Effective August 19, 2026 · Version 1.2
Privacy policy
This policy explains what we process when you visit supercenter.dev, create a workspace, connect an agent, or request public web and social data.
1. Controller and contact
The controller for account, billing, website, and business-administration data is Nikolaus Redl, trading as Supercenter, Kleistgasse 18/41, 1030 Vienna, Austria. VAT ID: ATU82884407.
Privacy and security requests: security@supercenter.app. We have not appointed a data protection officer because our current activities do not meet the mandatory appointment criteria; the address above remains the direct privacy contact.
2. Our role for customer data
For account, payment, security, and website data, we act as an independent controller. When a business customer uses the service to retrieve, enrich, or process data for its own purposes, that customer determines the purpose and legal basis and we normally act as its processor. Customer instructions include requests made through the dashboard, REST API, MCP, CLI, or a connected AI agent.
Our Data Processing Agreement sets out the Article 28 terms, security measures, and authorized subprocessors for that customer-directed processing.
3. Data, purposes, and lawful bases
Account and profile
Name, email address, avatar, authentication-provider identifiers, organization, and workspace membership.
Why: Create and secure your account, provide workspace access, and communicate about the service.
Legal basis: Contract (Art. 6(1)(b) GDPR) and legitimate interests in account security (Art. 6(1)(f)).
Authentication and security
One-time-code records, session identifiers, OAuth grants, API-key metadata, IP address, device/browser data, and security events.
Why: Authenticate users and agents, prevent abuse, investigate incidents, and enforce access controls.
Legal basis: Contract and legitimate interests in protecting the service and its users.
Workspace and capability data
Onboarding answers, tool and capability inputs, normalized outputs, source URLs, raw provider responses, execution records, and workspace settings. An MCP connector does not give us the agent's conversation history, memory, or files.
Why: Set up the workspace, understand the requested work, perform the request, return sourced results, support retries, meter usage, and troubleshoot failures.
Legal basis: Contract. For customer-controlled personal data, we normally act as processor on the customer’s documented instructions.
Public-source data
Publicly available names, professional information, company information, public profiles, posts, comments, pages, products, advertisements, and related source metadata.
Why: Return the public web, people, company, news, social, advertising, and marketplace data requested by a customer.
Legal basis: Customer instructions where we act as processor; otherwise legitimate interests in providing a public-data retrieval service, subject to necessity and balancing.
Usage, credits, and billing
Plan, subscription status, credit grants and debits, request identifiers, Stripe customer/subscription references, invoices, and payment status. We do not store complete card numbers.
Why: Process credit purchases, charge for the service, prevent duplicate charges, and maintain accounting records.
Legal basis: Contract and legal obligations, including tax and accounting duties (Art. 6(1)(c)).
Support and service messages
Emails, support requests, invitations, feedback, and delivery metadata.
Why: Respond to you, deliver essential service messages, and improve reliability.
Legal basis: Contract and legitimate interests in customer support and product quality.
Optional analytics and marketing
Pseudonymous online identifiers, hashed normalized email addresses, page views, onboarding response events and values, browser/device information, IP address, campaign parameters, conversion events, and masked session replay. Replay masks all text and inputs and excludes request headers and bodies. Consent snapshots and encrypted attribution data can support server-side conversion delivery.
Why: Understand product performance and measure marketing campaigns.
Legal basis: Consent where required, including for visitors identified as being in Europe. Legitimate interests and an opt-out model apply where local rules permit.
Providing core account, workspace, capability, and billing data is necessary to enter into or perform the service contract. Without it, we cannot provide the requested service. Optional analytics and marketing consent is never required to use the site or product.
4. Data obtained from public sources
Capability results can contain personal data that was not collected directly from the person concerned. It may originate from publicly accessible websites, search results, company websites, professional profiles, social networks, marketplaces, advertisement libraries, and the public pages or APIs of those services. The categories are described in section 3.
We disclose that data to the customer who requested it and to the technical providers needed to execute the request. When we act only as a processor, the customer is responsible for any notice required by Article 14 GDPR. If you believe a result contains inaccurate or unlawfully processed personal data, email security@supercenter.app with the source URL and enough information for us to locate it.
5. Recipients and service providers
We share data only where needed to provide, secure, measure, or charge for the service; when you instruct us to; or when law requires it. Our intended launch providers are listed below. A provider is used only when its related feature is configured or requested.
- Purpose:
- Website hosting, serverless execution, content delivery, private object storage, and operational logs
- Data:
- Network and request data, account and workspace data, capability payloads stored as private objects
- Role and location:
- Processor; United States and other Vercel processing locations.
- Safeguards:
- DPA, EU Standard Contractual Clauses, and other transfer safeguards where applicable.
- Purpose:
- Managed PostgreSQL database
- Data:
- Account, workspace, authentication, onboarding, usage, credit, billing, and execution records
- Role and location:
- Processor; Selected hosting region; support may involve other locations.
- Safeguards:
- DPA and EU Standard Contractual Clauses where applicable.
- Purpose:
- Transactional email, including sign-in codes, invitations, and service messages
- Data:
- Recipient address, email content, and delivery metadata
- Role and location:
- Processor; United States and subprocessor locations.
- Safeguards:
- DPA and EU Standard Contractual Clauses.
- Purpose:
- Checkout, subscriptions, invoices, payment methods, and fraud prevention
- Data:
- Customer and billing identifiers, transaction details, tax and payment information
- Role and location:
- Processor and, for certain regulated payment activities, independent controller; European Economic Area, United States, and Stripe group locations.
- Safeguards:
- Stripe data-processing terms and applicable transfer safeguards.
- Purpose:
- Google sign-in and, only with consent, website analytics and campaign measurement
- Data:
- Sign-in profile chosen by the user; for analytics, online identifiers, device/browser data, approximate location, and site activity
- Role and location:
- Independent controller for sign-in; processor for Google Analytics; roles may vary for advertising services; European Economic Area, United States, and Google processing locations.
- Safeguards:
- Google data-processing terms and applicable transfer safeguards.
- Purpose:
- Optional GitHub sign-in
- Data:
- GitHub account identifier, profile name, avatar, and email address within the scopes shown during authorization
- Role and location:
- Independent controller for GitHub's platform and sign-in processing; United States, the Netherlands, and GitHub processing locations.
- Safeguards:
- GitHub privacy terms, EU–US Data Privacy Framework certification, and applicable transfer safeguards.
Meta Platforms Ireland
Provider privacy information- Purpose:
- Meta Pixel campaign measurement and advertising, only with marketing consent
- Data:
- Online identifiers, browser/device data, page visits, and conversion events
- Role and location:
- Processor for certain measurement services and joint or independent controller for other Meta Business Tools processing; Ireland, United States, and Meta processing locations.
- Safeguards:
- Meta Business Tools Terms, Controller Addendum, and applicable transfer safeguards.
PostHog
Provider privacy information- Purpose:
- Product analytics and masked session replay, only with analytics consent
- Data:
- Pseudonymous identifiers, browser/device data, page and feature interactions, masked screen structure, and diagnostic events. Replay masks all text and inputs and excludes request headers and bodies
- Role and location:
- Processor; European Union cloud region for the intended production configuration.
- Safeguards:
- PostHog DPA and EU-hosted processing configuration.
LinkedIn Ireland
Provider privacy information- Purpose:
- Campaign attribution and conversion measurement, only with marketing consent
- Data:
- Hashed email address, advertising click identifier, browser/device data, and conversion events
- Role and location:
- Independent controller or processor, based on the LinkedIn service; Ireland, United States, and LinkedIn processing locations.
- Safeguards:
- LinkedIn data terms and applicable transfer safeguards.
TikTok Technology
Provider privacy information- Purpose:
- Campaign attribution and conversion measurement, only with marketing consent
- Data:
- Hashed email address, advertising identifiers, browser/device data, and conversion events
- Role and location:
- Independent controller or processor, based on the TikTok service; European Economic Area, United States, and TikTok processing locations.
- Safeguards:
- TikTok Business Products terms and applicable transfer safeguards.
Exa Labs
Provider privacy information- Purpose:
- Web, people, company, and news search and retrieval
- Data:
- Queries, requested fields, source URLs, returned public-source content, and technical request metadata
- Role and location:
- Processor or service provider for business API requests under the applicable customer agreement; United States and Exa subprocessor locations.
- Safeguards:
- Customer agreement and applicable international-transfer safeguards.
ScrapeCreators (Web Scraping Guy LLC)
Provider privacy information- Purpose:
- Public social-network, advertisement, and related API retrieval
- Data:
- Queries, public profile or content identifiers and URLs, returned public-source content, IP address, and request metadata
- Role and location:
- External service provider; the contractual data-protection role depends on the requested endpoint and applicable agreement; United States and service-provider locations.
- Safeguards:
- Provider terms; an Article 28 agreement and transfer safeguards must be completed where required.
Apify Technologies
Provider privacy information- Purpose:
- Fallback public-site extraction and execution of selected data-retrieval actors
- Data:
- Actor inputs, source URLs, requested public content, actor outputs, and technical request metadata
- Role and location:
- Processor for customer-directed actor execution; some actor creators can have a separate role; Czech Republic and Apify subprocessor locations.
- Safeguards:
- Apify Data Processing Addendum and EU Standard Contractual Clauses where applicable.
The retrieval-provider rows identify the current vendors that may receive a query, source URL, requested fields, public-source content, and technical request metadata when the related capability is used. We do not sell customer content or capability results.
6. International transfers
Some providers process data outside the European Economic Area. Where the destination does not benefit from an EU adequacy decision, we use an available lawful transfer mechanism such as the European Commission’s Standard Contractual Clauses, together with contractual, technical, and organizational safeguards. Some providers also participate in the EU–US Data Privacy Framework for eligible transfers. You may request information about the relevant safeguards from our privacy contact.
7. Retention
- Account, workspace, and membership records: while the account or workspace remains active, then normally up to 30 days after verified deletion, subject to backups and legal exceptions.
- Authentication sessions: up to seven days; OAuth and one-time-code records use shorter security-driven periods.
- Capability inputs, normalized outputs, and private raw provider responses: retained for the workspace so results can be supported and audited; there is currently no routine automatic expiry. They are removed with workspace deletion or a valid deletion request, unless a legal hold applies.
- Usage, credit, fraud-prevention, and operational records: for as long as needed to operate and defend the service, generally the account term plus applicable limitation periods.
- Invoices, transactions, and tax records: for the statutory accounting period, which can be up to ten years in Austria.
- Optional analytics and advertising data: according to the configured provider retention and your consent; expected browser-storage periods appear in the cookie policy.
We may retain a minimal suppression record after an opt-out so we can continue to respect it.
8. Security
We use transport encryption, provider-managed encryption at rest, hashed API keys and one-time codes, scoped authorization, workspace isolation, restricted production access, request validation, billing idempotency, and operational monitoring. No service can guarantee absolute security. If you believe credentials or data have been exposed, contact security@supercenter.app promptly.
9. Your rights
Subject to the GDPR’s conditions and exceptions, you may request access, correction, deletion, restriction, portability, or information about recipients. You may object to processing based on legitimate interests and at any time object to direct marketing. You may withdraw consent at any time without affecting processing already carried out lawfully.
Send requests to security@supercenter.app. We may need to verify your identity and normally respond within one month. Where we act for a customer, we will forward or refer the request to that customer.
You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, at dsb.gv.at, or to the authority in your habitual residence, workplace, or place of the alleged infringement.
10. Cookies, pixels, and consent
Necessary authentication and security storage operates without an optional choice. For visitors identified as being in Europe, PostHog, Google Analytics, Google advertising tools, and Meta Pixel remain off until the relevant consent category is granted. Outside Europe, they can start by default where local rules permit. Rejecting optional technologies does not prevent account creation or product use. Use “Privacy choices” in the footer to change or withdraw consent. Global Privacy Control is treated as a decline. Details are in our cookie policy.
11. Automated decisions and children
We do not make decisions about website visitors or account users that produce legal or similarly significant effects based solely on automated processing. The service is intended for business users aged 18 or older and is not directed to children.
12. Changes
We update this policy when our processing changes. Material changes will be highlighted in the service or sent to the account email where appropriate. The effective date and version at the top identify the current notice.
The transparency requirements reflected here follow Articles 13 and 14 of the EU General Data Protection Regulation.