The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally. Detailed information on data protection can be found in our privacy policy listed below.
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Information on the Data Controller" in this privacy policy.
How do we collect your data?
Your data is collected partly because you provide it to us. This may, for example, include data that you enter into a contact form.
Other data is collected automatically or with your consent when you visit the website by our IT systems. This is mainly technical data (e.g. internet browser, operating system or time of page request). The collection of this data takes place automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected in order to ensure error-free provision of the website and to protect it against abuse.
What rights do you have regarding your data?
You have the right to obtain information free of charge at any time about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
The data controller responsible for the processing of personal data on this website is:
Erseni LtdThe data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
We operate our website on our own servers, hosted by the following infrastructure provider:
Infrastructure provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen
We have full control over the servers and the data stored on them. The infrastructure provider only supplies the hardware and the network connection.
When you visit our website, information is automatically saved on our servers in server log files, which your browser transmits to us.
Details on the infrastructure provider's privacy policy: https://www.hetzner.com/legal/privacy-policy/
A data processing agreement pursuant to Art. 28 GDPR exists with the infrastructure provider.
The use of the server infrastructure is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in a reliable and secure provision of our website.
Our web server automatically saves information in so-called server log files, which your browser automatically transmits to us. These are:
This data is not merged with other data sources.
Server log files are stored for a maximum of 14 days and then automatically deleted, unless a specific security incident requires longer retention.
The collection of this data is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation and optimisation of our website – for this purpose, the server log files must be collected.
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Our website exclusively uses technically necessary cookies (in particular a session cookie and a CSRF protection cookie). These cookies are required for the operation of the website and enable basic functions.
The session cookie is automatically deleted when you close your browser. It is used exclusively to maintain your session and does not contain any personal data.
The storage of this cookie is based on Art. 6 (1) (f) GDPR and § 25 (2) (2) TDDDG. We have a legitimate interest in the technically error-free provision of our website.
You can set your browser to inform you about the setting of cookies or to generally reject cookies. If cookies are disabled, the functionality of this website may be limited.
When you share or request a secret via this service, our server only processes encrypted data. The key required for decryption is transmitted exclusively in the URL fragment (the part after the #) and never sent to our server. For this reason, we are technically unable to read the contents of your secret (zero-knowledge architecture).
No analytics, no advertising cookies, no tracking pixels. Server logs are used only for security and operation.
We process the following data:
Encrypted content is irreversibly and atomically deleted from our database when it is retrieved for the first time (hard delete). If a secret is not retrieved, we delete it at the latest after the validity period you have chosen (by default, a maximum of 7 days). Status metadata (no ciphertext, only the timestamps of creation, expiry and, where applicable, retrieval) is retained for up to 24 hours after expiry so that the status of a secret remains verifiable; after that, this metadata is also deleted.
The legal basis for the processing is Art. 6 (1) (f) GDPR. Our legitimate interest lies in providing the secret exchange in a privacy-preserving zero-knowledge form.
Because we deliberately do not maintain any user account and the stored ciphertext has no personal reference, rights to information, rectification and erasure cannot be exercised in practice – we cannot attribute secrets to an individual user. You can irreversibly delete your own secret at any time by retrieving it yourself via the recipient link (hard delete on first read).
We contact companies and organisations by email as part of business-to-business direct marketing and process business contact details obtained from publicly accessible sources for that purpose. In addition, we maintain a suppression list in which we record objections to such outreach so that we can honour them permanently and across all channels.
We process the following data for this purpose:
The sole purpose of processing data in the suppression list is to honour your objection under Art. 21 (3) GDPR, that is to ensure that you receive no further direct marketing from us. The data held in the suppression list is not used for any other purpose, in particular not for advertising, profiling or analytics.
The legal basis for maintaining the suppression list is Art. 6 (1) (c) GDPR in conjunction with Art. 21 (3) GDPR, that is our legal obligation to honour the objection. The legal basis for the direct outreach itself is Art. 6 (1) (f) GDPR; our legitimate interest lies in direct marketing addressed to business contacts.
Entries in the suppression list are stored indefinitely and exclusively for the purpose of permanently not contacting the address or domain concerned again. Deleting an entry would remove the effect of the objection and make renewed contact possible; indefinite storage is therefore the less intrusive option for you compared with erasure.
You may object to the processing of your address for direct marketing purposes at any time, informally by email to the address stated in the imprint or via the unsubscribe link contained in every message we send. After your objection, we process your address only within the suppression list. At your express request we will also delete the suppression list entry; in that case we can no longer technically rule out renewed contact.
You have the right to obtain information free of charge at any time about the personal data stored about you, its origin and recipients, and the purpose of the data processing (Art. 15 GDPR).
You have the right to request the correction of inaccurate personal data (Art. 16 GDPR).
You have the right under certain circumstances to request the restriction of the processing of your personal data (Art. 18 GDPR).
You have the right to request the deletion of your personal data, unless statutory retention obligations conflict with this (Art. 17 GDPR).
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format (Art. 20 GDPR).
You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 (1) (e) or (f) GDPR. You may also object at any time, without giving reasons, to the processing of your data for direct marketing purposes (Art. 21 GDPR).
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).
In our case (registered office in the Republic of Cyprus), the competent supervisory authority is:
Office of the Commissioner for Personal Data Protection
Iasonos 1, 1082 Nicosia, Cyprus
www.dataprotection.gov.cy
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place on this website.