Legal

Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains how OBELUS GmbH ("we", "us") processes personal data in connection with the Mapper Studio service and website. It applies alongside our Terms & Conditions.

1. Controller

The controller under Art. 4(7) GDPR is:
OBELUS GmbH · Westerhamer Weg 30 · 82024 Taufkirchen · Germany
Email: tomas.langara@obelus.de
Managing Director: Tomas Langara.

2. Categories of data processed

  • Account data: name, work email address, organization, role, and authentication credentials.
  • Contact data: information you provide via the contact form or email correspondence.
  • Technical/log data: IP address, user agent, request timestamps, referrer, and diagnostic logs necessary to operate and secure the service.
  • Uploaded data payloads and mappings: content you upload, transform, or send through Mapper Studio, processed strictly to perform the transformations you configure.
  • Usage data: product events (mapper created, test executed, publish attempt) used for operations and product improvement.

3. Purposes and legal bases

  • Providing the Mapper Studio service and fulfilling our contract with you (Art. 6(1)(b) GDPR).
  • Responding to inquiries and pre-contractual requests (Art. 6(1)(b) GDPR).
  • Operating, securing, and improving the service, preventing abuse and fraud (Art. 6(1)(f) GDPR, legitimate interests).
  • Complying with legal obligations such as tax and accounting law (Art. 6(1)(c) GDPR).
  • Where required, on the basis of your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.

4. Cookies and similar technologies

The website uses strictly necessary cookies and local storage entries to provide core functionality such as authentication, session handling, and theme preferences. We do not use tracking or advertising cookies. Where analytical or non-essential cookies are introduced, we will request your prior consent through a cookie banner.

5. Hosting and processors

The service is hosted with reputable European and international cloud infrastructure providers acting as processors on our behalf under Art. 28 GDPR. A current list of subprocessors is available on request. We have entered into data processing agreements with all processors and require appropriate technical and organizational measures.

6. Recipients

Personal data is disclosed only to (i) employees of OBELUS GmbH bound by confidentiality, (ii) processors acting on our documented instructions, (iii) professional advisors, and (iv) authorities where legally required. We do not sell personal data.

7. International transfers

Where personal data is transferred outside the EU/EEA, we rely on adequacy decisions or on the EU Standard Contractual Clauses together with supplementary technical measures, in accordance with Chapter V GDPR.

8. Retention

We retain personal data only as long as necessary for the purposes for which it was collected: account data for the duration of your subscription and thereafter as required by statutory retention periods (typically 6–10 years under German commercial and tax law); technical/log data typically for up to 90 days; uploaded data payloads according to your plan's retention settings.

9. Data security

We apply technical and organizational measures appropriate to the risk, including TLS encryption in transit, encryption at rest for secrets, SHA-256 hashing of outbound delivery secrets (never stored in plaintext), environment-variable secret injection in production, access controls based on the principle of least privilege, and continuous logging and monitoring.

10. Your rights

Subject to the conditions of the GDPR, you have the right to:
  • Access your personal data (Art. 15).
  • Rectification of inaccurate data (Art. 16).
  • Erasure (Art. 17).
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time, without affecting prior processing.
  • Lodge a complaint with a supervisory authority (Art. 77). In Germany, the competent authority for OBELUS GmbH is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht).
Requests can be sent to tomas.langara@obelus.de.

11. Automated decision-making

We do not use your personal data for automated decision-making with legal or similarly significant effect within the meaning of Art. 22 GDPR.

12. Updates to this policy

We may update this Privacy Policy to reflect changes in our services or in applicable law. Material changes will be announced in-app or by email in reasonable time before they take effect.