Privacy

English convenience translation. The German text is the contractual version; mandatory consumer protections remain unaffected.

Company
HOPCOMP GmbH
Address
Meinekestraße 5, 10719 Berlin
Managing director
Dillon Scott Gabriel Hoppé
Commercial register
Amtsgericht Charlottenburg, HRB 275111
VAT ID
DE456298421
Email
info@hopcomp.com

Controller and contact

The controller is HOPCOMP GmbH, identified in the legal notice. Please send privacy, access or deletion requests to the email address above. We process data to perform the requested check and fulfil the contract (Article 6(1)(b) GDPR), comply with legal obligations (point c), and protect the service and measure minimal usage statistics in our legitimate interests (point f).

Upload and automatic analysis

You can upload a service-charge statement as a PDF or photo. It may contain names, addresses, consumption and payment information. Upload only necessary documents you are entitled to use. You can redact unnecessary bank details or particularly sensitive information first. Documents are stored with access controls and statement data is extracted. No account is required. Your random private link grants access to the preview and, after payment, the report; keep it private.

Uploaded documents are transmitted to Google LLC or Google Ireland Ltd. through the Gemini API for analysis; extracted data is sent for text generation. We use the API with active billing (Paid Services). Under the Google API terms, paid-service data is not used for training or improving models. Google may temporarily retain data for abuse prevention and legal requirements. For large requests, we use the Files API and delete temporary files after processing; Google otherwise provides automatic deletion after 48 hours. Transfers to the United States or other third countries may occur. Google’s data-processing terms and applicable transfer safeguards, including standard contractual clauses or an applicable adequacy decision, govern those transfers. See Google privacy and data-processing terms.

The analysis produces suggestions, not decisions with legal or similarly significant effects under Article 22 GDPR. You choose any further action.

Hosting and security

The host is netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, under a data-processing agreement. The application uses encrypted connections once domain TLS is configured and stores documents outside the web directory. IP addresses are technically processed to deliver pages. The application and this nginx virtual host do not keep access logs containing private report links. Technical errors are logged without document contents.

Payments and optional email

Stripe processes payment information and the email address collected at checkout. The EEA provider is Stripe Payments Europe Ltd., Ireland; other Stripe companies may be involved. We never receive card details. We store payment status, checkout identifier, amount, consent timestamp, contract version and email address. Stripe may process data internationally; see Stripe privacy.

When email delivery is enabled, the email address, report link and contract confirmation are sent through Postmark (AC PM LLC, part of ActiveCampaign, United States). The basis is contract performance; the service’s contractual safeguards apply to third-country transfers. See Postmark privacy. Without email delivery, the success page displays the link and offers the contract confirmation for download.

No tracking cookies; minimal statistics

We use no cookies, local browser storage or third-party trackers. For daily statistics we store the page path without report tokens, referring host without the full URL, truncated campaign parameters (UTM), day and a daily salted hash of IP address plus browser identifier. Raw IP addresses and browser identifiers are not stored in analytics. We count uploads, previews, checkout starts, payments and revenue. The pseudonymous identifier does not link visits across days. Our legitimate interest is understanding operation and demand (Article 6(1)(f) GDPR). You may object for reasons relating to your particular situation. Since we do not store or access information on your device, we do not use a cookie-consent banner.

Retention

A daily task deletes uploads after 30 days, by the next daily run. Extracted data, findings, generated text and the private report link are deleted after twelve calendar months. Individual analytics events are deleted after 35 days. Payment and contract evidence is kept separately, without uploaded statements, to the extent required by law; accounting vouchers are generally retained for eight years. Email addresses and the report association are removed after twelve months. Postmark and Stripe may have independent statutory retention duties.

Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests. Where processing relies on consent, you may withdraw it prospectively. Your private link helps identify your request; do not publish it. You may complain to a data-protection authority, especially the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, datenschutz-berlin.de.

Updated: 6 September 2026.