Privacy Policy
thalas GmbH – thalas extract
Non-binding English translation for information purposes only. In case of any discrepancy, the German version prevails.
1. Controller and Contact
The controller responsible for data processing on this website and within the application within the meaning of the General Data Protection Regulation (GDPR) is:
thalas GmbH, Barckhausstraße 13, 60325 Frankfurt am Main, Germany
Email: contact@thalas.ai
2. Subject Matter and Legal Bases
This policy concerns personal data, i.e., information relating to an identified or identifiable natural person (e.g., name, email address, IP address). It explains how we process such data in connection with our web-based Excel Add-in thalas extract and our website.
Unless stated otherwise below, processing is based on the following legal grounds: the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), or the safeguarding of our legitimate interests (Art. 6(1)(f) GDPR). The applicable basis is stated for each processing activity.
3. Hosting and Server Location (Vercel)
Hosting. Our website and the application infrastructure are hosted with Vercel Inc. The legal basis is Art. 6(1)(b) and (f) GDPR (secure and efficient provision of our services).
Data residency. Our infrastructure is configured so that your content is processed in the Frankfurt am Main, Germany region. This also applies to the AI-based extraction, which we have restricted to processing within the European Union (Frankfurt region; see Section 4).
Transfers to the USA. Vercel Inc. is a US company. Insofar as personal data is transferred to the USA or access from the USA is possible, the transfer is based on the EU Standard Contractual Clauses (Art. 46 GDPR) and/or the provider’s certification under the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR).
Security. Data transmission is always encrypted (TLS/SSL).
4. Data Processing by thalas extract
Local processing in the browser. The documents you open (e.g., financial statements in PDF format) are processed locally in your browser and are not transmitted to our servers. Only the table sections you select (image excerpts) are transmitted to and processed by us in order to extract structured data using artificial intelligence. The legal basis is the performance of the usage contract concluded with you (Art. 6(1)(b) GDPR).
AI processing used. The extraction is carried out via the Google Gemini service (model gemini-2.5-flash; provider: Google Ireland Limited, Ireland, or Google LLC, USA), which we use through Google Cloud Vertex AI. For this purpose, the table sections you select are transmitted to and processed by Google. We have restricted the processing to the Frankfurt region (europe-west3) within the European Union. Google acts as our processor; a data processing agreement pursuant to Art. 28 GDPR is in place. As Google belongs to a US group and access from a third country cannot be entirely ruled out, any transfer of data to third countries is additionally safeguarded by the EU Standard Contractual Clauses (Art. 46 GDPR).
No AI training. We warrant that the transmitted table sections and the content extracted from them are not used to train, improve, or fine-tune any AI models. We have also secured this contractually with Google.
Real-time processing and deletion. We hold the transmitted table sections in memory only for the duration of the extraction process; immediately after processing is completed, they are deleted and are not stored. Your document itself remains in your browser and is never transmitted to our servers. Insofar as table sections are transmitted to Google for extraction, their processing and storage are governed by the data processing agreement concluded with Google.
5. Login via Microsoft 365 (Single Sign-On) and User Account
You log in to the Add-in via single sign-on (SSO) with your Microsoft 365 account.
Login process. Authentication takes place entirely within your company’s Microsoft environment (tenant); Office/Excel issues an access token for this purpose. We do not log in to Microsoft ourselves; we merely receive the issued token and validate it in our backend. For the login, we use our own Azure app registration with the permissions (scopes) “openid” and “profile”. As the login takes place within your own Microsoft tenant, Microsoft is not a processor of ours in this respect.
Data processed and purpose. From the token, we process the identity data it contains (name, email address, Microsoft user ID) for access control and to assign it to your user account. The legal basis is the performance of the usage contract (Art. 6(1)(b) GDPR).
User account. We create a permanent user account for you and store in it: email address, Microsoft user ID, subscription status, creation date, and – in the event of a payment – the Stripe customer ID. This data is used for recognition at login, license and status management, and billing. The account data is stored with our service provider Supabase (see Section 10).
Retention period. The account data is stored for the duration of the contractual relationship and deleted after it ends, unless statutory retention periods apply (see Section 9).
6. Server Log Files
When our website and application are accessed, the hosting provider records access data in server log files for technical reasons (including IP address, date and time of access, resource requested, volume of data transferred, user agent). This processing serves the security, stability, and error analysis of the service; the legal basis is Art. 6(1)(f) GDPR. The log data is deleted after a short period unless it is exceptionally required to investigate a specific incident.
7. No Cookies
We do not use any cookies on our website – neither technically necessary cookies nor third-party tracking or advertising cookies. Please note: “cookieless” does not mean that no data is processed; the processing activities described in this policy (in particular Section 6) remain unaffected.
8. Payment Processing (Stripe)
We use the payment service provider Stripe to handle subscriptions. When you make a payment, your billing and payment data are transmitted directly to Stripe; we have no access to full credit card data. The processing is carried out for the performance of the contract (Art. 6(1)(b) GDPR) and in accordance with the security standards of the credit card industry (PCI DSS). Insofar as Stripe transfers data to the USA, this is based on the EU Standard Contractual Clauses (Art. 46 GDPR) and/or certification under the EU-US Data Privacy Framework.
9. Contract and Billing Data, Retention Periods
In addition to the account data referred to in Section 5, we process contract and billing data to handle your subscription. The legal basis is Art. 6(1)(b) GDPR and, with regard to retention, Art. 6(1)(c) GDPR. We retain invoices and accounting-relevant records due to commercial and tax law obligations (in particular Section 257 HGB, Section 147 AO) for the statutory periods of up to ten years. After the respective periods expire, the data is deleted.
10. Recipients and Processors
To provide our services, we use carefully selected service providers that act as processors for us pursuant to Art. 28 GDPR. These are in particular:
- Vercel Inc. – hosting and infrastructure;
- Stripe – payment processing;
- Supabase – hosting of the user account database (processing in the EU/Frankfurt region; the account data does not leave the EU);
- Google – AI-based data extraction (Google Gemini via Google Cloud Vertex AI; processing in the EU/Frankfurt region, see Section 4).
Data processing agreements are in place with these service providers. Insofar as personal data is transferred to third countries (in particular the USA) in this context, the safeguards referred to in this policy apply (EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework). Disclosure to other third parties only takes place where this is legally permissible or required.
11. Your Rights
Under the GDPR, you have in particular the following rights:
- access to the data processed about you (Art. 15 GDPR);
- rectification of inaccurate data (Art. 16 GDPR);
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR);
- withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).
Right to complain. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Wiesbaden.
12. Contact
If you have any questions about the collection, processing, or use of your personal data, or about exercising your rights, please contact:
thalas GmbH, Barckhausstraße 13, 60325 Frankfurt am Main, Germany
Email: contact@thalas.ai