PRIVACY POLICY
Information about the processing of personal data when using the TopicPair website and closed beta.
1. Controller
Nico S. N. Köbsel
TopicPair · a project by len9one1
c/o IP-Management #11790
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: [email protected]
2. Scope
This Privacy Policy applies to the public website topicpair.com, the product previews provided there, the application process, and the access-restricted closed beta environment at beta.topicpair.com. The closed beta is active and intended exclusively for approved participants. For privacy purposes, the public preview, application process and closed beta environment are described separately.
3. Accessing the website / server and security data
When the website is accessed, technically necessary connection data is processed. This may include, in particular, the IP address, time of access, requested URL, HTTP status, referrer, and information about the browser and operating system.
The processing serves to deliver the website, maintain stability and security, and defend against abusive access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in operating the service securely and reliably.
TopicPair does not maintain its own visitor-profile or marketing database for the public website. Where infrastructure or security providers process technical log data, their technically or contractually defined retention periods apply.
4. Delivery via Cloudflare
TopicPair is delivered using Cloudflare services. In particular, network, connection and security data may be processed in order to deliver content, provide encrypted connections, and defend against attacks or abusive access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the security, availability and efficient delivery of the service.
Further information about Cloudflare’s data processing is available in the Cloudflare Privacy Policy.
5. Applying for the closed beta
If you apply for the closed beta, we process the information you submit through the application form. This currently includes your username, email address, city, postcode, short profile, selected interests, motivation, confirmation of the minimum age and — optionally — a social-media profile reference.
The purpose is to review and manage applications, select and contact beta participants, and organize the closed beta. The legal basis is Article 6(1)(b) GDPR; where additional measures are required for security or abuse prevention, Article 6(1)(f) GDPR may also apply.
The application is processed through a server-side endpoint and transmitted to the project mailbox using the Resend email service. A confirmation of receipt may be sent to the email address provided.
Application data is retained only for as long as necessary for selection, contact and organization of the beta. It is then deleted unless statutory retention obligations or legitimate reasons require further storage.
6. Closed beta environment
The closed beta environment is active and is not freely accessible to the public. For approved participants, the data required for access and use is processed. Depending on the feature used, this may include access or account identifiers, technical session data, selected topics, queue and connection status, conversation identifiers, and content entered by users in private conversations.
Where necessary for sign-in, topic selection, queueing, establishing a 1:1 connection and providing the private conversation, processing is based on Article 6(1)(b) GDPR. Safety, abuse-prevention and moderation measures may be based on Article 6(1)(f) GDPR.
TopicPair does not publish the exact personal locations of other participants. Where regional information is part of a beta feature, it serves the relevant topic or conversation context and is processed only to the extent necessary for that purpose.
As the closed beta continues to evolve technically, individual processing activities may change. New categories of data or additional external service providers will not be introduced silently; the privacy information will be updated before or when they are activated in production.
7. Product previews and local browser data
Publicly accessible product previews may store state locally in the browser to demonstrate flows such as topics, joining, demo sign-in or a sample conversation session. These demo states are used solely to demonstrate functionality and generally remain on the device being used.
Depending on the preview, this uses localStorage or sessionStorage The stored information can be deleted using browser controls; session-related data normally ends with the browser session.
Where storage or access is technically necessary to provide a function explicitly requested by the user, it is carried out in accordance with Section 25(2) No. 2 TDDDG without prior consent. Non-essential analytics, marketing or advertising technologies are not used without the required consent.
8. Map and font services
For the public map display, MapLibre GL JS is loaded via jsDelivr and map data is provided by OpenFreeMap. When these resources are requested, the browser may transmit technically necessary connection data — in particular the IP address and request information — to the respective providers.
Several pages also load fonts via Google Fonts. This may likewise cause the browser to establish a direct connection to Google servers.
These integrations support the technical and visual delivery of the website. Where personal data is involved, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in providing a functional and consistent presentation of the service.
9. Contact by email
If you contact us by email, we process your email address, the content of your message and, where applicable, any other information you provide. The processing is carried out in order to handle your request. Depending on the content, the legal basis is Article 6(1)(b) or (f) GDPR.
Requests are deleted once they have been fully resolved, unless statutory retention obligations or legitimate reasons require further storage.
10. No marketing tracking
TopicPair currently does not use its own non-essential marketing or advertising trackers such as Meta Pixel or Google Ads. If such technologies are used in the future, this will occur only after the privacy information has been updated accordingly and — where required — valid consent has been obtained.
11. Recipients and service providers
Personal data is disclosed only to entities or service providers that require it for the purposes described above. In the current public web presence, this includes in particular Cloudflare for delivery and security, Resend for technical email delivery in the application process, and Google Fonts, jsDelivr and OpenFreeMap for embedded web resources.
Where a service provider processes personal data on our behalf, it is engaged in accordance with Article 28 GDPR.
12. International data transfers
Where service providers process data outside the European Economic Area, transfers take place only on a basis provided for under the GDPR, such as an adequacy decision or appropriate safeguards including Standard Contractual Clauses.
13. Retention periods
Personal data is generally retained only for as long as necessary for the relevant purpose. It is then deleted or anonymized unless statutory retention obligations, security reasons, or the establishment, exercise or defense of legal claims require longer retention.
14. Your rights
Subject to the applicable legal requirements, you have, in particular, the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Article 6(1)(e) or (f) GDPR.
Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority. In particular, you may contact the authority responsible for your place of residence or for the location of the controller.
15. Security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access and unauthorized alteration. Security measures are continuously adapted to the relevant feature set and risk level as the beta evolves.
16. Changes to this Privacy Policy
This Privacy Policy will be updated when features, technical service providers or legal requirements change. The version currently published is authoritative.
17. Version
26 September 2026
