Privacy Policy
Information obligations pursuant to Art. 13 GDPR
1. Controller
The controller within the meaning of the GDPR and other national data protection laws is:
Buzzmatic GmbH & Co. KG
Schönhauser Allee 149, 10435 Berlin, Germany
Represented by its managing directors Raoul Schreck and Oguzhan Kalkan
E-mail: hello@vericlaim.eu
No data protection officer has been appointed. There is currently no obligation to appoint one under Art. 37 GDPR or § 38 BDSG, as fewer than 20 people are regularly engaged in the automated processing of personal data and no large-scale processing of special categories of data takes place. For any data protection enquiries, please use the contact address above.
2. Purpose of processing
VeriClaim is an AI-assisted service for the preliminary screening of health and cosmetic claims for conformity with the European Health Claims Regulation (EC 1924/2006), the Cosmetics Regulation (EC 1223/2009) and the common criteria under Regulation (EU) 655/2013. We process personal data in order to provide the user account, carry out the screenings requested and bill the scan credits used.
3. Legal basis
Processing takes place on the basis of Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest in a secure and functional service).
4. Data we process
- Account data: e-mail address, encrypted password, role (user, organisation admin, platform admin), organisation assignment.
- Submitted content: product texts, descriptions, label texts and uploaded spreadsheets submitted for screening. This content is passed on to external AI processors (see section 6).
- Usage metadata: scan credit history, timestamps, classification results.
- Technical data: IP address, browser type, time of access, page requested, stored in the server logs of our reverse proxy in order to prevent abuse.
5. Cookies
This website uses strictly necessary cookies only. Specifically, after you log in we set an encrypted session cookie (name: refresh_token) in order to keep you signed in across page views. This cookie is essential for the operation of the service (§ 25 (2) no. 2 TTDSG) and does not require consent. No marketing, analytics or third-party cookies are set.
6. Recipients and transfers to third countries
In order to provide the screening service, we pass product and text content to the following processors:
- Amazon Web Services EMEA SARL (Luxembourg) — hosting of the application in the
eu-central-1region (Frankfurt am Main, Germany). Data does not leave the territory of the European Union for this purpose. - Anthropic PBC (San Francisco, USA) — operation of the AI classification and rewriting engine (model: Claude). The text content to be screened is transmitted to the Anthropic API for classification. The transfer to the USA takes place on the basis of the Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR. According to Anthropic, the data is processed solely for the purposes of the API request and is not used to train models.
- OpenAI, LLC (San Francisco, USA) — generation of text embeddings for semantic search in our EU legal database and as a fallback classifier. The transfer to the USA likewise takes place on the basis of the Standard Contractual Clauses.
- Stripe Payments Europe, Ltd. (Dublin, Ireland) — processing of payments and issuing of invoices. The data processed comprises name, billing address, e-mail address, VAT identification number where applicable, and payment data. Any transfer to Stripe, Inc. (USA) takes place on the basis of the Standard Contractual Clauses. Full card details are processed exclusively by Stripe and never reach our servers.
- Resend, Inc. (Wilmington, Delaware, USA) — sending of transactional e-mails (registration confirmation, invitations, password resets, payment receipts, low balance notices). The data processed comprises the e-mail address and the content of the respective message. Processing takes place in the EU region (Ireland); any transfer to the USA takes place on the basis of the Standard Contractual Clauses.
7. Retention periods
Account data is stored for the duration of the user relationship and deleted within 30 days of termination, unless statutory retention obligations prevent this (for example commercial and tax law obligations under § 147 AO, 6 or 10 years respectively). Uploaded screening content and scan results are retained until actively deleted by the user or until the end of the contractual relationship. Server logs are anonymised or deleted after 30 days at the latest.
8. Your rights
You have the following rights at any time:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent (Art. 7 (3) GDPR)
An informal message to hello@vericlaim.eu is sufficient to exercise your rights.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The competent authority for the provider's region is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
10. Security
Communication between your browser and our servers is encrypted exclusively via TLS 1.2 or higher. Login data and session tokens are set as HttpOnly; Secure cookies and are not accessible to JavaScript. Passwords are stored exclusively as salted hashes.
Last updated: July 2026. This privacy policy is updated whenever there are material changes to the service or the legal situation.