Privacy policy

1. Controller for the data processing (hereinafter: “we”)

Mr Said El Ouaaziky Hassan
Wuhlestraße 7a
12683 Berlin

Contact:

Email: kontakt@aktegra.com
Contact form: https://www.aktegra.com/de/kontakt

Further details about us can be found in our provider identification.

2. Personal data, purposes of its processing and legal bases

Using our website is generally possible without you having to provide personal data. Providing personal data is voluntary.

Personal data is all information relating to an identified or identifiable natural person (hereinafter "data subject"). A natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more special characteristics that express the identity of that natural person.

The purpose of processing data is the operation of this website with information about our range of services together with contact options, as well as the provision of our software service Aktegra.

Personal data is collected on our website only where this is

  • necessary for the use of the website (legal basis: Art. 6(1)(1)(a) and/or Art. 6(1)(1)(b) of the General Data Protection Regulation (GDPR)),
  • necessary to protect our interest in improving the user experience and in maintaining the security of use (legal basis: Art. 6(1)(1)(f) GDPR),
  • necessary for the use of the services offered on the website and for pre-contractual measures, in particular for form entries (legal basis: Art. 6(1)(1)(a) and/or Art. 6(1)(1)(b) GDPR), or
  • necessary for concluding and performing a contract (legal basis: Art. 6(1)(1)(a) and (b) GDPR).

Further details on the processing of data can be found below under the corresponding headings:

3. Hosting, database, access data and technical logs

For hosting and providing our website we use the services of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. The website is delivered via Vercel's infrastructure. The database and the user and application data stored in it are operated through Supabase Inc., c/o Incorporating Services, Ltd., 3500 S. DuPont Highway, Dover, Kent 19901, Delaware, USA, in a data centre in Frankfurt am Main (AWS region "eu-central-1"). Supabase and Vercel process personal data on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR.

When our website is accessed, technically necessary connection data is processed. This may include in particular the IP address, the date and time of access, the page or file requested, the volume of data transferred, HTTP status codes, the referrer URL, browser type and version, operating system and information about the internet service provider. A complete access log of all page views is not kept. To a limited extent, however, technical error, security and container logs may arise. These may contain the data listed above, insofar as this is necessary for error analysis, for detecting and averting abusive access, and for ensuring the security and stability of our information technology systems.

Since Vercel is based in the USA, a transfer of personal data to the USA cannot be excluded. The transfer takes place on the basis of Vercel's certification under the EU-US Data Privacy Framework; in addition, the EU standard contractual clauses are used. Insofar as access to the data stored at Supabase from a third country should be necessary in the context of support or maintenance services, this takes place on the basis of the EU standard contractual clauses pursuant to Art. 46 GDPR.

Processing takes place on the basis of Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional provision of our website and in averting attacks and misuse.

4. Cookies

Our website stores cookies. Cookies are small files which make it possible to store specific, device-related information on the user's access device (PC, smartphone or similar). On the one hand they serve the usability of websites and thereby the users (for example storing login data). Further information can be found in the following sections of our privacy policy. In particular, we use a session cookie to maintain your sign-in via Supabase Auth, a temporary cookie for securely carrying out the sign-in process (PKCE verifier), and the cookie NEXT_LOCALE, in which the language version you have chosen is stored. To manage your consent we additionally use two of our own cookies: the cookie consent_analytics, in which your decision about the analytics cookies is stored (value "true" or "false"), and the cookie consent_id, which contains a randomly generated identifier that is meaningless in itself and serves exclusively to attribute your consent and any later withdrawal to the same record (section 13). Both are stored for 180 days; they contain no personal data, and the identifier is not derived from your data.

Insofar as you give consent for non-essential cookies, the legal basis is § 25(1) TDDDG and Art. 6(1)(1)(a) GDPR (consent). To obtain and manage your consent we use a consent management tool. The consent management tool serves the purpose of enabling you to select and manage your consent to the setting of cookies and the use of certain services in a data-protection-compliant manner, and of demonstrating our obligations in this respect pursuant to Art. 5(2) GDPR and Art. 7(1) GDPR. The legal basis for using the consent management tool is Art. 6(1)(1)(c) GDPR, that is, compliance with a legal obligation, as well as our legitimate interest under Art. 6(1)(1)(f) GDPR in a user-friendly, transparent and legally compliant arrangement of consent management.

You can obtain further information on this and on the cookies and services used from our consent management tool, and withdraw your consent at any time freely and without disadvantage with effect for the future.

As a user you can influence the use of cookies. Most browsers have an option with which the storage of cookies is restricted or entirely prevented. However, please note that use and in particular convenience of use will be restricted without cookies.

5. Contact by email

If you contact us by email or communicate with us via a form, we process the personal data you transmit. This includes in particular your email address, your name insofar as given, the content of your message and, where applicable, further information you transmit.

Processing takes place in order to handle your enquiry, to communicate with you and in case of follow-up questions. Insofar as your enquiry concerns the conclusion or performance of a contract, the legal basis is Art. 6(1)(1)(b) GDPR. Otherwise processing takes place on the basis of Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in handling enquiries appropriately, efficiently and comprehensibly.

For forwarding the emails arriving at kontakt@aktegra.com we use ImprovMX, 8 The Green, STE D, Dover, Delaware 19901, USA. The email inboxes are provided and administered through Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. ImprovMX and Google process personal data insofar as this is necessary for forwarding, receiving, storing and administering emails. ImprovMX makes a data processing agreement available for paying customers; according to its information, data of EU customers is stored in French data centres.

For sending sign-in links, transactional emails and emails in connection with forms we use Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA. In this context, in particular the recipient's email address, the respective content sent and technical sending and delivery information are processed.

Since ImprovMX and Resend are based in the USA, a transfer of personal data to the USA cannot be excluded. Insofar as such a transfer is made by ImprovMX, we base it on the EU standard contractual clauses pursuant to Art. 46 GDPR. Insofar as a transfer is made by Resend, it takes place on the basis of Resend's certification under the EU-US Data Privacy Framework and, in addition, on the basis of the EU standard contractual clauses pursuant to Art. 46 GDPR. Resend is certified under the EU-US Data Privacy Framework.

Insofar as access by Google LLC or other Google companies outside the European Economic Area should be necessary in the context of using the email inbox, the transfer takes place on the basis of Google LLC's certification under the EU-US Data Privacy Framework and, in addition, on the basis of the EU standard contractual clauses pursuant to Art. 46 GDPR.

6. Customer account

On our website you have the option of setting up a customer account in order to test Aktegra free of charge first and then to conclude the subscription you want. Through our protected customer area you can then maintain your company data, manage your booked subscription and access our software as well as view saved intermediate states. Signing in takes place via a sign-in link sent by email ("magic link"). We process the data you provide in the customer area exclusively in order to be able to make the customer area, your booked subscription and the software functions available to you. The legal basis for this is the necessity of performing the contract pursuant to Art. 6(1)(1)(b) GDPR.

7. Processing of the data you enter (questionnaire and organisation data)

In order to create the classification and documentation reports we process the information you enter in the questionnaire and the organisation data you provide. This includes in particular the company name, the address and information about the system assessed. This data is assigned to your user account and processed exclusively insofar as this is necessary for creating and providing the classification and documentation reports you have requested.

The legal basis for this processing is Art. 6(1)(1)(b) GDPR, since the processing is necessary for the performance of the contract concluded with you or for carrying out pre-contractual measures.

8. Notification about product availability

On our pricing page at https://www.aktegra.com/de#pricing you have the option of leaving your email address in order to be notified once about the availability of our paid services. In doing so we process your email address, the tariff you are interested in and your chosen language setting. The data is used exclusively for sending this one-off notification. No newsletter is sent and no use for other advertising purposes takes place. The data is stored in our database in Frankfurt am Main. To detect and limit automated or abusive requests we additionally process your IP address briefly as a technical counting key. The IP address is not stored permanently together with your registration, but deleted once the respective technical time window has elapsed. The legal basis is Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in securing the availability and integrity of our form.

In the event of a withdrawal we delete your data from the notification list. Once the notification has been sent, your data is likewise deleted afterwards.

The legal basis for the processing is your consent pursuant to Art. 6(1)(1)(a) GDPR. You can withdraw your consent at any time with effect for the future, for example by email to kontakt@aktegra.com.

9. Feedback function

You have the option of giving us feedback about our service voluntarily, in particular after downloading a document or via a link provided for this purpose on our website.

In doing so we process your rating on a scale of 1 to 5, any free text you enter, the time of submission and your chosen language setting. If you are signed in, the feedback is additionally assigned to your user account. If your feedback relates to a specific report, we additionally process that report's internal identifier.

You can optionally provide an email address if you would like a reply from us. Providing the email address and giving feedback are voluntary and not necessary for using our service.

We process feedback data in order to improve our service, our documentation reports and the usability of our offering. The legal basis is Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in the further development and improvement of our offering. Insofar as you voluntarily provide your email address for a query or a reply, processing takes place on the basis of your consent pursuant to Art. 6(1)(1)(a) GDPR. You can withdraw your consent at any time with effect for the future.

To detect and limit automated or abusive access we process the IP address briefly as a technical counting key. The IP address is not stored permanently together with the feedback, but deleted once the respective technical time window has elapsed. The legal basis for this is Art. 6(1)(1)(f) GDPR. Our legitimate interest lies in ensuring the security and availability of the feedback function.

10. Stripe

On our website you have the option of making payments by the credit cards Visa, Mastercard, American Express, Cartes Bancaires, Apple Pay and Link. If you make payment using these methods, payment processing takes place through the payment provider "Stripe". The provider is Stripe Payments Europe Ltd, Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland. The data required for this (card number, validity and verification number) is transmitted encrypted to the payment provider and cannot be viewed by the website operator. The payment provider transfers, processes and where applicable stores personal data outside the EU that is necessary for handling the payment. Stripe alone is responsible for the processing of this data. Insofar as personal data is processed in the transfers described, the processing takes place exclusively for the purpose of payment processing pursuant to Art. 6(1)(1)(b) GDPR.

For details on payment with Stripe please refer to the terms and the privacy provisions of the payment provider at https://stripe.com/de/terms.

11. Google Analytics

Our website uses Google Analytics in order to analyse our website and its use, to make it more user-friendly and effective, and to advertise and offer our services more optimally. The provider is Google LLC., 1600 Amphitheatre Parkway Mountain View, CA 94043, US, or Google Ireland Limited. For users whose habitual residence is in the European Economic Area or Switzerland, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, EU is the responsible controller for the Google services (hereinafter: "Google"). Google Ireland Limited is a company affiliated with Google LLC whose services we integrate and which must likewise comply with the General Data Protection Regulation. Google LLC is certified under the EU-US Data Privacy Framework and is thereby obliged to comply with European data protection requirements.

The legal basis for this is Art. 6(1)(1)(f) GDPR or, if you have given consent to the use on the basis of a notice provided by us on the website ("cookie banner"), the lawfulness of the use is governed by Art. 6(1)(1)(a) GDPR, § 25(1) TDDDG.

Google Analytics uses cookies, text files that are stored on your computer and that make it possible to analyse your use of the website. The information generated by cookies about your use of this website is generally transmitted to a Google server in the USA and stored there. However, the IP address transmitted by your browser within Google Analytics is not merged with other Google data. IP anonymisation is activated on our website. Your IP address is therefore shortened by Google beforehand within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide us with further services connected with website use and internet use.

You can give your consent to the use of Analytics via the cookie policy in the cookie settings by means of an opt-in (activation) and deactivate it again by means of an opt-out. You can also prevent the storage of cookies by setting your browser software accordingly; however, we point out that in this case you may not be able to use all functions of our website to their full extent. You can additionally prevent the collection of the data generated by the cookie and relating to your use of the website (including your IP address) by Google, and the processing of this data by Google, by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. You can find further information on Google's terms of use and privacy here and there.

12. Recipients of personal data

Beyond the sections above, personal data is passed on only to our employees.

Beyond that, your personal data is not passed on to third parties without your express consent, unless we are legally obliged to do so within the meaning of Art. 6(1)(1)(c) GDPR or the transfer of data is strictly necessary pursuant to Art. 6(1)(1)(b) GDPR for the performance of a contractual relationship.

We point out that data transmission on the internet (for example when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.

13. Duration of storage

We delete your data as follows:

Data categoryUsual storage periodNotes / purpose
Technical error, security and container logsApprox. 7 to 14 days, at most a few weeksEnsuring technical operation, IT security, error analysis as well as detecting and averting abusive access
Cookies – authentication and session cookiesUntil the end of the session or until the respective authentication session expiresTechnical functionality of the web app, sign-in and maintenance of the customer area
Cookie for the language setting (NEXT_LOCALE)Until the language setting is changed, until the cookie expires or until it is deleted by the userStorage of the language version selected by the user
Consent records and cookie settingsUntil consent is withdrawn; proof of the consent and of the withdrawal beyond that regularly for up to three yearsManagement and demonstration of consents required under data protection law
Contact enquiries by emailUntil the enquiry has been dealt with conclusively; beyond that regularly for up to three years, and where applicable longer in the case of business correspondence or a statutory retention obligationHandling the enquiry, demonstrating the communication and defending against legal claims
Customer account and contract dataDuring the active business relationship; thereafter regularly for up to six years, insofar as no longer retention obligations existPerformance of the contract, administration of the customer account, communication and demonstration of the contractual relationship
Access data and authentication informationUntil the user account is deleted or until the authentication session is changed or expiresSign-in via magic link, authentication and protection against unauthorised access
Questionnaire entries, organisation data and information about the AI system assessedDuring use of the service; after the end of the contract until a contractually provided export period expires, regularly 30 days, then deletion insofar as no retention obligations existCreation and provision of the classification and documentation reports
Classification and documentation reports created, as well as saved intermediate statesDuring use of the service; after the end of the contract until a contractually provided export period expires, regularly 30 days, then deletion insofar as no retention obligations existProvision, availability and export of the reports commissioned
Data for the notification about product availabilityUntil the one-off notification is sent or until consent is withdrawnSending the requested one-off notification; no newsletter and no other advertising
IP address for the product availability notificationOnly for the duration of the respective technical time window, regularly a few minutes to hoursLimiting automated requests and averting misuse; no permanent storage together with the notification registration
Feedback data, in particular rating, free text, time stamp, language setting, account assignment and where applicable report identifierUp to 12 months; thereafter deletion or anonymisationImprovement of the service, of the documentation reports and of usability
IP address for the feedback functionOnly for the duration of the respective technical time window, regularly a few minutes to hoursLimiting automated or abusive access; no permanent storage together with the feedback
Google Analytics data14 monthsAnalysis of the use of the website on the basis of consent; questionnaire content, organisation data, information about the AI system assessed and results of the risk classification are not transmitted to Google
Order, contract, invoice and payment status dataDuring the active business relationship; thereafter in accordance with statutory retention obligationsContract handling, billing, accounting and evidence of business transactions
Payment card dataNot stored by us; processing by Stripe according to its own storage periodsPayment processing; we generally receive only the payment and status information necessary for contract administration
Invoices and accounting recordsRegularly eight yearsCompliance with commercial and tax law retention obligations
Commercial and business lettersRegularly six yearsCompliance with commercial and tax law retention obligations

Otherwise it is reviewed annually whether the data stored by you can be deleted. Commercial and tax law retention obligations remain unaffected.

14. Rights of data subjects

You are not legally obliged to provide your personal data. However, provision may be necessary for concluding a contract or for functions of the website. If it is not provided, a contract or a function on the website may therefore not be able to be offered.

There is no automated decision-making on the website, and profiling does not take place.

The rights of data subjects arise in particular from Articles 15 to 23 and Article 77 GDPR as well as from §§ 32 to 37 of the new German Federal Data Protection Act (BDSG).

In relation to your personal data you have the right vis-à-vis us to

  • access, Art. 15 GDPR
  • rectification, Art. 16 GDPR
  • erasure, Art. 17 GDPR
  • restriction of processing, Art. 18 GDPR
  • portability, Art. 20 GDPR.

If you have given consent to the processing of personal data, you have the right of

  • withdrawal, Art. 7 GDPR

with effect for the future.

You further have the right to raise an

  • objection, Art. 21 GDPR

to the processing of personal data.

  1. You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which takes place on the basis of Art. 6(1)(1)(f) GDPR (data processing on the basis of a balancing of interests). If you object, we will no longer process your personal data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

  2. In individual cases we process personal data in order to carry out direct marketing. If this is the case for you, you have the right to object at any time to the processing of data concerning you for the purposes of such advertising. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection may be made without any particular form and should preferably be addressed to us, see above under 1.

If you are of the opinion that the processing of the personal data concerning you infringes data protection law, you always have the

  • right to lodge a complaint

with the competent supervisory authority, cf. Art. 77 GDPR. Without prejudice to any other administrative or judicial remedy, you have this right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement, if you are of the opinion that the processing of the personal data concerning you infringes the GDPR.

The contact details of the data protection officers in the federal states, of the supervisory authorities for the non-public sector, for broadcasting, for the churches, in Europe and abroad, as well as of the Virtual Data Protection Office, can be found there: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

The supervisory authority competent for us is the Berlin Commissioner for Data Protection, Alt-Moabit 59–61, 10555 Berlin.

Convenience translation. Only the German version is legally binding. Read the German version