Version: 1.2
Effective date: 2026-06-26
You can review or withdraw cookie consent at any time at Cookie settings.
AI transparency
BigRedBriefing may use AI to generate or materially transform briefing and news content. These outputs are labeled as AI-generated or created with AI by default unless a provable human-only path is explicitly documented.
Controller Identity
Controller: Kirla UG (haftungsbeschränkt)
Authorized representative: Thorsten Stams
Contact Details
General legal contact: contact@kirla-webservices.com
Support contact: support@kirla-webservices.com
Postal address: Platz der Einheit 2, 60327 Frankfurt am Main
Processed Data Categories
We process account identity data, authentication/security metadata, profile preference data, briefing content artifacts, billing ledger metadata, and support communications.
- Account identity: name, email, account role, verification state.
- Authentication/security: session versioning, rate-limit metadata, security event logs.
- Product/profile data: topics, regions, scheduling and preference metadata.
- Briefing operations: generated briefings, delivery records, source archive metadata.
- Billing metadata: wallet movements, references, and reconciliation records.
- Checkout and consent evidence: transaction-specific consent for immediate digital performance (timestamp, language, text version, evidence hash).
Processing Purposes
Data is processed to operate the service, secure accounts, deliver briefings, support billing operations, and provide support/compliance responses.
- Account creation, login, password recovery, and account security.
- Briefing generation, email delivery, and user-facing archives.
- Billing balance handling and transaction transparency.
- Service abuse prevention, diagnostics, and incident investigation.
Legal Bases
Processing is generally based on contract performance, legal obligations, and legitimate interests in operating and securing the service.
Optional cookie/service categories are processed on a consent basis and remain inactive until consent is recorded.
Recipients and Processors
Configured subprocessors are listed below and should be kept in sync with operational reality.
- Hosting and database service – dedicated server in Germany/EU
- Email delivery service – transactional SMTP delivery from Germany/EU
- OpenAI Ireland Ltd. – AI-assisted briefing generation; processes profile details such as topic preferences (Ireland/EU; onward processing by OpenAI L.L.C. USA under Standard Contractual Clauses)
- Anthropic PBC – AI inference with Claude models for selected briefing and chat steps (USA; Standard Contractual Clauses per Art. 46(2)(c) GDPR)
- Cloudflare Inc. – Turnstile bot protection and CDN/DDoS protection (USA; EU-DPF-certified with supplemental EU Standard Contractual Clauses)
- Manus AI (Butterfly Effect Pte Ltd) – AI-assisted source enrichment (Singapore; Standard Contractual Clauses per Art. 46(2)(c) GDPR)
- Google Ireland Ltd. (Gemini API) – AI inference on selected generation steps (Ireland/EU; onward processing by Google LLC USA under EU-DPF and supplemental Standard Contractual Clauses)
External Data Sources
To enrich the newsroom (e.g. market tiles), our server retrieves public reference data. These requests are made server-side only — your browser does not contact these providers directly, and no personal data is transmitted to them.
The following data sources are currently in use:
- Yahoo Finance (https://finance.yahoo.com): price and chart data for indices (DAX 40, S&P 500), commodity futures (Brent, gold), and cryptocurrencies (Bitcoin). Server-side retrieval via the public chart API without an API key.
- European Central Bank (ECB), retrieved via https://frankfurter.dev: EUR/USD reference rate (daily ECB publication).
International Transfers
Hosting, Datenbank-Betrieb und SMTP-Versand erfolgen ausschließlich auf Servern in Deutschland/EU. KI-Inferenz erfolgt teilweise im EU-Raum (OpenAI Ireland Ltd. mit Unterauftragsverarbeitung durch OpenAI L.L.C. USA sowie Google Ireland Ltd. mit Unterauftragsverarbeitung durch Google LLC USA — jeweils auf Basis von Standardvertragsklauseln gem. Art. 46(2)(c) DSGVO und ergänzendem EU-DPF) und teilweise direkt in den USA (Anthropic PBC) bzw. Singapur (Manus AI / Butterfly Effect Pte Ltd) auf Basis von Standardvertragsklauseln gem. Art. 46(2)(c) DSGVO. Cloudflare Inc. (USA) ist EU-DPF-zertifiziert und ergänzend mit EU-Standardvertragsklauseln abgesichert.
Retention and Deletion
Personenbezogene Daten werden nur so lange gespeichert wie für die Leistungserbringung oder die Erfüllung gesetzlicher Aufbewahrungspflichten erforderlich. Briefing-Verläufe und zugehörige Nutzungs-/Kostendaten werden nach Kontoschließung gelöscht oder anonymisiert; handels- und steuerrechtlich relevante Unterlagen bleiben für die gesetzlichen Aufbewahrungsfristen erhalten.
Deletion requests are handled via support at support@kirla-webservices.com.
- Security and abuse-prevention records may be retained for legitimate interests and legal obligations.
- Anonymization vs deletion policy:
Data Subject Rights
Users may request access, rectification, deletion, restriction, objection, and data portability where applicable under law.
Requests can be submitted via support contact channels listed on the contact page.
Cookies and Consent Categories
Strictly necessary cookies include `bigredbriefing_session` (authentication/session security) and `bigredbriefing_consent` (storing your consent choices and policy version).
The `brb_locale` preference cookie is only persisted after an explicit language switch and only if the preferences category has been allowed.
Cloudflare Turnstile is used as a technically necessary anti-bot security control for login, registration, contact, and password-reset forms.
One or more optional consent categories are available in this deployment and controlled through cookie settings.
Consent can be updated or withdrawn at any time via `/cookie-preferences`.
- Necessary: always enabled for core security and sign-in behavior.
- Preferences: available by consent (currently used for locale persistence).
- External services: available by consent (currently not required for Turnstile).
- Analytics: available by consent (configuration-enabled).
- Marketing: configured as inactive in this deployment.
Security, Logging, Account, Billing, and Email Flows
Security events, account recovery, verification, billing reconciliation, and delivery operations generate operational logs and metadata required to run and secure the service.
- Password reset and account security events.
- Rate-limit and abuse prevention telemetry.
- Billing wallet and reconciliation event metadata.
- Email verification and delivery status records.
Complaints and Supervisory Authority
Supervisory authority: Not published yet.
You may also contact the controller or support contact first for direct resolution.