Legal Information

Privacy & Cookie Policy

Information pursuant to Articles 13 and 14 GDPR · Datenschutzerklärung

Last updated: 10 August 2026

The short version. HypGuard runs no advertising, no tracking, no analytics and no profiling. We set no advertising cookies. Our webfonts are served from our own servers, so simply reading this site discloses nothing about you to Google or anyone else. The only third party your browser contacts is Cloudflare, for the security check that protects our two forms from abuse. Beyond that, we hold only what you deliberately send us through the contact form or the adoption assessment.

This policy explains what we do with personal data, on what legal basis, who else is involved, how long we keep it, and how you can exercise your rights. If anything here is unclear, write to us and we will explain it in plain terms.


1. Who is responsible

The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:

HypGuard
Syed Muhammad Azeem
Eberswalder Str. 2
30629 Hannover
Germany
Email: contact@mail.hypguard.com

We are not required to appoint a Data Protection Officer under Article 37 GDPR or § 38 BDSG. Data protection enquiries go to the address above and are handled by the controller personally.


2. What we collect, why, and on what legal basis

2.1 Visiting the site (server logs)

When you open a page, our hosting provider records the request: your IP address, the date and time, the page or file requested, the HTTP status, the referring page and your browser's user-agent string. This is unavoidable in operating a web server and is what allows us to deliver pages, diagnose faults and detect attacks.

Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is operating a functioning, secure website. We do not combine these logs with anything else and do not use them to build a profile of you.

2.2 The contact form

The contact form asks for your name, email address, company (optional) and message. When you submit it, we also record the time of submission and the IP address the submission came from, because an open contact form is otherwise trivially abused to send mail through our domain.

The message is delivered to our mailbox by email. We use it to answer you, and for nothing else — we do not add you to a mailing list.

Legal basis: Article 6(1)(b) GDPR where your enquiry concerns our services, since answering it is a step taken at your request prior to a possible contract; otherwise Article 6(1)(f) GDPR, our legitimate interest in responding to enquiries addressed to us. The IP address and timestamp are processed under Article 6(1)(f) for abuse prevention.

2.3 The adoption assessment questionnaire

The assessment collects a profile of the customer situation you are asking us about — organisation name (optional), industry, size, revenue band, operating regions, the technology being evaluated, deployment scope and stage, who is submitting, and your corporate email address — together with your answers to the assessment questions.

Your answers are assembled into a summary PDF in your own browser. That PDF is then emailed to the address you gave, with a copy to our assessor, who reviews it and prepares your report. The submission is what we work from, so we cannot deliver the assessment without it.

Legal basis: Article 6(1)(b) GDPR — processing necessary to perform the assessment you requested and to take steps prior to a contract. Please do not enter special categories of data (Article 9 GDPR) or personal details about named individuals in the free-text fields; the assessment is about an organisation's technology adoption, not about people.

2.4 The security check on our forms

Both forms are protected by Cloudflare Turnstile, a CAPTCHA alternative. To tell a person from a script it processes your IP address and signals about your browser and device. Cloudflare states that Turnstile does not use this to track individuals across sites and does not serve advertising cookies.

This is genuinely necessary rather than a convenience: our forms trigger outbound email, and without a working bot check the endpoints would be usable by anyone as a spam relay.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest, and yours, in a site whose forms cannot be hijacked. Any storage on your device that this involves is limited to what is strictly necessary to deliver the service you requested, within the meaning of § 25(2) no. 2 TDDDG.

2.5 Your privacy choices

When you answer the privacy notice, your choice is stored in your browser's local storage so we do not have to ask again on every page. It never leaves your device and contains no identifier for you.

Legal basis: § 25(2) no. 2 TDDDG and Article 6(1)(f) GDPR — storing your choice is strictly necessary to honour that choice.


3. Cookies and local storage

We set no advertising or analytics cookies. The complete list of what may be stored on your device is:

NameTypePurposeLifetime
hg_consent Local storage (first party) Remembers the privacy choice you made, so the notice is not shown again. 12 months
Cloudflare Turnstile Third party, strictly necessary Runs the security check on the contact and assessment forms and prevents a solved check being replayed. Session / short-lived

You can review or change your choice at any time using the privacy choices link, which appears in the footer of every page. You can also clear this site's storage in your browser settings; the notice will then simply appear again on your next visit.

If your browser sends a Global Privacy Control signal, we treat it as a standing refusal of everything optional and lock those switches off.


4. Who else processes your data

We keep the number of parties involved deliberately small. Each of the following acts as our processor under Article 28 GDPR:

ProviderRoleWhat it sees
Netlify, Inc. (USA) Hosting and serverless functions Server logs, and the contents of a form submission while it is being processed
Resend (USA) Transactional email delivery Recipient address, message content, and the assessment summary PDF
Amazon Web Services (Ireland, eu-west-1) Mail infrastructure used by Resend The outgoing message in transit
Cloudflare, Inc. (USA) Turnstile security check, DNS, inbound mail routing IP address and browser signals during the check; inbound email in transit

We do not sell personal data, do not share it for advertising, and do not pass it to anyone else unless we are legally obliged to.


5. Transfers outside the EEA

Netlify, Resend and Cloudflare are established in the United States, so some processing takes place there or may be accessible from there. Such transfers are made on the basis of the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR and, where the provider is certified under the EU–US Data Privacy Framework, on the adequacy decision under Article 45 GDPR.

You should be aware that United States law may give public authorities access rights that have no exact equivalent in the EU, and that a level of protection fully equivalent to the GDPR cannot be guaranteed in every case.


6. How long we keep it

  • Server logs — retained only for the short operational and security period applied by our hosting provider, then discarded.
  • Contact messages — deleted 12 months after your enquiry is closed, unless it develops into a business relationship.
  • Assessment submissions and reports — retained for 24 months so that we can deliver, explain and support the report, then deleted.
  • Business correspondence that becomes a commercial transaction — retained for the statutory periods that bind us as a German business, currently six years under § 257 HGB and up to ten years under § 147 AO. During that time the data is retained for those legal purposes only.
  • Your privacy choice — 12 months, after which we ask again.

If you ask us to erase your data earlier, we will do so wherever no statutory retention obligation prevents it.


7. Your rights

Under the GDPR you have the right to:

  • Access (Article 15) — a copy of the personal data we hold about you.
  • Rectification (Article 16) — correction of anything inaccurate.
  • Erasure (Article 17) — deletion, where no legal obligation requires us to keep it.
  • Restriction (Article 18) — a freeze on processing while a dispute is resolved.
  • Data portability (Article 20) — your data in a structured, machine-readable form.
  • Objection (Article 21) — you may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f). We will then stop unless we can show compelling legitimate grounds that override your interests.
  • Withdrawal of consent (Article 7(3)) — where processing rests on consent, you can withdraw it at any time with effect for the future.

To exercise any of these, write to contact@mail.hypguard.com. We answer within one month.

Right to lodge a complaint

You may complain to a supervisory authority, in particular in the Member State of your residence, place of work or the alleged infringement. The authority competent for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
www.lfd.niedersachsen.de


8. Automated decision-making

We want to be precise here, because the assessment is partly algorithmic. The questionnaire chooses which questions to put to you automatically, based on the profile you enter, so that you are asked only what is relevant to your situation.

That selection is not a decision about you. Your assessment report is written after review by a human specialist, and we make no automated decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. We do not profile you for advertising or credit-scoring purposes.


9. United States privacy rights

This section applies to residents of United States states with comprehensive privacy laws, including California (CCPA as amended by the CPRA), Colorado, Connecticut, Virginia, Utah and Texas. The practices described are the same for everyone; only the vocabulary differs.

What we collect

  • Identifiers — name, email address, IP address.
  • Commercial and professional information — company, role, and the assessment responses you submit.
  • Internet or network activity — standard server log data.

We collect these directly from you, or automatically from your browser when you visit. We use them to respond to you, to deliver the assessment you requested, and to keep the site secure. We do not collect sensitive personal information, and we do not use or disclose personal information for purposes other than those disclosed here.

No sale, no sharing

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined in the CCPA — and we have not done so in the preceding twelve months. We do not sell or share the personal information of minors under 16. Because we do not sell or share, there is nothing for a "Do Not Sell or Share My Personal Information" request to switch off; the link is nevertheless available through our privacy choices panel, and we honour Global Privacy Control signals.

Your rights

  • The right to know what we collect, use and disclose.
  • The right to delete the personal information we hold about you.
  • The right to correct inaccurate personal information.
  • The right to opt out of sale or sharing (we do neither) and of profiling for consequential decisions (we do not profile).
  • The right to non-discrimination for exercising any of these rights. We do not offer financial incentives for personal information.

Submit a request to contact@mail.hypguard.com. We will verify it by replying to the email address associated with the data, and respond within 45 days. An authorised agent may act for you with written permission.


10. Children

HypGuard is a business-to-business service. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.


11. Changes to this policy

If we change how we handle personal data — for example by introducing analytics, which we do not use today — we will update this policy, change the date at the top, and ask for your choice again where the law requires consent.


Hinweis für deutschsprachige Besucher

Diese Datenschutzerklärung ist in englischer Sprache verfasst, da diese Website durchgehend englischsprachig ist. Verantwortlicher im Sinne der DSGVO ist Syed Muhammad Azeem, Eberswalder Str. 2, 30629 Hannover. Zuständige Aufsichtsbehörde ist die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover. Diese Website verwendet keine Analyse-, Tracking- oder Werbetechnologien; Schriftarten werden lokal ausgeliefert. Auskunft in deutscher Sprache erhalten Sie jederzeit unter contact@mail.hypguard.com.