Privacy Policy
Version: October 2026 · German version governs
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
greenhats® GmbH
Buchenweg 22
35096 Weimar (Lahn), Germany
Represented by managing director Arwid Carlo Zang
Contact: support@greenhats.com · +49 6426 8989-022
Data protection enquiries: datenschutz@greenhats.com
No data protection officer has been appointed, as there is no statutory obligation to do so (Art. 37 GDPR).
2. General Information on Data Processing
This Privacy Policy informs you about the processing of personal data when using Code:Sniper. Personal data means any information relating to an identified or identifiable natural person. We process personal data exclusively in accordance with the GDPR and applicable German data protection law.
Data transmission is encrypted (TLS). The Service is directed exclusively at businesses (B2B).
3. Data Processing in Detail
| Category | Data | Purpose / Legal basis |
|---|---|---|
| Registration / login (OAuth) | Email address, name, profile picture, OAuth identifier, OAuth provider (GitHub, Google, Microsoft) | Provision of the account; performance of contract (Art. 6(1)(b) GDPR) |
| Source code upload | Contents of submitted ZIP archives and code pastes (may contain personal data) | Performance of the security analysis; Art. 6(1)(b) GDPR. Zero Data Retention, no training, EU-only, deletion within 24 h |
| Payment / billing | Name, email address, payment data (processed via Stripe) | Contract performance (Art. 6(1)(b) GDPR); statutory retention obligations |
| Transactional emails | Email address, account name | Welcome, scan-ready and expiry notices; contract performance or legitimate interest (Art. 6(1)(b)/(f) GDPR) |
| Feedback / support | Email address, content of the enquiry | Handling of the enquiry; Art. 6(1)(b) GDPR |
| Server log files | IP address, date/time, requested resource, referrer, user agent | Security, error analysis, abuse prevention; legitimate interest (Art. 6(1)(f) GDPR) |
4. Recipients and Processors
To provide the Service we use processors within the meaning of Art. 28 GDPR. Data is only disclosed to the extent necessary and on the basis of corresponding data processing agreements:
| Provider | Purpose | Data location |
|---|---|---|
| hosting.de | Infrastructure & hosting | Germany (ISO 27001) |
| Google Cloud / Google Gemini | AI analysis | EU (European region lock, Zero Data Retention) |
| OpenRouter | AI analysis | EU (EU-Only region, Zero Data Retention) |
| Stripe | Payment processing | PCI DSS Level 1 |
| Mailgun | Transactional emails | EU |
| GitHub, Google, Microsoft | OAuth authentication | SOC 2 / ISO 27001 |
| BorgBase / Vykar | Encrypted backups (database, without source code) | encrypted (AES-256) |
The data processing agreement concluded with OpenRouter is available at: https://openrouter.ai/assets/data-processing-agreement.pdf(opens in new tab)
5. EU-only & No Third-Country Transfer
Personal data is processed exclusively within the European Union. The AI services used are operated with EU regional restrictions (Google Gemini: European region lock; OpenRouter: EU-Only region). No transfer of personal data to the United States or other third countries takes place in the context of source-code analysis. Zero Data Retention applies to all AI processing: customer data is not used to train or improve models.
6. Retention Period
| Data category | Retention period |
|---|---|
| Source code (upload / extraction) | max. 24 hours, thereafter automatic and complete deletion |
| Server log files | 30 days |
| Backups (database, without source code) | 120 days |
| Account, project and report data | until deleted by the customer |
| Invoicing and tax data | statutory retention periods (6–10 years) |
Backups contain only user and account data, not the submitted source code. On request, we will completely delete personal data, unless statutory retention obligations apply.
7. Cookies and Local Storage
Code:Sniper uses only strictly necessary cookies and local storage: a session cookie for login and the locally stored language preference. No analytics, tracking, or marketing cookies are used, and no profiling is carried out. A consent banner is therefore not required.
8. Your Rights as a Data Subject
Under the GDPR you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (“right to be forgotten”, Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
To exercise your rights, contact datenschutz@greenhats.com. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent supervisory authority is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Wiesbaden, Germany.
9. AI Processing and Transparency (EU AI Act)
Code:Sniper is an AI-assisted system within the meaning of Regulation (EU) 2024/1689 (EU AI Act). Parts of the submitted source code are processed by AI models as part of the analysis. Processing takes place exclusively for the purpose of security analysis, with Zero Data Retention and without training on customer data.
10. Changes to this Privacy Policy
We reserve the right to adapt this Privacy Policy as necessary, e.g. in the event of changes to the services or the legal situation. The version published at the time of use applies.