Home / Privacy Policy

Privacy Policy

Last updated: June 2026

1. Controller

medairon UG (haftungsbeschränkt)
E-Mail: privacy@medairon.com

2. Data we collect

We process the following categories of data:

Data categoryPurposeLegal basisRetention
E-mail, NameAccount managementArt. 6(1)(b) GDPRUntil account deletion
Password (hashed)AuthenticationArt. 6(1)(b) GDPRUntil account deletion
Payment dataBillingArt. 6(1)(b) GDPR10 years (tax law)
Reach measurement (cookieless)Anonymous reach measurement, website improvementArt. 6(1)(f) GDPR26 months
Consent logProof of the consent decision (Art. 7(1))Art. 6(1)(f) GDPRAppropriate, proof-related period

4. Recipients / Processors

We disclose personal data to the following processors (Art. 28 GDPR). We do not sell personal data to third parties.

  • Supabase Inc. — database, authentication and file storage (including the consent log and our own analytics tables). Processing in an EU region.
  • Stripe Inc. — payment processing (subscriptions, one-time payments, webhooks). Transfer to the USA, see section 5.
  • Resend Inc. — sending of transactional emails. Transfer to the USA, see section 5.
  • Vercel Inc. — hosting, edge/CDN and cron jobs. All HTTP requests pass through Vercel (including IP address, user agent). Transfer to the USA, see section 5.
  • Hosting provider of our self-operated reach measurement (Umami) — operation of the server infrastructure on which the Umami instance and its own dedicated database run. The processor is the hosting provider, not the Umami software.

Note: fonts are served self-hosted at build time; no runtime call is made to Google servers. Google is therefore not a recipient.

5. Transfers to third countries

With the services Stripe, Resend and Vercel, personal data is transferred to the USA (third country).

For each of these US services we base this third-country transfer both on the EU-U.S. Data Privacy Framework (DPF) — to the extent the respective service is certified — and on the EU Standard Contractual Clauses (SCC, Implementing Decision (EU) 2021/914) as an independent basis. We deliberately maintain the SCC as an independent safeguard, because the DPF adequacy decision is currently subject to legal challenge.

6. Retention periods

Account data is retained until account deletion. Billing and payment data is retained for 10 years (tax and commercial-law retention obligation). The anonymous, cookieless reach measurement is deleted after 26 months. The consent log is retained for an appropriate period tied to its evidentiary purpose. Server and security logs are retained short-term.

7. Your rights

You have the right to access, rectify, erase, restrict processing, port your data, and object to processing. To exercise your rights, contact: privacy@medairon.com

8. Cookies & tracking

For audience measurement we use Umami — privacy-friendly analytics software that we operate ourselves (analytics.medairon.com) and that runs on its own dedicated database, separate from our application database. Umami collects audience data cookielessly and without cross-device tracking. We do not use external tracking services such as Google Analytics or Meta Pixel, and we do not sell personal data. The server on which our Umami instance runs is operated by a hosting provider acting as our processor (see section 4). Supplementary first-party analytics tables and the consent log are stored in our Supabase database (EU region).

9. Supervisory authority

You have the right to lodge a complaint with the competent supervisory authority. In Germany, this is the data protection authority of the federal state where we are established.