This privacy policy describes how Double Loop GmbH ("we", "us", "Double Loop") collects, processes, and protects personal data when you visit valuewe.com or use the ValueWE platform. It is drafted under the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing in the sense of Art. 4 (7) GDPR is:
Double Loop GmbH
Theaterstraße 13
52062 Aachen
Germany
Phone: +49 (0)241 97876-0
Email: [email protected]
2. Data Protection Officer
Double Loop GmbH has not appointed a statutory Data Protection Officer, as we do not meet the thresholds set out in § 38 BDSG. For any privacy-related question or to exercise your rights under the GDPR, please contact us at [email protected]. We will respond within one month, as required by Art. 12 (3) GDPR.
3. Categories of personal data we process
Depending on how you interact with us, we may process the following categories:
- Account data — name, email address, hashed password, organisation name, role (admin/user), preferred language.
- Authentication data — session identifiers, IP address at sign-in, device / browser fingerprint, encrypted two-factor authentication (2FA) secrets. 2FA is mandatory on every account.
- Billing data — billing address, VAT ID, invoice history. Card data is never stored on our infrastructure; it is tokenised and held by our payment processor (see § 7).
- Case workspace content — information you or your team enter or generate while using the wizard: customer names, opportunity descriptions, value drivers, numeric assumptions, attachments, AI prompts and outputs. This content is considered your Customer Data under our Terms of Service.
- Usage and telemetry data — messages per case, token counts, feature interactions, error logs, access logs. Used for service operation, security, and capacity planning.
- Website visitor data — when you visit
valuewe.com, your IP address, user agent, referrer, and requested URL are written to temporary server access logs for security and abuse prevention. - Correspondence — emails, sales conversations, and demo booking details you submit to us.
We do not knowingly collect special categories of personal data (Art. 9 GDPR), data from minors under 16, or data we do not need for the purposes listed below.
4. Purposes and legal bases for processing
Each processing activity has a defined legal basis under Art. 6 GDPR:
- Providing the ValueWE service (account creation, authentication, running the wizard, storing case workspaces, generating AI outputs, exports) — Art. 6 (1)(b) GDPR, performance of a contract.
- Billing and accounting (subscription management, invoicing, tax records) — Art. 6 (1)(b) and (c) GDPR. German commercial and tax law require us to keep invoice-related records for 10 years (§ 147 AO, § 257 HGB).
- Security, abuse prevention, fraud detection (rate limiting, access logging, alerting on suspicious activity) — Art. 6 (1)(f) GDPR, legitimate interest in keeping the service available and safe.
- Product improvement and debugging (aggregated usage analytics, error diagnostics) — Art. 6 (1)(f) GDPR, legitimate interest. We do not use your case workspace content for this purpose.
- Direct communication and demos (responding to your enquiries, scheduling and delivering demos) — Art. 6 (1)(b) GDPR (pre-contractual measures) or Art. 6 (1)(f) GDPR where you contact us on behalf of your organisation.
- Marketing emails — Art. 6 (1)(a) GDPR, consent. You can withdraw consent at any time via the unsubscribe link in every email, without affecting the lawfulness of prior processing.
- Compliance with legal obligations (e.g. responding to lawful requests from authorities) — Art. 6 (1)(c) GDPR.
5. AI processing and model training
ValueWE uses large language models to assist with research, drafting, quantification, and value communication. When you use an AI-assisted step, the relevant case context and your message are transmitted to the LLM provider listed in § 7 (Anthropic, OpenAI, or Google) for inference only.
We do not train AI models on your data. We contractually require the same of every upstream LLM provider we use: your case content, prompts, and model outputs are not used to train, fine-tune, or improve any model. API-tier contracts with these providers include no-training commitments, and we select only offerings that honour this.
ValueWE does not use automated decision-making within the meaning of Art. 22 GDPR to produce legal or similarly significant effects on you. AI-generated outputs are drafts that a human reviews and owns.
6. Retention periods
We only keep personal data for as long as it is needed for the purposes above, unless a longer retention period is legally required:
- Active account data and case workspaces — for the duration of your subscription.
- After account closure — case workspaces and account profile data are deleted within 30 days of closure. You can export your workspaces at any time before deletion.
- Invoices and accounting records — 10 years after the end of the calendar year in which the document was issued (§ 147 AO, § 257 HGB).
- Access logs — up to 90 days, then deleted or anonymised.
- Support correspondence — up to 3 years from last interaction.
- Backups — encrypted backups are retained on a rolling 30-day cycle and then overwritten.
7. Recipients and subprocessors
We share personal data only with carefully selected processors who act on our instructions under an Art. 28 GDPR data processing agreement. The table below lists the categories of subprocessors currently in use for ValueWE:
- Hosting & infrastructure — Hetzner Online GmbH, Gunzenhausen / Falkenstein, Germany. All customer data at rest is stored on servers located in Germany (EU).
- Database & backups — managed PostgreSQL and object storage hosted in the EU.
- Object storage for attachments and exports — Cloudflare R2, configured for EU jurisdiction (Cloudflare, Inc., US, with EU data processing).
- Payment processing — Stripe Payments Europe Ltd., Dublin, Ireland (with onward transfer to Stripe Inc., US, under the EU–US Data Privacy Framework and Standard Contractual Clauses).
- Transactional email delivery — Resend (Resend, Inc., US), under Standard Contractual Clauses.
- Large language model providers — Anthropic, PBC (US), OpenAI, LLC (US), and Google LLC (US). All API usage is contracted under no-training terms and Standard Contractual Clauses.
- CDN, DNS, and bot protection — Cloudflare, Inc. (US), under Standard Contractual Clauses.
An authoritative list of current subprocessors, including entity names and countries, is attached as an annex to our Data Processing Agreement. See the DPA page for how to request it.
8. International transfers
Personal data we store is held within the EU. Some subprocessors (notably LLM providers, payment processing, and transactional email) are located in the United States. For every transfer outside the EU/EEA we rely on one of the following Art. 46 GDPR safeguards:
- the EU–US Data Privacy Framework where the recipient is certified;
- Standard Contractual Clauses (SCCs) in their current EU version; and
- where necessary, supplementary technical measures (encryption in transit and at rest, pseudonymisation, strict purpose limitation).
9. Your rights as a data subject
Under the GDPR you have the following rights:
- Right of access (Art. 15) — confirmation of whether we process your data and a copy of it.
- Right to rectification (Art. 16) — correction of inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17) — deletion where legally permitted.
- Right to restriction of processing (Art. 18) — temporary freeze of processing in defined circumstances.
- Right to data portability (Art. 20) — export in a structured, commonly used, machine-readable format. Case workspaces are always exportable.
- Right to object (Art. 21) — including objection to processing based on legitimate interest.
- Right not to be subject to automated individual decision-making (Art. 22).
- Right to withdraw consent (Art. 7 (3)) at any time, without affecting the lawfulness of processing up to that point.
To exercise any of these rights, email [email protected]. We may ask for information to verify your identity before responding. We will respond within one month (Art. 12 (3) GDPR), extendable by two further months for complex requests.
10. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data infringes the GDPR (Art. 77 GDPR). The competent authority for Double Loop GmbH is:
Landesbeauftragte für Datenschutz und Informationsfreiheit
Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de
You may also contact the supervisory authority in the EU member state of your habitual residence or place of work.
11. Cookies and similar technologies
The ValueWE marketing site and application use only strictly necessary cookies required for session management, CSRF protection, and remembering your authentication state. These are based on Art. 6 (1)(f) GDPR and § 25 (2) No. 2 TTDSG and do not require prior consent. We do not use third-party advertising cookies or cross-site trackers.
If we add optional analytics in the future, we will update this policy and request consent before setting any non-essential cookie.
12. Security measures
We implement appropriate technical and organisational measures under Art. 32 GDPR to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- encryption in transit (TLS 1.2+) and encryption at rest (AES-256);
- mandatory two-factor authentication on every account;
- strict per-tenant data isolation — cross-tenant access is not possible by design;
- server-side prompt confidentiality — system prompts and internal configuration never leave our infrastructure;
- role-based access control, least-privilege principle, and audit logging;
- regular dependency scanning, backup verification, and incident response procedures;
- employee confidentiality obligations and need-to-know data access.
13. Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR) and, where the risk is high, will also inform affected data subjects without undue delay (Art. 34 GDPR).
14. Children
ValueWE is a professional B2B tool not directed at anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to this policy
We may update this privacy policy from time to time to reflect changes to our processing, our subprocessors, or applicable law. Material changes will be announced in the product or by email. The current version and its effective date are shown at the top of this page.
16. Contact
For any privacy-related questions or to exercise your rights, please contact us at [email protected]. For customers, our Data Processing Agreement is available on request — see the DPA page.