Privacy policy

This policy explains how VEHI Digital UG (haftungsbeschränkt) processes personal data when you use the HeyOlaf website and application.

Last updated: 29 September 2026

Controller

VEHI Digital UG (haftungsbeschränkt)

Am Pichelssee 58

13595 Berlin

Germany

No data protection officer is appointed. Privacy questions go to: info@heyolaf.com

What this covers

HeyOlaf is a workspace for projects, tasks, documents, files, team chat, and the assistant Olaf. Olaf only proposes. The application writes a change after a person confirms it.

Data we process

Depending on what you use, we process account data, session data, workspace content, invitations, notifications, contact-form messages, billing data, prompts sent to Olaf, and — only with consent — usage and advertising data. If you connect Google Calendar or Outlook, we also store the titles and times of the calendars you choose to show.

Legal bases

  • Contract (Art. 6 (1) (b) GDPR): account, workspace, invitations, support, and Olaf when you use the assistant.
  • Legal duty (Art. 6 (1) (c) GDPR): keeping invoices and accounting records.
  • Legitimate interest (Art. 6 (1) (f) GDPR): secure operation, abuse prevention, and the session list. You can object where your particular situation outweighs that interest.
  • Consent (Art. 6 (1) (a) GDPR and § 25 TDDDG): statistics, marketing cookies, and product email. You can withdraw consent at any time with effect for the future.

Account and session

An account needs a name and email address. With email and password we store the password only as a hash. If Google or Microsoft is offered on the sign-in page, you can create the account that way. We then take the name and email from the provider and do not receive its password. For a password account, the email must be verified before a workspace can be used. The session cookie better-auth.session_token lasts up to seven days. With the session we store IP address and browser so you can see active sessions in settings. Language is kept in the NEXT_LOCALE cookie for the browser session and, once you are signed in, on your profile.

Workspace content

Projects, tasks, comments, chat, documents, and files are visible to people who can open that workspace. We keep an audit log of administrative organization actions. Files are private. Downloads use short-lived signed links. You can create a personal calendar link. Anyone with the link can read those events. You can rotate the link in settings. Content in a shared workspace stays with the organization after you delete your account. We delete the profile and the membership.

Hosting and storage

When you open HeyOlaf, the host processes the data needed to serve the page: IP address, date and time, requested address, browser, and sometimes the previous page. The application, PostgreSQL database, and private file storage run at Hetzner Online GmbH in the EU, on the server in Nuremberg. Optional statistics and marketing scripts load only after you opt in. The domain is resolved through Vercel DNS. Vercel does not serve the application.

Email and contact

Verification, password reset, invitations, notifications, and contact requests are sent by Postmark (ActiveCampaign, LLC, USA). The contact form sends name, email, an optional company name, and the message. The legal basis is the contract or our interest in answering the request.

Product email

Product updates are sent only after a separate double opt-in. The confirmation link is valid for 48 hours. This consent is independent of the account. You can withdraw it from the unsubscribe link or by emailing us.

Payment

Personal subscriptions are billed to the account. Team subscriptions are billed to the organization. Stripe processes the payment. We do not store full card numbers. Included Olaf credits reset monthly. Purchased credit packs remain until they are used.

Assistant Olaf

Olaf is optional. A request leaves HeyOlaf only when someone uses the assistant in a workspace that person is allowed to open. The server assembles context from that access: names, projects, tasks, comments, and document text. If a calendar is connected, that request can include those event titles and times. The recipient is the IONOS AI Model Hub of IONOS SE in Germany, Berlin region. That call does not go to OpenAI. Olaf proposes. The application writes nothing until a person confirms.

Connected calendars

Connecting Google Calendar or Outlook is optional. HeyOlaf only reads the calendars you select. Refresh tokens are stored encrypted. We keep event titles and times, not descriptions, attendees, or meeting links. The same titles and times can be included when you ask Olaf a question, and then go to IONOS in Germany. Disconnecting a calendar deletes that account and its cached events. Deleting your HeyOlaf account does the same.

Cookies

Necessary cookies are always on. Statistics and marketing stay off in the European Economic Area, the United Kingdom, Switzerland, and when the country is unknown, until you allow them. In a recognized country outside those regions they may run without a notice until you change the choice. The choice is stored for 180 days in the heyolaf_consent cookie. You can change or withdraw it at any time from Cookie settings, in the site footer, and in account settings.

Theme (light, dark, or system) is stored in the browser’s local storage under the key theme, and on your profile. It is not a cookie.

  • heyolaf_consent

    Stores your statistics and marketing choice. 180 days. Necessary.

  • better-auth.session_token

    Keeps you signed in. 7 days. Necessary.

  • NEXT_LOCALE

    Remembers the website language. Browser session. Necessary.

  • _ga

    Distinguishes visitors for Google Analytics. 2 years. Statistics.

  • _ga_*

    Keeps Google Analytics 4 session state. 2 years. Statistics.

  • _gcl_au

    Measures ad clicks for Google Ads. 3 months. Marketing.

  • _fbp

    Recognizes the browser for the Meta pixel. 3 months. Marketing.

Google Tag Manager and Google Analytics

Google Analytics 4 measures how HeyOlaf is used: pages, approximate region, device, browser, and interactions. Google Tag Manager loads that measurement and can fire further tags. The container loads, but Consent Mode is denied first. analytics_storage is granted only after statistics consent. The legal basis is consent.

Google Ads and Meta

Google Ads and the Meta pixel measure advertising. They may set cookies and build an ad profile only after marketing consent sets ad_storage, ad_user_data, and ad_personalization to granted. Without Google Tag Manager, the Meta pixel loads only after that consent. With Google Tag Manager, the container receives the pixel ID and may fire Meta only with the same consent.

Google Search Console

We confirm site ownership with a meta tag for Google Search Console. The tag sets no cookie and sends no visitor profile. Google may still fetch public pages as a search engine.

Recipients

Data goes to these parties when the step needs them. The links open their own notices.

Countries outside the EU

IONOS and Hetzner process data in the EU. Postmark, parts of Stripe, Google, Microsoft, and Meta may process data in the United States. That relies on the European Commission’s standard contractual clauses. Where a provider is certified under the EU-US Data Privacy Framework, we also rely on that certification. You can ask for a copy of the safeguards at the privacy address.

Retention

We keep account data until you delete the account or the contract ends. Sessions end after seven days at the latest, or when you sign out. Team content stays while the organization keeps it. Product-email confirmation links expire after 48 hours. The cookie choice lasts 180 days. We keep invoices for the statutory period, usually ten years. Server logs are deleted once they are no longer needed for operation and security. Olaf threads live in the workspace and are deleted with it.

Your rights

You can request access, correction, deletion, restriction, and portability, and you can object to processing based on legitimate interest. You can withdraw consent with effect for the future. In settings you can export a copy of your account data and delete the account. If you are the only owner of an organization that still has other members, ownership has to be transferred first.

Complaint

You can lodge a complaint with a supervisory authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin, Germany. datenschutz-berlin.de

Required data

Email and password are required to create an account. Statistics, marketing, and product email are optional. HeyOlaf works without them.

Automated decisions

There is no solely automated decision that produces a legal effect or similarly significant impact. Olaf proposes. A person decides.

Cookies

We use necessary cookies for the session and language. Statistics and marketing stay off until you allow them. Privacy