Privacy Policy
Last updated: Sep 4, 2026
1. Controller
The controller responsible for the processing of personal data is:
Die Leoparden GmbH
Schillerstr. 60
70839 Gerlingen
E-mail: datenschutz@click2bill.app
2. Data Collected and Purposes
When using Click2Bill, the following categories of data are processed in particular:
- Account and login data (e-mail address, password hash, activation and login status): for the provision of the Service and for authentication.
- Tenant and membership data (tenant name, roles, memberships): for structuring multiple tenants and permissions.
- API credentials and tokens for third-party services (ClickUp, Lexware Office): stored in encrypted form, used exclusively for synchronisation on behalf of the customer.
- Content data from ClickUp and Lexware Office (spaces, folders, tasks, time entries, customers, invoice drafts): for the provision of the core functionality of the Service.
- Payment and billing data (the e-mail address provided during checkout, billing address, VAT ID if applicable, payment status): for processing paid subscriptions via our payment service provider Stripe and for the creation and dispatch of invoices via Lexware Office. The e-mail address provided during checkout is also used as the recipient address for invoice delivery. Card and SEPA mandate data is processed exclusively by Stripe; we do not receive this data.
- Server logs (IP address, timestamp, requested resource, user agent): for ensuring reliable operation, error analysis, and defence against attacks.
3. Legal Bases
Processing is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (legitimate interest in stable operation), and where applicable Art. 6(1)(a) GDPR where consent has been given.
4. Processors and Recipients
Click2Bill uses the following third-party providers for the provision of the Service, with whom Data Processing Agreements (DPAs) pursuant to Art. 28 GDPR have been concluded:
- Hosting: Neue Medien Münnich, Friedersdorf.
- ClickUp (ClickUp, USA): access to the customer's ClickUp workspace on their behalf.
- Lexware Office (Haufe-Lexware GmbH & Co. KG, Germany): access on behalf of the customer, as well as creation and delivery of subscription invoices to the e-mail address provided during checkout.
- Stripe (Stripe Payments Europe, Ltd., Ireland): processing of payments for paid subscriptions. Stripe processes the e-mail address provided during checkout, the billing address, and payment data as an independent controller for payment processing purposes.
Where data is transferred to third countries (in particular the USA), this is done on the basis of standard contractual clauses pursuant to Art. 46 GDPR and, where applicable, supplementary safeguards.
5. Retention Periods
Personal data is retained for as long as it is necessary for the provision of the Service or as required by statutory retention obligations (in particular under tax and commercial law). Following termination of the contract, account and content data will be deleted within 30 days, unless a longer retention obligation applies.
6. Rights of Data Subjects
You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR). Any consent given may be withdrawn at any time with effect for the future. Please direct enquiries to datenschutz@click2bill.app.
You also have the right to lodge a complaint with a supervisory authority. The competent authority is in particular the supervisory authority at the controller's registered office: Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI).
7. Cookies and Similar Technologies
Click2Bill uses technically necessary cookies (in particular for session and CSRF protection). Tracking cookies or analytics services are only set with explicit consent. Consent may be withdrawn at any time.
8. Security
The Provider implements technical and organisational measures pursuant to Art. 32 GDPR to ensure the security of processing. These include in particular TLS encryption of data transmissions, encrypted storage of sensitive data (e.g. API tokens), and a restrictive access-control concept.