Privacy policy
Information pursuant to Article 13 GDPR on the processing of your personal data via veyrisk.com.
General
In accordance with Article 13 of the GDPR, we hereby provide you with information regarding the processing of your personal data via the website veyrisk.com and the veyrisk platform (hereinafter referred to as the "Website") and your rights in this regard. Personal data refers to any information relating to an identified or identifiable natural person.
Data controller
neonotu GmbHEdelsbergstraße 8
80686 München
Deutschland
Represented by: Armin Haller
Email: contact@veyrisk.com
Phone: +49 89 2000 7975 0
When visiting the website (server log files)
When you visit our website, your browser automatically stores information in log files. In particular, the following data is collected:
- IP address
- Date and time of the request
- Page requested
- Browser type and version
- Operating system
- Referrer URL
This data is technically necessary to display the website correctly and to ensure its stability and security. The data is stored for up to 14 days and then deleted, unless an analysis for security purposes is required.
The legal basis for data processing is Article 6(1)(f) of the GDPR (legitimate interest in the secure and stable operation of the website).
Audience measurement with Matomo
On the public pages of veyrisk.com we use the open-source web analytics tool Matomo, but only if you agree in the notice banner. Before that, nothing from Matomo is loaded and no cookie is set. There is no audience measurement in the customer area of the platform.
With your consent, Matomo records which pages are viewed and when, which page referred you to us, as well as browser, operating system, screen size and approximate region. If the address you open contains a campaign identifier, for example from an advertisement, this is recorded as well. Matomo sets cookies on your device for this purpose. Your IP address is shortened before analysis so that it can no longer be attributed to you.
The legal basis is your consent under Article 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw it at any time with effect for the future: change audience measurement setting.
We run Matomo on a server of creoline GmbH, Bergstraße 9a, 48341 Altenberge, Germany, under a data processing agreement pursuant to Article 28 GDPR. The data does not leave the EU.
Your choice of light or dark theme and your decision in the notice banner are stored by your browser in its local storage (localStorage). They are not transmitted to us.
Contact and demo form
When you fill in the contact or demo form, we collect the following data:
- Name
- Email address (business)
- Company name (optional)
- Domain for the free first scan (optional)
- Services you are interested in (optional)
- Content of the enquiry
This data is processed solely for the purpose of handling your enquiry and, where necessary, to contact you. The same applies if you contact us by email or phone. The data will be deleted once the enquiry has been fully processed, after 90 days at the latest, unless there are legal or other retention obligations.
Processing is carried out in accordance with Article 6(1)(b) of the GDPR, provided the enquiry relates to the implementation of pre-contractual measures; otherwise, in accordance with Article 6(1)(f) of the GDPR (legitimate interest in communicating with prospective customers).
Free first scan
If you enter a domain in the form, we check its publicly visible attack surface passively. We only evaluate publicly available information, such as DNS records, public certificate logs, TLS configuration and HTTP headers. No port scans and no login attempts take place.
The result is reviewed by our team and sent to you only. We keep it until your enquiry is settled, for 90 days at most.
Processing is carried out in accordance with Article 6(1)(b) of the GDPR (pre-contractual measures at your request).
Customer account and platform
To use the platform, you create a customer account. When you do so and while you use the platform, we process in particular:
- Registration and login data (name, email address, password stored only as a non-reversible hash, key for two-factor authentication)
- Company details and account settings
- The domains you add and their proof of ownership
- Scan results for your own verified domains
We only carry out active checks such as port scans and vulnerability scans (including OpenVAS) for domains whose ownership you have first proven via a DNS record.
Processing is carried out in accordance with Article 6(1)(b) of the GDPR for the performance of the contract. We store the data for the duration of the contractual relationship and delete it once it ends, unless there are legal retention obligations.
Payment processing
Payments are processed via Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, the Netherlands. Your payment data (e.g. card or account details) is processed by Mollie. We only receive status and reference data on the payment from Mollie, such as whether and when a payment was made.
Processing is carried out in accordance with Article 6(1)(b) of the GDPR for the performance of the contract and Article 6(1)(c) of the GDPR to meet legal retention obligations. For details, see Mollie's privacy policy at mollie.com/privacy.
Sending emails
We send emails, such as replies to your enquiry or notifications from the platform, via neonotu GmbH's own SMTP server. No external email service provider is involved.
Hosting and technical service providers
The website and the platform are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers located in Germany. This is done on the basis of a data processing agreement in accordance with Article 28 of the GDPR.
Processing by our hosting provider is carried out on the basis of Article 6(1)(f) of the GDPR (operation of a secure and reliable IT infrastructure).
Disclosure of data
Data will only be disclosed to third parties if this is necessary to process your enquiry or to perform the contract, or if we are legally obliged to do so. Recipients are the service providers named above (hosting, payment processing, operation of Matomo). No data is transferred to third countries outside the EU.
Your rights
You have the following rights at any time:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
Special note on the right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(f) of the GDPR. Where the processing is based on consent, this may be withdrawn at any time. To exercise your rights, simply send us an informal notification.
Data processing security
We implement technical and organisational measures to protect your data from loss, misuse or unauthorised access. Data is transmitted between your browser and our website in encrypted form (TLS).
Contacting the data protection supervisory authority
You have the right to lodge a complaint with a data protection authority. The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 18
91522 Ansbach
Validity and amendments
This privacy policy is currently in force. We reserve the right to amend this privacy policy where necessary due to changes in the law, technical developments or new features.
Last updated: September 2026