Finally Compliant
Apply

Legal

Privacy policy

Last updated: September 21, 2026

The short version: the application form collects your name, work email, phone number, company and the answers you give, and we use them to evaluate your application and contact you about it. The site records how it is used, including session replay, and sends advertising measurement events to Meta, which also uses them for its own purposes. We do not sell your data. The detail follows.

  1. 01

    Who we are

    Finally Compliant is operated by Christian Schönlein, a sole proprietor based in Germany. For the processing described on this page, he is the data controller under the EU General Data Protection Regulation (GDPR).

    For any privacy question or request, use the contact form at finally-compliant.com/contact. Messages reach us directly and we answer by email to the address you give us.

    This policy covers this website and how we handle applications and inquiries. Work we perform inside a client’s systems under a signed engagement is governed by that engagement’s agreement, not this page.

  2. 02

    What we collect and why

    Visiting the site: our host processes technical connection data (IP address, timestamp, requested page, browser and device information) in server logs to deliver the site and keep it secure. Legal basis: our legitimate interest in operating a secure, functioning website (Art. 6(1)(f) GDPR).

    Applying: we process the data you enter in the application form (name, work email, phone number, company, and your answers) together with technical context your browser sends with it: the page you came from, our advertising parameters, your time zone, your IP address and browser identification. We use this to evaluate the application, decide whether to offer you a call, and contact you about it by email, phone, or text message. If you enter your contact details but leave before submitting, we keep what you entered up to that point and may follow up with you by email. Legal bases: steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to business inquiries (Art. 6(1)(f)). Answering the questions is voluntary, but without the answers and your contact details we cannot process an application.

    Booking a call: scheduling runs through Cal.com, which processes your name, email, phone number and chosen time on our behalf, and may send you a text reminder before the call. Calls take place over Google Meet. Legal basis: Art. 6(1)(b) GDPR.

    Writing to us: the contact form collects the email address you give and the message you write. Messages are routed into our internal Slack workspace so we see them immediately, and we answer by email. Legal bases: our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR), and our legal obligation to respond where your message is a data protection request (Art. 6(1)(c)).

  3. 03

    How applications are reviewed

    Your answers are scored automatically against fixed rules (for example: whether you already run a compliance platform, whether a deal is actually blocked, company size, deal size, timeline and budget). That scoring decides immediately whether you see a booking page or a decline page. It only decides whether we offer you a call and has no other effect on you. If you believe the outcome is wrong, tell us through the contact form and a person will review it.

    For applications that pass, a second automated step compiles publicly available information about you and your company (for example, your company website and public professional profiles) using external web-search and language-model services, and produces an internal fit assessment. A human reads that assessment and decides whether we hold the call. This step runs on our own systems in Germany.

    Legal basis for both steps: our legitimate interest in qualifying inbound applications before committing call time (Art. 6(1)(f) GDPR). You can object to this processing at any time (see “Your rights” below).

  4. 04

    Analytics and advertising

    We use PostHog (PostHog Inc., USA) to understand how the site is used: pages viewed, interactions, performance metrics, and session replay. When you fill in the application form, your answers (including your name, work email, phone number and company) also go to PostHog as event and profile data, so we can see where applications stall. Session replay hides the text you type into fields but records which answer options you select. Events are collected through our own domain and forwarded to PostHog.

    We use the Meta Pixel and the Meta Conversions API (Meta Platforms, Inc.) to measure whether our ads work and to build advertising audiences. The pixel sets cookies (such as _fbp) and transmits event data to Meta: pages viewed, your IP address and browser identification, the Meta cookie values, and a hashed form of your name, email and phone number once you have entered them in the application form. Meta may link this to your Meta account and also uses it for its own purposes under its own privacy policy. For the collection and transmission of this event data, Meta and we are joint controllers under Meta’s Business Tools terms; what Meta does with it afterwards is Meta’s own responsibility, and you can exercise your rights against either of us.

    Legal basis for both tools: our legitimate interest in measuring and improving the site and our advertising (Art. 6(1)(f) GDPR).

    Both tools store cookies and local data in your browser. The application form also keeps your answers in your browser’s session storage so a dropped connection does not lose your progress; that copy stays on your device and disappears when you close the tab. This site does not show a cookie banner. You can limit or block this measurement through your browser’s cookie, storage and tracking-protection settings, and manage how Meta uses data about you in your Meta ad preferences.

  5. 05

    Service providers and international transfers

    We share personal data only with providers that currently help us run this funnel: Vercel (USA, hosting), Slack/Salesforce (USA, internal routing and storage of applications and contact messages), Google (USA/Ireland, email and video calls), Cal.com (USA, scheduling and text reminders), PostHog (USA, analytics), Meta (USA/Ireland, advertising measurement), Cloudflare (USA, DNS), our US mobile carrier and Apple (USA, for the text message we send you after you apply), and the web-search and language-model services used in the pre-screening step (USA). Providers that process data on our behalf do so under data processing agreements; for the web-search and language-model services we rely on their standard terms.

    Where data leaves the EU/EEA (in particular to the USA), the transfer is safeguarded by the EU-US Data Privacy Framework for certified providers (including Vercel, Salesforce/Slack, Google, PostHog, Meta, and Cloudflare) or by EU Standard Contractual Clauses. You can ask us for a copy of the standard contractual clauses through the contact form; the Data Privacy Framework participant list is public at dataprivacyframework.gov. Beyond these providers, we disclose personal data only where the law requires it.

  6. 06

    Retention

    Applications, contact messages and related notes are kept for up to 24 months after our last contact with you, then deleted. If an engagement follows, contractual and statutory retention periods apply instead. Analytics events are kept for up to 12 months and session recordings for up to 30 days. Server and access logs are deleted within 30 days. Meta retains advertising event data under its own rules.

  7. 07

    Your rights

    Under the GDPR you can request access to your personal data (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20).

    You also have the right to object, on grounds relating to your particular situation, to any processing we base on legitimate interests, including the application screening and the analytics and advertising measurement described above (Art. 21 GDPR).

    To exercise any of these rights, use the contact form at finally-compliant.com/contact. You can also lodge a complaint with a data protection supervisory authority; the authority competent for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, Ansbach, Germany), or you can contact the authority where you live.

    For US residents: at our current size, US state privacy laws such as the CCPA do not apply to us. We still handle access and deletion requests from anyone, regardless of where you live, on the same terms as the GDPR rights above, including the limits where the law requires us to keep records.

  8. 08

    Changes

    We update this policy when the site or our tools change. The current version is always published here with the date above.