Privacy policy

Last updated: July 2026

Controller

Blue Ship Media Limited

Kinyra 28, Office 303, 8011 Paphos, Cyprus

Director: Thomas Dahlmann

Email: support@supportwunder.com

We are not legally required to appoint a data protection officer; for privacy requests, reach us at the email address above.

Our role: controller and processor

For data arising when you visit the website and register and manage your account (e.g. contact and billing data, server logs), we are the controller within the meaning of Art. 4(7) GDPR.

For the content we process on behalf of our customers as part of the service (in particular incoming support messages and the reply drafts generated from them), we act as a processor (Art. 28 GDPR) on the documented instructions of the respective customer. The customer is the controller for that processing; the basis is a data processing agreement (DPA).

Overview

We process personal data only to the extent necessary to provide our website and service. We use no tracking cookies and no analytics or social-media tools.

Server log files

When the website is accessed, technically necessary data (IP address, browser type, date and time of access) are processed on the basis of our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR) and deleted after 30 days at the latest.

Account and contract handling

To register and manage your account and to provide the service, we process your master data (e.g. name, email address, company) on the basis of Art. 6(1)(b) GDPR (performance of a contract). Billing is handled by our payment provider (see below).

Contacting us

If you contact us by email, we process your details to handle the request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual or contractual communication) or Art. 6(1)(f) GDPR (legitimate interest in responding).

The SupportWunder service (processing on customer instructions)

For customers of our service, we process incoming messages (email, WhatsApp, Telegram, website chat) to generate reply drafts automatically. In doing so we act as a processor; a data processing agreement (DPA) is provided.

Where those messages contain personal data of end customers, we receive that data from the respective customer as the sending party; we process it solely to provide the service and on the customer's instructions (cf. Art. 14 GDPR).

Drafts are generated using artificial intelligence and, by default, reviewed by a human before sending; no solely automated decision producing legal effects takes place. Automatic sending occurs only if the customer expressly enables the optional auto-send feature; it is disabled by default.

Service providers (sub-processors)

To provide the service we use carefully selected providers. Where they act as processors, agreements under Art. 28 GDPR are in place.

Unipile: email and messaging inbox connectivity (EU)

OpenAI: AI-assisted generation of reply drafts (USA; safeguarded by EU Standard Contractual Clauses)

Hetzner: hosting and data storage (Germany/EU)

Sentry: error and stability logging

Creem (Armitage Labs OÜ, Estonia): payment processing as Merchant of Record. Creem acts as its own controller for payment data, issues the invoices and remits VAT; the payment data therefore sits with Creem, not with us.

International data transfers

Where data are transferred to providers outside the European Economic Area (in particular OpenAI in the USA), this takes place on the basis of an adequacy decision of the European Commission or, where none exists, on the basis of the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) as an appropriate safeguard within the meaning of Art. 46 GDPR.

Retention

Message content is deleted automatically according to the retention period chosen by the customer (default: 90 days). When an inbox is disconnected, the stored content is deleted without undue delay. Account and billing data are stored for the duration of the contractual relationship and beyond within the scope of statutory retention obligations.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a supervisory authority.

If your request concerns data we process on behalf of a customer, we will refer you to the responsible controller.

Supervisory authority

Commissioner for Personal Data Protection, Nicosia, Cyprus (www.dataprotection.gov.cy). Individuals in Germany may additionally contact their competent state data protection authority.