Privacy policy
Last updated: 11 August 2026. Written to describe what this site and the prompt-crm application actually do with personal data.
1. Who is responsible
dionics media UG (haftungsbeschränkt), Birkhuhnweg 8, 31303 Burgdorf, Germany, represented by Thilo Krause. E-mail: websites@dionics.ai. See the imprint.
2. Visiting this website
Hosting is provided by Vercel Inc. (USA). Server logs process your IP address, time, requested URL, referrer and browser data to deliver the site and keep it secure — our legitimate interest (Art. 6(1)(f) GDPR). Transfers to the USA are covered by standard contractual clauses and Vercel's EU-U.S. Data Privacy Framework certification.
Optional Google Analytics 4 (Google Ireland Ltd.) loads only after you accept it in the cookie banner (Art. 6(1)(a) GDPR, § 25 TDDDG), with IP anonymisation. Details, including how to withdraw, are in the cookie notice.
3. The contact form
If you write to us through the form, we process the name, e-mail address and message you enter, to answer you (Art. 6(1)(b) or (f) GDPR). The message is delivered by Zoho Corporation's mail service as our processor. The form is protected by Google reCAPTCHA, which processes device and interaction signals to tell people from bots — legal basis is our legitimate interest in keeping the form usable (Art. 6(1)(f)); Google may transfer this data to the USA under its Data Privacy Framework certification.
4. Using the CRM application
If you hold an account, we process your name, e-mail address and a salted password hash, plus session records including IP address and user agent, to provide the service and secure the account (Art. 6(1)(b) and (f) GDPR).
If you connect a mailbox, its credentials are stored encrypted and are used solely to send and read mail on your instruction. Your outgoing e-mail goes through your own mailbox provider, not through ours.
5. If a business you run appears in this CRM
prompt-crm is a tool for finding and contacting local businesses. A workspace may therefore hold records about businesses — typically: business name, address, phone number, website, opening hours, Google rating and short excerpts of public reviews. This data comes from publicly accessible business listings (Google Maps, retrieved via the Apify platform). Legal basis for holding it: legitimate interest in business-to-business contact (Art. 6(1)(f) GDPR).
- Reviewer names and profile links are never stored. Review excerpts are kept without any identifier of the person who wrote them, and this happens at import — the names never reach the database.
- Records concern businesses, not private individuals; where a sole proprietor's business data is also personal data, the rights below apply in full.
- If you want your business's record corrected or deleted, e-mail websites@dionics.ai — deletion is permanent (the product deletes hard, it does not archive).
6. Where the data lives
The application database is operated by Neon Inc. on AWS in the us-east-1 region (United States). Processing in the USA is safeguarded by a data processing agreement incorporating the EU standard contractual clauses (Art. 46(2)(c) GDPR).
7. Processors
Vercel (hosting), Neon (database), Zoho (transactional e-mail), Google (Analytics — only with consent — and reCAPTCHA), Apify (retrieval of public business listings). Each processes data on our documented instructions under a data processing agreement.
8. Retention
Account data is kept until the account is deleted. CRM records are kept while the workspace uses them and are hard-deleted on removal — there is no archive copy. Server logs are retained for the short period the hosting provider keeps them.
9. Your rights
Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection to legitimate-interest processing (Art. 21) and withdrawal of any consent with effect for the future (Art. 7(3)) — all via websites@dionics.ai. You may complain to a supervisory authority (Art. 77); ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.
10. What we do not do
- No payment processing on this site and no payment data stored.
- No social logins.
- No advertising networks and no sale of personal data.
- No automated decision-making with legal effect (Art. 22 GDPR).
11. Changes
When the product gains features that change the processing, this policy is updated first and the date above changes.