Privacy policy

Version of 18 September 2026

English reading aid. This is a translation provided for your convenience. Only the German version of this privacy policy is legally binding; where the two versions differ, the German wording prevails.

Protecting your data matters to us. This policy explains which personal data we process when you use Foreseq.com (“Foreseq” or “the service”), for what purpose and on what legal basis. Foreseq is built for data minimisation: research and dossier data are not stored permanently, only publicly available professional information is processed, and the service runs on servers in Germany.

1. Controller

Q-Rad GmbH, Koßfelderstr. 4, 18055 Rostock, Germany
Represented by: Dr. med. Igor Toker
Email: igor.toker@q-rad.de
Further details in the imprint (German).

2. Hosting

We run Foreseq with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in a data centre in Germany. A data processing agreement (Art. 28 GDPR) is in place with the provider. The web server keeps no permanent access log files containing personal data; technical connection data (in particular the IP address) is processed only temporarily in order to deliver the pages and to fend off attacks. The legal basis is our legitimate interest in secure and efficient operation (Art. 6(1)(f) GDPR).

3. Visiting the website

When you open our pages, we process the technically necessary connection data (for example IP address, time of the request, requested resource) in order to deliver the content and ensure the security of the service. Legal basis: Art. 6(1)(f) GDPR.

4. Cookies and usage measurement

Foreseq uses strictly necessary cookies only. For signed-in users, the application uses an encrypted session cookie (HttpOnly) and a cookie protecting against cross-site request forgery (CSRF). These cookies are required for operation and contain no tracking information. We use no analytics, advertising or tracking cookies. Legal basis: section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6(1)(f) GDPR.

a) Usage measurement with Umami

To understand how our service is used, we use the analytics software Umami. Umami runs on our own server in Germany (see clause 2). No data is transmitted to third parties and the data does not leave our server.

The measurement works without cookies and without recognising you beyond a single visit. Your IP address, your browser identifier (user agent) and a random value that changes daily are combined into an irreversible checksum, which merely holds the page views of one visit together. The IP address itself is not stored; because the random value changes every day, recognising you on the following day is technically impossible.

We record: the page viewed, the referring source, country of origin, device type, screen size, browser and language, as well as individual events (for example clicking a button). Parameters in the address bar are removed before storage. No content is recorded – in particular no names of researched people, no calendar events, no dossier content and no search queries. Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in designing our service to meet actual demand.

Since no information is stored on your device for this measurement, no consent under section 25(1) TDDDG is required. The measurement script only reads a local switch (umami.disabled in local storage) with which you can turn the measurement off permanently; this read access serves solely to respect your objection.

b) Objecting to the usage measurement

You can object to the usage measurement at any time. We automatically respect the “Do Not Track” and “Global Privacy Control” settings of your browser. In addition, you can switch the measurement off permanently for this browser here:

c) Analysis of account usage

For signed-in users we additionally evaluate key facts about their own account statistically in order to improve the product: time of registration, sign-in method used, whether and when a calendar was connected, when the first dossier was created, the number of dossiers created, and whether a paid subscription exists. This is account master data; the content of your dossiers, your calendar events and data about researched people are not part of this analysis. Legal basis: Art. 6(1)(f) GDPR.

5. Signing in with Google and calendar access

If you sign in with your Google account, we use Google OAuth. The permissions requested are openid, email, profile and read-only calendar access (calendar.readonly).

The legal basis is your consent (Art. 6(1)(a) GDPR) through granting the Google permission, as well as the performance of the user relationship (Art. 6(1)(b) GDPR). You can revoke the permission at any time in your Google account settings.

6. Creating the dossiers (core function)

At your request, Foreseq creates a source-backed dossier about a person you select or enter (for example a meeting participant). For this we process that person’s name and – if provided – their company or organisation.

The legal basis is our legitimate interest in efficient, fact-based preparation for professional meetings (Art. 6(1)(f) GDPR). Data subjects can assert their rights (see clause 11) against us.

Information for the people researched (Art. 14 GDPR)

The data about the person researched does not come from that person but from publicly available sources. In principle, this triggers an obligation to inform under Art. 14 GDPR. Notifying each person individually is not possible for us without increasing the interference: we hold no contact details for the person researched – we deliberately exclude private email addresses and phone numbers – and the research results are not stored, so after the request there is no longer any basis for a notification. Obtaining and keeping such details would require more data than the research itself. We therefore rely on the exception in Art. 14(5)(b) GDPR (disproportionate effort) and instead provide the information required under Art. 14(1) and (2) GDPR publicly here – in particular on the purpose (this clause), the categories of data (professional, publicly available information), the source (publicly available internet sources), the recipients (clause 7), the storage period (clause 10) and the rights of data subjects (clause 11).

Anyone who does not want a dossier to be created about them can object to us at the address given in clause 1 (Art. 21 GDPR). We implement the objection and will not create any further dossiers about that person.

7. External services used and transfers to third countries

For research and dossier creation we use external service providers that process data on our behalf or as independent controllers. This may involve a transfer to the USA. Such transfers take place on the basis of appropriate safeguards, in particular the EU standard contractual clauses (Art. 46 GDPR) or – where the provider is certified – an adequacy decision (EU-US Data Privacy Framework). We transmit only the data required for the respective function.

a) Google (sign-in and calendar)

Google Ireland Limited / Google LLC. Data transmitted: OAuth and calendar data as described in clause 5.

b) OpenAI (web search and AI dossier)

OpenAI (USA). Data transmitted: name, company or organisation and, where applicable, the email domain. OpenAI performs the web search itself; the search queries contain the name and, where applicable, the company of the person researched.

c) Stripe (payment processing)

For the paid Business subscription we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland; data may be transferred to Stripe, Inc. in the USA). When a subscription is concluded and managed, Stripe processes the data required for this: name, email address, payment data (for example card details), invoice and turnover data. Payment data is entered directly with Stripe and does not reach our servers; we store only a Stripe customer reference, the plan booked and the subscription status. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and our statutory retention obligations (Art. 6(1)(c) GDPR). The transfer to the USA takes place on the basis of the EU standard contractual clauses or the EU-US Data Privacy Framework. Further information: https://stripe.com/privacy.

d) Resend (transactional emails)

For sending account-related emails – confirmation of registration, password reset, confirmation of a cancellation – we use the service Resend (Resend, Inc., USA). Data transmitted: email address, name where applicable, and the content of the respective message. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). The transfer to the USA takes place on the basis of the EU standard contractual clauses.

8. Fonts and external media

On our public pages we embed fonts from Google Fonts (Google Ireland Limited); when they are loaded, your IP address is transmitted to Google. In the application, portrait images from public search results are loaded from the respective source servers; in doing so, your IP address is transmitted to the respective provider. Legal basis: Art. 6(1)(f) GDPR (an appealing and functional presentation).

9. Newsletter and waiting list

Using the signup form on our website, you can join our waiting list to be informed about the launch of Foreseq.com and to receive a discounted launch offer. We process the data you provide: first name, last name and email address (mandatory), and – if provided – company and country. To document your consent, we additionally store the time of signup and confirmation.

Signup uses the double opt-in procedure: after submitting the form you receive an email containing a confirmation link. Only after you confirm it do we add you to the distribution list. This ensures that the address given actually belongs to you.

For sending and managing the waiting list we use the service Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany). Brevo processes the data mentioned as a processor on our behalf; a data processing agreement (Art. 28 GDPR) is in place.

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future – via the unsubscribe link in every email or by a message to the contact details given in clause 1. After a withdrawal, or after the market launch has been completed, your data is deleted from the distribution list unless statutory retention obligations prevent this.

10. Storage period

We do not store personal data for longer than is necessary for the purposes described. Research and dossier data are not stored permanently. The session cookie ends when you sign out or when the session expires. The data from the usage measurement (clause 4a) cannot be related to a person even at the point of collection; it is kept in aggregated form. Account data is stored for the duration of the account relationship.

11. Your rights

You have the following rights:

You can withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR). To do so, contact us using the details given in clause 1. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania.

12. Data security

Transmission is encrypted via TLS (https). We take technical and organisational measures to protect your data against unauthorised access, loss or manipulation.

13. Changes to this privacy policy

We adapt this privacy policy when the underlying processing or the legal situation changes. The current version published here applies.