Privacy Policy

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to our full privacy policy below.

Data Collection on This Website

Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the "Controller" section of this privacy policy.

How do we collect your data?
Some data is collected when you provide it to us — for example by filling in the waitlist form. Other data is collected automatically when you visit the website, including technical data such as your browser, operating system, or the time of the page request.

What do we use your data for?
Some data is collected to ensure the website functions correctly. Other data may be used for anonymised analysis of user behaviour. Data submitted via the waitlist form is used solely to contact you as part of the early access programme.

What rights do you have regarding your data?
You have the right to obtain, free of charge, information about the origin, recipients, and purpose of your stored personal data, as well as the right to have it corrected or deleted. You also have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time regarding these and other data protection questions.

2. Hosting

This website is hosted by:

Hetzner Online GmbH

Industriestr. 25
91710 Gunzenhausen, Germany

Processing is based on Art. 6(1)(f) GDPR. We have concluded a data processing agreement (DPA) with Hetzner. Servers are located exclusively in Germany or the European Union. No transfer to third countries takes place.

3. General Information and Mandatory Disclosures

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection legislation and this privacy policy.

Please note that data transmission over the internet may be subject to security vulnerabilities. Complete protection of data from access by third parties is not possible.

Controller

The controller for data processing on this website is:

Weiß & Siebert Solutions GmbH (operator of Revmatis)

Schulze-Delitzsch-Straße 41
70565 Stuttgart, Germany
Email: contact@revmatis.de

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

Retention Period

Unless a more specific retention period is stated in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a legitimate request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing it (e.g. statutory retention obligations under tax or commercial law).

Legal Basis for Processing

Where you have given consent to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. Where data is necessary for the performance of a contract or for pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. Processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR.

SSL / TLS Encryption

This site uses SSL or TLS encryption for security reasons. You can recognise an encrypted connection by the "https://" in the browser address bar and the padlock icon.

Objection to Promotional Emails

We hereby object to the use of contact details published as part of our legal notice obligation for the purpose of sending unsolicited advertising or informational material. We expressly reserve the right to take legal action in the event of unsolicited promotional communications, such as spam emails.

Your Rights as a Data Subject

You have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data, where no statutory retention obligations apply (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a common machine-readable format (Art. 20 GDPR)
  • Withdrawal of any consent given, with effect for the future (Art. 7(3) GDPR)
  • Lodge a complaint with the competent data protection supervisory authority (Art. 77 GDPR)

The competent supervisory authority for Baden-Württemberg is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Königstraße 10a, 70173 Stuttgart, Germany.

4. Data Collection on This Website

Cookies and Local Storage

This website does not use tracking cookies on public marketing and demo pages. Only technically necessary data (e.g. session information within the logged-in application) is stored in the browser's local storage. This data is used solely to provide functionality and is not used for advertising purposes.

Waitlist Form (Early Access)

If you apply for early access via the waitlist form, we collect the data you enter (name, email address, company, and where applicable the source URL). This data is processed solely for the purpose of handling your request and contacting you as part of the early access programme.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and, where consent was obtained, Art. 6(1)(a) GDPR. Data is retained until the purpose for processing no longer applies or you request deletion.

Contact by Email

If you contact us by email, your enquiry including all personal data arising from it (name, enquiry) will be stored and processed for the purpose of handling your request. We do not pass this data on without your consent.

The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in processing enquiries).

5. Analytics Tools

Umami Analytics

We use the web analytics tool Umami on the public pages of revmatis.de. The provider is Umami Software Inc., USA. Umami is not loaded in the logged-in area at app.revmatis.de or on demo pages.

Umami collects anonymised information about visits to our website, including pages viewed, referrer, and general browser and device information. Umami does not use cookies and does not create personal profiles. IP addresses are anonymised before processing and are not stored.

Processing is based on our legitimate interest in the anonymised analysis of website usage for the improvement of our services (Art. 6(1)(f) GDPR). As no personal data is transmitted and no cookies are set, consent is not required.

Data is processed via Umami's cloud infrastructure. For more information, see Umami's privacy policy: https://umami.is/privacy.

PostHog (Product Analytics)

Within the logged-in area of app.revmatis.de we use the product analytics tool PostHog. The provider is PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. Data is processed exclusively via PostHog's EU instance (eu.i.posthog.com) hosted within the European Union.

PostHog records product usage events within the application (pages visited, actions triggered such as running an analysis), your user ID and workspace membership, and general technical information such as browser type and time of interaction. We have disabled automatic capture of clicks and form inputs (autocapture), session recordings (session replay), and the storage of IP addresses. Only events we have explicitly defined for product analytics are recorded.

No tracking by PostHog takes place on our public marketing and demo pages. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in analysing and improving our product functionality within the contractual relationship). We have entered into a Data Processing Agreement with PostHog; transfers to the US parent company are safeguarded by EU Standard Contractual Clauses (2021/914). For more information, see https://posthog.com/privacy.

6. AI Services (LLM Providers and Observability)

Google Gemini API

We use Google's Gemini API for AI-powered analysis, scoring, and text generation within our application. The provider for customers in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA).

When AI-powered functions are used, the content you or your users enter (prompts) as well as customer data stored in the application (e.g. company information, contacts) is transmitted to Google and processed there to generate a response. We use exclusively the paid tier of the Gemini API. Google has contractually confirmed that this data is not used to train AI models and is only retained briefly for abuse checks before being deleted.

The legal basis is Art. 6(1)(b) GDPR (performance of contract) to the extent that processing is necessary to deliver the service you have purchased, and Art. 6(1)(f) GDPR (legitimate interest in providing effective AI-powered product functionality). Google's data processing terms (Data Processing Addendum) apply; transfers to third countries are safeguarded by EU Standard Contractual Clauses (2021/914). For more information, see https://policies.google.com/privacy.

Anthropic (Claude), fallback

If the Gemini API is temporarily unavailable, we fall back to Anthropic's Claude API so that AI-powered functions remain usable. The provider is Anthropic PBC, San Francisco, United States.

In that case the same content is transmitted as to Google: the prompts entered and the information about target companies required to produce a response. Names, email addresses, phone numbers and profile URLs of contacts are not transmitted to language models.

The legal basis is Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in the availability of product functionality). A data processing agreement is in place with Anthropic; transfers to the United States are safeguarded by EU Standard Contractual Clauses (2021/914). The data is not used to train AI models. For more information, see https://www.anthropic.com/legal/privacy.

LangSmith (LLM Observability)

For quality assurance, debugging, and improvement of our AI functions, we use LangSmith. The provider is LangChain, Inc., USA. Data is processed exclusively via LangSmith's EU region (eu.smith.langchain.com) hosted within the European Union.

LangSmith stores, for a limited period of 14 days, the requests (prompts) sent to the AI models, the responses returned, and associated technical metadata (duration, error messages, model identifier). This data may mirror the customer content contained in the prompts described above.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in ensuring the reliability and quality of our AI-powered product functionality). We have entered into a Data Processing Agreement with LangChain, Inc. including EU Standard Contractual Clauses (2021/914, Module 2). Internal access to trace data is restricted to a narrowly limited group of personnel. For more information, see https://www.langchain.com/privacy-policy.

7. Third-Party Services

Customer-Controlled Integrations (e.g. Apollo.io)

Certain features of Revmatis (e.g. contact discovery and enrichment) rely on integrations that customers connect themselves within the logged-in area of the application using their own account with a third-party provider. Revmatis currently supports Apollo.io (Apollo Global Corporation, USA) in this model.

Once the integration is active, Revmatis authenticates via OAuth 2.0 with the permissions granted by the customer and retrieves data (e.g. company and contact information) via the third party's API on the customer's behalf. Retrieved data is stored and further processed exclusively within the customer's workspace.

The contract for the use of the respective third-party service and the data protection responsibility for the data processed there lie directly between the customer and the third party. In particular, the customer is responsible for ensuring a valid legal basis for the processing of personal data obtained through the integration. Please refer to the privacy policy of the respective provider; for Apollo.io, see https://www.apollo.io/privacy-policy.

logo.dev (Company Logos)

We use the logo.dev service to display company logos. The provider is Logodev, Inc., USA. Logos are retrieved exclusively by our servers in Germany and delivered to your browser from there. Your browser does not connect to logo.dev, and your IP address is not transmitted to logo.dev. All that is transmitted to logo.dev is our server's address and the domain of the company whose logo is being displayed.

Processing is based on our legitimate interest in the visual presentation of company data (Art. 6(1)(f) GDPR). For more information, see: https://logo.dev/privacy.

Google Calendar (Appointment Booking)

Our demo pages offer the option to book a meeting via a link. By clicking the relevant button, you will be redirected to Google Calendar and will leave our website. From that point, only Google's privacy policy applies: https://policies.google.com/privacy. No data is transmitted to Google by us — the redirect is handled by your browser.

Last updated: July 2026