Impressum & privacy notice
For all sippar.network pages · last updated 2026-08-14 · Deutsche Fassung
Legal notice
Impressum
Information in accordance with § 5 DDG (Digitale-Dienste-Gesetz):
Elad Mintzer
Hasenheide 17
10967 Berlin
Germany
Email: elad@sippar.network
Sippar is operated by Elad Mintzer as an individual (sole proprietor / freelancer).
Responsible for content in accordance with § 18 (2) MStV: Elad Mintzer, address as above.
Consumer dispute resolution
We are neither obliged nor willing to participate in dispute-resolution proceedings
before a consumer arbitration board (§ 36 VSBG).
Privacy notice (Datenschutzerklärung)
Controller
The controller under the EU General Data Protection Regulation (GDPR) is
Elad Mintzer, address as in the Impressum above,
elad@sippar.network.
Which pages this notice covers
This notice covers all pages on sippar.network. Two of them
run a paid product, and they handle data differently, so each has its own section
below:
- Social search — sippar.network/social/
and sippar.network/social/brand-monitoring/.
- StableEnrich — sippar.network/enrich/.
All of these pages work without an account. There is no signup, no login, and we set
no cookies.
What every page does with data
- Server logs and rate limiting. Our servers process your IP
address to deliver the pages and to enforce per-visitor limits (abuse and cost
protection). Web-server logs are rotated daily and deleted after 14 days at the
latest; internal application logs are deleted after 7 days at the latest. Neither
your search text nor the company values you look up are written to the web-server
logs. Legal basis: Art. 6 (1)(f) GDPR — operating and protecting the service.
- Visit statistics. We count page visits in aggregate on the
server side from the web-server logs named above (numbers per page and day, no
visitor profiles). We also operate a self-hosted, cookieless analytics tool (based
on Plausible) on servers in an EU data center (Frankfurt, Germany region of Amazon
Web Services). It sets no cookies, stores no persistent identifiers, builds no
cross-site profiles, and produces aggregate statistics only (page views, referrers,
country, browser type); any transient technical identifier used to count a visit is
discarded within 24 hours. Legal basis: Art. 6 (1)(f) GDPR.
- Fonts. The Inter and JetBrains Mono typefaces are self-hosted:
the font files are served from this website's own server, together with the page
itself. Loading them sends no request to Google or to any other third party.
- Payments and credit. Paid searches and paid enrichment settle on
public blockchains. If you pay from your own wallet, your wallet address, the amount,
and the transaction are recorded on the relevant public blockchain. Blockchains are
public by design and worldwide; entries cannot be altered or deleted by us. Free
social searches are paid by Sippar's own wallet, so nothing about you is written
on-chain. If you buy credit, we additionally keep an internal ledger of your wallet
address, top-ups, charges, and transaction references as accounting records. Legal
basis: Art. 6 (1)(b) and (c) GDPR.
- Browser storage. If you buy credit, a session token is
stored in your browser's local storage so this browser is recognized on your next
visit. That storage is strictly necessary for the feature you asked for
(§ 25 (2) TDDDG — no consent banner required) and you can remove it at any time
via the page's “forget” option or by clearing your browser storage.
Nothing is stored for visitors who do not sign in or buy credit.
Social search (/social/ and /social/brand-monitoring/)
- Search queries. The text you type into the search box is sent to
our servers and forwarded to third-party data suppliers, which read publicly
available social media posts to answer it. The query is processed to deliver your
result and to prevent abuse. We do not store your search text in any database; it
passes through our servers in transit and can at most appear briefly in technical
logs (see retention below). Please do not type personal data into the search box
beyond what your search genuinely needs. Legal basis: Art. 6 (1)(b) and (f) GDPR.
- Prepared example reports. The example reports shown on the search
page are stored results of past searches. They contain material from publicly available
social media posts — post titles, the posting account's public name,
engagement numbers, and links to the original posts — and remain published
for as long as the example is part of the page, including in the page's public
source-code repository. We rely on the legitimate interest in demonstrating the
service with real results (Art. 6 (1)(f) GDPR). Because this material is collected
from public sources, informing every author individually would involve
disproportionate effort (Art. 14 (5)(b) GDPR); this notice provides that
information publicly instead. If a report quotes a post of yours and you want it
removed, email
elad@sippar.network and we will remove it
from the report.
StableEnrich (/enrich/)
- The list you import stays in your browser. When you paste or
upload a file (for example a CSV export from LinkedIn or your CRM), that file is
read and parsed by JavaScript running on your own device. It is not uploaded to our
servers. Contact names, job titles, email addresses, phone numbers and any other
column in your file are displayed back to you from your own browser's memory and
are never transmitted to us or to any data supplier. Closing or reloading the page
discards them.
- Only the company is looked up. When you run an enrichment, the
single value sent to our servers, and onward to the third-party data supplier, is
the company name or domain for each row you selected — for example
stripe.com. No person from your file is included in that
request. The supplier returns firmographic information about the organisation
(sector, size, location, funding and similar). Company-level records of this kind
are generally not personal data; where a company is a sole proprietorship the
record may nevertheless relate to an identifiable person, and the legal basis for
processing it is our and your legitimate interest in business information under
Art. 6 (1)(f) GDPR. We do not store the companies you looked up in any database
beyond the accounting record described under payments above. Legal basis:
Art. 6 (1)(b) and (f) GDPR.
- Person-level enrichment is not offered. This page does not look
up, buy, infer or enrich data about the individuals in your file, and no feature on
it sends a person's name to a data supplier.
How long we keep data
- Search queries: not stored in any database; at most transiently
in technical application logs, which are deleted after 7 days at the latest.
- The list you import into StableEnrich: never received by us — it
is parsed in your browser and discarded when you close or reload the page.
- Company lookups: not stored in any database; at most transiently
in technical application logs, which are deleted after 7 days at the latest.
- Web-server logs (IP address): rotated daily, deleted after
14 days at the latest.
- Internal application logs: deleted after 7 days at the latest.
- Visit statistics: kept as aggregate numbers only, which contain
no personal data; transient counting identifiers are discarded within 24 hours.
- Payment and credit records (wallet address, top-ups, charges,
transaction references): kept for as long as your credit exists and thereafter for
the statutory commercial and tax retention periods, currently up to ten years under
German law.
- Blockchain entries: permanent — public blockchains cannot be
altered or deleted by us.
- Prepared example reports (post titles, public account names,
links to posts): kept for as long as the example remains part of the page; removed
from the report on justified objection (see above). Past versions can persist in
the public source-code repository's history.
Data transfers to other countries
Some recipients of the data described above are located outside the EU/EEA, in
particular in the United States:
- Hosting. These pages are served from infrastructure of
Hivelocity, Inc. (Tampa, Florida, USA), so your IP address is processed on servers
in the United States. Hivelocity states that it is certified under the EU-U.S.
Data Privacy Framework (DPF), which the European Commission has recognized as
providing an adequate level of protection (Art. 45 GDPR).
- Search suppliers. Search queries are forwarded to Merit
Systems, Inc. (New York, USA — operator of the stablesocial.dev data service) and
may be passed on to its upstream data providers. These suppliers are not, to our
knowledge, certified under the EU-U.S. Data Privacy Framework, and we have not
concluded EU standard contractual clauses with them. For these transfers we rely
on Art. 49 (1)(b) GDPR: the transfer is necessary to run the search you request —
without it, the service you are asking for cannot be delivered. Please be aware
that data transferred on this basis may not enjoy a level of protection equivalent
to the EU's: US authorities may be able to access it, and enforcing your data
protection rights there may be harder. If you do not want your query text
transferred to these suppliers, do not use the search.
- Enrichment suppliers. The company name or domain you look up is
forwarded to Merit Systems, Inc. (224 West 35th Street, Ste 500 #2218, New York,
NY 10001, USA), which operates the stableenrich.dev data
service as part of its Stables services, and may be passed on to its own upstream
data providers (the firmographic record is produced by CompanyEnrich). These suppliers are
not, to our knowledge, certified under the EU-U.S. Data Privacy Framework, and we
have not concluded EU standard contractual clauses with them. For these transfers
we rely on Art. 49 (1)(b) GDPR: the transfer is necessary to run the lookup you
request — without it, the service you are asking for cannot be delivered. Please be
aware that data transferred on this basis may not enjoy a level of protection
equivalent to the EU's: US authorities may be able to access it, and enforcing your
data protection rights there may be harder. If you do not want a company value
transferred to these suppliers, do not run an enrichment. Your imported list is not
part of this transfer — it never leaves your browser.
Personal data of other people in search results
If you search for a person's name (or a query that identifies a person), we process
that person's data too: the query is forwarded to the data suppliers named above,
and the publicly available social media posts they return — which can contain
personal data of the posts' authors and of people mentioned in them — pass through
our servers to your browser. For this processing Sippar is a controller. The legal
basis is Art. 6 (1)(f) GDPR: our legitimate interest, and that of the person
searching, in operating a search over publicly available social media posts. We do
not store these results; they are delivered to the visitor who requested them and
the transient handling ends there.
We do not individually notify people whose data appears in search results. Doing so
would be impossible or would involve disproportionate effort within the meaning of
Art. 14 (5)(b) GDPR: the processing is transient, we keep no record of who was
searched, and we hold no contact details for the people concerned. As the measure
foreseen by Art. 14 (5)(b), this notice makes the information about that processing
publicly available. If you believe your data has appeared in search results, the
rights below apply to you as well — contact
elad@sippar.network.
The people in your StableEnrich list
Your imported file typically contains personal data of other people — colleagues,
contacts, connections. Sippar does not process it. The file is read
by JavaScript on your own device, is never uploaded to us, and no name, title or
contact detail from it is sent to us or to any data supplier. Only the company value
of the rows you select leaves your browser. For that reason Sippar is neither
controller nor processor for the contacts in your list, and no Art. 14 GDPR
information obligation toward them arises on our side.
You remain responsible for your own file. If you are using contact data in a
business context, you are the controller for it, and your own legal basis and
transparency obligations toward those people continue to apply — as they did before
you opened this page.
Recipients
The pages are served by our hosting providers (Hivelocity, Inc., USA; analytics on
Amazon Web Services, Frankfurt, Germany region). Search text and the company values
you look up are passed to the third-party data suppliers named above. Your imported
StableEnrich list is passed to nobody. We do not sell personal data and we do not use
it for advertising.
Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16),
erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20),
and objection to processing based on legitimate interest (Art. 21). To exercise any
of these, email elad@sippar.network. You
also have the right to lodge a complaint with a data protection supervisory
authority (Art. 77).
No profiling
We do not use automated decision-making or profiling within the meaning of
Art. 22 GDPR.
Back to sippar.network