Skip to content
  • Products
  • Custom software
  • Pricing
  • Contact
DEEN
Sign in
Contact us
  • Products
  • Custom software
  • Pricing
  • Contact
  • Sign in
  • Deutsch

Privacy policy

Effective: 5 October 2026

This translation is provided for convenience. The German version is legally binding.

Contents

  1. Controller
  2. Summary
  3. Hosting and server logs
  4. Analytics (Umami)
  5. Contact form and email
  6. Customer account and single sign-on
  7. Payments (Stripe / Link)
  8. Self-hosted installations and updates
  9. Newsletter
  10. Cookies and local storage
  11. Your rights
  12. Changes

Controller

Cyrellian Studios, owner Cedric Schmitt
Gabelsbergerstraße 13, 63069 Offenbach am Main, Germany
studio@cyrellian.com

We have not appointed a data protection officer because we are not required to. For privacy questions, write to us at the address above.

Summary

  • We use no tracking or advertising cookies and never pass data on for advertising.
  • We measure reach with a self-hosted, cookieless analytics tool (Umami) that does not store your IP address.
  • Our products run on your side: whatever you store in a self-hosted installation is processed by you, not by us.
  • Payments are handled by Link (Stripe) as seller; we never see card details.

Hosting and server logs

The website, customer accounts and the update service run on servers in Germany operated by: netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Deutschland (privacy notice). We have a data processing agreement with the provider (Art. 28 GDPR).

When you visit our pages, the web server processes technically necessary data: IP address, date and time, requested address, referrer, browser identifier and status code. This serves secure and stable operation (Art. 6(1)(f) GDPR). Logs are deleted after 14 days at the latest unless they are needed longer to investigate a specific security incident.

Analytics (Umami)

We use Umami, an open-source analytics tool we run ourselves on our own server, on this website, on plazello.com and on our documentation sites (docs.cyrellian.com, docs.plazello.com, docs.docsello.com). Umami sets no cookies and stores no IP addresses. Visits are counted via a daily-rotating, irreversible hash; no person can be identified from it and visits on different days cannot be linked. We record pages viewed, referrers, campaign parameters, coarse device and browser information, country and clicks on important buttons (e.g. “See pricing”, “Buy”). The data never leaves our server. The legal basis is our legitimate interest in improving our offering (Art. 6(1)(f) GDPR). If your browser sends “Do Not Track”, nothing is measured. In customer accounts we only measure page views of the purchase flow, and nothing at all in the operator console.

Contact form and email

When you write to us via the contact form or by email, we process your name, email address, optionally your company and your message in order to answer your request (Art. 6(1)(b) GDPR for requests relating to a contract, otherwise (f)). To prevent abuse we store an irreversible hash of your IP address, not the address itself. Requests are deleted 12 months after receipt at the latest unless statutory retention obligations require longer storage.

We receive and send email via Microsoft Exchange Online: Microsoft Ireland Operations Limited (Microsoft Exchange Online), One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Irland (privacy notice). We have a data processing agreement with Microsoft. Data may be transferred to the USA on the basis of the EU-US Data Privacy Framework, under which Microsoft is certified, and the EU standard contractual clauses.

Customer account and single sign-on

For a customer account on account.cyrellian.com we process your email address, name, a password (only as a secure hash), optional two-factor sign-in data, sign-in sessions and your licences, purchases and linked installations. When you sign in to one of our products with your account (single sign-on), we transmit your identifier, email address, name and permissions to that product. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). We log security-relevant events with the IP address ((f)). We keep the data until you delete your account, and purchase records beyond that for the statutory retention periods (up to 10 years).

Payments (Stripe / Link)

We sell paid licences through Stripe Managed Payments. The seller towards you (merchant of record) is Link, a Stripe service: Stripe Technology Europe, Limited (Link), The One Building, 1 Grand Canal Street Lower, Dublin 2, D02 H210, Irland (privacy notice). Stripe processes payment, invoice and tax data as an independent controller. From Stripe we receive name, email address, country, the item purchased, the amount and the payment status in order to unlock your licence (Art. 6(1)(b) GDPR). We never receive card details. Stripe may transfer data to the USA; Stripe is certified under the EU-US Data Privacy Framework.

Self-hosted installations and updates

Installations of our products run on your infrastructure; you process the data stored there under your own responsibility. If an installation is linked to your account, it regularly contacts our update service and transmits its installation identifier, licence token, product version and the server's IP address. We use this data to check licences and provide matching, signed updates (Art. 6(1)(b) GDPR).

Newsletter

If you subscribe to our newsletter, we send it via Mailjet: Mailjet SAS, 13-13 bis, rue de l'Aubrac, 75012 Paris, Frankreich (privacy notice). We process your email address and the time of your sign-up and confirmation (double opt-in) on the basis of your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time via the link in every issue; we then remove your address from the mailing list.

Cookies and local storage

We only store what is technically required for the function you request (Section 25(2) no. 2 TDDDG); no consent is needed for this:

  • “cy-lang” (cookie, 1 year): the language you chose for this website.
  • “cy-mode” (local storage): your choice between light and dark mode, if you make one.
  • Session cookies in customer accounts: keep you signed in and protect forms against abuse.

We serve fonts from our own server; no connection is made to Google or any other font provider.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to withdraw consent with effect for the future (Art. 7(3)). Just write to us at the address above.

Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation.

You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit.

Changes

We update this policy when our services or the law change. The version published on this page applies. See also: Imprint, Terms.

Cyrellian Studios builds software for online shops and documentation, and custom software for businesses.

Cyrellian Studios · Cedric Schmitt
Gabelsbergerstraße 13, 63069 Offenbach am Main, Germany
studio@cyrellian.com
VAT ID DE452561038

Products

  • Plazello
  • Docsello
  • Custom software
  • Pricing

Company

  • Contact
  • Imprint

Legal

  • Terms
  • Privacy
  • Cancellation & refunds

Customers

  • Sign in
  • Documentation

© 2026 Cyrellian Studios

DEEN