Ouhud GmbH
Deutschland · DSGVO/BDSG/TDDDG
Information pursuant to Art. 13 and 14 GDPR and Art. 19 of the Swiss Data Protection Act for OUHUD Search Intelligence.
This is a convenience translation. The legally binding version of this document is the German one.
Brief overview
OUHUD Search Intelligence is a B2B platform for SEO, content and measurable AI visibility. We do not use advertising or reach cookies for a mere visit. Personal data arises above all during the site audit, with accounts and teams, and when customers use content, websites, integrations or AI features.
Ouhud GmbH
Deutschland · DSGVO/BDSG/TDDDG
Ouhud Digital GmbH (in Gründung)
Switzerland · contact point being established
This policy applies to the websites and product interfaces we operate that refer to it, to the public site audit and to the platform OUHUD Search Intelligence with the modules Site Audit, Crawler, Knowledge, Topics, Content Studio, AI Visibility, Analytics and Publisher. It also applies to contract-related communication, support and — where enabled — subscription and payment features.
For persons in the European Union and the European Economic Area, the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and, for access to terminal devices, the Telecommunications Digital Services Data Protection Act (TDDDG) apply in particular. For processing with effects in Switzerland, the Swiss Data Protection Act (FADP) and the Data Protection Ordinance (DPO) apply in addition. Until registration and effective assumption of the Swiss business activity, Ouhud GmbH is the controller. The Swiss company in formation serves as an additional contact point.
Ouhud GmbHKaiserswerther Straße 13540474 DüsseldorfDeutschland
Ouhud Digital GmbH (in Gründung)Zürich, Schweiz
Before its entry in the commercial register, Ouhud Digital GmbH (in formation) does not yet have its own legal personality and is therefore not presented as sole controller. Until registration, Ouhud GmbH remains responsible; info@ouhud.ch ist eine zusätzliche Kontaktmöglichkeit für Personen in der Schweiz.
After entry in the commercial register and an effective assumption of the business activity, we will update this policy without delay with the exact company name, full business address, CHE number, authority to represent and allocation of responsibilities. Until then, the contact point is not to be understood as a formally designated representation under Art. 14 FADP.
We decide ourselves on the purposes and means of processing when operating our website, in the public site audit, in account and organisation management, authentication, security, billing and our own customer and support communication. For this we are the controller within the meaning of the GDPR or the controller under the Swiss FADP.
Soweit ein Kunde eigene Dokumente, Website-Inhalte oder personenbezogene Daten in der Plattform verarbeitet und wir ausschließlich nach seiner Weisung handeln, ist der Kunde Verantwortlicher und wir sind Auftragsverarbeiter nach Art. 28 DSGVO beziehungsweise Auftragsbearbeiter nach Art. 9 DSG. Dafür gilt unser data processing agreement. In this case data subjects receive the relevant information primarily from the respective customer; we forward their requests to that customer or support it in handling them.
The data comes from the data subject, from an administrator of their company, from an integration they have connected, from the use of the platform or from publicly accessible websites. Those affected may include prospects, customers, their employees and team members, support contacts as well as persons whose details appear in provided or publicly accessible content.
Depending on the operation, we process personal data on the basis of:
Employees and other users of a business customer are often not themselves contracting parties. We then process their account and usage data in particular on the basis of Art. 6 (1) (f) GDPR; our interest is the contractual provision of the platform to the organisation.
Under the Swiss FADP we process data in accordance with the principles of Art. 6 to 8 FADP. Where a justification is required, processing is based on consent, a statutory basis or overriding private or public interests within the meaning of Art. 31 FADP. The conclusion and performance of a contract may constitute an overriding private interest. The purposes and interests set out above apply accordingly.
Special categories of personal data are not required for ordinary use. Customers may only provide such data if this is lawful, necessary and agreed with us.
When the site is accessed, the delivering systems may receive in particular the full IP address, date and time, requested address and HTTP method, status code, volume of data transferred, referring page as well as browser and operating system details. This information is necessary for the connection, error analysis, capacity management and defence against abusive or harmful access.
Purposes and legal basis: technische Bereitstellung und Sicherheit; Art. 6 Abs. 1 lit. f DSGVO beziehungsweise unsere überwiegenden privaten Interessen nach Schweizer Recht. Recipients: befugte Mitarbeitende und der tatsächlich eingesetzte Hosting- beziehungsweise Infrastrukturbetreiber. Der konkrete Anbieter und Standort werden vor dem Produktivbetrieb in der service provider list ausgewiesen.
Log data is deleted or anonymised as soon as it is no longer required for operation, security and evidence and no legal obligation or specific security incident stands in the way. A fixed, system-wide period depends on the final hosting configuration and will be added before its production activation.
geo_sessionAfter signing in, we store the technically necessary cookie in the browser geo_session. Es enthält eine zufällige Sitzungskennung; serverseitig wird nur ihr SHA-256-Prüfwert gespeichert. Das Cookie ist httpOnly, SameSite=Lax and, in the production environment, limited to secure HTTPS connections. It expires on sign-out or after 30 days at the latest.
ouhud-themeIf you choose between light and dark appearance, we store that choice under ouhud-theme in your browser's local storage. The value remains there until you change it or clear the browser storage, and it is not transmitted to us for advertising or analytics purposes.
Both storage accesses serve a service you have expressly requested and are based in Germany on § 25 (2) no. 2 TDDDG. The subsequent processing of session data is based on Art. 6 (1) (b) or (f) GDPR. We currently do not use cookies or comparable techniques for advertising, reach measurement or cross-site recognition. Therefore no consent banner is currently required. Should we introduce non-essential technologies, we will obtain the necessary consent beforehand. Fonts are served locally.
If you consent to the “Reach measurement” category, we record which page was opened, which host name referred you, whether you use a phone, tablet or computer, and your display language. In addition, a random number is placed in your browser's session storage to link the page views of one visit; it is created only after your consent, applies to this browser window only and is gone when you close it.
We do not store your IP address, your browser identifier, query parameters from the address bar, or the full referring URL — with search engines that would contain your search query. No cookie is set and no service provider is involved: the counting runs on the same servers as the platform. We can only evaluate it in aggregate; individual page views are not retrievable, not even by us.
The legal basis is your consent under § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. You can withdraw it at any time via “Cookie settings” in the footer; from that moment nothing further is collected. The data is deleted automatically after 90 days.
If you have a domain checked, we process the entered and normalised domain, a random result token, the status and result of the check, timestamps, your full IP address and the user agent. If a corresponding feature is offered and used by you, we additionally process your e-mail address in order to assign or send the result.
Unser Server ruft die öffentlich erreichbare Startseite und die Datei robots.txt of the specified domain. The target server technically receives the IP address and browser identifier of our server, not your personal IP address. Publicly visible content may incidentally contain names or contact details.
Zwecke: Carrying out the requested check, retrieving the result, error analysis, security and a limit of five checks per IP address per hour. Rechtsgrundlage: Art. 6 (1) (b) GDPR applies to the details of the requesting user and the service provided to them. Operation and abuse protection as well as incidentally collected third-party data on the target website are based, where we are the controller ourselves, on Art. 6 (1) (f) GDPR and a balancing of interests. For users of a business customer, Art. 6 (1) (f) GDPR may apply overall. Under Swiss law, the corresponding overriding private interests apply.
The audit records are retained according to the criteria described in section 17. A fixed automatic deletion period is not yet technically set up for these records. A deletion request can be addressed to our data protection contact; statutory retention or defence interests remain reserved.
For registration and account management we process name, business e-mail address, organisation names, roles, memberships, inviter, invitation status, times of registration and sign-in as well as the last login. Passwords are stored exclusively as an irreversible Argon2 hash. Other team members of the same organisation can see name, e-mail address, role and last login insofar as this is intended for team management.
For sessions we process a token hash, full IP address, user agent, creation, expiry and last use time as well as the active organisation. Users can view and revoke their active sessions. Team invitations contain e-mail address, role, inviter and a token hash; an invitation link is valid for 14 days.
For a password reset we store the user reference, token hash, full request IP, expiry and use. The link is generally valid for 60 minutes; the record is deleted seven days after use or expiry. Zwecke: Kontobereitstellung, Zugriffskontrolle, Teamverwaltung, Missbrauchsabwehr und Sicherheitsnachweis. Rechtsgrundlage: Art. 6 (1) (b) or (f) GDPR as well as corresponding contractual and security interests under Swiss law.
Account deletion is currently handled via the data protection contact and implemented administratively; a self-service function is not yet available. Contractual, security and legally retained data may be excluded from deletion.
For invitations, password resets and other operationally necessary messages, recipient address, subject, message type, status, error message, attempt count and timestamps are processed. The content is transmitted to the configured SMTP service and may temporarily rest in the task queue during delivery. Separately stored technical task results expire after seven days. The local delivery log does not store the message text. The retention period for pending messages and delivery logs depends on the final infrastructure configuration and must be laid down bindingly before production operation.
If you contact us by e-mail, we process sender and recipient data, times, subject, content and attachments as well as the correspondence arising from handling the matter. Purposes and legal basis: Bearbeitung Ihrer Anfrage, Vertragsdurchführung und Dokumentation; Art. 6 Abs. 1 lit. b oder f DSGVO, bei gesetzlichen Pflichten Art. 6 Abs. 1 lit. c DSGVO, beziehungsweise die entsprechenden Grundlagen nach Schweizer Recht. Wir betreiben derzeit keinen Newsletter und kein Kontaktformular.
If you write to info@ouhud.ch, the person acting for the formation may receive your message and forward it for handling to the responsible Ouhud GmbH in Germany. The contact and content data contained in the message is thereby transferred between Switzerland and Germany.
The production e-mail and mailbox provider will be added to the service provider list with identity, location and transfer basis before it is used.
In projects we process domains, full URLs and paths, page titles, meta information, headings, language, link targets and anchor texts, technical findings, errors as well as crawl and check times. This data comes from the websites named by the customer and their publicly accessible pages. It may contain names of authors, contacts, reviewers or persons named in the legal notice.
Zweck: technical and content analysis, error detection, SEO evaluation and preparation of the reports requested by the customer. Where we act on customer instructions, the contract and the customer's documented instructions apply; the customer is responsible for the legal basis and for informing data subjects. Where we exceptionally process data under our own responsibility, this is based on Art. 6 (1) (f) GDPR and our interest in the requested website analysis, or on corresponding overriding interests under Swiss law.
For data not collected directly, this page simultaneously contains the information under Art. 14 GDPR and Art. 19 FADP. Where individual notification is legally required and no exception applies, it takes place within the statutory periods. Where individual notification would involve disproportionate effort because of the volume of publicly accessible web pages and the statutory conditions are met, we make this information publicly available, limit the purposes and observe deletion and objection requests.
When customers provide documents or content, we store and process in particular the original file name, the file and object storage reference, extracted text and text sections, entities, facts, source references, topics, briefs, drafts, revisions, quality reports, approvals and publication status. Vector embeddings may optionally be generated in order to retrieve relevant text sections.
Zwecke: Building the customer's own operational knowledge, research, topic planning, creation and review of content as well as traceable approval. As a rule we process this data as processor on the customer's instructions. Knowledge documents deleted on the customer side are first soft-deleted and removed from the active object storage after 30 days; the associated operation history is deleted after 90 days.
AI features depend on the configuration and are only used if they are enabled for the respective environment. Depending on the feature, organisation name, topics, URLs, selected knowledge sections, confirmed facts, prompts, drafts or texts to be checked may be transmitted to a language model or search provider. For vector embeddings, the selected text sections or search queries are processed. AI Visibility can send customer-defined questions to search or AI interfaces and store answer excerpts, sources and measured values.
Technisch vorgesehen sind – abhängig von Vertrag und Aktivierung – Dienste von Anthropic, OpenAI und Perplexity. Ob ein Dienst aktuell eingesetzt wird, welche Gesellschaft Vertragspartner ist, in welchem Staat verarbeitet wird, welche Aufbewahrung gilt und auf welcher Transfergrundlage die Übermittlung erfolgt, weist die aktuelle Dienstleisterliste . A service marked as “planned” or “open” is not yet a statement about productive use.
OUHUD does not use customer content to train a general-purpose AI model of its own. We only make a statement about use by external providers if the specific contract and the technical configuration bindingly exclude it; these conditions are documented before activation. Customers should not include personal or confidential data in free prompts where it is not necessary for the respective purpose. AI outputs may be incorrect and must be reviewed by a human before use or publication.
Customers can — where enabled for their environment — connect their own services. Technically envisaged or implemented are, among others, WordPress, Bing Webmaster Tools, IndexNow, webhooks as well as interfaces for Google Search Console and Google Analytics 4. Account identifiers, OAuth or API credentials, website and property IDs, search queries, page URLs, performance metrics, content, publication status and technical events may be processed in this context.
Credentials are stored encrypted. Transfers only take place after connection or activation by an authorised user: for example content to the customer's own WordPress system, signed events to a webhook determined by the customer or URLs to IndexNow. These parties receive data on the customer's instruction. Depending on the service and contract they may be the customer's system, the customer's processor or an independent controller; their own privacy notices apply to their own processing.
OUHUD Analytics evaluates imported project and performance data or such data generated within the platform. It is not visitor tracking on our public website. Rechtsgrundlage: Contract and customer instruction or Art. 6 (1) (b) or (f) GDPR as well as the corresponding bases under Swiss law.
If paid subscriptions and Stripe are activated for the respective environment, we transmit to Stripe in particular the business e-mail address, organisation identifier, price, customer and subscription references for checkout and the customer portal. In its own payment area, Stripe additionally processes payment, invoicing and, where applicable, address data. Complete card or account data is not stored on our systems. We receive and store in particular Stripe IDs, plan, status, timestamps and reduced event data.
Purposes and legal basis: Contract initiation, subscription management, payment and accounting; Art. 6 (1) (b) and (c) GDPR as well as corresponding contractual and statutory bases under Swiss law. Where Stripe itself decides on purposes and means for individual payment services, Stripe is an independent controller. The deployment status and the specific contracting party are set out in the service provider list.
Personal data is received only insofar as this is necessary for the respective purpose by:
Auftragsverarbeiter werden vertraglich gebunden und erhalten nur die für ihre Aufgabe erforderlichen Daten. Die list of service providers and data recipients names the provider, purpose, processing location and deployment status. As long as a provider is listed there only as “planned” or “open”, its identity, processing location and contractual or transfer basis must be completed before productive use.
Wir weisen den tatsächlich betroffenen Staat und die verwendete Garantie in der Dienstleisterliste aus. Daten werden nur dann in einen Staat außerhalb des Europäischen Wirtschaftsraums beziehungsweise – aus Schweizer Sicht – ins Ausland übermittelt, wenn die gesetzlichen Voraussetzungen erfüllt sind. Der Austausch zwischen der deutschen verantwortlichen Stelle und der Schweizer Gründungskontaktstelle kann insbesondere bei Anfragen über info@ouhud.ch erforderlich sein.
Transfers are based on an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, in particular the European Commission's standard contractual clauses with the necessary supplementary measures. From an EU perspective, an adequacy decision exists for Switzerland. For US recipients, an EU-US Data Privacy Framework is only relied upon if the specific recipient is currently certified; otherwise another effective transfer basis is required.
Germany and the EU and EEA states are in principle deemed states with adequate data protection under Annex 1 DPO. For other states, disclosure under Art. 16 FADP takes place only with adequate protection or with permissible safeguards, in particular recognised standard data protection clauses with the adaptations required for Switzerland and supplementary measures. For a US recipient, the Swiss-U.S. Data Privacy Framework is only relied upon if the specific recipient is currently certified for it. A statutory exception is used only in individual cases. A copy of the relevant safeguards can be requested via our data protection contact; trade secrets may be redacted.
We store data only for as long as the respective purpose, the contract, security and evidence interests or legal obligations require. It is then deleted or anonymised. In the event of a legal dispute or official proceedings, deletion may be suspended until conclusion. For data we process on behalf of a customer, that customer's documented instructions and the data processing agreement additionally apply.
| Data | Period or criterion |
|---|---|
| Session cookie | until sign-out, 30 days at the latest; server-side security records once the purpose ceases |
| Password reset | link generally valid for 60 minutes; record 7 days after use or expiry |
| Platform audit log | IP address and user agent anonymised after 30 days; event deleted after 730 days |
| Deleted knowledge documents | 30 days until final removal from active storage |
| Knowledge operation history | 90 days |
| Temporary task results | 7 days |
| Public audits, accounts, teams, projects, content and integrations | until the purpose or contract ends; thereafter upon a deletion request or a controlled administrative process, unless an obligation or legal defence stands in the way |
| Commercial and tax records in Germany | accounting vouchers and invoices generally 8 years, commercial and business letters 6 years, certain books and financial statements 10 years; longer periods possible in individual cases |
For categories without a fixed technical period, a binding deletion concept including hosting, log and backup periods will be defined before production operation. Until full automation, deletion requests are implemented administratively in a controlled manner.
We take technical and organisational measures appropriate to the risk. These include in particular encrypted transmission in the production environment, Argon2 password hashes, hashed session tokens, encrypted integration credentials, role-based permissions, separation of customer organisations, private object storage, logging of security-relevant actions as well as scanning and isolated processing of uploaded files. Only persons and systems that need it for their task are granted access. Absolute security can nevertheless not be guaranteed.
There is currently no solely automated decision that produces legal effects concerning a person or similarly significantly affects them (Art. 22 GDPR or Art. 21 FADP). Assessments, prioritisations and texts of the platform are working aids; publication in particular requires human approval. We do not use personal data for advertising profiles. Should this change, we will inform in advance about the logic, significance, consequences and the right to human review.
Subject to the statutory conditions, you have the right to:
Widerspruch: Where we process data on the basis of legitimate interests, you may object on grounds relating to your particular situation. We will cease processing unless we demonstrate compelling legitimate grounds or the establishment, exercise or defence of legal claims. You may object to processing for direct marketing at any time without giving special reasons.
Richten Sie Ihre Anfrage an info@ouhud.com. To protect your data, we may request suitable proof of identity. We generally respond within one month; in complex cases provided for by law, the period may be extended by up to two months.
Under Swiss law you may in particular request information about whether and which personal data we process about you (Art. 25 FADP), have inaccurate data rectified and, depending on the case, request erasure or destruction as well as a prohibition of a particular processing or disclosure (Art. 32 FADP). For automated processing based on consent or a contract, a right to release or transfer in a common electronic format may exist (Art. 28 FADP). You may withdraw consent for the future. In the case of an automated individual decision you may, under Art. 21 FADP, request human review and present your own point of view.
We generally provide information within 30 days. Statutory limitations and grounds for refusal remain reserved. Swiss data subjects may assert claims in court and report a possible violation to the FDPIC.
Anfragen aus der Schweiz richten Sie an info@ouhud.ch oder an den oben genannten Verantwortlichen in Deutschland.
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Complaint to the LDI NRW
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
CH-3003 Bern
Telefon +41 58 462 43 95
Contact and reporting options at the FDPIC
Within the scope of the GDPR, you may also contact another competent supervisory authority, in particular at your place of residence, place of work or the place of the alleged infringement. For reports under the Swiss FADP, the FDPIC is competent.
At least one domain is required for the public audit. For an account we need the marked registration and access details; without them we cannot provide an account, team access or a contract. Optional details and integrations are voluntary; without them only the respective additional feature is unavailable. We indicate statutory or contractual obligations to provide data in individual cases.
The platform is aimed at businesses and professional users, not at children or adolescents. We do not knowingly collect data from minors for our own purposes. Customers may only process data of minors if this is lawful and compatible with the agreed purpose of use.
We update this policy when features, providers, the legal situation or processing operations change. The version published on this page with its date is decisive. We inform customers in an appropriate form about material changes affecting an existing contractual relationship. Earlier versions are documented internally.
This text is a draft and does not replace legal advice. Before publication it should be reviewed by a lawyer specialising in IT and data protection law — in particular the liability rules and the statements on data processing.