The German version is the canonical legal version. This English version is provided for convenience. Where legally permissible and the versions differ, the German version prevails.
1. Controller
The controller under the GDPR and other applicable data-protection laws is:
Fairtech Group
Owner: Andrii Rzhavin
Sole proprietorship / trade business
Bartholomäus-Arnoldi-Straße 6
61250 Usingen
Germany
Email: info@fairtech.group
VAT ID: DE369713138
Fairtech Group operates ENRIVAQ.
Fairtech Group acts as controller for its own processing, including registration, contracts, billing, security, support, website operation and business communications.
Where Fairtech Group processes personal data contained in Customer Data on behalf of a customer who determines the purposes and means of processing, Fairtech Group generally acts as processor. The Data Processing Addendum (“DPA”) applies to such processing.
2. Privacy contact and Data Protection Officer
Privacy requests may be sent to info@fairtech.group.
No Data Protection Officer is currently appointed. Based on the current organizational structure, the general appointment threshold under Section 38(1) sentence 1 BDSG is not met. Statutory special cases requiring a DPO regardless of headcount remain unaffected.
3. Processing principles
We process personal data only where there is a legal basis and for defined purposes.
ENRIVAQ is primarily designed for product, catalog and technical data. Processing personal data is not the main purpose of the platform.
4. Website access and server logs
When you access our website or public services, we may process technical data such as IP address, date/time, requested URL, referrer where transmitted, browser/device data, HTTP status, technical errors and security/abuse signals.
We use this data to deliver the service, maintain security and availability, troubleshoot errors and prevent misuse.
The legal basis is Article 6(1)(f) GDPR and, where necessary for a contract, Article 6(1)(b) GDPR.
Security and session logs are generally retained for up to 90 days. Logs associated with a confirmed security incident may be retained for up to 12 months or until the investigation is completed.
5. Cookies and similar technologies
We use strictly necessary cookies and similar technologies where required to provide a service expressly requested by the user, including session/login state, security/CSRF protection, basic preferences and consent status.
Where Section 25(2) TDDDG applies, no consent is required for strictly necessary access. Subsequent personal-data processing is based, depending on purpose, on Article 6(1)(b) or (f) GDPR.
Optional analytics, marketing or personalization technologies are activated only after consent.
The legal basis is Section 25(1) TDDDG together with Article 6(1)(a) GDPR.
Consent is collected through our own consent banner. Users may reject optional categories and later withdraw or change consent through Cookie Settings.
When a request form is available, we set a first-party, strictly necessary security identifier for up to 90 days to enforce form limits and prevent misuse. It is not used for advertising, cross-site tracking or external profiling.
6. Google Analytics
We use Google Analytics only after prior consent.
For EEA users, the provider is generally:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
We use Google Analytics to understand website usage and improve navigation and content.
Depending on configuration, data may include page views, interactions, device/browser information, approximate location information, consent status and online identifiers.
We do not intentionally send Customer Data, catalog content, passwords, payment data or contact-form contents to Google Analytics.
The legal basis is consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
7. Contact forms
We provide Contact, Contact Sales and Book Demo forms.
Depending on the form, we may process name, business email, company, role, reason for contact, catalog type/size, message, industry, SKU count, product type, current PIM/ERP/ecommerce system, current problem, desired result and an optional example SKU.
The data is stored in ENRIVAQ’s own database and forwarded to the responsible team by email.
The legal basis is Article 6(1)(b) GDPR for pre-contractual requests and, for business contacts where appropriate, Article 6(1)(f) GDPR.
Leads that do not become customers are generally deleted six months after the last substantive contact unless another lawful retention ground applies.
To prevent repeated misuse of request forms, we use a first-party security identifier and a pseudonymous browser signature together with hashed email and IP identifiers. For support and manual unblocking, the submitted email and visitor IP are retained encrypted and shown only to authorized administrators; the raw browser fingerprint is never stored. No external fingerprinting provider is used. Security records are retained for up to 90 days. If a request is blocked incorrectly, contact info@fairtech.group.
8. Newsletter and marketing email
We do not currently operate a general newsletter through the website.
We send requested communication, contractual messages, registration/security notices, billing/payment information and service/support communication.
If a newsletter is introduced, it will use a separate lawful basis and, where required, voluntary consent and double opt-in.
9. Accounts
For ENRIVAQ accounts, we may process name, business email, verification status, E.164 phone number, organization, language, time zone, date/time format, role, organization membership, password hash, Google OAuth identity, MFA status, active sessions, security IP/user-agent logs and accepted legal-document versions.
Passwords are not stored in plaintext.
Legal basis: Article 6(1)(b) GDPR; security logging may additionally rely on Article 6(1)(f) GDPR.
Account/profile data is generally retained for the contract term plus up to 30 days. Contract/evidence records may be retained longer under applicable law.
10. Google OAuth
If Google OAuth is used, we receive identity information released for the requested scopes, typically a unique identifier, email address and basic profile information.
Legal basis: Article 6(1)(b) GDPR.
11. Billing and payment data
We process name/billing address, business information, VAT ID where provided, customer-specific quote and order information, confirmed catalog volume where linked to the account, invoices, payment status, transaction references and account-level billing information.
Legal bases are Article 6(1)(b) and (c) GDPR.
Invoices/accounting records are generally retained for eight years. Business correspondence is generally retained for six years.
12. Stripe
We use Stripe for payment processing.
For accounts outside North and South America, the contractual party under current Stripe terms is generally Stripe Payments Europe, Limited, Ireland.
Stripe may process payment and transaction information and may act as processor or independent controller depending on the activity.
We do not store complete card details where payment is processed directly by Stripe.
Stripe may process data through global infrastructure and, under its current framework, relies on mechanisms including the EU-US Data Privacy Framework and Standard Contractual Clauses for relevant transfers.
13. Customer Data
ENRIVAQ primarily processes product/catalog information including SKU, OEM/MPN, EAN/GTIN, titles, descriptions, technical attributes, categories/taxonomies, URLs/public sources, product documents where provided, compatibility/reference data, customer-specific schemas/rules and SEO/content fields.
Customer Data may contain limited business contact data where the customer has a lawful basis and it is necessary for the project.
ENRIVAQ is not intended for unrelated private personal data or special-category data.
14. Special categories
ENRIVAQ is not intended for intentional processing of special-category data under Article 9 GDPR.
Such data must not be uploaded without a separate written agreement, lawful-basis review, any required DPIA and additional safeguards.
15. AI processing
ENRIVAQ uses its own AI/model infrastructure for product-data processing, including structured processing, normalization, classification, validation and content generation.
Customer Data is not sent to external LLM providers such as OpenAI, Anthropic or Google to provide ENRIVAQ AI processing.
Customer Data is not used to train general-purpose models without a separate explicit agreement.
16. Hosting and primary data location
Primary ENRIVAQ infrastructure and Customer Data, databases, files, backups and primary application data are operated/stored in Germany under the current deployment model.
We use Hetzner Online GmbH and our own servers in Germany.
This statement relates to primary Customer Data storage. Supporting payment, analytics, security or network providers may have additional processing locations.
17. Cloudflare
We use Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA for network, DNS, CDN and security functions.
Cloudflare may process technical connection, security and metadata and, depending on routing, transient request data.
Our legal basis is Article 6(1)(f) GDPR based on security, availability and attack prevention.
18. Recipients
Personal data may be made available, where necessary, to hosting/infrastructure providers, network/CDN/security providers, payment providers, analytics providers after consent, email/communication providers, professional advisers and public authorities where legally required.
Access is limited to what is necessary.
19. Internal access
Only authorized persons receive access to personal data and Customer Data where required.
We apply role-based access and least privilege.
20. International transfers
Our core Customer Data architecture is based in Germany.
Supporting providers may involve processing outside the EEA.
Any restricted transfer is carried out only where Articles 44 et seq. GDPR are satisfied, for example through adequacy decisions, EU-US DPF participation where applicable, Standard Contractual Clauses and supplementary measures where required.
Information about safeguards may be requested at info@fairtech.group.
21. Retention
| Data | Standard retention |
|---|---|
| Account/profile | contract term + up to 30 days |
| Customer/Product Data | contract term; export window up to 30 days; working copies removed/anonymized within up to another 30 days |
| Leads without contract | 6 months after last substantive contact |
| Security/session logs | 90 days |
| Incident-related logs | up to 12 months or end of investigation |
| Backups | rotation up to 90 days |
| Invoices/accounting | generally 8 years |
| Business correspondence | generally 6 years |
| Contract/consent evidence | applicable statutory evidence/limitation period |
22. End of contract and deletion
After termination, access is disabled.
A customer may request an available data export within 30 days.
Working copies are then generally deleted or irreversibly anonymized within up to another 30 days.
Backup copies expire through rotation within 90 days unless lawful retention applies.
23. Automated decisions
ENRIVAQ does not make solely automated decisions about natural persons that produce legal or similarly significant effects.
It is not used for credit, employment, insurance or comparable person scoring.
24. Security
We use technical and organizational measures including TLS, HSTS in customer/admin areas, encryption at rest, password hashing, secret protection, role-based access, tenant isolation, MFA for privileged roles, session management, logs, backups, monitoring, incident response and patch/dependency management.
25. Data-subject rights
Subject to statutory conditions, individuals may have rights to access, rectification, erasure, restriction, portability, objection, withdraw consent and lodge a complaint.
Requests: info@fairtech.group
26. Supervisory authority
For Fairtech Group’s location, the relevant authority is:
The Hessian Commissioner for Data Protection and Freedom of Information
Wilhelmstraße 7
65185 Wiesbaden
Germany
27. Updates
We may update this policy to reflect changes in law, services, technology or providers.
Last updated: 18 September 2026