Who is responsible?
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Hyksos GmbH
Mümlingstalstrasse 58
64760 Oberzent, Germany
Phone: +49 6068 7597866
Email: info@hyksos.gmbh
Website: https://initti.com
Managing Director: Özge Haskaya
Registration Court: Darmstadt · HRB 106415
VAT ID: DE368276191
If you have any questions about the processing of your personal data, please do not hesitate to contact us at any time.
What data do we collect?
We only collect and process personal data that is necessary for the operation of the app. This includes in particular:
- Master data: Name, email address, and optionally phone number upon account registration
- Language preference: Your preferred language setting in the app
- Authentication data: Password (hashed, for account security), verification status (isVerified)
- Usage data: IP address, browser type, operating system, pages visited, time spent
- Device data: Device identifier, app version, operating system version
- Communication data: Content of support requests and messages sent to us
- Payment data: For paid services, payment data is processed through certified payment service providers
- Technical log data: Error reports, crash logs, performance metrics
2.1 Identity Verification (optional)
If you choose to verify your account, the app uses your device camera to scan your identity document and read the machine-readable zone (MRZ) to obtain your ID number.
We do not store a photo of your ID and we do not store the readable ID number. Instead, we immediately create a non-reversible verification token (e.g. a cryptographic hash of the ID number) and store only that token together with your isVerified status — to prevent duplicate accounts and abuse.
Why do we use your data?
Your data is processed exclusively for the following purposes:
- Providing and operating our app services and features
- Creating and managing your user account
- Optional identity verification to prevent multiple accounts and abuse
- Customer support and responding to your enquiries
- Improving and further developing our services
- Detecting and preventing misuse and implementing security measures
- Fulfilling legal obligations (e.g. bookkeeping requirements)
- Sending information and updates — provided you have given your consent
On what basis do we process data?
The processing of your personal data is based on the following legal grounds under the GDPR:
- Art. 6(1)(a) GDPR – Consent (e.g. for newsletters or cookies)
- Art. 6(1)(b) GDPR – Performance of a contract or pre-contractual measures
- Art. 6(1)(c) GDPR – Compliance with a legal obligation
- Art. 6(1)(f) GDPR – Legitimate interests (e.g. security, fraud prevention)
Who receives your data?
Your personal data will only be shared with third parties in the following cases:
- Processors who assist us in providing our services (e.g. hosting providers, analytics services) — always on the basis of a data processing agreement
- Payment service providers for the processing of transactions
- Authorities where we are legally required to do so or entitled to enforce our rights
- Third parties in the event of a business transfer or merger, provided that data protection rights are preserved
We do not sell your data to third parties.
How long do we store your data?
We store personal data only for as long as necessary for the respective processing purposes, or as required by statutory retention obligations.
- Account data: For as long as the account is active; upon deletion, data is promptly removed or anonymised
- Verification data: Only the non-reversible token and isVerified status until verification is removed or the account is deleted; the readable ID number is discarded immediately after token creation
- Log data: Typically 30–90 days
- Business records: In accordance with statutory retention periods (generally 10 years)
- Support communications: 3 years after the matter is closed
6.1 Account Deletion
You can delete your account at any time in the app under Profile → Settings → Delete Account. Once you confirm, we immediately deactivate your account and begin removing your personal data.
- What we delete: Account profile data (name, email, language), authentication data, and app usage data linked to your account
- Verification data: Until deletion is complete, we retain only the non-reversible verification token and the isVerified flag; these are then deleted as well
- What we do not retain: We do not store any ID photo; the readable ID number is discarded immediately after token creation
If you cannot access the app, you may also request deletion by emailing info@hyksos.gmbh from your registered email address.
Your data protection rights
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15 GDPR): You may request information about the personal data we hold about you
- Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data
- Right to erasure (Art. 17 GDPR): You may request the deletion of your data ("right to be forgotten")
- Right to restriction (Art. 18 GDPR): You may request that processing be restricted
- Right to data portability (Art. 20 GDPR): You may receive your data in a structured, machine-readable format
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests
- Right to withdraw consent: Any consent given may be withdrawn at any time with effect for the future
- Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority
To exercise your rights, please contact us at info@hyksos.gmbh.
How do we protect your data?
We implement appropriate technical and organisational security measures to protect your data against unauthorised access, loss, or manipulation:
- Encrypted data transmission via TLS/SSL
- Encryption of sensitive data in the database
- Access controls and role-based permissions for staff
- Regular security audits and penetration tests
- Privacy by Design principles embedded in our development process
Responsibility & Legal Framework
All transactions and activities within the app are carried out by users on their own responsibility. Users are required to comply with the laws of their respective countries.
initti.com / Hyksos GmbH accepts no liability for actions taken by users in violation of applicable law.
Updates to this Policy
We reserve the right to update this Privacy Policy as needed to keep it in line with current legal requirements or changes to our services.
For significant changes, we will notify you by email or via a prominent notice within the app. The latest version is always available at initti.com/privacy.
The date of the most recent update can be found at the top of this page.
Contact & Privacy Enquiries
We are happy to assist you with any questions or concerns regarding data protection:
Privacy Contact
Hyksos GmbH
Mümlingstalstrasse 58, 64760 Oberzent, Germany
Phone: +49 6068 7597866
Email: info@hyksos.gmbh
Website: https://initti.com
We process your requests within 30 days in accordance with GDPR requirements.