Privacy Policy
Last updated: July 2026 · Data processing exclusively on servers in Germany.
This is a translation for convenience. The German version is legally binding and should be reviewed by a lawyer before going live.
1. Controller
The controller responsible for data processing on this platform is:
MAXXmarketing GmbH, Karlsplatz 7, 80335 Munich, Germany.
Email: marketing@maxx-marketing.net, phone: +49 (0)89 92 92 86-0.
2. Principle: data residency in Germany
All data collected through Test it Baby — including recordings, transcripts and answers — is stored and processed exclusively on servers in Germany. There is no transfer of personal data to third countries (in particular the USA) for the core data storage.
3. Accessing the website (server logs)
When you access our pages, the server processes technically necessary data (e.g. IP address, date/time, page requested, browser type). The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). This data is retained only briefly to ensure operation.
4. Accounts (clients & testers)
To use the app we process account and profile data (e.g. email, name, and for testers categorisation details such as country, language, devices). The legal basis is performance of a contract (Art. 6(1)(b) GDPR). Passwords are stored only as a cryptographic hash.
5. Test participation, recordings & consent
For tests involving recording (screen and/or microphone), the recording takes place only after the participant's explicit, documented consent (Art. 6(1)(a) GDPR). The recording cannot technically start before consent has been given. Screen content, spoken comments and answers are processed to provide the client with feedback on their website or design. Consent can be withdrawn at any time with effect for the future.
6. Processors & services used
- Hosting (Germany): operation of the servers and storage of data in a German data centre.
- Transcription (local): speech-to-text conversion runs locally on our own servers in Germany; audio data does not leave the server for this.
- AI evaluation: an AI service (Anthropic) may be used for optional summaries. Only the text data required for the evaluation is passed on; processing takes place under a data processing agreement.
- Payouts to testers: a payout provider (Tremendous) may be used for compensation; only the data required for the payout is transmitted.
Data processing agreements pursuant to Art. 28 GDPR are in place, or will be concluded, with all processors.
7. Cookies
We use only technically necessary cookies (e.g. for login/session). No tracking for advertising purposes takes place. Legal basis: Art. 6(1)(f) GDPR and § 25(2) TDDDG (technically required).
8. Retention period
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention periods. Recordings and test data can be deleted by the client; on request we delete data of participating persons.
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to withdraw consent at any time. You also have the right to lodge a complaint with a data protection supervisory authority.
10. Contact for privacy matters
For any privacy-related concerns, reach us at marketing@maxx-marketing.net.