Last updated: July 2026 – Version 1.5 · Deutsche Version (rechtlich maßgeblich)
This is an English convenience translation of our privacy policy. In case of discrepancies, the German version prevails.
denschCollabs is deliberately designed to be data-minimal. We:
Our platform exists solely for the internal management of brand collaborations – from first inquiry to final invoice.
denschCollabs is a service provided by:
dasdensch.com
Dennis Schneider
Hannoversche Str. 11
37176 Nörten-Hardenberg
Germany
E-mail: datenschutz@dasdensch.com
The website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. As part of the hosting, STRATO processes personal data on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place.
When the website is accessed, STRATO automatically collects server log files. These contain:
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).
Using the platform requires a user account created by an administrator. The following data is processed:
Purpose: authentication at login, access management for the platform.
Legal basis: Art. 6(1)(b) GDPR (performance of contract), Art. 6(1)(f) GDPR (legitimate interest in secure access).
The core function of denschCollabs is recording and managing brand collaborations. The following data is stored in the course of use:
This data is entered and managed exclusively by the logged-in user. It is not shared with third parties and not used for any other purposes.
Legal basis: Art. 6(1)(b) GDPR (performance of contract), Art. 6(1)(f) GDPR (legitimate interest in managing one's own business relationships).
Users can upload documents (e.g. contracts, briefings, invoices) to the server. The following applies:
uploads/ directory on the server.Note: Users are themselves responsible for the contents of uploaded files and for complying with data protection requirements towards the persons contained therein.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
For paid subscriptions, payment processing is handled by the payment service provider Stripe Payments Europe, Ltd., Dublin, Ireland. Payment data (e.g. card details) is processed exclusively by Stripe and is not stored on our servers. We only receive anonymised reference IDs for managing the contractual relationship. More information: stripe.com/privacy
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
When creating or editing contacts, we offer autocomplete for company and address data. For this we use the Photon service, operated by komoot GmbH, Rheinsberger Str. 76/77, 10115 Berlin, Germany.
Autocomplete only becomes active when the user manually types text into the company or address field. Without input, no transmission takes place.
Availability / fallback: Photon is a free third-party service without an availability SLA. If Photon is unavailable, autocomplete is temporarily not offered. Contact entry remains fully usable manually in that case — all fields (company, address, postcode, city) can be filled in freely at any time. There is no automatic failover to another service and no caching of komoot responses.
More information: photon.komoot.io · komoot.com/privacy
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient and error-free address entry).
To display insights and performance data for content collaborations, users can connect their own social media accounts to denschCollabs via OAuth 2.0. Processing only takes place after active consent in the respective OAuth consent screen. The integration is optional – without a connection, the insights features of the respective platform are simply unavailable; all other features remain fully usable.
denschCollabs uses the following Google API Services:
youtube.readonly)yt-analytics.readonly)yt-analytics-monetary.readonly)Data retrieved: channel metadata (name, logo, subscriber count), video list, performance metrics of individual videos (views, watch time, impressions, CTR) and – if selected by the user – revenue data of individual videos. If the “minimum account age” option is enabled in a giveaway, the creation date of the YouTube channel of individual commenters is additionally retrieved via the YouTube Data API v3 to apply the filter rule; this value is not stored permanently.
Purpose: displaying this data in the logged-in user's own dashboard to evaluate the performance of collaboration videos.
Retrieval mode: If insights are enabled for an account, denschCollabs automatically retrieves updated performance data via the API once per day (approx. 04:50 UTC). This automatic retrieval replaces the manual refresh and takes place regardless of whether the user is logged in at that time.
Limited Use: denschCollabs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Storage: Access and refresh tokens are stored in the database on the denschCollabs server (STRATO VPS, Germany). All transfers between browser, server and the Google API take place exclusively over TLS-encrypted connections (HTTPS). Database access is restricted to the server user (no external database connections allowed).
Cache mechanism: Retrieved API responses are stored with a cached_at timestamp in the youtube_api_cache table. On every read, the system checks this timestamp; entries older than 24 hours are ignored (cache miss → new API call) and automatically overwritten on the next write. In addition, a nightly cron job (tools/cache-cleanup.php, 03:30) permanently removes expired entries from the database.
Revocation: The user can disconnect at any time within denschCollabs (influencer detail or Settings → “Disconnect”). Alternatively via the Google account: myaccount.google.com/permissions. After disconnecting, stored tokens are deleted immediately and cached API data is removed within 24 hours.
Legal basis: Art. 6(1)(a) GDPR (explicit consent in the OAuth consent screen), Art. 6(1)(b) GDPR (performance of contract).
For Instagram insights, denschCollabs uses the Instagram Graph API / Facebook Login for Business (operator: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland).
Data retrieved: Instagram business account ID, username, follower counts, reach, impressions and engagement statistics of individual posts of the user's own account.
Purpose: displaying these metrics in the logged-in user's own dashboard.
Retrieval mode: If insights are enabled for an account, denschCollabs automatically retrieves updated performance data via the API once per day (approx. 04:50 UTC). This automatic retrieval replaces the manual refresh and takes place regardless of whether the user is logged in at that time.
Revocation: within denschCollabs (“Disconnect” button) or directly via Facebook under Business Integrations.
Legal basis: Art. 6(1)(a) and (b) GDPR.
For TikTok insights, denschCollabs uses the TikTok Login Kit and the TikTok Display API (operator: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland).
OAuth scopes used:
user.info.basic – open ID, avatar, display name of the connected accountuser.info.profile – username, bio, profile link, verification statususer.info.stats – follower, following, likes and video countsvideo.list – list of the user's own public videos including performance statisticsData retrieved: open ID, username, display name, profile picture, video metadata and performance statistics (views, likes, comments, shares) of individual videos of the user's own account.
Purpose: displaying these metrics in the logged-in user's own dashboard.
Retrieval mode: If insights are enabled for an account, denschCollabs automatically retrieves updated performance data via the API once per day (approx. 04:50 UTC). This automatic retrieval replaces the manual refresh and takes place regardless of whether the user is logged in at that time.
Revocation: within denschCollabs (“Disconnect” button) or directly in the TikTok account under Settings → Privacy.
Legal basis: Art. 6(1)(a) and (b) GDPR.
Giveaway comments: Where the giveaway feature (see section 9.6) is used for TikTok posts, denschCollabs retrieves comments via the TikTok API (/v2/video/comment/list/). In doing so, data of commenters (open ID, display name, avatar URL, comment text) is processed. TikTok itself is not certified under the EU-US Data Privacy Framework; transfers to third countries (in particular the USA and China-based backend infrastructure) are based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
For Twitch insights and the giveaway feature, denschCollabs uses the Twitch API (operator: Twitch Interactive, Inc., 350 Bush Street, 2nd Floor, San Francisco, CA 94104, USA – a subsidiary of Amazon.com, Inc.).
Data retrieved (influencer account): Twitch user ID, login name, display name, profile picture URL, broadcaster type, and follower and subscriber statistics of the user's own channel.
OAuth scopes used: user:read:email, chat:read, channel:read:subscriptions, moderator:read:followers. The chat:read scope allows denschCollabs to receive the live chat of the connected channel and evaluate it for the giveaway feature. The connection is optional and requires active authorisation in the Twitch OAuth dialog.
Anonymous chat reading (Twitch IRC): Where the giveaway feature is active, the chat of the connected channel can alternatively be read via an anonymous Twitch IRC connection (without a user token). Twitch permits this method under its developer policy. No account credentials of the influencer are transmitted. The chat contents and user identifiers processed correspond to the data listed in section 9.6.
Purpose: displaying channel metrics in the user's own dashboard and – if enabled by the user – operating the giveaway feature (keyword detection in live chat).
Third-country transfer: As Twitch Interactive, Inc. is based in the USA, data is transferred to the USA during the OAuth exchange and API requests. Twitch Interactive, as a subsidiary of Amazon.com, Inc., is certified under the EU-US Data Privacy Framework (DPF) (certificate available at dataprivacyframework.gov). Legal basis for the third-country transfer: Art. 45 GDPR in conjunction with the EU Commission's adequacy decision on the DPF of 10 July 2023. Where the DPF certificate does not apply in an individual case, the transfer is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Revocation: within denschCollabs via “Disconnect” or directly in the Twitch account under twitch.tv/settings/connections. After disconnecting, access and refresh tokens are deleted immediately.
Legal basis: Art. 6(1)(a) and (b) GDPR.
Only data from accounts that the logged-in user has personally authorised is retrieved. Access is limited to read-only scopes – denschCollabs cannot post, modify or delete any content. Connections can be disconnected at any time without restricting any other platform features.
The giveaway feature allows users (influencers) to run automated giveaways based on chat messages (Twitch live chat) or comments (Instagram, YouTube, TikTok).
Data of participants processed: When taking part in a giveaway, the following data of chat participants or commenters is processed:
For Instagram, YouTube and TikTok, comments are loaded via the platforms' respective APIs exclusively upon a manual retrieval triggered by the user (“Fetch comments now”). This is distinct from the daily automated insights retrieval (see sections 9.1–9.3), which concerns insights metrics (reach, followers, performance data) of the user's own account — third-party giveaway comments are not collected by the insights cron.
Who is affected: persons who actively take part in a giveaway by entering the giveaway keyword in chat or by posting a qualifying comment. This participation is deliberate and public on the respective platform.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). The legitimate interest lies in running a giveaway organised by the respective influencer on behalf of our users. Participants act on their own initiative by actively entering a giveaway keyword or posting a comment. Processing is limited to what is necessary for evaluating the giveaway.
Information of data subjects (Art. 14 GDPR): As participants do not give consent directly to denschCollabs, they must be informed about the data processing pursuant to Art. 14 GDPR. This information is provided (a) via this privacy policy and (b) by the influencer, who is contractually obliged towards denschCollabs to inform their chat or community about the data processing before the giveaway starts.
OBS overlay and public winner display: After the draw is completed, the login name and display name of the winner(s) are shown in a token-protected OBS overlay (overlay-giveaway.php). This overlay is embedded into the livestream by the influencer; the winners' names are thus visible to the stream's viewers. This is based on the influencer's legitimate interest in a transparent, public draw (Art. 6(1)(f) GDPR). Winners are informed in advance through their participation in the public giveaway and the established practice of winner announcements (Art. 14 GDPR via the influencer's notice pursuant to § 6 of the Terms of Service).
Retention: Participation data is deleted 90 days after the giveaway ends. Winner data may be retained for up to 2 years (preservation of evidence in case of disputes). Deletion is automated.
Access and erasure: Data subjects can exercise their rights (Art. 15–17 GDPR) by e-mail to datenschutz@dasdensch.com. For identification, the platform username and the platform concerned must be provided.
denschCollabs offers optional features where images are read out with the help of an AI service:
Services used / user's own API access: The analysis is performed via an AI provider configured by the respective user in the settings. Available options:
The user's API key is stored encrypted (AES-256-CBC with a dedicated server key) in the database and can only be decrypted server-side. Without a configured key, no AI analysis takes place and nothing is transmitted to any AI provider.
Transmission path: The respective image is transmitted from the denschCollabs server (not directly from the user's browser) over a TLS-encrypted connection to the selected AI provider, read out there, and the recognised data is returned as structured text.
Image storage: Business card photos are not stored – they are processed transiently for extraction only and discarded immediately afterwards. Insights screenshots are stored on the denschCollabs server (STRATO VPS, Germany) until deleted by the user.
Third-party personal data (business cards): A business card typically contains personal data of a third person (name, position, phone number, e-mail address). The respective user is responsible for recording this data in their contact directory; denschCollabs processes it on their behalf. The alternative “paste text” input processes the card content exclusively locally in the browser and does not transmit any data to an AI provider.
Third-country transfer: Both providers are based in, or operate their processing infrastructure in, the USA; when the AI features are used, the transmitted images are transferred to the USA. Google LLC is certified under the EU-US Data Privacy Framework (DPF) (dataprivacyframework.gov); in this respect the legal basis for the transfer is Art. 45 GDPR in conjunction with the EU Commission's adequacy decision on the DPF. Where a provider is not certified under the DPF (which, in case of doubt, applies to Anthropic PBC), the transfer is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
Use for training purposes: Under the providers' API terms, content submitted via paid API access is not used to train the AI models. When using free tiers (in particular Google AI Studio), submitted content may however be evaluated by the provider for product improvement and possibly reviewed by humans. Anyone having third-party personal data (e.g. business cards) read out by AI should therefore use paid API access with corresponding data protection commitments, or use the AI-free input (“paste text”).
Optional / manual trigger: The AI extraction features are triggered exclusively by an active user action (selecting a photo or screenshot). All fields can be filled in manually at any time; the feature is not required for using denschCollabs.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient and error-free data entry) and Art. 6(1)(b) GDPR in the context of contract performance.
denschCollabs uses only technically necessary session cookies required for login and the secure operation of the platform. No tracking or marketing cookies are used.
Additionally, an optional cookie can be set for the “trust this device” feature:
Legal basis: § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR (legitimate interest in secure authentication).
A cookie banner is therefore not required.
denschCollabs employs the following technical security measures:
The website uses SSL/TLS encryption to protect transmitted content, recognisable by the lock symbol in the browser's address bar.
You have the right to:
You also have the right to lodge a complaint with the competent data protection supervisory authority. For Lower Saxony, this is the State Commissioner for Data Protection of Lower Saxony (LfD), Prinzenstraße 5, 30159 Hannover, Germany, www.lfd.niedersachsen.de.
For inquiries, please contact: datenschutz@dasdensch.com