Privacy

Privacy Policy for Hivora Cloud

This privacy policy explains how we process personal data when you use Hivora Cloud and its related web interface.

Last updated: March 21, 2026

1. Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Mario Lukas c/o IP-Management #9033 Ludwig-Erhard-Str. 18 20459 Hamburg Germany

2. Data protection contact

If you have any questions about data protection or wish to exercise your rights, you can contact us at any time:

Email: gdpr@hivora.eu

3. Provision of the platform and server log files

For technical reasons, our systems automatically collect log data whenever you access the web interface or backend infrastructure.

This includes in particular IP address, date and time of the request, browser type and browser version, operating system, device type, and the transmission status.

The processing is carried out for the purpose of ensuring the secure and stable provision of the platform, defending against attacks, filtering bots, and analysing system errors and stability issues.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our services.

4. Registration and user account

When you create a user account for Hivora Cloud, we process the data you provide in the registration form. This includes in particular your email address, password, user group, any supplementary free-text information, and your preferred language.

In addition, account-related preferences such as your preferred administrative area and language may be processed in order to adapt the platform to your account.

The processing is carried out for the purpose of setting up and managing your user account, providing protected platform functions, and configuring the application for your use.

The legal basis is Art. 6(1)(b) GDPR insofar as the processing is necessary for the performance of the user relationship. Where individual data serves the secure and needs-based design of the platform, the processing is based on Art. 6(1)(f) GDPR.

5. Master data of organisations (tenants) and contract handling

When an organisation uses Hivora Cloud — for example to operate a public report widget — we process the organisation- and contact-related data provided during onboarding. This includes in particular the name and legal form of the organisation, postal address, registration court and registration number (where applicable), VAT identification number (if provided), and the name, email address, and phone number of the contact person.

The processing is carried out for the purpose of initiating and performing the usage relationship, invoicing via our payment provider Stripe Payments Europe Ltd., complying with statutory retention obligations, and providing data processing on behalf of our tenants pursuant to Art. 28 GDPR.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (statutory retention obligations under the German Commercial Code (HGB) and Tax Code (AO)).

Contract and master data are stored for the duration of the contractual relationship and for the duration of the statutory retention periods (typically 6 to 10 years under HGB / AO).

6. Authentication, session management, and trusted devices

When you sign in to Hivora Cloud, we process data that is necessary for authentication and the secure management of your session. This includes authentication data, server-managed refresh tokens, and security-related session information.

To technically maintain your sign-in, the platform uses an HttpOnly refresh cookie. In addition, a token for a trusted device may be stored on your device so that, under certain conditions, you do not have to complete a new multi-factor challenge every time you sign in from the same browser.

The processing is carried out for the purpose of secure sign-in, abuse prevention, session management, and recognising trusted devices.

The legal basis is Art. 6(1)(b) GDPR and, additionally, Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting user accounts and preventing unauthorised access.

In addition, the platform stores your preferred display language in a functional cookie (named “hivora_lang”, valid for up to one year) so that the interface language is retained on subsequent visits. This cookie is technically functional and is set without consent; the legal basis is Art. 6(1)(f) GDPR (interest in a consistent, user-friendly presentation).

7. Multi-factor authentication and passkeys

To increase the security of your account, Hivora Cloud may use multi-factor authentication methods. For this purpose, we process security-related one-time codes, information about trusted devices, and data related to passkeys or WebAuthn credentials.

If you use passkeys, we store the technical metadata required for this purpose, in particular credential IDs, public keys, usage counters, optional device labels, and status information regarding use and revocation. Time-limited challenge data is also processed during WebAuthn procedures.

The processing is carried out exclusively for the purpose of strong authentication, securing your user account, and preventing unauthorised access.

The legal basis is Art. 6(1)(b) GDPR and, additionally, Art. 6(1)(f) GDPR.

8. Email communication for security and account purposes

We use your email address to send you security-related and account-related messages. This includes, in particular, emails for account verification, password reset, initial password setup, and one-time codes as part of multi-factor authentication.

The processing is carried out for the purpose of account security, identity verification, restoring account access, and communicating in connection with the use of your user account.

The legal basis is Art. 6(1)(b) GDPR and, additionally, Art. 6(1)(f) GDPR.

Delivery is carried out via an email infrastructure operated by us in data centres of Hetzner Online GmbH in Germany.

9. Recipients, processors, and third-country transfers

To the extent necessary for the operation of Hivora Cloud, we process personal data on systems operated by us in data centres of Hetzner Online GmbH in Germany.

Based on the current technical setup, this includes in particular systems for user accounts, databases, document storage, object-based file storage, caching, and email infrastructure.

According to the current state, personal data is not processed in countries outside the European Union or the European Economic Area.

10. Storage period

We store personal data only for as long as this is necessary for the respective purposes or as long as statutory retention obligations apply.

  • Server log files are generally stored for up to 30 days.
  • Account data is generally stored for the duration of the user account.
  • Refresh tokens are technically designed for up to 7 days.
  • Trusted device data is technically designed for up to 30 days unless it is revoked earlier.
  • Temporary security data such as one-time codes, challenges, or reset tokens is stored only for the short period required for the respective purpose.

11. Your rights as a data subject

Under the statutory requirements, you have in particular the following rights:

To exercise your rights, you can contact gdpr@hivora.eu.

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on Art. 6(1)(f) GDPR
  • Right to withdraw consent with effect for the future
  • Right to lodge a complaint with a supervisory authority

12. Obligation to provide certain data

To the extent that the provision of your email address, password, and any other information marked as required is necessary for the registration and use of a protected user account, the provision of this data is contractually required.

Without this data, we cannot create a user account or provide protected access to Hivora Cloud.

13. No automated decision-making

According to the current state, automated decision-making within the meaning of Art. 22 GDPR does not take place.

14. Web analytics with Matomo

On this website we use the self-hosted web analytics tool Matomo (https://matomo.org). The provider and operator of the Matomo instance is us; the data is processed exclusively on our own infrastructure at matomo.hivora.eu (EU) and is not shared with third parties.

Matomo is only loaded after your consent (Art. 6 (1)(a) GDPR). We obtain your consent via our cookie banner. Without consent no analysis takes place and no Matomo cookies are set.

After consent has been granted, Matomo processes the following data: truncated IP address, accessed URLs, time spent on the page, referrer URL, browser type, operating system, screen resolution, and clicks on links and downloads. Cookies (e.g. _pk_id, _pk_ses) are set to recognise sessions.

You can revoke your consent at any time with effect for the future by choosing ‘Decline’ in the cookie banner. On revocation, the cookies set by Matomo are deleted.