Your data, explained.
What we process when you visit vinishu.io - and on what basis.
This privacy policy applies to the website vinishu.io (the "Website"). It explains which personal data we process when you visit this Website, for what purposes, on what legal basis, and for how long. Separate privacy notices apply to our product (bot and fraud detection) and to the customer dashboard.
1. Controller
The controller for the data processing on this Website is:
Vinishu GmbH
Zu den Fuchshöhlen 8, 99098 Erfurt, Germany
Represented by Managing Director Jannes Spiegel
E-mail: info@vinishu.io
We have not appointed a data protection officer, as we are not legally required to do so. For any data protection matters, you can reach us at info@vinishu.io.
2. Your rights
With regard to your personal data, you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
Where you have given consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR). This does not affect the lawfulness of processing carried out before the withdrawal.
Right to object: Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation (Art. 21 GDPR).
Right to complain: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI), Erfurt - www.tlfdi.de. You may also contact the supervisory authority where you reside.
3. Accessing the Website / hosting
This Website is hosted by Vercel Inc., USA. When the Website is accessed, technically necessary data is processed in order to deliver the site securely and reliably. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and efficient provision). A data processing agreement (Art. 28 GDPR) is in place with Vercel. Regarding the transfer to the USA, see section 9.
4. Server log files
On each access, the system automatically collects data that your browser transmits:
- IP address
- date and time of access
- page/file requested and referrer URL
- browser type and version, operating system
- volume of data transferred and status code
This data serves delivery, stability, and security (e.g. detecting and preventing attacks). Legal basis: Art. 6(1)(f) GDPR. The log data is retained by our host (Vercel) only for a short period - depending on the plan, between one hour and a few days - and is then deleted.
5. Cookies and consent
We use cookies and comparable technologies. We set strictly necessary cookies without consent; all non-necessary (in particular analytics) cookies are set only if you have consented via our cookie banner. By default, everything is disabled ("default-deny"). You can change or withdraw your decision at any time via "Cookie settings" in the footer.
| Cookie | Purpose | Category | Lifetime |
|---|---|---|---|
vn_consent | stores your cookie decision | necessary | 12 months |
NEXT_LOCALE | stores your language preference | necessary | up to 1 year |
_ga | Google Analytics - distinguishing visitors | analytics (consent) | 2 years |
_ga_<id> | Google Analytics - session state | analytics (consent) | 2 years |
Depending on the configuration, Google Analytics may set additional cookies; the cookies actually set in your browser are authoritative.
Legal basis for necessary cookies: Section 25(2) TDDDG and Art. 6(1)(f) GDPR (legitimate interest in the technical provision and functionality of the Website). For analytics cookies: Section 25(1) TDDDG and your consent under Art. 6(1)(a) GDPR.
Categories in the cookie banner: Besides "Analytics", our banner offers the categories "Marketing" and "Functional". We currently set no cookies or comparable technologies in either of these categories; they are reserved for possible future use. Your selection there is stored only in our consent record (see below). Should we use marketing or functional cookies in future, we will do so only after your consent and will update this privacy policy accordingly.
Record of your consent (consent log): To demonstrate compliance with consent requirements, we log your decision (time, the choice made, your browser identifier (user agent), a technical transaction ID, and a value derived from your IP address by hashing). The IP address itself is not stored. We compute the hash with a secret key and the current date. Entries from different days therefore cannot be linked through it. The hash is pseudonymous, not anonymous: with the secret key, it could be matched to an IP address. We keep that key secret. We retain this record for up to 3 years. Legal basis: Art. 6(1)(c) in conjunction with Art. 5(2) and Art. 7(1) GDPR.
6. Analytics
Google Analytics 4 (with consent)
With your consent, we use Google Analytics 4 (GA4), a service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA). GA4 helps us understand how the Website is used and improve it.
- Consent control: GA4 loads only after your consent. We use Google Consent Mode v2 with the default set to "denied"; without consent, no analytics cookies are set and no analytics data is sent. Until you consent, the Google library (gtag.js) is not loaded, so no connection to Google is established.
- Data processed: pseudonymous usage data such as approximate location (country/region), device and browser information, and interactions on the Website. GA4 does not store the IP address; it is used only transiently for coarse location.
- Automatically collected events ("Enhanced Measurement"): page views, scrolls, outbound clicks, site search, form interactions, video interactions, and file downloads. Form field contents are not collected; detected e-mail addresses are automatically removed from URLs.
- Google Signals: is disabled. There is no cross-device association with Google accounts and no advertising or demographic analysis.
- Retention at Google: 14 months.
- Legal basis: your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw it at any time via "Cookie settings".
- Third-country transfer: when GA4 is used, data may be transferred to Google LLC in the USA (see section 9). A data processing agreement is in place with Google.
Vercel Web Analytics (cookieless)
We also use Vercel Web Analytics, a reach-measurement service of our host Vercel Inc. (USA). The service measures Website usage (e.g. page views, approximate origin, device type) without setting cookies and without cross-device recognition. From technical connection data (including the IP address), only an anonymous, non-reversible value is derived; the IP address itself is not stored.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly reach measurement). As the service is cookieless and does not access information on your device, no consent under Section 25 TDDDG is required.
- Retention: no personal data is permanently stored for this purpose; Vercel retains the anonymous, aggregated statistics for a limited period in line with the applicable plan.
- Third country: the provider is Vercel Inc., USA (see section 9).
7. Contacting us
If you use our contact form or send us an e-mail, we process the data you provide in order to handle your request. The form collects: your name, e-mail address, and the URL of your website (required), plus - optionally - your company name and your message.
- Purpose: handling and responding to your request, and where applicable initiating a business relationship.
- Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (handling general enquiries).
- Abuse protection: to prevent spam and automated submissions, we limit how frequently the form can be submitted per IP address. Legal basis: Art. 6(1)(f) GDPR.
- Technical data: with each request we also store your IP address and browser identifier (user agent) for security and abuse-prevention purposes. Legal basis: Art. 6(1)(f) GDPR.
- Storage & access: requests are stored in our own database (currently within the EU); only authorized team members have access via our internal dashboard.
- E-mail delivery: for notification and reply e-mails we use the e-mail service of 1&1 IONOS SE, Germany.
- Retention: we store requests until they have been fully processed and delete them at the latest 12 months after the last contact, unless a contractual relationship arises. If a contractual relationship arises, the statutory retention periods apply.
- Obligation to provide: providing the data is voluntary. However, without the data required to handle your request (in particular a means of contacting you), we cannot respond to it.
8. Bot Check
8.1 Data processed
When you use the Bot Check, we process the address of the website to be checked, your name, the name of your company and your email address. These details are mandatory. We also process the fact that you confirmed the terms for the Bot Check and consented to email contact under section 8.5, in each case which version and when, as well as the language in which you used the page. With your request, our web server also transmits your IP address and your browser identifier (user agent).
We store your request twice:
- As a contact request in our inbox: name, company, email address, website address, IP address and browser identifier, plus a note on the check, the terms, the consent and the language.
- As the record of the check: name, company, email address, the address of the checked website, the confirmation of the terms and the consent, each with version and time, the language and a hash value derived from your IP address, which is re-"salted" daily (pseudonymous, as described in section 5). The record does not contain the IP address itself.
We store the result of the check together with the record.
8.2 How the check works
Our web server (Vercel, section 3) transmits the details from the form to our backend, where we store them in our own database (currently within the EU). An automated browser then retrieves the publicly accessible pages of the website specified. The result relates to the checked website: the forms found, their field types, detected protective measures, the addresses of the pages they appear on and our assessment.
To assess the forms found, we use the AI model "Jev" of TypeSafe AI, Inc., San Francisco (USA). For each form found, we transmit its structure to TypeSafe: the type and technical names of its fields, the labels of its buttons and the area of the page it sits in. We add the address and title of a page on which the form appears and an excerpt of up to 600 characters of that page's visible text. So that the browser visits pages with forms first, we also transmit the addresses and link texts of links on the checked website, the names of its subdomains and the title of its home page. We do not transmit field contents. Nor do we transmit your name, your company, your email address or your IP address. If a checked page contains personal data of third parties, such as names in a legal notice or on a contact page, this data may be included in the text excerpts and link texts.
While the check is running and when you later retrieve the result, your browser connects directly to our backend. In doing so, we process your IP address in order to deliver the result and to limit the number of retrievals. The result can be accessed for 30 days via a link containing a randomly generated identifier. Anyone who knows this link can view the result.
8.3 Purposes and legal bases
We process your details in order to carry out the check and provide you with the result. If you use the Bot Check yourself as a contracting party, the legal basis is Art. 6(1)(b) GDPR. If you act for a company, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest then lies in carrying out the check that the company requested through you.
We store who requested a check and confirmed the terms so that we can prove this to the operator of a checked website or to authorities and defend against claims. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in being able to demonstrate that a check was requested by a person authorised to do so.
We limit the number of requests per IP address, email address and domain in order to protect the Bot Check against misuse and overload. The legal basis is Art. 6(1)(f) GDPR.
Our team receives a summary of each request by email and may write to you about your request, for example if there are questions about the result. The legal basis is Art. 6(1)(b) and (f) GDPR. We only send you marketing emails on the basis of your consent under section 8.5.
We process personal data of third parties that appears on a checked page on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in carrying out the check requested by the operator of the website. We do not analyse this data separately and do not use it for any other purpose.
8.4 Obligation to provide data
We need the mandatory details in order to carry out the Bot Check and to be able to prove who requested it. Without them, we cannot carry out a check.
The consent under section 8.5 is also a prerequisite for the Bot Check. We do not charge money for the Bot Check. What you give in return is your consent to us emailing you. The form says so too, right at the tick box. Without this consent, we do not carry out a Bot Check. You can use our contact form (section 7) and all other content on this Website without this consent.
8.5 Consent to email contact
In the form, you consent to Vinishu GmbH writing to you at the email address you provided: about your result, about bot protection and fraud prevention, and about its products and offers. The tick box for this is not pre-ticked and is separate from the confirmation of the terms. No other company writes to you on the basis of this consent.
Before we send you the first email on the basis of this consent, we ask you by email to confirm it via a link (double opt-in). This ensures that nobody enters someone else's address. If you do not confirm, we do not write to you on the basis of this consent.
The legal basis is your consent under Art. 6(1)(a) GDPR and Section 7(2) no. 2 of the German Act against Unfair Competition (UWG). Your consent remains valid until you withdraw it, at most for the period stated in section 8.7. You can withdraw it at any time with effect for the future, via the unsubscribe link in every email we send you on the basis of this consent, or informally at info@vinishu.io. A withdrawal does not affect a check already carried out or your result page. It has no other disadvantage for you. We store the proof of your consent on the basis of Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
8.6 Recipients
In addition to the services listed in section 9, TypeSafe AI, Inc., San Francisco (USA), receives the information on the checked website described in section 8.2. TypeSafe processes it on our behalf under a data processing agreement pursuant to Art. 28 GDPR. TypeSafe and its sub-processors process the data in the USA. TypeSafe has contractually committed not to use the data to train AI models without our consent. We do not give that consent. Under its terms, TypeSafe may derive technical usage data such as logs and statistics from the requests. TypeSafe may also analyse the requests to detect abuse and to comply with legal obligations. To the extent TypeSafe processes personal data for these purposes, TypeSafe is itself responsible for it. TypeSafe does not state a fixed retention period. Under the data processing agreement, TypeSafe stores the data for as long as the purpose of the processing and statutory periods require. We send the summaries to our team and our emails to you via 1&1 IONOS SE.
8.7 Retention
We delete the contact request in our inbox, i.e. name, company, email address, website address, IP address and browser identifier, 12 months after the request.
We delete the record of the check (section 8.1) and the result four years after the request. The result page can no longer be accessed via the link as early as 30 days after the check. The four years cover the regular limitation period of three years (Sections 195 and 199 of the German Civil Code, BGB). This period only starts at the end of the year in which a claim arose. A claim that arises in January is therefore only time-barred almost four years later. For that long, we need to be able to show who requested a check and which consent we received with it.
We use your consent under section 8.5 until you withdraw it, at most until we delete the record after four years. After a withdrawal, we note it so that we do not send you any further emails. The legal basis for this is Art. 6(1)(f) GDPR. We keep the proof of your consent and of any withdrawal for as long as the record of the check.
If a contractual relationship arises from your request, the statutory retention periods apply.
9. Recipients and transfers to third countries
We share personal data only with carefully selected processors with whom an agreement under Art. 28 GDPR is in place. Section 8.6 sets out what TypeSafe may additionally use data for under its own responsibility. We do not sell data or share it for third-party advertising.
Services used:
- Vercel Inc. (USA) - hosting of the Website, server logs, and Vercel Web Analytics
- Google Ireland Limited / Google LLC (Ireland/USA) - Google Analytics 4
- Google Cloud (EU region) - infrastructure/database, including for contact and consent data
- 1&1 IONOS SE (Germany) - e-mail delivery
- TypeSafe AI, Inc. (USA) - assessment of the forms found by the Bot Check using the AI model "Jev" (sections 8.2 and 8.6)
Transfers to third countries: the personal Website data (contact and consent data) is currently processed exclusively within the EU. For the Bot Check, we transmit the information on the checked website described in section 8.2 to TypeSafe AI, Inc. in the USA. TypeSafe is not certified under the EU-US Data Privacy Framework. We therefore base this transfer on the EU Standard Contractual Clauses (Module 2, Art. 46(2)(c) GDPR). They form part of our data processing agreement with TypeSafe. Using Google services (Google Analytics and Google Cloud) and hosting with Vercel may involve a transfer of personal data to the USA or to US companies. We base such transfers on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the respective recipient is certified, on the adequacy decision for the EU-US Data Privacy Framework. You can obtain a copy of the EU Standard Contractual Clauses, or further information about the safeguards relied upon, on request at info@vinishu.io.
Note: As our infrastructure expands, processing may in future also take place in further countries outside the EU. In that case we will base transfers on appropriate safeguards (in particular EU Standard Contractual Clauses) and update this privacy policy accordingly.
10. Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on this Website. The assessment in the Bot Check, including where it is produced with the AI model "Jev" (section 8.2), relates to the checked website and has no legal or similarly significant effect on you.
11. Data security
We take technical and organizational measures to protect your data, including TLS encryption of the connection and security measures at the server and application level.
12. Changes to this privacy policy
We update this privacy policy when our data processing changes or when legal requirements make it necessary.
In case of discrepancies, the German version prevails.