We take the protection of your personal data very seriously. This Privacy Policy explains what data we collect and how we process and use it in accordance with the European General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Controller
The controller responsible for the data processing on this website is:
upspawn software UG (haftungsbeschränkt)
Liebigstr. 1C
10247 Berlin
Deutschland
E-Mail: support@renamed.to
2. Data we collect
We collect and process the following categories of data:
2.1 Account and Contact Data
- Name and email address (for account creation and communication)
- Payment information (processed securely through Stripe)
- Account preferences and settings
2.2 Content and Usage Data
- Uploaded files and their metadata (names, sizes, types)
- File processing requests and AI-generated suggestions
- Usage patterns and feature interactions
- Access logs and timestamps
2.3 Technical Data
- IP address and device information
- Browser type, version, and language settings
- Operating system and screen resolution
- Cookies and similar tracking technologies (see Section 5)
3. Purpose of processing
We process your data for the following purposes:
3.1 Essential Services
- Provision of file renaming and AI-powered suggestions
- Account management and authentication
- File storage and retrieval
- Payment processing and billing
- Customer support and technical assistance
3.2 Security and Compliance
- Fraud prevention and security monitoring
- Compliance with legal obligations
- Protection of our systems and users
3.3 Improvement and Analytics (with consent)
- Service analytics and performance monitoring
- User experience optimization
- Product development and feature enhancement
4. Legal basis
We process your personal data on the basis of the following legal grounds according to Art. 6 GDPR:
- Art. 6 para. 1 lit. b GDPR – performance of a contract or steps prior to entering into a contract (account services, file processing)
- Art. 6 para. 1 lit. f GDPR – legitimate interests (security, fraud prevention, service improvement)
- Art. 6 para. 1 lit. a GDPR – your consent (analytics, marketing communications)
- Art. 6 para. 1 lit. c GDPR – compliance with a legal obligation (tax records, data retention requirements)
5. Cookies & tracking technologies
5.1 Essential Cookies (Always Active)
These cookies are essential for the website to function and cannot be disabled:
- Authentication cookies – Keep you logged in to your account
- Security cookies – Protect against fraud and unauthorized access
- Preference cookies – Remember your settings and choices
5.2 Analytics Cookies (Optional)
With your consent, we use analytics services to understand how our service is used:
- PostHog – Privacy-focused analytics to improve user experience
- Usage tracking – Anonymous data about feature usage and performance
5.3 Cookie Management
You can manage your cookie preferences at any time through our cookie banner or by contacting us. Disabling analytics cookies will not affect the functionality of our service.
6. Third-party services & data processors
We work with carefully selected service providers to deliver our services. All processors are bound by data processing agreements according to Art. 28 GDPR:
6.1 Essential Service Providers
Polar (Payment Processing)
Processes payments securely as our Merchant of Record. Data processed: Payment information, billing address.
Privacy policy: polar.sh/legal/privacy
Cloudflare R2 (File Storage)
Stores your uploaded files securely. Data processed: Files and metadata.
Privacy policy: cloudflare.com/privacypolicy
Mistral AI (AI Processing)
Alternative AI provider for file processing. Data processed: File names and metadata.
Privacy policy: mistral.ai/terms#privacy-policy
6.2 Optional Analytics Services
PostHog (Analytics)
Privacy-focused analytics service (only with your consent). Data processed: Anonymous usage data.
Privacy policy: posthog.com/privacy
7. International data transfers
Some of our service providers are located outside the European Economic Area (EEA). We ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Approved certification mechanisms
- Binding corporate rules where applicable
8. Data retention
We retain personal data only as long as necessary:
- Account data: Until account deletion plus 30 days for security
- Files: As long as stored by you, plus 30 days after deletion
- Payment data: 10 years for tax compliance (processed by Polar)
- Analytics data: 25 months maximum (anonymized)
- Support communications: 3 years for service improvement
9. Your rights under GDPR
You have the following rights:
- Access (Art. 15): Request copies of your data
- Rectification (Art. 16): Correct inaccurate data
- Erasure (Art. 17): Request deletion of your data
- Restriction (Art. 18): Limit how we process your data
- Portability (Art. 20): Receive your data in portable format
- Object (Art. 21): Object to processing for legitimate interests
- Withdraw consent: For consent-based processing
- Complaint (Art. 77): Lodge complaint with supervisory authority
To exercise these rights, contact us at support@renamed.to. We will respond within 30 days.
10. Data security
We implement appropriate technical and organizational measures:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication
- Employee training on data protection
- Incident response procedures
11. Contact & data protection officer
For questions about this Privacy Policy, data protection, or to exercise your rights:
12. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or through our service. Continued use after changes constitutes acceptance of the updated policy.
Last updated: 15 June 2025
Effective date: 05/07/2025