Privacy policy
This is a courtesy translation. The legally binding version is the German one:Datenschutzerklärung.
This policy covers the website (idahub.de) as well as registration and the contractual relationship. The processing of data that customers put inside IDA is carried out on the customer instruction and is governed by the data processing agreement.
1. Controller
S³ IT GmbHHeinrich-Hertz-Str. 28, 41516 Grevenbroich, Germany
Email: info@idahub.de
Phone: +49 2182 81514-0
2. Access data / server log files
When you visit our website, information transmitted by your browser is automatically stored in server log files - in particular the IP address and the requesting provider, the date and time of access and the page requested. This processing serves the secure and stable operation of the website (Article 6(1)(f) GDPR).
3. Web analytics with Matomo
We use Matomo for anonymised analysis of website use. Your IP address is anonymised before storage, so the data cannot be attributed to a specific person. The legal basis is Article 6(1)(f) GDPR. Where the specific configuration requires consent, processing takes place on the basis of Article 6(1)(a) GDPR; consent can be withdrawn at any time.
4. Contacting us
If you contact us by email or through a form, we process the details you provide in order to handle your enquiry (Article 6(1)(b) or (f) GDPR).
5. Registration, trial and contractual relationship
To set up a trial (30 days) and a customer account we process the data provided - in particular name, email address, company and credentials - and subsequently the data required to perform the contract. The legal basis is the performance of pre-contractual measures and of the contract (Article 6(1)(b) GDPR). To secure operation and prevent abuse, usage and log data may be processed (Article 6(1)(f) GDPR). When a trial is requested we store the IP address of the request for that purpose, in order to detect and prevent repeated or automated registrations. The registration form is additionally protected against automated requests by a proof-of-work puzzle solved in the browser; no cookies are set and no data is transmitted to third parties.
6. Payment processing
To bill paid contracts we process the billing address, the VAT identification number and - for SEPA direct debit - the account holder, IBAN and evidence of the mandate granted (time, name and IP address at the time of granting). The legal basis is performance of the contract (Article 6(1)(b) GDPR). Bank details are held exclusively in our billing system; for collection they are transmitted to our bank. This data is retained within the periods required by commercial and tax law.
7. Processing of data inside IDA (processing on instruction)
Where customers put personal data into IDA, or have it imported or retrieved through systems they connect (directory, inventory, monitoring, telephony, email or supplier systems, for instance), we process that data exclusively on behalf of and on the instruction of the respective customer, as a processor. The basis is the data processing agreement under Article 28 GDPR. The controller for that data is the customer.
8. Recipients and processors
Personal data is only passed on where this is necessary to perform the contract or another legal basis exists. Processors we use (hosting providers in Germany, for instance) are bound contractually under Article 28 GDPR. Transfers to third countries only take place where the statutory requirements are met.
Systems the customer operates themselves and connects to IDA are not processors engaged by us. Retrieving data from those systems and transmitting data to them happens on the customer instruction; the customer is responsible for the data protection admissibility and for any agreements required with the respective provider.
9. Retention
We store personal data only for as long as it is necessary for the purposes stated or as long as statutory retention obligations exist. Data from trial tenants is deleted at the latest 14 days after the trial ends, unless a paid contract is concluded. After the contract ends, or in the event of persistent non-payment, access is blocked; the data is deleted from the production systems after a period of 14 days. Restoration from backup copies is possible only in individual cases, against costs and without warranty; once the retention period of the backup copies has expired it is impossible. Statutory retention obligations remain unaffected.
10. SSL/TLS encryption
For security reasons this website and the service use SSL/TLS encryption.
11. Your rights
Within the statutory framework you have the right at any time to:
- information about the data stored about you (Article 15 GDPR)
- rectification of inaccurate data (Article 16 GDPR)
- erasure (Article 17 GDPR)
- restriction of processing (Article 18 GDPR)
- data portability (Article 20 GDPR)
- object to processing (Article 21 GDPR)
- withdraw consent given, with effect for the future
You also have the right to lodge a complaint with a data protection supervisory authority. To exercise your rights, a message to the contact details above is sufficient.
