789, USA) — Hosting des Frontends und der Serverless-Functions (u. a. /api/geo, /api/newsletter, /api/leads, /api/csp-report, Blog-Cron); Compute-Region Frankfurt (fra1). Drittlandmechanismus: EU-US Data Privacy Framework (DPF) + EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018).
- Fly, Inc. (2261 Market Street #4990, San Francisco CA 94114, USA) — Betrieb der Anwendungs-API api.rentprime.de mit Compute-Region Frankfurt (fra); verarbeitet Kern- und Mieterdaten. Drittlandmechanismus: EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018); Fly ist nicht DPF-gelistet.
- Supabase Inc. (970 Toa Payoh North #07-04, Singapur; Konzernmutter USA) — Hosting der Anwendungs-Datenbank in der EU-Region Stockholm/eu-north-1 (Schweden). Drittlandmechanismus: DPF + SCC.
- Cloudflare Inc. (101 Townsend St, San Francisco CA 94107, USA) — CDN-, DDoS- und WAF-Schutz; Edge-Verarbeitung in der EU. Drittlandmechanismus: DPF + SCC.
- Stripe Payments Europe Ltd., Dublin, Irland (Zahlungsabwicklung; Verarbeitung innerhalb der EU, Konzernanbindung an Stripe, Inc. USA — DPF + SCC).
- Brevo (Sendinblue SAS), 106 boulevard Haussmann, 75008 Paris, Frankreich — Verwaltung des Newsletter- und Lead-Formulars sowie transaktionaler E-Mail-Versand; Verarbeitung innerhalb der EU (kein Drittland-Mechanismus erforderlich). Rechtsgrundlage: Art. 6 Abs. 1 lit. a UK GDPR + DPA 2018 (Einwilligung).
- Resend, Inc., San Francisco, USA — Transaktions-Mail-Versand (Passwort-Reset, Vertragsbestätigungen). Drittlandmechanismus: DPF + SCC.
- Postmark (ActiveCampaign LLC), Chicago, USA — Transaktions-Mail-Fallback. Drittlandmechanismus: DPF + SCC.
- Twilio Inc., San Francisco, USA — SMS- und WhatsApp-Versand (nur bei aktivierter Mieterkommunikation). Drittlandmechanismus: DPF + SCC.
- finAPI / Klarna Kosma (Bank-Sync nach PSD2 — nur bei aktivierter Kontoanbindung; Verarbeitung innerhalb der EU).
- Anthropic PBC, San Francisco, USA (KI-Chatbot Lou und Vertrags-Check — nur bei aktiver Nutzung). Drittlandmechanismus: DPF + SCC.
- Anthropic PBC, San Francisco, USA (Claude Vision für Beleg-/OCR-Erkennung — nur bei aktiver Nutzung). Drittlandmechanismus: DPF + SCC.
Appropriate contracts per Art. 28 GDPR have been concluded with all processors.
12a. Transfer to third countries
Your core and tenant data are stored and processed encrypted within the EU (application database in Stockholm/Sweden, compute in Frankfurt and Stockholm with providers certified to ISO 27001). Since we use US providers for frontend hosting, API operation, database provisioning, CDN/WAF, transactional email, SMS/WhatsApp and individual AI functions, a transfer to the USA takes place in this respect. Affected are Vercel Inc., Fly Inc., Supabase Inc., Cloudflare Inc., Resend Inc., Postmark (ActiveCampaign LLC), Twilio Inc., Anthropic PBC and Google LLC. All US processors with the exception of Fly Inc. are certified under the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10.07.2023); for Fly Inc. and additionally for all others, EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018) apply, together with technical and organizational measures (encryption in transit and at rest, PII minimization, contractually guaranteed zero retention/no training with the AI providers). All named providers are listed as processors in the AVV.
Rechtsbehelf nach EO 14086: Betroffene Personen in der EU können sich gegen US-Geheimdienst-Zugriffe auf ihre Daten an den Data Protection Review Court (DPRC) wenden. Erstanlaufstelle ist die zuständige nationale Aufsichtsbehörde (für Deutschland: LDI NRW Düsseldorf, siehe oben), die Beschwerden an die EU-Kommission und an das US Office of the Director of National Intelligence (ODNI) weiterleitet.
13. Ihre Rechte als betroffene Person
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
13.1 Auskunftsrecht (Art. 15 UK GDPR + DPA 2018)
You may request confirmation from the controller whether your personal data is being processed by us. If such processing exists, you may demand further information.
13.2 Right to rectification (Art. 16 GDPR)
You have a right of rectification and/or completion against the controller, provided that the personal data processed is incorrect or incomplete. The controller must carry out the rectification without delay.
13.3 Right to erasure (Art. 17 GDPR)
You may demand from the controller that your personal data be deleted without delay, provided one of the statutory grounds applies and processing is not absolutely necessary.
13.4 Right to restriction of processing (Art. 18 GDPR)
Under certain conditions you can request the restriction of the processing of your personal data.
13.5 Right to data portability (Art. 20 GDPR)
You have the right to receive your personal data that you have provided to the controller in a structured, commonly used and machine-readable format.
13.6 Widerspruchsrecht (Art. 21 UK GDPR + DPA 2018)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6 (1) (e) or (f) GDPR.
13.7 Right to withdraw consent (Art. 7 para. 3 GDPR)
You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent before withdrawal.
13.8 Right to complain to a supervisory authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your residence, place of work or place of the alleged infringement — if you believe that the processing of your personal data violates the GDPR.
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Telefon: +49 211 38424-0
E-Mail: poststelle@ldi.nrw.de
14. Datensicherheit
We employ technical and organizational measures to protect your personal data against loss, manipulation and unauthorized access. Our security measures are continuously improved in line with technical developments.
- TLS 1.3 encryption for data transmission between browser and server
- AES-256 encryption of sensitive data at database level
- Password storage exclusively with bcrypt (no plain text)
- Two-factor authentication (2FA) optionally activatable
- Regular security audits and penetration tests
- Backup strategy with encrypted off-site copies
- Hosting bei nach ISO 27001 zertifizierten EU-Anbietern (Anwendungs-Datenbank in Stockholm/Schweden, Compute in Frankfurt und Stockholm)
15. Topicality and changes to the privacy policy
This privacy policy is currently valid and dated May 2026. Due to the further development of our website and offerings or changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. You can read and print the current version on our website. rentprime.de/datenschutz can be retrieved and printed by you.