Skip to content

Legal

Privacy Policy

1. Controller

IonKon GmbH Dessauer Straße 280 06886 Lutherstadt Wittenberg Germany Email: info@ionkon.de

2. Data protection officer

Tim Konrad IonKon GmbH Dessauer Straße 280 06886 Lutherstadt Wittenberg Germany Email: tim.konrad@ionkon.de Please use this address for any data protection question and to exercise the rights listed in section 15.

3. Hosting and provision of the website

This website is operated on a server provided by STRATO GmbH (Germany); the object storage for uploaded documents is also provided by STRATO GmbH (STRATO HiDrive object storage, data centres in Germany). As part of hosting, technically required data is processed, in particular IP address, date and time of access, requested content, HTTP status code, transferred data volume, referrer and user agent. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the secure, stable and efficient provision of the website). STRATO is involved as a processor pursuant to Art. 28 GDPR. For reach measurement, the web server evaluates its access logs. The originating address is truncated before it is written, to the first 24 bits for IPv4 and the first 32 bits for IPv6; cookie, set-cookie and authorization headers are not logged. The logs are deleted after 30 days. Nothing is stored on or read from your device for this purpose, so consent under Section 25 TDDDG is not required. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in recognising whether and via which pages the website is found).

4. Contact requests

When you use our contact form, we process your name, email address and message text in order to handle and respond to your request. For signed-in customers, the request is linked to the customer account; the name and email address are taken server-side from the authenticated session rather than freely editable form fields. The legal basis is Art. 6 (1) (b) GDPR where the communication is pre-contractual or contractual, and otherwise Art. 6 (1) (f) GDPR (legitimate interest in handling enquiries). Contact requests are deleted no later than 365 days after receipt; messages linked to a customer account are deleted immediately when that account is deleted.

5. Appointment booking and video calls

You can book a call via our booking page (termin.ionkon.de, running the Cal.com software on our own server in Germany). We process your name, company, e-mail address, the chosen time, your time zone and your request to organise and confirm the appointment and to send reminders (Art. 6(1)(b) GDPR). The booking is stored as an appointment linked to your contact in our customer management system (Twenty, also on our own server). The video call takes place on our own conferencing server (meet.ionkon.de, Jitsi Meet software). No account is required; calls are not recorded. When you join, the server processes your IP address and the display name you choose for the duration of the call. No data is passed on to third parties. We delete booking data once it is no longer required for maintaining the contact, at the latest when the retention periods in section 14 expire.

6. Sales, approaching prospects and CRM

We approach companies for which our offering is a plausible fit. In doing so we process business contact details of contact persons: first and last name, role within the company, business telephone number and email address, company name and address, the professional profile on business networks, and notes on the conversation, the requirement and the status of our approach. We do not process private addresses, details of private life or special categories of personal data under Art. 9 GDPR for this purpose. The purpose is winning new business customers, in particular the first approach by telephone and in writing, arranging meetings and maintaining the business relationship. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is direct marketing towards businesses (Recital 47 GDPR). Where a specific enquiry or the conclusion of a contract is at stake, the legal basis is Art. 6 (1) (b) GDPR. This data does not always come from you directly. Sources are publicly available information such as company websites and legal notices, professional networks such as LinkedIn and Xing, business databases, currently Dun & Bradstreet, as well as trade fairs, events and referrals. This information is provided pursuant to Art. 14 (2) (f) GDPR. The data is stored in our own CRM system. It runs on the same server in Germany as this website; no external CRM provider has access. For approaching prospects by telephone and for maintaining the data in the CRM system we have engaged CaBa IT Vertrieb & Beratung, Gärtnerstr. 115, 20253 Hamburg, Germany, as a processor under Art. 28 GDPR. If no business relationship comes about, we delete the contact details no later than 24 months after the last contact. Your right to object to this approach is set out in section 16.

7. Customer account and registration

For a customer account we process your email address, a cryptographic hash of your password, the first and last name of the contact person, company name, address, country and VAT identification number, together with the time your email address was confirmed. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract and pre-contractual steps). At registration we check your VAT identification number against the VAT Information Exchange System (VIES) of the European Commission; only the number itself is transmitted, no further details about you. The legal bases are Art. 6 (1) (b) and (c) GDPR (performance of a contract and VAT record-keeping duties). When you accept our terms and conditions we store the time, the text version and the IP address the acceptance was given from. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in evidencing the acceptance given). We count failed sign-in attempts for a limited period per combination of email address and IP address and delay further attempts. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in protecting accounts). These counters expire automatically after a short time. Contact and order data are additionally held in a customer management system we operate ourselves on the same server; no further provider is involved. You can delete your account at any time from within it. Invoices already issued and the associated order data remain unaffected where statutory retention periods apply (section 12).

8. Orders and order portal

When you order a model, we process the data you provide: company name, company description, use case, optional details about your website and the desired model, your email address, the selected tier and your record of consent (time and text version). Access to your order portal is provided through your customer account; for this we process your email address, a cryptographic hash of your password and a session identifier. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract).

9. Payment processing (BuchhaltungsButler)

Invoicing and payment processing are handled via BuchhaltungsButler. BuchhaltungsButler receives the data required for this (in particular company name, address, VAT ID, email address and invoice amount). We ourselves store payment status and invoice links, but no payment instrument data such as credit card numbers. The legal basis is Art. 6 (1) (b) GDPR.

10. Document upload and model training

Your uploaded documents go as a ZIP file directly into encrypted object storage provided by STRATO GmbH (STRATO HiDrive object storage, Germany); they do not pass through our web servers and are used exclusively to train your model. The substantive processing (preparation, removal of personal data, generation of synthetic training examples, and the training itself) is carried out by our own software on a GPU instance provisioned solely for your order and deleted afterwards, hosted at DataCrunch Oy (cloud brand "Verda", Finland); no external AI provider is used for this. STRATO and Verda are involved as processors pursuant to Art. 28 GDPR. The legal bases are Art. 6 (1) (b) GDPR and your consent pursuant to Art. 6 (1) (a) GDPR, obtained before processing begins, which you can revoke at any time with effect for the future.

11. Email delivery

We send transactional emails via the mail server of STRATO GmbH (Germany) to the address you provide: confirmation of your email address at registration, password reset links, processing status updates, invoices, the activation code once your model is ready, and reminders about the upcoming deletion once the 30-day availability window ends. The legal basis is Art. 6 (1) (b) GDPR.

12. Cookies and local storage

We only use technically necessary storage mechanisms: your language preference, a session cookie once you have signed in to your customer account, and a short-lived cookie while you confirm your email address. We do not use analytics or marketing cookies. The legal bases are Art. 6 (1) (f) GDPR and § 25 (2) TDDDG (strictly necessary functions).

13. Recipients and processors

We only pass on personal data where this is necessary for the purposes set out in this policy. The following act as processors under Art. 28 GDPR: STRATO GmbH, Germany: web server, database, mail server, encrypted object storage for uploaded documents, and the server on which our CRM system runs. DataCrunch Oy under the cloud brand Verda, Finland, and Akenes SA under the brand Exoscale, Switzerland: GPU compute for creating models, one dedicated instance per order which is destroyed afterwards. CaBa IT Vertrieb & Beratung, Germany: approaching prospects by telephone and maintaining data in the CRM system. BuchhaltungsButler GmbH, Germany: invoicing and payment reconciliation; receives master data only and no uploaded documents. All of them process within the European Union or Switzerland. Beyond this we pass on data where we are legally obliged to do so, for example to tax authorities.

14. Retention period

We store personal data only as long as necessary for the stated purposes or as required by statutory retention obligations. Contact requests are deleted no later than 365 days after receipt and earlier when an associated account is deleted. Order and invoice data is subject to commercial and tax retention periods (§ 257 HGB, § 147 AO). Uploaded documents and training data derived from them are deleted no later than 30 days after the finished model is delivered, and if no delivery takes place, no later than 180 days after the order starts (details in the terms and conditions and in the data processing agreement); a local copy the customer has already downloaded is not affected. Contact details of prospects from our sales outreach are deleted no later than 24 months after the last contact; entries on the suppression list under section 16 remain for as long as the objection applies.

15. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR). You may revoke any consent you have given at any time with effect for the future.

16. Objection to direct marketing

You have the right to object at any time to the processing of your personal data for direct marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing. If you object, we will no longer process your data for these purposes (Art. 21 (2) and (3) GDPR). An informal message is sufficient, for example by email to info@ionkon.de or verbally during a telephone call. This incurs no costs for you other than transmission costs at base rates. So that we do not approach you again, we store your name and contact details on a suppression list. This storage serves solely to honour your objection; the data is no longer used for marketing.

17. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is in particular: Landesbeauftragte für den Datenschutz Sachsen-Anhalt Otto-von-Guericke-Straße 34a 39104 Magdeburg Germany

18. Transfers to third countries

Core processing (hosting, data storage, model training) takes place in the EU and Switzerland; the European Commission has established an equivalent level of data protection for both. Transfers to other countries only take place where necessary and where the legal requirements (in particular Art. 44 et seq. GDPR) are met, e.g. through an adequacy decision or appropriate safeguards.

19. Automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

20. Version and updates

Version: 9 September 2026. This privacy policy is updated in the event of legal, technical or organisational changes.

Privacy policy · IonKon