1. Who is responsible
The controller within the meaning of the GDPR is:
Synergetic GmbH
Dr.-Helle-Straße 8
59558 Lippstadt, Germany
Richard Ahrend, Managing Director
contact@simplified-webhooks.com
We are not required to appoint a data protection officer. For any question about this policy or about your data, write to the address above and we will answer.
2. Two different roles
2.1As controller. For our website, your user account and our own analytics we decide why and how data is processed. That is what this policy describes.
2.2As processor. The content that flows through the service — the records from the Airtable bases our customers connect — is processed strictly on our customers’ instructions. There, our customer is the controller and we act on their behalf under our Data Processing Agreement. If your data reached us because a company routes its Airtable records through Simplified Webhooks, please contact that company; we will forward any request we receive directly.
3. Visiting the website
3.1When you open a page, your browser transmits technical data that our hosting provider processes to deliver it: IP address, date and time, the page requested, referrer, browser and operating system.
3.2Purpose: delivering the site, security, and troubleshooting. Legal basis: our legitimate interest in operating a functional, secure website (Art. 6(1)(f) GDPR).
3.3Server logs are deleted automatically after 30 days. We do not combine them with other data.
3.4Cookies and local storage. On the public website we set no cookies and store nothing on your device — which is why you see no cookie banner. Once you are logged in, the app uses cookies that are strictly necessary to keep your session alive and secure, and it stores a small amount of data in your browser to make the dashboard work: cached names of your Airtable bases, and form entries preserved while you are redirected through Airtable’s authorisation flow. All of it is required for the functions you have requested, and none of it is used for tracking or passed to third parties. Legal basis: § 25(2) no. 2 TDDDG, and Art. 6(1)(b) GDPR for the processing of the data itself.
4. Analytics and error tracking
4.1We use PostHog to understand how the product is used and to be alerted to errors. PostHog runs on its EU Cloud infrastructure in Frankfurt.
4.2We run PostHog in a configuration that stores nothing on your device — no cookies, no local storage — and that creates no profile for visitors who are not logged in. Because nothing is written to or read from your device, no consent under § 25 TDDDG is required. Requests are routed through our own domain, so no connection to a third-party domain is opened from your browser.
4.3Processed are: pages viewed, interactions with the product, browser and device type, approximate location derived from the IP address, and technical error details. For logged-in users these events are linked to the user account so we can support you and understand how the product performs.
4.4Legal basis: our legitimate interest in a functioning, measurable and reliable product (Art. 6(1)(f) GDPR). You may object at any time under section 11.
4.5We also use Vercel Web Analytics and Vercel Speed Insights to measure page views and loading performance. Both work without cookies and without cross-site identifiers. Legal basis: Art. 6(1)(f) GDPR.
5. Contacting us
5.1Our contact page embeds a form provided by Tally (Tally BV, Belgium). When the page loads, your browser connects to Tally and transmits your IP address. The details you enter — typically your name, email address and message — are processed by Tally on our behalf and forwarded to us.
5.2If you write to us by email instead, we process the content of your message and your address.
5.3Purpose: answering your enquiry. Legal basis: Art. 6(1)(b) GDPR where the enquiry concerns a contract or its initiation, otherwise our legitimate interest in responding (Art. 6(1)(f) GDPR).
5.4We keep correspondence for as long as needed to handle the matter, and longer where statutory retention periods under commercial or tax law apply.
6. Account and use of the app
6.1To use Simplified Webhooks you create an account. We process your email address, your name if you provide it, your password in hashed form, your plan, and authentication data such as sessions and API key hashes. Authentication runs on Supabase.
6.2During use we process the configuration you create — connected bases and tables, the events you subscribe to, destination URLs — and the delivery metadata of your webhooks: timestamps, delivery status, HTTP status codes and error messages.
6.3Purpose: providing the service, billing, support, and security. Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and, for security and abuse prevention, Art. 6(1)(f) GDPR.
6.4We may send you service emails about your account, security, or material changes to the service. Legal basis: Art. 6(1)(b) and (f) GDPR. Marketing emails are sent only with your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
7. Connecting Airtable
7.1When you connect Airtable, we store the access token — either a personal access token you provide or the tokens issued through Airtable’s OAuth flow — encrypted with AES-256-GCM, together with the identifiers of the bases and tables you select.
7.2We use that token solely to read the events and records you have configured and to manage the corresponding Airtable webhooks. You can disconnect at any time in your profile settings, which deletes the stored token; revoking it in Airtable ends our access immediately.
7.3The record content that flows through the service is processed on your instructions as described in section 2.2. Its content is deleted automatically 30 days after the event.
8. Recipients and processors
We use the following service providers, each bound by a data processing agreement under Art. 28 GDPR. They process data only on our instructions.
| Provider | Purpose | Place of processing |
|---|---|---|
| Google Cloud EMEA Limited, Ireland | Hosting of the API and background jobs, secret management | EU — Belgium |
| Supabase, Inc., United States | Database and authentication | EU — Frankfurt |
| Vercel Inc., United States | Hosting of the website and dashboard, web analytics, speed insights | EU — Frankfurt |
| PostHog, Inc., United States | Product analytics and error tracking | EU Cloud — Frankfurt |
| Tally BV, Belgium | Contact form | EU |
Beyond these, we disclose personal data only where we are legally obliged to do so, or where it is necessary to establish, exercise or defend legal claims.
Airtable is not listed here: it is your own system, which we access with the credentials you provide. Your relationship with Airtable is governed by your agreement with them.
9. Transfers outside the EU
All processing described in this policy takes place on infrastructure located in the European Union. Some of the providers listed above are companies established in the United States and may access data from there for support and maintenance. For those cases we have concluded the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with the provider, or rely on another mechanism permitted under Chapter V GDPR.
10. How long we keep data
| Data | Retention |
|---|---|
| Server logs | Deleted automatically after 30 days |
| Webhook event content | Deleted automatically 30 days after the event |
| Delivery metadata (no record content) | For the lifetime of the account |
| Account and configuration data | For the lifetime of the account, then deleted within 30 days |
| Airtable tokens | Until you disconnect or delete your account |
| Correspondence and business records | As long as needed, plus statutory retention periods (generally 6 or 10 years under German commercial and tax law) |
11. Your rights
11.1You have the right to access your data (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20), and to withdraw consent at any time with effect for the future (Art. 7(3)).
11.2Right to object. Where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). Write to contact@simplified-webhooks.com and we will stop unless we can demonstrate compelling legitimate grounds.
11.3You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf.
11.4We do not use automated decision-making or profiling that produces legal effects for you.
12. Is providing data required?
You are not legally obliged to provide personal data. However, we need the data described in sections 6 and 7 to provide the service — without an account and a connected Airtable credential, Simplified Webhooks cannot work. Visiting the website requires no data beyond what your browser transmits automatically.
13. Changes to this policy
We update this policy when the service or the law changes. The current version is always available at simplified-webhooks.com/privacy with its version number and effective date. For material changes affecting registered users, we give notice by email.