Privacy policy
Last updated: 30 July 2026
Controller and contact
The controller responsible for the processing of personal data on this website and within the platform, within the meaning of the General Data Protection Regulation (GDPR), is:
Sherloq GmbHBindingstr. 960598 Frankfurt am MainGermanyEmail: support@gosherloq.com
Use of the website
This section applies to every visitor to our website, whether or not you have a Sherloq account.
Server log data
When you visit our website, your browser automatically transmits information that our hosting provider stores in server log files: the pages requested, the date and time of access, the amount of data transferred, the browser type and version, the operating system, the referring URL and the IP address of the requesting device. We process this data on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in delivering the website reliably and securely. Log data is deleted or anonymised after a short period unless a specific security incident requires longer storage.
Contact form
Our website offers a contact form. When you use it, the details you enter, such as your name, email address and message, are transmitted to us and stored so that we can process your enquiry. Where your enquiry relates to a contract or pre-contractual steps we process this data under Art. 6(1)(b) GDPR; otherwise we rely on our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). We delete enquiry data once it is no longer needed and no statutory retention periods prevent deletion.
Cookies
This website currently uses only technically necessary cookies that are required for it to function. These do not require consent under Section 25 (2) TDDDG. We do not use tracking cookies, analytics services or advertising cookies, and we therefore do not display a cookie banner. Should this change, we will update this policy and, where legally required, obtain your consent beforehand.
Newsletter
We do not currently operate a newsletter. If we introduce one, it will use a double opt-in procedure, we will document your consent, and every email will contain an unsubscribe link. We will update this section before any newsletter goes live.
Booking a demo
Our website offers a 'Book a demo' button. It does not embed any third-party calendar; instead it links to an external scheduling page operated by HubSpot (hubspot.com). No data is collected on our website when the page loads. Only if you click the button and continue on HubSpot's scheduler is your data processed there, under HubSpot's own privacy policy.
Email delivery
When you submit our contact form, we use Resend (resend.com) to send a confirmation email to your address and notify our team. Resend processes your email address and name for this purpose. Legal basis: Art. 6(1)(b) GDPR. Resend's privacy policy: https://resend.com/legal/privacy-policy
Use of the platform
This section applies only if you create an account and use the Sherloq platform, our software for tracking the public LinkedIn activity of the profiles ("Profiles") you add to Watchlists.
Categories of personal data
Depending on how you use the platform, we may process: identification and authentication data (such as your name, business email address and a hashed password) for your account; contact data for premium accounts (such as business name, telephone number and address); Profile and target-activity data (such as a Profile's public LinkedIn handle and its publicly visible activity, including posts, reposts, comments, reactions, job changes and contact changes, for the Profiles you track); usage and technical data (logs, IP address, device information, timestamps and how you use features such as Watchlists and activity scoring); payment and billing data if you subscribe (such as invoicing data; full card details are handled by a third-party payment processor and are not stored on our servers); and any other information you provide voluntarily, such as support requests.
Purposes and legal bases
We process this data to provide and operate the platform, including authentication, account management, Watchlist creation and notifications about target activity (performance of a contract, Art. 6(1)(b) GDPR); to personalise and deliver notifications about LinkedIn Profile activity (legitimate interest, Art. 6(1)(f) GDPR); to process subscription payments (performance of a contract and legal obligation); to communicate with you about your account, support and security (legitimate interest); to send you marketing communications where you have consented or where otherwise permitted (Art. 6(1)(a) or 6(1)(f) GDPR), which you may object to or withdraw at any time; to comply with legal obligations (Art. 6(1)(c) GDPR); and to improve and develop the platform (legitimate interest).
Profile activity data and scoring
Because the platform tracks the activity of the LinkedIn Profiles you add to Watchlists and assigns scores based on weighted activity (posts, comments, reactions, job changes and so on), we process publicly available profile data and activity metadata. We may transform, enrich or anonymise aggregated data for internal research or product improvement while handling individual personal data in line with this policy. This scoring constitutes automated processing. You have the right to obtain meaningful information about the logic involved and the significance and envisaged consequences of such processing, and to request human intervention (Art. 22 GDPR).
Payments and billing
If you subscribe to a paid plan, payment and billing data is processed to fulfil the contract and to meet statutory accounting and tax obligations. Full card details are processed by a third-party payment provider and are not stored on our servers. The exact contractual arrangement with our payment provider is being finalised and will be reflected here.
Marketing communications
With your consent, or where otherwise permitted by law on the basis of our legitimate interest, we may send you marketing communications about the platform, product updates, offers and events. You can object or unsubscribe at any time via the link in each email or by contacting us. Essential service messages, such as account, security or billing notices, continue even if you opt out of marketing.
Recipients and service providers
We share personal data only with carefully selected service providers who process it on our behalf and under contract (Art. 28 GDPR), or where we are legally required to do so. The main providers are:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and file storage for form submissions and media | European Union |
| Vercel | Website hosting and delivery; server logs and IP addresses | European Union (Frankfurt) |
| Resend | Sending contact-form confirmation and internal notification emails | United States (EU Standard Contractual Clauses) |
| Paddle | Payment and subscription processing | Role being finalised (see Payments and billing) |
| HubSpot | Appointment booking, linked to only; no data collected here unless embedded | United States |
Where a provider processes data outside the European Economic Area (EEA), we ensure appropriate safeguards, such as the European Commission's Standard Contractual Clauses. Unless stated otherwise, we host and process data within the EEA. We will complete the required data processing agreements with each provider before launch.
We may also disclose data to integration partners that you explicitly connect, to legal or regulatory authorities where required by law, and, in the context of a corporate transaction such as a merger or sale, to the acquiring entity, provided it assumes equivalent data protection obligations.
Data security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration or destruction. These include encryption of data in transit and at rest, access controls, secure authentication and regularly updated security software. We follow the principles of privacy by design and by default.
Retention and deletion
We keep personal data only for as long as necessary for the purposes described in this policy and to meet legal, regulatory or contractual obligations. Relevant criteria include the length of your subscription or business relationship with us, statutory retention periods (for example for invoices) and whether we have a legitimate interest in retaining data for longer, balanced against your rights. When data is no longer needed, we securely delete or anonymise it.
Your rights
Subject to the conditions of applicable data protection law, you have the following rights regarding your personal data:
- Right to be informed about the data we process and why
- Right of access to a copy of the data we hold about you
- Right to rectification of inaccurate or incomplete data
- Right to erasure (the "right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on our legitimate interests or to direct marketing
- Right to withdraw consent at any time, without affecting processing carried out beforehand
To exercise any of these rights, please contact us at support@gosherloq.com. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence, place of work or the alleged infringement.
Changes to this policy
We may update this policy from time to time, for example to reflect changes to our services or to legal requirements. We will publish the current version here with an updated date and, where changes are significant, notify you by an appropriate means such as email or an in-app notice.

