Privacy Policy

1. Data Controller

Bernstein Holding UG (haftungsbeschränkt)
Eschenlohmühle 2
86862 Lamerdingen, Germany
Email: help@thememo.am

2. Overview

The Memo processes personal data only where necessary to provide the subscription, deliver the daily briefing, operate the website securely, process payments, respond to inquiries, and protect the product from unauthorised redistribution.

3. Data Collection

The following personal data may be processed:

4. Legal Basis

Processing is based on Art. 6(1)(b) GDPR where it is necessary to provide the subscription service, Art. 6(1)(c) GDPR where we must comply with legal obligations such as tax and accounting retention rules, and Art. 6(1)(f) GDPR where we have a legitimate interest in operating a secure, reliable, and high-quality service.

Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

5. Payment Processing

Payments are handled by Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA) and its sub-processors. When subscribing, you will be redirected to Stripe's checkout page. Stripe's privacy policy applies: stripe.com/privacy

6. Subscription and Email Delivery

The Memo is delivered by email to active subscribers. We use your email address for the daily briefing, account-related messages, payment or subscription notices, and essential service communications.

Email delivery is handled via Resend, Inc. and its sub-processors, a US-based email service provider operating under EU Standard Contractual Clauses. Resend's privacy policy applies: resend.com/legal/privacy-policy

If your subscription ends, delivery of the daily briefing will stop. We may retain minimal suppression or account records where necessary to document cancellation, prevent accidental reactivation, comply with legal obligations, or defend legal claims.

7. Contacting Us

If you contact us by email, we process the information you provide in order to respond to your request. This may include your email address, name, message content, and related correspondence. Processing is based on Art. 6(1)(b) GDPR where the request relates to a subscription, and otherwise on Art. 6(1)(f) GDPR.

8. Cookies and Tracking

This website does not use non-essential cookies, advertising cookies, or cross-site tracking technologies. No individual marketing profiles are created.

9. Website Analytics

We use Vercel Web Analytics and Vercel Speed Insights, provided by Vercel Inc. and its sub-processors, to collect anonymous, aggregated usage statistics (page views, referrers, country, device type) and page performance metrics (load times, interaction responsiveness). These services do not use cookies, do not store IP addresses, and do not create individual visitor profiles. Processing is based on Art. 6(1)(f) GDPR (legitimate interest in understanding how our website is used and improving its performance). Vercel's privacy policy applies: vercel.com/legal/privacy-policy

10. Hosting and Server Logs

This website is hosted on servers operated by STRATO AG (Otto-Ostrowski-Straße 7, 10249 Berlin, Germany) and its sub-processors. When accessing the site, technically necessary data may be processed in server log files, including IP address, access time, requested page, browser type, operating system, referrer URL, and request status.

Server logs are processed pursuant to Art. 6(1)(f) GDPR for security, troubleshooting, abuse prevention, and reliable operation of the website. Log data is not used to create visitor profiles.

11. SSL/TLS Encryption

This website uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” address in your browser. Encryption helps protect data transmitted between your browser and our website.

12. Cloudflare

We use Cloudflare services provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) and its sub-processors for security, performance optimisation, DNS, and content delivery. For this purpose, technically necessary connection data such as IP address, request metadata, browser information, and security events may be processed. Processing is based on Art. 6(1)(f) GDPR (legitimate interest in providing a secure, reliable, and performant website). Cloudflare's privacy policy applies: cloudflare.com/privacypolicy

13. PDF Watermarking

Each briefing PDF is individually watermarked with a subscriber-specific identifier derived from your email address. This is necessary to protect our intellectual property and enforce our Terms of Service. Processing is based on Art. 6(1)(f) GDPR (legitimate interest in preventing unauthorised redistribution).

14. Data Sharing

Personal data is shared only where necessary to provide the service, operate the website, process payments, comply with legal obligations, protect our rights, or work with carefully selected service providers.

Where required under Art. 28 GDPR, we have concluded data processing agreements with our processors.

15. International Data Transfers

Through the use of Stripe, Resend, Vercel, and Cloudflare, data may be transferred to the United States. Stripe is certified under the EU-US Data Privacy Framework. Resend, Vercel, and Cloudflare operate under EU Standard Contractual Clauses for data transfers.

16. Data Retention

Unless a more specific retention period applies, personal data is stored only for as long as necessary for the purpose for which it was collected, or as required by law.

Subscription data is stored for the duration of the subscription. After cancellation, your email address and name will be deleted within 30 days unless statutory retention periods, documentation obligations, suppression requirements, or legal claims require longer storage.

Invoice data is retained for 10 years in accordance with German tax law (§ 147 AO, § 257 HGB).

17. Your Rights

You have the right to:

To exercise your rights, please contact: help@thememo.am

18. Right to Object

You may object at any time to processing based on Art. 6(1)(f) GDPR for reasons arising from your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds or the processing is necessary for the establishment, exercise, or defence of legal claims.

If personal data is processed for direct marketing, you may object at any time. In that case, your data will no longer be processed for direct marketing purposes.

19. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach, Germany
www.lda.bayern.de

20. Changes

We reserve the right to update this privacy policy as needed. The current version is always available on this page.

Last updated: May 2026

← Back