Privacy Policy

for the SmoovOps website and the SmoovOps application, operated by ···

1. Controller and overview

1.1 Controller

···
c/o ···
···
···, Germany

Phone: ···
Email: ···

1.2 Two roles: controller and processor

When using SmoovOps, it's important to distinguish between two different roles Northwood UG plays:

  • As controller (Art. 4 No. 7 GDPR), we process personal data that relates directly to us or that is necessary to provide our website and to establish and carry out the contractual relationship with our customers — e.g. the name, email address, billing address, and payment data of the person who creates a SmoovOps account.
  • As processor (Art. 28 GDPR), we process the data our customers themselves enter and manage within SmoovOps — such as partner/CRM records, contract data, and invoice data relating to their own customers. Our customers remain the data protection controller for this data; we process it strictly on their documented instructions, under a Data Processing Agreement (DPA) made available under www.smoovops.com/en/avv.

This privacy policy primarily describes the processing for which we act as controller (Section 1). Details on data processing on your behalf are governed by the DPA.

1.3 Overview of key processing activities

PurposeDataLegal basis
Providing the websiteServer log data (IP address, browser type, timestamp)Art. 6(1)(f) GDPR
Account creation & contract performanceName, email, company details, billing dataArt. 6(1)(b) GDPR
Contact form / support requestsName, email, message contentArt. 6(1)(a) or (f) GDPR
Newsletter (if subscribed)Email addressArt. 6(1)(a) GDPR
Payment processingPayment data (via payment provider)Art. 6(1)(b) GDPR
Non-essential cookies/tracking (if used)Usage dataConsent, Sec. 25(1) TTDSG in conjunction with Art. 6(1)(a) GDPR

2. Hosting and technical infrastructure

SmoovOps runs on Amazon Web Services (AWS) infrastructure. Both the backend infrastructure (including AWS Lambda and DynamoDB) and the static frontend files (hosted via Amazon S3) are located in the AWS data center eu-central-1 (Frankfurt).

To deliver the website, we additionally use Amazon CloudFront (a content delivery network) and AWS WAF (a web application firewall) for protection against attacks. CloudFront is a global service with delivery locations ("edge locations") distributed worldwide. We have technically restricted delivery to locations in North America, Europe, and Israel ("Price Class 100") and additionally restricted access via a geo-restriction to visitors from the EU/EEA. However, exclusive delivery from locations within the EU/EEA cannot be technically guaranteed, since CloudFront automatically routes requests to the nearest available location from a network perspective.

Since Amazon Web Services, Inc. is a US-based company, use of CloudFront (and potentially other AWS services) may involve a transfer of data to a third country within the meaning of Art. 44 et seq. GDPR. AWS is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023); in addition, the AWS Data Processing Agreement includes the EU Standard Contractual Clauses as a fallback mechanism should that adequacy decision be invalidated in the future.

3. Data collected when visiting our website

3.1 Server log files

When you access our website, our provider automatically collects and stores information in server log files that your browser automatically transmits to us:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Host name of the accessing device
  • Time of the server request
  • IP address

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technically error-free and secure provision of the website). This data is not combined with other data sources.

3.2 Cookies and similar technologies

Technically necessary cookies or comparable storage methods (e.g. to maintain your login session) are used on the basis of Sec. 25(2) No. 2 TTDSG in conjunction with Art. 6(1)(f) GDPR.

For SmoovOps only essential cookies or comparable storage methods are used.

For storing user interface settings, localStorage is used.

To provide SmoovOps' offline capability, IndexedDB is used.

4. Contacting us

If you contact us via the contact form or by email, we store the data you provide (including name, email address, and message content) to process your request and any follow-up questions.

The legal basis for pre-contractual inquiries is Art. 6(1)(b) GDPR; otherwise it is your consent under Art. 6(1)(a) GDPR or our legitimate interest in responding to inquiries under Art. 6(1)(f) GDPR. Data is deleted once it is no longer required for processing, at the latest after 2 years, unless statutory retention obligations require otherwise.

5. Registration and use of the SmoovOps account

5.1 Account creation

Using SmoovOps requires registering a user account. In doing so, we collect:

  • Name and email address of the registering person
  • Company details (company name, address, VAT ID if applicable)
  • Chosen password (stored encrypted)
  • Details of the selected plan (free tier up to €25/month usage value, or paid plans)

The legal basis is Art. 6(1)(b) GDPR (performance or initiation of the usage agreement).

5.2 Use of the SmoovOps modules

In the course of using the application, we process — on behalf of and under the instructions of our customers (see Section 1.2) — the following categories of data that you yourself enter into SmoovOps:

  • Partners/CRM: contact details of your business partners and customers
  • Product Catalogue: product and service descriptions you enter
  • Contracts: contract documents and data you upload or create
  • Documents: documents you upload or create (including invoices, offers, delivery notes, letters, and receipts), including information required under GoBD and the XRechnung/ZUGFeRD e-invoicing standards where applicable, and data automatically extracted from them
  • Notes: notes and comments you record relating to partners, contracts, payments, and products
  • Payments: data on incoming/outgoing payments related to your invoices
  • Dashboard: aggregated analyses derived from the above data

This data is used exclusively to provide the respective feature and is not analyzed by Northwood UG for its own purposes, except where necessary to operate the service itself (e.g. troubleshooting) or required by law.

5.3 Import/export

SmoovOps supports importing and exporting your data in common formats (CSV, Excel, ODS). Files created via export are your own responsibility; please handle exported files with the same care as the original data within SmoovOps.

6. Payment processing

We offer payment via the payment provider Stripe. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland (or its affiliate Stripe, Inc., USA). The legal basis is Art. 6(1)(b) GDPR. For details on the safeguards applicable to processing by the US affiliate, see Section 9.

7. Newsletter

If you subscribe to our newsletter, we use your email address exclusively to send the requested information via AWS SES. The legal basis is your consent under Art. 6(1)(a) GDPR. You may unsubscribe at any time via the unsubscribe link in the newsletter or by an informal message to ···.

8. Recipients of data and processors

We generally do not share data with third parties unless this is necessary for contract performance or required by law. We currently use the following categories of processors/recipients:

  • Hosting/infrastructure: Amazon Web Services (AWS) in the region eu-central-1 / Frankfurt a.M. and us-east-1 / Northern Virginia
  • Payment processing: Stripe
  • Email delivery (transactional emails): AWS SES
  • Support/ticketing system: via E-Mail using 1blu

Data Processing Agreements under Art. 28 GDPR are in place with all listed providers that process personal data on our behalf.

Content delivery / attack protection: Amazon CloudFront, AWS WAF (Amazon Web Services, Inc., USA / AWS EMEA entities — delivery restricted to locations in Europe, North America, and Israel per price class configuration, with an additional geo-restriction limiting access to EU/EEA visitors)

9. International data transfers

In connection with the providers listed in Section 8, personal data may be transferred to third countries outside the EU/EEA within the meaning of Art. 44 et seq. GDPR:

  • Amazon Web Services (CloudFront, WAF): As described in Section 2, Amazon Web Services, Inc. is a US-based company. AWS is certified under the EU-US Data Privacy Framework; the EU Standard Contractual Clauses additionally apply as a fallback mechanism. The AWS WAF WebACL used to protect our CloudFront distribution is managed in the us-east-1 (Northern Virginia) region for technical reasons (AWS's API only allows CloudFront-scope WAF rules to be created there); this only processes request metadata for attack detection, not the content data of your SmoovOps account.
  • Stripe: For payment processing we work with Stripe Payments Europe, Ltd. (Ireland). As part of intra-group processing, data may be accessed by the affiliated US entity Stripe, Inc. Here too we rely on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR as the transfer safeguard.

All other processors listed in Section 8 process data exclusively within the EU/EEA.

10. Retention period

We generally store personal data only as long as necessary for the respective purpose:

  • Account data: until your account is deleted or the business relationship ends, then deleted unless statutory retention obligations apply
  • Invoice and accounting data: in accordance with statutory retention periods under Sec. 147 of the German Fiscal Code (AO) and Sec. 257 of the German Commercial Code (HGB) (generally 10 years for records subject to retention obligations)
  • Server log data: 30 days
  • Support/contact inquiries: 30 days

11. Your rights as a data subject

Under the GDPR, you have the following rights where the respective legal requirements are met:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of consent given, with future effect (Art. 7(3) GDPR)

To exercise these rights, please contact: ···

12. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data. The competent authority is generally the one for the German federal state in which we are based:

Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) Alt-Moabit 59-61
10555 Berlin

13. Currency and changes to this privacy policy

This privacy policy is currently in effect. As SmoovOps evolves (e.g. new features, new payment providers, AI features), it may become necessary to update this policy. The version available at the time of your visit applies.


Last updated: 29.07.2026