Privacy Notice
Version:
This Privacy Notice explains how personal data is processed when you visit Veviad's statically hosted website or submit a contact, demo or trial request.
Data Controller
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Veviad®
Karl-Theodor-Straße 74
D-80803 Munich, Germany
represented by: Shawn Maholick (Managing Director)
Phone: +49 (0)89 24581980
Privacy Contact
If you have questions about the processing of your personal data, contact us at privacy@veviad.com.
Static Delivery Through Cloudflare
The website is delivered as a static website through Cloudflare Workers Static Assets and the global network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you connect, Cloudflare processes technically necessary traffic and access data. This may include your IP address, date and time, requested URL, referrer address, browser and device information, transferred data volume, HTTP status, and information used for traffic routing and abuse prevention.
This processing enables the secure, fast and stable delivery of the website, troubleshooting and protection against attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, error-free and economical operation of the website. Our separate, self-hosted audience analytics with Umami is described below.
Local Language Preference
When you select a language, that preference may be stored locally in your browser so the website can be shown in your chosen language on a later visit. The preference remains on your device and is not sent to Veviad. You can delete it in your browser settings or replace it by selecting another language.
This local storage is necessary to provide the language feature you expressly request (section 25(2)(2) TDDDG). To the extent personal data is processed, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a consistent, user-friendly presentation.
Consent Management With CCM19
We use the cloud-based CCM19 consent manager provided by Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, Germany. CCM19 presents the choices for services requiring consent, prevents their activation before consent, stores your choice and records it so that we can operate the website in accordance with your decision and demonstrate any consent given. According to the provider, cloud processing takes place on servers in Germany.
The data processed may include a unique consent ID, timestamps, selected purposes and services, the language and version of the consent dialog, and technical request data. The IP address may be processed in technical server logs; according to CCM19, it is deleted from those logs after no more than 24 hours.
Storing your choice in the browser's local storage is necessary so that the website can respect your decision (section 25(2)(2) TDDDG). Processing to meet and demonstrate our consent obligations is based on Art. 6(1)(c) in conjunction with Art. 7(1) GDPR. We additionally rely on Art. 6(1)(f) GDPR for secure and reliable technical administration. Our legitimate interest is the demonstrable, privacy-compliant operation of the website.
You can reopen and change your choice or withdraw consent with effect for the future at any time through the “Privacy Settings” link in the footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Attribution Data During the Browser Session
The referrer and allowlisted UTM parameters from the requested URL may describe the current request context. Only if you have consented to the “Analytics” category in CCM19 may these details be kept temporarily in your browser's session storage so that the context is preserved while you navigate the website. Without that consent, we do not write attribution details to session storage. The local session copy is discarded no later than the end of the browser session.
If you submit a form, currently available attribution details may be sent to Veviad together with the language, page path and submission time, independently of any cross-page session storage. They help us understand the context of your request and the effectiveness of our own campaigns. Section 25(1) TDDDG applies to storing and reading the data in session storage, and the associated processing is based on your consent under Art. 6(1)(a) GDPR. Transmitting and evaluating the details together with your request is based on Art. 6(1)(b) GDPR and, additionally, Art. 6(1)(f) GDPR. Our legitimate interest is the traceable handling and attribution of incoming requests.
Contact, Demo and Trial Requests
When you submit a form, we process the information you enter. This includes your first and last name, business email address, company or organisation, country, request type and message or use case and, where provided, your telephone number, industry, organisation size and package of interest. We also process the recorded consents, the displayed document versions, technical request metadata and the attribution details described above.
The information is transmitted over an encrypted connection to the Veviad Admin request interface and stored in Veviad's internally operated request and customer management system based on Directus. We use it to answer your request, arrange a demo, discuss pricing or possible applications, qualify the request and organise subsequent communication in a traceable manner. The legal basis is Art. 6(1)(b) GDPR for pre-contractual steps and, additionally, Art. 6(1)(f) GDPR for efficient, secure and traceable processing.
For a trial request, a pending request is created first. Before any environment is provided, you confirm your email address; the request may then be assessed using the information you supplied and assigned for manual review. A trial environment can only be provided after successful assessment. Processing for the provision, operation and termination of the trial is based on Art. 6(1)(b) GDPR.
Any consent to receive product and offer information is collected separately and is voluntary. The legal basis is Art. 6(1)(a) GDPR. You may withdraw this consent at any time with effect for the future. Alternatively, you can contact us by email; the email service providers involved then process the content you send.
Cloudflare Turnstile
We use Cloudflare Turnstile to protect the forms against automated submissions and abuse. When the form section is loaded, code is retrieved from challenges.cloudflare.com. Cloudflare may process, in particular, the IP address, browser and operating-system information, user agent, time, hostname and technical browser and device signals and may generate short-lived identifiers. The proof generated by Turnstile is verified server-side with Cloudflare and is not stored as request data in the CRM.
The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is protecting the forms and downstream systems against spam, bots and misuse. To the extent information is stored on or read from your device, this is necessary to provide the form function you expressly request in a protected manner (section 25(2)(2) TDDDG). Further information is available in Cloudflare's Turnstile Privacy Addendum.
Self-Hosted Audience Analytics With Umami
We self-host Umami at analytics.cloud.veviad.com. Umami helps us understand aggregate website reach, campaign attribution and conversions. The Umami script is loaded and analytics begins only after you have consented to the “Analytics” category in CCM19. Analytics data is processed in the Umami instance operated by Veviad; the Umami software provider does not receive access to this data merely because we use its self-hosted software.
The data processed may include the sanitised page URL or path, page title and sanitised referrer; only the allowlisted campaign parameters utm_source, utm_medium, utm_campaign, utm_term and utm_content; and browser, operating system, device type, screen size and language. The IP address may be used to derive a coarse geographic location. It necessarily reaches our analytics server and is processed transiently to handle the request, derive the coarse location and generate a pseudonymous session identifier, but is not stored as an IP address in the Umami analytics dataset.
Umami is used without analytics or marketing cookies, visitor accounts and without sending form fields or other contact details deliberately entered by you. The session storage described in the attribution section is used only after you have consented to analytics. We do not use Umami for session replay, heatmaps, personal profiles or advertising. Veviad does not intentionally copy free text, email addresses, names or other form content into event names, event data or campaign parameters. Incoming UTM values are limited to short technical campaign codes. An automatic filter discards values containing spaces, disallowed characters or phone-like digit sequences, but cannot reliably detect every form of personal data. Campaign links must therefore not contain personal data in UTM parameters.
Section 25(1) TDDDG applies to storing or reading information on your device. The legal basis for processing personal analytics data is your consent under Art. 6(1)(a) GDPR. Consent is voluntary, and you can use the website without analytics. You can withdraw your consent with effect for the future at any time through the “Privacy Settings” link in the footer.
We additionally honour your browser's Do Not Track signal; when it is enabled, no Umami analytics events are sent. This additional technical signal does not replace making or withdrawing your choice through the privacy settings.
Recipients of Personal Data
Within Veviad, access is limited to the people responsible for sales, demos, customer support, trial assessment and technical operations, to the extent required for the particular request. Contact, demo and pricing requests are handled in the Veviad Admin/Directus system. Trial requests are additionally processed by the systems responsible for assessment and provisioning.
Cloudflare receives the technical data required for hosting, delivery and abuse prevention. As the provider of the CCM19 cloud service, Papoo Software & Media GmbH processes the data required for consent management and proof. Analytics data collected with Umami is processed in Veviad's self-hosted instance at analytics.cloud.veviad.com and is accessible only to the responsible people at Veviad. Access-restricted internal notifications about requests may be sent through Slack (Slack Technologies Limited, Dublin, Ireland) to the responsible Veviad staff. They may contain contact details, company, request type, package of interest, a shortened message and an internal request identifier. Email service providers process data where necessary for confirmations and communication. Personal data is not disclosed to third parties for advertising purposes.
Storage and Deletion
For unverified trial requests, the verification link expires after 72 hours. The personal details in an unverified request are then redacted by a regularly scheduled cleanup process; the verification token, which is stored only as a hash, and the temporary eligibility lock are removed.
Contact, demo and verified trial requests that do not result in a contract are generally retained for up to 24 months after the last substantive contact. They are then deleted or anonymised unless continued storage is required for a specific pre-contractual process, to establish, exercise or defend legal claims, or under statutory retention obligations. If a contract is concluded, the applicable statutory and contractual retention periods apply. Data in a provisioned trial environment is handled in accordance with the Trial Terms.
The CCM19 choice stored locally in your browser remains valid for 365 days unless you change it sooner or delete it through your browser settings. According to the provider, consent records are ordinarily retained in the CCM19 cloud for one year and technical deletion may take up to one additional month. According to the provider, IP addresses in technical CCM19 server logs are deleted after no more than 24 hours.
Umami event and session data is currently stored in the self-hosted instance until it is deleted manually following a necessity review or the analytics purpose ceases to apply. No automated cleanup process is configured at present, so we cannot currently guarantee a shorter technical maximum retention period. Data that is no longer required for the analytics purposes described above is deleted.
We process a voluntary marketing consent until it is withdrawn. We may subsequently retain evidence of the grant and withdrawal where required for the applicable statutory limitation period. You can delete data held in local or session browser storage at any time through your browser settings.
Your Rights
Subject to the applicable statutory requirements, you have rights of access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing. Where processing is based on Art. 6(1)(f) GDPR, you may object on grounds relating to your particular situation. We will then stop the processing unless compelling legitimate grounds or grounds for the establishment, exercise or defence of legal claims take precedence. You may withdraw consent at any time with effect for the future; withdrawal does not affect the lawfulness of processing carried out before withdrawal. You can change or withdraw consent to Umami and the associated session storage through “Privacy Settings” in the footer. The Do Not Track signal is an additional technical safeguard.
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.
Technical Pre-Assessment
Trial requests may be technically pre-assessed using the company and use-case information provided and assigned for further processing, manual review or a not-suitable outcome. No decision is made solely by automated means that produces legal effects concerning you or similarly significantly affects you.
Transfers to Third Countries
Cloudflare and Slack may process data in the United States and other countries outside the EU or European Economic Area. Where applicable, transfers to the United States are based on a valid certification under the EU-U.S. Data Privacy Framework; EU Standard Contractual Clauses and supplementary safeguards are used additionally or alternatively. Details are provided in the respective privacy information and data processing agreements.
Updates to This Privacy Notice
We update this Privacy Notice when the website, the services used or legal requirements change. The version stated on this page is authoritative.