For the data protection officer: everything Airrange does with data, in one file. Position, customer controls, data processing agreement with annexes, provider list, privacy policy and retention.
This page is for data protection officers and anyone who reviews Airrange before using it. It sums up how we see our role and why. The binding texts are the data processing agreement, the privacy policy and the provider list; this page explains them.
Airrange is a builder: a creator loads an Excel workbook, turns it into an app, a form or a calculator and publishes the result by link, on their own domain or in Microsoft Teams. End users enter data there. Airrange does not collect that data for its own purposes, does not analyse it and does not pass it to other customers. Every app belongs to the creator who built it, and everything end users enter belongs to that creator’s account.
That is why, for the apps and their inputs, we see ourselves as the creator’s processor (Art. 28 GDPR): the creator decides which data their app collects, where it flows and for what purpose. We provide the tools, the storage in Frankfurt and the connections they set up. For our own purposes, i.e. accounts, subscriptions, support and measuring product usage, we are the controller; that is covered by the privacy policy.
No feature that transfers data to a third party is active by itself. E-mail notifications, CRM connections, Google Sheets, custom webhooks, Google fonts, embedded videos: each exists in an app only because the creator set it up there. For every provider, the provider list names which decision of the creator triggers or prevents the transfer.
Two AI features we treat specially. The assistant in the builder helps the creator lay out and build their app; it knows the elements and sheet names but no cell contents, and runs only when the creator opens it. Smart Fill, which fills forms from end users’ free text or documents, is built but not released. When we release it, the creator will have to switch it on per app deliberately and will be told that their end users’ text goes to an AI provider in the USA and that, as controller, they need a legal basis for it.
For business customers with their own domain there are domain policies with which an administrator switches AI features, the support chat, public sharing and the Google integration off for all users of their domain. A per-account privacy policy, with which every customer switches individual providers off, is the next step; the data protection package will then show the state of the switches of the respective account.
Every provider is in one list with seat, data transmitted, third-country safeguard and the customer’s control, which is the recipients section of the privacy policy and whose Part A1 also forms Annex 3 of the DPA, generated from one source so there are never two versions. We announce changes of providers to customers 30 days in advance.
Anyone using an app built with Airrange needs no account for it. We create a random visitor identifier in the browser to attribute inputs to the same browser, and we measure usage pseudonymously. We do not profile end users, do not link inputs across apps of different creators and sell nothing. Which data an app collects is determined and answered for by the creator; they have to inform their end users about it. We explain to end users in our privacy policy what Airrange itself does with their data.
End users of the apps never come into contact with any AI from Airrange: no input anyone makes in a published app is sent to an AI model. Today, AI is solely an aid for the creator while building their app. AI models never run in the browser and never on data the creator or their end user did not put into the feature themselves. Which data a feature sends is in the privacy policy, including where it is whole texts. No AI output decides anything with legal effect; all of it is suggestions a human reviews. Our AI providers do not use API data for training.
We answer data protection questions, access and deletion requests at legal@airrange.io. For business customers we provide the complete data protection package with the data processing agreement and the provider list as a file on request.
This section describes what a customer controls themselves: per app through the creator, per domain through an administrator, per account through the user.
Every transfer to a third party from an app requires a setup by the creator. Without that setup nothing flows:
| Feature | Recipient | Active only if |
|---|---|---|
| E-mail notification on inputs, e-mail flow, scenario e-mail | Pipedream / Resend (USA) | the creator sets up a recipient address or the flow |
| CRM flow | HubSpot, Salesforce (the creator’s account) | the creator connects the account and maps fields |
| Google Sheets | Google (the creator’s account) | the creator connects the account |
| Webhook, web service | URL entered by the creator | the creator enters the URL |
| Google fonts | Google Fonts | the creator chooses a Google font |
| Videos, Unsplash images | YouTube, Vimeo, Unsplash | the creator embeds them |
| E-mail verification of end users | Hanko, Pipedream / Resend | the creator uses the e-mail element with verification |
| AI assistant | OpenAI | the creator opens the assistant in the builder |
| Smart Fill | Groq | not released; once released: the creator switches it on per app |
For customers with their own domain that we have set up as an enterprise domain, domain administrators switch off for all users of their domain:
| Switch | Effect |
|---|---|
| AI features off | Assistant and Smart Fill are unavailable; the server rejects requests |
| Support chat off | Chat widget is not loaded |
| Public sharing off | Apps only for named recipients |
| Google integration off | No Google Sheets connection |
| PDF export, table export, embedding, hosted workbooks off | Feature locked in the interface |
| Allowed users | Only listed addresses of the domain |
This Data Processing Agreement (“DPA”) governs the processing of personal data by airrange software GmbH, Sperberweg 7, 82152 Krailling, Germany (“Airrange”, “processor”) on behalf of the customer (“Customer”, “controller”) when using Airrange. It supplements the Airrange Terms of Service (airrange.io/terms, “Terms”) and becomes part of the contract when the user agreement is concluded, without the need for a separate signature. A signed copy is available on request (legal@airrange.io).
(1) This DPA covers the processing of personal data that Airrange carries out on behalf of the Customer when providing the Service under the Terms (“Customer Data”). Nature, purpose, categories of data and data subjects are set out in Annex 1.
(2) Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given in Art. 4 GDPR.
(3) “Apps” are the applications, forms, calculators and dashboards the Customer creates from workbooks with Airrange, including their publication by link, on a custom domain, as an embed or in Microsoft Teams. “End users” are persons who use an app of the Customer. “Flows” are processing steps the Customer sets up in an app that store, send or transfer inputs to a system chosen by the Customer.
(1) Airrange as processor. The Customer is the controller and appoints Airrange as processor for
The Customer decides which data its apps collect, where it flows and for what purpose. It is responsible for complying with the obligations data protection law imposes on controllers, in particular for informing its end users.
(2) Airrange as controller. Airrange processes the following on its own responsibility and not on behalf of the Customer:
The Airrange Privacy Policy (airrange.io/privacy-policy) applies to this processing.
(1) Airrange processes Customer Data only on documented instructions from the Customer, unless required to do so by Union or Member State law; in that case Airrange informs the Customer of that legal requirement before processing, unless that law prohibits it.
(2) The Customer’s instructions are set out in full in the Terms, this DPA, the policies the Customer sets and the Customer’s operation of the Service. Every setup of an app by the Customer, such as a form element, a flow, a connection to a CRM system or a Google Sheet, a Google font, an embedded video or the activation of an AI feature, counts as a documented instruction to the extent defined by that setup. With the domain policies and, once available, the account’s privacy policy, the Customer instructs Airrange not to use certain features or providers; Airrange enforces this instruction technically as described in Annex 2 and in the data protection package.
(3) The Customer gives further instructions in text form to legal@airrange.io. Airrange may refuse instructions that go beyond the agreed scope of services or carry them out for reasonable remuneration.
(4) Airrange informs the Customer without delay if, in its opinion, an instruction infringes data protection law, and may suspend carrying it out until the Customer confirms or changes it.
The Customer ensures that
The Customer informs Airrange without delay if it detects errors or irregularities in the processing.
Airrange ensures that all persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Only persons who need access to provide the Service, support or fix incidents are given access to Customer Data.
(1) Airrange takes the technical and organisational measures described in Annex 2 under Art. 32 GDPR to ensure a level of security appropriate to the risk.
(2) The measures are subject to technical progress. Airrange may replace them with equivalent or better measures; the level of security must not fall below the agreed level.
(1) The Customer gives Airrange general authorisation to engage sub-processors. The sub-processors engaged when the contract is concluded are listed in Annex 3 and are deemed approved.
(2) Airrange informs the Customer in text form at least 30 days before engaging a new or replacing an existing sub-processor (e.g. by e-mail or by updating Annex 3 with notice by e-mail). The Customer may object to the change within this period in text form for good cause. If the parties cannot agree, the Customer may terminate the user agreement with effect from the date the sub-processor is engaged.
(3) Airrange contractually binds each sub-processor to data protection obligations that substantially correspond to those in this DPA. Airrange is liable to the Customer for the sub-processor’s compliance with these obligations under Art. 28(4) GDPR.
(4) Recipients the Customer chooses and connects itself (Annex 3, Part C) and ancillary services Airrange uses from third parties without those third parties having access to Customer Data are not sub-processing within the meaning of this DPA.
Customer Data is processed outside the EU/EEA only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision (e.g. the EU-U.S. Data Privacy Framework) or the EU Standard Contractual Clauses (Module 3, processor to processor) that Airrange concludes with the respective sub-processor. Database and file storage are in the EU region Frankfurt; the sub-processors concerned and the respective safeguard are listed in Annex 3.
(1) Airrange assists the Customer with appropriate technical and organisational measures in responding to data subject requests. The Service enables the Customer to view, export and delete workbooks, apps and its end users’ inputs itself.
(2) If a data subject contacts Airrange directly, Airrange forwards the request to the Customer without delay where the Customer can be identified, and does not answer it itself unless the Customer instructs it to or the law requires it.
(3) Taking into account the nature of processing and the information available, Airrange assists the Customer in complying with the obligations under Art. 32 to 36 GDPR (security, notifications, data protection impact assessment, prior consultation).
(4) Airrange may charge reasonable fees based on effort for assistance that goes beyond the features of the Service and is not caused by a breach by Airrange.
Airrange notifies the Customer of a personal data breach concerning Customer Data without undue delay after becoming aware of it, at the latest within 48 hours, to the e-mail address stored in the account. Airrange’s management is responsible for the notification. The notification contains, as far as known, the information under Art. 33(3) GDPR; missing details are supplied later. Airrange immediately takes the measures necessary to secure the data and to mitigate possible adverse effects. Notification of supervisory authorities and data subjects is the Customer’s responsibility.
(1) During the term of the contract, the Customer can export and delete workbooks, apps and inputs itself at any time. The periods after which deleted and expired data is physically removed are in the “Retention and deletion” section of the data protection package.
(2) After the user agreement ends, Airrange deletes the Customer Data or returns it, at the Customer’s choice, unless there is a legal obligation to retain it. Return takes place through the export functions of the Service (Excel export of workbooks, export of inputs), which the Customer uses before deletion. The Customer requests account deletion at legal@airrange.io; Airrange carries it out within 30 days of receipt and confirms it in text form. Copies in backups and in the restore archive are removed no later than the end of the periods stated in the “Retention and deletion” section.
(3) Sub-processors delete Customer Data in accordance with the contracts concluded with them; Airrange instructs deletion where Customer Data is still stored there.
(1) On request, Airrange provides the Customer with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. The data protection package, the description of measures in Annex 2 and certificates and audit reports of sub-processors (e.g. the hosting providers’ ISO 27001 or SOC 2) will normally suffice as evidence.
(2) The Customer may carry out further audits, including inspections, at most once per calendar year after giving reasonable notice (at least 30 days) during normal business hours, itself or through an auditor bound to confidentiality who does not compete with Airrange, unless a supervisory authority requires more or there is a specific reason. Each party bears its own costs.
Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the Terms apply. As a processor, Airrange is only liable for damage caused where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the Customer’s lawful instructions.
(1) This DPA applies for the term of the user agreement and beyond for as long as Airrange processes Customer Data.
(2) In the event of conflicts between this DPA and the Terms, this DPA prevails in matters of data protection.
(3) Airrange may change this DPA under the procedure provided in the Terms, in particular to adapt it to changes in the law or in sub-processors. § 7 takes precedence for sub-processors.
(4) The laws of the Federal Republic of Germany apply. To the extent permitted by law, the place of jurisdiction is the registered office of airrange software GmbH.
(5) Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.
Storing, calculating, displaying, sharing and publishing workbooks and the apps created from them; storing, sending and transferring end-user inputs according to the flows the Customer set up; processing by AI models to the extent described in the privacy policy, where the Customer switches them on.
For the term of the user agreement; deletion under § 11.
This annex describes Airrange’s technical and organisational measures as of 8 October 2026.
These providers process workbooks, apps and end-user inputs on our behalf under Art. 28 GDPR. This part is Annex 3 of the data processing agreement; the sub-processors named here are deemed approved under DPA § 7. “Customer can switch off” describes which decision of the creator prevents a transfer.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off | Contract / notice |
|---|---|---|---|---|---|---|
| Amazon Web Services EMEA SARL | The application’s database and file storage: accounts, workbooks, app configurations, shares, end-user inputs, tables, uploads | All data of the application | Luxembourg — Database (DynamoDB, AppSync) and file storage (S3) in the EU region Frankfurt (eu-central-1) | Processing in the EU; AWS data processing addendum with Standard Contractual Clauses for support access from third countries; AWS is certified under the EU-U.S. Data Privacy Framework | Cannot be switched off (core function) | Provider DPA |
| Vercel Inc. | Running airrange.io and app.airrange.io, server functions, storage of generated PDFs, web analytics and speed insights, logs | All data that passes through the application; connection data on every request (IP address, browser); usage events without any personal identifier (event, plan, sign-in method, account domain); generated PDFs; logs with masked e-mail addresses | Covina, California, USA — Server functions, PDF storage (Blob) and logs in the Frankfurt region (AWS eu-central-1); static content delivered through Vercel’s content delivery network | EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreement | Cannot be switched off (core function) | Provider DPA |
| Hanko GmbH | Sign-in of creators (e-mail code, passkey, Google account) and e-mail verification of end users in apps that require it | E-mail address, account ID, session data (session 30 days) | Kiel, Germany — Hosted in Germany | Processing in the EU | Cannot be switched off (core function) | Provider DPA |
| Microsoft Ireland Operations Ltd. | Sign-in with a Microsoft 365 account, access to Excel files in OneDrive and SharePoint via Microsoft Graph, Teams app, file connections for published apps | Name, e-mail address, account ID, profile photo; contents of connected Excel files; OAuth access tokens that Airrange stores for file connections | Dublin, Ireland | Microsoft Data Protection Addendum with Standard Contractual Clauses; EU-U.S. Data Privacy Framework | Only with Microsoft sign-in or use of Microsoft files; file connections are set up by the creator | Provider DPA |
| Pipedream Inc. | Automation service through which Airrange sends e-mails (invitations, verification codes, notifications about inputs, scenario e-mails), triggers internal notifications on sign-up and new apps, receives the website’s contact form, and connects creators’ CRM systems and Google Sheets (Pipedream Connect) | Recipient addresses and contents of e-mails, including end-user inputs where the creator set up notifications; on sign-up e-mail address, account ID and sign-in method; for CRM connections the form fields the creator mapped; creators’ OAuth accounts for HubSpot, Salesforce and Google are stored at Pipedream | San Francisco, California, USA | Standard Contractual Clauses | E-mail and CRM flows only if the creator sets them up; invitation and verification e-mails and the sign-up notification cannot be switched off | Provider DPA |
| Resend Inc. | Delivery of the e-mails Airrange triggers via Pipedream | Recipient address, subject and content of the e-mail | San Francisco, California, USA | Standard Contractual Clauses (the provider’s data processing agreement) | As for Pipedream | Provider DPA |
| OpenAI, L.L.C. | AI assistant in the app builder (suggestions for layout and elements) | The creator’s chat history with the assistant; labels and texts of app elements, sheet names and used ranges; no cell contents of the workbook | San Francisco, California, USA | OpenAI data processing addendum with Standard Contractual Clauses; EU-U.S. Data Privacy Framework | Only when the creator opens the assistant; enterprise domain administrators switch AI features off for their domain, enforced on the server | Provider DPA |
| Pusher Ltd. (behind the add-in service excel-inventory.airrange.io) | Real-time notification of the Excel add-in about new inputs; the add-in service itself is operated by Airrange | A “new input” signal to the add-in over one channel per target workbook: identifiers only (submit, document, configuration), no input contents; the channel name contains the workbook’s file name and author | London, United Kingdom — Cluster “eu” (EU data centre) | Adequacy decision for the United Kingdom | Cannot be switched off (core function) | Provider DPA |
| Redis Ltd. (Redis Cloud, behind the add-in service excel-inventory.airrange.io) | Data store of the Excel add-in (shared cell ranges, share settings, user records) and metadata and caches of SpreadAPI | Values, formulas, formats, images and charts of the shared range (7 days, extendable to 120 days); share password, recipient addresses; e-mail, name, user agent, Office version, licence and IP addresses of the add-in user; workbook identifier (contains file name and author) | Mountain View, California, USA — AWS eu-central-1, Frankfurt | Processing in the EU (Frankfurt); data processing agreement with Standard Contractual Clauses | Only if the creator uses the Excel add-in and shares a range | Provider DPA |
Providers that process data under their own responsibility and are therefore not sub-processors: the payment provider, and fonts and media the end user’s browser loads directly from the provider when the creator uses them in their app.
Systems to which the creator transfers their end users’ inputs because they connect or name them themselves. The creator is the controller of that transfer; they are listed for completeness.
The current version of this annex is published in the data protection package at airrange.io/data-protection-package. Not in this annex: providers that process only the users’ account, contract and billing data (privacy policy, “Recipients” section).
This list is the “Recipients” section of our privacy policy; Part A1 is also Annex 3 of our data processing agreement. Both are generated from a single source so that there are never two versions. Changes of sub-processors are announced to customers 30 days ahead (DPA § 7).
These providers process workbooks, apps and end-user inputs on our behalf under Art. 28 GDPR. This part is Annex 3 of the data processing agreement; the sub-processors named here are deemed approved under DPA § 7. “Customer can switch off” describes which decision of the creator prevents a transfer.
These providers process only account, contract, support and prospect data on our behalf. They do not concern customer data and are therefore not part of Annex 3. Hanko is in Part A1 because, besides creator sign-in, it also handles e-mail verification of end users.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off | Contract / notice |
|---|---|---|---|---|---|---|
| Attio Ltd. | Managing the customer relationship with creators (sign-up, plan, newly created apps) | E-mail address, account ID, sign-in method, sign-up source, plan; title and short description of newly created apps | London, United Kingdom | EU adequacy decision for the United Kingdom; Attio data processing agreement | Cannot be switched off (core function) | Provider DPA |
| Cal.com, Inc. | Demo scheduling: booking links on the website and an embedded calendar on individual pages | When the embedded calendar loads, IP address and browser; on a booking, name, e-mail address and the details the booking person provides | San Francisco, California, USA | EU Standard Contractual Clauses (Module 2) in the data processing agreement with Cal.com, Inc. | Website only; never in the application or in apps | Provider DPA |
| Chatwoot Inc. | Support chat in the builder | The creator’s e-mail address, chat contents, IP address, browser | USA | Explicit consent of the creator under Art. 49(1)(a) GDPR before the chat starts; data processing agreement with Standard Contractual Clauses requested (gdpr@chatwoot.com) | Builder only and only after the creator agrees on the first click of the chat button; whether the e-mail address is sent along is their choice; changeable at any time in the account menu. Not on the website, never in published apps; enterprise domain administrators switch the chat off for their domain | – |
| Wistia Inc.; Scribe (ScribeHow) | Help and tutorial videos and step-by-step guides in the builder | IP address, browser, playback telemetry | Cambridge, Massachusetts, USA; San Francisco, USA | EU-U.S. Data Privacy Framework | Only when opening help in the builder; never in published apps | Provider DPA |
Providers that process data under their own responsibility and are therefore not sub-processors: the payment provider, and fonts and media the end user’s browser loads directly from the provider when the creator uses them in their app.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off | Contract / notice |
|---|---|---|---|---|---|---|
| Stripe Payments Europe Ltd. | Creator subscriptions and invoices | E-mail address, customer ID, subscription status; payment details are entered directly at Stripe and never reach Airrange | Dublin, Ireland | Processing in the EU; Standard Contractual Clauses within the Stripe group; Stripe Inc. is certified under the EU-U.S. Data Privacy Framework | Only with a paid plan | Privacy notice |
| Google Ireland Ltd. (Google Fonts) | Loading fonts in published apps when the creator chose a Google font | The end user’s IP address and browser | Dublin, Ireland; served by Google LLC, USA | EU-U.S. Data Privacy Framework | Only if the creator chooses a Google font; with a system font nothing is loaded | Privacy notice |
| YouTube (Google Ireland Ltd.), Vimeo.com Inc., Unsplash Inc. | Videos and images the creator embeds in their app, loaded by the end user’s browser directly from the provider | The end user’s IP address and browser; for YouTube and Vimeo also their cookies | Dublin, Ireland; New York, USA; Montreal, Canada | EU-U.S. Data Privacy Framework (Google, Vimeo); adequacy decision for Canada (Unsplash) | Only if the creator embeds a video or an Unsplash image | – |
Systems to which the creator transfers their end users’ inputs because they connect or name them themselves. The creator is the controller of that transfer; they are listed for completeness.
| Service provider | Service | Data transmitted | Seat / location | Third-country safeguard | Customer can switch off | Contract / notice |
|---|---|---|---|---|---|---|
| HubSpot, Inc. | Create a contact or form submission in the creator’s HubSpot account | Form fields of end users mapped by the creator (e.g. e-mail, name, company) | Cambridge, Massachusetts, USA (EU data centre depending on the account) | The creator’s contract with HubSpot | Only if the creator sets the feature up in their app | – |
| Salesforce, Inc. | Create a lead in the creator’s Salesforce account | Form fields of end users mapped by the creator | San Francisco, California, USA | The creator’s contract with Salesforce | Only if the creator sets the feature up in their app | – |
| Google Ireland Ltd. (Google Sheets, Google Drive) | Append rows to a creator’s spreadsheet; read the creator’s spreadsheets as a data source | End-user form fields; contents of the connected spreadsheets | Dublin, Ireland | The creator’s contract with Google | Only if the creator sets up the connection; enterprise domain administrators switch the Google integration off for their domain | – |
| Webhook and web service URLs entered by the creator | Send inputs to a system of the creator’s own or fetch calculations from there | Form fields and, depending on the setup, the end user’s identifier | Anywhere, determined by the creator | The creator’s responsibility | Only if the creator sets the feature up in their app | – |
Features whose code exists but which are not enabled. They move to Part A1 only once released; until then no data flows.
This privacy policy informs you under Art. 13 and 14 of the General Data Protection Regulation (GDPR) about which personal data we process when operating the website airrange.io and the Airrange application (app.airrange.io, including published apps on custom domains, the Teams app and the Excel add-in), for what purposes, on which legal basis and which rights you have.
airrange software GmbH
Sperberweg 7
82152 Krailling
Germany
Phone: +49 (0)89 28741023
E-mail: legal@airrange.io
Commercial register: Munich Local Court, HRB 271683
Managing director: Stephan Methner
For all questions about data protection and to exercise your rights, contact us at legal@airrange.io.
No data protection officer has been appointed. Please send data protection requests to legal@airrange.io or by post to the address in section 1.
Depending on your relationship with Airrange, we process your data in different roles:
Website and application are hosted by Vercel Inc. (Covina, California, USA); Vercel’s server functions and file storage run for us in the Frankfurt region (AWS eu-central-1), static page content is delivered through Vercel’s content delivery network. When a page is opened, Vercel processes technically necessary connection data: IP address, date and time, URL requested, referrer, browser and operating system information and status codes (server log files). The website’s font is served from our own server; visiting the website opens no connection to Google.
Purpose: delivering the website, stability, security and abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and functioning offering). Retention: server log files are deleted after the hosting provider’s retention period, unless they are needed longer to investigate a security incident.
Vercel is a US company certified under the EU-U.S. Data Privacy Framework; in addition we have concluded a data processing agreement with Standard Contractual Clauses with Vercel (sections 16 and 17).
Contact form. Through the contact form you send us your name, e-mail address and message. The form hands the details to our automation service Pipedream (section 15), which forwards them to us. Purpose and legal basis: answering your request, Art. 6(1)(b) and (f) GDPR. Retention: until the request is dealt with and for the duration of any subsequent business relationship.
Demo appointments. You book appointments via Cal.com, Inc. (USA). On individual pages the booking calendar is embedded and loads as soon as it becomes visible; Cal.com then receives your IP address and browser data. On a booking, Cal.com processes your name, e-mail address and details on our behalf. Legal basis: Art. 6(1)(b) GDPR (appointment at your request), for loading the calendar Art. 6(1)(f) GDPR.
The application’s data (accounts, workbooks, app configurations, shares, inputs in apps, tables, uploaded files) is stored at Amazon Web Services in the EU region Frankfurt (DynamoDB database, S3 file storage). PDF files generated by apps (section 15) are kept in Vercel’s file storage in the Frankfurt region.
Server functions write logs at Vercel to find errors and detect abuse; e-mail addresses in them are masked.
Legal basis: Art. 6(1)(b) GDPR (contract with the creator) and (f) GDPR (operation and security).
We use no advertising or tracking cookies and no cookies from ad networks or social networks. We set cookies and entries in the browser’s local storage (localStorage) only where they are necessary to provide the feature you request (§ 25(2) no. 2 of the German TDDDG): sign-in, attribution of your inputs to your browser, caches and settings. No consent is required for that, which is why we show no cookie banner. The main entries:
| Name | Type | Purpose | Duration |
|---|---|---|---|
| hanko | Cookie (sign-in service) | Session after signing in by e-mail code or passkey | Until sign-out, at the latest 30 days after signing in |
| msal.* | localStorage and cookie (Microsoft) | Sign-in with a Microsoft 365 account; contains the Microsoft tokens | Until sign-out or token expiry |
| publicUserId | localStorage | Random visitor identifier that attributes inputs in apps to the same browser; also for end users without an account | Unlimited, until the browser clears its storage |
| ar_verified_email_*, airrange_verified_emails | localStorage | In apps with e-mail verification, remembers the verified address so it need not be confirmed again (obfuscated, not encrypted) | 30 days |
| workbook-*, cachedata-* | localStorage | Cache of the last loaded workbook or app for faster loading | 7 days |
| submittedChanges_*, unsubmittedChanges_*, range_* | localStorage | Inputs in apps not yet submitted or last submitted | Until submission or clearing the cache |
| userPhoto, ar-chatwoot-identified, supportChat, recentsList-*, publicList-all, signup_source | localStorage | Profile photo from Microsoft, identification and your choice for the support chat, recently opened apps, sign-up source | Until sign-out or clearing the storage |
| cw_conversation, cw_user_id | Cookie and localStorage (Chatwoot) | Identifier of the support chat in the builder so you find your chat history again; only if you enabled the chat | Until the browser storage is cleared |
Cookies of third-party content embedded in apps (YouTube, Vimeo) are set by the respective provider; see section 12. You can clear local storage at any time in your browser or, as a creator, via “Clear Local Cache” in the account menu.
We measure the use of website and application with Vercel Web Analytics and Vercel Speed Insights. Both work without cookies. Transmitted are the page opened, referrer, browser and device type, coarse location derived from the IP address (the IP address itself is not stored by Vercel) and load times.
In the application we additionally send events such as “sign-in”, “app created” or “app opened”, without any visitor identifier; for signed-in creators with plan, sign-in method and the domain of the e-mail address. Measurement also runs in published apps, there only with the event itself. The visitor identifier from section 6 is not transmitted to the usage measurement.
Purpose: understanding which features are used, finding errors and performance problems. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the service). You can object to the measurement at legal@airrange.io.
You create an account with your e-mail address. Sign-in runs via Hanko GmbH (Kiel, Germany; hosted in Germany) by one-time code to your e-mail address, by passkey or via your Google account, or via your Microsoft 365 account (section 14). When signing in with Google, Google transmits your e-mail address and name to Hanko; of these we store the e-mail address. We store e-mail address, account ID, sign-in method, language setting, plan and licence data, time of registration and the sign-up source (e.g. a referral link).
On registration we transmit e-mail address, account ID, sign-in method and sign-up source via our automation service (section 15) to our CRM system Attio Ltd. (London, United Kingdom; EU adequacy decision) to look after you as a customer. When you create an app, the CRM system receives the app’s title and short description.
After registration you receive an onboarding e-mail with usage tips. We send further product-related messages to existing customers only about similar services of our own; each such e-mail contains an unsubscribe link (§ 7(3) German UWG). We do not send a general newsletter.
Purpose: providing the account, performing the contract, customer care. Legal basis: Art. 6(1)(b) GDPR; for customer care in the CRM and product-related messages Art. 6(1)(f) GDPR. Retention: until the account is deleted (section 18).
The contents of an account (workbooks, apps, shares) are tied to the e-mail address. Whoever controls the mailbox controls the account. If the mailbox owner changes, for example with a reused company address, the new owner can access content tied to that address. Delete your account before giving up an address.
Paid plans are billed through Stripe Payments Europe Ltd. (Dublin, Ireland). You enter payment details directly at Stripe; we do not receive them. For the payment processing itself Stripe is an independent controller (privacy notice at stripe.com/privacy). We store your Stripe customer ID, the plan and the subscription status. Legal basis: Art. 6(1)(b) GDPR; for retaining invoices Art. 6(1)(c) GDPR (8 years under German tax and commercial law).
If you write to support@airrange.io, we store your request and our reply. In the builder we offer signed-in creators a support chat via Chatwoot (Chatwoot Inc., USA). When you first click the chat button you decide whether the chat starts and whether your e-mail address is sent along so we can reply to you; nothing from Chatwoot is loaded before that, and you can change your choice at any time in the account menu. If the chat is active, Chatwoot receives your IP address and browser data, when you chat the chat contents and, if you allowed it, your e-mail address. Chatwoot stores an identifier in your browser so you find your chat history again next time. The chat is not loaded on the website airrange.io or in published apps. Legal basis: your consent, Art. 6(1)(a) GDPR; for the transfer to the USA your explicit consent under Art. 49(1)(a) GDPR, about whose risks we inform you before the chat starts (currently no adequacy decision and no Standard Contractual Clauses with Chatwoot yet). You can withdraw your consent at any time in the account menu; the chat is then no longer loaded. Retention: until deletion on request.
Workbooks that creators load, apps they build from them and everything end users enter into those apps we process exclusively on behalf of the respective creator. The creator decides which data their app collects, where it flows (e-mail, CRM system, Google Sheet, custom webhook) and how long they keep it. The basis is our data processing agreement, which is part of the data protection package (airrange.io/data-protection-package).
We do not analyse this data for our own purposes, do not pass it to other customers and do not use it to train AI models. Our staff access it only where operation or support require it.
If you have questions about data you entered into an app built with Airrange, contact the operator of the app. If your request reaches us, we forward it to the creator where we can identify them.
SpreadAPI (spreadapi.io) is our second service: workbooks you upload there we provide as a calculation service through an interface (API, MCP server). We store the workbooks encrypted at AWS in Frankfurt; calculation results are cached for at most 15 minutes, the input values of calls are not stored; API keys are stored only as a SHA-256 hash; metadata and caches are held at Redis Cloud in the EU. Here too we act on the customer’s behalf for the contents of the workbooks and the call data.
When you open an app built with Airrange, whether at app.airrange.io, on the creator’s own domain, embedded in another website or in Microsoft Teams, we process as controller:
Depending on how the creator set up their app, your browser loads content directly from third parties: Google Fonts if the creator chose a Google font; YouTube or Vimeo videos and Unsplash images if they embedded them. The respective provider then receives your IP address; YouTube and Vimeo set their own cookies. Whether an app contains such content is the creator’s decision; they inform you about it in their own privacy notice.
Legal basis for the data we process ourselves: Art. 6(1)(f) GDPR (operation, security). The view statistics the creator sees for their app (visitor identifier or account ID and time per view) we keep on their behalf (section 11). You need no account with us to use an app.
End users of published apps never come into contact with any AI feature. No input in a published app is sent to an AI model. Today, AI is solely an aid for the creator while building their app; that changes only if we release Smart Fill (see below), and even then only in apps where the creator deliberately switches it on.
Assistant in the builder. Creators can use an AI assistant while building an app. We transmit to OpenAI, L.L.C. (USA) the chat history with the assistant, labels and texts of the app elements as well as sheet names and used ranges of the workbook. We do not transmit cell contents, i.e. values and formulas; the assistant helps lay out and build the app, not analyse the workbook. The assistant runs only when the creator opens it. We log usage per request with a masked e-mail address. According to OpenAI, data from the API is not used for training; we send every request with the setting not to store it at the provider. OpenAI may still keep requests for up to 30 days for abuse monitoring.
Smart Fill (filling forms from free text, dictation or documents) is built but not released. If released, the creator has to switch it on per app; the text end users enter would then be transmitted to Groq, Inc. (USA). Dictation uses the browser’s speech recognition; the recording goes to the browser’s manufacturer (e.g. Google for Chrome). We update this policy before any release.
No AI output decides anything with legal effect; all of it is suggestions a human reviews. Legal basis: for the assistant Art. 6(1)(b) GDPR towards the creator; for personal data in workbooks we act on the creator’s behalf (section 11). Domain administrators can switch AI features off for their domain; the switch is checked on the server.
If you sign in with your Microsoft 365 account or use Excel files from OneDrive or SharePoint, we receive from Microsoft your name, e-mail address, account ID and profile photo as well as the content of the files you open. In Microsoft Teams we exchange the Teams sign-in token on the server for a Microsoft Graph token (on-behalf-of).
The file connection to Microsoft 365 is a legacy feature being phased out and used only in individual cases. It requires signing in with a Microsoft account; anyone who signs in by e-mail code or passkey is not offered the option. If you set up such a connection for a published app so the app reads data from your Excel file stored in Microsoft 365 (OneDrive, SharePoint), we store the Microsoft access tokens required for that in our database. These tokens travel over encrypted connections only and are kept in storage encrypted by AWS. The tokens exist as long as the file connection exists. You can revoke the permissions at any time in the account menu (“Microsoft Consents”) or in your Microsoft account.
If you connect Google Sheets or a CRM system (HubSpot, Salesforce) to an app, the sign-in there runs via Pipedream Connect; the credentials are stored by Pipedream, not by us (section 15). Your e-mail address serves as the identifier of your account at Pipedream.
Legal basis: Art. 6(1)(b) GDPR.
E-mails Airrange sends (workspace invitations, share notifications, confirmation codes, notifications about inputs, scenario e-mails to end users, internal notifications) are triggered via the automation service Pipedream Inc. (USA); they are delivered via Resend Inc. (USA). Transmitted are recipient address, subject and content of the e-mail. Recipient addresses of invitations, shares and notifications we receive from the creator who issues the invitation or share; we use them for that delivery only. If an e-mail contains end-user inputs because the creator set up a notification or an e-mail flow, those inputs pass through the named services too. For scenario e-mails we generate a PDF with the inputs, store it in Vercel’s file storage under an unguessable address and link it in the e-mail.
When a form is submitted, we additionally send a signal to our own add-in service (excel-inventory.airrange.io, Vercel, Frankfurt region) so that an open Excel add-in can load the new input immediately; for this we use Pusher Ltd. (London, cluster “eu”). The signal contains identifiers only (input, document, configuration) and the identifier of the target workbook, no input contents.
Excel add-in. If you use our Excel add-in, the add-in service processes on start an identifier of your workbook formed from file name, author and creation date, and after sign-in your e-mail address, name, browser and Office version, licence and IP address; the add-in refreshes these details at regular intervals while it is open. When you share a cell range, we upload the values, formulas, formats, images and charts of that range to our data store at Redis Ltd. (Redis Cloud, Frankfurt data centre) and keep them there for 7 days, on request up to 120 days. The whole file is never uploaded. On first sign-in we report your account via our automation service to our CRM system (section 8).
Pipedream is being replaced by n8n (operated in Frankfurt); we announce the change under § 7 of the DPA. Legal basis: Art. 6(1)(b) GDPR; for end-user inputs we act on the creator’s behalf.
The following providers process data on our behalf (Part A), are third parties processing data under their own responsibility (Part B), or recipients a creator chooses themselves (Part C). Part A1 is also Annex 3 of our data processing agreement; everything is generated from one source so there are never two versions.
These providers process workbooks, apps and end-user inputs on our behalf under Art. 28 GDPR. This part is Annex 3 of the data processing agreement; the sub-processors named here are deemed approved under DPA § 7. “Customer can switch off” describes which decision of the creator prevents a transfer.
These providers process only account, contract, support and prospect data on our behalf. They do not concern customer data and are therefore not part of Annex 3. Hanko is in Part A1 because, besides creator sign-in, it also handles e-mail verification of end users.
Providers that process data under their own responsibility and are therefore not sub-processors: the payment provider, and fonts and media the end user’s browser loads directly from the provider when the creator uses them in their app.
Systems to which the creator transfers their end users’ inputs because they connect or name them themselves. The creator is the controller of that transfer; they are listed for completeness.
Beyond that we disclose data only where legally required or where you have consented.
Database and file storage are in the EU. Some providers are based in the USA, the United Kingdom or Canada. We base transfers there either on an adequacy decision of the EU Commission (EU-U.S. Data Privacy Framework for certified US companies; United Kingdom; Canada), on the EU Standard Contractual Clauses we conclude with the respective provider, or, for the support chat, on your explicit consent under Art. 49(1)(a) GDPR (section 10). Which safeguard applies to which provider is in the provider list (section 16; in the data protection package section 4 and DPA Annex 3).
We store account data until the account is deleted, invoice data for 8 years. The periods for all other types of data are in the “Retention and deletion” section of the data protection package (airrange.io/data-protection-package). Data you delete can no longer be retrieved immediately and is removed for good in the regular deletion run. Request account deletion at legal@airrange.io; we carry it out and tell you what remains for legal reasons.
You have the rights towards us to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future. Contact legal@airrange.io for this.
Right to object (Art. 21 GDPR). Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), in particular for usage measurement, customer care in the CRM system and the technical data when an app is opened, you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims. Send your objection to legal@airrange.io.
For data you entered into an app built with Airrange, the operator of the app is your contact; we support them in responding.
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
For an account we need an e-mail address; without it no sign-in is possible. All other information is voluntary. End users of an app decide themselves what they enter; whether an input is required for the app’s purpose is determined by the creator.
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
All connections are TLS-encrypted. Database and file storage are in Frankfurt. The technical and organisational measures are described in Annex 2 of the data processing agreement in the data protection package.
We adapt this policy when our service or the law changes and state the date of the last change above. Material changes affecting creators are announced by e-mail.
Data a user deletes can no longer be retrieved immediately and is removed for good in the regular deletion run. The table names the retention period per type of data.
| Type of data | Retention |
|---|---|
| Account, subscription | Until the account is deleted |
| Workbooks, apps, shares | Until deleted by the user; then removed for good in the deletion run |
| End-user inputs (forms, tables, scenarios) | As long as the app exists; scenarios of expired links are removed in the deletion run |
| Generated PDFs (scenario e-mails) | Until the associated app is deleted or on request |
| Files in file storage (S3) | Until the associated record is deleted or on request |
| Visitor identifier and device data of anonymous end users | 90 days |
| Notifications (in-app) | 90 days |
| View statistics per share (pseudonymous identifier, date) | For the duration of the share; deletion on the creator’s instruction (DPA § 9) |
| Excel add-in: shared cell ranges | 7 days, extendable by the creator to 120 days |
| Excel add-in: user record | Until the account is deleted |
| Server logs | Per the hosting provider’s retention period |
| Archive of deleted records (for restore) | At most 24 months |
| E-mail verification code | 5 minutes, not stored |
| Invoices and accounting records | 8 years (statutory retention) |
Request account deletion at legal@airrange.io. We then delete workbooks, apps, shares, files, the account record, the sign-in identity, the contact in the CRM system and connected accounts and access tokens. What remains: