Privacy Policy
Version v1.0.1 | Last updated: 2026-07-29
We take the protection of your data seriously. This privacy policy explains what data we collect, why we collect it, how we protect it, and what rights you have. The short version: our core infrastructure is in Germany. We do not sell your data or use advertising cookies, and our self-hosted analytics is activated only after your consent. Optional external services, including Google sign-in, payment providers, and error analysis, are described individually below.
1. Data Controller (Art. 4(7), Art. 13(1)(a) GDPR)
Cryon UG (haftungsbeschränkt)
Landsberger Str. 35
04157 Leipzig
Germany
Managing Director: Jonas Kutavicius
Email: info@werkzeu.ge
We have not appointed a separate Data Protection Officer as we do not meet the requirements of Art. 37 GDPR / § 38 BDSG. For all data protection matters, please contact us at the email address above.
2. Principles of Data Processing
We process personal data exclusively according to the following principles:
- Data minimization: We only collect data that is actually necessary for the respective purpose.
- Purpose limitation: Data is only used for the purpose for which it was collected.
- Transparency: This policy explains exactly what we do and why.
- Storage limitation: We delete data once the processing purpose no longer applies.
- No data sales: We never sell, rent, or trade your data.
- No use for AI training: We do not use your content data to train our own or third-party AI models.
3. Hosting & Server Location
Our core infrastructure runs on dedicated servers operated by Hetzner Online GmbH in Germany (data centers in Nuremberg and Falkenstein). Hetzner is a German company based in Gunzenhausen and is fully subject to German and European data protection law.
The core application, accounts, database, and file storage are not hosted by a US hyperscaler. Individual optional or supporting functions nevertheless use external providers and international infrastructure. This policy lists those recipients according to their actual purpose.
DNS resolution is handled by INWX GmbH (Germany). Email delivery runs through the SMTP relay service of INWX GmbH (smtp.webspace.bz, headquartered in Germany). INWX is a German domain and hosting provider and acts as a data processor pursuant to Art. 28 GDPR.
Our core infrastructure is operated in the EEA. Processing outside the EEA cannot be completely excluded for individual external services, particularly payment processing and error analysis; Sections 8 and 18 describe the recipients and safeguards.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable and secure provision of our services).
Data processors pursuant to Art. 28 GDPR:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany - Hosting, server infrastructure, object storage
- INWX GmbH, Zwinglistr. 1, 10555 Berlin, Germany - Email delivery (SMTP relay), DNS resolution
- Functional Software Inc. (Sentry), 132 Hawthorne Street, San Francisco, CA 94107, USA - Error tracking and analysis. Processing and storage take place in the provider's EU region (Frankfurt data centre); the provider is a US company, so access from a third country cannot be fully excluded. A data processing agreement and EU Standard Contractual Clauses apply. Default PII transmission is disabled, and known sensitive fields, headers, and request content are scrubbed before transmission. Technical error data, reduced request context, and pseudonymous identifiers may be processed.
Payment service providers (see Section 8): PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg), Mollie B.V. (Netherlands), and the Stripe entities responsible for the particular payment transaction (Ireland).
Other recipients or independent controllers involved only when the relevant function is used:
- Intuition Machines, Inc. (hCaptcha, USA) - bot protection for contact and certain registration or checkout flows; processes in particular IP address, browser, and interaction signals
- Google Ireland Limited and affiliated companies - only for voluntary Google sign-in; Google learns about the sign-in attempt
- UNPKG with global CDN infrastructure - FFmpeg WASM files are delivered to your browser only when you start certain media tools; IP address, headers, timestamp, and requested file are processed
- ExchangeRate-API (open.er-api.com) - our server retrieves current fiat reference rates; amounts you enter are not transmitted
- CoinGecko - our server retrieves current crypto reference rates; amounts you enter are not transmitted
- Have I Been Pwned - for the password leak check, our server sends only the first five hexadecimal characters of a SHA-1 hash under the k-anonymity method, never your password or complete hash
- OpenStreetMap tile servers and external pages linked by a tool - only when you call the corresponding map or link function
4. Data Collected by Tier
4.1 Guest (no registration)
Without signing in, we store no account data. Many guest tools run entirely in your browser. If a tool needs a server request, we process the submitted inputs and technical connection data required to provide and secure that function.
When you access any page, the following technical data is briefly processed:
- IP address (technically necessary for the connection)
- Browser type and version
- Operating system
- Referrer URL
- Time of access
This data is stored in access log files. Log rotation removes these access logs after no more than 7 days. We do not combine them with other data sources for advertising or profiling.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing and securing the website).
4.2 Free Account
Upon registration, we store:
- Email address
- Display name (freely chosen)
- Language preference (German or English)
- Subscription status
- Registration date
- Amtsprofil (optional): If you set it up, we store the envelope encrypted in your browser against your account on our servers. We do not receive the password, key, or plaintext.
Passwords:The password you set at registration is stored only as a cryptographic scrypt hash — the plaintext password is never stored and cannot be reconstructed. If you sign in via magic link, no password is transmitted.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
4.3 Plus Subscription
In addition to Free account data:
- Files: Uploaded and created files are stored on Hetzner Object Storage (S3-compatible) in Germany.
- Payment data: See Section 8 (Payment Processing).
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
4.4 Pro Subscription
In addition to Plus account data:
- Community content: Posts, comments, and chat messages are stored in our PostgreSQL database on German servers.
- Team data: For team usage, we store member-to-team assignments and permissions.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
4.5 Organization, Personnel, and Communication Features
When an organization uses Pro features, it may process data about its employees, customers, suppliers, and other contacts. Depending on the enabled function, this can include master data, roles, working time, absences, sick-note and AU information, payroll and social-insurance data, bank and tax data, CRM contacts, booking details, files, email content, and encrypted credentials for a connected mailbox.
Cryon remains the controller for account administration, billing, security, and its own product communication. Where a customer organization determines the purposes and means of processing personnel, customer, or communication data, Cryon processes that data on the organization's behalf. The organization must determine access rights, legal bases, information duties, and permitted input. Special categories of personal data, especially health or disability data, may be entered only with an appropriate legal basis and suitable access controls.
This processing is governed by our data processing agreement pursuant to Art. 28 GDPR. It is accepted separately when an organization purchases a team subscription.
The self-hosted Collabora Online component for document editing and LiveKit component for video or audio meetings run on the described Werkzeu.ge infrastructure. On public booking pages, we process the contact, appointment, and note data entered by the guest, plus technical connection data; the provider of that booking page receives the submitted data.
5. Cookies & Local Storage
5.1 Cookies
We use technically necessary cookies for authentication, security, interface choices you expressly make, and storage of your consent decision. The optional analytics cookie wz_aid is set only after you consent.
| Cookie | Purpose | Duration | Attributes |
|---|---|---|---|
__Host-werkzeuge.session_token | Authentication and session | 14 days | HTTPOnly, Secure, SameSite=Lax |
__Host-werkzeuge.signup-recovery, werkzeuge_oauth_signup_consent, and short-lived auth state | Secure continuation of registration and OAuth sign-in | 10 minutes to no more than 24 hours | HTTPOnly, Secure, SameSite=Lax |
werkzeuge:cookie-consent | Stores your consent decision | 1 year | Secure, SameSite=Lax |
werkzeuge:shell-mode, werkzeuge:visual-mode-chosen, werkzeuge:onboarding-done | Your interface choice and completed onboarding | 1 year | Secure, SameSite=Lax |
wz_ref | Attributes an explicitly opened referral when registration occurs | 30 days | HTTPOnly, Secure, SameSite=Lax; set only after visiting a referral link |
wz_aff | Attributes an explicitly opened affiliate link (partner program) when registration occurs | 30 days | HTTPOnly, Secure, SameSite=Lax; set only after visiting an affiliate link |
wz_aid | Random, IP-independent identifier for consented product-funnel measurement | 180 days | Secure, SameSite=Lax; set only with analytics consent |
We set no advertising cookies and no advertising-network cookies. Technically necessary cookies and local entries for functions you expressly request are used without consent where Section 25(2) No. 2 TDDDG applies. We ask for your consent before analytics processing. Details are available in our Cookie Policy.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical functionality); § 25(2) No. 2 TDDDG (technical necessity).
5.2 Local Storage
We use your browser's local storage for local functions you request, such as drafts, notes, tool state, preferences, and workspace layouts. This data:
- Never leaves your browser
- Has a function-specific lifetime; short-lived drafts may expire after 30 minutes, while preferences remain until deletion
- Is stored with function-specific keys
- For selected HR tools, is additionally separated by account and organisation and removed from the browser on logout
- Can be deleted at any time via your browser settings
Device access is based on Section 25(2) No. 2 TDDDG where the entry is necessary for the expressly requested function. The Cookie Policy lists typical keys and deletion options.
6. Web analytics (reach measurement)
We use self-developed, self-hosted analytics software running on our own infrastructure in Germany. No data is sent to third parties, and no third-party analytics service is involved.
What we retain is anonymous.Our analytics database holds nothing but daily totals: a date, a two-letter country code, a device category and operating system, a page path, and counts. A typical record reads “2 August 2026 - Spain - 11 visits”. These records contain no identifier of any kind - no IP address, no cookie value, no account reference, no user agent string - and cannot be related back to an individual visitor by any means reasonably likely to be used. They are statistics, not profiles.
Your IP address is never stored. It is processed only in volatile memory, for the duration of a single request, and for exactly two purposes:
- to determine a country at country level only (via the local DB-IP Lite database - no external lookup, your address is never transmitted anywhere), and
- to be converted, using a secret key that changes daily, into a 16-character value that feeds a probabilistic counting structure. That structure records only how many distinct visitors there were, never which ones, is held in our cache rather than our database, and is discarded after 24 hours. Because the key changes daily, nothing can be linked from one day to the next.
Your IP address is never written to the analytics database, never exported, and never used to build a profile.
Device informationis derived from the user agent your browser sends. We keep only the device category and the operating system family (for example “Desktop / Windows”). The full user agent string is discarded.
Retention. The anonymous statistics are kept indefinitely. Because they carry no personal reference, the storage limitation principle (Art. 5(1)(e) GDPR) does not bind them, and a long baseline is what makes year-over-year comparison possible. The identifying inputs remain short-lived: the daily pseudonym expires after 24 hours, and the server access logs after 7 days.
Legal basis.Because we neither store nor read any information on your device for this purpose, § 25 TDDDG does not apply. The brief processing of your IP address to derive a country and a daily count rests on our legitimate interest in understanding the reach and reliability of our service (Art. 6(1)(f) GDPR). Our interest is limited to aggregate figures; your interests are protected by the fact that nothing identifying is retained. You may object at any time under Art. 21 GDPR by contacting us.
The optional wz_aid cookie is different.It is stored on your device, it is set only with your explicit consent in the cookie settings (Art. 6(1)(a) GDPR, § 25(1) TDDDG), it is valid for a maximum of 180 days, and you can withdraw it at any time. Declining it does not prevent the anonymous counting described above, and declining it costs you no functionality.
6.1 Bot Detection and Abuse Prevention
To secure the service, we process technical request information for rate limits, fraud detection, and defense against abusive access. This security processing is separate from optional audience analytics. Evaluation of the user-agent header by device, operating system, or bot property and the JavaScript beacon confirming human page views enter the audience statistics only with analytics consent.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
6.2 Product events (funnel measurement)
To understand where our service convinces or fails, we record a closed list of twelve product events(e.g. “registration completed”, “checkout started”). We store no IP address and no user agent. For signed-in browser-originated product events are sent only after analytics consent; a random pseudonymous identifier (wz_aid) may then be used. Independently, the server records necessary contract events such as a completed checkout against the account. Events are deleted automatically after 180 days; on account deletion, the personal reference is removed unless an overriding evidence obligation applies.
Legal basis: Art. 6(1)(b) GDPR (account events), Art. 6(1)(a) GDPR (pseudonymous identifier, consent).
6.3 Payment-backed trial & referral program (abuse prevention)
To prevent the one-time payment-backed trial and the referral program from being exploited through multiple accounts, we store a keyed SHA-256 check value for the normalized email address when a trial starts. When a referral is recorded, we temporarily store a corresponding IP-address check value. They are used only to determine whether a trial was already used or an abuse threshold was reached. These are pseudonymous, not anonymous data. IP check values in referral records are removed after seven days. The email check value remains after account deletion for the permanent one-trial rule; access and purpose are restricted to abuse prevention.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting free services from abuse).
6.4 Promotional emails (consent only)
Seasonal reminder emails (e.g. tax deadlines), winback and referral emails are sent only if you have expressly consented to promotional communication (consent at registration or in settings, revocable at any time). Every such email contains an unsubscribe link (List-Unsubscribe). You receive at most one email per campaign; we document the send for proof purposes (Sec. 7 UWG). Transactional emails (payment confirmations, reminders for your own deadlines, trial expiry) are independent of this consent.
Legal basis: Art. 6(1)(a) GDPR, Sec. 7(2) no. 2 UWG (consent).
7. Authentication
Registration uses your email address and a password. The password is stored exclusively as a cryptographic hash and cannot be reconstructed.
For login you may alternatively request a magic link: a one-time login link by email, with no password entry.
We optionally offer Sign in with Google. Google learns about your login; we receive only your email address and name from Google, and the account link requires your explicit confirmation. Without Google login, your authentication data is processed exclusively on our own servers.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
8. Payment Processing
For paid subscriptions (Plus, Pro), we use the following payment service providers:
8.1 PayPal
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.
Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
8.2 Mollie
Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands.
Privacy policy: https://www.mollie.com/privacy
8.3 Stripe
Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, Ireland. The Stripe entity responsible in a particular case depends on the payment method and processing context.
Privacy notice: https://stripe.com/de/privacy
When you make a payment, the following data is transmitted to the respective payment provider:
- Email address
- Name and, where applicable, billing address
- Subscription type and amount
- Transaction ID
We do not store credit card data, bank account details, or payment instrument details. The complete payment processing and storage of sensitive payment data is handled exclusively by the respective provider. We store the provider customer, subscription, and transaction identifiers, as well as payment status, amount, currency, and payment timestamp for contract and booking reconciliation.
Depending on the processing activity, payment providers process data as processors and/or independent controllers, in particular for payment execution, fraud prevention, and regulatory compliance. They may involve affiliates and payment networks outside the EEA. Such transfers are subject to the safeguards described by the respective provider, in particular adequacy decisions or EU Standard Contractual Clauses.
Legal basis: Art. 6(1)(b) GDPR (performance of contract); Art. 6(1)(c) GDPR (legal obligation for tax record-keeping of invoice data).
9. File Storage
Files you create or upload with a registered account are stored on Hetzner Object Storage (S3-compatible) in Germany. The storage includes:
- The file itself
- Metadata (file name, size, creation date, associated tool)
- Access permissions (which user owns the file)
In the optional encrypted folder, file contents and descriptive metadata such as the filename, type, and original size are encrypted in your browser before upload. Our servers receive only ciphertext, an opaque object identifier, ciphertext size, and the encrypted key configuration. The separate folder password and unencrypted keys do not leave the browser. Because of this encryption, we cannot recover, search, preview, or virus-scan these files.
During account deletion, files are removed from active storage unless a legal duty or another permissible reason requires continued retention. Backup copies expire according to the cycle described in Section 14.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
10. Amtsprofil (Identity Vault)
The Amtsprofil is an encrypted identity vault that stores personal data (name, address, tax ID, marital status, etc.) to auto-fill forms.
Zero-knowledge architecture: All data in the Amtsprofil is encrypted client-side in your browser. The encryption key is derived from the vault passphrase you choose and does not leave your browser. Only the authenticated encrypted envelope is sent to our servers and stored against your account. The password, derived key, and plaintext are not transmitted. An encrypted local copy may remain as a browser cache.
The encrypted envelope is synchronized between your signed-in browsers. If you clear local browser data or change devices, this encrypted server copy remains. If you forget the vault passphrase, neither we nor support can decrypt the envelope; you can only delete it and start again. The account-scoped envelope is deleted when you reset the Amtsprofil or delete the account; backup copies expire under Section 14. If you use individual Amtsprofil details in another tool, further processing is governed by the information provided for that tool.
Legal basis for account-linked storage and synchronization: Art. 6(1)(b) GDPR (providing the vault function you requested). Section 25(2) No. 2 TDDDG applies to the technically necessary local cache. Transfer of individual details into another tool is described separately for that tool.
11. Community Features
When you use community features (posts, comments, chat, groups), the following data is stored:
- Content of your posts and comments
- Chat messages
- Group memberships
- Activity timestamps
- Your publicly visible display name
This data is stored in our PostgreSQL database on Hetzner servers in Germany. Community posts are publicly visible or group-restricted, depending on your settings.
You can edit or delete your posts at any time. Upon account deletion, your community content is anonymized or, upon request, completely deleted.
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
12. Email Communication
We send you emails in the following cases:
- Magic links for login— technically required, no consent needed
- Transactional emails— payment confirmations, invoices, subscription changes
- Deadline reminders— reminders for regulatory deadlines you have set yourself
- Security notifications— unusual login activity, password changes
We do not send newsletters without your explicit consent. Email delivery runs through INWX GmbH (SMTP relay smtp.webspace.bz, headquartered in Germany). INWX acts as a data processor pursuant to Art. 28 GDPR.
Through the contact form, we process your name, email address, topic, message, hCaptcha evidence, and technical protection data. The message is forwarded to our support mailbox and is not additionally stored in a contact-form database. Support correspondence remains until the request is completed and afterwards only as long as needed for follow-up, defense of claims, or statutory evidence.
If you report allegedly illegal content, we additionally process the exact URL or content identifier, the selected report category, the legal basis you identify, your statement of facts, and your good-faith declaration. We need this information to assess the notice, communicate receipt and the decision, and meet statutory evidence and cooperation duties. The report receives a reference and is processed in the responsible mailbox like other support correspondence.
Legal basis: Art. 6(1)(b) GDPR (performance of contract) for transactional emails; Art. 6(1)(c) GDPR for notice handling required by law and Art. 6(1)(f) GDPR for support, abuse prevention, and establishing or defending legal claims; Art. 6(1)(a) GDPR (consent) for any future newsletter.
13. Legal Bases for Processing (Art. 6 GDPR)
| Processing Activity | Legal Basis |
|---|---|
| Server log files (IP, browser data) | Art. 6(1)(f) (legitimate interest) |
| Session cookie | Art. 6(1)(f) (legitimate interest); § 25(2) No. 2 TDDDG |
| Registration & account data | Art. 6(1)(b) (performance of contract) |
| Payment processing | Art. 6(1)(b) (performance of contract) |
| Invoices & bookkeeping | Art. 6(1)(c) (legal obligation, § 147 AO, § 257 HGB) |
| File storage | Art. 6(1)(b) (performance of contract) |
| Amtsprofil (client-side encrypted, account-linked envelope) | Art. 6(1)(b) GDPR; local cache: Section 25(2) No. 2 TDDDG |
| Community content | Art. 6(1)(b) (performance of contract) |
| Transactional emails | Art. 6(1)(b) (performance of contract) |
| Consent-based web analytics | Art. 6(1)(a) (consent via cookie banner) |
| Error tracking (Sentry) | Art. 6(1)(f) (legitimate interest); data is minimized and scrubbed before transmission |
| Security measures (rate limiting, bot detection, access protection) | Art. 6(1)(f) (legitimate interest) |
| Support and notices of illegal content | Art. 6(1)(c) and (f) (statutory duties, support, abuse prevention, and legal defense) |
14. Data Retention Periods
| Data | Retention | Basis |
|---|---|---|
| Server log files | 7 days | Legitimate interest |
| Session data | 14 days (or until the session is revoked) | Technical necessity |
| Account data | Until account deletion | Performance of contract |
| Files (Plus/Pro) | Until deleted by user or account deletion | Performance of contract |
| Community content | Until deleted by user or account deletion | Performance of contract |
| Support correspondence and notices of illegal content | Until finally handled, then only as needed for follow-up, evidence, legal defense, or statutory periods | Statutory duties and legitimate interest |
| Public appointment bookings | Appointment and contact data until deletion by the booking-page provider or deletion of that provider's account; the guest IP address for no more than 7 days | Performance of the booking provider's contract and legitimate interest in abuse prevention |
| Invoice data | Generally 8 years depending on record type, and up to 10 years in individual tax-law cases | In particular § 147 AO and § 257 HGB |
| Payment receipts | The statutory term applicable to the booking or payment record, generally 8 years and up to 10 years in individual cases | In particular § 147 AO and § 257 HGB |
| Local storage drafts | Function-specific: some short-lived drafts for 30 minutes, other local content until deletion | Section 25(2) No. 2 TDDDG and the legal basis for the relevant function |
After the applicable retention period, data is deleted or anonymized. Account deletion is first scheduled with a 14-day safety period. After that, active data that is no longer required is deleted or anonymized. Open payments, refunds, delivery evidence, or statutory retention duties can delay minimization of individual records; access remains restricted to that purpose.
Note on backups: Our encrypted server backups are retained for up to 30 days. During this window, deleted data may still be present in a backup snapshot. Restores happen only in disaster scenarios (hardware loss etc.) and after review. After the backup cycle, the relevant snapshots are overwritten. If a backup is restored, deletion and restriction decisions that had already taken effect are applied again.
15. Your Rights
Under the GDPR, you have the following rights:
15.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether personal data concerning you is being processed, and if so, to access that data and receive a copy.
15.2 Right to Rectification (Art. 16 GDPR)
You have the right to request the correction of inaccurate data and the completion of incomplete data. You can change most data directly in your profile settings.
15.3 Right to Erasure (Art. 17 GDPR)
You have the right to request the deletion of your personal data, provided no statutory retention obligations apply. You can delete your account at any time in the settings. Deletion is also possible by emailing info@werkzeu.ge.
15.4 Right to Restriction (Art. 18 GDPR)
You have the right to request restriction of processing if you contest the accuracy of the data, the processing is unlawful, we no longer need the data, or you have lodged an objection.
15.5 Right to Data Portability (Art. 20 GDPR)
Where the requirements of Art. 20 GDPR apply, you have the right to receive data you provided in a structured, commonly used, and machine-readable format. The profile data export provides machine-readable, account-linked data. It does not replace a broader access request under Art. 15 GDPR; you can contact us by email for that request.
15.6 Right to Object (Art. 21 GDPR)
You have the right to object to the processing of your data based on Art. 6(1)(f) GDPR (legitimate interest). We will then cease processing unless we can demonstrate compelling legitimate grounds.
15.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on your consent, you may withdraw it at any time with effect for the future.
Exercising your rights: Simply email us at info@werkzeu.ge. We generally inform you of the action taken within one month. If an extension permitted by Art. 12(3) GDPR is required, we inform you within the first month of the reasons and the extended period.
16. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Sächsischer Datenschutz- und Transparenzbeauftragter
(Saxon Data Protection and Transparency Commissioner)
Devrientstraße 5
01067 Dresden, Germany
Website: https://www.datenschutz.sachsen.de
17. Security Measures
We employ extensive technical and organizational measures to protect your data:
- Transport and network protection: Public connections are TLS-encrypted (HTTPS). Internal services are protected by the private server network, firewalls, and, where used, a private certificate authority.
- Application protection: Input validation, authorization checks, and controls against abusive requests protect the application.
- Rate limiting: Protection against brute-force attacks and abuse.
- Zero-knowledge encryption: Particularly sensitive data (Amtsprofil) is encrypted client-side. We cannot access the plaintext.
- Password hashing: Passwords are hashed with scrypt.
- HTTPOnly cookies: Session cookies cannot be read by JavaScript.
- Regular backups: Encrypted backups on separate servers.
- Secret management: Runtime credentials are not delivered to the browser and are restricted to the services and operator access that require them.
- Access restriction: Administrative production-server access is limited to authorized, key-based access.
18. Data Transfer to Third Countries
Our core infrastructure is operated on servers in Germany or elsewhere in the European Economic Area (EEA). Individual recipients, their affiliates, or subprocessors may also process personal data outside the EEA. This particularly concerns payment providers and the error-analysis service described below. Where no adequacy decision exists, such transfers rely in particular on EU Standard Contractual Clauses and supplementary safeguards used by the respective provider. Details are available in each provider's privacy notice.
Exception - Sentry (error tracking): For detecting and resolving technical errors, we use the service Sentry (Functional Software Inc., San Francisco, USA). Error data is processed and stored in the provider's EU region (Frankfurt); because the provider is a US company, access from a third country cannot be fully excluded. Automatic PII transmission is disabled. Technical scrubbing removes or masks known email addresses, session data, credentials, headers, and sensitive fields before transmission. Because free text, file names, or stack traces can contain unexpected information, processing of personal error data cannot be excluded completely. Stack traces, browser/OS versions, reduced request context, and pseudonymous identifiers may be processed. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability and error resolution of our services).
19. Automated Decision-Making
We do not make solely automated decisions that produce legal or similarly significant effects within the meaning of Art. 22 GDPR. Automated security and abuse rules may limit requests, reject a free trial, or flag a case for manual review. Contract termination, refunds, and permanent account measures are not decided solely by a general AI or profiling system.
20. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in the legal framework or changes to our service. The current version is always available on this page. For significant changes affecting your rights, we will notify registered users by email.
21. Contact
For questions about data protection, exercising your rights, or this privacy policy, you can reach us at:
Cryon UG (haftungsbeschränkt)
Landsberger Str. 35
04157 Leipzig, Germany
Email: info@werkzeu.ge

DE
EN