Privacy Policy
This policy explains how Opaix GmbH processes personal data when you visit this website, contact us, request our resources or purchase from our shop, in accordance with the EU General Data Protection Regulation (GDPR).
1. Controller
Opaix GmbH, Grüner Weg 54, 23566 Lübeck, Germany, info@opaix.com, +49 (0) 162 4534410. Full company details are available in our Imprint.
2. Hosting & server logs
Our website is hosted by IONOS SE (Germany). Form submissions and account/content data are processed by our own application backend, operated for us on a server within the European Union. When you access the site or the backend, technically necessary server log data, including your IP address, date and time of access, the resource requested, referrer and user agent, is processed to deliver the service and ensure its security and stability.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in secure, reliable operation). Retention: log data is stored only as long as necessary and then deleted.
3. Web analytics (Umami)
We use Umami, a privacy-friendly, cookieless analytics tool that we host ourselves on our own server in Germany. No data is passed to a third party. Umami sets no cookies, stores no IP addresses and does not track you across devices or websites: it derives an anonymous, daily-rotating identifier from a hash of your IP address and user agent, which cannot be reversed and cannot be linked to you. All measurement is aggregated (page views, referrer, country, device type), so no cookie consent banner is required.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in understanding aggregate website usage). Retention: aggregated statistics only.
4. Contact & enquiries
If you contact us via the contact form or by email, we process the data you provide (e.g. name, email address, message) to handle your request. The message is stored in our application backend so we can respond and follow up.
Legal basis: Art. 6 (1)(b) GDPR (pre-contractual communication) and Art. 6 (1)(f) GDPR (legitimate interest in responding to enquiries).
5. Training requests
When you request a training via our form, we process the details you provide (e.g. name, email, organization, selected training, preferred format and date) to prepare an offer and respond to your request.
Legal basis: Art. 6 (1)(b) GDPR (steps taken at your request prior to entering a contract).
6. Downloads (White Paper & resources)
Some resources, such as our White Paper, are provided after you enter your email address and give your consent. We store your email address and the fact that you requested the resource so we can provide it and, where you agreed, keep you informed about related content. You can object or withdraw your consent at any time.
Legal basis: Art. 6 (1)(a) GDPR (consent).
7. Newsletter (double opt-in)
If you subscribe to our newsletter, we use a double opt-in procedure: we send a confirmation email to the address you provided and only add you to the list once you confirm. We store your email address and consent for this purpose. Every newsletter contains an unsubscribe link, and you can withdraw your consent at any time with future effect.
Legal basis: Art. 6 (1)(a) GDPR (consent).
8. Email delivery (Resend)
To send transactional and newsletter emails (e.g. confirmation and notification messages) we use Resend, Inc. (USA) as a processor acting on our instructions. Where personal data is transferred outside the EU/EEA, it is safeguarded by EU Standard Contractual Clauses.
Legal basis: Art. 6 (1)(b) and (a) GDPR, depending on the email; Art. 28 GDPR (processing on our behalf).
9. Shop & payments (Stripe)
Purchases in our shop are processed via Stripe Payments Europe, Ltd. The data required to complete the payment (e.g. name, contact and payment details) is transmitted to Stripe acting as payment service provider. Stripe's own privacy terms apply in addition.
Legal basis: Art. 6 (1)(b) GDPR (performance of the purchase contract) and Art. 6 (1)(c) GDPR (legal retention obligations, e.g. tax law).
10. Spam protection (Cloudflare Turnstile)
Our forms are protected against automated abuse by Cloudflare Turnstile, a service of Cloudflare, Inc. When you submit a form, your IP address and browser information are transmitted to Cloudflare so it can distinguish human visitors from bots. Turnstile does not use tracking cookies and does not profile you across websites. Processing may take place on servers in the USA; Cloudflare is certified under the EU–US Data Privacy Framework, and EU Standard Contractual Clauses apply in addition.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in protecting our forms from spam and abuse).
11. Recipients & data transfers
We share personal data only with processors who support our operations (e.g. hosting, email, payment) under data processing agreements, and only to the extent necessary. We do not sell or rent your personal data. Where a service involves a transfer outside the EU/EEA, it is safeguarded by appropriate measures such as EU Standard Contractual Clauses.
12. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with future effect. To exercise your rights, contact info@opaix.com.
13. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD).
14. Updates
We may update this policy to reflect changes in our services or legal requirements. The current version always applies.
