Back to home

Legal

Privacy Policy

Privacy Policy for HansaChat. Learn how we collect, use, and protect your data. Last updated: 11 September 2026.

Last updated: 11 September 2026 · Version 2026-09-11

1. Our Role

HansaChat is operated by Igor Tverdokhleb, trading as HansaChat, Barkentinenstr. 20, 23558 Lübeck, Germany. Contact: igor@hansa.chat. He is the controller for the processing carried out for HansaChat’s own purposes described below.

For workspace content that customers and their users send, upload, or manage in HansaChat, HansaChat generally acts as a processor on behalf of the workspace owner or customer. The workspace owner or customer decides why the workspace is used, who is invited, what content is added, and how long the workspace should remain active.

For account administration, billing, security, abuse prevention, support, website, and service communication data, HansaChat acts as the controller.

2. Information We Process

Depending on how you use HansaChat, we may process:

  • Account data such as name, email address, password hash, verification state, locale, and session data.
  • Workspace data such as workspace names, memberships, roles, channels, direct messages, mentions, reactions, uploaded files, and message metadata.
  • Billing and subscription data such as plan, billing interval, subscription status, coupon use, checkout identifiers, and customer email address.
  • Operational and security data such as IP address, country header, browser/device information, authentication events, request logs, error reports, and abuse-prevention signals.
  • Support, contact, and feedback data such as email address, message content, company size, and any information you choose to send us.
  • Email delivery data such as recipient address, sender information, subject, message body, delivery status, bounce, and complaint metadata.
  • Customer relationship data such as account identifier, registration event, workspace name and plan, environment marker, and first-touch acquisition source and medium, recorded in our self-hosted CRM when you register or create a workspace. We do not store your raw signup IP, name, or UTM term/content in the CRM.

3. Purposes and Legal Bases

We process personal data to:

  • For processing for our own purposes, we rely on Article 6(1)(b) GDPR where necessary to perform a contract with you or take steps you request before a contract; Article 6(1)(c) where a legal obligation requires processing; and Article 6(1)(f) for the legitimate interests identified below. Optional processing based on consent relies on Article 6(1)(a). Processing workspace content on a customer’s behalf follows its documented instructions under the DPA; the customer determines the legal basis for that processing.
  • Administer customer accounts and subscriptions and send necessary account, billing and service communications: contract performance for the contracting individual; legitimate interests in administering the customer relationship for business contacts who are not personally party to the contract.
  • Handle tax, accounting and legally required billing records: compliance with applicable tax and accounting obligations; administer payments, refunds and contractual billing issues: contract performance where applicable.
  • Protect accounts, users and infrastructure, prevent abuse, diagnose faults and maintain necessary security records: legitimate interests in secure, reliable operation and the prevention and defence of unlawful activity.
  • Respond to support and contact requests: contract performance or requested pre-contractual steps where applicable; otherwise legitimate interests in answering enquiries and resolving service issues.
  • Maintain customer relationship records for registrations and workspaces: contract performance where necessary for the contracting individual, and legitimate interests in customer administration and understanding acquisition sources. Acquisition attribution is not treated as necessary for providing chat.

4. Workspace Content and Visibility

HansaChat is a workspace communication product. Public channel content is available to workspace members who can access those channels. Private channel content is available to members of those private channels. Direct messages are available to their participants.

Workspace owners and admins can manage workspace settings, users, and access. They cannot automatically read private channel content or direct messages unless they are members or participants, but they may control account and workspace-level settings within the product.

5. HansaChat Operator Access

As the service operator, HansaChat has the technical capability to access workspace data, including messages, files, user records, and memberships. We only use this access when needed for maintenance, troubleshooting, security, abuse prevention, legal compliance, or when a customer asks us to help with a specific issue.

Where German telecommunications secrecy applies, HansaChat does not obtain knowledge of communication content or circumstances beyond what is necessary to provide the service or protect its technical systems. Use for another purpose requires a law that expressly permits it in relation to telecommunications.

We do not sell workspace data or use message content for advertising.

6. Hosting and Sub-processors

BunnyWay d.o.o. (bunny.net) provides edge delivery, CDN, DNS/proxy and DDoS protection, processing connection and request metadata as needed. It also stores backup copies encrypted by HansaChat before transfer in Frankfurt, Germany and Stockholm, Sweden. Edge delivery may involve locations outside the EEA; where Chapter V GDPR applies, we use applicable adequacy decisions or Standard Contractual Clauses and supplementary safeguards. Information about the applicable safeguards is available from igor@hansa.chat.

HansaChat hosts core application data on IONOS Cloud. Account, workspace, and message data is stored in a managed MySQL-compatible Database as a Service (DBaaS). Uploaded files are stored in IONOS Cloud Object Storage and encrypted at rest.

Transactional and service emails are sent through our European partner EmailLabs (Vercom S.A.), which may process the email addresses, message content, and delivery metadata needed to deliver those emails.

Paid subscription checkout, tax, invoice, refund, and payment-related workflows are handled through Creem, our merchant-of-record and billing provider. Creem only receives data needed for billing and subscription handling.

7. Retention and Deletion

Retention depends on the workspace and account state:

  • Demo workspaces are deleted after 24 hours.
  • Free workspaces remain writable and are deleted after 90 days without a persisted message. Workspace owners receive warnings with 30, 7, and 1 day remaining. A new persisted message restarts the inactivity period.
  • A cancelled paid or trial workspace remains usable through the paid or trial period, then becomes read-only for 90 days and is permanently deleted. Reactivation during that period restores write access and cancels the scheduled deletion.
  • An owner-requested workspace deletion makes the workspace read-only immediately and permanently deletes it after a 30-day grace period unless the owner cancels the request.
  • Workspace databases and uploaded objects are removed by the applicable deletion process. Deleted workspace data ages out of encrypted backups according to the documented backup-retention schedule.
  • Accounts remain in place while the owner has any active, read-only, deletion-scheduled, or archived workspace. For immediate deletion requests under the GDPR, see section 10.
  • Billing records, invoices, security logs, and legal records may be retained longer where required for accounting, fraud prevention, dispute handling, or legal compliance.

8. Analytics, Cookies, and Logs

Website analytics runs on our self-hosted Umami instance without cookies for every visitor: pages visited (including campaign parameters), the site you came from, browser and device type, screen size, language, country, and button or download interactions. Visits are separated using a salted hash of the connection and browser signature; raw IP addresses are never stored.

After choosing "Accept all", we additionally record anonymized session replays and heatmaps to understand usability; form inputs are masked during recording. We never collect form contents, personal data, full URLs, or cross-site identifiers. You can change or withdraw your choice at any time via the "Privacy settings" link in the footer.

Aggregate product metrics (for example member and message counts per workspace, used for milestone analytics) are computed by the chat backend and contain no message content, names, or individual activity.

HansaChat does not use third-party advertising trackers. We collect limited operational analytics such as browser name, country, and visited pages to understand usage and keep the service working.

We do not intentionally log IP addresses for analytics. IP addresses may still appear in security, infrastructure, payment, email delivery, or error-monitoring records when needed to operate and protect the service.

9. Core Data Storage

Core workspace and application data, including messages and account records, is stored in IONOS Cloud DBaaS. Uploaded files are stored separately in encrypted IONOS Cloud Object Storage.

EmailLabs and Creem process only the limited workflow-specific data needed for email delivery and billing.

Customer relationship records are stored in our self-hosted CRM on the same private IONOS cluster and are reachable only inside the cluster and over a dedicated VPN.

10. Your Rights

Depending on your location and the role of your workspace owner, you may have the right to access, rectify, erase, restrict, object to processing, request portability, and withdraw consent where processing is based on consent.

Workspace content requests may need to be handled by the workspace owner or customer as controller. You can contact us at igor@hansa.chat and we will route or support the request where appropriate.

You may also have the right to lodge a complaint with a competent data protection supervisory authority.

You may request immediate deletion of your account and the personal data concerning you under Article 17 GDPR, without waiting for the standard account or workspace grace period. Please create a support ticket in the “Privacy / GDPR request” category, state that you request immediate deletion, and identify the account and any affected workspace. Do not include passwords or unnecessary sensitive information.

We assess the request without undue delay, verify identity where reasonably necessary, and erase data without undue delay where the right to erasure applies. We normally inform you of the action taken within one month of receipt. Any extension permitted by the GDPR will be explained within that month. Legal retention obligations, the establishment, exercise or defence of legal claims, and other statutory exceptions may prevent deletion of some records; we explain any refusal or restriction. Requests about customer-controlled workspace content are forwarded to the responsible customer and supported under the DPA.

If you cannot sign in or prefer another contact route, email igor@hansa.chat. A support ticket is our normal handling route, not a condition for exercising your statutory rights.

Create a privacy request ticket

11. Required Data

Some data is necessary to provide the service. For example, without an email address we cannot create an account, send security emails, or manage billing. Without workspace content and membership data, the chat service cannot function.

12. Contact Us

If you have any questions about this Privacy Policy or how HansaChat processes personal data, please contact us at igor@hansa.chat.