Montella — Privacy Policy

Datenschutzerklärung
Last updated: 27 July 2026

This Privacy Policy explains how Yanay Brook, trading as “Montella” (“Montella”, “we”, “us”), processes personal data when you visit our website, communicate with us, or use the Montella platform and AI agents (together, the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller and Contact

Controller (Verantwortlicher): Yanay Brook, trading as “Montella”, Oskar-Helene-Park 36, 14195 Berlin, Germany.

Contact for data protection matters: team@montella.dev. Full provider details are in our Impressum at https://montella.dev/impressum.

We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR / § 38 BDSG. You can raise any data protection matter using the contact details above.

2. Scope of this Policy and Our Two Roles

(1) This Policy covers personal data for which Montella is the controller — that is, where we decide why and how data is processed. This includes visitors to our website, people we contact for business development, our business contacts and clients’ representatives, and users of our own accounts and tools.

(2) Where we act only as a processor — that is, where we run our AI agents or platform on data provided by a business client — the client is the controller and decides the purposes of processing. That processing is governed by a data processing agreement (Auftragsverarbeitungsvertrag, Art. 28 GDPR) between us and the client, not by this Policy. If you are an individual whose data a client processes through the Service, please contact that client to exercise your rights (see Section 10).

3. Your Data Protection Rights

Where Montella is the controller, you have the following rights, subject to the conditions in the GDPR:

- Access (Art. 15) — to obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) — to have your data deleted where the legal conditions are met.
- Restriction (Art. 18) — to have processing restricted in certain cases.
- Data portability (Art. 20) — to receive data you provided in a structured, commonly used, machine-readable format.
- Objection (Art. 21) — to object to processing based on our legitimate interests. You may object to direct marketing at any time, and we will stop such processing.
- Withdraw consent (Art. 7(3)) — where processing is based on consent, you may withdraw it at any time with effect for the future.
- Not to be subject to solely automated decisions (Art. 22) that produce legal or similarly significant effects (see Section 11).

Right to complain (Art. 77): You may lodge a complaint with a supervisory authority. The authority competent for Montella is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI), Alt-Moabit 59–61, 10555 Berlin.

4. Website Use and Hosting

(1) When you visit our website, our hosting providers automatically process server log data, including your IP address, browser type and version, the pages you visit, and the date and time of access. This is necessary to deliver the website securely and reliably.

(2) Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a secure, functioning website. Retention: server logs are retained for 30 days and then deleted.

(3) Our marketing website is hosted by Framer B.V. (Amsterdam, Netherlands), within the EU. Our platform and application infrastructure is provided by Vercel, Inc. (USA); transfers to the USA are protected by the EU Standard Contractual Clauses (see Sections 14–15).

5. Cookies and Consent

(1) We use cookies and similar technologies that are strictly necessary to operate the website and the Service. These do not require consent (§ 25(2) TDDDG; Art. 6(1)(f) GDPR).

(2) We currently do not deploy third-party analytics or advertising cookies. If we introduce non-essential cookies or analytics in the future, we will request your consent through a cookie banner beforehand (§ 25(1) TDDDG; Art. 6(1)(a) GDPR), and you will be able to withdraw it at any time.

6. Contacting Us

(1) If you contact us by email or through a contact form, we process the data you provide (such as your name, email address and message) to handle your enquiry and any related correspondence.

(2) Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or pre-contractual steps; otherwise Art. 6(1)(f) GDPR (our legitimate interest in responding to enquiries). Retention: for as long as needed to handle your enquiry and any follow-up, then deleted unless retention is required by law.

7. Business Development and Marketing (B2B)

(1) We identify and contact decision-makers and representatives at businesses in the real estate sector to offer our services. We may use publicly available professional data and business networks (e.g. LinkedIn) and process your name, job title, employer, business contact details, public professional profile and our interaction history with you.

(2) We also send business emails (including reports) and measure delivery, opens and clicks to understand engagement. For this we process your business email address, name, employer and email-engagement data.

(3) Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in B2B direct marketing and in measuring its effectiveness. We keep our outreach targeted and relevant, and § 7 UWG is observed. Retention: prospect data is kept for up to 24 months from the last meaningful contact; email-engagement logs for 12 months; then deleted or anonymised.

(4) Your choice: you can object to this processing at any time (Art. 21 GDPR) using the contact details in Section 1 or the opt-out in our messages, and we will stop contacting you.

8. Business Relationship and Contact Management

(1) We maintain records of our business contacts, prospects and clients’ representatives — including name, role, employer, business contact details, notes, meeting history and deal status — to manage our relationships and pipeline.

(2) Legal basis: Art. 6(1)(f) GDPR (managing business relationships) and, where steps are taken toward a contract at your request, Art. 6(1)(b) GDPR. Retention: for the duration of the business relationship; dormant contacts are reviewed and pruned periodically.

9. The Montella Platform and AI Agents

(1) When you use the Service under your own account, we process your account and usage data (such as your name, business email, role, login and activity data) to provide, secure, maintain and support the Service, and we process the content you submit (“Inputs”) to generate outputs for you.

(2) Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the Service) and Art. 6(1)(f) GDPR (securing and improving the Service).

(3) Use of data for improvement: we may use aggregated and anonymised data — which no longer identifies you or any individual — to analyse and improve the Service. We do not use your Inputs or content to train general-purpose AI models for other customers without your consent.

(4) To generate outputs, Inputs may be transmitted to third-party AI model providers acting on our behalf; where available we use EU endpoints and no-training options (see Section 14).

10. Where We Act as a Processor for Business Clients

(1) A core part of the Service is running AI agents and workflows on data provided by our business clients (for example, letting and outreach support, reporting, and back-office automation). In that case the client is the controller and Montella is the processor. We process such personal data only on the client’s documented instructions under an Art. 28 GDPR data processing agreement.

(2) For that processing, personal data is handled transiently to deliver the Service and is not stored persistently on our systems; any data we retain is aggregated or anonymised so it no longer identifies a person. No special categories of personal data (Art. 9 GDPR) are processed unless the client has expressly agreed this in writing with additional safeguards.

(3) Your rights: if you are an individual whose personal data a client processes through the Service, please direct requests to that client as the controller. We will support the client in responding, and will forward any request we receive directly to the relevant client without undue delay.

11. Automated Processing and AI Transparency

(1) The Service uses artificial-intelligence models to generate outputs. Outputs are produced by automated means and may be inaccurate or incomplete; they are intended to support, not replace, human decision-making, and are reviewed by a person before being relied upon.

(2) We do not use the Service to make decisions based solely on automated processing that produce legal or similarly significant effects on you within the meaning of Art. 22 GDPR. Where we or our clients would deploy such processing, appropriate safeguards and human oversight are put in place.

(3) Where required by applicable law, including Regulation (EU) 2024/1689 (the EU AI Act), we disclose that content is AI-generated or that you are interacting with an AI system.

12. Accounting, Invoicing and Legal Obligations

(1) To issue invoices, keep our books and meet tax obligations, we process billing and transaction data (such as name, business/billing address, contact and payment data, and invoice data), and share it with our accountant, the tax authority (Finanzamt, via ELSTER), our bank and DATEV, as required.

(2) Legal basis: Art. 6(1)(c) GDPR (legal obligations under the HGB, AO and UStG) and Art. 6(1)(b) GDPR (contract performance). Retention: statutory retention periods apply, generally 8–10 years (§ 147 AO, § 257 HGB).

13. Investor and Other Business Relations

We process contact and correspondence data of investors and other business partners to manage those relationships. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in these relationships) and Art. 6(1)(b) GDPR for pre-contractual steps. Retention: for the duration of the relationship, then pruned when no longer relevant.

14. Recipients and Sub-processors

We use carefully selected service providers who process personal data on our behalf under data processing agreements (Art. 28 GDPR), and disclose data to statutory recipients where legally required. The main recipients are:

Recipient — Purpose — Location — Transfer safeguard

Framer B.V. — Marketing website hosting — Netherlands (EU) — None needed (EU)
Vercel, Inc. — Platform hosting / infrastructure — USA — EU SCCs
Resend, Inc. — Email delivery & tracking — USA — EU SCCs
Formagrid, Inc. (Airtable) — CRM / data storage — USA — EU SCCs
Google LLC (Workspace) — Email, documents, storage — USA — EU-US DPF + SCCs
Anthropic / OpenAI — AI model inference for agents — EU / USA — EU SCCs; EU endpoint / no-training where available
Canva — Design / proposals — Australia / USA — EU SCCs
Qonto (Olinda SAS) — Business banking — France (EU) — None needed (EU)
DATEV eG — Bookkeeping — Germany (EU) — None needed (EU)
GlobalTax — External accounting / tax — Germany (EU) — None needed (EU)
Finanzamt / ELSTER — Statutory tax filing — Germany (EU) — Not applicable
LinkedIn — Business-development outreach — Ireland (EU) / USA — EU SCCs

Because our platform processing is transient, several providers process personal data only in transit rather than storing it. We do not sell personal data.

15. International Data Transfers

Some recipients are located outside the EU/EEA (in particular in the USA). Where we transfer personal data to such recipients, we rely on appropriate safeguards under Chapter V GDPR — primarily the EU Standard Contractual Clauses, and, for providers certified under the EU-US Data Privacy Framework, an adequacy decision. You may request a copy of the relevant safeguards using the contact details in Section 1.

16. Data Retention

We keep personal data only as long as necessary for the purposes described above or as required by law. In summary:

Data — Retention period

Website server logs — 30 days
Contact / enquiry data — Until the enquiry is resolved, then deleted (unless legally required)
Prospect / outreach data — Up to 24 months from last meaningful contact
Email-engagement logs — 12 months, then aggregated / anonymised
CRM / business-contact data — Duration of the business relationship, reviewed periodically
Accounting / tax records — 8–10 years (§ 147 AO, § 257 HGB)
Client data processed via the platform — Transient; returned or deleted per the client’s Art. 28 DPA

17. Data Security

We implement appropriate technical and organisational measures to protect personal data (Art. 32 GDPR), including individual accounts and least-privilege access, strong unique passwords, encryption in transit (TLS), data minimisation, access logging, and a documented process for detecting and handling personal data breaches. We keep these measures under review as the Service develops.

18. No Processing of Children’s Data

The Service is intended for businesses and professionals and is not directed at children. We do not knowingly process the personal data of children.

19. Changes to this Policy

We may update this Policy to reflect changes to the Service or to legal requirements. The current version is always available on our website with the “Last updated” date shown above. Where changes are material, we will take reasonable steps to inform affected users.

20. How to Contact Us

For any question about this Policy or to exercise your rights, contact: Yanay Brook, trading as “Montella”, Oskar-Helene-Park 36, 14195 Berlin, Germany — team@montella.dev.