Privacy Policy

The German version is authoritative. Regiofy is operated from Germany and reviewed under German law. Where the two texts differ, the German version prevails.

1. Controller

Minoka GbR, represented by its partners Aladin Bisevac and Sercan Kahraman c/o Postflex #10006, Emsdettener Str. 10, 48268 Greven, Germany Email: impressum@minoka.de

We have not appointed a data protection officer; the conditions of section 38 of the German Federal Data Protection Act (BDSG) do not apply to us. For any data protection question you can reach us at hello@regiofy.ai.

2. Where the data is held

Regiofy runs on a server in Falkenstein, Germany (Hetzner Online GmbH). The database, the files and the backups are held there. For individual tasks — such as retrieving reviews, AI analysis, sending emails and payment — we pass data to further services, each named in section 8; some of them are located outside the European Union.

3. When you visit the website

Visiting the site involves processing technically necessary data: IP address, date and time, the address requested, the volume of data transferred, and the browser type. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in secure operation. The same applies when a public review page, or a review widget on a third-party website, is loaded from our server.

Requests are not written to an access log.

The server's system logs, which may contain an IP address — for instance on errors or refused connections — are deleted after 14 days at the latest.

4. Cookies

Regiofy only sets cookies that are necessary for operation: the language you chose, your session once you are signed in (it expires no later than 30 days after you last used it), in the customer area the "sidebar-collapsed" cookie, which remembers for a year whether you collapsed the sidebar, and on regiofy.ai the "consent" cookie, which keeps your choice about audience measurement for six months so that we do not ask you again on every visit. Necessary cookies do not require consent (§ 25(2) no. 2 TDDDG). We do not use marketing tools, and the audience measurement described below sets no cookies. Only if you load the map on a public review page may Google set its own cookies (section 11).

Audience measurement on regiofy.ai

On the website regiofy.ai we count page views using Matomo, to learn which content is read — only if you choose "Accept" in the notice on your first visit. Without your consent, your browser does not load the counting script. We do not count anything under app.regiofy.ai — neither in the customer area nor on the public review pages. Matomo runs on our own server in Germany; the data is not passed on to anyone. Your browser loads the counting script from regiofy.ai/z/zeichen.js, and the count is sent to regiofy.ai/z/zeichen.

What is transmitted: the page requested, the page you came from, the time on your device, how long the page took to load, and clicks on links to other websites or on downloads. From the details your browser sends with every request anyway, Matomo derives the browser, operating system and language. Your IP address is shortened by two bytes before it is stored; from the shortened address Matomo derives a rough location, such as the country. To group the page views of one visit, Matomo computes a checksum from IP address and browser details on our server.

Matomo places no identifier on your device: no cookies, no local storage; only your choice is stored, in the "consent" cookie (section 4). The script does not query screen size, extensions, or the more detailed device information a browser supplies on request. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).

We delete the individual page views after 25 months at the latest (750 days are configured), so that periods more than a year apart can still be compared; after that only totals remain, such as views per page and day, with no link to an individual visit.

You can withdraw your consent at any time with effect for the future: via "Change consent" at the bottom of every page of the website. If your browser sends the "Do Not Track" signal, we do not count your visit even with your consent.

5. Account and contract data

For a user account we process your name, email address, your password only as an irreversible hash, your membership of an organisation, the language you chose and, if you upload one, a profile picture. If you set up a passkey, we store its public key and details about the device; if you switch on two-factor sign-in, we store the secret for it and the backup codes. For every sign-in session we store the IP address and browser identifier, so that a session can be identified and ended. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

For support and troubleshooting, we as the operator can view Regiofy as an account sees it. The legal basis for this is Art. 6(1)(f) GDPR: our legitimate interest in finding errors and answering questions.

If you sign in with your Google account, Google gives us your name, email address and profile picture, as well as the sign-in tokens Google issues for this; in the process Google learns that you are signing in to Regiofy. Google acts under its own responsibility, for users in the European Economic Area Google Ireland Limited. Signing in with Google is optional; an account with email address and password works just as well. You can delete your account and your organisation yourself at any time, the organisation after the trial or contract has ended on the page for choosing a plan; deleting an organisation deletes its locations, reviews and profile reports with it. On request to hello@regiofy.ai we delete it as well. Deleting your account alone does not delete the organisation; if it has no members left afterwards, its subscription ends at the end of the paid period.

6. Contact form and enquiries in the app

Details submitted through the contact form on the website — name, email address, message and optionally the topic — are stored as an enquiry so that we can answer it. If you write to us from within the app, we store your message and the category you chose (question, bug, billing, wish), together with your account's name and email address, the organisation and its plan at the time of the enquiry, the page of the app you wrote from, and the location if that page belongs to one. In both cases the language you were using the site in is stored as well. From within the app you can attach up to three screenshots to a message; we store them re-encoded, without their metadata (such as where a picture was taken), on our server and delete them together with the enquiry.

For every enquiry we store the history: your messages, our replies, the processing status and internal notes. We send our reply by email to the address given (section 8); for enquiries from the app it also appears in the app. We notify ourselves about a new enquiry by email with the number, the origin (website or app), the category, the plan and a link into our administration — never the text of your message. If you reply to us by email, what section 12 says about emails applies to that message.

If you wrote to us through the contact form, our reply email contains a personal link. The page it opens shows the history of your enquiry, and you can reply there; anyone who knows the link can read along and reply in your name. Of the link itself we store only a one-way value that cannot be traced back to it, and every new reply from us brings a new link that replaces the old one.

To limit abuse we count how many enquiries arrive within an hour from the same IP address, the same email address and the same account. The IP address is counted only as a one-way value that cannot be traced back, held in the web service's memory; the address itself is not stored for this.

The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns or aims at a contract, otherwise Art. 6(1)(f) (answering enquiries, protecting the form against abuse).

If you delete your account or your organisation, an enquiry remains until the period named in section 12 ends — with no link to the account, organisation or location, but with the name, email address, message and any attached screenshots.

If you do not reply to our response within 14 days, the enquiry counts as dealt with. Only a reply in the app or through the link in our reply email counts for this; a reply by email reaches our mailbox and does not stop the period. Enquiries are deleted six months after they have been dealt with.

7. Payment processing via Stripe

You pay for the Local and Branches plans online through the payment service Stripe. Our contracting party at Stripe is Stripe Payments Europe, Limited (Ireland).

When you book a plan, we redirect you to a Stripe payment page. We pass on your email address, the plan you chose and internal identifiers of your organisation. Whatever Stripe asks for on its payment page — payment details such as card number or bank account, your name and, depending on the payment method, your address — you enter directly with Stripe; it never reaches our servers. We load no Stripe scripts on our own pages. Stripe tells us which plan has been paid for and manages your subscription; for this we store your Stripe customer and subscription numbers. As the organisation's owner you reach invoices, payment methods and cancellation under billing in the settings, which opens your customer account at Stripe.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract); where we are obliged to retain invoices, Art. 6(1)(c) GDPR.

Stripe processes the data partly on our behalf and partly under its own responsibility, for instance to prevent fraud and to meet its own legal obligations. For this purpose Stripe also records your IP address and details about your device and browser on its payment page. Stripe may transfer data to Stripe, LLC in the USA, which is certified under the EU-US Data Privacy Framework (section 8). Stripe describes how it handles data at https://stripe.com/privacy.

If you choose a payment method from another provider on the payment page, such as PayPal, Klarna, Amazon Pay or Google Pay, that provider receives the payment details it needs and processes them under its own responsibility, in accordance with its privacy notice.

8. Recipients and processors

These services receive data from us (as at 26 September 2026):

ServicePurposeLocationWhat is transmitted
Hetzner Online GmbHserver, database, files, backupsGermanyall application data
DataForSEO OÜretrieval of public reviews, search positions and business listingsEstoniaplace identifier, category and coordinates of a business or an area, search terms. No data about our users.
OpenRouter, Inc.AI analysis and text generationUSAreview texts and the businesses' replies to them, without author names; details about the business (section 9); for the profile report the name, rating and number of reviews of neighbouring businesses (section 11)
Googlesign-in with Google, if you choose it; business data (Places API); in the customer area the map preview when creating a location and photos from reviews; on review pages images from posts, if the customer displays themIreland, transfer to the USAon sign-in your name, email address and profile picture (section 5); search text and place identifier of a business; when the map preview and images load, your IP address
Stripe Payments Europe, Limitedpayment processingIreland, transfer to the USAemail address, chosen plan, internal identifiers of your organisation; whatever you enter with Stripe (section 7)
Lettermint B.V., Zwollesending the emails Regiofy issues: address confirmation, password reset, sign-in link, invitation to an organisation, our replies to enquiries, notifications about poor reviews to a customer's users, notices to ourselvesNetherlands, processing within the European Economic Area under the agreementrecipient's email address and name and the content of the message; for replies to enquiries our reply, including the personal link for enquiries made through the contact form; for notifications about reviews the author's name, star rating and the review text or its beginning. Notices to ourselves contain no text of an enquiry (section 6)
ALL-INKL.COM – Neue Medien Münnich, Friedersdorfmailboxes under @regiofy.aiGermanyemails sent to us or answered by us

In the customer area your browser loads photos from reviews directly from the platform the review is on, including Tripadvisor; the platform receives your IP address in the process.

Data processing agreements under Art. 28 GDPR are in place with every service on this list except Google: with Hetzner and ALL-INKL concluded in the respective customer account, with DataForSEO, OpenRouter, Stripe and Lettermint as part of their contract terms. Google acts under its own responsibility, for users in the European Economic Area Google Ireland Limited; on the map on the public review page see section 11.

Transfers to the USA. On 10 July 2023 the European Commission found that companies certified under the EU-US Data Privacy Framework ensure an adequate level of protection (Art. 45 GDPR). Google LLC and Stripe, LLC are certified (checked on 22 September 2026 at https://www.dataprivacyframework.gov/list). OpenRouter, Inc. is not certified; with OpenRouter the European Commission's standard contractual clauses apply, which form part of its data processing agreement (Art. 46(2)(c) GDPR).

9. AI analysis via OpenRouter

For the AI features — recognising the sentiment and topics of a review, generating suggested replies, posts and descriptions, answers to questions on the Google profile, profile analyses — we send texts to OpenRouter, Inc. in the USA. OpenRouter forwards them to a provider of the AI model in use and returns its answer to us.

What is transmitted: the text and star rating of a review, the business's reply to it, the text of a question from the Google profile, details about the business (such as name, category, address, opening hours), for the profile report also the name, rating and number of reviews of the businesses around it (section 11), and the instructions a customer gives for a text. We do not transmit authors' names: the greeting in a suggested reply is added on our own server, and where the name appears in the business's reply or as a signature in the review, we replace it with a placeholder beforehand. The text of a review may nonetheless contain information about people, for instance where someone is described in it or named by another name. Data about our users — name, email address — does not go to OpenRouter.

The legal basis is Art. 6(1)(f) GDPR: our customers' and our own legitimate interest in analysing and answering reviews. For texts a customer commissions, it is Art. 6(1)(b) GDPR.

OpenRouter is our processor (section 8). OpenRouter only stores requests and responses if the customer switches this on in their account; we have not switched it on. OpenRouter chooses which provider behind it handles a request; we do not specify it. These providers may store requests under their own rules; OpenRouter lists them per provider at https://openrouter.ai/docs/guides/privacy/provider-logging. OpenRouter offers processing within the EU only on its Enterprise plan, which we do not use.

10. Error logging

Error reports from the website, the customer area, the public review pages and the review widget, and errors on our server, go to a self-hosted GlitchTip instance on the same server in Germany. An error is recorded when it occurs. Technical details go with it so that it can be traced: browser, operating system, the address requested and the last steps before it, such as pages visited, clicks on controls and requests to our server. We make no session recordings. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in error-free operation. Error reports are deleted after 90 days.

11. Reviews from public sources

This section is addressed to everyone who has reviewed a business on Google, Tripadvisor or Trustpilot (Art. 14 GDPR).

What we process and where it comes from. For every business a customer sets up in Regiofy, we retrieve via DataForSEO OÜ (Estonia) the public reviews from the platforms the customer connects for that business — on Google the most recent, up to 4,490: the name and profile picture under which the review was published, the link to the profile and public details from it (such as the number of reviews, and on Tripadvisor also home town and type of visit), star rating, text, date, attached pictures and the business's reply.

We likewise retrieve public questions from a business's Google profile, with the name under which they were asked; for a suggested answer only the text of the question goes to OpenRouter. For a conversation with a business that is not yet a customer, we also retrieve its public Google reviews and store the rating, date and text of individual reviews without names, for as long as the business is on our list (below, "Businesses we approach as potential customers").

What for. The customer sees the reviews of their business in one place, gets them analysed and can reply to them. For this the texts are analysed by AI without names (section 9). For a poor review, Regiofy notifies the customer's users in the app and, depending on the settings, by email, with the author's name, the star rating and the text or its beginning. If the customer switches on a public review page or embeds a widget on their website, we show there the most recent reviews above a minimum number of stars (four by default), with name, link to the profile, profile picture, star rating, text and date — as they appear on the platform. The profile pictures are served by our own server, so visitors load nothing from the review platforms for them. Images the customer embeds themselves — posts from their Google profile, or a logo via a web address — are loaded by the browser from there.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in a business being entitled to know and show what is publicly written about it, and to reply. The reviews were published by their authors themselves, and we only show them in connection with the business they concern.

How long. The reviews remain stored for as long as the location exists in the customer's account. If the customer disconnects a platform or deletes the location, the reviews are deleted, and with them the notifications about them in the app. Regiofy does not automatically remove a review you delete on the platform; write to us and we will delete it on our side as well and block it, as after an objection (contact and block below).

Objection. You can object to the processing of your review at any time (Art. 21 GDPR), by email to hello@regiofy.ai or through the contact form at https://regiofy.ai/en/contact, ideally with a link to the review. We will then remove it from Regiofy, including from the public review page, the widget and the notifications in the app, and block it so that a later sync does not pick it up again. The legal basis for the block is our legitimate interest in respecting your objection or request in later syncs as well (Art. 6(1)(f) GDPR). A notification that has already gone by email to one of the customer's users is in that user's mailbox; that is beyond our reach.

We do not notify authors individually: we have no contact details for them, only the name under which they published. This policy is therefore publicly available (Art. 14(5)(b) GDPR).

Map. A public review page may show a Google Maps map. It only loads when you click it; the notice on the map states beforehand that Google receives your IP address in the process. By clicking you give your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Google then processes the data under its own responsibility — for users in the European Economic Area, Google Ireland Limited — may set cookies and may transfer data to Google LLC in the USA (section 8). Details: https://policies.google.com/privacy. The consent applies to that one page view; on your next visit the map again only loads after a click.

Reviews containing special categories of data

A review may contain information that Art. 9 GDPR protects specifically — most likely health data, where the business being reviewed is a medical or dental practice, a pharmacy or a physiotherapist. Anyone who writes about how their treatment went is making a statement about their own health.

We do not ask for such information and we do not look for it specifically. It reaches us solely because the person who wrote it made it public themselves on Google, Tripadvisor or Trustpilot; that is what the processing rests on (Art. 9(2)(e) GDPR). It is processed like any other review: display in the customer area, display on the public review page if the business wants one, and analysis by the AI (section 9). The text and the star rating go to OpenRouter, Inc. in the United States; the name of the person who wrote the review does not.

If you would rather we did not, write to hello@regiofy.ai. We will then remove the review from our records, together with the notifications about it, and block it permanently, so that a later sync does not pick it up again. The copy on the platform itself can only be deleted by you, there — it is beyond our reach.

Businesses we approach as potential customers

This part is addressed to the owners of businesses (Art. 14 GDPR).

To introduce Regiofy to businesses, we search via DataForSEO OÜ for public listings of businesses in an area and category. From a listing we take, for instance, the name, address, telephone number, website, category, rating, number of reviews and whether the Google profile has been claimed. For the businesses we want to approach, we keep a list with the status of our approach and notes from the conversation. For a conversation we may retrieve a business's public Google reviews and build an overview from them: rating, distribution, reply rate and individual review texts, without the authors' names. We keep the results of a search for 30 days so that the same search is not retrieved again; after that we delete them.

If you run the business as an individual, this is personal data. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in presenting our offer to businesses it suits (Recital 47). We delete an entry on a list once the approach is concluded and we no longer need it, and immediately if you object. You may object to this advertising at any time (Art. 21(2) GDPR), by email to hello@regiofy.ai. After your objection we also delete the business from the saved search results and from our customers' profile reports (below) and put it on a block list so that no later search and no later report picks it up again. About the business, the list holds only its Google identifiers with the date and reason of the entry, no name, no address, no notes. The legal basis for this is our legitimate interest in respecting your objection in later searches and reports as well (Art. 6(1)(f) GDPR).

Businesses near a customer

This part is addressed to the owners of businesses (Art. 14 GDPR).

For a customer's profile report we search via DataForSEO OÜ for the public Google Maps listings of businesses in the same or a related category near the customer's business. From up to ten listings we take the name, address, category, rating, number of reviews, number of photos, whether the Google profile has been claimed, the position in the search and the listing's Google identifiers. From this we calculate where the customer's business stands compared with its surroundings, and we name those businesses in the report with their name, rating and number of reviews, and where names are identical, also with street and house number. We do not retrieve the review texts of those businesses for this. Name, rating and number of reviews also go to OpenRouter for the assessment in the report (section 9).

From the customer's Google profile we also store, at the location and in every profile report, the list of businesses people often search for alongside it, with name and Google identifiers. The customer can show these names on their public review page.

If you run the business as an individual, this is personal data. The legal basis is Art. 6(1)(f) GDPR: our customer's legitimate interest in comparing their business with the businesses around it, just as anyone can see for themselves in the map search. The details from the map search stay stored with the report for as long as the report exists (section 12). Both the details from the map search and the "often searched together" list are also held in the run data of our background jobs while we work on a report or on location data; we delete them there no later than 14 days after the job has finished. We do not notify these businesses individually, as we do not contact them; this notice is therefore publicly available (Art. 14(5)(b) GDPR).

You may object to this processing (Art. 21 GDPR) by email to hello@regiofy.ai. We then remove your business from the stored reports, including the texts and PDF files in them, and from our customers' "often searched together" lists. We also add it to the same block list as in the customer search so that no later report includes it again; the list holds only its Google identifiers with the date and reason. A report that a customer has already downloaded is beyond our reach.

12. Retention

  • User account: until the account is deleted, including beyond the end of a contract.
  • Locations and reviews: for as long as the location exists in the account. If a customer disconnects a platform, that platform's reviews are deleted.
  • Notifications in the app about a review: for as long as the review exists.
  • Review block list: the platform and identifier of a review we have blocked following an objection or at your request, with the date and a note on the reason; permanently.
  • Customer-search results: 30 days after retrieval; a result for a business that has objected, immediately.
  • Customer-search lists: until the approach is concluded; immediately upon objection.
  • Customer-search block list (also applies to the surroundings in the profile report): for as long as we approach businesses through the customer search or produce profile reports with surroundings.
  • Businesses near a customer in the profile report: for as long as the report exists; reports are deleted together with the organisation (section 5). The "often searched together" list: at the location for as long as the location exists; as part of a report for as long as the report exists. Immediately upon objection.
  • Run data of background jobs: 14 days at most after a job has finished.
  • Session: no later than 30 days after last use; the record with IP address and browser identifier is deleted no later than one day after it expires.
  • Enquiries (contact form and app): six months after they have been dealt with, including attached screenshots.
  • Audience measurement: individual page views 25 months at most (750 days are configured), totals only after that.
  • Server system logs: 14 days at most.
  • Error reports: 90 days.
  • Backups: daily backups for seven days, weekly backups for four weeks. Deleted data therefore disappears from the backups after around four weeks at the latest.
  • Emails in our mailboxes: for as long as we need them to deal with the matter; emails that prepare or conclude a business transaction, for the statutory periods (§ 147 AO, § 257 HGB).
  • Invoices: for the statutory retention periods (§ 147 AO, § 257 HGB).

13. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and data portability (Art. 20 GDPR). You may withdraw any consent you have given at any time with effect for the future.

To exercise these rights, contact: hello@regiofy.ai

You also have the right to lodge a complaint with a supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.

Right to object

Where we process data on the basis of Art. 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. Send your objection to hello@regiofy.ai. Audience measurement is based on your consent, which you withdraw via "Change consent" at the bottom of every page of the website (section 4).

No automated decisions about individuals

Regiofy analyses reviews automatically: it produces sentiment ratings, scores for a business profile and suggested replies (section 9). These analyses relate to businesses, not to the people who wrote the reviews, and they are suggestions — what a business does with them is decided by a person. There is no automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning anyone or similarly significantly affects them.

14. Status

Version of 26 September 2026