Privacy policy
This is a convenience translation. In case of discrepancies, the German version prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
iontic GmbH
Augartenstraße 24
76137 Karlsruhe
Germany
Phone: +49 721 47007114
Email: kontakt@iontic.de
2. General information on data processing
As a rule we process personal data of our users only to the extent necessary to provide a functioning website together with our content and services. Processing regularly takes place only with the user's consent or where a legal basis permits the processing (in particular Art. 6 GDPR).
3. Hosting and server log files
This website is operated on servers in the European Union. On every request the system automatically records data and information about the requesting device in server log files. Recorded are: IP address, date and time of access, requested resource, volume of data transferred, HTTP status code, referrer URL as well as browser and operating system type.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technical provision, stability and security of the website. The log files are stored for threat prevention and abuse detection and are generally deleted after 14 days at the latest, unless security-relevant incidents require longer retention.
4. Registration and user account
Using the dashboard requires creating a user account. In doing so we process the email address you provide, a stored password hash as well as optional details on two-factor authentication and passkeys. This data is necessary to establish and carry out the usage relationship.
The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). The data is stored for as long as the account exists and is removed after its deletion, unless statutory retention obligations apply.
5. Processing of form submissions
The core function of Mailan is receiving and forwarding form submissions transmitted through the endpoints embedded by our customers. In doing so we process the data transmitted in the respective forms (e.g. name, email address, message) as well as technical metadata such as IP address and timestamp for spam protection and abuse detection.
Towards the end users of the embedded forms we act as a processor within the meaning of Art. 28 GDPR; the operator of the embedding form is the controller for the respective form processing. Submissions are stored for the duration of the service provided to the respective customer and deleted on their instruction.
The IP address and browser identifier (user agent) transmitted with a submission are only needed for spam and abuse defence. We therefore shorten the IP address after seven days to its network part (e.g. 203.0.113.0), so it no longer identifies an individual connection, and delete the user agent entirely. Only the coarse device category (desktop, mobile, tablet) and a country code derived locally from the IP address are retained for statistical purposes; no external geolocation service is contacted, and no location more precise than the country is stored.
For statistical purposes we additionally aggregate submissions into anonymous daily counts per form (e.g. the number of delivered and filtered submissions, attachment counts, which form fields were filled in, and coarse device and country distributions). These aggregates contain no form contents, IP addresses, user agents or individual location records and are therefore retained beyond the deletion of the submissions themselves, for up to two years.
6. Contacting us
If you contact us by email or through a contact form, we process the details you provide (e.g. email address and message) in order to handle your enquiry. The legal basis is Art. 6 (1) (b) GDPR for contract-related enquiries, otherwise Art. 6 (1) (f) GDPR (interest in answering the enquiry). The data is deleted as soon as it is no longer required to achieve that purpose.
7. Cookies and local storage
We use technically necessary mechanisms only. In particular, after you sign in we store authentication tokens in your browser's local storage in order to maintain your session. This storage is required to operate the dashboard; the legal basis is § 25 (2) TDDDG in conjunction with Art. 6 (1) (b) GDPR. We do not use tracking or marketing cookies.
8. Payment processing
If you book paid plans, the data required for processing is transmitted to the respective payment service provider. The legal basis is Art. 6 (1) (b) GDPR. We retain billing-relevant data within the statutory commercial and tax retention periods.
9. Your rights as a data subject
You have the following rights towards us regarding the personal data concerning you:
Right of access (Art. 15 GDPR),
Right to rectification (Art. 16 GDPR),
Right to erasure (Art. 17 GDPR),
Right to restriction of processing (Art. 18 GDPR),
Right to data portability (Art. 20 GDPR),
Right to object to processing (Art. 21 GDPR),
Right to withdraw consent given (Art. 7 (3) GDPR).
An informal message is enough to exercise your rights: kontakt@iontic.de.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement. For iontic GmbH the competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
11. Validity of this privacy policy
This privacy policy is currently valid. As our website develops further, or due to changed statutory or regulatory requirements, it may become necessary to amend this privacy policy.