Privacy Policy · Datenschutzerklärung
Privacy policy
As of:
With this privacy policy, we inform you about how personal data is processed when you use Peak Atlas and our website at app.peak-atlas.com.
Summary in English
Google user data at a glance
What we request
Peak Atlas uses Google Sign-In (OAuth 2.0 / OpenID Connect) only to authenticate you. We request the basic scopes email and profile and nothing else.
What we receive
Your Google account ID, your name, your email address (and whether Google has verified it) and a link to your profile image.
How we use it
Only to create your Peak Atlas account or match it to your existing one, to sign you in, and to show your name and email address inside Peak Atlas. We do not use it for advertising, and we do not sell it.
What we don’t access
Signing in with Google does not give Peak Atlas access to your Gmail, Google Drive, Google Calendar, contacts or any other Google service.
Peak Atlas’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. To delete your account and data, email philipp.rueckert@peak-atlas.com. The binding German version follows below.
Peak Atlas is a digital business platform for entrepreneurs, companies and teams. The platform enables users to organize their work, use business applications, manage information and – where activated by the user – connect external services and integrations to their workspace.
1. Controller
The controller for the processing of personal data in connection with Peak Atlas is:
Peak Atlas HQ GmbHEichhornstraße 5
97070 Würzburg
Germany
Email: philipp.rueckert@peak-atlas.com
Authorized representatives: Philipp Rückert (Managing Director)
Register court: Würzburg Local Court, HRB 17790
VAT ID: DE456847573
2. What data we process
Depending on how you use Peak Atlas, the following categories of personal data in particular may be processed:
- Master and profile data, in particular name, email address and profile picture
- Account and authentication data
- Organization and workspace assignments
- content you enter or upload within Peak Atlas
- Settings and preferences
- Information about use of the platform
- technical data such as IP address, browser type, operating system, time of access and technical log data
- Support and communication data
- data from external services or integrations, if you expressly activate such a connection
Which data is processed specifically depends on which Peak Atlas functions you use.
3. Purposes and legal bases of processing
We process personal data in particular for the following purposes:
Providing Peak Atlas
We process data that is required to provide user accounts, workspaces, applications and other functions of Peak Atlas.
Processing takes place in particular to perform the user relationship and, where applicable, on the basis of legitimate interests in providing and securely operating our platform.
Authentication and account security
We process account and authentication data in order to uniquely identify users, enable sign-ins and prevent unauthorized access.
Operation, security and error analysis
Technical data and log data may be processed in order to:
- to provide the platform technically,
- to detect and fix errors,
- to prevent misuse and security incidents,
- to ensure the stability and security of the platform.
Support and communication
If you contact us, we process the data you send us in order to handle your request.
Further development of the platform
We may use usage information in a privacy-compliant manner to further develop the features, usability, stability and security of Peak Atlas.
Where consent is required for this, processing takes place exclusively after prior consent.
4. Sign-in with Google
Peak Atlas offers the option to sign in with a Google account. If you select “Continue with Google,” we use Google OAuth 2.0 / OpenID Connect for authentication. The technical handling of the sign-in is carried out by our authentication provider Supabase.
Requested permissions
When you sign in, Peak Atlas requests only the basic permissions email and profile. No further Google permissions are requested.
Data we receive from Google
- unique Google account ID,
- name,
- email address and whether Google has verified it,
- link to your Google profile picture.
We use this information exclusively to create your Peak Atlas account or assign it to your existing account, to authenticate you and to display your basic profile data (name and email address) within Peak Atlas. The data is stored together with your user account in the database of our authentication provider Supabase.
No automatic access to other Google services
Signing in with Google alone does not give Peak Atlas access to content from Gmail, Google Drive, Google Calendar or other Google services. Peak Atlas does not use Google credentials received during sign-in to access Google services.
Such access would only occur if Peak Atlas offers a corresponding integration in the future, you expressly activate this function, and Google shows you the specific permissions requested in advance. We request Google permissions only to the extent they are required for the respective function the user wants. This privacy policy will be updated accordingly before any such change.
Use of Google user data
To the extent Peak Atlas receives data via Google APIs, we use this data exclusively for the functions presented to the user and requested by them. Google user data is not sold and not used for advertising purposes.
We only share Google user data to the extent that this:
- is required to provide a function requested by the user (e.g. to our technical service providers named in section 8),
- is necessary to meet legal obligations,
- is necessary to protect against security risks, misuse or fraud, or
- has been expressly authorized by the user.
Our use and transfer of information received via Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements that apply there.
You can revoke Peak Atlas's access to your Google account at any time in your Google account settings at myaccount.google.com/connections.
5. External integrations
In the future, Peak Atlas may enable users to connect external services to their workspace. No external integrations are currently active. In principle, a connection is only established once the user activates the integration in question or grants the required permissions.
The scope of the data processed depends on:
- the respective service,
- the selected integration,
- the permissions granted by the user, and
- the specific function the user wants to use.
In line with the principle of data minimization, permissions are requested only to the extent required for the respective function. In principle, a user can disconnect an integration again, to the extent the respective function allows it.
6. Content within Peak Atlas
When users enter, create or upload content in Peak Atlas, we process this data to the extent necessary to provide the respective function. This may include, for example:
- tasks,
- projects,
- notes,
- company information,
- files,
- comments,
- settings and
- other content created by the user.
Users retain their rights to the content they contribute. We do not use this content for purposes incompatible with providing Peak Atlas, unless a separate legal basis or consent exists for it.
7. AI-powered features
Peak Atlas may offer AI-powered features, for example for search, summarization, analysis or support in work processes. The “Ask Peak” function in the Smart Bar is currently a preview; no content is transmitted to AI service providers in the process.
If a user uses such a function in the future, the content required for the specific request may be processed and, where applicable, transmitted to an AI service provider we use. We limit this processing to the data required for the respective function. Where external AI service providers are used, they are engaged within the framework of the applicable data protection requirements.
Data received via Google Sign-In is not transmitted to AI service providers and not used to train AI models.
8. Hosting and technical service providers
We use technical service providers to operate Peak Atlas. These may include, in particular, providers of the following services:
- hosting and deployment,
- databases,
- authentication,
- storage,
- error analysis,
- email delivery,
- security and infrastructure services.
The central infrastructure providers currently used are Supabase (database and authentication), Vercel (hosting and delivery of the application) and Sentry (error analysis; Functional Software Inc., processing in the EU region Frankfurt, transmitted via our own domain, without IP addresses, cookies or session recording). Where service providers process personal data on our behalf, they are engaged in accordance with the statutory requirements.
9. Transfers to third countries
Some of the service providers we use may have their registered office outside the European Economic Area or process data outside the European Economic Area.
To the extent personal data is transferred to a third country in this context, we ensure that the applicable data protection requirements are met. This may take place in particular on the basis of an adequacy decision, appropriate safeguards or other transfer mechanisms provided for by law.
10. Cookies, local storage and similar technologies
Peak Atlas uses technically necessary cookies and comparable technologies in order to:
- to maintain a sign-in (session cookies of our authentication provider),
- to store security-relevant information,
- to save user settings (such as pinned and recently opened apps in your browser's local storage) or
- to provide the functions expressly requested by the user.
Our own usage measurement without cookies
To understand how Peak Atlas is found and used, we record usage events on our own systems, such as pages viewed (without URL parameters; identifiers and invitation links are truncated), solutions opened in Discover, steps reached in the Energy Audit, completed onboarding steps and milestones reached in the apps. Free text such as search terms is not recorded.
- For visitors without an account, we store nothing on your device for this purpose and read nothing from it. A visit is summarized only via a random identifier in the working memory of the open page; it expires as soon as the page is reloaded.
- We store neither IP addresses nor browser or device identifiers, only the domain of the referring page and, where applicable, campaign parameters (utm) from the link through which you came.
- If you sign in, we assign the visit from which you signed in to your account. Events of signed-in users are assigned to the respective account.
- We additionally analyze the same events, with the same truncations, using PostHog (PostHog Inc., processing in the EU cloud in Frankfurt). Transmission takes place exclusively from our servers, without an IP address and without location detection; your browser loads no third-party script for this, nothing is stored on your device, and there is no session recording and no automatic capture of clicks or inputs. We do not use marketing or advertising tracking.
- If your browser sends the “Global Privacy Control” or “Do Not Track” signal, we do not record any usage events.
The legal basis is our legitimate interest in developing and improving Peak Atlas to meet needs (Art. 6(1)(f) GDPR). You can object to the processing at any time, e.g. by email to philipp.rueckert@peak-atlas.com.
Fonts are delivered from our own server. If, in the future, storing information on or accessing information from your device is not technically necessary, this will only take place on the basis of the required consent.
11. Retention period
In principle, we store personal data only as long as is necessary for the respective processing purposes. Account and workspace data is in principle stored for the duration of the user relationship.
After an account is deleted or the contractual relationship ends, personal data is deleted or anonymized, unless statutory retention obligations or other legitimate reasons prevent immediate deletion.
Technical backups may persist for a limited period before they are overwritten or deleted as part of regular backup cycles.
12. Deletion of an account and data
Users can request the deletion of their Peak Atlas account and of the personal data associated with their account – including data received via Google Sign-In – at any time. An email to the following address is sufficient: philipp.rueckert@peak-atlas.com
If a direct account deletion function is offered within the application, it can be used as well.
We delete personal data unless statutory retention obligations or other legal grounds for further storage exist.
Removing an external integration in principle prevents future access via that connection. Data that has already been lawfully processed is handled in accordance with the rules described in this privacy policy.
13. Recipients of data
Personal data may be transmitted, to the extent necessary, to the following categories of recipients in particular:
- hosting and infrastructure providers,
- authentication providers,
- database and storage providers,
- communication and support providers,
- integration providers you have activated,
- security and technical service providers,
- authorities or other bodies, where a legal obligation exists.
We do not sell personal data.
14. Data security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure. These include in particular:
- encrypted data transmission (HTTPS/TLS),
- access controls at the database level, so that users can only access their own data,
- secure authentication without storing a password of our own when signing in with Google,
- regular technical updates, and
- further security measures appropriate to the risk.
15. Your rights
Subject to the statutory requirements, you have the following rights in particular:
- Right of access,
- Right to rectification,
- Right to erasure,
- Right to restriction of processing,
- Right to data portability,
- Right to object to certain processing,
- Right to withdraw consent given, with effect for the future.
To exercise your rights, you can contact us at philipp.rueckert@peak-atlas.com.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
16. Changes to this privacy policy
Peak Atlas is continuously being developed. It may therefore be necessary to adapt this privacy policy, for example when new features, integrations or service providers are added.
The current version is available at app.peak-atlas.com/privacy. In the event of material changes, we will inform users in an appropriate manner.
17. Contact
If you have questions about data protection or the processing of personal data, you can reach us at:
Peak Atlas HQ GmbHEichhornstraße 5
97070 Würzburg
Germany
Email: philipp.rueckert@peak-atlas.com
