Privacy Policy
1. Data Controller
The data controller in the sense of the GDPR is:
eye-i4 GmbH
Mönchweilerstraße 12
78048 Villingen-Schwenningen
Email: kontakt@eye-i4.de
3. Types of Data Processed
- Master data (e.g. names, addresses)
- Contact data (e.g. email, phone)
- Content data (e.g. registrations, profile info)
- Usage data (e.g. pages visited, access times)
- Metadata and communication data (e.g. IP addresses)
4. Purposes of Processing
- Provision of the platform and its functions
- Management of memberships, courses, and events
- Communication with users (e.g. registration confirmations)
- Security and stability measures
5. Legal Basis
The processing of personal data is based on Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. b GDPR (contract performance), Art. 6 para. 1 lit. c GDPR (legal obligation) and Art. 6 para. 1 lit. f GDPR (legitimate interests).
6. Recipients of Personal Data
We use the following data processors to provide the service:
- Microsoft Azure (Germany West Central) — Hosting of the web application and database. Processing location: Germany. Basis: Data processing agreement (DPA) according to Art. 28 GDPR.
- SendGrid (Twilio Inc.) — Sending of transactional emails (registration confirmations, notifications). Processing location: USA. Basis: Standard Contractual Clauses (SCC) according to Art. 46 GDPR.
No data is shared with third parties for other purposes.
7. Storage Duration
Personal data is deleted or blocked as soon as the purpose of storage no longer applies. Storage beyond this period takes place if this is provided for by European or national legislators (e.g. tax law retention obligations of 10 years).
8. Rights of Data Subjects
Data subjects have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
9. Cookies and Local Storage
This website uses only technically necessary cookies. No tracking, analytics or advertising cookies are used. All resources (CSS, JavaScript, fonts) are served locally from our own server — there is no loading from external CDN services.
| Cookie Name | Purpose | Storage Duration | Type |
|---|---|---|---|
lang |
Stores the selected display language (de, en, fr, es, it, pl, nl, cs) | 365 days | Technically necessary |
.AspNetCore.Antiforgery.* |
CSRF protection for form submissions (Cross-Site Request Forgery prevention) | Session (browser session) | Technically necessary |
.AspNetCore.Cookies |
Authentication session for logged-in users | Session / until logout | Technically necessary |
Since only technically necessary cookies are used, consent according to § 25 para. 2 TTDSG is not required.
10. Changes to this Privacy Policy
This privacy policy may be adjusted to reflect changes in the legal situation or to the service. The current version is available on this page.