Privacy Policy
Last updated: 17 July 2026. This policy explains how we process personal data when you use this website, in line with the EU General Data Protection Regulation (GDPR / DSGVO).
1. Controller
The controller responsible for data processing on this website is:
Kerim Akkis, trading as “Akkistech” (brand: “Odoino” by Akkistech)
Freisinger Str. 1, 28215 Bremen, Germany
Email: [email protected] · Phone: +49 421 67373077
Full provider details are in our Impressum. We have not appointed a Data Protection Officer, as we are not legally required to do so; for any privacy matter, contact us at the address above.
2. Scope & principles
This policy applies to the website at odoino.com and the services offered through it. We process personal data only where there is a legal basis to do so, limit it to what is necessary for the stated purpose (data minimisation), and keep it only as long as needed (see Section 12). We do not sell personal data, and we do not use it for advertising.
3. Legal bases for processing
Where we process your personal data, we rely on one of the following legal bases under Art. 6(1) GDPR:
- Art. 6(1)(b) — performance of a contract (or steps prior to it), e.g. fulfilling an order or a free download you requested;
- Art. 6(1)(c) — compliance with a legal obligation, e.g. statutory retention of invoices and evidence of consent;
- Art. 6(1)(f) — our legitimate interests, e.g. operating and securing the website, preventing abuse, and answering enquiries, balanced against your rights;
- Art. 6(1)(a) — your consent, where we ask for it (you can withdraw consent at any time with future effect).
4. When you visit this website (server & access data)
When you access the site, technical data is processed so the site can be delivered securely and reliably: your IP address, the date and time of the request, the page or resource requested, referrer, and details of your browser/operating system. This data is processed to deliver the content, ensure stability and security, and defend against attacks and abuse (e.g. rate limiting). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website).
The site is delivered through Cloudflare, which acts as a content-delivery network, reverse proxy, and TLS provider in front of our origin server. Cloudflare processes connection data (including your IP address) on our behalf to route traffic, terminate encryption, and mitigate attacks. See Section 10 for the providers we use.
5. Cookies & local storage
We do not use tracking, advertising, or analytics cookies, and we do not embed third-party tracking. The site functions with only strictly necessary technology.
When you respond to the cookie banner, your choice is stored in your browser’s local storage (a single entry, odoino-cookie-consent) so we don’t ask again — it stays on your device and is not transmitted to us. Strictly necessary technology of this kind does not require consent (§ 25 Abs. 2 TTDSG); the banner is informational and forward-looking. If we ever introduce analytics, it will load only after a separate, explicit opt-in.
6. Contact form
If you use the contact form, we process the name, email address, and message you provide, in order to receive and respond to your enquiry. The message is stored and also delivered to us by email (see Section 9). Legal basis: Art. 6(1)(b) where your enquiry relates to a contract, otherwise Art. 6(1)(f) (legitimate interest in handling enquiries). Providing this data is voluntary, but necessary for us to respond.
To protect the form against automated abuse, we use Cloudflare Turnstile, a privacy-friendly bot check. It may process technical information (e.g. your IP address and browser signals) to distinguish humans from bots; unlike many CAPTCHA services, it does not use cookies for cross-site tracking. Legal basis: Art. 6(1)(f) (legitimate interest in preventing spam and abuse).
7. Purchases & payment processing
To fulfil a paid order, we process your email address, any name provided, and the order and product details. We use this to create your order, issue your license, deliver your download link, and meet our accounting and tax obligations. Legal basis: Art. 6(1)(b) (contract) and Art. 6(1)(c) (statutory retention).
Payment is handled by Stripe. Your payment details (e.g. card number) are entered on Stripe’s hosted checkout and are processed by Stripe directly — we never see or store your card data.Stripe provides us only with the information needed to fulfil and account for the order (such as your email, payment status, and a transaction reference). Stripe’s own processing is described in its privacy policy. Legal basis: Art. 6(1)(b).
8. Free downloads
For a free download, we process the email address you provide in order to send you a one-time download link and to record your acceptance of the license. This email is used only to deliver that download (a transactional purpose) — we do not add it to any marketing or newsletter list without your separate, explicit consent. Legal basis: Art. 6(1)(b) (delivery of the requested content) and Art. 6(1)(f) (evidence of license acceptance).
9. License acceptance & consent records
When you accept our license terms at checkout or before a free download, we record that acceptance — the email address (where applicable), the terms version, a timestamp, and, for evidentiary and abuse-prevention purposes, your IP address and browser user-agent. This lets us demonstrate that consent was given and, for paid immediate downloads, that the statutory conditions for the loss of the right of withdrawal were met (§ 356 Abs. 5 BGB — see our Right of Withdrawal page). Legal basis: Art. 6(1)(c) (legal obligation to document) and Art. 6(1)(f) (legitimate interest in proof of the transaction).
10. Service providers & recipients
We use carefully selected service providers who process data on our behalf as processors under Art. 28 GDPR (data-processing agreements in place). We do not otherwise share your data except where required by law.
- Cloudflare — CDN, reverse proxy, TLS, and attack mitigation (processes connection data incl. IP), and Turnstile bot protection on the contact form.
- Stripe — payment processing for paid orders.
- Zoho — email delivery (order confirmations, download links, contact-form messages), on Zoho’s EU infrastructure.
- Our self-hosted server infrastructure, on which the website and database run.
11. International data transfers
Our email provider (Zoho) processes email delivery on EU infrastructure. Some providers (notably Cloudflare and Stripe) are established in or may process data in the United States or other third countries. Where personal data is transferred outside the EU/EEA, it is safeguarded by appropriate measures — in particular the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework — together with additional technical measures such as encryption in transit.
12. Retention
We keep personal data only as long as necessary for the purpose it was collected, and then delete or anonymise it:
- Order & invoice data: retained for the statutory periods under German commercial and tax law (up to 10 years, §§ 147 AO, 257 HGB).
- License-acceptance / consent records: kept for the duration of the contract and applicable limitation periods, to evidence consent.
- Contact-form data: kept as long as needed to handle your enquiry and any follow-up, then deleted unless a longer period is required by law.
- Server/access data: kept only briefly for security and troubleshooting, then deleted or anonymised.
13. Your rights
Subject to the conditions of the GDPR, you have the right to:
- Access (Art. 15) — confirmation of whether we process your data, and a copy of it;
- Rectification (Art. 16) — correction of inaccurate or incomplete data;
- Erasure (Art. 17) — deletion, where no overriding legal ground (e.g. statutory retention) applies;
- Restriction (Art. 18) of processing;
- Data portability (Art. 20) — receiving certain data in a structured, machine-readable format;
- Objection (Art. 21) — to processing based on legitimate interests, on grounds relating to your situation;
- Withdraw consent (Art. 7(3)) at any time, with effect for the future, where processing is based on consent.
To exercise any of these rights, contact us at [email protected].
14. Right to lodge a complaint
You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your residence, workplace, or the place of the alleged infringement. The authority competent for us is:
Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen
Arndtstraße 1, 27570 Bremerhaven, Germany
15. Data security
We use appropriate technical and organisational measures to protect your data, including TLS/HTTPS encryption of all traffic to and from this site, access controls, and separation of internal operator tools from the public site. No transmission over the internet can be guaranteed to be perfectly secure, but we take reasonable steps to protect your data against loss, misuse, and unauthorised access.
16. Automated decision-making
We do not use automated decision-making, including profiling, that produces legal or similarly significant effects concerning you (Art. 22 GDPR).
17. Is providing data mandatory?
Providing personal data is not a statutory requirement, but some data is necessary to enter into or perform a contract with us — for example, without an email address we cannot deliver your download or order confirmation. Where data is required for that purpose, not providing it means we cannot provide the corresponding service.
18. Changes to this policy
We may update this policy to reflect changes to our services or legal requirements. The current version is always available on this page, with the “last updated” date at the top.
Datenschutzerklärung — Deutsche Übersetzung
Unverbindliche Übersetzung zur besseren Verständlichkeit. Maßgeblich ist die englische Fassung oben. Stand: 17. Juli 2026.
1. Verantwortlicher
Verantwortlich für die Datenverarbeitung auf dieser Website ist Kerim Akkis, handelnd unter „Akkistech“ (Marke: „Odoino“ by Akkistech), Freisinger Str. 1, 28215 Bremen, Deutschland, E-Mail: [email protected], Telefon: +49 421 67373077. Vollständige Angaben im Impressum. Ein Datenschutzbeauftragter ist gesetzlich nicht erforderlich und nicht bestellt.
2. Grundsätze
Wir verarbeiten personenbezogene Daten nur auf gültiger Rechtsgrundlage, beschränkt auf das für den jeweiligen Zweck Erforderliche (Datenminimierung), und speichern sie nur so lange wie nötig. Wir verkaufen keine Daten und nutzen sie nicht für Werbung.
3. Rechtsgrundlagen
Je nach Vorgang stützen wir uns auf Art. 6 Abs. 1 DSGVO: lit. b (Vertrag/vorvertragliche Maßnahmen), lit. c (rechtliche Verpflichtung, z. B. Aufbewahrung), lit. f (berechtigtes Interesse, z. B. sicherer Betrieb, Missbrauchsabwehr, Anfragenbearbeitung) sowie lit. a (Einwilligung, jederzeit mit Wirkung für die Zukunft widerruflich).
4. Beim Besuch der Website (Server-/Zugriffsdaten)
Beim Aufruf werden technische Daten verarbeitet (u. a. IP-Adresse, Zeitpunkt, angefragte Ressource, Referrer, Browser-/Systemangaben), um die Inhalte sicher und stabil auszuliefern und Angriffe/Missbrauch abzuwehren (z. B. Rate-Limiting). Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO. Die Auslieferung erfolgt über Cloudflare (CDN, Reverse Proxy, TLS), das Verbindungsdaten einschließlich IP-Adresse in unserem Auftrag verarbeitet.
5. Cookies & lokaler Speicher
Wir verwenden keine Tracking-, Werbe- oder Analyse-Cookies und binden keine Drittanbieter-Tracker ein. Ihre Auswahl im Cookie-Banner wird ausschließlich im lokalen Speicher Ihres Browsers abgelegt (Eintrag odoino-cookie-consent) und nicht an uns übertragen. Für solche unbedingt erforderlichen Technologien ist keine Einwilligung nötig (§ 25 Abs. 2 TTDSG). Eine etwaige Analyse würde erst nach gesonderter, ausdrücklicher Einwilligung geladen.
6. Kontaktformular
Bei Nutzung des Kontaktformulars verarbeiten wir Name, E-Mail-Adresse und Nachricht, um Ihre Anfrage zu beantworten. Rechtsgrundlage: Art. 6 Abs. 1 lit. b bzw. lit. f DSGVO. Die Angabe ist freiwillig, aber zur Beantwortung erforderlich. Zum Schutz vor automatisiertem Missbrauch setzen wir Cloudflare Turnstile ein, eine datenschutzfreundliche Bot-Prüfung; dabei können technische Informationen (z. B. IP-Adresse, Browser-Signale) verarbeitet werden, ohne Cookies zum seitenübergreifenden Tracking. Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO.
7. Käufe & Zahlungsabwicklung
Zur Erfüllung einer bezahlten Bestellung verarbeiten wir E-Mail-Adresse, ggf. Namen sowie Bestell-/Produktdaten (Vertrag, Lizenzierung, Lieferung, Buchhaltung). Die Zahlung erfolgt über Stripe; Zahlungsdaten geben Sie direkt bei Stripe ein — wir sehen oder speichern keine Kartendaten. Rechtsgrundlage: Art. 6 Abs. 1 lit. b und lit. c DSGVO.
8. Kostenlose Downloads
Für kostenlose Downloads verarbeiten wir Ihre E-Mail-Adresse ausschließlich zur Bereitstellung des einmaligen Download-Links und zur Dokumentation der Lizenz-Zustimmung — nicht für Werbung ohne gesonderte Einwilligung. Rechtsgrundlage: Art. 6 Abs. 1 lit. b und lit. f DSGVO.
9. Lizenz-Zustimmung & Einwilligungsnachweise
Bei Annahme der Lizenzbedingungen speichern wir die Zustimmung (ggf. E-Mail-Adresse, Version der Bedingungen, Zeitstempel sowie zu Nachweis-/Missbrauchszwecken IP-Adresse und Browser-Kennung), u. a. zum Nachweis des Erlöschens des Widerrufsrechts nach § 356 Abs. 5 BGB. Rechtsgrundlage: Art. 6 Abs. 1 lit. c und lit. f DSGVO.
10. Auftragsverarbeiter & Empfänger
Wir setzen sorgfältig ausgewählte Dienstleister als Auftragsverarbeiter (Art. 28 DSGVO) ein: Cloudflare (CDN/Proxy/TLS sowie Turnstile-Bot-Schutz im Kontaktformular), Stripe (Zahlungen), Zoho (E-Mail-Versand, EU-Infrastruktur) sowie unsere selbst gehostete Serverinfrastruktur. Eine darüber hinausgehende Weitergabe erfolgt nur, wenn gesetzlich vorgeschrieben.
11. Drittlandübermittlungen
Der E-Mail-Versand (Zoho) erfolgt auf EU-Infrastruktur. Einzelne Dienste (insbesondere Cloudflare und Stripe) können Daten in den USA oder anderen Drittländern verarbeiten. Soweit Daten außerhalb der EU/des EWR übermittelt werden, geschieht dies auf Grundlage geeigneter Garantien, insbesondere der EU-Standardvertragsklauseln und – soweit anwendbar – des EU-US Data Privacy Framework, ergänzt um technische Maßnahmen wie Transportverschlüsselung.
12. Speicherdauer
Bestell-/Rechnungsdaten: gesetzliche Aufbewahrungsfristen (bis zu 10 Jahre, §§ 147 AO, 257 HGB). Einwilligungsnachweise: für Vertragsdauer und Verjährungsfristen. Kontaktdaten: bis zur Erledigung der Anfrage, danach Löschung, soweit keine längere Pflicht besteht. Server-/ Zugriffsdaten: nur kurz zu Sicherheits-/Fehleranalysezwecken.
13. Ihre Rechte
Sie haben nach Maßgabe der DSGVO das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch (Art. 21) sowie auf Widerruf erteilter Einwilligungen (Art. 7 Abs. 3). Kontakt: [email protected].
14. Beschwerderecht
Sie haben das Recht, sich bei einer Aufsichtsbehörde zu beschweren. Für uns zuständig ist: Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen, Arndtstraße 1, 27570 Bremerhaven.
15. Datensicherheit
Wir treffen geeignete technische und organisatorische Maßnahmen (u. a. TLS/HTTPS, Zugriffskontrollen, Trennung interner Betreiber-Tools vom öffentlichen Auftritt), um Ihre Daten zu schützen.
16. Automatisierte Entscheidungen
Eine automatisierte Entscheidungsfindung einschließlich Profiling mit rechtlicher oder ähnlich erheblicher Wirkung (Art. 22 DSGVO) findet nicht statt.
17. Bereitstellungspflicht
Die Bereitstellung ist gesetzlich nicht vorgeschrieben, für einen Vertrag jedoch teils erforderlich (z. B. E-Mail-Adresse zur Lieferung). Ohne die erforderlichen Daten können wir die jeweilige Leistung nicht erbringen.
18. Änderungen
Wir können diese Erklärung anpassen. Die aktuelle Fassung ist stets auf dieser Seite mit Datum abrufbar.
