Privacy Policy
Protecting your personal data is important to us. This privacy policy explains which personal data we process when you use Zefaj Finance, for what purposes, and on what legal basis.
Controller
The controller within the meaning of the GDPR is:
Zefaj Immobilien – Owner Nol Zefaj
Asternstr. 10, 71034 Böblingen, Germany
Email: info@zefaj-immobilien.com · Phone: +49 163 1684265
VAT ID: DE342137575
1. General information on data processing & legal bases
We generally process personal data only to the extent necessary to provide a functioning platform, content, and services. Processing is carried out in accordance with the GDPR, the German Federal Data Protection Act (BDSG), and the German Telecommunications and Telemedia Data Protection Act (TDDDG).
Legal bases:
• Consent: Art. 6(1)(a) GDPR.
• Performance of a contract / pre-contractual measures: Art. 6(1)(b) GDPR.
• Legal obligation: Art. 6(1)(c) GDPR.
• Legitimate interest: Art. 6(1)(f) GDPR.
• Storing/reading information (cookies): Section 25 TDDDG.
2. Service providers used
To provide the platform, we use technical service providers, in particular for hosting, database storage, file storage, email delivery, and payment processing. These providers receive personal data only to the extent necessary for the respective service.
This includes, in particular, hosting and infrastructure providers, database providers, email service providers, payment service providers, and, where applicable, tax or legal service providers, insofar as this is necessary for the performance of a contract, billing, or the fulfilment of legal obligations.
3. Provision of the platform and server log files
Each time our platform is accessed, the hosting provider we use (Vercel Inc.) automatically collects information that your browser transmits to the server. Processing takes place on servers within the European Union (location: Frankfurt am Main).
The following data is collected in what are known as server log files:
• IP address of the requesting device
• Date and time of access
• Name and URL of the file / page accessed
• Website from which the access originates (referrer URL)
• Browser type and version used
• Operating system of your device
Legal basis: Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the technical provision, stability, and security of the platform and in investigating and preventing abusive or malicious access (e.g. cyberattacks).
Retention period: For security reasons (e.g. to investigate misuse or fraud), the data is stored for a maximum of 14 days and then automatically deleted or anonymized by truncating the IP address. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.
4. Registration and user account
Using the platform requires setting up a user account. In doing so, we process your email address, your password, your first and last name, and optionally your phone number and a profile picture. Your password is not stored in plain text but is processed exclusively in hashed form and protected by appropriate security procedures.
To log you in and secure your account, we also process session data, in particular the IP address, device type, browser identifier (user agent), and an approximate location derived from the IP address. This data serves to secure your account and detect unauthorized access.
The legal basis is Art. 6(1)(b) GDPR for providing the contractual service, as well as Art. 6(1)(f) GDPR with regard to account security.
5. Entry of real estate and financial data
When using the analysis tools, you can enter real estate and finance-related data, such as property addresses, purchase prices, financing and loan details, rental income, costs, modernization measures, tax assumptions, and self-defined forecast values.
We process this content data to provide you with the platform's calculation, simulation, analysis, and storage features.
The legal basis is Art. 6(1)(b) GDPR. This data is not analyzed for advertising purposes, sold, or passed on to third parties for marketing purposes.
Content data is accessed only insofar as this is necessary for the operation of the platform, troubleshooting, security, support, or the fulfilment of legal obligations.
6. Payment processing (Stripe)
Payments for paid subscriptions are processed via the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland.
When you take out a paid subscription, the data required for payment processing is transmitted to Stripe or collected directly by Stripe. This may include, in particular, name, email address, billing data, payment amount, payment status, chosen payment method, transaction data, and technical information relating to payment processing.
You enter payment details such as full credit card or account data directly with Stripe. We ourselves do not receive complete payment data, but rather, in particular, customer and subscription identifiers, payment status, invoice and transaction information, and information required to manage the subscription.
Processing takes place for the execution and management of paid subscriptions on the basis of Art. 6(1)(b) GDPR. Insofar as we store payment- and invoice-related data on the basis of statutory retention obligations, processing is based on Art. 6(1)(c) GDPR.
Stripe may also process personal data under its own responsibility, in particular for payment processing, fraud prevention, security, fulfilment of legal obligations, and the enforcement of its own rights. Further information on the processing of personal data by Stripe can be found in Stripe's privacy policy at https://stripe.com/privacy.
7. Sending emails (Resend)
To send transactional emails, in particular registration, verification, login, security, password, and contract emails, we use the service Resend (Resend, Inc., USA). In doing so, your email address, technical delivery information, and the respective email content are processed, in particular.
The legal basis is Art. 6(1)(b) GDPR and our legitimate interest in reliable email delivery pursuant to Art. 6(1)(f) GDPR. We do not use this service for promotional newsletters unless separate consent has been given for this.
8. Email security and spam filtering
For receiving and sending emails, we use the services of Hornetsecurity GmbH, Am Listholze 78, 30177 Hannover, Germany. Incoming and outgoing emails are analyzed in order to detect malware and spam.
Processing takes place on the basis of our legitimate interest in a secure IT infrastructure and communication (Art. 6(1)(f) GDPR). We have concluded a data processing agreement (DPA) with the provider.
9. Hosting, database, and storage
Our platform is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA, whereby the website is delivered via European server locations (including Frankfurt am Main). Data is stored in a Postgres database provided by Neon Inc., 2045 Lincoln Hwy, Ste 2110, Edison, NJ 08817, USA, on servers located in Frankfurt am Main (Germany). For file uploads such as profile pictures we use the storage service Vercel Blob (also stored in the EU / Frankfurt am Main).
These providers process personal data exclusively on our behalf on the basis of data processing agreements pursuant to Art. 28 GDPR. As these are providers based in the USA, a transfer of data to a third country takes place. This transfer is legally safeguarded: both providers are certified under the EU-US Data Privacy Framework (DPF), which guarantees an adequate level of data protection. In addition, the European Commission's Standard Contractual Clauses (SCCs) have also been agreed.
The legal basis for the purely technical use of the infrastructure is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, stable, and efficient operation of the platform. Insofar as data is actively transmitted by you when using features (e.g. when uploading a profile picture), the legal basis is Art. 6(1)(b) GDPR (performance of a contract).
10. Contact form
If you contact us via the contact form, we process the data you provide (first name, last name, email address, optionally phone number, and your message) in order to handle and respond to your request.
The legal basis is Art. 6(1)(b) GDPR insofar as the request is aimed at concluding or performing a contract. Otherwise, the legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in effectively responding to and documenting inquiries.
The data you enter in the contact form remains with us until you ask us to delete it or the purpose for storing the data ceases to apply (e.g. after your request has been dealt with). Mandatory statutory provisions – in particular statutory retention periods (e.g. for business correspondence under the German Commercial Code or the German Fiscal Code) – remain unaffected.
11. Cookies
We use exclusively technically necessary cookies (also referred to as “essential cookies”). These are strictly necessary for the operation of the platform, ensuring IT security, and keeping you signed in (e.g. for session management). No consent is required for the use of these cookies.
We do not use any cookies for analytics, tracking, or advertising purposes.
Cookies used and retention period:
• Session cookie (session ID): Used to assign page views to an ongoing browser session and to store the login status. This cookie is automatically deleted as soon as you close your browser (retention period: for the duration of the session).
• Consent cookie (cookie_consent): Stores your decision regarding our cookie notice (acceptance or rejection) so that this notice is not displayed again on future visits (retention period: 12 months / 365 days).
The legal basis for storing information on the user's device is Section 25(2) no. 2 TDDDG, as the cookies are strictly necessary to provide the service expressly requested by you. The subsequent processing of personal data is based on Art. 6(1)(f) GDPR, based on our legitimate interest in a technically error-free, secure, and optimized provision of our platform.
12. Transfer of data to third countries
Some of the service providers we use are based in, or process personal data in, countries outside the European Union (so-called “third countries”), in particular the USA (e.g. Vercel Inc. and Neon Inc., as described in the sections above).
Legal safeguards: Insofar as a transfer of data to third countries takes place, this is done exclusively on the basis of appropriate safeguards pursuant to Art. 44 et seq. GDPR. These include, in particular:
• Adequacy decisions of the European Commission: For the USA, the EU-US Data Privacy Framework (DPF) exists. Insofar as our US providers are certified under this framework, the level of data protection is legally deemed adequate.
• Standard Contractual Clauses of the European Commission (SCCs): With providers that are not certified or where additional safeguards are necessary, we conclude the Standard Contractual Clauses approved by the European Commission pursuant to Art. 46(2)(c) GDPR.
We point out that in the USA, despite these safeguards, there is a risk that government authorities (e.g. intelligence services) may access your data without you, as an EU citizen, being able to take effective legal action against this. We minimize this risk by choosing European server locations, in particular Frankfurt.
13. Retention period and data deletion
As a rule, we process and store personal data only for as long as is necessary to fulfil the respective purposes or as required by statutory retention periods. Once the respective purpose ceases to apply or these periods expire, the corresponding data is routinely deleted or anonymized in accordance with data protection requirements.
• Account and content data: Your account and content data are stored for the duration of the contractual relationship and deleted after it ends, unless statutory obligations require further retention.
• Contact inquiries & cookies: For specific processing activities (e.g. inquiries via the contact form or the use of cookies), the shorter storage and deletion periods stated in the respective sections of this privacy policy apply.
• Business and invoice data: Invoice- and payment-related data as well as business correspondence are subject to statutory retention periods, in particular under Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB). The retention period is generally ten years, whereby the period begins at the end of the calendar year in which the last entry, statement, or conclusion of contract was made.
14. Your rights as a data subject
Under the GDPR, you have the following rights regarding the personal data concerning you:
• Right of access (Art. 15 GDPR): You can request information about the data we process about you.
• Right to rectification (Art. 16 GDPR): You can request the correction of inaccurate data.
• Right to erasure (Art. 17 GDPR): You can request the deletion of your data (“right to be forgotten”).
• Right to restriction of processing (Art. 18 GDPR): You can request the restriction of data processing.
• Right to data portability (Art. 20 GDPR): You can request to receive your data in a structured format.
• Withdrawal of consent: Insofar as data processing is based on your express consent (Art. 6(1)(a) GDPR), you can withdraw it at any time with effect for the future.
Important notice – Right to object (Art. 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest).
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, or the processing serves the establishment, exercise, or defense of legal claims.
Contact for exercising your rights: To exercise all of the aforementioned rights, an informal notification by email to info@zefaj-immobilien.com is sufficient.
Right to lodge a complaint with the supervisory authority (Art. 77 GDPR): You also have the right to lodge a complaint about our processing of your personal data with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, phone: 0711 / 61 55 41 – 0, email: poststelle@lfdi.bwl.de.
15. Data security
We take appropriate technical and organizational security measures (TOMs) in line with the current state of the art pursuant to Art. 32 GDPR in order to protect your personal data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
• Encrypted transmission (TLS): To protect the security of your data during transmission, we use an encryption method corresponding to the current state of the art (e.g. TLS/HTTPS). You can recognize an encrypted connection by the status bar of your browser (padlock symbol) and by the address bar beginning with “https://”.
• Protection of access data: When you create a user account on our platform, your password is never stored in plain text. It is stored exclusively in the form of an irreversible cryptographic checksum (hashed and salted), so that even in the event of a potential data breach, no access to your actual password is possible.
16. Currency and changes to this privacy policy
This privacy policy is currently valid.
As our platform and offerings develop further, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The respective current privacy policy can be accessed and printed out by you at any time on this website.
Last updated: July 2026