Home / Privacy Policy
Privacy Policy
Last updated: June 2026
Table of contents
1. Controller
medairon UG (haftungsbeschränkt)
E-Mail: privacy@medairon.com
2. Data we collect
We process the following categories of data:
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| E-mail, Name | Account management | Art. 6(1)(b) GDPR | Until account deletion |
| Password (hashed) | Authentication | Art. 6(1)(b) GDPR | Until account deletion |
| Payment data | Billing | Art. 6(1)(b) GDPR | 10 years (tax law) |
| Reach measurement (cookieless) | Anonymous reach measurement, website improvement | Art. 6(1)(f) GDPR | 26 months |
| Consent log | Proof of the consent decision (Art. 7(1)) | Art. 6(1)(f) GDPR | Appropriate, proof-related period |
3. Legal basis (GDPR)
Processing is based on Art. 6(1)(b) GDPR (contract performance) for registered users, Art. 6(1)(f) GDPR (legitimate interest) for the anonymous, cookieless reach measurement and for the consent log (proof of the consent decision), and Art. 6(1)(c) GDPR (legal obligation) for the tax- and commercial-law retention of billing data.
4. Recipients / Processors
We disclose personal data to the following processors (Art. 28 GDPR). We do not sell personal data to third parties.
- Supabase Inc. — database, authentication and file storage (including the consent log and our own analytics tables). Processing in an EU region.
- Stripe Inc. — payment processing (subscriptions, one-time payments, webhooks). Transfer to the USA, see section 5.
- Resend Inc. — sending of transactional emails. Transfer to the USA, see section 5.
- Vercel Inc. — hosting, edge/CDN and cron jobs. All HTTP requests pass through Vercel (including IP address, user agent). Transfer to the USA, see section 5.
- Hosting provider of our self-operated reach measurement (Umami) — operation of the server infrastructure on which the Umami instance and its own dedicated database run. The processor is the hosting provider, not the Umami software.
Note: fonts are served self-hosted at build time; no runtime call is made to Google servers. Google is therefore not a recipient.
5. Transfers to third countries
With the services Stripe, Resend and Vercel, personal data is transferred to the USA (third country).
For each of these US services we base this third-country transfer both on the EU-U.S. Data Privacy Framework (DPF) — to the extent the respective service is certified — and on the EU Standard Contractual Clauses (SCC, Implementing Decision (EU) 2021/914) as an independent basis. We deliberately maintain the SCC as an independent safeguard, because the DPF adequacy decision is currently subject to legal challenge.
6. Retention periods
Account data is retained until account deletion. Billing and payment data is retained for 10 years (tax and commercial-law retention obligation). The anonymous, cookieless reach measurement is deleted after 26 months. The consent log is retained for an appropriate period tied to its evidentiary purpose. Server and security logs are retained short-term.
7. Your rights
You have the right to access, rectify, erase, restrict processing, port your data, and object to processing. To exercise your rights, contact: privacy@medairon.com
9. Supervisory authority
You have the right to lodge a complaint with the competent supervisory authority. In Germany, this is the data protection authority of the federal state where we are established.