Privacy Policy

1. Data Protection at a Glance

General Notes

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified.

Data Collection on this Website

Who is responsible for data collection?
Data processing on this website is carried out by the website operator: SynthScript, Inh. Christoph Kretschmer, Hornisgrindestraße 9, 77855 Achern, Germany. Email: [email protected].

How do we collect your data?
Your data is collected when you provide it to us (e.g. contact form) or automatically when visiting the website through our IT systems (technical data such as browser, operating system, time of page access).

What do we use your data for?
Some data is collected to ensure error-free provision of the website.

Your rights:
You have the right at any time to receive free information about the origin, recipient and purpose of your stored personal data, as well as the right to rectification, erasure and restriction of processing.

2. Hosting

We host the content of our website with IONOS (IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany). Details: IONOS Privacy Policy.

The use of IONOS is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in reliable presentation of the website). We have concluded a Data Processing Agreement (DPA).

3. Cookies

This website uses cookies — small text files stored on your device.

We use the following cookies:

  • ss_lang — Stores your language preference (DE/EN). Technically necessary, duration: 1 year.
  • ss_consent — Stores your cookie consent. Technically necessary, duration: 1 year.

As these are strictly necessary cookies only, no separate consent is required under § 25 para. 2 TTDSG. You can disable cookies in your browser settings.

4. Your Rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to lodge a complaint with the supervisory authority

Competent supervisory authority: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Postfach 10 29 32, 70025 Stuttgart, Germany.

5. Newsletter

Description and consent

This website offers a free newsletter subscription. When you sign up, your email address — and any other details you provide — will be stored and used to send the newsletter based on your consent (Art. 6 para. 1 lit. a GDPR).

Double opt-in

Newsletter registration uses a double opt-in procedure. After signing up you will receive a confirmation email. Your address is only added to the mailing list after you confirm. This ensures that no one can sign up with someone else's address.

Email service provider: Brevo

Newsletters are sent via Brevo (Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France). Your email address is stored on Brevo's servers within the EU. Brevo allows us to analyse newsletter campaigns — when you open an email, a web beacon records whether the message was opened and which links were clicked.

We have concluded a data processing agreement (DPA) with Brevo. Details: Brevo Privacy Policy.

Unsubscribe

You can withdraw your consent to data storage and its use for newsletter delivery at any time, e.g. via the unsubscribe link in the newsletter. The lawfulness of processing carried out prior to withdrawal remains unaffected.

6. Reporting Security Vulnerabilities

If you report a security vulnerability in one of our products to us, for example to security@synthscript.de in accordance with our security policy, we process the following data: your email address, your name or a pseudonym (if provided), the content of your report including attachments, and any further correspondence. Providing your name is voluntary; you may also contact us under a pseudonym.

Purpose and legal basis

We process this data to assess and fix the reported vulnerability and to communicate with you about it. The legal basis is Art. 6 para. 1 lit. c GDPR insofar as we fulfil our vulnerability handling obligations under Regulation (EU) 2024/2847 (Cyber Resilience Act), and otherwise Art. 6 para. 1 lit. f GDPR (legitimate interest in the security of our products and their users).

Reporting to authorities

If your report concerns an actively exploited vulnerability or a severe security incident, Art. 14 of Regulation (EU) 2024/2847 requires us to notify it via ENISA's Single Reporting Platform to the German Federal Office for Information Security (BSI) as the competent CSIRT and to the European Union Agency for Cybersecurity (ENISA). The legal basis is Art. 6 para. 1 lit. c GDPR. We only transmit the technically necessary information. We only share your name and contact details with your consent (Art. 6 para. 1 lit. a GDPR).

Disclosure to third parties

If a vulnerability affects a component made by another party, such as an open-source library, we pass the technical details on to those responsible for it. We only mention your name there with your consent. The same applies to credits in our security advisories and in CVE records. CVE records are published by the MITRE Corporation in the USA; if you agree to be credited there, your name or pseudonym is transferred to the USA (Art. 49 para. 1 lit. a GDPR). You can withdraw your consent at any time with effect for the future; however, we cannot change CVE records that have already been published.

Retention period

We store your report and the correspondence until the matter has been resolved and beyond that only as far as necessary to meet legal documentation and record-keeping obligations, in particular under Regulation (EU) 2024/2847. The data is then deleted.