x70
Legal

Privacy Policy

Last updated: 2026-07-18. This Privacy Policy explains how Daniel Ensminger, trading as x70 (“we”, “us”, “our”), processes personal data when you use https://x70.one, https://app.x70.one, and related services, in line with the EU General Data Protection Regulation (GDPR) and applicable German data protection law (BDSG).

1. Controller

The controller responsible for processing is:

Daniel Ensminger
x70

Altheimer Eck 15
80331 München
Germany
Email: contact@x70.one

See also our Imprint (Impressum).

2. Categories of personal data

Depending on how you interact with us, we may process:

  • Contact & lead data: name, email address, phone number, business name, website URL, message content, and related inquiry details submitted via contact or proposal request forms.
  • Newsletter data: email address and subscription status if you opt in.
  • Account & portal data: name, email, password hash or passkey credentials, organization membership, role, session and device information, change requests, and billing metadata when you use the client portal.
  • Payment data: billing email, customer ID, and subscription/invoice status processed by our payment provider (Stripe). We do not store full card numbers on our servers.
  • Technical data: IP address, browser type, device information, pages visited, referrer, and approximate location derived from IP, when analytics or security tooling is active.
  • Communications: emails and support messages exchanged with us.

3. Purposes and legal bases

We process personal data for the following purposes:

  • Responding to inquiries and providing proposals (Art. 6(1)(b) GDPR — steps prior to a contract; Art. 6(1)(f) — legitimate interest in answering business inquiries).
  • Performing contracts for website design, setup, hosting, and portal access (Art. 6(1)(b) GDPR).
  • Processing payments and subscriptions via Stripe (Art. 6(1)(b) GDPR; Art. 6(1)(c) where required for tax/accounting).
  • Sending newsletters only with your consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
  • Security, abuse prevention, and rate limiting (Art. 6(1)(f) GDPR — legitimate interest in protecting our services).
  • Analytics and product improvement (PostHog, Vercel Analytics) only after you consent via our cookie banner (Art. 6(1)(a) GDPR). Session recording, where enabled, masks form inputs.
  • Legal obligations such as bookkeeping and responding to lawful requests (Art. 6(1)(c) GDPR).

4. Cookies and similar technologies

We use strictly necessary cookies and local storage for security, authentication, and remembering your cookie preferences. Optional analytics cookies and similar technologies (including PostHog and Vercel Analytics) are used only if you click “Accept all” on our consent banner. You can change your choice at any time via “Cookie settings” in the site footer.

Theme preference may be stored locally on your device and is not used for tracking.

5. Recipients and processors

We use carefully selected service providers who process data on our behalf under Art. 28 GDPR agreements where applicable:

  • Vercel Inc. — website hosting and edge delivery
  • Convex, Inc. — application database and authentication backend for the client portal
  • Stripe, Inc. / Stripe Payments Europe, Ltd. — payments and subscriptions
  • Resend, Inc. — transactional and newsletter email
  • PostHog, Inc. — product analytics (consent-based)
  • Upstash, Inc. — rate limiting / Redis where configured

We do not sell your personal data. We share data only with processors needed to operate the service, or where required by law.

6. International transfers

Some providers are based in the United States or other countries outside the EEA. Where transfers occur, we rely on appropriate safeguards such as the EU–US Data Privacy Framework (where the provider is certified) and/or Standard Contractual Clauses (SCCs), plus supplementary measures as required.

7. Retention

  • Contact / lead inquiries: typically up to 24 months after the last meaningful contact, unless a contract is formed or longer retention is required.
  • Newsletter: until you unsubscribe or we delete the list entry.
  • Customer / portal accounts: for the duration of the contract and thereafter as required for legal claims, accounting, and tax (generally up to 10 years under German commercial and tax law where applicable).
  • Analytics data: according to the configured retention in the analytics tools, and only while consent remains valid.
  • Server logs / security: for short periods needed for security and troubleshooting, unless a longer period is needed to investigate an incident.

8. Your rights

Under the GDPR you may have the right to:

  • Access your personal data (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time without affecting the lawfulness of processing before withdrawal (Art. 7(3))
  • Lodge a complaint with a supervisory authority (Art. 77), in particular Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), or the authority where you live or work

To exercise these rights, email contact@x70.one.

9. No automated decision-making

We do not use personal data for automated decision-making producing legal or similarly significant effects under Art. 22 GDPR.

10. Children

Our services are directed at businesses and adults. We do not knowingly collect personal data from children under 16.

11. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be communicated via the website or email where appropriate.

12. Contact

Questions about privacy: contact@x70.one. Related documents: Terms of Service and Imprint.

Join 2,000 other businesses and creators getting our insights.

+8.7K

By subscribing you consent to email updates. You can unsubscribe anytime. See our Privacy Policy.