Privacy Notice
Last updated: 2026-09-21
1. Scope and controller
This Privacy Notice applies to the ConnectWunder app, the ConnectWunder website and their public pages, interfaces and connected features that refer to this notice. The controller for the processing described here that is carried out for our own purposes is:
Yonju EOOD (Bulgarian limited liability company), ul. Brezovska 36, 4th floor, 4003 Plovdiv, Bulgaria. Managing Director: Sebastian Maier.
Privacy requests: info@yonju.de. Further provider details are available in the Imprint.
2. Processing on behalf of customers
Yonju EOOD generally acts as controller for account, contract, billing, support and security data. The respective customer is generally the controller for person, company, communication, meeting and document data processed in their workspace. Yonju EOOD processes this data as a processor under the customer's instructions. The Data Processing Agreement describes the details, data categories and subprocessors.
If you are affected as a customer's employee, contact or meeting participant, please first contact that customer about their processing purposes. We support them in handling your request.
3. Data, purposes and legal bases
Public pages, operation and security
When pages are accessed, technically necessary connection data is processed, including IP address, time, requested address, browser and device information, and status and error data. This serves delivery, maintenance, troubleshooting and abuse prevention. The basis is Article 6(1)(f) GDPR; our legitimate interest is secure and reliable operation.
Accounts and authentication
We process names, email addresses, workspace assignments, roles, authentication and permission data to establish, manage and secure access. The basis is Article 6(1)(b) GDPR for contract performance and Article 6(1)(f) GDPR for managing and securing business user accounts.
Contracts, usage and billing
We process order, contract, invoice and payment status data, records of contract acceptance, and usage data concerning executed features and consumed services. Purposes include activation, contract performance, billing and keeping evidence. The bases are Article 6(1)(b) and (c) GDPR and Article 6(1)(f) GDPR for establishing, exercising or defending legal claims. For purchases through Digistore24, we receive the order and status information needed for allocation, activation and billing; payment details may be processed directly by the sales partner.
Support
For enquiries, we process your contact details, the message and the technical or contractual information needed to handle it. The basis is Article 6(1)(b) GDPR or our legitimate interest in responding to enquiries under Article 6(1)(f) GDPR.
Workspace, AI and communication
Depending on the features used, ConnectWunder processes contact data, relationships, calendar and meeting data, notes, documents, files, tasks, messages, audio, transcripts and derived content. This includes FlowListnr and FlowWritr features where connected. Processing serves organisation, synchronisation, transcription, summarisation and AI-assisted work on the customer's behalf. The customer determines the purpose and legal basis and is responsible for required notices and consent, particularly for recordings.
For connected services such as Google Calendar, we process authorised content, permissions and connection data within the scope of the enabled integration. Through the public API, MCP and authorised assistants, permitted applications can access authorised workspace data and execute actions. Check which application receives which permissions before granting access. You can disconnect Google Calendar in account settings; those settings also provide deletion of imported Google Calendar user data.
Public sharing makes selected content accessible to people with the sharing link to the extent permitted by the sharing settings. Select shared content carefully.
4. Browser storage, fonts and notifications
The app uses technically necessary cookies and browser storage for authentication, language, time zone and app features, among other purposes. A service worker supports the installable app and technical caching. Necessary access to device storage is based on section 25(2)(2) TDDDG; personal data processing is based on Article 6(1)(b) or (f) GDPR depending on its purpose.
Fonts are loaded from Google Fonts. As a technical consequence, Google receives in particular your IP address and browser connection data. The purpose is consistent presentation; the basis is Article 6(1)(f) GDPR. Processing information is available from Google Fonts.
If you enable push notifications, we process the technical push registration and deliver notifications through your browser's push service. The basis is your consent under Article 6(1)(a) GDPR. You can disable notifications in app or browser settings.
Optional usage analytics and session recording
With your consent, we use Google Analytics 4 for usage statistics and OpenReplay for session recording, troubleshooting and usability improvements. You choose separately for each purpose. The legal bases are Article 6(1)(a) GDPR and, for storing or accessing information on your device, section 25(1) TDDDG. This analysis does not take place without your respective consent. Core features remain available without consent; signing in or accepting the Terms and Conditions does not replace it.
You can change your choices and withdraw consent for the future at any time through the consent settings of the respective website or app. This stops further collection for the purpose you deselect. Withdrawal does not affect the lawfulness of earlier processing. To request deletion of data already associated with you, contact info@yonju.de.
Google Analytics 4
Google Analytics 4 is a service provided by Google Ireland Limited, Ireland. We use it to measure reach, visitor sources, use of pages and features, and journeys leading to registration or purchase, and to improve our services. Data includes page and feature views, clicks, scrolling and interaction events, timestamps and engagement duration, referral sources and campaign information, browser, device and language information, approximate location, and pseudonymous visitor and session identifiers. Conversion events may also include product, plan, value and currency information. The IP address is technically processed when establishing the connection; according to Google, GA4 does not log or store it. This does not make the remaining usage data anonymous.
GA4 uses cookies including _ga and _ga_<ID> to recognise browsers and sessions. Their lifetime is up to two years from being set or renewed during a visit; your browser may impose shorter limits. In Google Analytics, event data is retained for up to 14 months and then removed during the monthly deletion cycle. For user identifiers, this period may restart with new activity. For year-over-year comparisons, we retain personal usage data in our own analytics for up to 24 months and then delete it. Aggregated reports without a link to individual people may be retained for longer-term comparisons.
Google processes analytics data on our behalf. Google LLC in the United States and other Google subprocessors may have access. Transfers to appropriately certified US recipients rely on the adequacy decision for the EU-US Data Privacy Framework; where no adequacy decision applies, the Standard Contractual Clauses provided for in Google's processing terms and necessary supplementary safeguards apply. Details and accessible safeguards are provided in Google's processing terms, its subprocessor list and its international transfer information. See also Google's Privacy Policy.
OpenReplay
With your separate consent, OpenReplay records interactions with the interface: page views, clicks, mouse movements, scrolling, timestamps, device and browser information, and sanitised technical error and performance data. We use this to reconstruct sessions and produce aggregated analyses such as heatmaps to identify usability problems and fix errors. This reconstructs the application's interface; it is not a camera, microphone or full-screen recording.
We host OpenReplay ourselves on our infrastructure with netcup GmbH, Germany, with storage in the European Economic Area. The hosting provider processes data on our behalf. Recordings and associated analytics metadata are retained for no longer than 180 days and then deleted. Access is restricted to authorised people who need the data for product improvement or troubleshooting.
Input fields, passwords, payment details and confidential workspace content such as contacts, messages, documents and transcripts are excluded from recordings or masked before transmission. Technical diagnostics do not contain authentication headers or network request or response bodies. Pseudonymous session identifiers are used in the browser to associate related events.
Linking website, app and analytics activity
Where your consent covers the relevant ConnectWunder websites and the app, we may link usage events using a pseudonymous identifier, for example to understand the journey from a campaign through registration to use of a feature. In the signed-in area, this identifier may be associated with your account and is therefore not anonymous. Names, email addresses and confidential workspace content are not sent to Google as analytics identifiers or event content. Analytics events are linked to OpenReplay recordings only if you consent to both purposes. The data is used for usage analysis and troubleshooting, not for solely automated decisions with legal or similarly significant effects on you.
5. Recipients and international transfers
Access is provided to people who need it for their duties and to hosting, authentication, AI, audio, communication, billing and support providers. Depending on the feature, these include Google Cloud/Firebase, OpenAI and ElevenLabs; processing details appear in the DPA and subprocessor list. Recipients may also include payment and sales partners, professional advisers, and authorities and courts where legally required.
Some recipients may process data outside the European Economic Area. Such transfers are subject to Articles 44–49 GDPR, in particular adequacy decisions or appropriate safeguards such as Standard Contractual Clauses and any necessary supplementary measures. You can request information on the relevant safeguards through our privacy contact.
6. Retention and provision of data
We retain personal data for as long as needed for its purpose. Relevant criteria include the contract term, workspace and deletion settings, statutory retention obligations and periods needed to establish or defend claims. Data is deleted or anonymised once the purpose and any conflicting obligations cease. Customer data is governed by customer instructions and the DPA's return and deletion provisions.
Certain account and contractual data is necessary to provide access and purchased services. Without it, we cannot offer the relevant service. Other information is voluntary unless marked as required.
7. Your rights
Subject to legal requirements, you have rights of access, rectification, erasure, restriction and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation; you may object to direct marketing at any time. You may withdraw consent for the future without affecting the lawfulness of prior processing.
You may lodge a complaint with a data protection supervisory authority, particularly in your place of habitual residence, workplace or the place of the alleged infringement. Contact us at info@yonju.de. Where needed, we verify your entitlement to protect data against unauthorised disclosure.
8. Automated decisions and changes
For the processing described here carried out for our own purposes, Yonju EOOD does not make solely automated decisions with legal or similarly significant effects on you. AI features support workspace activities; the customer or user decides how to use their results.
We update this notice when the described processing or requirements change materially. The current version remains publicly accessible at this address.