Privacy
Language notice: The German version of this privacy notice is the original version. This English version is provided to inform English-speaking users and is intended to accurately reflect the German version. In the event of any discrepancy, the German version shall prevail.
This Privacy Notice explains how personal data is processed in connection with Tasia. Tasia is a web-based B2B SaaS offering for the structured collection of customer requests and the AI-assisted preparation, review, approval, transmission and integration of quotation drafts.
1. Controller and Contact
The controller within the meaning of the General Data Protection Regulation is:
Sebastian Spohr Media, Haydnstraße 17a, 93053 Regensburg, Germany
Hereinafter “Tasia”, “we” or “us”.
Privacy inquiries and data subject rights: privacy@tasia.io
General inquiries: contact@tasia.io
Support: support@tasia.io
2. Scope and Data Protection Roles
This Privacy Notice applies in particular to:
- visitors to our website;
- customers, account holders, administrators and invited users;
- prospects and end customers who use a request form provided through Tasia or receive a quotation sent through Tasia;
- support contacts and reporting persons;
- newsletter subscribers;
- persons liable for payment and invoice recipients.
2.1 Tasia as Controller
We process data under our own responsibility where we determine the purposes and essential means ourselves. This applies in particular to:
- operation of the website and our own tenant-independent security and abuse-prevention logs;
- registration, contractual account, authentication and billing;
- our own communications, support, newsletter and accounting;
- our own data-minimizing audience measurement;
- compliance with legal obligations and the establishment, exercise or defense of legal claims.
2.2 Tasia as Processor
When a customer uses Tasia for its request and quotation processes, the customer generally determines the purpose, legal basis, content, recipients and deletion of the personal data processed in that context. Tasia regularly processes this data on instructions as a processor.
This applies in particular to:
- information in request forms;
- data of prospects and end customers;
- property, project, service and requirements data;
- pricing, calculation and quotation data;
- uploaded quotations, price lists, files, emails and attachments;
- prompts, AI outputs and quotation drafts;
- approval, delivery, export and integration data;
- customer-specific rules and corrections.
The Data Processing Agreement available at www.tasia.io/dpa applies to this processing.
Article 28 GDPR governs contractual processing on behalf of a controller but does not constitute an independent legal basis in relation to data subjects. The customer itself must ensure that a legal basis under Article 6 or Article 9 GDPR exists and that the required information is provided.
2.3 Customer Request Forms and Quotations
A customer can make a request form available:
- embedded in its own website; or
- through an address provided by Tasia.
The respective customer remains responsible for the content, purpose, legal basis and recipients of its form. Its privacy information must be appropriately accessible at the form. For questions concerning the use of information entered, the specific request or a quotation received, the respective customer is generally the appropriate contact.
Tasia processes form entries and the connection and status data required for the technical execution of the specific request or quotation process on behalf of the customer. Only where Tasia determines its own purposes independently of the specific customer process, for example for cross-tenant IT security, attack detection, abuse prevention, legal obligations or the establishment, exercise or defense of legal claims, does separate processing take place under Tasia’s own responsibility. The content of a request is not routinely reused for other purposes in this context.
By default, a form submitted through Tasia constitutes a non-binding request. Tasia does not make any decision based solely on automated processing regarding acceptance, rejection, price or conclusion of a contract and does not become a party to the contract for the services offered by the customer.
3. Website, App, Forms, Quotation Pages and Technical Logs
When our website, the app, a request form, a quotation or approval page, or an API endpoint is accessed, technically necessary data is processed. This may include:
- IP address;
- date and time;
- URL or API resource accessed;
- HTTP method, status code and amount of data transferred;
- referrer, where transmitted;
- browser, operating system, user agent and device information;
- technical error, performance, connection and security information;
- form identifier, tenant assignment and technical session information;
- delivery, access or error status, where a message or quotation is made available through Tasia.
Purposes: Delivery and operation, API provision, secure assignment to the correct customer, security, attack detection, error analysis, stability, capacity planning and abuse prevention.
Roles and legal bases:
- If you use the Tasia website or your own Tasia account, we process the data required for this purpose under Article 6(1)(b) GDPR, insofar as the processing is necessary for a contract with you or for pre-contractual measures taken at your request.
- For business users acting on behalf of a customer, account and access management is generally based on Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and orderly performance of the B2B contract.
- We process our own tenant-independent security, error and abuse-prevention logs under Article 6(1)(f) GDPR. Our legitimate interest lies in operating the Service securely, stably and protected against unauthorized use.
- Where legal obligations apply, processing is based on Article 6(1)(c) GDPR.
- If you access a form, quotation page or another function of a Tasia customer, Tasia generally processes the data required for that customer’s request or quotation process on behalf of that customer. The customer determines the legal basis in relation to you; Article 6(1)(b) GDPR is not invoked across the board as Tasia’s own legal basis for this purpose.
Where technical information is required both for the customer process and for an independent security purpose, the purpose, access and storage period are each limited to what is necessary.
4. Account, Contract and Use
For registration, login, account management and performance of the contract, we process in particular:
- name, business email address and contact details;
- company, organization, role or function;
- login, authentication and security data;
- passwords exclusively in hashed form;
- account status, plan, roles, permissions and settings;
- acceptance and contractual records, including accepted document versions, times of acceptance and the acting user;
- registration, login, change and security timestamps;
- technical usage, session, API, quota and security data.
Purposes: Setting up and managing the account, authentication, provision of functions, team and role management, performance and evidence of the contract, support, security, billing, and fraud and abuse prevention.
Legal bases: Article 6(1)(b) GDPR where the data subject is itself a contracting party or takes pre-contractual action; Article 6(1)(f) GDPR for managing business contacts, authorized users and permissions and for security, traceability and abuse prevention; Article 6(1)(c) GDPR where legal obligations apply.
Our legitimate interest lies in the orderly and secure performance of the B2B contract with the respective customer.
If a customer invites additional users, we generally receive their business email address and, where applicable, name, organization and intended role from the inviting customer or its administrator. This is also the source of the data within the meaning of Article 14 GDPR. The invitation refers to this Privacy Notice.
Administrators may view and manage account, role and usage information for their organization to the extent provided. Required information in the registration, contracting or payment process is necessary for the respective service; without it, the account or contract may not be set up or performed. Information marked as voluntary is optional.
5. Request Forms, Quotation Data, Documents and Customer Data
When request and quotation processes are created, configured, used and handled, we may process the following data in particular on behalf of the customer:
5.1 Forms and Requests
- name, business or private contact details;
- company, organization, function and contact person;
- address, property or service location;
- requested services, quantities, areas, intervals, dates and priorities;
- project, property, requirement and specification details;
- budget, price or payment parameters, where requested;
- free-text information, responses, selection values and form data;
- uploaded images, files, plans or other attachments;
- records of consent, confirmation and information, where the form uses such functions;
- technical transmission, session and abuse-prevention data.
We generally receive this data directly from the person completing the form or from a system connected by the customer.
5.2 Price, Service and Quotation Data
- services, line items, quantities, units and dependencies;
- price lists, hourly rates, surcharges, discounts, minimum quantities and calculation rules;
- quotation numbers, text, terms, deadlines and statuses;
- recipient, delivery, access, approval and change information;
- existing quotations, order documents, files, emails and other imported content;
- manual changes, corrections and approvals;
- stored quotation drafts and AI outputs;
- export and integration data.
The customer or its users determine which data is imported, stored, evaluated, approved, sent or transferred to a third-party system. We do not generally review Customer Data in advance for personal data, confidentiality or legal permissibility.
5.3 Purposes and Roles
Purposes on behalf of the customer: Provision of forms, structured collection of requirements, analysis and assignment of information and documents, configuration of price and service rules, preparation and editing of quotation drafts, approval, delivery, export, integration, support, backup and deletion.
Where we process this data on instructions, we act as a processor under the DPA. The customer is responsible for the legal basis, data minimization, accuracy, deletion periods and information provided to data subjects.
Where processing is necessary for our own security, handling of abuse, legal obligations or the establishment, exercise or defense of legal claims, we may act as an independent controller to that extent. The legal bases are then Article 6(1)(f) or (c) GDPR.
Tasia is not designed for the regular processing of special categories of personal data under Article 9 GDPR, data relating to criminal convictions and offenses under Article 10 GDPR, or comparably highly sensitive data. Such data may be processed only if Tasia has expressly approved the specific use case in text form, the processing is lawful and necessary, and additional appropriate safeguards have been agreed.
6. AI Functions and Customer-Specific Improvement
6.1 Data Processed and Purposes
When an AI function is used, the following may be processed in particular, depending on the selected function:
- prompts, instructions and free text;
- form entries and requirements;
- existing quotations, price lists, service data, files and email content;
- price, quantity, service and dependency rules;
- quotation drafts, line items and wording;
- manual changes, approvals and corrections;
- technical metadata such as timestamps, model identifiers, token quantities, status information and error information.
Purposes: Extraction and structuring of information, identification of missing information, suggestion of appropriate follow-up questions, assignment to services and rules, preparation of line items and text, creation of quotation drafts, and customer-specific improvement of future results.
6.2 AI Inference via TensorX
Customer Data is currently processed for AI functions through TensorX Limited (formerly Tensorix). TensorX is used for Tasia Customer Data exclusively for AI inference initiated by the user or request process.
Tasia uses a contractually agreed EU/EEA configuration for this purpose. Under this configuration:
- request and output content is processed by TensorX only temporarily for inference;
- this content is not stored or logged there on a permanent basis;
- it is not disclosed to model developers or other model providers;
- it is not used to train, fine-tune or generally improve AI models.
Technical usage, security and billing metadata may be stored to the extent necessary. This may include timestamps, model identifiers, token quantities, status, error and cost information. As of the date of this Privacy Notice, TensorX documents a retention period of up to twelve months for usage metadata, API logs and security logs. Request and output content is not included. Tasia generally retains its own AI operational logs that are not relevant to billing only for as long as necessary for operation, security and error analysis.
Important: The absence of permanent storage of request and output content at TensorX does not mean that form entries, documents or quotation drafts incorporated into Tasia are not stored in the customer account. Storage in Tasia takes place in accordance with the selected function, the customer settings and the DPA.
6.3 Customer-Specific Optimization
Tasia may use approved quotations, price and service rules, and manual corrections to better adapt future results to the specifications and working methods of the same customer, insofar as the corresponding function is enabled or used in the customer account. This processing is carried out on behalf of the customer and within its tenant environment.
We do not use personal Customer Data, form entries, prompts or quotation content for cross-customer training, fine-tuning or general improvement of our own or third-party foundation AI models.
Non-personal, anonymized or sufficiently aggregated information may be used for error analysis, security, capacity planning, statistical evaluation and product improvement where re-identification of individual persons or customers is excluded.
6.4 Transparency, Labeling and Automated Decisions
Tasia implements the applicable transparency and labeling obligations under the AI Act within its area of legal responsibility. Where a person interacts directly with an AI system and a notice is legally required, it is provided in an appropriate form. The respective customer is responsible for additional notices or labels resulting from its specific configuration, publication or use of AI outputs.
AI outputs are drafts and recommendations. Tasia does not make any decision based solely on automated processing within the meaning of Article 22 GDPR that produces legal effects concerning a person or similarly significantly affects that person. A quotation is used for business purposes only after review and approval by the customer.
The customer is responsible for the legal basis for personal data processed in AI functions. Access credentials, private keys, complete payment data and comparably critical secrets must not be entered. Special categories of personal data under Article 9 GDPR, data under Article 10 GDPR and comparably highly sensitive content may be processed only if Tasia has expressly approved the specific use case in text form and the required additional safeguards have been agreed.
7. Delivery, Approvals and Integrations
Where the customer sends or makes available quotations, notifications or other messages through Tasia, we may process in particular:
- names and contact details of recipients;
- subject line, message text and quotation content;
- time of sending, delivery status and technical error messages;
- access, approval and status information, where the respective function provides for this;
- assignment to customer, request, quotation and user.
Transactional messages are sent through Scaleway Transactional Email.
If the customer connects Tasia to a CRM, ERP, accounting, industry-specific or other third-party system, we process the data and access information authorized by the customer to the extent necessary to carry out the requested transfer.
The customer decides on the selection, legal basis and configuration of the third-party system. A recipient or third-party provider selected by the customer itself may be an independent controller or a processor of the customer. Its further processing is governed by the agreements between the customer and that third-party provider.
Data protection role: Tasia generally acts as processor when Customer Data is sent, approved and transferred. We may act under our own responsibility for our own security, delivery and abuse-prevention logs.
8. Communications, Support and Reports
If you contact us by email, form or a support channel, we process in particular:
- names, contact details, company and function;
- content of the inquiry;
- transmitted files, screenshots or Customer Data;
- timestamps, communication history and technical metadata.
Purposes: Handling inquiries, support, initiation and performance of contracts, documentation, security, abuse prevention, and the establishment, exercise or defense of legal claims.
Legal bases: Article 6(1)(b) GDPR for contract-related inquiries; Article 6(1)(f) GDPR for other communications, support, documentation, security and the establishment, exercise or defense of legal claims; Article 6(1)(c) GDPR where legal obligations apply.
For reports concerning unlawful, contract-violating or security-relevant forms, quotations, content or accounts, we process information about the reporting person, contact details, affected URLs or accounts, descriptions, evidence, handling status, decisions and technical logs.
Information may be disclosed to affected customers, involved persons, service providers, legal advisers, authorities or courts where this is necessary and permitted for investigation, remediation, legal compliance or the establishment, exercise or defense of legal claims.
For automatically triggered account, invitation, security, request and function emails, we use Scaleway Transactional Email. For individual communications through our contact, support and privacy addresses, we use email infrastructure from IONOS.
9. Newsletter
For newsletter registration, consent management and distribution, we use CleverReach, a service provided by CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany.
The data processed includes in particular the email address, voluntarily provided name, time of registration and confirmation, record of consent, list or topic selection, registration, unsubscribe and suppression status, and technical delivery, error and security information. The IP address and technical metadata may be logged during registration and confirmation.
Registration uses a double opt-in process. No personal analysis of opens or clicks takes place in the configuration we use. Consent may be withdrawn at any time through the unsubscribe link or by contacting privacy@tasia.io.
Legal bases: Article 6(1)(a) GDPR for the newsletter; Article 6(1)(f) GDPR for evidence of consent, abuse prevention, deliverability and management of unsubscribes; Article 6(1)(c) GDPR where documentation obligations apply.
After unsubscribing, we delete the data insofar as it is no longer required. An email address may remain stored on a suppression list to ensure that the withdrawal is permanently respected. Records of consent may be retained until the expiry of applicable limitation and documentation periods.
10. Payments, Invoices and Accounting
For paid services, we process in particular:
- name, company, billing address and email address;
- plan, price, currency and tax information;
- invoice data, payment status and transaction identifiers;
- limited payment method details;
- information for fraud prevention and regulatory review.
We use Stripe for payment processing. Under the Stripe agreement, Stripe Payments Europe, Limited is generally the contracting party for accounts outside North and South America. Depending on the processing, Stripe may act as processor or independent controller, in particular for payment infrastructure, fraud prevention, risk assessment, anti-money laundering and other regulatory obligations. Complete card details are not stored in our own systems.
We use sevDesk for accounting, invoicing and tax documentation. Customer, invoice, payment, tax and accounting data may be processed in this context.
Legal bases: Article 6(1)(b) GDPR for the contract and payment; Article 6(1)(c) GDPR for tax, commercial and regulatory obligations; Article 6(1)(f) GDPR for payment security, fraud prevention, receivables management and the establishment, exercise or defense of legal claims.
11. Cookies and Plausible Analytics
11.1 Strictly Necessary Technologies
We do not use advertising cookies. Strictly necessary cookies or comparable technologies may be used for login, session management, authentication, form progress, CSRF protection, security, language settings and expressly requested functions.
The legal basis for accessing or storing information on the end device is Section 25(2) no. 2 TDDDG, insofar as this is strictly necessary to provide a service expressly requested by the user. Subsequent processing is based on Article 6(1)(b) or (f) GDPR.
11.2 Self-Hosted Plausible Analytics
For our own data-minimizing audience measurement, we use Plausible Analytics Community Edition in the standard self-hosted configuration on STRATO infrastructure. The analysis serves Tasia exclusively. We do not provide customers with personal visitor analytics for their forms or quotations through Plausible. No analytics data is transferred to Plausible Insights OÜ or the Plausible cloud service.
The standard configuration does not set cookies, use Local Storage, generate persistent identifiers or enable a visitor profile across devices or days. To determine daily unique visits, the IP address, user agent, website domain and a salt that changes daily are briefly processed into a daily value. The salt is changed and deleted after 24 hours. Raw IP addresses and complete user-agent data are not permanently stored in the Plausible database.
The following is processed or derived in particular:
- hostname and page path;
- HTTP referrer;
- browser, operating system and device type;
- country, region and city derived from the IP address;
- time, page views and aggregated visit statistics;
- expressly configured non-personal events or properties.
We do not supply Plausible with names, email addresses, account IDs, request content, quotation content or other directly identifying properties.
Purposes: Audience measurement, product improvement, error detection and capacity planning without advertising profiles.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in analyzing and improving Tasia with as little personal data as possible.
In the configuration described, Plausible does not store analytics information on the end device and does not access persistent identifiers stored there. Should we use a function in the future that requires consent under Section 25 TDDDG, it will be activated only after consent has been given.
Fonts are delivered locally through our infrastructure; no connection to Google Fonts is established when they are loaded.
12. Recipients, Service Providers and Third-Country Transfers
We disclose data only where this is necessary for the purposes described and legally permissible. The recipients regularly used include:
| Service provider | Purpose | Processing |
|---|---|---|
| Scaleway SAS | Hosting of the platform, Managed MySQL, storage, backups, network, and transactional emails and quotation notifications | European Union according to the region used |
| STRATO GmbH | Hosting of the self-operated Plausible Community Edition | Germany or EU |
| IONOS SE | Domain, DNS, email mailboxes and individual communications | Germany or EU, depending on the product |
| CleverReach GmbH & Co. KG | Newsletter, double opt-in and list management | Germany or EU; possible additional processing under the provider’s terms |
| Stripe Payments Europe, Limited and affiliated Stripe companies | Payment, fraud prevention and regulatory obligations | EU and, where applicable, third countries |
| sevDesk GmbH | Accounting and invoices | Germany or EU, depending on the provider service |
| TensorX Limited (formerly Tensorix) | AI inference for analysis of requests, price and service data, and preparation of quotation drafts | European Union or EEA according to the configuration used |
Other recipients may include authorities, courts, legal and tax advisers, banks, payment networks, auditors or debt collection service providers where this is legally required or permissible for enforcement or defense of legal rights.
The primary Tasia infrastructure is operated within the European Union. Third-country transfers may occur in connection with Stripe and individual support, security or subprocessor chains. Such transfers take place only subject to the requirements of Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision, the EU-U.S. Data Privacy Framework, EU Standard Contractual Clauses and required supplementary measures, or a statutory derogation.
Further information about the applicable safeguards may be requested at privacy@tasia.io, insofar as third-party rights and security interests do not prevent disclosure.
Where the customer transfers data to a third-party system or recipient selected by it, the customer is responsible for the selection, legal basis and further processing by that recipient.
13. Retention Periods and Security
We store personal data only for as long as necessary for the respective purpose or for as long as legal obligations and legitimate interests in the establishment, exercise or defense of legal claims exist.
| Data category | Standard period or criterion |
|---|---|
| Server and security logs | generally up to 30 days; longer in the event of security incidents, suspected abuse or legal necessity |
| Account and contract data | for the duration of the contract; thereafter deletion or restriction, unless obligations or interests in the establishment, exercise or defense of legal claims apply |
| Forms, requests, documents, price and service data, and quotation drafts | until deletion by the customer or, after termination of the contract, in accordance with the Terms of Use and DPA |
| Approval, delivery, export and integration data | according to customer settings and contract duration; longer where required for evidence, security or the establishment, exercise or defense of legal claims |
| AI request content not stored at TensorX | only for the ongoing inference; no permanent storage of prompt or output content at TensorX under the intended configuration |
| Technical AI metadata | at TensorX, under the rules documented as of the date of this Privacy Notice, for up to twelve months for usage, billing, analysis and security; request and output content is not included; Tasia’s own non-billing-related logs are generally retained only for the required period |
| AI outputs stored in Tasia | like other Customer Data and quotation drafts |
| Invoices and accounting records | generally 8 years; documents subject to a longer statutory period for that longer period |
| Commercial and business correspondence | generally up to 6 years, where legally required |
| Support and contact inquiries | generally up to 24 months after completion; longer in the case of an ongoing contract, obligations, evidence, security or the establishment, exercise or defense of legal claims |
| Newsletter data | until withdrawal or unsubscribe; suppression and evidence data until the purpose no longer applies |
| Plausible data | no permanent storage of raw IP addresses or complete user agents; event and statistical data generally for no more than 24 months, followed by deletion or further aggregation |
Deleted Customer Data may remain for a limited period in backups or technical remnants until it is overwritten in the ordinary course. It is generally not used productively there. The end of the regular backup cycle, no later than 90 days after deletion from active systems, is considered the time of complete deletion. Mandatory statutory retention obligations remain unaffected; affected data is restricted and deleted once the obligation ceases to apply.
We implement appropriate technical and organizational measures pursuant to Article 32 GDPR. These include in particular:
- TLS-encrypted transmission;
- multi-factor authentication for privileged administrative access or equivalent risk-appropriate safeguards;
- protection of data at rest and backups through technically available and risk-appropriate encryption;
- password hashing;
- logical tenant separation;
- private or restricted database connections;
- permission management and regular reviews;
- security logging;
- updates and vulnerability management;
- backups and recovery tests;
- procedures for handling security and data protection incidents.
Absolute protection against all risks cannot be guaranteed for internet-based services.
14. Rights of Data Subjects
Subject to the statutory requirements, data subjects have rights in particular to:
- access;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- objection;
- withdraw consent.
Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Requests may be directed to privacy@tasia.io. To protect the data, we may require reasonable verification of identity.
Where processing is based on Article 6(1)(f) GDPR, an objection may be made on grounds relating to the data subject’s particular situation. An objection to direct marketing may be made at any time without stating specific grounds.
Where data is processed by a Tasia customer in a request or quotation process, that customer is often the controller. In that case, insofar as permissible and possible, we forward the request to the customer or refer the data subject to it and support the customer in accordance with the DPA.
Data subjects may lodge a complaint with a data protection supervisory authority. The authority generally competent for Tasia is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
15. Supplementary Documents and Changes
The Terms of Use available at www.tasia.io/terms also apply to the use of Tasia.
The DPA available at www.tasia.io/dpa applies to processing on behalf of a controller; in the event of a conflict concerning such processing, it shall prevail.
We amend this Privacy Notice when data processing activities, functions, service providers or legal requirements change. The current version is made available on our website. Where possible, we additionally inform registered users by email or in the account of material changes that significantly affect them.