Skip to content
Privacy Policy

Privacy Policy

Important Note The German version (datenschutzerklaerung.de.md) is the legally authoritative one; this English version is a convenience translation.

Version 1.0, 15.09.2026

1. Controller and contact

The controller within the meaning of Art. 4 Nr. 7 DSGVO is:

TALDEA GmbH, Tal 44, 80331 Munich, Germany Commercial register: Amtsgericht München, HRB 288991 · Managing Director: Jasenko Dizdarevic VAT ID: DE365854751

For any data protection matter, and to exercise your rights under Art. 15 to 21 DSGVO, contact us at: support@azhdaya.io

We have not appointed a data protection officer. The threshold in § 38 Abs. 1 BDSG is not met, and we do not carry out any core activity within the meaning of Art. 37 Abs. 1 lit. b, c DSGVO.

2. Scope

This policy covers the Azhdaya web console, its landing page and the documentation. It describes the processing for which we are the controller. For the content our customers have processed through the Service we are a processor; see section 9.

3. Website access and server log files

On every request our servers automatically record the data your browser transmits: IP address, date and time, the resource requested, transfer status, volume transferred, referrer, and details of your browser and operating system.

The legal basis is Art. 6 Abs. 1 lit. f DSGVO. Our legitimate interest lies in secure and uninterrupted operation, in detecting and defending against attacks, and in being able to trace faults.

These logs are deleted after 14 days. They are not combined with other data sources for the purpose of building profiles.

4. Cookies

We use strictly necessary cookies only. There is no analytics, no audience measurement and no tracking. For that reason no consent is required: storage is strictly necessary under § 25 Abs. 2 Nr. 2 TDDDG in order to provide the service you have expressly requested.

The cookies used are:

  • azhdaya_session — keeps you signed in. Lifetime matches the session, httpOnly.
  • azhdaya_signup_draft — refers to the package you selected during registration. The selection itself is stored server-side, not in the cookie.
  • azhdaya_signup_email — carries the e-mail address you entered between registration steps.

The legal basis for the associated processing of personal data is Art. 6 Abs. 1 lit. b DSGVO.

5. Registration and user account

To register you we process your name, e-mail address, your password as a hash value, your organisation details and the package selected. In ongoing use this extends to the projects you create, the repository access tokens you store, and records of your activity in the Service.

The legal basis is Art. 6 Abs. 1 lit. b DSGVO; the processing is necessary to perform the contract of use. Without this data no account can be provided.

The data is stored for the term of the contract and deleted after it ends in accordance with section 12.

6. Inviting further users

Where an organisation administrator invites further people, we process their e-mail address to send the invitation and create the account. The legal basis is Art. 6 Abs. 1 lit. b DSGVO in relation to the invited person, and Art. 6 Abs. 1 lit. f DSGVO in the inviting organisation’s interest in managing its team. The inviting organisation is responsible for the lawfulness of passing that address to us.

7. Payment processing

Paid packages are billed through Stripe. The provider is Stripe Payments Europe Ltd., Dublin, Ireland. You enter payment details directly with Stripe; full card data never reaches our systems. We receive the payment status, the invoice data and a customer identifier.

The legal basis is Art. 6 Abs. 1 lit. b DSGVO. Where Stripe transfers data to affiliates in the United States, this is done on the basis of an adequacy decision or standard contractual clauses under Art. 46 Abs. 2 lit. c DSGVO.

Invoice records are retained for ten years under § 147 AO and § 257 HGB.

8. Sending e-mail

For system messages — verification, invitations, account notices — we use the Google Workspace SMTP relay. The provider is Google Ireland Limited, Dublin, Ireland. The recipient address, the subject and the content of the message are transmitted.

The legal basis is Art. 6 Abs. 1 lit. b DSGVO where the message serves performance of the contract, and otherwise Art. 6 Abs. 1 lit. f DSGVO in reliable delivery. Where a transfer to the United States occurs, it is based on an adequacy decision or standard contractual clauses under Art. 46 Abs. 2 lit. c DSGVO.

9. Test runs and artefacts

The actual purpose of the Service is executing our customers’ test suites. The content processed in doing so — repository content, test data, logs, recordings, traces and screenshots — may contain personal data.

In respect of that content we are not the controller but a processor acting for the respective customer. The controller is the customer who submits the test suite. The agreement required by Art. 28 Abs. 3 DSGVO is contained in section 12 of our Terms of Service. Data subjects should address their rights to that customer; requests reaching us are forwarded without undue delay.

10. Hosting

The Service is hosted with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, Amtsgericht Ansbach HRB 6089. The data centres used are located in Germany and Finland and therefore within the European Economic Area.

We operate the database and object storage on that infrastructure ourselves; no further service provider is involved in them.

The legal basis is Art. 6 Abs. 1 lit. f DSGVO in economical and secure operation. A data processing agreement under Art. 28 DSGVO is in place with Hetzner.

11. Fonts

The Roboto Mono typeface is downloaded when the application is built and served from our own server (next/font). No connection to Google servers is made when the page loads, and no IP address is transmitted there.

12. Retention periods

  • Server log files: 14 days (section 3).
  • Account, project and organisation data: for the term of the contract, then deleted within 30 days under section 9.4 of the Terms of Service.
  • Runs and artefacts: according to the retention period of the booked package.
  • Invoice and accounting records: ten years under § 147 Abs. 3 AO, § 257 Abs. 4 HGB.
  • Invitations: until accepted, at most six months.

Beyond that we retain data for as long as statutory retention obligations exist or claims are being asserted, exercised or defended (Art. 17 Abs. 3 lit. e DSGVO).

13. Recipients and processors

RecipientPurposeLocation
Hetzner Online GmbHHosting, compute, storageGermany, Finland
Stripe Payments Europe Ltd.Payment processingIreland, possibly USA
Google Ireland LimitedSending e-mailIreland, possibly USA

Any disclosure beyond this occurs only where you have consented, where we are legally obliged, or where it is necessary to assert, exercise or defend legal claims.

14. Your rights

You have the right of access (Art. 15 DSGVO), rectification (Art. 16 DSGVO), erasure (Art. 17 DSGVO), restriction of processing (Art. 18 DSGVO) and data portability (Art. 20 DSGVO).

You may object under Art. 21 DSGVO to processing we base on Art. 6 Abs. 1 lit. f DSGVO. Any consent given may be withdrawn at any time with effect for the future under Art. 7 Abs. 3 DSGVO.

To do so, contact data.protection@azhdaya.io.

Irrespective of the above, you have the right to lodge a complaint with a supervisory authority (Art. 77 DSGVO). The authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.

15. No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 Abs. 1 DSGVO takes place.

16. Changes to this policy

We update this policy when our processing or the legal position changes. The current version is always available in the console. In the case of material changes we additionally notify registered users by e-mail.