1. Privacy at a Glance 2. Hosting 3. General Information and Mandatory Disclosures 4. Data Collection on This Website 5. Newsletter 6. Appointment Booking 7. Third-Party Websites
1. Privacy at a Glance
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.
Who is responsible?
Data processing is carried out by the website operator. You can find contact details in the "General Information" section.
How do we collect your data?
Your data is collected when you provide it to us (e.g. newsletter registration) or automatically when you visit the website (IP address and time of access).
What do we use your data for?
Some data is collected to ensure the error-free operation of the website. Other data may be used to process your inquiries or to send the newsletter.
2. Hosting
We host our website's content with the following provider:
The provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur. When you visit our website, IONOS collects various log files including your IP addresses. For details, see IONOS's privacy policy: https://www.ionos.de/terms-gtc/terms-privacy
The use of IONOS is based on Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. We have concluded a data processing agreement (DPA) with IONOS.
3. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
We would like to point out that data transmission over the Internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.
Data Controller
Venedy GmbH
Authorized Managing Directors: Lukas Hügle & Armin Skollik
Herzogstraße 105, 80796 Munich
Phone: +49 174 302 8495
Email: info@venedy.io
The data controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of the processing of personal data.
Storage Duration
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a legitimate request for erasure or revoke a consent, your data will be deleted, unless we have other legally permissible reasons for storing it (e.g. retention periods under tax or commercial law).
General Information on the Legal Bases
If you have consented to the processing of data, we process your personal data on the basis of Art. 6(1)(a) GDPR. If you have consented to the storage of cookies, the data processing is additionally based on § 25(1) TDDDG (German Telecommunications and Digital Services Data Protection Act). Consent can be revoked at any time.
If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. The data processing may furthermore be based on our legitimate interest under Art. 6(1)(f) GDPR.
Recipients of Personal Data
In the course of our business activities, we work together with various external parties. We only pass on personal data to external parties if this is necessary in connection with the performance of a contract, if we are legally obliged to do so, if we have a legitimate interest, or if another legal basis permits the disclosure of the data. When using processors, we only pass on personal data on the basis of a valid data processing agreement.
Revocation of Your Consent to Data Processing
Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out up to the revocation remains unaffected by the revocation.
IF THE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA.
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING AT ANY TIME. IF YOU OBJECT, YOUR DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING.
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority. Competent supervisory authority: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.
Right to Data Portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.
Access, Rectification and Erasure
Within the scope of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of the data processing, and, if applicable, a right to rectification or erasure of this data.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your data if:
- You dispute the accuracy of your data (for the duration of the verification)
- The processing is unlawful and you request the restriction instead of erasure
- We no longer need the data, but you need it to assert legal claims
- You have objected (as long as it is not yet clear whose interests prevail)
SSL/TLS Encryption
This site uses SSL or TLS encryption for security reasons. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock symbol in your browser bar.
Automated Decision-Making
Automated decision-making, including profiling, pursuant to Art. 22 GDPR does not take place.
4. Data Collection on This Website
Contact Form
If you send us inquiries via the contact form, your details, including the contact data you provide, will be stored for the purpose of processing the inquiry. We will not pass on this data without your consent.
Legal basis: Art. 6(1)(b) GDPR (initiation of a contract) or Art. 6(1)(f) GDPR (legitimate interest in efficient processing).
Inquiry by Email or Telephone
If you contact us by email or telephone, your inquiry, including all personal data resulting from it, will be stored and processed by us for the purpose of processing it.
Cookies
This website does not set any cookies. The audience measurement described in the following section also works without cookies and stores nothing on your device. It reads exactly one value from your browser: the objection marker that you set yourself using the switch below — and which it must read in order to honour your objection.
There are two exceptions, each of which is triggered exclusively by an active step you take:
- If you start the booking widget by clicking it, the booking application sets technically necessary cookies (see section 6, Appointment Booking).
- If you object to the audience measurement using the switch below, we store an objection marker in your browser. Without this marker, we would be unable to honor your objection on your next page view.
Legal basis in both cases: § 25(2) No. 2 TDDDG (strictly necessary in order to provide the service you have expressly requested). No consent is required for this.
Audience Measurement with Umami (Self-Hosted)
To evaluate the use of this website statistically, we use the open-source software Umami. We host Umami ourselves on our own server in Germany (IONOS SE, Berlin data centre — the same provider that hosts this website, see section 2, Hosting); the measurement endpoint is umami.venedy.io. The measurement data is not passed on to the maker of Umami or to any other third party, and it is not transferred to a third country. The software does not establish any outbound connections; telemetry and update checks are disabled.
Nothing is stored, exactly one value is read. The measurement works without cookies and stores nothing on your device; the session reference exists in memory only. The script reads exactly one value from your browser, the objection marker umami.disabled. It only exists if you have objected using the switch below; reading it is strictly necessary in order to honour that very objection and is therefore permitted without consent under § 25(2) no. 2 TDDDG. Beyond that, the script transmits only information that your browser sends anyway when you load a page:
- the address (URL) you accessed. From its query string we transmit campaign parameters only (
utm_*,gclid,msclkid,fbclid), which tell us which ad or newsletter brought you here. Every other parameter is removed before anything is sent. - the page you visited before (referrer); here too we transmit only the campaign parameters named above from its query string, all others are removed
- the page title and the hostname
The measurement code we serve does not even read screen resolution or language settings from your browser. The measurement therefore neither accesses information on your device nor stores anything there. § 25(1) TDDDG consequently does not apply, and no consent is required for the measurement.
Information derived on the server. From the data that your browser transmits anyway, we additionally derive on our server:
- browser, operating system and device type (from the browser identification, the user agent)
- country, region and city (from the IP address, determined via a local MaxMind database inside our container, without any request to an external service). The IP address itself is never stored; it is evaluated in memory for this lookup only and then discarded. No location is derived beyond city level; no coordinates are collected.
Visitor identifier. In order to attribute page views within a single day to one session, we form an irreversible hash value from the IP address, the browser identification, the website identifier and a secret random value (salt) that changes daily. Your IP address itself is not stored in the analytics database; there is no field for IP addresses there. Because the salt is rotated daily, recognition beyond the same day is impossible.
What does not take place. No session replay, no heatmaps, no profiling, no scoring, no automated decision-making within the meaning of Art. 22 GDPR, no merging of data across device or provider boundaries, and no use for advertising networks.
Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest lies specifically in the statistical evaluation of visitor numbers and page views, the detection of technical errors and dead links, the demand-oriented design of our content, capacity planning, understanding where our audience is located (country, region and city level), and measuring the success of our own campaigns — that is, which ad or newsletter brings visitors to us.
Storage duration. The raw measurement data is deleted automatically after 12 months; the deletion job runs daily.
You can object to the audience measurement at any time with effect for the future. The following switch disables the measurement permanently for this browser. It remains disabled until you re-enable it here.
The objection is implemented by means of a marker in your browser. It therefore applies only to this browser and this device and is lost if you clear your browser data.
Server Log Files
Independently of the audience measurement, the web server writes access logs. They serve IT security and operational stability, not audience measurement.
- Website: When you visit our website, information is automatically collected in server log files, in particular the IP address of the accessing computer as well as the date and time of access. IP addresses are deleted or anonymized after a maximum of 7 days.
- Measurement endpoint (umami.venedy.io): Here, IP addresses are stored in truncated form from the outset; the last octet is set to 0. The retention period is 7 days.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and trouble-free operation of our systems and in defending against attacks).
5. Newsletter
If you sign up for our newsletter, we process your data to send you information about our products and services in the field of API security.
Processed Data
- Email address
- Name (if provided)
- Time of registration and confirmation
- IP address at registration and confirmation (to prove consent)
Double Opt-In Procedure
We use the double opt-in procedure. After you register, you will receive an email with a confirmation link. You will only be added to our mailing list after clicking this link.
Legal Basis
The processing is based on your consent (Art. 6(1)(a) GDPR). You can revoke this consent at any time.
Storage Duration
Your data will be stored until you unsubscribe from the newsletter. We retain the consent records for 6 years.
Unsubscribing
You can unsubscribe from the newsletter at any time. Every newsletter email contains an unsubscribe link. Alternatively, you can also unsubscribe from the newsletter via our unsubscribe page.
6. Appointment Booking
On our website you can schedule a call with us via a booking widget. For this we use a self-operated instance of the open-source scheduling software Cal.com at cal.venedy.io. The software runs on IONOS servers in Germany managed by us (see the Hosting section; a data processing agreement is in place with IONOS).
Connection Only After Click
When you visit our pages, no connection to the booking system is established. The widget only loads once you actively click "Show available times". Only then does the booking application set technically necessary cookies required for selecting an appointment.
Data Processed
- Name and email address
- Selected appointment and time zone
- Optional information from the booking form (e.g. message, company)
Legal Basis
Processing is based on Art. 6(1)(b) GDPR (pre-contractual measures taken at your request). The technically necessary cookies set when the widget loads are covered by § 25(2) No. 2 TDDDG.
Retention Period
We store booking data for as long as necessary to handle the appointment and subsequent communication, at most until the purpose ceases to apply or you object.
7. Third-Party Websites
This website may contain hyperlinks to third-party websites. If you follow such a hyperlink, please note that we cannot accept any responsibility or guarantee for third-party content or privacy policies.
Our website contains links to our company presence on LinkedIn. Information on data processing by LinkedIn can be found in LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy
Contact for Privacy Questions
For questions regarding the collection, processing, or use of your personal data, please contact: info@venedy.io
Last updated: July 2026