Your data remains manageable.
Keep track of the information you provide and exercise your data protection rights.
- Access and rectification
- A data copy in a machine-readable format
- Deletion subject to statutory retention requirements
Loading security information …
HADBA connects data, analyses and next steps for your sales. See what information is processed, how access is limited and where your decision matters.
From source to result: explore how data enters HADBA, is processed and becomes useful.
Choose a stage to explore the details.
Public website and market signals form the starting point. Your metrics, uploaded content and connected analytics sources add to the data basis, depending on how you use the platform.
Simplified illustration of protection principles. Not a live monitor of your data.
Data control, technical protection, limited access and transparent processing belong together.
Keep track of the information you provide and exercise your data protection rights.
Safeguards apply to transmission, storage and access.
Read-only analysis and instructed write operations are different access paths.
AI forms part of processing. Conditions and service providers are disclosed.
HADBA processes information from the functions you use and sources you provide. One connection does not automatically open your entire organisation.
Content you enter or upload can become part of an analysis. Free text can contain sensitive information too. Before submitting it, check which information is needed for your analysis.
Permissions follow the function. A data connection is not blanket authorisation to change your systems.
For example, GA4 and Shopify: metrics are read for analysis. This does not grant general write permissions to your shop or advertising account.
An export can create contacts in your CRM. It requires your credentials and is triggered or explicitly enabled by you.
Availability depends on the supported system and your plan. A CRM export feature is not universal CRM read access.
From initial access to the end of use. Disconnecting and deleting are different actions.
You authorise a supported source.
The selected function processes its data basis.
See results and assess your next step.
A data copy and plan-dependent result exports.
Revoke further access.
On request and subject to retention rules.
Disconnecting a source does not automatically delete previously stored data. Deletion follows a separate data protection process.
Technical and organisational measures for storage, access and processing.
The SaaS platform runs in Germany; the database is in the EU. The ISO 27001 statement refers to the database provider’s data centres, not a certification held by HADBA.
The website runs on Vercel. AI and other service providers may process data outside the EU. Recipients and transfer safeguards are described in the privacy notice.
Read the privacy notice →Align identity access, collaboration and bespoke connections with your organisation. The exact scope is agreed individually.
SSO on request, configured with your identity provider by agreement.
Access by responsibility instead of shared credentials. Features and scope depend on your plan.
Review interfaces and security requirements in advance and document the scope in your offer.
Detailed answers to your most pressing questions on compliance and data protection.
Your inputs are not used to train our provider’s AI models by default. Processing to create your analysis results and short-term retention for abuse prevention and operational security are described in our privacy notice.
The SaaS platform runs in Germany; the database is in the EU. The ISO 27001 statement refers to the database provider’s data centres, not a certification held by HADBA. The website runs on Vercel. AI and other service providers may process data outside the EU. Recipients and transfer safeguards are described in the privacy notice.
Yes. We provide the DPA under Art. 28 GDPR on request; digital self-service provision in the portal is in preparation.
For example, GA4 and Shopify: metrics are read for analysis. This does not grant general write permissions to your shop or advertising account. An export can create contacts in your CRM. It requires your credentials and is triggered or explicitly enabled by you.
Database backups are created through the database provider. Backups of uploaded files are a separate concern. We can clarify scope and operational status for your recovery requirements; a database backup alone does not imply complete file recovery.
A personal data breach triggers the relevant reporting and information procedures under applicable data protection requirements. Required steps depend on the nature and risk of the incident. Please contact us directly with specific security questions.
The privacy notice lists providers used for hosting, AI processing, research and email, including information about possible transfers outside the EU. It is the authoritative public overview; further information is available on request.
Public website and market signals, metrics and content you provide, and data from authorised connections, depending on the functions you use. Unconnected internal systems are not automatically accessible.
You revoke further access through the connection. This does not automatically delete previously stored data or results. Their deletion follows the separate data protection process.
You can exercise your rights of access, rectification, portability and deletion. Result and asset exports depend on your plan and are distinct from the data copy provided under data protection rights. Statutory retention obligations may prevent immediate complete deletion.
Every module shows its source rate: how many of its values can be traced to a source and how many are locked rather than estimated — with numerator and denominator, expandable down to the individual metric and its origin. A value without a traceable source is locked, not guessed. In addition you can produce an AI transparency dossier in your settings: a document for your audit, your enterprise customer or your management, summarising the systems in use, the processing locations, the origin of the figures per module, the human oversight and the log of your account. It is not AI-generated; it is assembled from reviewed statements and your stored data.
Enterprise supports SSO on request and individually agreed connections. Team permissions and session policies are configured within the available features. Please discuss your specific requirements with us in advance.
Start with the Revenue Snapshot or discuss your data protection and integration requirements first.