Last updated: 17 August 2026

This is a translation provided for convenience. In case of any discrepancy, the German version at siteviewer.com/datenschutz prevails.

Controller

The controller for the processing of personal data on this website and in the siteviewer application is:

  • Bross Ventures GmbH
  • Türkenstr. 29a, 80799 Munich, Germany
  • Managing Director: Dr. Florian Bross
  • Munich Local Court, HRB 283227
  • Email: hello@siteviewer.com

We have not appointed a data protection officer because the statutory conditions for doing so do not apply. For any privacy question, please contact us at the address above.

Scope and our two roles

This policy covers two separate offerings:

  • the website siteviewer.com and all its subpages
  • the application app.siteviewer.com, where customers manage building captures and publish virtual walkthroughs

Two roles need to be kept apart:

For your account, registration and contact data we are the controller. We decide ourselves why and how these data are processed. Most of this policy concerns that role.

For the content our customers upload to the application we are a processor. This includes scans, photographs, panoramas, floor plans and everything derived from them — including people who happen to appear in a capture. The respective customer alone decides about these data as controller; we process them solely on their instructions and under a data processing agreement pursuant to Art. 28 GDPR. If you appear in a capture and wish to exercise your rights, please contact the company that commissioned it. We will name the responsible contact on request.

Your rights

Subject to the statutory conditions, you have the following rights towards us:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a common, machine-readable format (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR)

Notice of your right to object: where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

If you have an account in the application, you can exercise two of these rights yourself: under Account you will find an export of your most important personal data in a machine-readable format and the option to delete your account. Deletion is confirmed with a one-time code that we send you by email. The export deliberately does not include every peripheral record — such as the delivery logs of our system emails; you can obtain complete access under Art. 15 GDPR at any time on request.

For anything else, an informal message to hello@siteviewer.com is enough.

You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence. The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.

The siteviewer.com website

Hosting and server logs

This website is operated by Cloudflare and delivered from its globally distributed data centres — for visitors from Europe, usually from within Europe. In doing so, Cloudflare processes technically necessary connection data, in particular your IP address, the address requested, the date and time, the browser type and the referrer transmitted. We need these data to deliver the website at all and to protect it against attacks.

The legal basis is our legitimate interest in a secure and available web presence (Art. 6(1)(f) GDPR).

Please note the difference from the application: the application and all customer content are held in a German data centre (see below), whereas this marketing website runs on Cloudflare's infrastructure.

Protection against automated requests

The contact form uses Cloudflare Turnstile. Turnstile checks whether a request comes from a human or from an automated program and thereby protects the form against abuse. Your IP address is transmitted to Cloudflare and evaluated in the process; to tell humans and machines apart, Turnstile evaluates transient technical characteristics of your browser that are discarded after the check. In the integration we use, Turnstile sets no cookies and stores nothing permanently on your device.

The legal basis is our legitimate interest in keeping our contact form functional and free of spam (Art. 6(1)(f) GDPR).

Contact form

If you write to us through the contact form, we process the details you enter there: name, email address and your message are mandatory; company, telephone number and topic are optional.

Your enquiry is sent to our mailbox by email via Microsoft 365. A copy remains in the mailbox of the technical sender. You also receive an automatic acknowledgement at the address you provided; that acknowledgement does not repeat your message.

The legal basis is Art. 6(1)(b) GDPR, as your enquiry is directed at entering into or performing a contract. For enquiries without a contractual context we rely on our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR).

We delete your enquiry once it has been dealt with conclusively and no statutory retention obligations apply. Business correspondence is subject to commercial and tax retention periods of six and ten years respectively.

Visitor statistics

To understand which content is in demand and whether our contact form works, we keep our own, very frugal access statistics. They work without cookies: nothing is stored on your device and nothing is read from it. That is also why we do not ask for your consent — § 25 TDDDG does not apply.

We record five events: the first visit of the day, every further page view, a successfully sent contact enquiry, a rejected one, and a click on one of our buttons. For the first visit we additionally note which external site you came from (the referrer address transmitted by your browser) and which campaign parameters were in the address; for a sent enquiry, the topic selected in the form; for a rejected enquiry, the technical reason, so that a broken step in the form does not go unnoticed for months.

For the clicks a small script runs in your browser. It reports only which button was pressed — from a fixed, short list — and on which page. It stores nothing on your device and reads nothing from it, so what is said above still holds: § 25 TDDDG does not apply here either.

So that repeat visits are not counted several times, we derive a checksum from your IP address and your browser identifier. The key used for it changes every night at 00:00 UTC — after that the same visit can no longer be connected to the previous day. We do not store your IP address itself.

The legal basis is our legitimate interest in shaping our offering to demand (Art. 6(1)(f) GDPR). As a precaution we treat the checksum as pseudonymous and delete all entries after twelve months. The figures are shown in aggregate in the administration area of our application, where they are visible to our system administrators only.

What this website does not do

We deliberately keep this website lean, so we want to state explicitly:

  • We set no cookies — neither for analytics nor for advertising.
  • We embed no Google services — including fonts. All typefaces are served from our own server.
  • We carry out no profiling and no automated decision-making within the meaning of Art. 22 GDPR.

Your light or dark appearance preference is stored locally by your browser only once you actively switch it yourself. It is not transmitted to us; storing and reading it back is strictly necessary to provide the service you expressly requested — remembering your choice (§ 25(2) no. 2 TDDDG).

The app.siteviewer.com application

Account and sign-in

For an account we process your name, your email address, your language preference, your membership of an organisation and your role within it, as well as status information about the account, such as the end of a trial period or a suspension. Name and email address are required to maintain the account; without them we cannot provide one. You sign in either with a one-time code that we email to you or through your company's Microsoft account. We do not store a password.

If you sign in through your company's Microsoft account, we receive your name, your email address and — where present in your company profile — your profile picture from Microsoft and store them in your account. We also store the technical sign-in credentials Microsoft issues for the sign-in. Whether your organisation can use Microsoft sign-in is decided by its administration.

After sign-in we set a technically necessary session cookie. It is valid for 24 hours at a time and is extended while you actively use the application; without use it expires after 24 hours at the latest. It serves solely to recognise you during your session; no tracking takes place. For each session we also store the IP address and browser identifier to protect it against abuse.

The legal basis is the performance of the usage contract (Art. 6(1)(b) GDPR). Where the account is provided by your employer, we process your data on that company's behalf.

Invitations

If an organisation invites you into the application — as a member or as an external contractor — we process your email address before any account exists, together with the inviting organisation, the inviting person, the intended role and the invitation's expiry date. We receive this information from the inviting organisation, not from you. An invitation can be accepted for 14 days; after that it lapses. The record remains traceable for the inviting organisation and is deleted at the latest together with that organisation or with the accounts of the people involved.

The legal basis is the performance of the usage contract with the inviting organisation (Art. 6(1)(b) GDPR); towards you, our legitimate interest in being able to admit you at that organisation's request (Art. 6(1)(f) GDPR).

Logs in the application

So that we can detect faults, investigate security incidents and trace changes to customer data, we keep four kinds of log:

  • System logs record technical events, such as an error while processing a capture or sending an email.
  • Change logs record who changed which record and when, including IP address and browser identifier.
  • Activity logs record security-relevant events such as sign-ins, grants, role changes and publications — likewise including IP address and browser identifier.
  • Delivery logs document which system email was sent to which address.

In addition, operating the platform produces technical web server access logs (including IP address, time and address requested, kept for 14 days) and platform operating logs (kept for 30 days).

The legal basis is our legitimate interest in secure operation and in the traceability of changes (Art. 6(1)(f) GDPR). Retention periods are listed below.

When you delete your account, we remove from the change, activity and delivery logs everything that points back to you — name, email address, IP address and browser identifier; the recipient address in the delivery log is replaced with a checksum that carries no name. The event itself is retained as security evidence until its retention period expires, but without any link to you. System logs contain no names and no contact details and expire after 90 days at the latest.

Emails from the application

The application only sends functional emails, such as sign-in and confirmation codes, invitations, notices about grants and about being added to an organisation, seat requests to an organisation's administration, enquiries from within the application to our sales team including an acknowledgement, and warnings before retention and usage periods expire. We do not send a newsletter. Delivery runs through Azure Communication Services; open and click tracking is switched off there. For each message we store the recipient address, message type, subject, time and delivery status as evidence — and, if delivery failed, the technical error message (see the retention periods below).

Counters that help us improve the application

Three places in the application keep counts, all deliberately frugal:

  • Help section. We record which chapters and hints you opened, completed or dismissed, how often you opened the help section, and how many searches there were in total and how many returned nothing. Only counts and the per-chapter status are stored — the search text you type never leaves your device.
  • Fault report in the walkthrough. If the three-dimensional view aborts for lack of memory, if a walkthrough fails to load, or if graphics output falls back to slower software rendering, your browser reports technical characteristics of the device and the loaded scene once (performance class, graphics unit model, memory size class, number of processor cores, quality level, memory use, window size, scene size, technical error code and error text) together with your account identifier, your browser identifier and the identifier of the site concerned. The application reads these characteristics locally anyway to choose the appropriate rendering quality; they are transmitted only when something goes wrong. Without that report we would only learn about faults when someone writes to us.
  • Use of individual features. Per day we count how often a walkthrough was opened, how often the display fell back to the slower software graphics, how often a walkthrough failed to load, how often a capture was processed, published or failed, and by which route new accounts were created (trial, domain approval or invitation). These counts carry no identifier — not of your account, not of your organisation, not of the walkthrough concerned. The database holds exactly one number per event type and day. That is deliberate: an analysis showing who viewed which walkthrough for how long would, at your employer, amount to monitoring performance and conduct and would require the consent of their works council.

The legal basis is our legitimate interest in a working and understandable application (Art. 6(1)(f) GDPR). The help-section counts are tied to your account and are deleted with it; the fault report sits in the system log and is subject to its 90-day period; the usage counts are deleted after 24 months.

Usage events in the application

Since August 2026 we additionally record individual usage events with your account identifier: which event type from a fixed list occurred (such as "signed in", "walkthrough opened", "measurement created", "view switched", "panel opened"), when, which publication or site and therefore which organisation was concerned, which part of the application you were in (walkthrough, editor, studio), which measuring tool was used in which mode, and how much time you actively spent in the application. Since August 2026 this also covers how long loading a walkthrough took, and with it the coarse performance class of your device in three steps (low, medium, high) — without it, a long loading time could not be told apart as caused by our application or by a weak device. Further device data such as graphics unit, memory size or screen size are not transmitted here; those exist only in the event of a fault (see above). Content is not part of this: no positions, no measured values, no text.

We delete these raw events after 90 days — with your account immediately. What persists are exclusively daily summaries without any link to a person (24 months, like the counts).

The analysis separates person and content: per person, our system administrators see only an activity profile — sessions, usage time, active days, the number of measurements per tool. Which walkthrough was viewed for how long is reported per organisation and per site only, never per person; an organisation's administration does not receive that per-person view either. The line drawn in the previous section therefore stands: monitoring the performance or conduct of individual employees is not possible with what is reported.

Nothing is stored on or read from your device for this; there, the session and sequence numbers of the bundled reports live only in the page's memory. In our database we store them together with the respective event; they are subject to the same 90-day period. The legal basis is our legitimate interest in understanding how the application is used, in order to improve it and to look after our customers (Art. 6(1)(f) GDPR).

Local storage in your browser

The application keeps a number of settings and working states exclusively locally in your browser and reads them back from there: the chosen appearance and language, display and quality settings of the walkthrough, your progress in the help section and with the onboarding hints, protective data that guards the 3D view against memory crashes, locally created measurements, and a cache of map tiles (30 days at most). Storing and reading these is strictly necessary to provide the features you requested (§ 25(2) no. 2 TDDDG). Unless described otherwise above, this data is not transmitted to us; you can delete it at any time through your browser's site-data settings.

Where your sign-up came from

If you reach us through an advertising or campaign link, its address carries information about which measure brought you here. If you then create an account, we record that information on your account once — together with the name of the site you came from and the first page you opened here.

Of that site we deliberately store only its name, for example „google.com“ or „linkedin.com“, never the full address with its path and search parameters. If you reach us via siteviewer.com, we note the site you originally arrived at siteviewer.com from — otherwise every account would simply say „siteviewer.com“, which answers nothing about which channel is worthwhile. Which search term you typed we never learn: search engines stopped passing that on years ago.

Since August 2026 we additionally record on the account how it came about in the first place — as a trial access, through an organisation's approved e-mail domain, or through an invitation — and, in the latter two cases, which organisation took you on. We already kept this as a plain daily figure without any identifier; on the account it lets us see which domain approval actually leads to accounts.

We evaluate this in aggregate only, to see which measure is worthwhile; we do not look at which individual account came through which link.

Nothing is placed on your device for this: the information lives only for the duration of your visit, in the browser's memory, and is carried along in the address bar as you click onwards. Close the tab and it is gone — we could keep it with a cookie, but that would require a consent banner, and a marketing figure is not worth that to us. It is accepted only within 24 hours of the account being created, and only once; after that the recorded origin can no longer be changed.

The legal basis is our legitimate interest in evaluating our advertising measures (Art. 6(1)(f) GDPR). The information is deleted together with your account.

To show locations on a map and for address search we use services from Mapbox (Mapbox Inc., United States). When you open a map, your browser loads the map tiles and satellite imagery directly from Mapbox servers. Your IP address and technical details about your browser are transmitted to Mapbox in the process. If you use the address search, the search term you enter is transmitted to Mapbox as well.

The Mapbox map library additionally reports to Mapbox that a map was loaded and used. For these reports it places a random identifier assigned by the library in your browser's local storage; it contains no information about you as a person, is never read by us, and serves Mapbox for usage-based billing and improvement of the service.

The legal basis is our legitimate interest in an intelligible spatial presentation of locations (Art. 6(1)(f) GDPR). Regarding the transfer to the United States, please see the section “Recipients and transfers to third countries”.

Feedback from within the application

For individual accounts that we enable specifically — typically test partners — the application shows a feedback button through which observations can be reported directly to our development team; for all other accounts it is switched off. If you send a report through it, your browser transmits it to our ticket system exponential (app.exponential.at), operated for us on servers of Hetzner Online GmbH in the European Union: your message, a screenshot if you choose to attach one, and the technical context of the report — name, email address, account identifier, organisation, seat type, trial period, page visited, screen dimensions and the application's version.

You trigger the report yourself. The legal basis is our legitimate interest in investigating and fixing reported defects (Art. 6(1)(f) GDPR). We keep the reports for as long as is necessary to trace the fix.

Customer content

Captures, walkthroughs and all files derived from them are stored in a Microsoft Azure data centre in Frankfurt am Main, Germany. For this content we act as a processor on behalf of our customers (see above).

Fixed rules apply to this content:

  • Deleted content stays in the recycle bin for 30 days and is then removed permanently.
  • Free workspaces are deleted after 365 days without use; we warn by email 30 days, 7 days and one day in advance.
  • If an organisation is deleted, we remove its content completely after a period of 90 days. All that remains is data-minimised security evidence without names, email addresses, IP addresses or browser identifiers; that too is deleted after 24 months.

Our system administrators have no standing access to customer content. Access for support purposes is only possible through a time-limited session — four hours at most — that requires a stated reason, is logged and is visible to the organisation in its own audit trail. Only during an organisation's initial set-up do our administrators access it directly for the purpose of setting it up; these accesses are logged and visible in the organisation's audit trail as well.

Recipients and transfers to third countries

We pass personal data only to carefully selected service providers acting for us as processors. These are currently:

Recipient Purpose Place of processing
Microsoft (Azure) Operation of the application, database, file storage Frankfurt am Main, Germany
Microsoft (Azure Communication Services) Sending the application's system emails Germany
Microsoft 365 Receiving and sending this website's contact enquiries European Union
Cloudflare Website hosting, protection against attacks, Turnstile, storage of the visitor statistics Europe, parent company in the USA
Mapbox Map tiles, satellite imagery, address search, usage reports of the map library United States
Hetzner Online GmbH Operation of our ticket system for feedback from within the application European Union

Where data is transferred to the United States, the providers concerned — Microsoft, Cloudflare and Mapbox — are certified under the EU-US Data Privacy Framework, so an adequacy decision pursuant to Art. 45 GDPR applies. In addition, the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR are in place with these providers.

We provide customers with a current list of our sub-processors on request.

Retention periods at a glance

Data Retention
System logs (technical events) 90 days
Change logs 12 months
Activity logs (security-relevant) 12 months
Email delivery logs 12 months
Web server access logs of the application 14 days
Platform operating logs 30 days
Sign-in sessions expire after 24 hours without use, deleted within two days after that
One-time sign-in codes expire after 5 minutes, deleted within two days after that
Account data until the account is deleted
Invitations acceptable for 14 days; the record is deleted with the inviting organisation or the accounts involved
Help-section counts until the account is deleted
Sign-up origin until the account is deleted
Content in the recycle bin 30 days
Unused free workspaces 365 days
Content of a deleted organisation 90 days
Data-minimised security evidence 24 months
Visitor statistics entries 12 months
In-app usage counts (no personal reference) 24 months
In-app usage events (with account identifier) 90 days, immediately with the account; daily summaries without personal link 24 months
Contact enquiries until conclusively dealt with, subject to statutory retention periods

Security

We take technical and organisational measures to protect your data. These include encrypted transmission throughout (TLS 1.2 or higher), encrypted storage, a role-based permission system with strict separation between organisations, malware scanning of uploaded files, and an audit trail of security-relevant events. We provide customers with an overview of these measures on request.

Changes to this policy

We update this policy when our processing or the legal requirements change. The version published here is the applicable one; the date at the top shows its status.

Provider information pursuant to § 5 DDG is available in the legal notice.