Legal · Last updated October 6, 2026
Privacy Policy
InstallCue processes only what is needed to prepare a delivery, installation or service visit. This policy (Art. 13 and 14 GDPR) explains which data we process, for what purpose, on which legal basis, and which rights you have. It covers the website, the workspace and customer links.
1. Controller
Neithra Technologies – Fabian LorenzThaler Weg 2a
51647 Gummersbach
Germany
support@installcue.com
Phone: +49 2266 4889976 (Germany), +1 332 287 9966 (USA)
For data that an equipment dealer or installer collects from its own customers through InstallCue (customer links), that company is the controller; we process such data as a processor under Art. 28 GDPR. A data processing agreement is available on request.
2. What we process
Visiting the website
When you visit, technically necessary connection data is processed (IP address, time, page requested, browser) to deliver and secure the site and is kept briefly in server logs. Legal basis: Art. 6 (1) (f) GDPR.
Contact form
When you write to us through the form, we process your name, company, email, optional phone number, country, job volume and message to answer your request. Legal basis: Art. 6 (1) (b) and (a) GDPR. We delete the request once it is handled, and after twelve months at the latest if no business relationship follows. The same applies to a call request (page “Request a call”); instead of the job volume, you can tell us there which plan interests you and when we can reach you.
Contact and demo enquiries submitted through the form or product adviser are handled together in the operator’s central Neithra Office. The enquiry dialog also allows you to provide your industry, planned start and an editable summary. These details are transmitted only when you submit; the complete chat is not automatically included.
To protect against automated submissions, your browser solves a small calculation when you submit the contact, enquiry or cancellation form; we also check a field that is invisible to people and the time taken to fill in the form. This happens without third parties and without cookies. Legal basis: Art. 6 (1) (f) GDPR.
Registration and workspace
Optional AI support requires your consent. Your messages pass through the central Neithra service to the model provider named in the dialog. Product identity, pseudonymous user/conversation identifiers and usage data support routing and cost limits; answers may be cached temporarily to prevent duplicate calls (expiry after 24 hours). Account and job data are not automatically sent to the model. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time with effect for the future; if the model provider is established outside the EU/EEA, section 4 applies to the transfer. For a team support request from your signed-in account, contact details, company and customer number are added for processing in Neithra Office.
When you sign up we process your company name, your name, work email address and a password (stored only as a hash). In the workspace we process the jobs, templates, team members, settings and billing data you create. To order a plan we process the country of the registered office, billing address, VAT ID, billing email and the order itself; plans of up to 1,000 per month are paid through Stripe, to which we pass the company name, address, country and VAT ID; Stripe checks an EU VAT ID against the EU database VIES. Larger plans are invoiced directly by us. Legal basis: Art. 6 (1) (b) GDPR, and for keeping invoices Art. 6 (1) (c) GDPR with § 147 German Fiscal Code and § 257 German Commercial Code.
Customer links
Recipients of a customer link enter answers about access, measurements, utilities and site contacts, confirm them, and may optionally upload photos. No account is required. Links contain a random key of at least 256 bits; only a hash is stored. Photos are kept in private storage and are reachable only through short-lived signed addresses.
Notifications
We send request and reminder emails on behalf of the respective company, and notify the responsible employees when a customer submits answers or a blocker appears. Delivery and bounce status is recorded.
3. Cookies and local storage
We use only technically necessary cookies and local-storage entries. They are strictly required to provide the service you ask for and therefore need no consent (Art. 5 (3) ePrivacy Directive, Section 25 (2) no. 2 TDDDG). The related processing is based on Art. 6 (1) (b) and (f) GDPR.
We use no advertising or cross-site tracking tools. Audience measurement (section 9) works without cookies and without an identifier on your device. That is why we do not ask for consent; the cookie notice only informs you and can be shown again via “Cookie notice” in the footer. Should that change, we will ask for your consent first and update this policy.
| Name | Purpose | Duration |
|---|---|---|
| installcue_access_token / installcue_refresh_token | Workspace sign-in (HTTP-only cookie) | until sign-out, at most 30 days |
| installcue-market, installcue-language | Region, currency, units and language (cookie) | 12 months |
| installcue-cookie-notice | Remembers that you closed the cookie notice (local storage) | until you clear the browser storage |
| installcue:<link>, installcue:tour:* | Offline draft of the customer form, introduction seen (local storage) | until submission / until you clear the browser storage |
4. Recipients and service providers
We share data only with contractually bound service providers (Art. 28 GDPR). Depending on the configuration these are:
- netcup GmbH (Nuremberg, Germany) – hosting of the application and its database on our own server
- Cloudflare – network and connection protection (tunnel, DNS; Turnstile bot protection on the sign-up and contact forms only if enabled) and R2 object storage for photos and encrypted backups
- Resend – delivery of transactional e-mail
- Stripe – payment processing and invoices for plans ordered online (up to 1,000 per month); payment data stays with Stripe
- Expo – push notifications of the employee app, only if enabled
- OpenAI or, where enabled and named in the support dialog, OpenAI and Google Gemini – messages of the optional AI support, only after your consent; the Google option additionally requires confirmation that you are at least 18. Pseudonymous conversation context is stored centrally for follow-up questions and support handoffs. Cases with no activity for 30 days are removed during regular operation. Separately submitted contact emails follow their own retention periods. In the authenticated admin support dialog, a separate opt-in can additionally share the stored plan, local access status and ability to create requests. These facts are read under the current workspace authorization; this read time is not a payment verification. No customer or job records, invoice files or payment identifiers are included. Pseudonymous workspace and caller references bind the central request; the AI receives only the limited facts.
Where a provider processes data outside the EU/EEA, transfers rely on adequacy decisions (for example the EU-US Data Privacy Framework) or the European Commission's standard contractual clauses.
5. Retention
Workspaces choose a retention period for job data and photos (default: 730 days). A daily automatic deletion run then removes the photos and the completed jobs with their answers, measurements, recipients, reminder schedules and notes. Unattached uploads are removed after 24 hours. Review and audit logs are kept longer as evidence of the release decision. Account and billing data is kept for the contract term and afterwards within statutory retention periods (generally eight years for invoices under § 14b UStG; other records according to their statutory category and any applicable longer legal period). Cancellation and other contract-ending declarations are retained as business correspondence for six years from the end of the year in which they were received, unless a longer statutory retention duty applies (for example § 147 German Fiscal Code, § 257 German Commercial Code), and then deleted or anonymised. A read-only workspace after the contract ends is deleted on request within 30 days.
6. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Consent can be withdrawn at any time with effect for the future. Write to support@installcue.com. You may also lodge a complaint with a supervisory authority, for example the one where you live or the authority responsible for us, the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (Kavalleriestraße 2–4, 40213 Düsseldorf).
Recipients of a customer link should first contact the company that sent the link; we support that company in fulfilling your rights.
7. Notice for users in the United States
Additional international rights: applicable US state law may give you rights to access, correction, deletion and a portable copy, and rights concerning sale, targeted advertising or certain profiling. Applicability depends on the law, its thresholds and the processing concerned; business contact data is not automatically excluded in California. We do not sell personal data or use it for cross-context behavioural advertising. Browser Do Not Track signals do not change the necessary processing described here; our service does not use cross-site advertising tracking. This is distinct from legally recognised opt-out preference signals such as Global Privacy Control. Send a rights request to the contact in this notice or the legal notice, without needing a paid account. An authorised agent may act with evidence of authority. We verify identity proportionately to the request, normally through the known account or contact address; we request additional evidence only where necessary and do not disclose another person’s data. We explain any refusal and applicable exceptions. You may request a review by replying to that decision; we handle requests and any statutory appeal within the applicable legal deadlines and explain any permitted extension. We do not discriminate for exercising privacy rights. Where UK GDPR or Swiss data protection law applies, their rights and safeguards also remain available; you may contact the UK Information Commissioner (ico.org.uk) or the Swiss FDPIC (edoeb.admin.ch), respectively. For data controlled by a customer, we forward or assist with the request as its processor. Changes to these practices are shown with the updated date of this notice; material changes affecting existing accounts are also communicated through the account or contact address before they take effect, with consent where required. If Canadian privacy law applies, you may also use the same contact to request access or correction, withdraw consent where applicable or complain about our handling; you may contact the competent federal or provincial privacy authority (priv.gc.ca). A professional email address alone does not exclude all related account or usage data from protection.
8. Security
Connections are encrypted with TLS, records are isolated per tenant, and every site approval is attributed to a person. Details: Security.
9. Audience measurement (Umami)
We measure how this website is used with the open-source software Umami, which we operate ourselves on a server of netcup GmbH in Germany. Umami sets no cookies and stores no identifier on your device. Your IP address is used only briefly to determine your approximate location (country, region, city) and to form a daily rotating identifier that cannot be traced back to you; it is not stored. We store the pages viewed, referring page, browser, operating system, device type, language, approximate location and events such as opening the checkout or submitting a form. Data is transmitted via Cloudflare, which we use to deliver our websites. The legal basis is our legitimate interest in improving our offering (Art. 6(1)(f) GDPR). Data is deleted after 24 months. If your browser sends “Do Not Track” or “Global Privacy Control”, no measurement takes place.