Privacy Policy

Last updated: September 26, 2026

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Data Collection on This Website

We collect data that you provide to us (e.g., through contact forms) and data that is automatically collected by our IT systems when you visit the website (e.g., IP address, browser type, access time).

Your Rights

You have the right to access, correct, or delete your personal data at any time. You also have the right to restrict processing and to data portability. If you have given consent for data processing, you can withdraw it at any time.

2. Hosting

This website is hosted by an external service provider. Personal data collected on this website is stored on the servers of the hosting provider. This primarily includes IP addresses, contact requests, and website access data.

3. Contact Forms

When you use our contact forms, your data is processed for the purpose of handling your inquiry and stored based on your consent or for contract fulfillment (Art. 6 para. 1 lit. a or b GDPR).

4. Payment Provider

Stripe

We use Stripe for payment processing. When you make a payment, your transaction data is processed by Stripe. For more information, see Stripe's privacy policy: https://stripe.com/privacy.

5. Database and Storage

Supabase

We use Supabase for data storage and authentication. Your data is stored on Supabase servers in the EU region, so it is processed within the European Union. For more information, see Supabase's privacy policy: https://supabase.com/privacy.

6. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right to access your data
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

7. Additional Processors

Resend (email delivery)

All outbound email is sent through Resend, Inc., USA — newspaper delivery, trial-expiry reminders and system notifications. This processes the recipient address, name and the content of the message. Legal basis: Art. 6 para. 1 lit. b GDPR.

Anthropic (news section generation)

We use an AI model from Anthropic PBC, USA, to select and summarise the news section. Only publicly available news articles and your chosen topic setting are transmitted. No personal data belonging to your guests or your account is sent. Legal basis: Art. 6 para. 1 lit. b GDPR.

GNews (news sources)

The news articles themselves are retrieved through the GNews API (gnews.io). Only the language and country of the requested edition are transmitted; no personal data.

SerpApi (hotel research)

We use SerpApi, LLC, USA, to research publicly listed hotel contacts. Search terms and locations are transmitted; publicly visible business data is returned. Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in contacting commercial prospects).

Art. 28 GDPR data processing agreements are in place with every provider named above. Where data is transferred to the USA, this rests on the EU Standard Contractual Clauses.

8. AI-Powered Content Generation

We use AI technologies to create personalized newspaper content. These process publicly available news content and information you provide (e.g., hotel name, location) to generate tailored content.

AI-powered processing is based on Art. 6 para. 1 lit. b GDPR (contract fulfillment). There is no automated decision-making within the meaning of Art. 22 GDPR that has legal effect on you. All generated content can be reviewed and modified by you before use.

9. Contact

For questions about data protection, please contact:
MorningPaper
Robert Wolffgang
Phone: +49 251 590512
Email: hello@panhelios.de