R
ramp.app
Get Started
R
ramp.app
Get Started

Privacy Policy

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any data that can be used to personally identify you.

Data Collection on This Website

Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.

How do we collect your data?
Your data is collected primarily when you provide it to us. This could, for example, be data that you enter into a contact form.

Other data is automatically collected, or collected with your consent, by our IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of page visit). This data is collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure the flawless delivery of the website. Other data may be used to analyze your user behavior, with the aim of improving our service.

What rights do you have regarding your data?

You have the right at any time to obtain information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent for data processing, you can revoke this consent at any time in the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data, as well as the right to lodge a complaint with the competent supervisory authority.

2. Hosting

We host the content of our website with the following provider:

Microsoft Azure (West Europe)

This website is hosted on Microsoft Azure in the West Europe region (Netherlands). The personal data collected on this website is stored on the servers of the host. This can primarily include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access, and other data generated via a website.

External hosting is carried out for the purpose of contract fulfillment towards our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast, and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR).

Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.

3. General Information and Mandatory Notices

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations and this privacy policy.

Responsible Entity

The responsible entity for data processing on this website is:

C Ring GmbH

Heinrichshofweg 4h

50939 Köln

Email: hello@ramp.app

Phone: +49 221 29266107

Data Protection Officer (DPO)

You can reach our Data Protection Officer at: datenschutz@ramp.app

Retention Period

Unless a more specific retention period is stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, the deletion will take place after these reasons cease to apply.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You can revoke a consent that has already been given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Information, Deletion, and Correction

Under the applicable legal provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, and the purpose of data processing, and if necessary, a right to correction or deletion of this data. For this and other questions on the topic of personal data, you can always contact us.

Right to Data Portability

You have the right to receive data that we process automatically on the basis of your consent or in fulfillment of a contract, in a common, machine-readable format either for yourself or a third party. If you request the direct transfer of data to another controller, this will only be done insofar as it is technically feasible.

Right to Lodge a Complaint with the Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority. This right exists without prejudice to any other administrative or judicial remedies.

4. Data Collection on This Website

Cookies

Our website uses so-called “cookies.” Cookies are small text files that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device.

Cookies that are necessary for the provision of the electronic communications service (essential cookies) are stored on the basis of § 25(2) TTDSG. We have a legitimate interest in the storage of cookies for the technically error-free and optimized provision of our services. To the extent that consent for the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (§ 25(1) TTDSG, Art. 6(1)(a) GDPR); consent may be revoked at any time.

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website — for this purpose, the server log files must be collected.

Contact Form

When you send us inquiries via the contact form, your details from the inquiry form, including the contact information you provide there, will be stored with us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent. The processing of this data is based on Art. 6(1)(b) GDPR, insofar as your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if requested.

Inquiry by Email or Phone

When you contact us via email or phone, your inquiry, including all resulting personal data (name, request), is stored and processed by us for the purpose of handling your concern. We do not share this data without your consent.

5. Analytics Tools

PostHog (EU Cloud)

This website uses PostHog, a privacy-first analytics tool. PostHog collects anonymized usage data to improve the user experience. The data is processed in the PostHog EU Cloud (Frankfurt, Germany) and is not shared with third parties.

PostHog is only activated after you have given your consent (opt-in). The legal basis is Art. 6(1)(a) GDPR (consent). Without your consent, no analytics data is collected.

You can revoke your consent at any time by adjusting the cookie settings or by contacting us at datenschutz@ramp.app.

6. AI-Powered Services

Our Promise: Your data belongs to you.
We use AI technologies exclusively for processing your requests. The following providers are integrated:

Anthropic (Claude) — San Francisco, USA

OpenAI (GPT) — San Francisco, USA

OpenRouter — with upstream providers (Google Gemini, Meta Llama, Mistral, etc.)

Legal basis: Processing is carried out on the basis of your consent (Art. 6(1)(a) GDPR). You explicitly consent to AI processing when using AI features on the platform. Without consent, no data is transmitted to AI providers.

  • Not used for training — Your conversations are not used to train AI models
  • Encrypted in transit — All data is transmitted over secure TLS connections
  • Controlled by you — You can have your data deleted at any time
  • Never sold — We never sell your data to third parties

Opt-out: You can opt out of AI processing at any time in your account privacy settings or by contacting datenschutz@ramp.app. In that case, AI-based features of the platform will no longer be available to you.

7. Newsletter

If you wish to subscribe to the newsletter offered on our website, we require your email address as well as information that allows us to verify that you are the owner of the provided email address and that you agree to receive the newsletter. Additional data will not be collected or will only be collected on a voluntary basis. The legal basis is Art. 6(1)(a) GDPR (consent).

You can revoke your consent at any time, for example through an “unsubscribe link” in the newsletter. The legality of the data processing already carried out remains unaffected by the revocation.

8. Plugins and Tools

This website does not use third-party social media plugins that collect your data without your consent. External content is only loaded after you have given your explicit consent.

9. Sub-Processors

We use the following sub-processors for the provision of our services:

Sub-ProcessorPurposeLocationSafeguards
Microsoft AzureHosting, compute, databaseWest Europe (NL)DPA, EU data residency
AnthropicAI processing (Claude)USADPA, EU-US DPF, zero-retention API
OpenAIAI processing (GPT)USADPA, EU-US DPF, zero-retention API
OpenRouterAI model routingUSADPA, SCCs
PostHogAnalyticsEU (Frankfurt)DPA, EU data residency
StripePayment processingUSA / IrelandDPA, EU-US DPF, PCI DSS
ResendTransactional emailUSADPA, SCCs

An up-to-date list of sub-processors can be requested at any time from datenschutz@ramp.app.

10. Data Transfers to Third Countries

Some of our sub-processors are based in the United States. Data transfers to the USA are safeguarded by the following mechanisms:

  • EU-US Data Privacy Framework (DPF): Providers certified under the DPF (Anthropic, OpenAI, Stripe) are considered to offer an adequate level of data protection pursuant to the European Commission's adequacy decision of 10 July 2023.
  • Standard Contractual Clauses (SCCs): For providers not certified under the DPF, we rely on the EU Standard Contractual Clauses adopted by the European Commission, supplemented by additional technical and organizational measures (TOM) where necessary.

We ensure that all third-country transfers comply with Chapter V of the GDPR. You can request copies of the applicable safeguards by contacting datenschutz@ramp.app.

11. Retention Periods

We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, or as required by law. The following standard retention periods apply:

Data CategoryRetention PeriodLegal Basis
Account dataDuration of contract + 30 daysArt. 6(1)(b) GDPR
AI conversation logs90 days after last activity, or upon user deletionArt. 6(1)(a) GDPR
Invoices & billing data10 years§ 147 AO, § 257 HGB
Server log files14 daysArt. 6(1)(f) GDPR
Contact form inquiriesUntil processing is complete + 6 monthsArt. 6(1)(b)/(f) GDPR
Analytics data (PostHog)12 monthsArt. 6(1)(a) GDPR

After the retention period expires, data is automatically deleted or anonymized, unless a longer retention is legally required.

12. Automated Decision-Making (Art. 22 GDPR)

We do not use fully automated decision-making processes within the meaning of Art. 22 GDPR that produce legal effects or similarly significantly affect you.

While AI-generated content is created automatically, all business-critical decisions (e.g., contract conclusion, account suspension, creditworthiness assessment) are always subject to human review.

Should we introduce automated decision-making processes in the future, we will inform you in advance and ensure your rights under Art. 22(3) GDPR (right to obtain human intervention, to express your point of view, and to contest the decision).

Last updated: April 20, 2026