Privacy Policy

The German version of this Privacy Policy is authoritative. The processing described here is governed by applicable European Union and German data protection law. The English text below is provided as an automatic convenience translation only and does not replace or modify the German version.

Automatic Translation

Status: June 23, 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

LunaONE GmbH
Mildred-Scheel-Bogen 64
80804 Munich
Germany

Email: service@finalwording.com

2. General Information

This Privacy Policy explains the processing of personal data when visiting finalwording.com, contacting us, and using Final Wording, unless a separate privacy policy or agreement applies.

Personal data means any information relating to an identified or identifiable natural person. We process personal data only where there is a legal basis, in particular to provide our services, communicate, perform contracts, comply with legal obligations, or based on legitimate interests.

3. Hosting, Technical Provision, and Server Log Files

When our website or app is accessed, technically necessary data is processed so that pages can be delivered, operated securely and reliably, and errors can be investigated. This may include IP address, date and time of access, requested URL, referrer URL, browser type, operating system, transferred data volume, and status codes.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and efficient provision of our website and services. Log data is generally stored only as long as necessary for security, error analysis, and abuse prevention, and then deleted or anonymized unless longer retention is legally required.

4. Contact

If you contact us by email or through the contact form, we process the data you provide, especially email address, message, and voluntary information, to handle and respond to your inquiry.

The legal basis is Article 6(1)(b) GDPR where the inquiry relates to a contract or pre-contractual measures, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is handling incoming inquiries.

We use Resend as an email service provider to send contact form messages. The content submitted through the form is transmitted to Resend so that the message can be delivered. Where Resend processes personal data on our behalf, this is based on a data processing agreement. Transfers to third countries may, where required, take place on the basis of appropriate safeguards under Articles 44 et seq. GDPR.

We retain inquiries as long as necessary to handle them. Business letters and contract-relevant communication may be stored longer due to commercial and tax retention obligations.

5. Customer Account and Use of Final Wording

When registering for and using Final Wording, we process data necessary to provide and administer the service. This may include name, email address, company, workspace membership, roles and permissions, login and security data, usage and billing data, documents, comments, approvals, versions, technical events, and support communication.

The legal basis is Article 6(1)(b) GDPR where processing is necessary for contract performance or pre-contractual measures. For security, abuse prevention, and stability purposes, the legal basis is Article 6(1)(f) GDPR. For statutory retention obligations, the legal basis is Article 6(1)(c) GDPR.

Content customers introduce into Final Wording may contain personal data. Where we process such data on behalf of the customer, we act as processor within the meaning of Article 28 GDPR. In that case, the customer is responsible for the lawfulness of processing, transparency obligations, and data subject rights.

6. Documents, Comments, Version History, and Author Tracking

Final Wording is used for collaborative document work. To provide the functions, we process content and metadata that users create or upload in the workspace. This includes document text, comments, edits, approvals, timestamps, versions, and assignments to users or AI agents.

This processing is necessary to provide document, review, approval, and tracking functions. The legal basis is Article 6(1)(b) GDPR for contractual services and Article 6(1)(f) GDPR for traceability, security, and abuse prevention.

7. AI Functions

AI functions are optional. When users actively use AI functions, inputs, selected passages, context information, and outputs may be processed to provide the requested function, such as drafting, rewriting, shortening, or restructuring text.

Depending on configuration, processing may take place through customer-provided API keys or AI services connected by the Provider. Where personal data is transferred to AI service providers, this happens only to provide the respective function and on the basis of appropriate contractual and data protection arrangements. Customers should not enter sensitive or unnecessary personal data into AI prompts unless required for the purpose.

The legal basis is Article 6(1)(b) GDPR for providing the booked function and Article 6(1)(f) GDPR for security, error analysis, and abuse prevention.

8. Billing and Payment Data

For billing, accounting, and receivables management, we process contract, invoice, and payment data. This may include name, company, address, email address, VAT information, subscription plan, usage volumes, invoice amounts, payment status, and tax-relevant information.

The legal bases are Article 6(1)(b) GDPR for contract performance and Article 6(1)(c) GDPR for statutory retention and documentation obligations. We retain commercially and tax-relevant documents according to statutory periods.

9. Cookies and Similar Technologies

Our website uses a technically required locale cookie to store the selected language. The cookie is used to display the website in the appropriate language version. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a user-friendly, language-appropriate presentation. Where the cookie is necessary for the language function requested by the user, Section 25(2) TDDDG may also apply.

We do not use analytics or marketing cookies on the website.

10. Google Fonts

Our website loads fonts from Google Fonts through Google servers. Google may process technical data, especially IP address and browser information, to deliver the fonts.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A transfer to Google LLC in the United States cannot be excluded. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is a consistent, performant presentation of the website. Where consent is required, processing is based on Article 6(1)(a) GDPR.

11. Recipients and Service Providers

We use technical service providers that support us with operation, provision, security, communication, billing, and further development of our services. Recipients may include hosting providers, email service providers, payment and accounting service providers, support tools, security and monitoring providers, and AI service providers.

Where service providers process personal data on our behalf, we enter into data processing agreements under Article 28 GDPR. Disclosure to third parties takes place only where necessary for contract performance, where there is a legal obligation, where you have consented, or where we have a legitimate interest and your overriding interests do not prevail.

12. Third-Country Transfers

If personal data is processed outside the European Union or the European Economic Area, this occurs only where the requirements of Articles 44 et seq. GDPR are met. This may be based in particular on an adequacy decision by the European Commission, EU Standard Contractual Clauses, or other suitable safeguards.

13. Retention Period

We store personal data only as long as required for the respective purposes. Thereafter, data is deleted or anonymized unless statutory retention obligations, contractual documentation obligations, legitimate security interests, or legal claims require longer storage.

Customer data and workspace content are generally stored for the duration of the contract. After the contract ends, they are deleted after reasonable export, backup, and deletion periods unless statutory obligations or legitimate interests prevent deletion.

14. Your Rights

Data subjects have the following rights subject to statutory requirements: access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR, data portability under Article 20 GDPR, and objection under Article 21 GDPR.

Where processing is based on consent, you may withdraw consent at any time with future effect. The lawfulness of processing before withdrawal remains unaffected.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority generally responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de.

15. Right to Object under Article 21 GDPR

If we process personal data based on Article 6(1)(f) GDPR, you may object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise, or defense of legal claims.

16. Security

We take technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. Measures are selected considering the state of the art, implementation costs, the nature and scope of processing, and the risks to data subjects.

17. Changes to this Privacy Policy

We may update this Privacy Policy if our services, service providers, or legal requirements change. The current version is available on this website.