Legal & Trust

Transparency, privacy, and operational safeguards.

Find our imprint, privacy policy, and notes on cookies/analytics, security, and data processing.

Imprint

Amyla · Noël Sabosch

Stadtweg 87
24837 Schleswig
Germany

VAT ID: DE278802588
Responsible for content: Noël Sabosch

Privacy policy

Last updated: 23 July 2026

This privacy policy explains which personal data we process on this website and for what purposes.

Controller

The controller is Amyla · Noël Sabosch, Stadtweg 87, 24837 Schleswig, Germany. Contact: info@amyla.net.

Hosting and server logs

We operate the application, public load balancing, and database with UpCloud Oy, Aleksanterinkatu 15 B, 7th floor, 00100 Helsinki, Finland, in UpCloud data centre DE-FRA1 in Frankfurt am Main, Germany. UpCloud processes this data as our processor.

When you access the website, we process technically necessary data to deliver the site, keep it secure, and investigate errors. This includes in particular:

  • IP address
  • date and time of access
  • requested URL or page/file
  • referrer URL
  • user agent / browser and system information
  • response status and transferred data volumes

Server and proxy logs on our hosting infrastructure are generally deleted or overwritten after no more than 30 days. If a specific security incident or error occurs, affected log data may be retained for longer until the investigation and any necessary legal enforcement have been completed. It is then deleted unless a statutory obligation requires further retention. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operating a secure and stable website).

Contact requests and email

If you contact us via the contact form or email, we process the data you provide, for example:

  • name
  • email address
  • message / project context
  • optional: budget range

The contact form creates an email that is sent through the European SMTP endpoint of AhaSend B.V., Willem Fenengastraat 16, 1096 BN Amsterdam, the Netherlands. AhaSend processes sender and recipient details, message content, and delivery metadata. Complete message content is not retained by AhaSend beyond the processing required for immediate transmission. Technical delivery metadata is retained for seven days. The message is delivered to our mailbox provided through Google Workspace by Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland. Google Workspace is not loaded directly in your browser, but it stores the contact request received by us.

Processing is necessary to respond to your enquiry and take steps prior to entering into a contract under Art. 6(1)(b) GDPR. Where an enquiry does not concern a potential contract, processing is based on our legitimate interest in handling business communications under Art. 6(1)(f) GDPR.

Your name, email address, and message are required for processing a request submitted through the contact form; providing a budget range is voluntary. Without the required details, we cannot process the request through the form.

Protection against automated submissions

To protect the form against automated abuse, we use the self-hosted open-source software ALTCHA. The web component and computational logic are delivered exclusively from our servers. Our server at UpCloud creates a signed computational challenge that your browser solves locally as proof of work. The solution is then verified exclusively by our Laravel application.

In this configuration, ALTCHA does not set a cookie, use local browser storage, evaluate interaction signals, or send a request to an ALTCHA Sentinel, SaaS, or CDN service. Only the connection data technically required for delivery and verification and the computed solution are processed. To prevent reuse, a one-way value derived from the challenge signature is stored in our cache until the challenge expires, for no longer than ten minutes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and spam).

Error analysis with Laravel Nightwatch

We use Laravel Nightwatch, provided by Laravel Holdings Inc., 60 Broad Street, 24th Floor, #1559, New York, NY 10004, USA, to identify technical errors and performance problems. Monitoring data is stored in the EU data region selected by us.

In captured execution contexts, Nightwatch may process the request method, full URL including query parameters, IP address, technical request headers, response status, data volumes and timings, as well as exception, stack-trace, and log data. SQL query text and, for outgoing HTTP requests, the method, URL, status, and data volume may also be captured. For sent emails, the installed Nightwatch module captures the mailable class, subject, number of recipients and attachments, duration, and technical status, but neither the message content nor recipient addresses. Request content capture is disabled; sensitive headers such as cookies and authorisation data are redacted.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in error analysis, IT security, and reliable operation).

Retention period

  • Server and proxy logs: generally no more than 30 days; in the event of a specific security incident or error, where necessary until the investigation and any required legal enforcement have been completed
  • ALTCHA replay prevention: no longer than ten minutes
  • Nightwatch monitoring data: generally no more than 30 days
  • Pirsch analytics data: until deleted from the Pirsch account; separately stored user-agent data for no longer than three months according to the provider
  • AhaSend: technical delivery metadata for seven days; complete message content is not retained beyond the processing required for immediate transmission
  • Contact requests in Google Workspace: until final processing; beyond that only where statutory retention obligations or the establishment, exercise, or defence of legal claims require it

Recipients and processors

We use processors only where necessary for hosting, web analytics, email delivery, mailbox operation, or technical monitoring. These include UpCloud Oy, Emvi Software GmbH, AhaSend B.V., Google Cloud EMEA Limited, and Laravel Holdings Inc. ALTCHA runs exclusively on our UpCloud infrastructure and is not an external recipient.

UpCloud processes our application data in Frankfurt, Pirsch is operated in Germany, and AhaSend uses its European SMTP endpoint in Germany for our mail delivery. With Google Workspace and Laravel Nightwatch, processing by US companies or access from the USA cannot be completely excluded. Where a provider or subprocessor processes data in a third country, we rely, depending on the provider, on an adequacy decision, in particular the EU-US Data Privacy Framework, and/or on European Commission Standard Contractual Clauses under Art. 44 et seq. GDPR.

For more information, see the UpCloud Privacy Notice, the Pirsch Privacy Policy, the AhaSend Privacy Notice, the Google Privacy Policy, and the Laravel Nightwatch Privacy Policy.

Your rights

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent with effect for the future where processing is based on consent (Art. 7(3) GDPR)

To exercise your rights, an informal message to info@amyla.net is sufficient. We do not use solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular the Independent State Centre for Data Protection Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.

Email: info@amyla.net

Cookies & server-side web analytics

We use cookies only where they are necessary for the technical operation of the website. We do not set analytics, marketing, or consent cookies.

Essential cookies

  • amylanet_session: contains a random session identifier and maintains the session required for navigation, forms, and security features; retained for 120 minutes after the last activity
  • XSRF-TOKEN: contains a security token that protects forms against cross-site request forgery; retained for 120 minutes

These cookies are required to provide the website requested by you. The legal bases are Art. 6(1)(f) GDPR and Section 25(2)(2) TDDDG. As there are no cookies requiring consent or comparable access to your device, no consent banner is required.

Cookie-free web analytics with Pirsch

We use Pirsch Analytics, provided by Emvi Software GmbH, Nickelstraße 1b, 33378 Rheda-Wiedenbrück, Germany, as our processor to measure audience reach and improve the website. Analytics is performed exclusively server-side; no Pirsch script is loaded in your browser, and Pirsch does not place cookies or other information on your device.

When a page is viewed, our server sends the requested full URL, IP address, user agent, language preference, any technical client hints supplied by the browser, and referrer to Pirsch. We do not request additional client hints such as the operating system version, device model, or viewport size through response headers or the User-Agent Client Hints JavaScript API. Pirsch processes this data to derive information including the visited path, referrer and UTM parameters, time, language, browser, operating system, device type, and approximate country and city.

Pirsch uses the IP address, user agent, date, and a website-specific salt to create a non-reversible visitor ID. According to the provider, the IP address is neither stored nor logged; visitors can be recognised for no longer than 24 hours and cannot be recognised across websites. Separately stored user-agent data is deleted after no more than three months.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is privacy-conscious audience measurement and the improvement of our website. As Pirsch neither accesses information on your device nor stores information there, consent under Section 25(1) TDDDG is not required. You may object to this processing on grounds relating to your particular situation under Art. 21 GDPR by emailing info@amyla.net.

Liability & copyright

Liability for content

We aim to keep information accurate and up to date. However, we do not warrant the correctness, completeness, or timeliness of the content.

Liability for links

This website may contain links to external sites. We have no control over their content; the respective provider is responsible for linked pages.

Copyright

Content and works created on this website are subject to copyright. Reproduction, modification, and distribution require prior written permission unless permitted by law.

Security Commitments

We operate systems with “security by default” in mind and apply appropriate technical and organisational measures to protect data and infrastructure.

  • transport encryption (HTTPS/TLS)
  • kept-up-to-date software and dependency updates
  • access controls on a need-to-know basis
  • monitoring to detect outages and abuse

If you’d like to report a vulnerability, please email a description (including reproduction steps). We’ll respond as quickly as possible.

Email: info@amyla.net

Data Processing

For client engagements, we can provide a data processing agreement (DPA) under Art. 28 GDPR on request.

  • Transparent list of service providers/subprocessors on request
  • Defined technical and organisational measures (TOMs)
  • Support for data subject requests, incident handling, and deletion/return at the end of the engagement

Details are aligned per engagement and system landscape.

Email: info@amyla.net