Skip to main content
Settlio

Privacy Policy

Datenschutzerklärung

Effective date: July 12, 2026 · Last updated: July 12, 2026

01

Controller (Verantwortlicher)

The controller responsible for processing your personal data on this website within the meaning of Art. 4(7) GDPR is:

MindFlow / Nicolas Christof Hilz

Josephsburgstraße 27

81673 München

Germany

Email: support@settlio.de

A data protection officer has not been appointed because the statutory thresholds under § 38 BDSG are not met. You may direct all data-protection queries to the controller at the email above.

02

Scope

This policy applies to the Settlio web application and the website operated by the controller (collectively the “Service”). It does not apply to third-party sites linked from the Service.

03

Categories of personal data processed

(a) Account data

Email address; password (stored only as a salted hash by our authentication provider); session identifiers / JWT.

(b) Profile data you provide

Nationality (ISO country code), visa type, work-permit track, employment mode (employee / freelancer / student), expected annual salary (optional), reduced-threshold-case flag, relocation-strategy choice (pre-entry work visa or post-entry residence permit), planned arrival date in Germany, intended work-start date, target city (Munich, Berlin, Hamburg, Frankfurt, Stuttgart, or Cologne), housing status, and — for students — financial-means type (e.g. blocked account or scholarship). Family details: family-relocation mode, has-children flag, children age bracket, family target arrival date, and Elterngeld (parental-benefit) expectation; plus the accelerated-procedure flag.

(c) Step-progress data

Per-step completion timestamps and user-marked dates (e.g. visa appointment booked, Anmeldung (address registration) completed).

(d) Technical data automatically collected

IP address, user-agent string, request timestamps, and HTTP status codes in server log files, plus the strictly necessary authentication session set by our auth provider in your browser’s local storage. Your IP address and account identifier are also processed transiently to enforce request rate limits (abuse prevention).

(e) Payment data

When you purchase Full Access, payment is taken on a checkout page hosted by our payment provider Stripe, to which you are redirected. You enter your card details directly on Stripe’s page; those details are processed by Stripe and are never received or stored by us. For our records we store a payment reference: your Stripe customer ID, Stripe checkout session ID, payment status (e.g. paid, pending, failed, refunded), the payment timestamp, and whether a Family Add-on was purchased. To issue the invoice required by law, Stripe also provides us with the billing information you enter at checkout — your billing name and billing address — together with the amount paid; from these we generate an invoice that we send to you by email. The invoice is not stored in our application database. The payment methods offered are those shown by Stripe Checkout and may include card, Apple Pay, Google Pay, PayPal, SEPA Direct Debit, iDEAL, Bancontact, and EPS, depending on your country and device. Immediately before payment you confirm the required acknowledgements — that you accept the Terms and this Privacy Policy, and that you expressly request immediate provision of Full Access — and we keep a record that these were given, with a timestamp, as evidence of the contract.

(f) Support correspondence and in-app feedback

When you contact us — for example by email at support@settlio.de, or through the in-app feedback form — the content of your message, your email address, and any details you choose to include. Feedback submitted through the in-app form may also include the page you were on when you submitted it, your visa type, and a reference to the related roadmap step.

We do not collect special categories of personal data within the meaning of Art. 9 GDPR. The Service is directed at adults relocating for work or study; we do not knowingly process data of children under 16.

From the information above, the Service automatically generates your outputs — your personalized relocation roadmap and your readiness and confidence scores.

04

Purposes and legal bases (Art. 6(1) GDPR)

4.1 Account creation, authentication, and provision of the Service

Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures). Without this data we cannot provide the Service; provision is a contractual requirement.

4.2 Optional profile fields (e.g. expected salary)

Used to personalize the recommended steps — Art. 6(1)(a) GDPR (consent). You may decline these fields without losing access to the Service and may withdraw consent at any time with effect for the future.

4.3 Server log files and security/abuse prevention

Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and abuse-free operation of the Service.

4.4 Strictly necessary authentication storage

Art. 6(1)(b) and (f) GDPR. Storage on your end-device is lawful under § 25(2) Nr. 2 TDDDG (formerly TTDSG) without consent, because it is strictly necessary to provide the Service you have expressly requested.

4.5 Compliance with legal obligations

Art. 6(1)(c) GDPR — for example, responding to data-subject requests, and tax / commercial-law retention if and when applicable.

4.6 Processing of payments

Art. 6(1)(b) GDPR (performance of the contract for Full Access). The payment itself, together with fraud prevention and the fulfillment of Stripe’s own legal and regulatory obligations, is carried out by Stripe as described in its privacy policy; for those latter purposes Stripe acts as an independent controller.

4.7 Handling your support requests

Art. 6(1)(b) GDPR where your request concerns your contract or account; otherwise Art. 6(1)(f) GDPR for general enquiries, our legitimate interest being to receive, answer, and document your request.

We do not use your data for marketing automation, advertising, profiling within the meaning of Art. 22 GDPR, or any automated decision-making with legal or similarly significant effects.

05

Recipients and processors (Art. 28 GDPR)

We rely on the following categories of processors, each bound by a written data-processing agreement (Auftragsverarbeitungsvertrag):

(a) Database, authentication, and backend infrastructure

Supabase (Supabase Inc.). The EU region (Frankfurt, eu-central-1) is selected. Supabase acts as our processor for hosting, authentication, error monitoring, and operational communication, and may engage its own sub-processors for those purposes. The current, authoritative list of Supabase sub-processors is published in the Supabase Data Processing Agreement.

(b) Hosting and content delivery of the web application

Vercel Inc. Primary processing facilities are in the United States. Vercel processes the server request data (including IP address, user-agent, and request metadata) needed to serve the application and keep it secure. International transfers take place under the safeguards described in Section 6.

(c) Transactional email delivery

Resend (Resend, Inc., USA). Used to send account and payment-lifecycle emails (welcome, payment confirmation with your invoice attached, unlock confirmation, failed-payment notice). Resend processes the recipient email address, the message content, and the invoice document attached to the payment confirmation.

(d) Payment processing

Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA). When you buy Full Access we redirect you to Stripe’s hosted checkout to take payment. Stripe processes your payment and card data on our behalf as a processor and, for fraud prevention and its own legal and regulatory obligations, as an independent controller. See Stripe’s privacy policy at stripe.com/privacy.

(e) Rate limiting / abuse prevention

Upstash, Inc. (USA). We use an Upstash Redis instance to enforce request rate limits. It transiently processes your IP address and account identifier to detect and block abuse; these entries expire automatically after short time windows.

(f) Internal feedback notifications

When you submit the in-app feedback form, a notification is delivered to our internal support inbox through a configured SMTP email server so we can read and respond to it. That server processes your email address and the content of your feedback (including the page you were on and your visa type). This notification is sent only where such a server is configured, and is separate from the transactional email in (c).

We do not sell or rent personal data. We do not share data with advertisers, analytics providers, or social networks, and there is no cross-site tracking or third-party chat widget on the Service. Apart from the payment provider named above, your data is not shared with any other payment or marketing party.

06

International transfers (Art. 44–49 GDPR)

Wherever possible, we choose EU-based processors and store data within the EEA. Because some of our processors and their authorised sub-processors are based in or operate from the United States, personal data may be transferred outside the EEA. Such transfers take place exclusively on the basis of safeguards permitted by Art. 44 ff. GDPR, in particular:

  • an adequacy decision of the European Commission (e.g. the EU-US Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795, where the recipient is certified); and/or
  • the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller-to-processor) or Module Three (processor-to-processor), as applicable.

You may request a copy of the relevant safeguards by writing to support@settlio.de.

07

Retention periods (Art. 13(2)(a) GDPR)

We retain personal data only as long as necessary for the purposes set out above:

(a) Account and profile data

For the duration of your account; deleted within 30 days after you delete your account, unless longer retention is required to comply with a legal obligation or to defend legal claims.

(b) Step-progress data

Same as account data.

(c) Server log files

IP address, user-agent, timestamp, and status code: deleted after a maximum of 14 days; if retained longer for security investigation, IP addresses are anonymised.

(d) Contract-evidence data

Up to 3 years after termination of the contract (statute of limitations under § 195 BGB).

(e) Statutorily mandated commercial / tax records

If and when applicable to the controller: up to 10 years (§ 147 AO, § 257 HGB).

(f) Support correspondence

Kept only as long as necessary to process your request and any required follow-up, then deleted — subject to the statutory retention obligations in (d) and (e) where applicable.

08

Your rights (Art. 15–22 GDPR)

You have the right to:

  • access your personal data (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure / “to be forgotten” (Art. 17);
  • restriction of processing (Art. 18);
  • data portability for data you have provided on the basis of consent or contract, in a structured, machine-readable format (Art. 20);
  • object to processing based on Art. 6(1)(f) at any time on grounds relating to your particular situation (Art. 21);
  • withdraw any consent you have given, with effect for the future, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
  • not be subject to a decision based solely on automated processing (Art. 22) — we do not engage in such decision-making.

To exercise any of these rights, email support@settlio.de. We will respond within one month (Art. 12(3) GDPR).

You may also delete your account at any time directly from your profile page — this removes your profile, relocation plan, and roadmap progress from our systems.

09

Right to lodge a complaint (Art. 77 GDPR)

Without prejudice to any other administrative or judicial remedy, you may lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. The competent supervisory authority for the controller is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 18, 91522 Ansbach

Telephone: +49 (0) 981 180093-0

Email: poststelle@lda.bayern.de

10

Cookies, local storage, and tracking

We do not load any third-party analytics, tracking, or advertising services. The Service contains no scripts or SDKs from Google Analytics, Google Tag Manager, Meta/Facebook, PostHog, Sentry, Mixpanel, Segment, Amplitude, Hotjar, Datadog, FullStory, HubSpot, Intercom, Drift, Crisp, or comparable providers, and no chat, NPS, or other third-party widgets. We do not embed a payment SDK on our own pages; payment is taken on a separate Stripe-hosted checkout page to which you are redirected (see below).

The backend providers named as processors and sub-processors in Section 5 (for example those used for hosting, database, error monitoring, or operational communication) operate server-side only. They are not analytics, tracking, or advertising scripts, and none of them run as code in your browser or track you across sites.

Fonts (Inter) are bundled at build time via Next.js’ built-in font loader and served from the same origin as the application — your browser does not connect to fonts.googleapis.com or fonts.gstatic.com at runtime.

We do not set our own cookies. The only session mechanism is Supabase Auth, which stores your authentication token in your browser’s local storage (default key sb-<project>-auth-token). This entry is strictly necessary to keep you signed in.

In addition, the Service writes a small number of strictly first-party, functionally necessary local-storage entries: to remember which onboarding prompts, orientation guides, and informational notes you have already dismissed; and to cache your checklist and step-completion progress (your readiness checks) so your ticked items appear instantly and survive a page refresh. The dismissal entries contain no profile data — only timestamps, anonymous signature hashes of your relevant profile fields, or simple yes/no flags. The checklist and readiness cache mirrors the step-progress data we also hold for your account (see Section 3(c)) and is stored under a key specific to your account. None of these entries are transmitted to third parties.

When you proceed to payment, you are redirected to a checkout page hosted by Stripe. On that page Stripe may set cookies and process data under its own domains and privacy policy; this is outside the scope of this Service’s storage and is necessary to process the payment you have requested.

Pursuant to § 25(2) Nr. 2 TDDDG, no consent is required for storage of or access to information on your end-device where this is strictly necessary so that the provider of a telemedia service can provide a telemedia service expressly requested by the user. Because we use only strictly necessary storage and no tracking, we do not display a cookie banner.

11

Provision of data — statutory or contractual requirement

The account data and the minimum required profile fields are necessary to enter into and perform the contract for use of the Service. If you do not provide them, we cannot create an account or generate a relocation plan. Optional profile fields are provided on the basis of consent and are not required.

12

Automated decision-making / profiling

We do not carry out any automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). The Service does generate personalized recommendations and scores — your roadmap, readiness score, and confidence score — automatically from the information you provide, but these are informational only and do not produce legal or similarly significant effects.

13

Security measures

We use industry-standard technical and organizational measures to protect personal data, including HTTPS for all data in transit, salted password hashing handled by our authentication provider, row-level security on the database, and least-privilege access to administrative functions. Card payments are handled entirely by Stripe, a PCI-DSS Level 1 certified provider; we never receive or store your card data. No system can be guaranteed completely secure; we kindly ask users to choose strong, unique passwords and to notify us promptly at support@settlio.de if they suspect any compromise of their account.

14

Changes to this policy

We may update this Privacy Policy to reflect changes in our processing or in the law. The current version is always available at this page. Material changes will be communicated to registered users by email.

15

Contact

For all data-protection questions, contact: support@settlio.de.

Privacy Policy | Settlio