Privacy Policy
Ackord credits are commercial adjustments for a named incident. Confirmation is not a legal opinion, admission, or general release.
Who is responsible
Ackord is offered by Semion Kasparovich in Germany. Contact for privacy requests: [email protected]
What we store
We store the work email you use to sign in, organisation name, incident and claim fields (customer email, incident text, SLA or clause text, amount, status), magic-link tokens, audit events, optional Slack webhook and Notion token you save, and Stripe customer or subscription identifiers after checkout. We do not store full card numbers. Stripe does.
Why we store it
We process this data to run Ackord: sign you in, send the customer magic link, record confirm or dispute, keep the claim history, and bill the plan you chose. Legal bases are contract (Art. 6(1)(b) GDPR) and, for security logs, legitimate interest (Art. 6(1)(f) GDPR).
Cookies
Ackord sets a session cookie after vendor sign-in so the claims cabinet stays signed in. It is required for the service. We do not set advertising cookies.
Processors
Hosting runs on Railway. Card and subscription billing runs on Stripe. Transactional mail uses the mailbox configured for the service. Each processor acts only on our instructions for this product.
How long
Account and claim records stay while the organisation uses Ackord and for a reasonable period after, so a confirmed incident can be shown later. Magic links expire after 7 days. You can ask us to delete an account.
Your rights
You may request access, correction, deletion, restriction, or portability of your personal data, and you may object to processing based on legitimate interest. You may lodge a complaint with a German data protection authority.
Transfers
Stripe and Railway may process data outside the EU under their own transfer tools (standard contractual clauses or an adequacy decision).