Data protection provisions
Last updated:
August 1, 2026
This privacy policy informs you about the nature, scope and purpose of the processing of personal data (“data”) when using the website and the Supercount AI platform. For data processed within the platform on behalf of our customers, the respective data processing agreement (DPA) pursuant to Art. 28 GDPR additionally applies.
1. Controller
Supercount AI FlexCo, Peter-Behrens-Platz 10, 4020 Linz, Austria. E-mail: sebastian@supercount.ai. Managing Directors: Mag. Markus Waghubinger, Sebastian Kaiser-Mühlecker, MSc.
2. Types of Data Processed and Purposes
a) Provision of the website: We process technically required data (including IP address, date/time of access, requested page, referrer, browser/device information) in order to provide the website and ensure system security. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
b) Contact (e-mail, contact form): We process the information you provide in order to handle your enquiry. Legal basis: contract or pre-contractual measures (Art. 6(1)(b) GDPR), otherwise legitimate interest (lit. f).
c) Performance of contract: Master, contact, contract and payment data for the provision of our services, billing and customer support. Legal basis: contract (Art. 6(1)(b) GDPR). We process our customers’ client/accounting data exclusively as a processor on the basis of the DPA; the respective customer remains the controller.
d) Web analytics and cookies: We use exclusively technically necessary cookies for authentication and session management. Our website is provided via the website builder Framer (Framer B.V., Netherlands). For reach measurement we use Framer’s privacy-friendly, cookie-less analytics; no cookies or comparable trackers are set, and the data serves exclusively for technical optimisation. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
3. Recipients of Data / Sub-processors
To provide our services we use carefully selected service providers contractually bound under Art. 28 GDPR. Region information describes the region configured for product processing; it does not mean that all support, security or account processes of the providers take place exclusively in that region.
a) Website and platform frontend: The marketing website is provided via Framer (Framer B.V., Netherlands). The platform (app) frontend is delivered by Vercel Inc. (USA) via a global edge network with EU regions. No document images or accounting content are hosted at Vercel; technical usage data (e.g. IP address, headers, user agent) may be processed.
b) Backend, database and authentication: Supabase Pte. Ltd. (Singapore) – configured project region EU (Frankfurt). The DPA executed for Supercount was historically concluded with Supabase Inc.; the current contracting entity is Supabase Pte. Ltd. The technical storage and processing location is Frankfurt. Worldwide support or intra-group ancillary processing may trigger third-country access; the contractual safeguards apply, including EU Standard Contractual Clauses (SCC). In addition, Google Cloud (EU regions) is used for infrastructure/processing.
c) AI services for automated accounting processes: Google Vertex AI (Gemini models) via Google Cloud EMEA Limited – restricted to EU regions and EU endpoints (primarily Frankfurt); no training with customer data. AWS Bedrock (Anthropic Claude models) via Amazon Web Services EMEA SARL – exclusively EU region (Frankfurt), in-region inference without cross-region or global inference; for this processing route Zero Data Retention is configured (no model invocation logging, no storage of inputs or outputs by AWS) and no training with customer data takes place; models that require retention or disclosure to the model provider are unavailable under Supercount’s AWS configuration and are not used.
Optional AI route (only upon activation by the respective firm): OpenAI functions exclusively via the chain Supercount AI → finothek GmbH (Linz) → OpenAI Ireland Ltd. (Dublin). Supercount AI does not maintain a direct OpenAI account. Under the finothek data processing agreement, content logging at the OpenAI endpoint is fully disabled and Supercount’s project interfaces do not permit content logging; finothek does not take note of the content. Training and feedback sharing are disabled; no training with customer data. OpenAI retains API data on its side for a maximum of 30 days and then deletes it; no further-reaching zero-data-retention is promised. A possible intra-group transfer to OpenAI OpCo LLC (USA) is safeguarded by EU Standard Contractual Clauses.
Further optional AI routes (only upon activation by the respective firm): Mistral AI SAS (Paris, France) and Scaleway SAS (Paris, France) via EU endpoints in France; no training with customer data. Without express activation by the firm, no processing takes place via these routes; the processing route is not switched automatically.
d) E-mail services: Plus Five Five, Inc. d/b/a Resend (USA) for transactional system e-mails; the sending region Ireland (eu-west-1) is used for the configured domain. Mailgun Technologies, Inc. (Sinch) for the EU-side inbound receipt/e-mail handling.
e) Error and security monitoring: Functional Software, Inc. d/b/a Sentry – EU endpoint (de.sentry.io). PII scrubbing is enabled; document and content data are not intended for transmission, and error data is technically minimised.
f) DATEV interface (optional, only upon activation by the firm): Klardaten GmbH (Berlin, Germany) – processing in the EU; bilateral data processing agreement with explicit reference to Section 203 German Criminal Code / Section 80 Austrian WTBG 2017.
g) Payment processing: Currently no automated payment processing takes place via the platform; invoicing and payment are handled manually outside the software.
4. Data Transfers to Third Countries
Product processing is fixed to EU regions and EU endpoints (in particular AWS Frankfurt, configured Google EU regions, Supabase Frankfurt). This technical region setting does not exclude that individual providers process data in third countries for support, account or security processes. Where processing takes place outside the EU/EEA, we base it on appropriate safeguards under Chapter V GDPR, in particular an adequacy decision (EU-US Data Privacy Framework, DPF) or EU Standard Contractual Clauses (SCC).
As of 24 July 2026, Vercel Inc., Functional Software (Sentry), Mailgun Technologies, Inc. and Resend are listed in the Data Privacy Framework register; for the Supabase constellation and the optional finothek/OpenAI chain, SCCs apply. The DPF status is re-checked before larger transfers.
5. Storage Period
We store data only for as long as necessary for the respective purposes. Accounting and contract data are subject to commercial and tax retention obligations (in Austria generally 7 years, Section 132 BAO / Section 212 UGB). Enquiry data is deleted once no longer required, unless a statutory retention obligation exists. For data in the customer platform, the provisions of the respective DPA apply (including a 30-day export window after the end of the contract, followed by deletion from the production systems; technically isolated security copies are overwritten within the documented rotation and deletion cycles of the respective providers).
Purpose and limits of storage: Data is stored on a case basis, solely so that the AI functions used by the users of a case receive the most useful context for that case. No training of AI models and no commercial exploitation takes place; storage serves solely for the provision of the service. When a case/mandate is deleted, the associated data and patterns are removed practically immediately; only individual objects such as document images may remain briefly at infrastructure services (e.g. Google) for recovery purposes and are then also deleted. The 30-day window relates exclusively to the data-export option after termination of the contract.
6. Your Rights as a Data Subject
Subject to the GDPR, you have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You may withdraw a given consent at any time with effect for the future (Art. 7(3)).
7. Right to Lodge a Complaint
If you believe that the processing of your data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in Austria the Austrian Data Protection Authority (www.dsb.gv.at).
8. Changes to this Privacy Policy
We update this privacy policy when our processing, the services used or legal requirements change significantly. The version published on the website from time to time applies.

