Privacy Policy

Last updated: August 2026

This privacy policy explains how personal data is processed when you use a1-office (available at https://app.n3urala1.com) and our website https://n3urala1.com.

Please note: This is a translation for your convenience. In case of any discrepancy, the German version of this privacy policy is legally binding.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Robert Heine — N3URAL.A1, Wekeln 24, 47877 Willich, Germany · Email: robert@n3urala1.com

No data protection officer has been appointed, as the conditions of Art. 37 GDPR / § 38 BDSG do not currently apply.

2. Two roles — an important note upfront

a1-office is a multi-tenant SaaS CRM for business customers. Under data protection law we act in two distinct roles:

a) Controller (for our own data): For the data we collect ourselves in order to provide and bill our service — such as account and contract data of our business customers, access logs and website data — we are the controller. This privacy policy primarily describes that processing.

b) Processor (for our customers' content data): The content our business customers (tenants) store in a1-office — in particular their leads, contacts, deals, invoices, projects and communications — is processed solely on behalf of and on the instructions of the respective customer. For that data the customer is the controller and we are the processor (Art. 28 GDPR). This is governed by a separate data processing agreement (DPA) which we conclude with every business customer. Data subjects should address access and erasure requests primarily to the respective customer as controller.

3. Purposes and legal bases of processing

  • Providing and operating a1-office, performance of contract — account, contract and usage data — Art. 6(1)(b) GDPR (contract)
  • Authentication / login — email, name, provider ID, password hash — Art. 6(1)(b) GDPR
  • Invoicing and retention for tax purposes — invoice and payment data — Art. 6(1)(c) GDPR (legal obligation)
  • Security, abuse and error prevention, logs — IP address, timestamps, action logs — Art. 6(1)(f) GDPR (legitimate interest)
  • Stable operation through service providers (hosting, mail, AI) — Art. 6(1)(b) and (f) GDPR
  • Strictly necessary cookies / session — session cookie — Art. 6(1)(f) GDPR; § 25(2) TDDDG (technically required)

4. What data we process

  • Account and profile data: name, email address, organisation/tenant affiliation, role, password hash or OAuth identifier.
  • CRM content data (on behalf of the customer): leads, contacts, deals, invoices, projects, time tracking, notes, communications.
  • Usage and log data: IP address, timestamps, features accessed, audit log entries.
  • Billing data: invoice and, where applicable, payment information.
  • Cookies / session: a strictly necessary session cookie to maintain your login.

5. Authentication via third parties (Google / Microsoft)

In addition to email and password, we offer sign-in via Google (Google Ireland Limited) and Microsoft (Microsoft Ireland Operations Ltd.). If you use this option, we receive from the respective provider the data required for authentication (in particular name, email address and a user identifier). The legal basis is Art. 6(1)(b) GDPR. The privacy terms of the respective provider apply in addition.

6. Recipients / processors (sub-processors)

To provide the service we use carefully selected service providers as processors (Art. 28 GDPR). Agreements are in place with all of them; where there is a third-country element, the EU Standard Contractual Clauses (SCC, 2021/914) apply.

  • Vercel Inc. — hosting of the public marketing websites (not the a1-office application and not customer data) — USA, delivered via EU edge — DPA + SCC + supplementary measures
  • Scaleway — database and application hosting (a1-office core data) — EU, Paris (fr-par) — processed within the EU; DPA; ISO 27001
  • Resend — transactional email delivery — EU, Ireland — processed within the EU; DPA
  • Requesty (EU router, router.eu.requesty.ai) — AI inference for the "Klaus" assistant — EU (model hosting via EU providers) — EU-only routing; no-training and zero data retention are configured on the service
  • Cloudflare — DNS resolution — global (anycast) — DPA + SCC

We provide our business customers with an up-to-date list of sub-processors as part of the data processing agreement and inform them of any changes.

7. Transfers to third countries

The core data of a1-office — database, application and encryption keys — is processed exclusively within the EU (Scaleway, Paris region). The AI path is likewise limited to processing within the EU. Where individual services with a third-country element are used (see section 6), this is based on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with supplementary technical and organisational measures.

8. AI-assisted processing (the "Klaus" assistant)

a1-office includes an AI-assisted assistant ("Klaus") which processes CRM data on request in order to generate answers and suggestions. AI inference runs exclusively through an EU router (Requesty, router.eu.requesty.ai) with model hosting inside the EU. The service is configured so that no content is retained (zero data retention) and no model training takes place on the data transmitted (no training). No automated decision producing legal effects within the meaning of Art. 22 GDPR takes place; the final decision always remains with a human. In line with the EU AI Act (Reg. 2024/1689), the AI feature is identified as an AI system (Art. 50 transparency).

9. Retention periods

  • Account and contract data: for the duration of the contractual relationship, then erased subject to statutory retention obligations.
  • Invoice and accounting data: 10 years pursuant to § 147 of the German Fiscal Code (AO) / GoBD.
  • Log data: generally short-term, then erased or anonymised.
  • Customers' CRM content data: on the instructions of the respective customer and in accordance with the DPA (erasure or return at the end of the contract).

10. Your rights as a data subject

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), and the right to withdraw consent with effect for the future (Art. 7(3)).

A message to robert@n3urala1.com is sufficient to exercise these rights. If your request concerns data we process on behalf of one of our business customers (CRM content), we will refer you to the customer acting as controller, or act only on their instructions.

11. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de

12. Data security

We implement technical and organisational measures (Art. 32 GDPR), in particular transport encryption (TLS), access control and tenant-separated data storage (multi-tenant isolation), to protect your data.

13. Changes to this privacy policy

We update this privacy policy when the legal situation or our processing changes. The version published here is the one that applies.


Last updated: August 2026 · The German version of this privacy policy is legally binding.