---
title: "Privacy Policy | Calinora"
description: "How Calinora handles personal data on calinora.io and checkout.calinora.io, including cookies, checkout, and contact form processing."
url: "https://www.calinora.io/privacy-policy/"
robots: "noindex, nofollow"
---

# Privacy Policy

**Last updated:** 7 September 2026

**Data Controller:**\
Calinora - Julian Bergner\
Gartenweg 18, 96215 Lichtenfels, Germany\
E-Mail: <support@calinora.io>\
VAT ID: DE457214166

A Data Protection Officer has not been appointed, as the conditions under Art. 37 GDPR and § 38 of the German Federal Data Protection Act are not met.

This Privacy Policy explains how Calinora (“we”, “us”, “Provider”) collects, processes, and protects personal data when you visit our website, use our checkout process, or interact with our services. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection law.

This policy applies to the websites at calinora.io (including the www, docs and blog subdomains), to our checkout and license services at checkout.calinora.io and license.calinora.io, to the agent binary download service at downloads.calinora.io, to the backend that receives contact form submissions, and to related services such as licensing, billing, and customer support.

## 1. Data We Collect and Process

### 1.1 Contact Form Inquiries

When you use the contact form on our product page, we collect:

- **Name** (required) - to identify you in our communications.
- **Work email address** (required) - to respond to your inquiry.
- **Company name** (required) - to understand your business context.
- **Role** (required) - to provide more relevant responses.
- **Message** (optional) - to understand your request.

The submission is transmitted to our contact form backend hosted on Microsoft Azure (Section 2.4), which delivers it as an email via Azure Communication Services (Section 2.5) to our support mailbox at <support@calinora.io>, hosted by Microsoft 365 (Exchange Online). Submissions are not stored in any other database.

**Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). Where the inquiry relates to a potential contractual relationship, Art. 6(1)(b) GDPR (pre-contractual measures) may additionally apply.

### 1.2 Checkout and Payment Data

When you purchase a Subscription (via Stripe Checkout for the Trial and Standard plans, or through a direct Enterprise onboarding process), the following data is collected and processed, depending on the plan (the free Trial collects only your name and email address; billing address and VAT ID are collected for paid plans):

- **Name and email address** - for license issuance and billing.
- **Company name and billing address** - for invoicing and tax compliance (paid plans).
- **VAT identification number** (if provided) - for reverse charge processing (paid plans).
- **Payment information** (credit card or other payment method) - processed exclusively by Stripe; we do not store or have access to full payment card details.
- **Subscription details** - selected plan, billing period, and number of licensed brokers.

After checkout, Stripe transmits to us your email address, your Stripe customer, subscription and invoice identifiers, and the purchased quantity, which we use to issue your License Key.

**Legal basis:** Art. 6(1)(b) GDPR (performance of contract).

### 1.3 License Management Data

When a License is issued, we store:

- **License key metadata** - license ID, plan type, issue and expiry dates, broker count, and the issued License Key itself (which embeds your email address as the licensee identifier together with the invoice and subscription identifiers).
- **Contact and billing identifiers** - the email address the License was issued to and, for Enterprise Licenses, the company name.
- **Subscription identifiers** - to link the License to the billing relationship.
- **Automated renewal credentials** - unique tokens used by the Software to securely retrieve updated License Keys during an active Subscription, without requiring manual intervention (Standard and Enterprise plans).
- **Internal notes** - for Enterprise Licenses we may record short internal notes about the contract (for example the order form reference).

This data is necessary to issue, manage, and renew License Keys.

**Legal basis:** Art. 6(1)(b) GDPR (performance of contract).

### 1.4 Server Log Data

When you access our website, checkout service, license service or download service, our hosting providers (Microsoft Azure and, for proxied requests, Cloudflare) may automatically collect:

- IP address (full IP addresses may be temporarily retained in raw server logs for security and abuse prevention purposes)
- Date and time of access
- Requested URL and referrer
- Browser type and operating system
- HTTP status code and data volume transferred

Our checkout, license and contact form backends additionally write application logs (Azure Application Insights) that may include the email address associated with a license issuance and, for failed bot-protection checks, the submitting IP address. These logs are used solely for troubleshooting and abuse prevention.

This data is processed for security purposes and to ensure the stable operation of our website and services.

**Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in IT security and website stability).

### 1.5 Bot Protection Data

When you open a page that contains a form protected by Cloudflare Turnstile, and again when you submit it, your IP address, browser metadata and interaction signals may be processed to verify that the submission is human-initiated. No personally identifying data beyond what is described in Section 2.3 is collected for this purpose. Cloudflare Turnstile does not use cookies for tracking purposes.

**Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in protecting forms against automated abuse).

### 1.6 Email Correspondence

When you contact us directly by email (for example at <support@calinora.io>), or when we correspond with you in the course of an Enterprise onboarding or contract negotiation, we process the personal data contained in that correspondence: your name, email address, company and role where stated, and the content of the messages. This data is stored in our support mailbox, hosted by Microsoft 365 (Exchange Online), and is used solely to handle your request and to prepare, conclude and perform the contract.

**Legal basis:** Art. 6(1)(b) GDPR (pre-contractual measures and performance of contract) where the correspondence relates to a Subscription or a prospective Subscription; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).

## 2. Third-Party Services

### 2.1 Stripe (Payment Processing)

We use **Stripe, Inc.** (and its European entity, Stripe Payments Europe, Ltd.) to process payments. When you complete a purchase, your payment data is transmitted directly to Stripe. We do not store or process your full credit card details. Stripe acts as a data processor on our behalf for the processing of payment transactions we initiate. For its own fraud prevention, regulatory compliance, and financial reporting purposes, Stripe also processes data as an independent data controller. We have entered into a Data Processing Agreement with Stripe in accordance with Art. 28 GDPR.

Stripe’s privacy policy: <https://stripe.com/privacy>

**Legal basis:** Art. 6(1)(b) GDPR (performance of contract).

### 2.2 Cloudflare (Hosting and Security)

Our website is served through **Cloudflare, Inc.** for content delivery, DDoS protection, and performance optimisation. Cloudflare may process IP addresses and request metadata as part of its services. We have entered into a Data Processing Agreement with Cloudflare in accordance with Art. 28 GDPR.

Cloudflare’s privacy policy: <https://www.cloudflare.com/privacypolicy/>

**Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in website security and performance).

### 2.3 Cloudflare Turnstile (Bot Protection)

We use **Cloudflare Turnstile** on the contact form on our product page to protect it against automated abuse and spam. The Turnstile widget is loaded from challenges.cloudflare.com when a page containing the contact form is opened; Cloudflare then processes your IP address, browser metadata and interaction signals to determine whether the visitor is human. When you submit the form, our backend forwards the Turnstile response token and your IP address to Cloudflare for verification. Cloudflare Turnstile does not use cookies for tracking purposes. Cloudflare Turnstile is covered under the Data Processing Agreement with Cloudflare described in Section 2.2.

**Legal basis:** Art. 6(1)(f) GDPR (legitimate interest in protecting forms against abuse).

### 2.4 Microsoft Azure (Infrastructure)

Our website (static files), checkout service, license service, agent binary downloads and contact form backend are hosted on **Microsoft Azure** (Azure Storage static websites and Azure Functions) in Microsoft Azure data centres in the European Union (West Europe and Germany West Central regions). Requests are routed through Cloudflare (Section 2.2) before reaching Azure. License records, subscription data, and checkout session data are stored in Azure Table Storage; application logs are stored in Azure Application Insights (Section 1.4). We have entered into a Data Processing Agreement with Microsoft Corporation in accordance with Art. 28 GDPR, which governs Microsoft’s processing of personal data on our behalf.

Microsoft’s privacy statement: <https://privacy.microsoft.com/privacystatement>

**Legal basis:** Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in reliable infrastructure).

### 2.5 Transactional Emails

Transactional emails (contact form delivery to our support mailbox, license key delivery, license re-send) are sent through **Azure Communication Services Email**, a Microsoft Azure service, from a calinora.io sender address. The Azure Communication Services resource we use has its data location in Europe, so the content of these emails - for contact form submissions the data you entered, and for license emails your email address and License Key - is processed by Microsoft within the European Union. Billing notifications, invoices and payment receipts are sent by Stripe. No other email delivery service is used. License emails contain your License Key, subscription identifier and, for Standard and Enterprise plans, the license fetch token; treat them as confidential. The processing of your email address for these purposes is covered by the data processing arrangements described in Sections 2.1 and 2.4.

## 3. Cookies and Tracking

Our website does not use tracking cookies, advertising cookies, or third-party marketing pixels. We do not engage in cross-site tracking or behavioural advertising.

The following strictly necessary cookies may be set when you use our website and checkout service. These cookies are essential for security, infrastructure, or transactional functionality and do not require separate consent under the ePrivacy Directive.

### 3.1 Cloudflare Security Cookies

Because our website is served through Cloudflare (see Section 2.2), Cloudflare may automatically set the following cookies on proxied requests:

- **`__cf_bm`** - distinguishes automated traffic from human visitors (Bot Management). Duration: 30 minutes, refreshed on activity.
- **`_cfuvid`** - identifies individual clients behind shared IP addresses for rate limiting. Session cookie.
- **`__cfruid`** - used internally by Cloudflare for request differentiation. Session cookie.
- **`cf_clearance`** - records that a visitor has successfully passed a Cloudflare security challenge. Set only when a challenge is triggered.

These cookies are set and managed by Cloudflare, not by our application. They serve exclusively security and infrastructure purposes.

### 3.2 Cloudflare Turnstile

Cloudflare Turnstile (see Section 2.3) may use session-scoped browser storage to verify that form submissions are human-initiated. This does not involve persistent tracking cookies.

### 3.3 Checkout State Cookie

During the purchase flow on checkout.calinora.io, our checkout service sets a **`checkout_state`** cookie. This cookie is used to verify the integrity of the checkout session and prevent cross-site request forgery. It is `HttpOnly`, scoped to the checkout API path, and short-lived. A matching server-side record (a random session token and the Stripe Checkout session identifier, without any personal data) is kept to validate the return from Stripe.

### 3.4 Stripe Cookies

Stripe (see Section 2.1) may set strictly necessary cookies during the checkout process to enable payment functionality and fraud prevention. These cookies are managed by Stripe and are required for the payment service to function.

### 3.5 Local Storage

Our website stores your theme preference (light, dark, or system) in your browser’s local storage under the key `calinora-theme`. Local storage is not a cookie and is not transmitted to our servers.

Because all cookies used on our website are strictly necessary for security or transactional functionality, no cookie consent banner is required and none is displayed.

## 4. Data Retention

- **Contact form data:** Retained for up to 12 months after the inquiry has been concluded, and deleted thereafter unless a contractual relationship is established, in which case the data becomes subject to the contractual and legal retention periods described below.
- **Billing and invoice data:** Retained for the legally required period under German tax and commercial law (currently 10 years pursuant to § 147 of the German Fiscal Code, § 257 of the German Commercial Code).
- **License management data:** Retained for the duration of the Subscription. After termination, license records that form part of billing documentation are retained for the legally required period (10 years per § 147 of the German Fiscal Code / § 257 of the German Commercial Code). License data not required for billing or legal compliance is deleted within 12 months after Subscription end.
- **Checkout session state records:** Deleted no later than 30 days after the checkout attempt.
- **Server and application log data:** Automatically deleted no later than 90 days after collection, unless retention is required for a specific security investigation.

## 5. International Data Transfers

Our service providers Stripe, Cloudflare and Microsoft are US companies or have US parent companies and process some data outside the European Economic Area (EEA), in particular in the United States. Such transfers are based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework, under which Stripe, Inc., Cloudflare, Inc. and Microsoft Corporation are certified. In addition, our contracts with these providers include the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a fallback safeguard.

Our backend infrastructure and data stores on Microsoft Azure, including the Azure Communication Services resource used for transactional email (Section 2.5), are located in the European Union (West Europe and Germany West Central regions, and the Europe data location for Communication Services, see Section 2.4). Microsoft’s global operations may involve support access from outside the EEA, which is safeguarded under our Data Processing Agreement with Microsoft and the transfer mechanisms described above.

## 6. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encrypted data transmission (TLS), access controls, and secure hosting infrastructure.

## 7. No Processing of Customer Application Data

Our Software (Calinora Pilot) is self-hosted and operated entirely within the Customer’s own infrastructure. We do not host, operate, or manage the Software on behalf of customers. We have no access to and do not process any data from the Customer’s Kafka clusters, application environment, or infrastructure. No data processing agreement is required between us and the Customer for the operation of the Software.

The Software does not send telemetry, usage statistics, crash reports, cluster metadata, or any customer data to us. Validation of License Keys is performed offline. The Software contacts our servers in only two optional situations: (a) if automatic license fetching is enabled, it sends the subscription ID and the fetch token to license.calinora.io at the configured interval (default hourly) and receives the current License Key in return; (b) if the Pilot Agent feature is enabled and no local agent binary directory is configured, it downloads agent binaries from downloads.calinora.io at startup. In both cases our infrastructure receives the connection metadata described in Section 1.4 (in particular the IP address of the Software instance). We do not store fetch timestamps or IP addresses in license records. Both calls can be disabled by supplying the License Key via `LICENSE_STRING` and the agent binaries via a local directory, in which case the Software makes no connection to us at all.

**Legal basis:** Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in secure software distribution).

## 8. Your Rights Under GDPR

You have the following rights regarding your personal data:

- **Right of access** (Art. 15 GDPR) - You may request information about the personal data we hold about you.
- **Right to rectification** (Art. 16 GDPR) - You may request correction of inaccurate personal data.
- **Right to erasure** (Art. 17 GDPR) - You may request deletion of your personal data, subject to legal retention obligations.
- **Right to restriction of processing** (Art. 18 GDPR) - You may request that we restrict the processing of your data in certain circumstances.
- **Right to data portability** (Art. 20 GDPR) - You may request a copy of your data in a structured, commonly used, machine-readable format.
- **Right to object** (Art. 21 GDPR) - You may object to the processing of your data where we rely on legitimate interests as the legal basis.
- **Right to withdraw consent** (Art. 7(3) GDPR) - Where processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal.

We do not engage in automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

The provision of your name, email address, company name, and billing details is a contractual requirement necessary for the conclusion and performance of the Subscription agreement. If you do not provide this information, we will be unable to enter into or perform the contract.

To exercise any of these rights, please contact us at <support@calinora.io>.

## 9. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Calinora is:

Bavarian State Office for Data Protection Supervision\
Promenade 18, 91522 Ansbach, Germany\
Website: <https://www.lda.bayern.de>

## 10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Changes will be posted on this page with an updated revision date. For material changes to this Privacy Policy, we will notify existing customers by email at least 30 days before the changes take effect. We encourage you to review this policy periodically.

## Contact

If you have any questions about this Privacy Policy or your personal data, please contact us at <support@calinora.io>.
