Controller
The controller responsible for processing personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
- Name or company
- Michele Esposito – Appkaizen
- Address
- Smaragdstraße 18
80995 München
Germany - info@appkaizen.de
Further details are in the legal notice. In this policy, “we” and “us” refer to the controller.
This policy covers the website. The processing of data within the TXNORA service itself, that is via the API, is governed by separate agreements with our customers.
Hosting and server logs
This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel delivers the pages and runs the server-side functions, for example the processing of the contact form.
With every visit, Vercel processes technically necessary connection data, in particular your IP address, the date and time, the requested address and details about your browser and operating system (user agent). This data is kept in logs (server logs) that serve the delivery, stability and security of the website. We do not combine it with other data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable delivery of the website. The logs are deleted automatically according to Vercel’s retention periods. Logs needed to investigate a specific security incident may be kept until it has been resolved.
We have a data processing agreement with Vercel (Art. 28 GDPR).
Transfer to the USA
Vercel is based in the USA, so personal data may be transferred there. According to Vercel, it is certified under the EU-US Data Privacy Framework. The transfer is based on the European Commission’s adequacy decision (Art. 45 GDPR) and, where it does not apply, on the EU standard contractual clauses (Art. 46(2)(c) GDPR). You can request a copy of these safeguards from us. More information is available in Vercel’s privacy policy (opens in a new tab).
Encrypted transmission
This website is delivered exclusively over an encrypted connection (TLS, recognizable by “https://” in your browser’s address bar). Data you send to us, for example through the contact form, cannot be read by third parties in transit.
Fonts
The fonts on this website (Space Grotesk, Inter and JetBrains Mono) are embedded locally and delivered together with the website. No connection is made to servers of Google or other font providers when you visit.
Requests via the contact form
Using the “Request trial access” contact form, you can ask us for trial access to the API, the developer documentation and our pricing. We process the following details:
- Name (required)
- Work email address (required)
- Company (required)
- Role in the company (optional)
- Use case, chosen from a list (required)
- Message (optional)
We also record the page language, the time of the request, the form page and a randomly generated reference number that is not derived from your details. We do not include your IP address or browser identifier in the request.
Purpose
We use these details exclusively to process your request, reply to you and send you trial access, the developer documentation and our pricing. We do not use them for advertising or newsletters.
Email confirmation
After submitting, you receive a confirmation at the address you entered. It contains your first name, the selected use case and the reference number, but not the content of your message. The reference number also appears in the address of the confirmation page and may therefore show up in the server logs.
Legal basis
The legal basis is Art. 6(1)(b) GDPR insofar as your request is aimed at concluding a contract (pre-contractual measures at your request). If you make the request on behalf of a company, we process your business contact details on the basis of Art. 6(1)(f) GDPR; our legitimate interest is answering business inquiries.
Required details
Without the required details we cannot process your request. There is no legal or contractual obligation to provide the data.
Recipients
The request is delivered by email to our mailbox. Our hosting provider, the email delivery service Brevo and our mailbox provider are involved, each as a processor (see Email delivery via Brevo and Email mailbox). We do not pass your details on to any other third parties.
Retention
We delete requests that do not lead to a contract no later than 12 months after our last contact. If a contract is concluded, the statutory retention obligations apply, for example under commercial and tax law.
Please do not send real transaction data
Please do not enter real customer or transaction data in the form. A short description of your plans is enough for a request.
Protecting the form from abuse
To prevent automated abuse of the form, we use measures that work without cookies, without CAPTCHAs and without third-party services:
- Hidden check field: a field that people do not see and only programs fill in. If it is filled in, no request is delivered.
- Signed timestamp: when the form page is loaded, the server adds the time of loading to the form together with a cryptographic signature. On submission we check the signature and whether a plausible amount of time has passed. The timestamp is not linked to you and is not stored on your device.
- Limit per IP address: we accept only a few requests in a short time from one IP address (for IPv6, from the associated /64 network). For this purpose, the address is used in the server’s memory for 15 minutes and then deleted with the next request to the server, at the latest when the server instance shuts down. It is not stored permanently.
- Limit on confirmations: we send only a few confirmations per day to the same email address. To do this, we do not keep the address in plain text but only as a check value formed with a secret key (HMAC) that cannot be reversed. It is used in the server’s memory for 24 hours and then deleted with the next request, at the latest when the server instance shuts down.
- Origin check: we do not accept requests that your browser marks as triggered by another website.
For blocked requests we log only the reason, without IP address, email address or content. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting the form and our mailbox from abuse.
Email delivery via Brevo
We send the emails about your request, that is the notification to our mailbox and the confirmation to you, via Brevo, a service of Brevo GmbH (formerly Sendinblue GmbH), Köpenicker Straße 126, 10179 Berlin, Germany. Brevo processes the content of these emails, in particular the details from the form, on our behalf. We have a data processing agreement with Brevo (Art. 28 GDPR).
The legal basis is the same as for processing your request (Art. 6(1)(b) or (f) GDPR). We use Brevo only for emails about your request, not for newsletters or advertising. Tracking whether emails are opened or links are clicked is switched off for these emails. Brevo keeps delivery logs only for the shortest period that can be set in the account.
According to Brevo, it processes the data in the EU and uses sub-processors, some of which are based in the USA. Transfers there are covered by the adequacy decision on the EU-US Data Privacy Framework or by EU standard contractual clauses. More information is available in Brevo’s privacy policy (opens in a new tab).
Email mailbox and contact by email
Requests from the form and emails you send us directly arrive in our mailbox hosted by SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spain. The provider processes the emails on our behalf (Art. 28 GDPR).
If you email us directly, we process your email address, your name if provided and the content of your message in order to answer your inquiry. The legal basis is Art. 6(1)(b) GDPR if your inquiry relates to a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering inquiries). The same retention period applies as for requests via the form.
No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on this website.
The transaction examples on these pages are fixed example data. When you view, switch or copy the examples, no data is sent to the TXNORA API or to us.
Links to other websites
This policy contains links to websites of other providers, for example to the privacy information of Vercel and Brevo. No data is transferred to these providers when you visit our website. Only when you follow a link do you leave our website; the privacy information of the respective provider then applies.
Your rights
Insofar as we process your personal data, you have the right to:
- access (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing (Art. 21 GDPR)
To exercise these rights, simply contact info@appkaizen.de.
Right to object under Art. 21 GDPR
Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. Here, this concerns the server logs, abuse protection and the handling of business inquiries.
We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, place of work or place of the alleged infringement. The authority responsible for us is: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Status and changes
This policy was last updated in October 2026. We adapt it when the technology of this website, our offering or the legal situation changes. The version published on this page applies.
This English version is a translation for convenience. In case of any discrepancy, the German version prevails.
