Privacy Policy
Convenience translation. Only the German version is legally binding: Datenschutzerklärung
1. Controller
Atlaxis Digital Services GmbH, Hintere Grabenstraße 25, 72070 Tübingen
Email: [email protected], Telephone: +49 7071 5392505
2. What this is about
Earlyswell analyses publicly accessible sources and shows which topics are gaining importance in politics, funding, research, online media and social networks. Personal data arises in two places: when the application is used (sections 3–5) and in the analysed sources themselves (section 6).
3. Access, hosting and Cloudflare
Earlyswell runs on a server owned by Atlaxis Digital Services GmbH in Germany; no external hosting service provider is used.
Access takes place via the network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare establishes the encrypted connection to your browser and in doing so processes your IP address and technical connection data in order to enable delivery and to fend off attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and available operation). A data processing agreement is in place with Cloudflare; the transfer to the USA is safeguarded by the EU Standard Contractual Clauses.
Our logs do not contain IP addresses, with one exception, sign-in protection (section 4): if you request a sign-in link or sign in with a password, we generate from your IP address an encrypted fingerprint (HMAC with a secret key) from which the address cannot be recovered, and delete it after 24 hours.
4. Account and sign-in
To use the service, you create an account. We store your email address, optionally your name, the organisation you belong to, your role there, the time of registration and of your last sign-in, and the topics you create. The legal basis is Art. 6(1)(b) GDPR (provision of the service). The data remains stored until you delete your account — you can do this yourself at any time under “Organisation & subscription”; there you can also download your data. If the trial ends without a booking or a subscription ends, the account remains read-only for 30 days; after that we delete the organisation’s data. Deleted data remains in our backup copies for up to eight weeks, until these copies are overwritten as scheduled.
Sign-in takes place via a link that we send by email. The link is valid for 20 minutes and can be used only once;
only a checksum is stored, not the link itself. If you wish, you can additionally set a password;
we store it only as a non-reversible hash (scrypt with a random salt), never in plain text. After five
failed attempts, signing in with a password is blocked for 15 minutes; if a password is set or changed,
we notify you by email. After sign-in, we set a
session cookie (esw_sitzung, 30 days, only over encrypted connections, not readable by scripts).
It is technically necessary for sign-in (§ 25(2) no. 2 TDDDG) and contains no tracking identifier.
To prevent anyone from flooding other people’s mailboxes with sign-in emails, we limit the number of sign-in links per email address and per connection. For this purpose, we store the fingerprint of the IP address with each request (see section 3) for 24 hours. The legal basis is Art. 6(1)(f) GDPR (protection against misuse).
4a. Emails
We send sign-in links, invitations, — unless you unsubscribe from it — the weekly report and — only if you switch them on — instant alerts on new legislative steps via our mailbox at Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland. An adequacy decision of the European Commission exists for Switzerland. The legal basis is Art. 6(1)(b) GDPR.
4b. Payments
If you take out a paid subscription, Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland, processes the payment. You enter your payment details directly with Stripe; we do not receive them, but only a customer identifier, the status of the subscription and the invoice data. The legal basis is Art. 6(1)(b) and (c) GDPR (contract, retention obligations under tax law). We retain invoices and accounting records for eight years (§ 147 AO). Stripe may transfer data to the USA; for this, the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework apply.
5. Settings in the browser
If you switch between the light and dark appearance, your browser stores this choice locally
(localStorage, entry “theme”). This information does not leave your device. No tracking,
analytics or marketing cookies and no external font or analytics services are used.
6. Personal data in the analysed sources
The analysed sources contain names: members of parliament, parliamentary groups and ministries in parliamentary documents of the Deutscher Bundestag (German Federal Parliament) (DIP) of the state parliaments (so far Brandenburg), of the Austrian and of the UK Parliament (movers and sponsors of bills), institutions and procedures of EU legislation (EUR-Lex, European Parliament), authors and their institutions in scientific publications (OpenAlex), persons in headlines of online articles, and posts on the social network Bluesky. Federal funding programmes and funding calls of the European Commission generally contain no personal data. We store this information as it was publicly published, together with the source and time of retrieval, and use it exclusively to analyse topics over time and to be able to substantiate every statement back to its source. No profiles of persons are created. Creating topics about individual private persons is prohibited under our Terms and Conditions; topics about public officials and public figures in their public role are permitted.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the traceable analysis of public information. The data is stored for as long as the respective time series is maintained. Notifying the persons named individually (Art. 14 GDPR) would involve a disproportionate effort (Art. 14(5)(b) GDPR); this policy serves to provide information. You may object at any time (section 8).
6a. Posts on Bluesky
We analyse German-language posts from Bluesky’s public data stream. Posts by private individuals are only counted: we store neither text nor account, but for each topic merely a checksum of the post address, so that a post is not counted twice and can be subtracted if deleted. We delete these checksums after 30 days; only the number of posts per week is kept permanently. Only posts from public accounts of authorities, parties, parliamentary groups, media, associations and research institutions that appear under their own web address are stored with text and link and displayed as evidence. If a post is deleted on Bluesky, we delete it on our side as well. The legal basis is Art. 6(1)(f) GDPR.
6b. Online media (GDELT)
We obtain German-language online articles from the public article list of the GDELT Project (gdeltproject.org): headline, teaser, address and time. We match them against the topics in working memory only. For each topic and week, we store a checksum of the headline (for counting) and, as evidence, at most ten articles with outlet, date and address. We store and display headlines only from publishers that have not objected to their use; we never store teasers. Only for these publishers do we retain the article list for 32 weeks and delete it thereafter; we delete checksums of all headlines for the total number per week after two weeks. The legal basis is Art. 6(1)(f) GDPR.
7. Recipients
The only recipients are the service providers named: Cloudflare (section 3), Proton (4a) and, for subscriptions, Stripe (4b). Beyond this, no data is transferred to third parties. Backup copies are kept on storage devices owned by Atlaxis Digital Services GmbH, not with third parties. We do not use any third-party AI services; counts, topic assignments and regions are produced by rule-based analysis on our own server.
7a. No automated decisions
We do not make any automated decisions within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
8. Right to object
Where we process data on the basis of Art. 6(1)(f) GDPR (sections 3, 4, 6, 6a and 6b), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds that override your interests. An informal message to [email protected] is sufficient.
9. Your further rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20). To exercise these rights, please contact [email protected].
You may also lodge a complaint with a data protection supervisory authority, for example with the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg).