Legal
Privacy Policy
Last updated: July 25, 2026
1. Responsible Party
Company: Web Brauerei
Owner: Philipp Bartels
App / Website: Mandokit
Address: Wilhelmstraße 57, 71083 Herrenberg, Deutschland
Contact: [email protected]
2. Two Roles: Controller and Processor
Mandokit processes personal data in two clearly separated roles. This distinction runs through the entire policy:
– As a controller within the meaning of Art. 4 (7) GDPR we process your own data as a user: account and contract data, billing, support, website usage, newsletter, feedback board, and the use of our free online tools.
– As a processor within the meaning of Art. 28 GDPR we process the content you create, upload, or research in Mandokit: your lead and contact data, your templates, and the correspondence sent and received through your connected mailboxes.
In the second role you are the controller and we process the data exclusively on your instructions. The details are governed by a data processing agreement pursuant to Art. 28 GDPR, which we provide on request at [email protected]. You decide which people you research and contact, and you are responsible for the lawfulness of that outreach.
3. Data Collected
When you use our website and services, we process the following categories of data:
– Account data: name and email address on registration, password (stored exclusively as a bcrypt hash), role, and onboarding status. Before first use we additionally store your confirmation that you use Mandokit for business purposes – with a timestamp and the version of our Terms applicable at that time. We need this record to perform the contract and to demonstrate that no consumer contract exists (Art. 6(1)(b) and (f) GDPR).
– Contract and billing data: booked plan, term, credit and additional quotas, redeemed coupons, Stripe customer ID, and invoice data. The payment data itself is processed by Stripe (see section 7).
– Usage data: pages visited, time on page, click behaviour, device and browser type – only if you have consented to analytics.
– Technical data: IP address, date and time of access, referrer URL, log files, and cookies. We also process IP addresses briefly in memory to limit the number of requests to our servers (abuse protection).
– Credentials of connected mailboxes: SMTP and IMAP servers, ports, usernames and passwords, and OAuth tokens. Passwords and tokens are stored encrypted only (AES-256-GCM).
– Content and communication data: your lead and contact data, templates, notes and tasks, as well as emails sent through Mandokit and received in connected mailboxes, including sender, recipient, subject, text, HTML content, and raw message.
– Voluntary information: entries in contact and tool forms, support requests, feedback, and ratings.
We do not collect special categories of personal data under Art. 9 GDPR. Mandokit is not intended to process such data – please do not enter it into the application.
4. Legal Bases for Processing
We process personal data on the following legal bases pursuant to Art. 6 (1) GDPR:
– Performance of a contract (Art. 6 (1)(b) GDPR): provision of our services, account management, payment processing, and support requests.
– Consent (Art. 6 (1)(a) GDPR): e.g. analytics cookies and newsletter. You may withdraw your consent at any time with effect for the future.
– Legitimate interests (Art. 6 (1)(f) GDPR): improving our services, fraud and abuse prevention, IT security, and analysis of website usage. Our legitimate interest lies in optimising and securely operating our platform.
– Legal obligation (Art. 6 (1)(c) GDPR): compliance with tax and commercial law retention obligations.
5. Account, Registration, and Sign-In
An account is required to use Mandokit. We store your name, email address, and password; the password is stored exclusively as a bcrypt hash and is not readable by us. Sign-in uses a session cookie. For password resets and email confirmation we generate time-limited tokens that are deleted once they expire. Legal basis: Art. 6 (1)(b) GDPR.
6. Cookies & Tracking
We use cookies and similar technologies. Technically necessary cookies are set without consent (Art. 6 (1)(f) GDPR). All other cookies (analytics, marketing) are only set with your explicit consent (Art. 6 (1)(a) GDPR). Your decision is stored in a cookie; you can change it at any time via your browser settings.
Necessary Cookies
These cookies are required for the basic functioning of the website (session management, authentication, language setting, CSRF protection, storing your cookie decision) and cannot be disabled without impairing core functionality. Legal basis: Art. 6 (1)(f) GDPR.
Google Analytics
We use Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyse website usage. The analytics script is only loaded after you have agreed in the cookie banner – without consent no data is transmitted to Google. We have enabled IP anonymisation so that your IP address is truncated within the EU/EEA. The data collected is generally transferred to a Google server in the USA and stored there (on the basis of standard contractual clauses). Legal basis: Art. 6 (1)(a) GDPR. You can prevent collection by installing the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout) or by withdrawing your consent. Retention period of analytics data: 14 months.
7. Payment Processing
For payment processing we use Stripe (for customers in the EEA: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; parent company: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA). During a purchase your payment data is transmitted directly to Stripe and processed there. Mandokit does not store full credit card numbers, only a Stripe customer ID, the booked plan, and the payment status. Payment and subscription events are received via a secured interface from Stripe and stored to avoid duplicate bookings. Stripe also processes your data as an independent controller in accordance with its privacy policy (https://stripe.com/privacy). Legal basis: Art. 6 (1)(b) GDPR.
8. Mailboxes, Domains, and Sending
Mandokit sends and receives emails through mailboxes that you connect yourself or that we set up for you. In doing so we process on your behalf:
– Credentials: SMTP and IMAP hosts, ports, usernames, and passwords of the connected mailboxes. Passwords are stored encrypted (AES-256-GCM) and decrypted only at the moment a connection is established.
– Message content: sent and received emails are stored in your account with sender, recipient, subject, date, text and HTML content, and the raw message, so that you can see and reply to the conversation in Mandokit.
– Deliverability: we regularly check the state of your mailboxes (health check) and, on request, run an automated warm-up in which mailboxes exchange messages with each other. Only your own or our own mailboxes take part – no third-party data.
– Domains: at your request we register sending domains through the registrar INWX. You are entered as the domain owner (registrant); Web Brauerei is listed only as the administrative, technical and billing contact. For this we transmit the owner details collected during the order process — company, address and phone number, plus your account email address — to the registrar. This data is passed on to the relevant registry and is, depending on the domain ending, wholly or partly retrievable via WHOIS; for .de domains DENIC does not publish owner details. Legal basis: Art. 6 (1)(b) GDPR.
– Unsubscribes: for the unsubscribe link in your emails we generate an encrypted token. If a recipient unsubscribes, we store the address in an account-specific suppression list so it is not contacted again.
We do not perform open or click tracking in your outreach emails: we use neither tracking pixels nor rewritten tracking links. Legal basis in relation to you: Art. 6 (1)(b) GDPR.
9. Research and Enrichment of Business Contacts
With Mandokit you research business contact data. In doing so we process, on your behalf, data from publicly accessible sources as well as data you upload yourself.
– Sources: Google Maps and Google search results, public LinkedIn company and person profiles, the German commercial register, imprint, contact, and home pages of websites, and lists you import (e.g. CSV or Excel).
– Data processed: company name, address, phone number, email address, website, social media profiles, commercial register data, VAT identification number, and the names and roles of contact persons.
– Technical implementation: to retrieve public sources we use the Apify platform and our own website retrieval. To check the deliverability of email addresses we use our own methods (MX and SMTP queries) and the Bouncer service.
– Storage location: results are assigned to your account and stored in our database in Germany. You can delete and export individual records or entire lists at any time.
In this respect we act exclusively on your instructions (see section 2). The legal basis in relation to you is the contract (Art. 6 (1)(b) GDPR); in relation to the data subjects you, as the controller, will usually rely on Art. 6 (1)(f) GDPR.
10. Use of Artificial Intelligence
Mandokit offers features based on large language models: enrichment and clean-up of lead data, checking whether a record matches your target audience, creating and optimising email templates, personalising individual messages, and classifying incoming replies.
– Provider: Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA (Claude API). Processing takes place on our instructions as a processor; the transfer to the USA is based on standard contractual clauses.
– Data transmitted: depending on the feature, company and contact data of the respective record, excerpts of publicly retrieved website and register content, and your template and message texts.
– Purpose limitation: the data is used exclusively to answer the respective request. According to the provider's contractual commitments, the content is not used to train its models.
AI features only run when you explicitly start the corresponding action. You can use the platform entirely without them.
11. Information for Recipients of Our Customers' Communication
This section is addressed to people whose data is processed by our customers using Mandokit – for example because they received a business email through our platform (information obligation under Art. 14 GDPR).
– The controller is the customer who contacted you. That party is named in the signature or imprint of the email. Mandokit acts solely as a processor in this respect.
– Origin of the data: publicly accessible sources such as company websites and their imprint, Google Maps, Google search results, public LinkedIn profiles, and the commercial register – or the controller's own existing records.
– Categories: business contact data such as name, role, business email address, phone number, address, website, and publicly available company information. Private data is not collected deliberately.
– Your rights under Art. 15 to 22 GDPR are directed primarily at the controller. You can unsubscribe at any time via the unsubscribe link in the email; your address is then blocked from further outreach.
You may also contact us directly at [email protected]. We will forward your request to the controller without delay and support its implementation, for example deletion or suppression.
12. Free Online Tools
On our website we provide free tools, including email verification, email lookup, spam testing, blacklist, DNS, SSL, and website security checks, and VAT identification number validation. We process your input exclusively to carry out the respective check.
– No permanent storage: inputs and results are not written to our database. They are only cached in memory for a short time (usually a few minutes) so that repeated requests do not have to be executed again.
– Your IP address is processed briefly in memory to limit the number of requests. Legal basis: Art. 6 (1)(f) GDPR (protection against abuse).
– External queries: depending on the tool we query Google's public DNS service, public blacklist directories (DNSBL), the Google Safe Browsing API, the URLhaus database by abuse.ch, the European Commission's VIES service, and – for email verification – the mail servers of the respective recipient domain and the Bouncer service.
– Spam test: for this test you send an email to a test mailbox we provide. We read the message, evaluate its headers and the folder it was delivered to, and then move it to the trash folder of the test mailbox.
Please only enter data in the tools that you are entitled to check.
13. Contact Form, Newsletter, and Feedback Board
– Contact form: we store name, email address, subject, and message in order to handle your request (Art. 6 (1)(b) or (f) GDPR).
– Newsletter: if you subscribe, we store your email address on the basis of your consent (Art. 6 (1)(a) GDPR). You can unsubscribe at any time via the unsubscribe link or by emailing us.
– Feedback board: posts, comments, ratings, and votes are stored together with the name you provide and – if you are signed in – the link to your account. Posts and comments are visible to other users; please do not enter confidential data there.
– Appointment booking: on our website we link to Calendly (Calendly LLC, USA) for scheduling calls. Data is only transmitted once you open the link; Calendly's privacy policy then applies.
14. Data Sharing & Processors
We only share personal data where this is necessary to provide our services, where you have consented, or where we are legally obliged to do so. Agreements pursuant to Art. 28 GDPR are in place with all processors. We use:
Hosting
Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) – hosting of the application and databases in data centres in Germany.
CDN & Security
Cloudflare, Inc. (101 Townsend St, San Francisco, CA, USA) – content delivery network, TLS termination, and protection against denial-of-service attacks. Data transfer to the USA on the basis of standard contractual clauses.
Media Storage
ImageKit (ImageKit.io, India) – storage, optimisation, and delivery of the images on our website.
Email Delivery
Google Workspace / Gmail (Google Ireland Limited) – email communication, system notifications, and support.
Payments
Stripe (Stripe Payments Europe, Limited, Ireland; Stripe, Inc., USA) – payment processing, see section 7.
AI Processing
Anthropic PBC (548 Market St, San Francisco, CA, USA) – processing of texts and records for AI-supported features (drafting, enrichment, qualification), see section 10. Processing takes place on our instructions; according to the provider's contractual commitments the content is not used to train its models. Data transfer to the USA on the basis of standard contractual clauses.
Web Research & Email Verification
Apify Technologies s.r.o. (Prague, Czech Republic) – execution of the research features on publicly accessible sources. Bouncer (Usebouncer sp. z o.o., Poland) – verification of email addresses. Only the data required for the respective check is transmitted.
Domain Registration
INWX GmbH & Co. KG (Berlin, Germany) – registration and management of domains ordered through the app at your request. Only the domain and contact data required for registration is transmitted.
15. Fonts, Images, and Profile Pictures
The fonts we use are bundled at build time and served from our own servers – opening our pages therefore does not create a connection to Google servers. We do not use a tag manager. Images on our website are delivered via ImageKit. In the inbox view of the application we display profile pictures via the Gravatar service (Automattic Inc., USA); for this, a hash of the respective email address is transmitted to Gravatar. Legal basis: Art. 6 (1)(f) GDPR.
16. Connecting Your Google Workspace & Use of Google API Services
When you connect your own Google Workspace in Mandokit, we access certain data of your Google account through the Google APIs with your explicit consent as a workspace administrator. This access serves solely to set up domains and mailboxes and to send and receive emails. We request the following permissions (scopes):
– Account address (openid, userinfo.email): to identify the consenting administrator and to uniquely assign the connection.
– Manage domains (admin.directory.domain): to add, list, and check the verification status of domains in your workspace.
– Domain verification (siteverification): to prove domain ownership via a DNS TXT record.
– Manage users and mailboxes (admin.directory.user): to create, list, and delete mailboxes in your workspace.
Mailbox Access via the Gmail API
Access to mailbox content is not part of the consent described above. It requires that you additionally set up domain-wide delegation for our service account in your Google Workspace admin console. Only then can Mandokit use the Gmail API to send (gmail.send), read (gmail.readonly), and mark as read (gmail.modify) messages on behalf of the mailboxes you provide. Without this authorisation granted by you, there is no access to mailbox content.
Use
Data retrieved via the Google APIs is used exclusively to provide and operate the features you have activated. We do not use this data for advertising purposes, do not sell it, and do not pass it on to third parties except where necessary to provide the services or required by law. Human review only takes place where necessary for security, to comply with applicable law, or with your explicit consent. In particular, data from Google Workspace APIs is not used to train generalised AI or machine learning models.
Storage & Revocation
For the persistent connection we store an encrypted refresh token together with the associated administrator address and workspace ID. You can disconnect at any time in Mandokit; the token is then deleted and access revoked. You can also revoke access at any time at https://myaccount.google.com/permissions.
Limited Use
Mandokit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
17. Retention Periods
We store personal data only for as long as it is necessary for the respective purpose:
– Account data: for the duration of the business relationship and up to 30 days after account deletion (data export window).
– Lead, template, and message data: for as long as you keep it in your account. You can delete it yourself at any time; it is removed no later than 30 days after account deletion.
– Credentials of connected mailboxes and Google Workspace tokens: until you remove the access or connection, or delete your account.
– Payment and invoice data: in accordance with tax and commercial law retention obligations for up to 10 years (Sec. 147 AO, Sec. 257 HGB).
– Usage data / analytics: a maximum of 14 months (Google Analytics), then automatic deletion.
– Server log files: a maximum of 30 days, then automatic deletion.
– Input into free tools: held only transiently in memory and deleted after a few minutes at most.
– Suppression list of unsubscribed addresses: retained for as long as necessary to prevent renewed outreach (Art. 21 (3) GDPR).
– Support requests: up to 3 years after the request is closed (limitation period).
– Consent records (cookie consent): 3 years to document the consent.
Once the retention period expires, the data is deleted or anonymised, unless a statutory retention obligation applies.
18. International Data Transfers
Our application and databases are operated in Germany. Individual processors are based outside the EU/EEA, in particular Stripe, Cloudflare, Google, Anthropic, and Automattic (USA) as well as ImageKit (India). Data transfers take place on the basis of standard contractual clauses (Art. 46 (2)(c) GDPR) and, where applicable, on the basis of the EU-US Data Privacy Framework (adequacy decision of the EU Commission under Art. 45 GDPR). Apify (Czech Republic) and Bouncer (Poland) process data within the EU. We ensure that an adequate level of protection is guaranteed.
19. Data Security
We use appropriate technical and organisational measures to protect your personal data: encryption of data in transit (TLS), storage of account passwords exclusively as bcrypt hashes, encryption of stored mailbox passwords and OAuth tokens with AES-256-GCM, access and permission controls, rate limiting on our interfaces, regular security updates, and backups. However, no system is completely secure, and transmitting data over the internet is at your own risk.
20. Automated Decision-Making
Mandokit uses automated methods to pre-sort researched records: target audience qualification uses a language model to assess whether a record matches the audience described by our customer, and incoming replies are automatically classified by relevance. These assessments concern business contacts and serve solely as a pre-selection. They have no legal effect and do not similarly significantly affect the data subjects within the meaning of Art. 22 GDPR; the decision on whom to contact is always made by the responsible customer. Should you nevertheless consider that an automated decision significantly affects you, you may request human review at [email protected], express your point of view, and contest the decision.
21. Your Rights
If you are located in the EU/EEA, you have the following rights under the GDPR:
– Right of access (Art. 15 GDPR) – request a copy of your stored data
– Right to rectification (Art. 16 GDPR) – have incorrect data corrected
– Right to erasure (Art. 17 GDPR) – request deletion of your data
– Right to restriction of processing (Art. 18 GDPR)
– Right to data portability (Art. 20 GDPR) – receive your data in a common format
– Right to object (Art. 21 GDPR) – in particular against processing based on legitimate interests
– Right to withdraw consent (Art. 7 (3) GDPR) – at any time with effect for the future
– Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise any of these rights, please contact us at [email protected]. Our competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany. If your rights concern data we process on behalf of one of our customers, we will forward your request to the controller there (see section 11).
22. Changes to This Policy
We may update this privacy policy from time to time. In the event of material changes we will inform you by email or through a notice in the application. The latest version is published here with an updated 'Last updated' date.
23. Contact
If you have questions about data protection or wish to exercise your rights, please contact us at:
[email protected] · Web Brauerei, Wilhelmstraße 57, 71083 Herrenberg, Deutschland