Privacy Policy

Last updated: 2026-08-06

1. Controller

The controller responsible for data processing on this website is:

Kimmo Vallema
Franziskanerstraße 5
41564 Kaarst
Germany

Telephone: +49 151 2528 3806
E-mail: [email protected]

No data protection officer has been appointed; there is no obligation to appoint one under Art. 37(1) GDPR or § 38(1) BDSG. For any data protection matter please contact us directly using the details above.

2. Overview of data processing

The following notes provide an overview of what happens to your personal data when you visit this website. We take the protection of your personal data very seriously and treat it confidentially and in accordance with statutory data protection provisions and this privacy policy.

Personal data means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR) – for example your name, your e-mail address or your IP address.

3. Hosting

3.1 Our own server in Germany

This website and its associated services (content management system, customer account and licence management, database) run on our own servers in Germany (self-hosting). Your personal data is processed there and is not transferred to an external hosting provider.

3.2 Cloudflare (delivery and security filtering)

Traffic between your device and our server is routed through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, or Cloudflare Germany GmbH, Rosental 7, 80331 Munich (reverse proxy). Cloudflare handles content delivery, TLS encryption and the mitigation of attacks and abusive traffic. In doing so, Cloudflare necessarily processes connection data, in particular your IP address, the date and time of access, the URL requested, the referrer and details of your browser and operating system, and may set a technically necessary cookie for security purposes in order to detect bot traffic.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure, performant and resilient provision of the website. Insofar as information is stored on or read from your device, this is strictly necessary for providing the service you have expressly requested (§ 25(2) no. 2 TDDDG). Cloudflare also operates in the USA, so a transfer to a third country may take place. Such a transfer is based on the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR, which form part of the data processing agreement concluded with Cloudflare; insofar as the provider is additionally certified under the EU-US Data Privacy Framework, an adequacy decision of the Commission applies.

4. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the browser address bar switching from “http://” to “https://” and by the padlock symbol in your browser bar. When SSL/TLS encryption is active, the data you transmit to us cannot be read by third parties.

In addition we take technical and organisational measures in line with the state of the art pursuant to Art. 32 GDPR, in particular hashed-only storage of passwords and session tokens, access restrictions on database and administration systems, and separation of system components.

5. Server log files

Each time this website is accessed, information is automatically recorded in what are known as server log files, which your browser transmits automatically:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the file retrieved
  • Browser used and, where applicable, operating system
  • Referrer URL (the page previously visited)

This data is collected for the secure operation of the website and for troubleshooting. It is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). Log files are deleted automatically after 14 days.

6. Cookies and storage on your device

This website uses exclusively technically necessary cookies and comparable storage techniques. No tracking, analytics, advertising or reach-measurement cookies are used, and your usage behaviour is not evaluated.

Specifically, we store the following on your device:

  • NEXT_LOCALE (cookie, 12-month lifetime) – stores the language you selected so that the website appears in the same language on subsequent visits.
  • cookie-consent (browser local storage, retained until you delete it) – records that you have taken note of the notice about these storage techniques, so that it is not shown again on every visit.
  • Login token (browser local storage, only while you are signed in to the customer area) – keeps you signed in. The entry is removed when you sign out.
  • Cloudflare security cookie (see section 3.2) – distinguishes human access from automated bot traffic.

No consent is required for this storage under § 25(2) no. 2 TDDDG, because it is strictly necessary in order to provide the service you have expressly requested. The legal basis for the associated processing is Art. 6(1)(f) GDPR, and additionally Art. 6(1)(b) GDPR within the customer area. You can delete or block cookies and local storage entries at any time via your browser settings; the language selection and the customer area may then no longer be fully available.

7. Contacting us by e-mail

If you contact us by e-mail, the details you provide, including the contact data you supply, are stored by us for the purpose of handling your enquiry and in case of follow-up questions. We do not pass this data on without your consent. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in handling the enquiry).

Please note that an unencrypted e-mail could be read by third parties in transit; for confidential content we are happy to offer you a secure transmission channel.

8. Quotation requests via the form

8.1 Data processed

The quotation request form lets you describe your project to us. The following is processed:

  • Mandatory details: name and e-mail address – without these we cannot process and answer the request.
  • Optional details: telephone number, company, selected features, free-text notes and the chosen language.

We use this data solely to process your request, to submit a quotation and to communicate with you about it. You automatically receive an acknowledgement by e-mail; at the same time we receive a notification of the new request. The details are stored in our database on the server described in section 3.1.

The legal basis is Art. 6(1)(b) GDPR, since the processing serves to carry out pre-contractual measures at your request. Insofar as your enquiry is not aimed at concluding a contract, the legal basis is Art. 6(1)(f) GDPR.

8.2 Cloudflare Turnstile (spam protection)

To protect the form against automated submissions we use Cloudflare Turnstile, a service of Cloudflare, Inc. as named in section 3.2. When the form is loaded, a script is retrieved from challenges.cloudflare.com; device and connection data – in particular your IP address, browser information and interaction data – is transmitted to Cloudflare and evaluated there. According to the provider, no user profiles are created for advertising purposes.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against misuse, spam and automated attacks. The service is loaded only on pages that contain a form.

9. Customer account and login

You can create a customer account in order to manage software licences. In doing so we process your name, your e-mail address and your password. The password is stored exclusively as a cryptographic hash; it is technically impossible for us to see the plaintext password.

To keep you signed in we create a session, for which a hash of the session token and an expiry time are stored. Expired sessions are deleted automatically.

The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary to provide the customer account and to perform the licence agreement. You can have your customer account deleted at any time; we will then delete the associated data unless statutory retention obligations (see section 11) prevent this.

10. Sending e-mails

To deliver contract- and enquiry-related e-mails – such as acknowledgements, licence deliveries, invoice notices or password reset messages – we use an external mail server operated by our e-mail service provider InMotion Hosting, Inc., 555 S. Independence Blvd., Virginia Beach, VA 23452, USA. The recipient address and the content of the respective message are processed on the provider’s systems. Transmission between our server and the mail server is TLS-encrypted. As the provider is based in the USA, a transfer to a third country takes place in this respect, based on the European Commission’s standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

The legal basis is Art. 6(1)(b) GDPR insofar as the messages serve to perform a contract, and otherwise Art. 6(1)(f) GDPR. We do not send newsletters or e-mail advertising.

11. Retention periods

We process personal data only for as long as is necessary for the respective purposes. We then delete the data unless a statutory retention obligation applies. In detail:

  • Server log files: deleted automatically after 14 days (section 5).
  • Quotation requests: generally up to twelve months after the correspondence has concluded (section 8).
  • Customer account and licence data: for the duration of the contractual relationship and the licence term; deleted thereafter unless a retention obligation applies.
  • Session data: deleted automatically once the session expires.
  • Invoices, accounting records and contract documents: retained in accordance with commercial and tax law periods under § 257 HGB and § 147 AO (six and eight years respectively). During this period processing is restricted to fulfilling those obligations; the legal basis is Art. 6(1)(c) GDPR.

12. Your rights

You have the following rights under the GDPR:

  • Access (Art. 15 GDPR) – you can find out at any time what data we hold about you.
  • Rectification (Art. 16 GDPR) – you can have inaccurate data corrected.
  • Erasure (Art. 17 GDPR) – you can request the deletion of your data.
  • Restriction (Art. 18 GDPR) – you can have the processing restricted.
  • Data portability (Art. 20 GDPR) – you can receive your data in a commonly used format.
  • Objection (Art. 21 GDPR) – you can object at any time to processing based on Art. 6(1)(f) GDPR.

To exercise your rights please contact us by e-mail: [email protected]

13. Right to withdraw consent

Insofar as the processing of your data is based on your consent (Art. 6(1)(a) GDPR), you have the right to withdraw that consent at any time. The lawfulness of processing carried out on the basis of the consent up to the point of withdrawal remains unaffected.

14. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Postfach 20 04 44
40102 Düsseldorf, Germany
www.ldi.nrw.de

15. No automated decision-making

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.

This English text is a translation provided for convenience. The authoritative German version of this privacy policy is available at /datenschutz.