Privacy Policy
1. Controller
Convexio GmbH
Eifflerstraße 43
22769 Hamburg
Email: info@convexio.de
2. Hosting and server log files
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When you access this website, the hosting provider automatically records information in so-called server log files that your browser transmits automatically. This includes:
- IP address of the requesting device
- Date and time of the request
- Name and URL of the retrieved file
- Amount of data transferred
- Message indicating whether the retrieval was successful
- Browser type and browser version
- User operating system
- Referrer URL (the page visited previously)
Processing is based on Article 6 para. 1 lit. f GDPR. Our legitimate interest lies in ensuring stable website operation and defending against attacks. Server log files are deleted automatically after 14 days. This data is not merged with other data sources.
3. Cookies, tracking, and operational telemetry
This website does not use cookies and does not use third-party tracking or analytics tools. We process first-party operational telemetry and server logs in aggregate in order to diagnose errors, understand which pages and browser-local tools are opened, and keep the website reliable. Depending on the source, entries contain the requested or visited path, the normalized page path, language, route type, tool identifier where applicable, timestamp, IP address, user agent, and technical error details. We do not assign visitor IDs, create user profiles, or merge this data with other data sources. Processing is based on Article 6 para. 1 lit. f GDPR. Operational telemetry and server log files are deleted automatically after at most 14 days.
4. Contact by email
If you contact us by email, your details, including the contact data you provide, will be stored by us for the purpose of handling the inquiry and in case of follow-up questions. We do not share this data without your consent. Processing is based on Article 6 para. 1 lit. b GDPR (pre-contractual measures or contract performance) or Article 6 para. 1 lit. f GDPR (legitimate interest in responding to your inquiry).
5. SaaS platform
This privacy policy also applies to the use of our SaaS platform. Two roles must be distinguished:
- For account, contract, communication, and billing data of our customers’ contacts, we are generally the controller.
- For personal data contained in uploaded documents, extractions, exports, and other customer data, we generally process data as a processor for the respective customer.
Within the SaaS platform, we process in particular:
- master data and contact data of users
- authentication and access data
- invoicing and payment information
- uploaded documents and the data contained in them
- extraction, analysis, editing, and export data
- technical logs, security data, and audit data
Processing is carried out for the provision of the platform and contract performance on the basis of Article 6 para. 1 lit. b GDPR, to fulfill statutory retention and documentation obligations on the basis of Article 6 para. 1 lit. c GDPR, and for IT security, abuse prevention, error analysis, and stable product operation on the basis of Article 6 para. 1 lit. f GDPR.
Where we process customer documents and the personal data contained in them on behalf of our customers, this takes place on the basis of Article 28 GDPR in conjunction with the underlying customer contract and any data processing agreement that has been concluded.
6. Payment processing and billing
We use Stripe as our payment service provider for managing payment methods, subscriptions, invoices, and payments. Identification data, invoicing data, payment data, and transaction data may be transmitted to Stripe and processed there for payment processing, fraud prevention, and regulatory obligations.
Only the contract, invoice, payment, and transaction data required for payment processing and billing are transmitted to Stripe. Uploaded documents, extracted content, analysis results, and other domain-specific customer data are not transmitted to Stripe.
Where we use Stripe Elements, sensitive payment data such as credit card numbers or IBANs are entered directly into input fields provided by Stripe and transmitted directly to Stripe. Convexio does not receive or store these complete payment details.
In addition, we process billing-relevant usage data such as selected plans, metering events, invoice status, and payment status where this is necessary for providing the SaaS platform, invoicing, contract performance, and defending or enforcing legal claims.
7. Recipients and storage period
We use technical service providers for hosting, storage, application operation, and security functions as processors or subprocessors. Data is only disclosed to other third parties where this is necessary for contract performance, to fulfill legal obligations, or to enforce legal claims.
We store account, contract, and invoice data for the duration of the contractual relationship and thereafter in accordance with statutory retention obligations. Customer documents and derived content are generally stored for as long as this is required for platform use, traceability, restoration, or contractually agreed retention. Security, audit, and billing logs are retained only as long as necessary for operational, security, or evidentiary requirements.
8. Your rights
You have the following rights with regard to your personal data:
- right of access (Article 15 GDPR)
- right to rectification (Article 16 GDPR)
- right to erasure (Article 17 GDPR)
- right to restriction of processing (Article 18 GDPR)
- right to data portability (Article 20 GDPR)
- right to object (Article 21 GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.
Where we process data on behalf of our customers, requests relating to domain-specific customer data should generally first be addressed to the respective customer as the controller under data protection law.