Legal Information

Privacy Policy

1 Privacy at a Glance

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Who is responsible?

Data processing is carried out by the website operator. You can find contact details in the "General Information" section.

How do we collect your data?

Your data is collected when you provide it to us (e.g., newsletter registration) or automatically when visiting the website (IP address and time of access).

What do we use your data for?

Some data is collected to ensure error-free provision of the website. Other data may be used to process your inquiries or send newsletters.

2 Hosting

We host our website content with the following provider:

IONOS

The provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When you visit our website, IONOS collects various log files including your IP addresses. For details, please refer to IONOS's privacy policy: https://www.ionos.de/terms-gtc/terms-privacy

The use of IONOS is based on Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. We have concluded a data processing agreement (DPA) with IONOS.

3 General Information and Mandatory Information

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

Please note that data transmission over the Internet (e.g., when communicating via email) may have security gaps. Complete protection of data against access by third parties is not possible.

Data Controller

Venedy GbR

Authorized representatives: Lukas Hügle & Armin Skollik

Herzogstraße 105, 80796 Munich, Germany

Phone: +49 174 302 8495

Email: info@venedy.io

The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.

Storage Duration

Unless a more specific storage period has been stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate deletion request or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing it (e.g., tax or commercial law retention periods).

General Information on Legal Basis

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. If you have consented to the storage of cookies, data processing is additionally based on § 25(1) TDDDG (German Telecommunications-Telemedia Data Protection Act). Consent can be revoked at any time.

If your data is required for contract performance or pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Data processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR.

Recipients of Personal Data

In the course of our business activities, we work with various external parties. We only transfer personal data to external parties if this is necessary for contract performance, if we are legally obligated to do so, if we have a legitimate interest, or if another legal basis permits data transfer. When using data processors, we only transfer personal data on the basis of a valid data processing agreement.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The legality of data processing carried out before the revocation remains unaffected by the revocation.

Right to Object to Data Collection (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION.

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING AT ANY TIME. IF YOU OBJECT, YOUR DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES.

Right to Lodge a Complaint with the Supervisory Authority

In the event of violations of the GDPR, data subjects have a right to lodge a complaint with a supervisory authority. Competent supervisory authority: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.

Information, Rectification and Erasure

Within the framework of applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing, and if applicable, a right to rectification or erasure of this data.

Right to Restriction of Processing

You have the right to request restriction of the processing of your data if:

  • You dispute the accuracy of your data (for the duration of verification)
  • The processing is unlawful and you request restriction instead of erasure
  • We no longer need the data, but you need it for legal claims
  • You have objected (pending determination of whose interests prevail)

SSL/TLS Encryption

This site uses SSL/TLS encryption for security reasons. An encrypted connection is indicated when the browser address bar changes from "http://" to "https://" and by the lock symbol in your browser bar.

Automated Decision-Making

Automated decision-making including profiling pursuant to Art. 22 GDPR does not take place.

4 Data Collection on this Website

Server Log Files

When visiting our website, information is automatically collected in server log files:

  • IP address of the accessing computer
  • Date and time of access

This data is collected to ensure trouble-free operation and to defend against attacks. IP addresses are deleted or anonymized after a maximum of 7 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security).

Contact Form

If you send us inquiries via the contact form, your information including contact details will be stored for the purpose of processing your inquiry. We will not share this data without your consent.

Legal basis: Art. 6(1)(b) GDPR (contract initiation) or Art. 6(1)(f) GDPR (legitimate interest in effective processing).

Inquiry via Email or Phone

If you contact us by email or phone, your inquiry including all resulting personal data will be stored and processed by us for the purpose of processing your request.

Cookies

No Tracking Cookies

This website does not use tracking cookies or analytics tools like Google Analytics. We only use technically necessary cookies where required.

Legal basis: Art. 6(1)(f) GDPR and § 25(2) No. 2 TDDDG (no consent required for technically necessary cookies).

5 Newsletter

If you subscribe to our newsletter, we process your data to send information about our products and services in the field of API security.

Processed Data

  • Email address
  • Name (if provided)
  • Time of registration and confirmation
  • IP address at registration and confirmation (to prove consent)

Double Opt-In Procedure

We use the double opt-in procedure. After registration, you will receive an email with a confirmation link. Only after clicking this link will you be added to our mailing list. This ensures that only you can register with your email address.

Legal Basis

Processing is based on your consent (Art. 6(1)(a) GDPR). You can revoke this consent at any time by using the unsubscribe link in each newsletter or by contacting us directly.

Storage Duration

Your data will be stored until you unsubscribe from the newsletter. We retain consent records (time, IP address) for 6 years to be able to prove our lawful processing.

Unsubscribe

You can unsubscribe from the newsletter at any time. Every newsletter email contains an unsubscribe link. Alternatively, you can also unsubscribe via our unsubscribe page.

Use of Google Gmail API

For the technical delivery of our newsletter, we use the Gmail API from Google Cloud.

Provider: Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland (for customers with billing address in EMEA). Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Data Processing Agreement: We have a data processing agreement (Cloud Data Processing Addendum) with Google pursuant to Art. 28 GDPR. Google processes data exclusively according to our instructions.

Third Country Transfer: When using Google services, data may be transferred to the USA. The USA has an adequacy decision from the EU Commission (EU-US Data Privacy Framework). Google LLC is certified under the Data Privacy Framework. Additionally, we have agreed to EU Standard Contractual Clauses (SCCs) with Google.

Security Measures: Google is ISO 27001, ISO 27017, and ISO 27018 certified and maintains SOC 2 and SOC 3 reports.

More information: Google Privacy Policy | Sub-processors | Data Privacy Framework

6 Third-Party Websites

This website may contain hyperlinks to third-party websites. If you follow such a hyperlink, please note that we cannot accept any responsibility or guarantee for external content or privacy policies. Please verify the applicable privacy policies before transmitting personal data to these websites.

LinkedIn

Our website contains links to our company presence on LinkedIn. When you click on these links, you will be redirected to the LinkedIn platform. Data such as your IP address will be transmitted to LinkedIn. Information about data processing by LinkedIn can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy

Contact for Privacy Questions

For questions regarding the collection, processing, or use of your personal data, for information, rectification, restriction, or deletion of data, as well as revocation of consent or objection to specific data use, please contact:

info@venedy.io

Last updated: January 2026