Legal

Privacy policy

This policy describes which personal data is processed when you visit this website and use Foreqast, on what legal basis, and what rights you have as a result.

1. Controller

The controller within the meaning of the GDPR for the processing of personal data on this website and in the application is:

Controller
Patrick Landolt
Sole proprietorship, trading as “Foreqast”
Holzhausen 15
18435 Stralsund
Germany
Data protection officer
We are not required to appoint a data protection officer: fewer than 20 people are constantly engaged in the automated processing of personal data (Section 38 (1) BDSG), and our processing does not currently require a data protection impact assessment. Please direct data protection enquiries to the email address above.

The full provider identification is available in the imprint.

2. Hosting and place of processing

All application data is stored in the European Union. We use the following processors for this, and have an Art. 28 GDPR data processing agreement in place with each of them:

Supabase, Inc.
Database, authentication, file storage and server-side functions. Processing region eu-central-1 (AWS, Frankfurt am Main, Germany). As Supabase is a US company, any support access is covered by the EU Standard Contractual Clauses.
Vercel, Inc.
Delivery of the website and the application. Visitors from Europe are served from European locations; the transfer is covered by the EU Standard Contractual Clauses.

3. Access data and server log files

When you access this website, technically necessary access data is processed (e.g. IP address, time of the request, resource requested, referrer, user agent). The legal basis is Art. 6 (1) (f) GDPR — the legitimate interest in operating the service securely and reliably.

This access data arises at our hosting provider. We do not combine it with other data and do not evaluate it to analyse user behaviour. Where our server-side functions need the IP address to prevent abuse, it is immediately hashed with a random key and is neither stored nor logged.

We do not create or store access logs ourselves. Log files arise solely at our hosting provider and are deleted automatically there in line with its retention period; we access them only to investigate faults and abuse.

4. Cookies, analytics and consent

We use Vercel Web Analytics to measure reach. The measurement is cookieless: it sets no cookies and neither stores nor reads any information on your device. Our hosting provider Vercel derives a hash from the IP address, the user agent and a daily-rotating random value in order to count returning visits; the IP address itself is not stored, and the hash cannot be traced back to you. There is no cross-device recognition and no profiling. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in understanding which content is found and read. Beyond that we use no tracking or marketing technologies: no advertising or conversion pixels, no session recording, no third-party error tracking and no embedded chat service. Fonts, images and video are served exclusively from our own servers, and the analytics script is served from our own domain as well.

We store in your browser only what is strictly necessary to operate the service. Such storage is exempt from consent under Section 25 (2) no. 2 TDDDG — which is why this website deliberately has no cookie banner.

sidebar:state (cookie)
Remembers whether the sidebar in the application is expanded or collapsed. Lifetime 7 days. Set by us, not by any third party.
Login session (localStorage)
The access token for your login. Without it you would be signed out on every page change. Removed when you sign out.
Application preferences (localStorage)
Your own settings — active company, forecast options, view preferences, colour scheme. This data stays in your browser.

The only exception are videos on our blog that are hosted on YouTube. They do not load automatically: you first see a preview served from our own servers and have to start the video explicitly. Only then is a connection to YouTube (Google Ireland Limited) established and your IP address transmitted. The legal basis is your consent under Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG, which you give by starting the video.

5. Contacting us and early access

If you write to us by email or complete the early-access form, we process the data you provide in order to answer your enquiry. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR.

The early-access form and the financial self-check are provided by Typeform S.L. (Barcelona, Spain). The data is processed within the EU and an Art. 28 GDPR data processing agreement is in place. We process the details you enter in the form — typically name, email address, company name and your answers.

We use these details solely to deal with your enquiry. You will only receive marketing emails if you have separately agreed to them, and you can withdraw that agreement at any time. Retention period for enquiries: We delete your enquiry once it has been dealt with conclusively, and at the latest 12 months after the last contact.

6. User account and application data

To provide the application we process account data as well as the financial and accounting data you upload yourself or connect through an integration. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).

Specifically, we process:

Account data
Email address, password (stored only as a hash), display name, company name, revenue band, login timestamps and — if enabled — your second authentication factor.
Accounting data
From your DATEV or CSV exports: journal entries, booking texts, account and contact names, voucher numbers, amounts and dates. Booking texts and contact names are additionally stored encrypted.
Planning data
Invoices, bills, contracts, subscriptions and projects you enter, as well as employee data (name, role, salary, working hours) where you enter it for headcount planning.
Shop connection (optional)
If you connect your Shopify store we retrieve aggregate order totals per day, week and month only. Your customers' names, email addresses and postal addresses are never transmitted to us.
Bank connection (planned)
Bank account connectivity is prepared but not yet active. This policy will be updated before it becomes available.

You can download your data as a machine-readable file and delete your account entirely at any time — both under “Account” in the settings. Deleting your account also irreversibly removes all companies and their financial, accounting and payroll data.

If you process third-party personal data — such as your employees' salary data or your business partners' names — you are the controller for it and we are your processor. We provide an Art. 28 GDPR data processing agreement for that; request it at patrick@foreqast.app.

7. Recipients and international transfers

We disclose personal data only to the recipients below. We do not sell data, and we do not use your data to train AI models.

Supabase, Inc.
Database, authentication and account emails. Stored in Frankfurt am Main, Germany. Any support access from the USA: EU Standard Contractual Clauses.
Vercel, Inc.
Delivery of the website and application, access log files. EU Standard Contractual Clauses.
Typeform S.L.
Early-access and self-check forms. Established and processing in Spain (EU) — no third-country transfer.
Shopify International Ltd.
Only if you connect your store yourself. Established in Ireland (EU); the data retrieval happens at your initiative.
Google Ireland Limited
Only if you explicitly start a YouTube video on our blog (see section 4). Without that click no transfer takes place.

Beyond this we may disclose data to public authorities where we are legally obliged to. We maintain a current list of our processors and make it available to business customers on request.

8. Retention

Personal data is deleted as soon as the purpose of processing ceases to apply, unless commercial or tax retention obligations require otherwise.

Account and application data
For as long as your account exists. If you delete your account they are removed immediately and irreversibly, together with all company and financial data. They disappear from backups as the backup window expires.
Server log files
Short-term at the hosting provider, see section 3.
Support requests and feedback
24 months after the request is closed. Earlier requests stay findable for follow-up questions during that period and are deleted afterwards.
Invoices and accounting vouchers
Statutory retention periods apply to our own bookkeeping: 8 years for accounting vouchers under Section 147 AO and up to 10 years under Section 257 HGB. Such data is restricted rather than deleted for the duration of those periods (Art. 17 (3) (b) GDPR).

The accounting data you upload to Foreqast belongs to your own books — those retention obligations fall on you, not on us. We do not retain it on your behalf.

9. Your rights

You have the following rights vis-à-vis the controller: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Any consent you have given may be withdrawn at any time with effect for the future (Art. 7 (3)).

Two of these rights can be exercised directly in the application without contacting us: under Settings → Account you can download everything stored about you as a machine-readable file (Art. 15 and Art. 20) and delete your account together with all its data (Art. 17).

For everything else, an informal message to patrick@foreqast.app is sufficient. We respond without undue delay and at the latest within one month (Art. 12 (3) GDPR).

10. Right to lodge a complaint

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the one at the controller's registered office:

Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern
Werderstraße 74a
19055 Schwerin
www.datenschutz-mv.de

You may also contact the supervisory authority where you habitually reside or where the alleged infringement took place.

11. Changes to this policy

This privacy policy will be updated when the processing or the legal situation changes. The version published here applies. Last updated: 7 August 2026.