Skip to content
Start

Privacy Policy

This policy tells you which data we process, what for, who else sees it, how long we keep it and what rights you have.

Last updated: 08/09/2026

This is a translation for your convenience. In case of dispute, the German version applies.

Who is responsible?

Purple Digital UG (haftungsbeschränkt) represented by the managing director Christoph Sterkel Eifflerstraße 43 22769 Hamburg, Germany E-mail: datenschutz@halloamt.de

We have not appointed a data protection officer.

What this is about

HalloAmt helps you fill in German government forms. To do that we process information that is very personal: your name and address, income, family circumstances, nationality, residence status and which social benefit you receive.

We are aware of what that means. This policy therefore tells you exactly which data we process, what for, who else sees it, how long we keep it and what rights you have.

Which data we process and why

1. Your account — e-mail address and password; if you sign in with Google, the identifier and e-mail address held there. Purpose: so that you can sign in and find your applications again. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). How long: until you delete your account. Accounts created without registration are deleted automatically after 30 days.

2. What you enter in the chat — everything you provide so that a form can be filled in: name, date and place of birth, address, nationality, marital status, details about children and spouse, bank details (IBAN), tax identification number, details about work and income, residence status and the type of benefit you receive. Plus the conversation history. Purpose: to fill in the form correctly, and so that you do not have to enter everything again for your next application. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). How long: until you delete the application or your account.

3. Your completed form — the filled-in PDF. Legal basis: performance of a contract. How long: free previews are deleted after 7 days. The finished, paid PDF is yours and remains until you delete it, the application it belongs to, or your account. When you delete an application, a record without any content remains with us: date, status and the confirmation that you checked the form before downloading it. It contains none of your entries; we need it to count your subscription quota correctly and to be able to show, in case of a dispute, that the form was available to you before you submitted it.

4. Your payment — payment status, subscription data, customer number at Stripe. We never see your card details — you enter those directly with Stripe. Legal basis: performance of a contract; for invoices additionally statutory retention obligations (Art. 6(1)(c) GDPR). How long: subscription data until account deletion; accounting records for as long as the law requires.

5. Protection against misuse — an encrypted identifier derived from your IP address (not the IP address itself), usage counters and the cost per request. Purpose: so that nobody can abuse the service automatically and cause costs we cannot bear. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). How long: 90 days.

6. Your feedback — what you write to us via the feedback or bug report form. This includes the text, the page you were on, the version of the interface and a rough device hint such as “Chrome on Android”. An e-mail address for follow-up questions is optional. Legal basis: legitimate interest (Art. 6(1)(f) GDPR); for the optional e-mail address your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time. How long: until processed; if you delete your account, we delete your reports with it.

7. If you request a form — name of the form, authority, your location, your e-mail address and, if you upload one, the file. Purpose: so that we can add the form and reply to you. Legal basis: performance of a contract and legitimate interest. How long: uploaded files are deleted as soon as we have identified the form, at the latest after 30 days.

Who sees your data besides us

We work with service providers. There are two kinds, and the difference matters to you:

  • On our behalf means: the provider may only do with your data what we tell them to. We remain responsible, and this policy here applies.
  • On their own responsibility means: the provider decides themselves what to do with the data. Their own privacy policy applies to that, not ours.

On our behalf (processors, bound by our instructions)

WhoWhat forWhere
Supabaseaccount, database, storage of your data and PDFsdata centre Frankfurt am Main
Anthropicthe AI that runs the chat and fills in the formUSA
Cloudflaredelivery of the websiteworldwide, EU locations
Resenddelivery of our emails — address, subject and contentUSA
Stripeprocessing of your paymentEU company, corporate group based in the USA

With each of these five providers there is a data processing agreement under Art. 28 GDPR.

Recipients acting on their own responsibility

WhoWhat forWhere
Googleonly if you use “Sign in with Google”USA
StripepaymentEU entity, group based in the USA
Resendwho wrote to which address and whenUSA
easybellour phone line and the announcementGermany

Google does not act on our behalf: when you use “Sign in with Google”, you sign in with Google — Google is responsible for that itself, and Google’s own privacy policy applies. If you do not use that route, Google learns nothing about you.

Stripe has both roles, and our contract says so: Stripe handles the payment on our behalf; for its own purposes, above all fraud detection, Stripe decides itself. That is why Stripe appears in both lists.

Resend also has both roles, and that is also stated in our contract: Resend sends your email on our behalf — address, subject and content. Resend also processes the traffic data, i.e. who wrote to which address and when, for its own purposes and decides on this itself. That is why Resend appears in both lists.

We do not measure whether you open or click an email. Resend could offer this; we have not set it up. There is no tracking pixel and no rewritten links.

Beyond that we pass nothing on — in particular not to authorities, employers, landlords or credit agencies. You submit your applications yourself.

If you call us

Our phone number is answered by an automated announcement. No conversation takes place — nobody picks up, and you cannot leave a message either.

Our telephone provider easybell sends us an email after a call. It contains your phone number and the time of the call — so that we can see that someone called. Nothing is recorded: easybell does not store such calls but forwards them to us immediately by email.

easybell is itself responsible for the connection data — under the legal framework, a telephone provider always is, for the circumstances of telecommunications. That is why easybell is listed above rather than among the processors, and why there is no data processing agreement for this.

The call email lands in our inbox and is deleted manually once it has been dealt with. The legal basis is our legitimate interest in being reachable (Art. 6 Abs. 1 lit. f DSGVO).

Transfer to the USA — what you should know

So that the AI can fill in your application, your chat texts are transferred to Anthropic in the USA and processed there. This concerns exactly the information listed under point 2 above.

What applies here:

  • Your data is not used to train the AI.
  • We have specified that processing takes place exclusively in the USA and not in changing countries.
  • Your data is stored in Frankfurt am Main, not in the USA.
  • Not transferred are your account, your payment data and the finished PDF — that is created on our server in Frankfurt, without the AI.

The USA is not a country whose level of data protection the European Commission has generally recognised as equivalent. That is why we base every transfer on one of the safeguards the GDPR provides for this:

RecipientWhat we base the transfer on
Anthropic — your chat textsStandard contractual clauses of the EU Commission (Implementing Decision (EU) 2021/914, Modules 2 and 3). They form part of our data processing agreement with Anthropic.
Stripe — paymentOur contracting party is Stripe Payments Europe, Ltd. in Ireland. For onward transfers within the Stripe group, the standard contractual clauses and the certification under the EU-US Data Privacy Framework apply.
Google — only with “Sign in with Google”Google LLC is certified under the EU-US Data Privacy Framework. This transfer is therefore covered by the adequacy decision of the European Commission — it needs no additional safeguard.
Cloudflare — delivery of the websiteStandard contractual clauses of the EU Commission (Implementing Decision (EU) 2021/914). They form part of the data processing agreement which our terms of use with Cloudflare incorporate.
Supabase — account, database, storageStandard contractual clauses of the EU Commission (Implementing Decision (EU) 2021/914). Your data is stored in Frankfurt am Main; the transfer concerns access by the US parent company.
Resend — delivery of our emailsOur contractual partner is Plus Five Five, Inc. in San Francisco. The transfer is based on the Standard contractual clauses of the EU Commission (Implementing Decision (EU) 2021/914, Module 2) and additionally on the certification under the EU-US Data Privacy Framework. According to the contract, processing takes place predominantly in the USA.

You can request a copy of these safeguards from us. Write to datenschutz@halloamt.de and we will send them to you.

How long Anthropic keeps your texts. Permanently, your data is stored only with us in Frankfurt am Main (see above). At Anthropic the transferred text additionally remains for up to 30 days; after that Anthropic deletes it. Within that period Anthropic may review it for security and abuse-prevention purposes.

If Anthropic’s automated abuse detection flags an event, Anthropic may retain inputs and outputs for up to two years. This applies regardless of everything else and is not in our hands.

How we protect your data

  • Encryption in transit and at rest.
  • Each person sees only their own data; this is enforced in the database, not just in the interface.
  • Our administration area shows you only under an identifier, not by name. Anyone who wants to see real names needs two-factor authentication, and every such access is logged. We keep this log for 730 days.
  • We store your IP address only in encrypted form.
  • Your drawn signature is deleted after being inserted into the PDF and is not retained.

Your rights

You may ask us at any time for:

  • Access to the data we hold about you (Art. 15 GDPR)
  • Rectification if something is wrong (Art. 16)
  • Erasure of your data (Art. 17)
  • Restriction of processing (Art. 18)
  • Portability of your data in a transferable format (Art. 20)
  • Objection to processing based on legitimate interest (Art. 21)

Write to datenschutz@halloamt.de. We reply within one month.

You can delete things yourself, and there are two levels. You delete a single application under “My forms” → “Delete application”: this removes the conversation, your saved answers and the PDFs for that application — your stored details are kept and can be changed or removed individually under “My data”. Your account and all data are deleted under “Delete account”; this removes your details, your forms and any running subscription.

What account deletion does not remove — and why

One thing remains, and we tell you plainly instead of hiding it: If you have purchased from us, we keep a small record of that purchase — even after account deletion. It contains your email address in plain text, the product purchased, the price, the date, and the times of your consents, your confirmation before download, and any cancellation or withdrawal.

Why: In a dispute over a purchase, each side must be able to prove what was agreed and when. Without your address, the record would be worthless to both sides — it would only show that someone consented. That is why the address is stored there in plain text and not as an unreadable checksum: a checksum proves nothing to anyone who doesn't already know it.

Legal basis: Art. 17 Abs. 3 lit. b und lit. e DSGVO — the right to erasure does not apply where the data is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

How long: up to four years (three years from the end of the year in which the claim arose, §§ 195, 199 BGB). For information that is also invoicing data, longer tax retention periods may apply. After that, the record is deleted.

Who can see it: no one, through the application. This data is stored in a way that makes it technically inaccessible from either the user area or the admin area — it is only retrieved when a matter actually concerns such a record.

If you have never purchased anything, this record is never created in the first place.

You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (the Hamburg Commissioner for Data Protection and Freedom of Information).

Ludwig-Erhard-Str. 22, 20459 Hamburg
Tel. (040) 428 54 – 4040 · Fax (040) 428 54 – 4000
mailbox@datenschutz.hamburg.de · datenschutz.hamburg.de

Do you have to provide this data?

No. You decide what you enter. Without the information required by the respective form, however, we cannot fill it in — that is the purpose of the service.

Artificial intelligence — what it does and what it does not

You are talking to an AI, not to a person. The chat is run by an AI language model (Claude by Anthropic). It asks the questions, understands your answers and enters them into the fields of the official form. We tell you this because the EU AI Regulation (Regulation (EU) 2024/1689, Art. 50) requires it — and because you should know before you provide personal details.

The AI decides nothing. It fills in. Your application is decided solely by the authority. There is no automated decision-making within the meaning of Art. 22 GDPR: no assessment of whether you are entitled to something, no evaluation of your person, no rejection and no approval.

Please check the result. An AI can misunderstand something or enter it in the wrong field. That is why we always show you a preview of the completed form before you download it. You are the one submitting the application to the authority — and you should have read what it says beforehand.

What we do not do: We do not mark the completed forms as "AI-generated". They contain your own details, merely transferred into the right fields — no content invented by an AI. Such a note could also give the authority the false impression that someone else intervened in your application.

Which data is sent to Anthropic and what happens to it there is described above under "Who sees your data besides us" and "Transfer to the USA".

Cookies and analytics

We use no cookies for advertising or analytics purposes and do not measure your behaviour. Only what is necessary for operation is stored on your device: your sign-in and the current application. Under § 25(2) TDDDG we do not need consent for this.

How we count our reach. We want to know how many people reach our pages and which pages are read. For this we use no third-party analytics tool — no Google Analytics, no Plausible, no tracking pixel. Our own server counts instead, as sparingly as possible:

  • We store daily counters only: "this page was opened this many times today", "this many visits came from a search engine today". There is no record of an individual visit.
  • Of the site you came from we store only the website name (for example google.com) — never your search query and never the exact address.
  • From the address of the page you opened we remove everything after the question mark, and identifiers (such as a document number) are grouped together.
  • To avoid counting a visitor twice on the same day we form a non-reversible checksum from your IP address, your browser identifier, a secret addition and today's date. Because the date is part of it, tomorrow produces an entirely different checksum: we cannot recognise you across several days — not even retrospectively. These checksums are deleted after two days, the daily counters after 400 days.
  • Nothing is stored on or read from your device for this counting — no cookie, no identifier. That is why we need neither your consent nor a cookie banner for it.

The legal basis is our legitimate interest in knowing the reach of our own service (Art. 6(1)(f) GDPR).

Changes

We adapt this policy when the service changes. The version with the date given above applies.