Zelviq Quantitative

Privacy Policy

This is a non-binding courtesy translation. The German version is authoritative.

This policy describes the processing as it actually happens and is substantively drafted. It has not yet been reviewed by legal counsel. Before the site goes public, the values marked [OPEN] must be decided and the text as a whole must be reviewed.

1. Controller

The controller for the processing of personal data on this website within the meaning of Art. 4(7) GDPR is:

[FIRMENNAME]
[STRASSE UND HAUSNUMMER]
[PLZ ORT]
Deutschland
Email: [KONTAKT-EMAIL]

A data protection officer has [OPEN: been appointed / not been appointed – the duty to appoint one under Art. 37 GDPR and §38 BDSG must be assessed against the actual headcount and activity].

2. Overview of processing operations

This website gets by with few processing operations. In full, they are:

  • Server log files on every page request (section 3)
  • Country-of-origin check for regionally restricted content (section 5)
  • The details you enter in the contact form (section 6)
  • Notifying the operator of a new enquiry (section 7)
  • IP addresses used to rate-limit the contact form (section 8)
  • A login token in the browser's local storage (section 9)

There is no audience measurement, no user analytics, no profiling for advertising and no embedding of external content. See section 11.

3. Visiting the site: server log files

The web server records every request in log files. This covers the usual connection data: the IP address of the requesting device, date and time, the address requested, the HTTP status code, the volume of data transferred and – where the browser sends them – the referrer and the user agent.

The purpose is technical operation: delivering the page, troubleshooting and defending against abusive access. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in an operational service that is defended against attack.

The server is located in a data centre in Helsinki, Finland, and therefore within the European Union. The infrastructure is operated by Hetzner Online GmbH. A data processing agreement under Art. 28 GDPR is [OPEN: to be concluded with the host, or the existing agreement to be evidenced].

Retention period: 7 days. The log files are rotated daily and deleted after seven days at the latest; deletion is carried out by a fixed server rule (logrotate), not by hand.

4. Cloudflare (planned, not currently active)

For operation under our own domain we plan to put Cloudflare (Cloudflare, Inc., USA) in front of the site as a content delivery network and protection against denial-of-service attacks. As things stand, Cloudflare is not integrated – the website is served without any upstream network.

Once integrated, every request will first pass through Cloudflare servers. Connection data including the IP address will be processed, and a transfer to the USA – a third country – may occur. Cloudflare would act as a processor under Art. 28 GDPR; the legal basis for the integration would be Art. 6(1)(f) GDPR (secure and available operation). The basis for the third-country transfer under Art. 44 et seq. GDPR – standard contractual clauses, an adequacy decision, or both – is [OPEN: to be determined and documented before activation and named specifically here; this policy must then be updated].

5. Country-of-origin check

Some of our content may not be shown in every region for regulatory reasons. To control this, our application evaluates the country code that the upstream network (see section 4) derives from the IP address and passes along as a header. Only that two-letter code is evaluated; it is not stored and does not feed into any analysis. If the code is missing, the content is treated as blocked.

The legal basis is Art. 6(1)(c) GDPR in conjunction with our obligation to observe marketing restrictions, alternatively Art. 6(1)(f) GDPR. As Cloudflare is not currently integrated, this evaluation does not yet happen in practice.

6. Contact form

When you submit the contact form we process exactly what you enter there. We store:

  • your name (truncated to 200 characters)
  • your email address (truncated to 200 characters)
  • your message (up to 4,000 characters)
  • the time the enquiry arrived
  • the time you gave consent, recorded separately

The entries are written to a file on the same server that runs the website (logs/contact_requests.jsonl). Nothing is emailed to third parties. The IP address the enquiry came from is not stored alongside your message – it is only held transiently for rate limiting (section 8).

The form contains an additional field that is invisible to you and serves to catch automated submissions. If it is filled in, we discard the enquiry entirely without storing anything.

The purpose is handling your enquiry. The legal basis is your consent under Art. 6(1)(a) GDPR, which you give via the checkbox in the form and whose timestamp we record so that it can be evidenced under Art. 7(1) GDPR. Where your enquiry aims at entering into or performing a contract, Art. 6(1)(b) GDPR applies in addition.

You may withdraw your consent at any time with effect for the future (Art. 7(3) GDPR); an informal message to the address above is enough. This does not affect the lawfulness of processing carried out until then.

Retention period: 6 months from receipt. Enquiries older than that are removed from the file automatically; the cleanup runs daily on the server. If your enquiry leads to a contract, the statutory commercial and tax retention periods apply to the records that then arise – those records sit outside the file described here.

7. Notifying the operator of a new enquiry

So that enquiries are not left unattended, a form submission triggers a push notification to the operator's devices. Your name and email address are transmitted in it; the text of your message is not.

Delivery technically runs through the push service of the respective browser or device manufacturer. The content of the notification is end-to-end encrypted (web push encryption per RFC 8291); the push service relays it but cannot read it. Connection data nevertheless arises there. The legal basis is Art. 6(1)(f) GDPR – our interest in dealing with enquiries promptly. The data protection classification of the push service and any agreement under Art. 28 GDPR are [OPEN: to be determined depending on the device or browser used].

8. Rate limiting on the contact form

The contact form is the only place where data is written to our server without a login. To prevent abuse we count requests per sender IP address: five requests are possible immediately, after which the allowance refills at one request per minute. Anyone who exhausts the allowance receives an error instead of having data stored.

The IP address needed for this is held in memory only, is not written to any storage medium and is not linked to your enquiry. It is lost when the service restarts, and the number of addresses held is capped. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against automated bulk submissions.

9. Login: token in the browser's local storage

Customers can log in to a dashboard. After a successful login the browser stores a proof of login – a signed token – in local storage (localStorage) under the name apex_token. On every call to our programming interface the website sends this token along so that the interface can tell who is asking and deliver content the account is entitled to see.

The token stays on your device until you log out or clear your browser data. It serves the login alone, contains no identifiers for cross-device recognition and is not evaluated for analytics or advertising.

Technically this is not a cookie but local storage. That makes no difference to the consent question: §25 TDDDG covers any storing of information on your device. We rely on the exception in §25(2) no. 2 TDDDG – without this proof the login you expressly requested cannot be provided. We therefore do not use a consent banner. This classification is [OPEN: to be confirmed by legal counsel].

10. Fonts

The typeface used is served from our own server. No connection is made to Google Fonts or any other font service. Your IP address is therefore not transmitted to Google or any third party. This applies to every page of this site.

11. No analytics, no tracking, no advertising cookies

We use no audience measurement (no Google Analytics, no Matomo, no Plausible or anything comparable), no advertising networks, no visitor recognition and no tracking pixels. No third-party content is embedded – no maps, videos, fonts or scripts from foreign servers. Loading this website therefore establishes no connection to any provider other than our own server.

We set no cookies in the technical sense. The only entry this website leaves on your device is the login token described in section 9 – and only if you log in.

12. Recipients

We do not pass personal data on for marketing purposes. Access is limited to:

  • the operator of the server infrastructure (hosting, see section 3)
  • in future, Cloudflare as the upstream network (section 4)
  • the device manufacturer's push service when notifications are delivered (section 7)
  • public authorities, where we are legally obliged to provide information

No transfer to third countries currently takes place; it would only arise once Cloudflare is integrated (section 4).

13. Retention

We store personal data only for as long as it is necessary for the respective purpose or as long as statutory retention obligations require. Server log files are deleted after 7 days (section 3), contact enquiries after 6 months (section 6). Both periods are enforced automatically. The IP addresses used for rate limiting are not stored permanently (section 8).

14. Your rights

You have the following rights against us:

  • Access (Art. 15 GDPR) – whether and which data we process about you
  • Rectification (Art. 16 GDPR) – correction of inaccurate and completion of incomplete data
  • Erasure (Art. 17 GDPR) – unless a retention obligation prevents it
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) – release in a common, machine-readable format
  • Objection (Art. 21 GDPR) – against processing we base on a legitimate interest; here that is sections 3, 7 and 8
  • Withdrawal of consent (Art. 7(3) GDPR) – at any time with effect for the future

An informal message to [KONTAKT-EMAIL] is sufficient. We respond free of charge and within the time limits of Art. 12(3) GDPR.

15. Right to lodge a complaint with a supervisory authority

Irrespective of the above, you may lodge a complaint with a data protection supervisory authority under Art. 77 GDPR, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us depends on our registered seat and is [OPEN: to be entered with name and address once the company seat is registered].

16. Automated decision-making

Visiting this website involves no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

Our trading service, by contrast, generates trading decisions on a rule-based basis without human intervention in the individual case. Whether this constitutes an automated decision producing a significant effect on customers under Art. 22(1) GDPR, and what safeguards follow from that, is [OPEN: to be assessed by legal counsel and – if applicable – described here together with the right to object and to obtain human intervention]. How the service works is described in our terms and conditions (Terms).

17. Security

This website is served over TLS. Access to the server is restricted to key-based authentication, password login is disabled on the server side, and a firewall limits which services are reachable. Account passwords are stored only as hashes.

18. Changes to this policy

If the processing changes – for instance when Cloudflare is activated – we will amend this policy. The version published here applies. Last updated: [OPEN: enter the date on publication].