Privacy Policy

Last updated: 13 July 2026

General

We hereby inform you, in accordance with the legal requirements of data protection law (in particular pursuant to the new BDSG and the European General Data Protection Regulation “GDPR”), about the type, scope, and purpose of processing personal data through our services. This privacy policy applies to the Bnder website and web application, Bnder workspaces and public pages, email and browser notifications, optional AI functions, optional Slack and Discord integrations and bots, payment functions, and our social media profiles. For the definition of terms such as "personal data" or "processing," please refer to Art. 4 GDPR.

Name and Contact Details of the Controller

Our Controller (hereinafter "Controller") within the meaning of Art. 4 No. 7 GDPR is:

Bnder UG (haftungsbeschränkt)
Im Flath 12
38542 Leiferde
Germany
Phone: +49 511 80764975
E-Mail: contact@bnder.net
Website: https://www.bnder.net
Register Court: Local Court of Hildesheim
Register Number: HRB 209373
Managing Director Authorized to Represent: Jan Brinkmann

Changes to this Privacy Policy

We reserve the right to adapt this privacy policy to comply with changed legal requirements or in case of changes to our services. We will inform you about significant changes on our website. The current version is always available on our website.

Types of Data, Purposes of Processing, and Categories of Data Subjects

Below we inform you about the type, scope, and purpose of the collection, processing, and use of personal data.

Types of Data We Process

  1. Account and authentication data, including display name, email address, verification status, authentication identifiers, profile picture, language, timezone, and notification preferences
  2. Workspace and collaboration data, including workspace memberships, projects, tasks, comments, tickets and customer contact data, documents, calendar events, files, settings, permissions, and audit or activity information
  3. Integration identifiers and content required for an integration selected by a user or workspace, including Slack workspace and user identifiers, Discord server and user identifiers, calendar connection data, and OAuth authorization data
  4. IT usage and security data, including IP address, device and browser information, access times, requested pages, diagnostic events, and security logs
  5. Search queries and indexed workspace content when search is used
  6. Notification and communication data, including recipient addresses or push tokens, message content, delivery status, and related metadata
  7. Inputs, context, generated results, and usage metadata when an optional AI function is used
  8. Payment and contract data, including transaction, subscription, billing, and invoice information; payment instrument data is processed directly by Stripe and is not stored by us

Purposes of Processing Pursuant to Art. 13 (1) (c) GDPR

  1. To create, verify, secure, and administer Bnder accounts and sessions
  2. To provide workspaces and the collaboration functions selected by users, including tasks, tickets, documents, calendars, files, public pages, search, and notifications
  3. To connect and operate optional Slack, Discord, calendar, OAuth, and other integrations requested by a user or workspace administrator
  4. To provide optional AI-assisted suggestions and chat functions when they are enabled or invoked
  5. To process contracts, subscriptions, invoices, and payments
  6. To protect, monitor, troubleshoot, and improve the availability, security, and usability of our services and to create usage statistics
  7. To meet legal obligations and handle requests for access, export, correction, or deletion

Categories of Data Subjects Pursuant to Art. 13 (1) (e) GDPR

  • Visitors to our website and public Bnder pages
  • Registered users, invited users, and members or guests of Bnder workspaces
  • People whose contact or request data is entered into tickets or public forms by themselves or authorized workspace users
  • Users of optional Slack, Discord, calendar, OAuth, search, notification, and AI functions
  • Customers and billing contacts who use paid services

The data subjects are collectively referred to as "Users."

Bnder Accounts and Workspace Content

We process account data to register and authenticate users, verify email addresses, recover access, and apply account preferences. Workspace content is processed to provide the features selected by the user or workspace, including projects, tasks, tickets, documents, calendars, files, public pages, permissions, and activity records. Visibility depends on the workspace settings, memberships, permissions, and any deliberate publication or sharing configured by authorized users.

Users may request an export through the application where available or contact us using the details below. Account deletion and workspace deletion are separate operations because workspace content may belong to a team and may contain contributions from several users.

Optional AI Functions

When a user or workspace enables or invokes an AI-assisted function, the content needed for that function may be sent to the configured AI service provider. This may include task or ticket text, selected workspace context, chat messages, and instructions needed to generate labels, priorities, summaries, suggestions, or answers. Bnder currently uses OpenAI models through its configured AI gateway. We process this data to provide the requested feature and do not use raw prompts, model responses, or reasoning as general application log content. Users should not enter information into an AI function that they are not authorized to process.

Optional Integrations and Notifications

Slack, Discord, calendar, OAuth, browser-push, and email functions are optional or depend on workspace configuration. If they are used, we process the identifiers, authorization data, selected content, and delivery metadata required to perform the requested synchronization, notification, or integration action. Removing an integration stops new integration processing, subject to technical cleanup periods and legal retention obligations.

Use of Algolia

We use Algolia to provide a fast and relevant search function on our website. The following data is processed:

  • Search queries
  • Interactions with the search function
  • Usage data (e.g., IP address, device type, access times)

Algolia processes this data as a processor on our behalf and stores it on servers within the EU. For more information, see Algolia’s privacy policy at https://www.algolia.com/policies/privacy.

Use of Posthog for Usage Statistics

We use Posthog, an analytics service, to generate anonymized usage statistics. Processing is carried out solely to improve our services technically, increase user-friendliness, and ensure system stability. No use for advertising purposes takes place.

Data Processed:

  • Page views, click paths, and interactions within our services
  • Device information (e.g., browser type, operating system, screen size)
  • Timestamps and technical performance data

Data Security:

  • User IDs are pseudonymized before processing.
  • Identifiable parameters from URLs (e.g., IDs in paths or query parameters) are masked to prevent conclusions about specific individuals.
  • No personal profiles are created.

Processing is based on Art. 6 (1) (f) GDPR, on our legitimate interest in analyzing and optimizing our services.

Storage & Transfer:

Data is processed on Posthog servers within the EU. If processing occurs outside the EU, appropriate safeguards (e.g., standard contractual clauses under Art. 46 GDPR) are applied. More information: https://posthog.com/privacy

Use of Mailgun for Email Delivery

We use Mailgun, provided by Mailgun Technologies, Inc., 112 E Pecan St. #1135, San Antonio, TX 78205, USA, to send emails to our users (e.g., system notifications, transactional emails, confirmations, technical information).

Processed Data:

  • Recipient’s email address
  • Content of the emails sent
  • Metadata of email communication (e.g., sending time, delivery status, email server IP address)
  • Technical data (e.g., user agent of the email client, if applicable open rates via tracking pixels)

Legal Basis: Processing is carried out pursuant to Art. 6 (1) (f) GDPR, based on our legitimate interest in reliable, secure, and scalable email delivery. If communication relates to a contractual relationship, the legal basis is Art. 6 (1) (b) GDPR.

Data Processing & Third-Country Transfer: We have a data processing agreement with Mailgun. Mailgun may transfer data to the USA or other third countries. EU Standard Contractual Clauses are used to ensure adequate data protection under Art. 46 GDPR.

More information: https://www.mailgun.com/privacy-policy/

Data Processing by Our Discord Bots

Our Discord bots process data to provide you with the full functionality of our services. All transmitted data is stored on secure servers in the EU. Processing is automated and exclusively serves the provision of bot functions. You can request deletion of your data at any time by removing the bot from your server and sending us a request to our contact address.

We also use external service providers such as Cloudflare (for secure access), Google Cloud (for hosting and data processing), and Algolia (for search functionality).

Payment Processing via Stripe

We use Stripe as a payment service provider to process payments for our paid services. The payment information you provide (e.g., credit card numbers, bank details) is transmitted directly to Stripe and processed by them. We do not store any payment data ourselves.

Processing by Stripe is carried out in accordance with applicable data protection regulations and solely for payment processing purposes. Stripe may transfer your data to the USA. To ensure adequate protection, Stripe uses EU Standard Contractual Clauses and other approved measures.

More information: https://stripe.com/de/privacy.

  • Where we obtain your consent, Art. 6 (1) (a) GDPR is the legal basis.
  • If processing is necessary for the performance of a contract or pre-contractual measures, Art. 6 (1) (b) GDPR is the legal basis.
  • If processing is required to comply with a legal obligation (e.g., retention obligations), Art. 6 (1) (c) GDPR applies.
  • If processing is necessary to protect vital interests, Art. 6 (1) (d) GDPR applies.
  • If processing is necessary for legitimate interests, and your interests or rights do not override them, Art. 6 (1) (f) GDPR applies.

Disclosure of Personal Data to Third Parties and Processors

We only disclose personal data to third parties if necessary for contractual obligations, if we are legally obliged, or if a legitimate interest exists.

We use the following processors:

  • Google Cloud Platform: For hosting, storage, and processing of data within the EU.
  • Cloudflare: To secure our website and services (e.g., against DDoS attacks).
  • Stripe: For payment processing, with possible transfer outside the EU (e.g., to the USA).
  • Mailgun Technologies, Inc.: For sending emails, with possible third-country transfers (e.g., USA) secured by Standard Contractual Clauses.
  • Algolia: For indexing and searching content where search is used.
  • PostHog: For pseudonymized product usage and stability analytics.
  • OpenAI and the configured AI gateway provider: For content submitted to optional AI-assisted functions.

Data Transfer to Third Countries

In principle, personal data is processed within the EU. However, due to the use of Google Cloud, Cloudflare, and Stripe, data may be transferred to third countries (outside the EU). In such cases, we ensure compliance with Art. 44 ff. GDPR, particularly through Standard Contractual Clauses and other safeguards.

Deletion of Data and Storage Period

Unless otherwise stated, your personal data will be deleted or blocked as soon as the purpose of storage ceases, unless further retention is required for evidence or due to legal obligations (e.g., commercial retention: 6 years, tax retention: 10 years).

Account deletion removes or anonymizes personal account data according to the applicable deletion workflow. Workspace content is retained, transferred, anonymized, or deleted according to workspace ownership, permissions, contractual obligations, and the deletion action selected by an authorized workspace owner. Removing a Slack or Discord integration stops new synchronization; integration-specific credentials and data are then removed according to the applicable cleanup workflow. Verification-link records are retained for up to seven days so replayed links can be recognized and are then deleted through automated expiry. Immediate deletion may be requested using the contact details below, subject to the rights of other workspace members and statutory retention obligations.


Rights of Data Subjects

You have the following rights:

  • Right of Access (Art. 15 GDPR)
  • Right to Rectification (Art. 16 GDPR)
  • Right to Erasure (Art. 17 GDPR) or alternatively restriction of processing (Art. 18 GDPR)
  • Right to Data Portability (Art. 20 GDPR)
  • Right to Lodge a Complaint (Art. 77 GDPR) with a supervisory authority

Right to Object

Users may object to the processing of their personal data at any time, particularly for direct marketing purposes.


Contact for Data Protection Inquiries

Email: contact@bnder.net Address: Im Flath 12, 38542 Leiferde, Germany