← Back

This is an English courtesy translation for your convenience. The legally binding version is the German original — see the German version.

Privacy Policy

This statement provides information about which personal data is processed when using the service SpamProtec and this website, for which purposes, and on what legal basis.

1. Controller

MessingerDesign — Philipp & Werner Messinger GbR
Dahmestraße 10, 12526 Berlin
Telephone: · E-mail: pmessinger (at) messingerdesign (punkt) de

2. Role and legal bases (consumers / businesses)

The core of the service is the automated screening of incoming e-mails for spam, phishing and malicious content. To this end, SpamProtec accesses the mailboxes connected by the customer via IMAP and processes e-mail content and metadata (sender, recipient, subject, headers, message body).

Consumers (B2C): Vis-à-vis consumers, the provider itself determines the means and purposes of the processing required to deliver the service and is therefore an independent controller (Art. 4 No. 7 DSGVO (GDPR)); no data processing agreement is concluded with consumers. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (GDPR) (performance of a contract) and, with regard to third-party data — in particular the senders of incoming messages — Art. 6 Abs. 1 lit. f DSGVO (GDPR) (legitimate interest in e-mail/IT security and spam/phishing defense, Recital 49).

Businesses (B2B): If a business processes personal data of third parties via the service in the course of its activities, the customer is the controller and the provider is the processor (Art. 28 DSGVO (GDPR)) on the basis of a data processing agreement to be concluded separately (view DPA). In this case, data subjects (e.g. the customer's communication partners) should primarily contact the respective customer to exercise their rights.

3. Data-minimizing AI screening with pre-anonymization

Part of the classification is performed by external AI models. A strict data protection concept applies here:

4. Recipients and sub-processors

The respective current list of sub-processors is maintained in the DPA.

5. Account and usage data of the web interface

For the operation and protection of the web interface, we process:

6. Reach measurement of the website (meinKI Analytics)

For the statistical evaluation and improvement of this website, we use meinKI Analytics — a reach measurement operated on our own infrastructure. No data is passed on to external analytics service providers and no transfer to third countries takes place. The measurement is carried out in two stages:

Advertising performance measurement (Google Ads): If you reach our website via one of our ads, we process the click and campaign identifiers passed in the address (e.g. Google gclid, utm_*) in order to measure the effectiveness of our advertising; if you later start a free trial, we attribute it to that ad. Without your consent, this happens only for the session via a non-persistent, purely functional first-party cookie (sp_attr) that is normally deleted when you close your browser (Art. 6 Abs. 1 lit. f DSGVO (GDPR)). Only with your consent is this identifier stored persistently (up to 90 days) so that later visits can be attributed too (§ 25 Abs. 1 TDDDG, Art. 6 Abs. 1 lit. a DSGVO (GDPR)); withdrawal takes effect for the future (the cookie is then downgraded to the current session). If you sign up for a free trial, we additionally store the click identifier transaction-related in the contract data (only until account setup is completed) and as a pseudonymous event in our self-operated statistics system (Art. 6(1)(b) and (f) GDPR). For measurement, the click identifier together with the fact that a trial was started may be transmitted to Google (Google Ads); no e-mail or message content is transmitted. No cookies of the advertising platform are set.

7. Reports and system e-mails

As part of the service, we send system e-mails (e.g. quarantine reports, login codes, invitations) to the stored addresses. The legal basis is Art. 6 Abs. 1 lit. b DSGVO (GDPR); reports can be deactivated in the settings.

8. Storage period

9. Your rights

You have the rights under Art. 15–21 DSGVO (GDPR): access, rectification, erasure, restriction of processing, data portability, as well as the right to object to processing on the basis of Art. 6 Abs. 1 lit. f DSGVO (GDPR). In addition, there is a right to lodge a complaint with a data protection supervisory authority, e.g. the Berlin Commissioner for Data Protection and Freedom of Information. Insofar as data is processed on behalf of a customer, we forward requests from data subjects to the responsible customer or assist them in responding.

10. Data security

We employ measures corresponding to the state of the art, including TLS transport encryption, encrypted storage of credentials, a roles and permissions concept, tenant separation, logging of security-relevant events, daily backups and automatic monitoring.

11. Contact for data protection matters

pmessinger (at) messingerdesign (punkt) de

As of: June 2026 · SpamProtec · MessingerDesign GbR