Legal
Privacy policy
This is a courtesy translation. The German version of this privacy policy is the legally authoritative one.
Last updated: September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Kzyx UG (haftungsbeschränkt)Hauptstraße 50
71543 Wüstenrot, Germany
Represented by: Reinhard Marcel Schatzmann
E-mail: support@kzyx-solutions.com
A data protection officer has not been appointed, as there is no legal obligation to do so.
2. Hosting, server log files and outgoing e-mail
This website is hosted by STRATO GmbH, Berlin (Germany). When you visit the site, the web server automatically processes technical access data (server log files): IP address, date and time of access, requested page, transferred data volume, browser type and version, and operating system.
This processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the website and the prevention of attacks. Log data is deleted after 14 days at the latest, unless a security incident requires longer retention.
Outgoing e-mail runs through STRATO GmbH's servers as well: every message we send you — a confirmation, a download notification — is delivered through their mail servers. STRATO GmbH is therefore a recipient within the meaning of Art. 13(1)(e) GDPR and acts as our processor (see section 9).
3. Contact form and e-mail contact
When you contact us via the contact form or by e-mail, we process the data you provide (name, e-mail address, company if given, subject and message) solely to handle your enquiry.
- Purpose: answering and processing your enquiry, and initiating a contractual relationship where applicable.
- Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in handling general enquiries).
- Retention: enquiries are deleted once they have been fully dealt with and no statutory retention obligations apply — after 12 months at the latest.
- Recipients: data is not shared with third parties; it is stored on our systems and forwarded internally by e-mail.
To protect the contact form against automated spam submissions, we additionally store the sender's IP address and browser identifier (user agent) with each message submitted through the form. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is preventing misuse of the form and warding off spam. This data is deleted together with the enquiry (see retention above).
Submissions are also checked automatically for typical spam patterns. Submissions identified as spam are not stored as a message and are not forwarded by e-mail; to fend off further automated submissions we do however log the IP address and the subject line of the discarded submission, together with a per-day counter. IP addresses that offend repeatedly are temporarily blocked at the server. This log and block data is deleted after 14 days at the latest. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse).
4. Share, download and release links
From our portal we send out links through which you can view or download files: share links to images and videos (/share/…), download links to individual files (/download/…) and release links to software builds (/setup/…). When you open such a link, this is what we process:
- View counter: we count how often the link was opened. To do so, the browser identifier (user agent) of the request is evaluated and assigned to a category (person, messenger preview, search engine, technical tool), so that the automatic preview of a forwarded link is not counted as your having opened it. Only the respective counter is stored — neither the browser identifier itself nor your IP address.
- Time: when a person opens a link or downloads a file from it, we store the time of that last access with the link.
- Download counter: for download links we count the downloads taken so that an agreed download budget can be honoured; automated fetches are counted separately.
- Cookies: if a download or release link is protected by a password, we set a short-lived cookie once it has been entered correctly, which keeps the link unlocked for your browser; when a file is downloaded from either kind of link we additionally set a short-lived cookie so that an interrupted and resumed download is not charged to the budget twice. Both contain nothing but the encrypted identifier of the link and are technically necessary (Section 25(2) TDDDG).
- Notification: when a file is downloaded, the person who created the link may be told by e-mail. That e-mail contains the file name, any note stored with it, the time and the counter — nothing about you.
- Release links: on the page of a software build, the browser identifier of the request is also evaluated in order to show the build matching your operating system first. This happens during the request only; the result is not stored.
Opening such a link is not written to the portal's security log; no IP address or browser identifier of the visitor is stored in the process. Opening a share page does additionally count towards this website's cookieless daily statistic described in section 7; download and release pages are not counted there.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is being able to tell whether a file we provided arrived, and enforcing an agreed download budget. Section 25(2) TDDDG applies to the two cookies in addition. Retention: counters and times belong to the link and exist as long as it does; they are deleted when the link is deleted. An expired or withdrawn link can no longer be opened. The cookies expire by themselves after a short time.
If you receive such a link because you are recorded as the contact for a customer of ours, we process the contact details held in our customer records for that purpose: name, e-mail address and, where given, telephone number and postal address. The legal basis is Art. 6(1)(b) GDPR where the processing serves the performance of the contract with your company, and otherwise Art. 6(1)(f) GDPR; our legitimate interest is running the working relationship with our business partners. We delete this data once the business relationship has ended and no statutory retention obligations apply (§ 257 HGB, § 147 AO).
5. The portal's sign-in page
The portal at kzyx-solutions.com/portal is a company-internal area; no registration is possible there and accounts are created by us only. The sign-in page itself, however, is publicly reachable, and that has one consequence for people without an account: every failed sign-in attempt is logged — with the time, the e-mail address that was entered and the IP address it was made from. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is fending off sign-in attempts by unauthorised people and being able to establish them. These entries are not deleted automatically; they are removed once they are no longer needed for that purpose.
What the portal processes about the people who hold an account there is set out in a separate privacy notice, which those people are given inside the portal.
6. Cookies and local storage
This website only uses technically necessary cookies and local storage:
- a cookie storing your language preference,
- a session cookie protecting forms against cross-site request forgery,
- an authentication cookie for registered portal users (only after login),
- your colour-scheme preference (light/dark) in your browser's localStorage — this information never leaves your browser,
- the two short-lived cookies at a download or release link (see section 4).
The legal basis is Section 25(2) of the German TDDDG in conjunction with Art. 6(1)(f) GDPR. Technically necessary cookies do not require consent, so no cookie banner is used.
7. Pseudonymous audience measurement, no third-party tracking
We do not use advertising services or third-party analytics, and we do not embed content from third-party servers (fonts, scripts, images). All resources are served from our own server.
For audience measurement we operate our own cookieless statistics: when a page is viewed, we store only aggregate counters (calendar day, language, page viewed) and — to count each visitor once per day — a truncated checksum (hash) derived from the IP address and browser identifier together with a secret value and the calendar day. The IP address itself is never stored; the checksum changes daily, so recognition across days is ruled out and the stored data does not allow direct attribution to a person. No cookies are set for this and no information is stored on or read from your device, so no consent is required (Section 25 TDDDG does not apply).
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the statistical analysis of the use of our website. You may object to this processing at any time (Art. 21 GDPR, see section 10).
8. Transport encryption
All content is transferred via TLS (HTTPS). Data you send to us — for example through the contact form — is protected against eavesdropping in transit.
9. Processors
For the processing described on this page we use one service provider, which processes personal data for us on our instructions (Art. 28 GDPR):
- STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany — hosting for this website and the portal, and outgoing e-mail.
There are no other recipients. No transfer to a third country outside the European Union takes place for this processing.
10. Your rights
As a data subject you have the following rights:
- access to the personal data we process about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
To exercise your rights, an informal e-mail to support@kzyx-solutions.com is sufficient.
11. Right to lodge a complaint
You have the right to lodge a complaint about our processing of your personal data with a data protection supervisory authority (Art. 77 GDPR), in particular in the German federal state of your habitual residence or of our registered office. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-WürttembergHeilbronner Straße 35
70191 Stuttgart, Germany
E-mail: poststelle@lfdi.bwl.de