Skip to content
  • Roles
  • How it works
  • Security
  • Founder
  • Contact
DEEN
Request early access
  • Roles
  • How it works
  • Security
  • Founder
  • Contact
Request early access
← Back to the home page

Privacy policy

This is a translation; the German version (Datenschutzerklärung) is the binding one.

1. Privacy at a glance

General information

The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on data protection can be found in the privacy policy below.

Data collection on this website

Who is responsible for the data collection on this website?

The data on this website is processed by the website operator. You can find the operator’s contact details in the section “Information on the controller” in this privacy policy.

How do we collect your data?

Some of your data is collected because you provide it to us. This can, for example, be data that you enter in a contact form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system or the time of the page view). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour. If contracts can be concluded or initiated via the website, the data transmitted is also processed for contract offers, orders or other order enquiries.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time about this and any other questions on data protection.

2. Hosting

We host the content of our website with the following provider:

External hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data and other data generated via a website.

External hosting is used for the purpose of fulfilling contracts with our potential and existing customers (Art. 6⁠(1)⁠(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6⁠(1)⁠(f) GDPR). If consent has been requested, processing is carried out exclusively on the basis of Art. 6⁠(1)⁠(a) GDPR and § 25⁠(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

Our host(s) will only process your data to the extent necessary to fulfil their service obligations and will follow our instructions with regard to this data.

We use the following host:

netcup GmbH
Emmy-Noether-Straße 10
76131 Karlsruhe, Germany

Data processing agreement

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General information and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.

Please note that data transmission over the internet (e.g. when communicating by e-mail) can have security gaps. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller responsible for data processing on this website is:

Kai Jansen
c/o Clear-Media UG
Europaring 90
53757 Sankt Augustin, Germany

E-mail: kontakt@fidaryn.com

The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, e-mail addresses or similar).

Storage period

Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be deleted once these reasons cease to apply.

General information on the legal basis for data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6⁠(1)⁠(a) GDPR or Art. 9⁠(2)⁠(a) GDPR if special categories of data under Art. 9⁠(1) GDPR are processed. In the case of express consent to the transfer of personal data to third countries, data processing is also based on Art. 49⁠(1)⁠(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), the data processing is also based on § 25⁠(1) TDDDG. Consent can be withdrawn at any time. If your data is required to fulfil a contract or to carry out pre-contractual measures, we process your data on the basis of Art. 6⁠(1)⁠(b) GDPR. Furthermore, we process your data if this is necessary to fulfil a legal obligation, on the basis of Art. 6⁠(1)⁠(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest under Art. 6⁠(1)⁠(f) GDPR. The relevant legal basis in each individual case is set out in the following paragraphs of this privacy policy.

Recipients of personal data

In the course of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data to external parties if this is necessary to fulfil a contract, if we are legally obliged to do so (e.g. disclosure of data to tax authorities), if we have a legitimate interest under Art. 6⁠(1)⁠(f) GDPR in the disclosure, or if another legal basis permits the disclosure. When using processors, we only pass on our customers’ personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected.

Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)

IF THE DATA PROCESSING IS BASED ON ART. 6⁠(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS ON WHICH A PROCESSING OPERATION IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21⁠(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION UNDER ART. 21⁠(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

Information, correction and deletion

Within the scope of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction or deletion of this data. You can contact us at any time about this and any other questions on personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was or is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have lodged an objection under Art. 21⁠(1) GDPR, your interests and ours must be weighed against each other. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data may, apart from its storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to advertising e-mails

We hereby object to the use of contact data published as part of the legal notice obligation for sending advertising and information material that has not been expressly requested. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited advertising information, for example through spam e-mails.

4. Data collection on this website

Enquiries by e-mail, telephone or fax

If you contact us by e-mail, telephone or fax, your enquiry, including all personal data resulting from it (name, enquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.

This data is processed on the basis of Art. 6⁠(1)⁠(b) GDPR if your enquiry is related to the fulfilment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6⁠(1)⁠(f) GDPR) or on your consent (Art. 6⁠(1)⁠(a) GDPR) if this has been requested; consent can be withdrawn at any time.

The data you send to us via contact requests remains with us until you ask us to delete it, withdraw your consent to storage or the purpose for storing the data no longer applies (e.g. after your request has been processed). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.

Source of sections 1 to 4: eRecht24 (translated)

5. Additional information about this website

No cookies, no tracking

The public pages of this website set no cookies, store nothing on your device, use no analytics or tracking services and load no content from other providers. Fonts, images and scripts are on our own server.

There is one single exception in the non-public investor area: after a successful login it sets one strictly necessary session cookie (section 7). Without a login it sets no cookie either.

No access logs

Our web server processes your IP address and the details of your request only to deliver the page to your browser (Art. 6⁠(1)⁠(f) GDPR). We write no access logs; the IP address is not stored after delivery.

E-mail mailbox

E-mails to us are received and stored by the mail server of netcup GmbH (address in section 2). A data processing agreement with netcup covers this as well.

Founder photo

The photo of the founder shows a real person; the background is generated with AI. The photo is therefore labelled "AI background" directly on the image.

6. Requests and waitlist via our forms

What data we collect

With the forms you can join the waitlist or send a request as a pilot customer, investor or partner. Depending on the form, we collect your e-mail address and, as far as you provide them, your name, company or organisation, industry, company size, the software you use, the topic, the ticket size, your challenge and your message. Required fields are marked.

Confirmation by e-mail (double opt-in)

After sending, you receive an e-mail with a confirmation link. Your request only becomes active once you confirm. We delete unconfirmed details automatically after 48 hours. With the confirmation you receive a link with which you can delete your details or unsubscribe from news at any time.

Proof of your consent

For every consent we store the time, the version and a checksum of the text shown, the language and the time of confirmation and of any withdrawal. We do not store your IP address. To prevent abuse we keep in memory only an irreversible checksum (HMAC) of your IP address, computed with a random key that is itself never stored, and, for the per-address limit, your e-mail address. Neither is ever written to disk, both are lost on a restart, and they are deleted after about 24 hours at the latest (until the next cleanup run).

Legal basis

For the waitlist and news about FIDARYN, the legal basis is your consent (Art. 6⁠(1)⁠(a) GDPR), which you can withdraw at any time. We process requests as a pilot customer, investor or partner to take steps prior to entering into a contract (Art. 6⁠(1)⁠(b) GDPR).

Storage period

  • Unconfirmed details: 48 hours after sending.
  • Waitlist: until you unsubscribe or delete your details, at the latest 6 months after our e-mail announcing the launch of FIDARYN.
  • Requests as a pilot customer, investor or partner: 12 months after the last contact.
  • We keep an anonymous event log without personal data (for example "request confirmed" with a time) for 3 years.

Deletion happens automatically.

Sending the e-mails

We send confirmation e-mails and notifications via the mail server of netcup GmbH (address in section 2), with which a data processing agreement is in place.

7. Investor area

What we process the data for

One part of this website is a non-public area for investors, funds, business angels and advisers who have asked for access. There we show the project status and news. We decide on and grant the access; nobody else can reach the area: its pages are linked nowhere and are not included in search engines. The controller is the same as for the rest of this website (section 3).

What data we store

For every account we store:

  • Your details from the access request: name, e-mail address, organisation and, as far as you provided it, your message.
  • Account data: language, status, the times of request, confirmation, decision, activation and last login, and details on failed attempts, lockouts and warnings.
  • The proof of your consent: type, version and checksum of the text shown, language, and the times of giving and confirming the consent.
  • Your password only as a salted scrypt hash, never in plain text.
  • The acceptance of the confidentiality and disclaimer notice: version, checksum, language and time.
  • Sessions: only the checksum (SHA-256) of the session key, the CSRF secret generated per session, and the times of creation, last use and absolute end.
  • Single-use links (confirmation, decision, set password, reset password): only their checksums and their validity.
  • An event log: time, event, the account id (not your e-mail address), who acted (owner, investor, system) and a reference to the version of a text or to the reason. It contains no IP address, no password and no link.

We do not store an IP address here either. To prevent abuse we only use a short-lived, irreversible checksum of the IP address in memory; it is not written to disk and is lost on a restart. In addition, the abuse brake of the access-request and "forgot password" forms keeps the e-mail address in memory for about 24 hours (until the next cleanup run), likewise without storing it on disk.

Legal bases

We provide the access you asked for as a step prior to entering into a contract at your request (Art. 6⁠(1)⁠(b) GDPR). The proof of your consent documents your consent to the storage and processing of the request itself (Art. 6⁠(1)⁠(a) GDPR). We process security-related records, that is failed logins, lockouts and the event log, on the basis of our legitimate interest in the security of the access (Art. 6⁠(1)⁠(f) GDPR).

The only cookie

After a successful login we set one single cookie: __Host-fid_inv. It holds a random session key; only its checksum is kept on the server. The cookie isHttpOnly, Secure and SameSite=Strict, has the path/, no Domain and no expiry date: it ends when you close the browser, after 30 minutes without a request and at the latest 8 hours after the login. It serves only the login in this area and is not passed on to third parties.

The legal basis is § 25(2) no. 2 TDDDG. The cookie is strictly necessary for the function you asked for, and we set it only after the login. No consent banner is needed for it.

Storage periods

  • Unconfirmed access requests: 48 hours after the request.
  • Confirmed requests we have not decided on: 30 days after the confirmation.
  • Grants that were never taken up (approved, but no password set): 30 days after the decision, unless we sent the invitation again and its link is still valid.
  • Rejected requests: we delete the name, organisation, message and consent records at once with the decision; we keep the e-mail address and the time of the decision until the account is deleted 30 days after the decision.
  • Revoked accounts: 30 days after the decision, the password hash is deleted at once.
  • Active accounts without a login and without a password change: 12 months, after a warning by e-mail 30 days before. If the warning could not be delivered, we retry and delete the account after 12 months anyway once 7 delivery attempts have failed.
  • Event log: 2 years. If you delete your account yourself, only the account id remains of it (never your e-mail address, your name or other personal data), until that entry too is 2 years old.

Recipients

We pass no data to third parties except to our processors: netcup GmbH as the host of the server and as the provider of the mail server (address in section 2). A data processing agreement with netcup is in place. No transfer to third countries is intended.

Your rights and deleting your account

You have the rights set out in section 3: information, correction, deletion, restriction of processing, data portability and objection. On the account page you can delete your account yourself at any time and immediately; this deletes the account data, the consent records, the password hash, the notice acceptances, all sessions and all single-use links. For a request under Art. 15 GDPR we provide you on request with a complete copy of the data stored about you; only the checksums of your password and of the single-use links are left out. Please use the contact details given in section 3.

AI you can trust.

  • Roles
  • Security
  • FAQ
  • Founder
  • Contact
  • Investors
  • Legal notice
  • Privacy

© 2026 FIDARYN · In development: past the idea, not yet ready for market.