Privacy
Legal Documents

Privacy Policy

Last updated: May 2026 Language: English GDPR Compliant
01 — Controller

Who is responsible?

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

Hyksos GmbH

Mümlingstalstrasse 58

64760 Oberzent, Germany

Phone: +49 6068 7597866

Email: info@hyksos.gmbh

Website: https://initti.com

Managing Director: Özge Haskaya

Registration Court: Darmstadt · HRB 106415

VAT ID: DE368276191

If you have any questions about the processing of your personal data, please do not hesitate to contact us at any time.

02 — Data We Collect

What data do we collect?

We only collect and process personal data that is necessary for the operation of the app. This includes in particular:

  • Master data: Name, email address, and optionally phone number upon account registration
  • Language preference: Your preferred language setting in the app
  • Authentication data: Password (hashed, for account security), verification status (isVerified)
  • Usage data: IP address, browser type, operating system, pages visited, time spent
  • Device data: Device identifier, app version, operating system version
  • Communication data: Content of support requests and messages sent to us
  • Payment data: For paid services, payment data is processed through certified payment service providers
  • Technical log data: Error reports, crash logs, performance metrics

2.1 Identity Verification (optional)

If you choose to verify your account, the app uses your device camera to scan your identity document and read the machine-readable zone (MRZ) to obtain your ID number.

We do not store a photo of your ID and we do not store the readable ID number. Instead, we immediately create a non-reversible verification token (e.g. a cryptographic hash of the ID number) and store only that token together with your isVerified status — to prevent duplicate accounts and abuse.

03 — Purpose of Processing

Why do we use your data?

Your data is processed exclusively for the following purposes:

  • Providing and operating our app services and features
  • Creating and managing your user account
  • Optional identity verification to prevent multiple accounts and abuse
  • Customer support and responding to your enquiries
  • Improving and further developing our services
  • Detecting and preventing misuse and implementing security measures
  • Fulfilling legal obligations (e.g. bookkeeping requirements)
  • Sending information and updates — provided you have given your consent
05 — Data Disclosure

Who receives your data?

Your personal data will only be shared with third parties in the following cases:

  • Processors who assist us in providing our services (e.g. hosting providers, analytics services) — always on the basis of a data processing agreement
  • Payment service providers for the processing of transactions
  • Authorities where we are legally required to do so or entitled to enforce our rights
  • Third parties in the event of a business transfer or merger, provided that data protection rights are preserved

We do not sell your data to third parties.

06 — Retention Period

How long do we store your data?

We store personal data only for as long as necessary for the respective processing purposes, or as required by statutory retention obligations.

  • Account data: For as long as the account is active; upon deletion, data is promptly removed or anonymised
  • Verification data: Only the non-reversible token and isVerified status until verification is removed or the account is deleted; the readable ID number is discarded immediately after token creation
  • Log data: Typically 30–90 days
  • Business records: In accordance with statutory retention periods (generally 10 years)
  • Support communications: 3 years after the matter is closed

6.1 Account Deletion

You can delete your account at any time in the app under Profile → Settings → Delete Account. Once you confirm, we immediately deactivate your account and begin removing your personal data.

  • What we delete: Account profile data (name, email, language), authentication data, and app usage data linked to your account
  • Verification data: Until deletion is complete, we retain only the non-reversible verification token and the isVerified flag; these are then deleted as well
  • What we do not retain: We do not store any ID photo; the readable ID number is discarded immediately after token creation

If you cannot access the app, you may also request deletion by emailing info@hyksos.gmbh from your registered email address.

07 — Cookies

Cookies & Tracking

Our app and website use cookies and similar technologies for the following purposes:

  • Technically necessary cookies: Ensuring basic functionality and session management
  • Analytics cookies: Anonymised analysis of usage to improve our services (only with your consent)
  • Preference cookies: Storing your settings and language preferences

You can reject or delete cookies at any time via your browser settings. Please note that this may limit the functionality of our services.

08 — Your Rights

Your data protection rights

As a data subject, you have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR): You may request information about the personal data we hold about you
  • Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data
  • Right to erasure (Art. 17 GDPR): You may request the deletion of your data ("right to be forgotten")
  • Right to restriction (Art. 18 GDPR): You may request that processing be restricted
  • Right to data portability (Art. 20 GDPR): You may receive your data in a structured, machine-readable format
  • Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests
  • Right to withdraw consent: Any consent given may be withdrawn at any time with effect for the future
  • Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority

To exercise your rights, please contact us at info@hyksos.gmbh.

09 — Data Security

How do we protect your data?

We implement appropriate technical and organisational security measures to protect your data against unauthorised access, loss, or manipulation:

  • Encrypted data transmission via TLS/SSL
  • Encryption of sensitive data in the database
  • Access controls and role-based permissions for staff
  • Regular security audits and penetration tests
  • Privacy by Design principles embedded in our development process
10 — User Responsibility

Responsibility & Legal Framework

All transactions and activities within the app are carried out by users on their own responsibility. Users are required to comply with the laws of their respective countries.

initti.com / Hyksos GmbH accepts no liability for actions taken by users in violation of applicable law.

11 — Changes

Updates to this Policy

We reserve the right to update this Privacy Policy as needed to keep it in line with current legal requirements or changes to our services.

For significant changes, we will notify you by email or via a prominent notice within the app. The latest version is always available at initti.com/privacy.

The date of the most recent update can be found at the top of this page.

12 — Contact

Contact & Privacy Enquiries

We are happy to assist you with any questions or concerns regarding data protection:

Privacy Contact

Hyksos GmbH

Mümlingstalstrasse 58, 64760 Oberzent, Germany

Phone: +49 6068 7597866

Email: info@hyksos.gmbh

Website: https://initti.com

We process your requests within 30 days in accordance with GDPR requirements.