Política de Privacidad
Este documento legal está disponible actualmente en alemán e inglés. La traducción profesional al español está en preparación.
Privacy Policy — Silverfriend GmbH
Courtesy translation of the binding German Datenschutzerklärung. In case of any discrepancy, the German version prevails.
Last updated: 10 September 2026 · Version: 2.4
This edition is identical in content to the privacy policy shown in the SilverFriend app (labelled there as version 1.2 of the consolidated legal texts); the website continues its own version numbering.
1. Scope and addressees of this policy
This privacy policy applies to the processing of personal data by Silverfriend GmbH ("SilverFriend", "we") in the context of our phone-companion service for older people. It is addressed to two groups of people:
- Subscribers (family members who take out the subscription) — they use the subscriber app on iOS or Android and/or visit the website silverfriend.de.
- End users (older people we accompany by phone) — they have no app or online access to SilverFriend; their contact with us is exclusively by phone (landline or mobile). Older people receive this policy together with the welcome brochure — by post or, at the subscriber's choice, by e-mail.
Data residency in Germany. All personal data we store — account data, profiles, call records, memory notes, evidence — resides on servers in Germany, including at our cloud provider. Processing and our core services take place in the European Union and are subject to the GDPR. Some processors are based outside the EU (sections 9 and 10); your data is stored exclusively in Germany.
The two groups have different consent routes and different data sets; we separate them at the relevant points of this policy. For the voice service on the phone, the spoken information during the call also plays a role; its wording is reproduced in Annex C.
2. Controller (Art. 4(7) GDPR)
The controller for the processing described below is:
Silverfriend GmbH
Döringstraße 6, 10245 Berlin, Germany
Commercial register: Amtsgericht Charlottenburg, HRB 277280 B · VAT ID: DE457343045
E-mail: datenschutz@silverfriend.de · Phone: +49 15678 616839
Managing director: Feras Alsamawi
3. Data Protection Officer and privacy contact
We have appointed an external Data Protection Officer (Art. 37 GDPR, Section 38 BDSG). You may contact them directly at any time with any question about data protection or the exercise of your rights:
IITR Datenschutz GmbH, Dr. Sebastian Kraska · Marienplatz 2, 80331 Munich, Germany · Phone: +49 89 18917360 · E-mail: email@iitr.de
For all other privacy matters, reach us centrally at datenschutz@silverfriend.de or by post: Silverfriend GmbH, Datenschutz-Anfragen, Döringstraße 6, 10245 Berlin, Germany.
4. Competent supervisory authority
The competent data-protection supervisory authority for Silverfriend GmbH is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, https://www.datenschutz-berlin.de. You have the right at any time to lodge a complaint with this or another competent supervisory authority (Art. 77 GDPR).
5. The two data-subject roles — overview
SilverFriend is a constellation in which one person (the subscriber) books a service from which another person (the end user) benefits. The data-protection architecture reflects this duality consistently.
| Role | Who | Contact medium | Main processing | Legal basis |
|---|---|---|---|---|
| Subscriber (family member) | Adult who takes out the subscription | App; website only for information and the waiting list | Account, profile maintenance, billing, call overview, push notifications, optional usage analytics, support requests | Art. 6(1)(b) GDPR (contract); for usage analytics and marketing Art. 6(1)(a) |
| End user (older person) | Older person accompanied by phone | Phone (no app access) | Real-time voice processing (without audio recording), written call record, memory notes, life chronicle, wellbeing notice | Art. 6(1)(a) + Art. 9(2)(a) GDPR; in the event of danger Art. 6(1)(d) + Art. 9(2)(c) |
The end user's consent is never obtained via an app click by the subscriber, but directly from the older person themselves — by one of the three routes described in section 7.4. The end user can say "nicht mehr anrufen" ("please stop calling") at any time; the calls are stopped once the wish has been reviewed after the call — normally the same business day. Calls take place exclusively within our call hours: every day, including weekends and public holidays, from 07:00 to 20:00 German time; the last call starts no later than 19:45, and a conversation that has begun may run past 20:00. Our team reviews flagged conversations within the service hours, every day from 09:00 to 20:00 (section 8).
6. What data we process — subscriber-related
6.1 When you visit the website silverfriend.de
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, browser user-agent, request timestamp | Site delivery, security logging | Art. 6(1)(f) GDPR (legitimate interest: operations and security) | 14 days in access logs, then deleted or pseudonymised |
| Pseudonymous session data (privacy-focused analytics, with consent) | Reach analytics | Art. 6(1)(a) GDPR + §25(1) TTDSG | 13 months (anonymised) |
| Contact-form contents | Reply to enquiry | Art. 6(1)(b) GDPR (pre-contractual) | until resolved + 6 months |
| Newsletter sign-up | Sending requested content | Art. 6(1)(a) GDPR + §7(2)(3) UWG | until withdrawal |
Cookies and similar device-storage technologies are described in the paragraphs below.
Meta Pixel (Facebook/Instagram). The Meta Pixel with ID 1748447405861991 is embedded on this site. The pixel is only loaded after you actively consent to the "Marketing" category — no data is transmitted to Meta before that point. Once consented, the pixel allows us to measure the effectiveness of our advertising on Facebook and Instagram and to share conversion events (e.g. page views) with Meta. Cookies (_fbp, _fbc) are then set and data is transmitted to Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland); within the corporate group, data is also shared with the parent company Meta Platforms, Inc. (USA). The legal basis for the US transfer is the EU Standard Contractual Clauses (Module 2) together with the EU-US Data Privacy Framework. Legal basis for the processing: Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG. You can withdraw your consent at any time via the cookie-settings button in the footer.
6.2 When you create a subscription account in the subscriber app
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| First name, surname, e-mail address, own phone number, postcode | Contract performance, profile maintenance | Art. 6(1)(b) GDPR | Subscription term + 30 days |
| Authentication data (hashed password, pseudonymous user identifier, sign-in tokens, device identifier, sign-in timestamp, sign-in IP) | Account sign-in, session management | Art. 6(1)(b) GDPR | Session tokens: up to 30 days; inactive sessions cleaned up after 180 days |
| Payment data (subscription status, purchase receipts, device identifier, pseudonymous app-user identifier at the subscription manager) | Contract processing, billing, bookkeeping | Art. 6(1)(b) and (c) GDPR (§ 147 AO) | Subscription history: 3 years after cancellation; tax-relevant records: 10 years |
| Consent records (app confirmations, ordering-process checkboxes) | Accountability under Art. 7(1) GDPR | Art. 6(1)(c) GDPR | 3 years after withdrawal or end of contract |
| Support requests (topic, message, optional callback number, case number, app version) | Handling your request | Art. 6(1)(b) GDPR | 2 years after the request is closed |
6.3 Maintenance of the older person's profile by the subscriber
During onboarding and ongoing profile maintenance, the subscriber stores data about the older person they wish to have accompanied:
| Data category | Purpose | Legal basis |
|---|---|---|
| Older person's first name, phone number, birthday, language, living situation | Creating the call profile | Art. 6(1)(b) GDPR (contract with the subscriber); for the voice processing itself additionally the older person's own consent (section 7.4) |
| Postcode and town (required); street and house number (optional) | Postcode/town: personalisation of the conversations (events, local weather). Street/house number: postal delivery of the welcome brochure; in the event of a confirmed acute danger (section 8) disclosure to the emergency services | Art. 6(1)(b) GDPR; in the event of danger Art. 6(1)(d) GDPR |
| Interests and favourite topics | Personalisation of the calls | as above |
| Preferred call times (within the call hours, every day 07:00 to 20:00) | Call scheduling | as above |
| Contact details for wellbeing notices, optionally a second contact (name, e-mail and/or phone number) | Reachability in the event of a confirmed flag (section 8) | Art. 6(1)(b) GDPR; in the event of a notification Art. 6(1)(d) GDPR |
Regular call processing begins only once the older person has given their consent by one of the three routes in section 7.4.
6.4 Push notifications in the subscriber app
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Push token (device identifier) | Delivery of notifications | Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG | Until withdrawal, account deletion, app uninstallation or 90 days of inactivity |
| Notification type (e.g. "new call overview available", "wellbeing notice") | Controlling the app display | as above | as above |
| Content of the push message | not in the payload — the app retrieves details via an authenticated interface | — | — |
We send no names, no call content and no personal excerpts in push messages.
6.5 Usage analytics and crash reports in the subscriber app (only with consent)
To improve the app, we evaluate — exclusively after your express in-app consent (opt-in, off by default, revocable at any time in the settings) — pseudonymous usage data and crash reports. Without consent, the corresponding software components are not initialised; no collection whatsoever takes place.
| Data category | Service provider | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Pseudonymous usage/event data (areas and functions used, closed event list; pseudonymous user identifier; no names, e-mail addresses, phone numbers, free text or call content) | PostHog (EU cloud, Germany) | Product/usage analytics to improve the app | Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG | 90 days raw, 24 months aggregated |
| Crash and diagnostic reports (technical error data, device/OS version; release builds only) | Google Firebase Crashlytics | Stability and bug fixing of the app | Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG | 90 days |
This evaluation concerns exclusively the subscriber's use of the subscriber app. It has no connection whatsoever with the phone conversations, their content or the older person's data.
6.6 Marketing communication and newsletter (only with express consent)
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, e-mail address, consent record | Sending product updates and newsletters | Art. 6(1)(a) GDPR + § 7(2) no. 3 UWG (double opt-in) | Until withdrawal; suppression list 3 years |
| Open and click events (if separately consented to) | Campaign performance measurement | Art. 6(1)(a) GDPR | 18 months |
6.7 Security logging and abuse prevention
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, user agent, pseudonymous user identifier (if signed in), firewall events, interface access logs | Detection and investigation of abuse and security incidents | Art. 6(1)(f) GDPR (recital 49) | 30 days in full, 12 months aggregated |
6.8 AI companion for events on silverfriend.de/events
On silverfriend.de/events ("Events for seniors") you can type a question about the events calendar into a text field — for example "What's on in Heidelberg this weekend?". We call this feature the AI companion for events. The answers are written by a language model (artificial intelligence), not by a person; we say so directly next to the input field.
What is transmitted. Only when you actively send a question is your text (at most 300 characters) transmitted to our servers, together with the town, period and categories selected on the page, the identifiers of up to ten events currently shown, the page language and the calendar's data version. Input the page itself understands as a filter (for example "dance Heidelberg weekend") is evaluated in your browser and never leaves it. No name, e-mail address, account or cookie is transmitted. Please do not enter personal data into the field — neither your own nor a family member's; the search does not need it.
Where it is processed. The request travels through an Amazon Web Services interface in Frankfurt am Main (region eu-central-1) to a function we operate, which selects matching entries from our calendar and phrases the answer with a language model on the Amazon Bedrock platform. The language model runs in Amazon data centres within the European Union; Amazon may distribute the request between its EU regions (so-called EU inference profiles). No processing takes place outside the European Union. No other AI provider is involved. Amazon does not use your input to train models (section 9).
What is stored. Your question and the answer are not stored; they are discarded once answered. The technical logs of our function keep, for 90 days: the recognised search intent (town, period, category and individual search terms derived from the question), the number of matching events, error messages and — only if the request limit was exceeded — your IP address. The wording of your question is not logged. The Amazon Bedrock platform logs technical metadata only (time, model, size), never content. Section 6.7 applies to the interface's access logs (IP address, time).
Abuse protection. We limit the number of requests per browser session (ten; the counter lives in your browser's session storage and is deleted when you close it) and per IP address (ten per minute; our firewall sets further limits). The IP address is used for this only briefly, in memory.
No automated decision. The answers are pointers to calendar entries. They have no legal effect and are not based on an assessment of you as a person (section 13). Dates, times and venues come from the organisers and municipalities; please check them on the source page named with each entry.
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Question text (free text, at most 300 characters), the page's filter state (town, period, categories, "free only"), identifiers of up to ten events shown, language, calendar data version | Answering your question about the events calendar | Art. 6(1)(f) GDPR (legitimate interest: providing a search aid you trigger yourself; every transfer happens only on your input) | Not stored; processed only for the duration of the answer (seconds) |
| Technical log (recognised search intent, match count, errors, time) | Operation, troubleshooting, cost control | Art. 6(1)(f) GDPR | 90 days |
| IP address (request limit, firewall, interface access log) | Abuse prevention | Art. 6(1)(f) GDPR (recital 49) | Memory: minutes; logs: section 6.7 |
7. What data we process — end-user-related (phone call)
7.1 Before the first call
Before the first regular call takes place, two things happen:
- Consent. The older person gives their consent by one of the three routes in section 7.4 — in the personal consent call with a member of SilverFriend's staff, or by e-mail/SMS confirmation. Without this consent, no regular call takes place.
- Welcome brochure. Before the first call, the older person receives a welcome brochure — by post or, at the subscriber's choice, by e-mail — which explains in age-appropriate language what SilverFriend is, which phone number will call them, at what times calls are possible, which topics they can raise, what SilverFriend does and does not do, and how they can stop the service at any time. This privacy policy is enclosed with the brochure — so that the complete mandatory information under Art. 13 GDPR reaches the older person themselves.
At the start of the speech model's first call ("first call"), the older person additionally receives a spoken introduction (Annex C). At the start of every call, SilverFriend discloses that a voice AI is speaking.
7.2 During and after the call
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Voice signal during the conversation | Real-time processing by the speech model (understanding and answering) | Art. 6(1)(a) + Art. 9(2)(a) GDPR | only at the moment of processing — no audio recording is created or stored |
| Written call record | Memory extraction and conversational continuity; basis of the review by our team (section 8) | Art. 6(1)(a) + Art. 9(2)(a) GDPR | 14 days; in the event of a confirmed escalation until the end of the third calendar year following the incident (section 8); extended under section 11 if a legal claim is asserted |
| Recording of the consent call (section 7.4, route 1) | Proof of consent (Art. 7(1) GDPR) | Art. 6(1)(c) GDPR; for the part of the conversation before consent to the recording is given, Art. 6(1)(f) GDPR | Term of the contract plus 3 years; the recording is technically write-protected against subsequent alteration, as a result of which final deletion may take place up to seven years after the recording |
| Structured memory notes (e.g. "likes nature documentaries about northern Germany", "wedding anniversary on 14 May") | Personalisation of future conversations | as for the call record | up to 2 years on a rolling basis, older notes trimmed by relevance |
| Life chronicle (long-term biographical milestones) | Long-term continuity | as for the call record | Subscription term + 30 days |
| Call metadata (start, end, duration, outcome of the call, model and text version) | Service delivery, accountability | Art. 6(1)(b) and (f) GDPR | 12 months |
| Review log of the wellbeing review (case identifier, stage, steps taken, timestamps, initials of the reviewing person — without conversation wording, pseudonymised) | Proof of proper procedure, defence against legal claims | Art. 6(1)(f) GDPR | 10 years |
Incidental content belonging to special categories of personal data (Art. 9 GDPR) — such as mentions of health, religious topics or political opinions — is not actively elicited by the system, but may arise in the course of a conversation and is stored in the call record insofar as relevant to conversational continuity. The legal basis for this is the explicit consent under Art. 9(2)(a) GDPR, which is obtained by one of the three routes in section 7.4 and which expressly names this case. Biometric characteristics of the voice are neither collected nor used for recognition.
7.3 After the call — call overview for the subscriber
From every call, a brief, deliberately minimalist call overview is generated for the subscriber — no content, no summary of the conversation, no mood assessment. It contains exclusively: whether the call took place (presence), the duration of the conversation, the number of words spoken and the top topics of the conversation in a short keyword list (e.g. "garden, weather, family, wedding-anniversary reminder").
We create and communicate no mood assessment, no sentiment score, no health inference and no emotional evaluation. This express self-restriction is anchored both in our system design (no model output about mood) and in a filter stage before display in the subscriber app. A more detailed explanation can be found in our AI information.
7.4 How we obtain the end user's consent
We offer three equally valid routes by which the older person gives their data-protection consent to the voice processing. On all three routes: the consent is declared by the older person themselves — never by an app click or a declaration by the subscriber. Consent by a representative (for instance on the basis of a power of attorney or guardianship) is not provided for; SilverFriend does not examine such documents. The full wording of the consent text is identical in content on all three routes, expressly names that health information mentioned by the older person themselves is also covered by the consent (Art. 9(2)(a) GDPR), and is logged with its version.
Route 1 — consent call (personal call by our team). A member of SilverFriend's staff calls the older person at a time agreed with the subscriber, explains the service in plain language and obtains consent orally. This call is recorded — but only after the older person has expressly agreed to the recording; this agreement is confirmed once more after the recording has started. The legal basis for the short part of the conversation before the agreement to the recording is Art. 6(1)(f) GDPR (legitimate interest in keeping evidence). The recording serves exclusively as proof of consent and is kept for the term of the contract plus three years (section 7.2). The speech model's later calls are not recorded.
Route 2 — e-mail confirmation. The older person receives, at their own e-mail address, an invitation with a single-use link valid for 72 hours to a confirmation page in plain language and large print. Confirmation takes place in two steps: step 1 confirms that the older person received this message themselves; step 2 contains the full consent text and the consent. All information is visible without a further click, and this privacy policy is linked before the consent. The confirmation is logged in an audit-proof manner (timestamp, version of the consent text, account assignment, technical evidence in hashed form, failed attempts).
Route 3 — SMS confirmation. As route 2, but by SMS to the older person's own mobile number.
A refusal ("no") is also stored — only the fact and the time — so that no further contact takes place.
Withdrawal. The older person can withdraw their consent at any time and without formality — most simply by saying "nicht mehr anrufen" ("please stop calling") during a call. The withdrawal takes effect from the moment it is expressed; the calls are stopped once the wish has been reviewed after the call — normally the same business day. The review by a member of staff precedes the stop and serves solely to rule out misunderstandings; it is not an approval requirement. A withdrawal via the opt-out link or to the team is implemented immediately, because there is nothing there to interpret. With the withdrawal, the legal basis for the further storage of the call record, the memory notes, the life chronicle and the older person's profile details (interests, call times, living situation) ceases; we delete this data seven days after confirmation of the withdrawal. The phone number remains stored only as a block entry so that no further call is made. Only the proof of consent and withdrawal (sections 6.2, 7.2) and documented safety events and the review log (section 8) are retained. We inform the subscriber that the older person no longer wishes to receive calls — without conversation content — and point out their right of termination. The lawfulness of the processing carried out until the withdrawal remains unaffected (Art. 7(3) GDPR).
8. Wellbeing notice (observation of anything that stands out, with human review)
After every call has ended, our system automatically checks the written call record for explicit statements and conversational events that may indicate acute danger to the older person — an explicit statement about self-harm or suicidal thoughts, a described medical emergency, an indication of ongoing abuse. No mood, sentiment or health analysis takes place (section 7.3). No audio recording exists; the review relies exclusively on the call record.
Every flag detected is then reviewed personally by a member of SilverFriend's staff. Where there are indications of acute danger to life or limb, the review takes place within the service hours without delay; otherwise usually within 48 hours after the call. The service hours are every day — including weekends and public holidays — from 09:00 to 20:00 German time; no review takes place outside the service hours; calls placed before 09:00 are reviewed from 09:00 on. No specific processing or delivery time is promised.
What happens after the review — in three stages:
- Stage 1 — callback (only where there are indications of acute danger to life or limb). A member of staff first calls the older person back themselves to clarify the situation and advises them to call the emergency services themselves if needed.
- Stage 2 — asking the contacts to get in touch. We ask the contacts stored in the subscriber profile — first the first contact, and the optionally stored second contact if the first cannot be reached — to get in touch with the older person. In the case of a confirmed flag without acute danger, this is the only step; in the case of acute danger, it happens in parallel with the callback. This request contains no content from the conversation, no diagnosis, no assessment — it says in essence only: "Please get in touch with your relative."
- Stage 3 — emergency call. If, in the case of acute danger, there is no response or the danger is confirmed, SilverFriend may alert the emergency services (112; in the case of danger from other persons also the police, 110) and in doing so pass on the older person's name, phone number, town and — where stored — address. An emergency call by SilverFriend is only possible for phone lines in Germany.
The system never places an emergency call automatically; whether and when an emergency call is made is decided by a human being in every individual case. No notification takes place during the call itself. The function is not a home emergency call service, not a medical device and does not replace the emergency number 112; during the conversation itself, the speech model tells the older person the emergency number 112 where needed. The responsibility for calling the emergency services in an emergency they recognise themselves remains with the older person and their relatives.
Legal bases. For the automated detection and the human review: Art. 6(1)(d) GDPR and Art. 9(2)(c) GDPR (vital interests of a person who may not be capable of giving consent at the acute moment). For the notification of the contacts: Art. 6(1)(d) GDPR; the notification contains no special categories of personal data. For the disclosure to the emergency services (112) or the police (110): Art. 6(1)(d) and Art. 9(2)(c) GDPR.
Retention in the event of escalation. If the human review confirms an escalation, we retain the call record of the call concerned and the associated safety event until the end of the third calendar year following the incident. The purpose of this extended retention is the traceability of the incident and the defence against possible legal claims; the legal basis is Art. 9(2)(f) or Art. 6(1)(f) GDPR. If a legal claim is asserted or announced, or if legal proceedings are pending, retention is extended until their final conclusion (section 11). We keep the review log — without conversation wording, pseudonymised — for 10 years; safety events without a confirmed escalation for 3 years; the delivery logs of the notifications for 90 days.
9. Recipients and processors (subprocessors)
A complete, continuously updated list can be found at silverfriend.de/datenschutz/subprocessors. The main recipients are:
| Recipient | Role | Contractual basis | Location |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Processor (hosting, database, real-time speech model, language model of the AI companion for events on the website, key management, e-mail delivery) | Art. 28 GDPR + EU Standard Contractual Clauses Module 2 + contractual assurance: no model training with our content | Luxembourg / EU; storage location of all data: Germany; AWS Inc. (USA) as sub-processor |
| Twilio Ireland Limited | Processor (phone routing, SMS delivery) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | Dublin (Ireland); Twilio Inc. (USA) as parent company |
| Google Ireland Limited (Firebase Cloud Messaging) | Processor (push notifications) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | Dublin (Ireland); Google LLC (USA) as parent company |
| PostHog | Processor (usage analytics of the subscriber app — only after opt-in, pseudonymous, no end-user data) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | EU cloud, Germany; PostHog Inc. (USA) as parent company |
| Google (Firebase Crashlytics) | Processor (crash reports of the subscriber app — only after opt-in, no end-user data) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | Dublin (Ireland); Google LLC (USA) as parent company |
| HubSpot Ireland Limited | Processor (blog delivery, waiting list, subscriber CRM, e-mail communication, and website tracking only after marketing consent — subscriber data only, no end-user data; the website itself is not served by HubSpot) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | Dublin (Ireland), data residency EU (Germany); HubSpot Inc. (USA) as parent company |
| Google Ireland Limited (Google Analytics 4, Google Tag Manager) | Processor (website reach measurement — only after consent in the cookie banner, section 6.1) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | Dublin (Ireland); Google LLC (USA) as parent company |
| Meta Platforms Ireland Ltd. (Meta Pixel) | Processor (measuring the effectiveness of advertising on Facebook/Instagram — only after marketing consent, section 6.1) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | Dublin (Ireland); Meta Platforms, Inc. (USA) as parent company |
| RevenueCat Inc. | Processor (subscription and entitlement management in the app-store environment) | Art. 28 GDPR + Standard Contractual Clauses Module 2 | USA |
| Apple Inc. / Apple Distribution International | Joint controller for App Store transactions | App Store agreement | Cork (Ireland) / USA |
| Google LLC / Google Commerce Limited | Joint controller for Play Store transactions | Play Store agreement | Dublin / USA |
| Tax adviser | Processor (bookkeeping, tax returns) | Art. 28 GDPR | Germany |
| Print service provider for the welcome brochure | Processor (postal delivery) | Art. 28 GDPR | Germany |
| Emergency control centre (112) or police (110) | Independent controller as recipient — only in the confirmed acute danger case (section 8, stage 3): name, phone number, town, address where stored | Art. 6(1)(d), Art. 9(2)(c) GDPR | Germany |
In addition, we use the following providers internally, which process no personal data of our subscribers or end users:
| Provider | Purpose | Data-protection position |
|---|---|---|
| OpenRouter (USA) | Language-model access for internal topic research | No personal data is transferred; technically excluded |
| Firecrawl (USA) | Retrieval of public web content (TV listings, event listings) | No personal data is transferred; inputs are exclusively curated internet addresses |
10. Transfers to third countries
All servers are in the European Union; all data is stored exclusively in Germany (Germany and the Nordics are the only places where services operated by SilverFriend handle any customer data). No customer data is stored outside Germany. In certain cases, transfers to the United States take place:
- Group control level of the EU subsidiaries of our US providers (AWS, Twilio, Google, HubSpot, PostHog, Meta) — no production content; control and support operations.
- RevenueCat as a US-based subscription manager — processes a pseudonymous app-user identifier and subscription data.
For each of these transfers, the following are in place: (1) EU Standard Contractual Clauses Module 2 under Decision (EU) 2021/914, (2) — insofar as the respective provider is certified — the EU-US Data Privacy Framework (DPF) as an adequacy basis (Art. 45 GDPR), (3) supplementary technical and organisational measures: encryption of stored data with our own keys, encrypted transmission, data storage at European level, data minimisation (e.g. only token and type code in push messages, subscriber data only at HubSpot, pseudonymisation at RevenueCat and PostHog).
A transfer impact assessment is held by our data-protection contact point and can be provided in summarised form on request.
11. Retention period
We store personal data only for as long as is necessary for the respective processing purposes or as required by a statutory retention obligation. The specific retention periods are stated per data category in the data tables (sections 6 and 7). Our deletion concept follows DIN 66398:2016 and is documented internally.
General note: If a legal claim is asserted or announced, or if legal proceedings are pending, the retention of the data required for this is extended until their final conclusion. Backups of our database are overwritten no later than after 30 days; deleted data is not restored from backups.
Summary overview:
| Data area | Retention period |
|---|---|
| Subscriber account (general) | Subscription term + 30 days' grace, then deletion; account deletion in the app is completed within 30 days |
| Tax-relevant records | 10 years (§ 147 AO, § 257 HGB) |
| Audio recording of the speech model's calls | none — no audio recording is created |
| Recording of the consent call | Contract term + 3 years (technical write protection, final deletion up to 7 years after the recording) |
| Call records | 14 days; in the event of a confirmed escalation until the end of the third calendar year after the incident; extended in the event of legal claims |
| Memory notes | up to 2 years on a rolling basis, older ones trimmed by relevance |
| Life chronicle | Subscription term + 30 days |
| Older person's data after withdrawal ("nicht mehr anrufen") — call records, memory notes, life chronicle, profile details | Deletion 7 days after confirmation of the withdrawal; phone number only as a block entry; evidence and safety events remain for their own periods |
| Safety events (flags) | 3 years; in the event of a confirmed escalation as for the call record |
| Review log of the wellbeing review (without wording, pseudonymised) | 10 years |
| Delivery logs of the wellbeing notices | 90 days |
| Security logs | 30 days in full, 12 months aggregated |
| Consent records (logs, including "no") | 3 years after withdrawal or end of contract |
| Support requests | 2 years after closure |
| Usage-analytics data (PostHog) | 90 days raw, 24 months aggregated |
| Crash reports (Crashlytics) | 90 days |
| Website server logs | 14 days |
| Questions to the AI companion for events (website) | none — question and answer are discarded once answered |
| Technical log of the AI companion for events (no wording) | 90 days |
12. Your rights
You have the following rights towards SilverFriend at any time: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21), withdrawal of consent at any time with effect for the future (Art. 7(3)) and complaint to the competent supervisory authority (Art. 77).
Please send your request informally to datenschutz@silverfriend.de. We respond within one month of receipt; in complex cases we may extend the period by two further months under Art. 12(3) GDPR and will inform you of this within the first month.
Identity verification: For subscribers, identity is verified via the subscriber-app account or via a confirmation code sent to the e-mail address or phone number stored in the account. For older people, it is verified via a callback to the phone number stored in the profile with spoken confirmation.
Exercising rights during the call: The older person can also exercise their rights directly during the call. The statement "nicht mehr anrufen" ("please stop calling") results in the calls being stopped once the wish has been reviewed after the call — normally the same business day (section 7.4); the statement "bitte alle meine Daten löschen" ("please delete all my data") is recorded as a formal erasure request. Both statements are reviewed by a member of staff and implemented permanently; the calls remain suspended from the review onwards.
Supervisory authority for complaints: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, https://www.datenschutz-berlin.de.
13. Automated decision-making within the meaning of Art. 22 GDPR
Automated decision-making within the meaning of Art. 22 GDPR does not take place in the SilverFriend service. In particular:
- No credit, personality, health or mood profiles are created.
- The AI companion for events on the website (section 6.8) gives pointers to calendar entries; it makes no decision with legal effect and does not assess you as a person.
- No legally significant or similarly significant individual decisions are made automatically.
- The voice AI conducts the conversation within a defined behavioural framework, but does not issue any evaluative decision about the older person.
The only model-supported detection with external effect is the detection of signs of danger (section 8) — and precisely there, a human always decides: without personal review by a member of staff, neither a notification is sent nor an emergency call made.
14. Security (Art. 32 GDPR)
We use, among others, the following technical and organisational measures:
- Data stored exclusively on servers in Germany (section 10).
- Encryption of stored data with our own, regularly rotated keys; the consent-evidence store is additionally technically protected against alteration and premature deletion.
- Encrypted transmission on all transmission paths; encrypted voice media streams insofar as the telecommunications provider supports this.
- Role-based access control with strictly separated roles for application, analysis and maintenance; consent records are protected against deletion and subsequent alteration (append only, no overwriting).
- Management of credentials exclusively via a central secrets store; no clear-text secrets in program code, configuration files or logs.
- Web application firewall in front of all public interfaces.
- Structured security logs without clear-text personal data; stored encrypted.
- Data-protection impact assessments for the voice processing and for the subscriber app, documented internally and available to the supervisory authority on request.
- Regular security reviews and data-breach exercises.
15. Cookies and similar storage technologies
On the website silverfriend.de, we use cookies and comparable technologies only insofar as this is necessary for the operation of the website (technically necessary cookies, § 25(2) TDDDG) or you have previously consented to non-essential cookies (§ 25(1) TDDDG). Consent is obtained via a consent banner and can be withdrawn at any time via "Cookie settings" in the footer. In the subscriber app, the same applies to the consent-based usage analytics and crash reports (section 6.5). Details of the services used can be found in section 6.1. On the events page your browser stores the selected town locally at your request ("Remember town") so it is preselected on your next visit; this storage is necessary for the function you requested (§ 25(2) no. 2 TDDDG), stays in your browser and is removed via "Forget".
16. Changes to this privacy policy
We update this policy in the event of substantial changes to our processing and inform active subscribers of this via the subscriber app and by e-mail. For the older person, in the event of substantial changes, we enclose an updated version with the mailing or inform them during the call. We keep a change history at the end of this policy. (Contractual special rights of termination in the event of changes to the service are governed by the Terms of Service, § 13.)
17. Change history
| Date | Version | Material changes |
|---|---|---|
| 2026-04-13 | 1.0 | Initial publication (pre-launch) |
| 2026-04-17 | 1.1 | Named processors explicitly (AWS, Twilio, FCM, RevenueCat, HubSpot); specified Frankfurt data centre; added app-specific privacy disclosures and privacy nutrition labels (Apple/Google); added children and minors section; added contact phone number; added language switcher |
| 2026-05-08 | 1.2 | Added Meta Pixel (Facebook/Instagram) as a processor; pixel only fires after marketing consent (TTDSG § 25(1), GDPR Art. 6(1)(a)); EU-US Data Privacy Framework added as transfer basis |
| 2026-08-24 | 1.3 | New section 5.7 (usage analytics and crash reports in the mobile app: PostHog and Google Firebase Crashlytics, both opt-in); section 5.5 corrected — its earlier statement that the app shares no data with third-party analytics providers had not been accurate since July 2026; privacy nutrition labels (5.6) extended with product-interaction and diagnostics data; section 7 extended with Google Ireland Limited (Analytics 4 / Tag Manager and Crashlytics), Meta Platforms Ireland Ltd. and PostHog, Inc.; section 8 extended with the PostHog third-country note; adopted “wellbeing notice” as the name of the safety feature and clarified in section 11 that a person reviews the result before any notice is sent |
| 2026-09-05 | 1.4 | Corrected the spoken withdrawal: calls are stopped once we have recognised the wish “nicht mehr anrufen” after the conversation — no longer a promise that this happens immediately (section 10); removed a reference to an internal document in section 9 |
| 2026-09-05 | 1.5 | Section 7 aligned with the subprocessor list v1.3: voice processing at AWS is real-time, no audio recording of the regular calls is stored, a written call record is kept for 14 days; HubSpot's role made precise (blog delivery, waiting list, subscriber CRM, email communication, and consent-gated website tracking); the website itself is not served by HubSpot. Section 5.3 extended with the written call record (14 days) and the recording of the one-off consent call (contract term + 3 years). Storage location described consistently: servers in the European Union, storage exclusively in Germany |
| 2026-09-06 | 2.0 | Complete new version: three equally valid consent routes for the older person (no representative route); no audio recording of the speech model's calls, written call record 14 days; call hours (daily 07:00–20:00) and service hours (daily 09:00–20:00) as separate windows; wellbeing notice as a staged model with callback and emergency call by staff; withdrawal during the call with deletion seven days after confirmation; retention in the event of escalation until the end of the third calendar year; review log 10 years; older person's address optional with emergency purpose; storage location: servers in the EU, storage exclusively in Germany; website analytics (section 6.1) carried over unchanged |
| 2026-09-07 | 2.1 | Data residency in Germany stated explicitly (section 1, section 9 AWS row, section 10, section 14); controller's phone number added in section 2; sentence on website/app version numbering added in the header; Annex C.2: "short overview" instead of "short summary" |
| 2026-09-08 | 2.2 | External Data Protection Officer appointed (IITR Datenschutz GmbH) |
| 2026-09-10 | 2.3 | Described the AI companion for events on the website (new section 6.8: transfer only on active send, processing at AWS in the EU, no storage of question and answer, log 90 days); added overview rows in section 11, the Art. 22 note, "Remember town" (section 15) and the share functions (Annex A) |
| 2026-09-10 | 2.4 | Spoken withdrawal: the calls are stopped once a person has reviewed the wish after the call — normally the same business day; the review precedes the stop (section 7.4, withdrawal, rights during the call, Annex B). A withdrawal via the opt-out link or to the team is still implemented immediately. |
Annex A — Web-specific additions
Website hosting. silverfriend.de is operated on European cloud infrastructure with a content delivery network; blog content and the waiting list are provided via HubSpot with data residency in the EU (Germany). Server logs are kept for 14 days and then deleted or pseudonymised (section 6.1).
Reach measurement. Reach measurement and advertising performance measurement take place only after your consent in the cookie banner; the services used, their legal basis and the transfer to the USA are described in section 6.1.
Contact forms and waiting list. Entries go to our processing mailboxes or into the waiting list. We keep them for 90 days; in the event of lead conversion, until the end of the contract + 30 days.
Embedded content. We avoid third-party components that would send your data to external servers without your consent. Video embeds, where used at all, are integrated exclusively in privacy-friendly mode.
AI companion for events. Questions you actively send on silverfriend.de/events are answered by a language model on Amazon Bedrock in Amazon's EU data centres; question and answer are not stored, the technical log (without wording) is kept for 90 days. Details in section 6.8.
Share functions. The "Share", "WhatsApp", "E-mail" and "Add to calendar" buttons on the events page merely create a link or text that opens in your own app. We embed no software from those providers and do not learn whether or with whom you share something.
Annex B — Subscriber-app-specific additions
App sign-in and authentication. You sign in with e-mail address and password. Session tokens are stored in the secure device keychain (iOS Keychain, Android Keystore); they do not leave the device.
Permissions. The app requests only the permissions required for the respective function: push notifications (with consent). The app requests no microphone, camera, location or contacts access.
Usage analytics and crash reports (opt-in). On the first start after registration, we ask you whether we may collect pseudonymised usage data and crash reports (section 6.5). Without your consent, the analytics components (PostHog, Firebase Crashlytics) remain completely deactivated. You can change your decision at any time in the settings; on withdrawal, the local analytics identifiers on the device are discarded.
Support requests. You can reach our support by e-mail at kontakt@silverfriend.de. In doing so we process your message, your account e-mail and the technical details you provide. Call content is never transmitted.
Pausing, ending, death. When pausing the calls or deleting the account, you can voluntarily tell us a reason — by e-mail to kontakt@silverfriend.de. The notice "deceased" ends the calls immediately and permanently; the older person's data is deleted in accordance with the periods in section 11. We require no proof for this.
In-app account deletion. The app provides a "Delete account" screen. Deletion is initiated immediately after identity verification, completed within 30 days and traced in the audit log. Account deletion does not end a subscription taken out in the app store; you cancel that in the respective store.
Push notifications. The app receives push messages exclusively after your consent. The messages contain only a type code and a timestamp — no names, no content.
iOS privacy manifest. The iOS version of the app contains the privacy manifest file required by Apple, so that you can view the privacy label in the App Store.
Platform footnote (Apple, Google). Certain data — such as device identifiers and diagnostic data — is processed at platform level by Apple or Google. This processing is subject to the respective platform privacy policy and not directly to our responsibility.
Annex C — Spoken information during the call
C.1 — AI disclosure in every call. Every call by the speech model begins with a disclosure of its AI nature in the first sentence:
"Hallo {Vorname}, hier ist SilverFriend, Ihr KI-Begleiter. {Begrüßungsfrage}" — in English: "Hello {first name}, this is SilverFriend, your AI companion. {greeting question}"
This wording is a fixed part of every call.
C.2 — Introduction in the speech model's first call. The first call requires consent already given (section 7.4) and additionally begins with the following introduction in age-appropriate language (spoken in German; English rendering for information):
"Hello {first name}, this is SilverFriend, your AI companion. You have already agreed that I may call you regularly — thank you for that. I am not a real person, but a voice software. I will call you regularly, always between 7 a.m. and 8 p.m., to chat with you — about your day, your memories and things that interest you. To do that, I keep a few notes from our conversations. I give no medical advice, I never ask for bank details, and I will never claim to be your daughter or your son.
Our conversation is not recorded. Only a written record is created, which is deleted after 14 days. Your family later sees only a short overview: how long we talked and which topics we had — no assessments, no content.
If, after a conversation, something suggests that you are not well, a person from SilverFriend looks at it, and we then ask your family to get in touch with you. We do not tell your family anything about the content of our conversation. In an emergency, please always call 112 yourself — I am not made for that.
You can say 'nicht mehr anrufen' at any time, and then I will not call you again. You can also say 'alle meine Daten löschen', and then we pass that on to our data-protection contact point. Would you like to talk to me today?"
A negative answer ("no", "nicht mehr anrufen") results in the call being ended kindly; further calls are stopped once the wish has been reviewed after the call — normally the same business day (section 7.4, withdrawal).
