Legal

Privacy policy

How this website handles personal data under the GDPR. Version 1.7 — 2026-10-11.

Auf Deutsch lesen (verbindliche Fassung)

This is a courtesy translation. The German version is the authoritative one.
Overview. This website uses no cookies and stores no information on your device. It loads neither external fonts nor content from third-party servers. We run our own script for anonymous analytics on the same server in Germany as the website. We also process the data your browser sends when it requests a page and the information you send when contacting us. For our application Freiday at freiday.octabits.io, see section 12; for the public demo at approval.octabits.io, section 5.

1. Controller

DK2 Ventures UG (haftungsbeschränkt)
Uhlbacher Str. 34
70329 Stuttgart
Germany

Represented by Daniel Hartmann. Email: mail@dk2.eu · Phone: +49 711 25294236

We have not appointed a data protection officer; we are not required to under Art. 37 GDPR or § 38 BDSG.

2. Hosting and server log data

This website is a set of static files delivered by a server we operate ourselves. The server sits in a data centre run by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. A processor agreement under Art. 28 GDPR is in place with the data centre operator.

When you open a page, your browser transmits data that is processed in server log files in order to deliver it, in particular:

  • your IP address,
  • the date and time of the request,
  • the page or file requested and the amount of data transferred,
  • the HTTP status and referring URL,
  • your browser and operating system as reported by the user agent string.

This data is needed to deliver the requested pages and keep the website operating securely. The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in delivering a functioning, secure website. We do not merge this data with other sources.

Retention: log data is temporarily written to the web server process’s standard output. We do not collect, archive or analyse it. It is discarded no later than the next restart of that process.

Transfer to a third country: this website is delivered exclusively from servers in Germany; no transfer to a third country takes place in doing so.

3. Cookies, analytics and tracking

This website uses no cookies, local storage or fingerprinting. It does not access information on your device within the meaning of § 25 TDDDG. We therefore do not need consent for this purpose and do not display a cookie banner.

For analytics we use Umami, an open-source analytics application that we run ourselves. It operates on the same servers in Germany as the website (section 2). No external analytics provider is involved. Your browser loads the measurement script from analytics.reynt.co and reports page views there. This address belongs to our own server, where we analyse visits to our websites. We record:

  • the page requested and the referring page,
  • your browser, operating system and device type as reported by the user agent,
  • your screen size and browser language setting,
  • the country, region and city derived from your IP address,
  • clicks on external links and file downloads, particularly the two CV PDFs.

The IP address is not stored. So that several requests on the same day count as one visit, the software derives an anonymous session identifier on the server from the IP address, the user agent and the domain; the IP address itself is discarded, and only the characteristics listed above remain. We do not assign user identifiers, create profiles or track visitors across websites. This data is not combined with other data sources.

The legal basis is Art. 6 (1) (f) GDPR, our legitimate interest in knowing which content gets read without recognising or following the people who read it. Because we operate the software ourselves, no processor is involved in analytics and no data is passed to any third party; processing and storage happen exclusively on our servers in Germany, and there is no transfer to a third country.

Objecting: you can prevent analytics requests by blocking analytics.reynt.co in your browser or content blocker. We do not use an opt-out cookie. Your right to object under Art. 21 GDPR applies independently of this option (section 9).

4. External content

We do not load fonts, scripts, stylesheets, images, maps, videos or other embedded content from third-party servers. The website and the analytics script described in section 3 are delivered by our own servers. Text is displayed using fonts already installed on your device.

This website contains external links, including links to GitHub, npm and reynt.co. If you follow one, the destination site’s privacy policy applies. We have no control over its data processing.

5. Public demo at approval.octabits.io

At approval.octabits.io we run a public demo of our software: the approval of a software product by information security and data protection, prepared by an agent and signed by two people. Every organisation, person and vendor in it is invented. Please do not enter real personal data there.

Your own copy. "Start the demo" makes the server create a copy of the demo that only you can see. It is reached through a random identifier kept in a cookie; you give no name, no email address and no password. The copy is deleted automatically, with everything you entered or uploaded in it, 24 hours after you started it; the deletion runs every hour, so the copy is gone after 25 hours at the latest.

What is processed:

  • the server log data described above; the application's own log shortens your IP address before writing it (for IPv4, to its first three blocks);
  • your IP address in counters that limit how many copies can be started and how many sign-ins attempted from one address — deleted two hours after the last request at the latest;
  • IP address and user agent in the demo's sign-in session, deleted with your copy;
  • whatever you enter or upload in the demo, deleted with your copy.

Cookies. The demo sets strictly necessary cookies only: demo_sandbox (the identifier of your copy, 24 hours), __Secure-better-auth.session_token (signing in as one of the invented people) and, only if you switch the language, locale (one year). The demo cannot work without them; no consent is required under § 25(2) No. 2 TDDDG. The demo does no reach measurement and loads nothing from third-party servers.

No AI providers. The steps an "agent" performs in the demo are done by a fixed, scripted model on our own server. Nothing from the demo is sent to an AI provider or any other third party; the application has no access to the internet.

Legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in showing our software and protecting the demo from abuse.

Retention: as above — the copy for 25 hours at most, the counters for two hours at most. The copies live in a database that exists only inside the demo application itself; it is not backed up and copied nowhere. If the application restarts, every copy is gone at once. Processing takes place exclusively on servers in Germany; there is no transfer to a third country.

6. Contacting us

There is no contact form. If you email or call us, we process the contact details and the content of your message in order to answer it. The legal basis is Art. 6 (1) (b) GDPR where your enquiry relates to a contract or its initiation, and otherwise Art. 6 (1) (f) GDPR, our legitimate interest in responding to enquiries addressed to us.

You are not legally or contractually required to provide your data (Art. 13 (2) (e) GDPR). However, we cannot answer your enquiry without the information needed to handle it.

Email provider: our mailbox is operated by Fastmail Pty Ltd, Melbourne, Australia, and the data is stored on servers in the United States. Fastmail processes the content and traffic data of your message as a processor under Art. 28 GDPR. There is no adequacy decision for Australia, and we do not rely on the EU-U.S. Data Privacy Framework here — the transfer rests on Standard Contractual Clauses under Art. 46 (2) (c) GDPR. A copy of the safeguards is available on request via the contact details above.

We keep correspondence for as long as it is needed to deal with the matter, and beyond that only where statutory retention periods under commercial and tax law require it (generally six or ten years under § 257 HGB and § 147 AO). Email is transmitted between servers using TLS, but it is not end-to-end encrypted. Please consider this when sending confidential information.

7. Recipients

Personal data from this website reaches only:

  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) as the operator of the data centre our server sits in — see above and section 5;
  • Fastmail Pty Ltd (Melbourne, Australia) as the operator of our mailbox — see above.

There are no other recipients. We do not disclose data to advertising networks or data brokers, or carry out profiling.

8. Automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15),
  • have inaccurate data corrected (Art. 16),
  • have data erased (Art. 17) or its processing restricted (Art. 18),
  • receive your data in a portable format (Art. 20),
  • object at any time to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21), and
  • withdraw any consent you have given, with effect for the future (Art. 7 (3)).

To exercise any of these, write to mail@dk2.eu.

10. Complaints to the supervisory authority

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart.

11. Changes to this policy

We update this policy when the data processing described here changes. The current version and date appear at the start of the policy.

12. Freiday (freiday.octabits.io)

At freiday.octabits.io we run Freiday: someone with an account connects their calendars and shares, by link, when they are busy and when they are free. The controller is the company named in section 1. This section covers Freiday; sections 2 to 7 concern this website and the demo only. Your rights and the right to complain (sections 9 and 10) apply to Freiday as well.

12.1 Your account

  • Email address — to sign you in with a code sent by email, and for messages about your account (for example when a connected calendar can no longer be reached). Freiday asks for nothing else about you, such as a name.
  • Passkeys, if you add one: the public key and the name you give it. The private key never leaves your device.
  • Sign-in sessions: an identifier, the expiry and the browser identification (user agent). Your IP address is not stored with a session.
  • Settings: time zone, working hours, language and what counts as busy.

The legal basis is Art. 6 (1) (b) GDPR: without this data we cannot provide Freiday to you.

12.2 Your calendars

You connect calendars with a calendar link (ICS), a CalDAV account (such as iCloud with an app-specific password) or by signing in at Google or Microsoft. We store the credentials — the link, the username and app password, or the access tokens Google or Microsoft issue — encrypted, and the names of your calendars too.

From your calendars Freiday takes busy times only: start, end, whether the time is busy, tentative or free, and whether it is all-day — for the past 7 and the coming 56 days. Freiday does not store titles, places, attendees or descriptions. At Google, Freiday asks only for your free/busy times and the list of your calendars; at Microsoft, only the start, end, all-day flag and status of your events. A calendar link or CalDAV delivers whole events instead; Freiday reads only the busy times from them and discards everything else at once, without storing it.

Freiday's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Freiday uses that data only to show you and the recipients of your links when you are busy, shares it with no one, and uses it neither for advertising nor to train AI models.

Google, Microsoft, Apple and other calendar services are not our processors here: you choose them and give Freiday access yourself. The data held there is governed by your agreement with that provider. You can end Freiday's access at any time, at the provider or with “Remove” in Freiday.

The legal basis is Art. 6 (1) (b) GDPR.

12.3 Blocks, links and their recipients

Times you block by hand are stored with a label if you give one (encrypted). For each link you share, Freiday stores the recipient's name and a note if you enter them (both encrypted), the expiry and the window; and the names of your presets (encrypted).

Whoever opens a link sees, inside its window, when you are busy and when you are free, your note and your time zone — no event details. About the people who open a link, Freiday stores for each view only the time, the browser family and the device class (such as “Safari · mobile”), so you can see whether your link was opened. The full browser identification and the IP address are not stored, and the page sets no cookies. To protect Freiday from overload, it counts requests per IP address and minute; these counters are deleted after about ten minutes at the latest. The legal basis for this data is Art. 6 (1) (f) GDPR; the legitimate interest is showing the link's owner whether it was opened and protecting the service from misuse.

12.4 Agents you connect

You can connect Freiday to an AI agent you use yourself (over the Model Context Protocol). Such an agent can read your busy times and links and propose links; a link exists only once you approve it — otherwise the proposal lapses after 24 hours. Freiday records which agent called which function for you (arguments as identifiers only), digests of what went to the agent, and every approval in a tamper-evident log — without names. What the agent does with the data it reads is governed by your agreement with its provider, who is not our processor. Freiday itself uses no AI model.

12.5 Hosting, email and operations

  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) operates the data centres Freiday and its database run in — in Germany only. A data processing agreement under Art. 28 GDPR is in place.
  • Sendinblue SAS (Brevo) (106 boulevard Haussmann, 75008 Paris, France) sends Freiday's emails (sign-in codes and notices about your account) and receives your email address and the message for that, as a processor under Art. 28 GDPR.

Freiday's operational logs, traces and metrics stay in our own system at Hetzner. Before they are written, Freiday removes credentials and email addresses from them and cuts IP addresses to their network. They are deleted after 30 (logs), 7 (traces) and 90 days (metrics).

The database is backed up daily. The backups are kept for 30 days in Hetzner's object storage in Germany; we keep an encrypted copy for up to 24 months on a backup system of our own. Deleted data remains in the backups until they expire.

Freiday uses no analytics, no tracking and no advertising, and loads nothing from third-party servers.

12.6 Cookies and browser storage

Freiday sets only what it needs to work: the sign-in cookie of your session, a cookie for at most ten minutes while you sign in at Google or Microsoft that secures the way back to Freiday, and two markers in the browser's session storage — whether you have just signed in, and whether Freiday should offer you a passkey. No consent is required for these under § 25 (2) no. 2 TDDDG. The page a link opens sets no cookies.

12.7 Retention and deletion

  • Busy times are replaced every time Freiday syncs with your calendar.
  • Expired or revoked links are deleted with their views 30 days after they end.
  • Notices in the bell are deleted after 90 days.
  • Everything else Freiday keeps until you delete your account.

“Delete my account” (Settings → Account) deletes your data and destroys the key it was encrypted with. What remains is only the evidence of approvals, agent calls and your requests under Art. 15 and 17 GDPR — identifiers and outcomes, no names and no content — which we keep to meet our accountability obligation (Art. 5 (2), Art. 6 (1) (c) GDPR).

Your rights in Freiday: “Download my data” (Settings → Account) gives you everything Freiday stores about you in one file (Art. 15 and 20 GDPR); “Delete my account” exercises your right to erasure (Art. 17 GDPR). For anything else, write to mail@dk2.eu (section 9).


Further legal information: Imprint · Datenschutzerklärung (verbindlich)