Privacy Policy

This Privacy Policy explains how personal data is processed when you use the Eigenverft website and related services.

This policy describes how we process personal data when you visit or use this website. It applies to website content, technical operation (including security and stability), and features that may be available such as accounts and personalized services.

When you access this website, technical data is processed (server logs) to deliver the website, ensure security and stability, and troubleshoot issues.

Data categories

  • IP address
  • Date and time of request
  • Requested URL / page
  • HTTP status code
  • Referrer (if sent by your browser)
  • User agent (browser/device information)

Details

  • Purpose: Providing and operating the website and services; ensuring security, stability, troubleshooting; preventing abuse and attacks.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interests: secure and reliable operation of the service; prevention and investigation of misuse).
  • Retention: 90 days (rolling log retention), unless a longer retention is required to investigate security incidents or meet legal obligations.
  • Recipients / processors: STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (hosting provider).

If additional processors are used (e.g., email delivery, CDN, analytics), they will be listed in this policy and/or on the relevant feature page.

Some features allow you to enter or paste information (for example text to format, validate, or transform). We process such input only to provide the requested output and to operate the service securely.

  • Data categories: user-provided text/content; technical metadata required to handle the request (e.g., timestamps, technical identifiers).
  • Purpose: providing the requested feature output; troubleshooting; preventing misuse and attacks.
  • Legal basis: Art. 6(1)(b) GDPR (providing the requested service) and, where applicable, Art. 6(1)(f) GDPR (security and abuse prevention).
  • Retention: inputs are processed transiently and are not stored as a feature by default. Technical logs are handled as described in “Website access & server logs”.

Cookies may be used to operate and secure the website and to provide requested features. We differentiate between Required, Recommended, and Optional cookie categories. Required cookies are needed for core functionality and security and are set regardless of your preference because the service would not work properly without them. Recommended cookies improve the user experience (for example remembering certain UI settings). They may be suggested in the Privacy settings, but they are only stored and used after you confirm your choice (for example by clicking Save settings or selecting Accept all). Optional cookies (for example analytics or marketing) are only used after you provide consent and can be withdrawn at any time via the Privacy settings.

Your cookie preference is stored in a first-party cookie so we can remember your choice. If you reject non-essential categories, the website prevents setting non-essential cookies where technically possible and may delete existing non-essential cookies. Some cookies appear only during specific authentication flows (e.g., external sign-in, 2FA, or “Remember me”) and may not be present in every session.

Note: In some environments (for example corporate networks with security gateways or TLS inspection), additional cookies may be inserted by network infrastructure or client-side security software. Such cookies are not set by Eigenverft and are outside our control.

Cookie / Key Purpose Category Type Lifetime Status
evf_consent_prefs Stores your cookie category preferences (required/recommended/optional) so we can remember your selection. Required First-party Persistent (configured by the application; may change over time). Active
evf_consent Technical consent marker used by the website to determine whether optional non-essential cookies may be set. (May be absent if optional categories are rejected.) Required First-party Persistent (configured by the application; may change over time). Active
evf_affinity Routing session affinity (routes requests consistently to the same backend instance, if enabled). Required First-party Persistent (configured by routing/hosting; may change over time). Active
evf_xsrf CSRF protection for forms (anti-forgery). Required First-party Session or short-lived (depending on the feature and browser settings). Active
evf_auth Authentication session cookie (used when accounts/login are enabled and you sign in). Required First-party Session or persistent (depending on sign-in settings such as “Remember me”). Active (only when signed in)
evf_external Temporary cookie used during external sign-in flows (only if external login providers are enabled). Required First-party Short-lived (until sign-in flow completes). Active (only during external sign-in)
evf_2fa_uid Temporary cookie used during two-factor authentication (2FA) sign-in flows (only if 2FA is used). Required First-party Short-lived (until sign-in flow completes). Active (only during 2FA)
evf_2fa_rm Cookie used for “Remember me” / persistent sign-in (only if you choose a persistent login and sign-in is enabled). Required First-party Persistent (until expiry, logout, or manual deletion; duration depends on your sign-in settings). Active (only if enabled)
Recommended cookies (e.g., UI preferences) may be introduced in the future. They improve usability and may be shown as recommended in the Privacy settings (for example highlighted). They are only stored and used after you confirm your choice (for example by clicking Save settings or selecting Accept all). Recommended First-party Depends on the feature. Not active currently
Optional analytics cookies (e.g., for aggregated usage measurement) may be introduced in the future and will only be used after consent. Optional First-party / third-party (depends on provider) Depends on the provider. Not active currently
Optional marketing cookies (e.g., advertising or cross-site tracking) may be introduced in the future and will only be used after consent. Optional First-party / third-party (depends on provider) Depends on the provider. Not active currently

Legal basis: Required cookies are used to provide requested technical functions and to operate the website securely (Art. 6(1)(f) GDPR; and where applicable Art. 6(1)(b) GDPR for providing requested services such as account login). Recommended cookies (when present) are used based on your choice in the Privacy settings (and where applicable device access/storage under § 25(1) TDDDG and processing under Art. 6(1)(a) GDPR, depending on the specific feature). Optional cookies (when enabled) are used based on your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can change or withdraw your consent at any time via the Privacy settings.

If accounts are available, we process personal data to create and manage your account, authenticate you, and provide personalized services and user-specific settings.

Data categories

  • Account identifier (e.g., username)
  • Email address
  • Password hash and authentication data
  • Account settings and preferences
  • Login/security metadata required to operate and secure the service

Details

  • Purpose: Account creation and login; providing requested personalized services; security and abuse prevention.
  • Legal basis: Art. 6(1)(b) GDPR (providing requested services / account functionality) and Art. 6(1)(f) GDPR (security of the service).
  • Storage principle: Account data is kept for as long as your account exists and is needed to provide the service; after deletion we remove or anonymize data unless legal obligations require retention.

If optional profile fields or additional account features are introduced, this policy will be updated accordingly.

We plan to use Google Analytics (GA4) to understand how visitors use our website and to improve our services. We also use aggregated insights to evaluate marketing performance and optimize content and features. Google Analytics will only be enabled after you provide consent.

Provider

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland

Typical data categories

  • Online identifiers (e.g., cookie identifiers)
  • Device and browser information
  • Pages visited and usage events
  • Approximate location/region (derived)
  • IP address (processed as part of providing the service)

  • Status: Planned / not active yet
  • Purpose: Measuring website usage; improving product and user experience; troubleshooting; evaluating marketing performance.
  • Legal basis (when enabled): Consent — device access/storage under § 25(1) TDDDG and processing under Art. 6(1)(a) GDPR.
  • Property (planned): GA4 (Measurement ID will be added when enabled).
  • International transfers: Depending on configuration, data may be processed outside the EU/EEA. Where required, appropriate safeguards (e.g., EU Standard Contractual Clauses) will be used.
  • Opt-out / withdrawal: You can withdraw consent at any time via the Privacy settings (once enabled).

Your rights

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent at any time (Art. 7(3) GDPR), where processing is based on consent

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

We may update this policy to reflect changes in services, legal requirements, or technical setup.

For all privacy-related requests, please contact the controller:

Carsten Riedel
Hansering 68
31141 Hildesheim
Germany

Contact: eigenverft [at] outlook [dot] com

Last updated: 2026-01-03

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.