Jump to content
Supercharge Your
Invision Community Website

Premium Invision Community apps for payments, analytics, SEO, and automation. Built for operators who want more from their platform.

Privacy Policy

Privacy Policy

Effective date: April 9, 2026
Last updated: July 17, 2026

At XENNTEC UG (haftungsbeschränkt) ("XENNTEC", "we", "us", "our"), accessible from https://xenntec.com and https://my.xenntec.com, one of our main priorities is the privacy of our visitors and customers. This Privacy Policy describes what information we collect, how we use it, and your rights under the EU General Data Protection Regulation (GDPR).

If you have questions about this Privacy Policy, contact us at [email protected].

1. Data Controller

XENNTEC UG (haftungsbeschränkt)
Westerbuchberg 79
83236 Übersee
Deutschland

E-Mail: [email protected]
Commercial Register: Amtsgericht Traunstein, HRB 30728
VAT ID: DE351727590

2. What Information We Collect

2.1 Account Registration (my.xenntec.com)

When you create an account on our customer portal, we collect:

  • Display name / username
  • Email address
  • Password (stored hashed, never in plain text)
  • IP address at registration and login
  • Browser and device information

2.2 Purchases and Payments

When you purchase products through our store, we collect:

  • Billing information (name, address, country) for tax calculation
  • Transaction records (product, amount, date, payment status)
  • License keys generated and associated with your account

Payment processing is handled by third-party providers. We do not store your credit card numbers, bank account details, or cryptocurrency wallet addresses. See Section 7 for details on payment processors.

2.3 Server Log Files

When you visit xenntec.com or my.xenntec.com, our servers automatically collect:

  • IP address
  • Browser type and version
  • Operating system
  • Referrer URL
  • Date and time of access
  • Pages requested

This data is used for security monitoring and is not linked to personal accounts. Log files are deleted after statistical analysis.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure and stable operation.

2.4 Contact by Email

If you contact us via email, we store your name, email address, and message content to process your inquiry. This data is deleted once the inquiry is resolved, unless legal retention obligations apply.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest).

3. Cookies

3.1 Landing Page (xenntec.com)

Our landing page does not use cookies. We use your browser's localStorage to remember your theme preference (light/dark mode). This data is stored locally in your browser and is never transmitted to our servers.

3.2 Customer Portal (my.xenntec.com)

Our customer portal uses the following essential cookies that are required for core functionality and cannot be rejected:

  • ips4_member_id — stores the member ID of the currently logged-in user
  • ips4_login_key — saves the session identifier
  • ips4_IPSSessionFront — contains your current session ID
  • ips4_loggedIn — identifies if you are logged in (used by caching)
  • ips4_device_key — stores the device identifier
  • ips4_hasJS — identifies if JavaScript is enabled in the browser
  • ips4_cookie_consent — stores your cookie consent preferences
  • ips4_cookie_consent_optional — stores the opt-in status for guests
  • ips4_guestTermsDismissed — identifies when the guest terms bar has been dismissed
  • ips4_noCache — ensures output is not cached when needed
  • ips4_lastSearch — stores the last search timestamp
  • ips4_clearAutosave — stores editor identifiers to truncate auto-saved content
  • ips4_oauth_authorize — temporarily stores session data for third-party login
  • ips4_forumpass_* — tracks authentication for password-protected areas
  • ips4_cm_reg — stores an invoice ID during registration purchases
  • ips4_location — stores estimated location for tax calculation
  • ips4_currency — stores the currency selected by the member
  • ips4_guestTransactionKey — identifies guests viewing pending transactions

Legal basis: Art. 6(1)(f) GDPR — these cookies are strictly necessary for the operation of the portal.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our websites and services
  • Process purchases, generate license keys, and manage your account
  • Communicate with you regarding support, updates, and account matters
  • Calculate and apply applicable taxes
  • Detect and prevent fraud, abuse, and unauthorized access
  • Comply with legal obligations (e.g., tax record retention)

We do not use your data for advertising, profiling, or automated decision-making.

5. Data Retention

  • Account data: retained as long as your account is active. Upon account deletion, personal data is removed unless legal retention periods apply.
  • Transaction and invoice data: retained for 10 years as required by German tax law (§ 147 AO, § 257 HGB).
  • Server logs: deleted after statistical analysis, typically within 30 days.
  • Support correspondence: deleted after the inquiry is resolved, unless part of an ongoing business relationship.

6. Hosting and Infrastructure

6.1 Self-Hosted Infrastructure

Both xenntec.com and my.xenntec.com are operated on our own infrastructure. Data processing occurs on servers within the European Union.

6.2 Cloudflare

We use Cloudflare, Inc. for DNS, DDoS protection, and secure tunneling. Cloudflare may process your IP address and connection metadata to provide these services. Cloudflare acts as a data processor on our behalf.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the security and availability of our services.

Privacy Policy: https://www.cloudflare.com/privacypolicy/

7. Third-Party Services

All fonts used on xenntec.com are self-hosted on our own servers. No connection to third-party font providers (such as Google Fonts) is established when you visit our landing page.

7.1 Cloudflare Turnstile (my.xenntec.com)

We use Cloudflare Turnstile as an anti-bot verification service on our customer portal. Turnstile analyzes browser behavior to determine whether a visitor is human. This analysis may process your IP address, browser characteristics, and interaction patterns. Data is forwarded to Cloudflare for processing.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting our services from automated abuse and spam.

Privacy Policy: https://www.cloudflare.com/privacypolicy/

7.2 Stripe (Payment Processing)

We use Stripe, Inc. to process credit card and other electronic payments. When you make a purchase, you are redirected to Stripe's hosted checkout page. Stripe collects and processes your payment information (card details, billing address) directly. We receive only a transaction confirmation, amount, and status — we do not store your payment card data.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

Privacy Policy: https://stripe.com/privacy

7.3 NOWPayments (Cryptocurrency Payment Processing)

We use NOWPayments to process cryptocurrency payments. When you choose to pay with cryptocurrency, your transaction is processed through NOWPayments' infrastructure. We receive payment confirmation and status updates via webhooks.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract.

Privacy Policy: https://nowpayments.io/privacy-policy

7.4 IPS Spam Defense (my.xenntec.com)

Our customer portal uses the IPS Spam Defense Service to prevent spam registrations. This service receives the email address and IP address of registering members to assess the likelihood of spam.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing spam and protecting service integrity.

Privacy Policy: https://invisioncommunity.com/legal/privacy

7.5 Fastmail (Email Delivery)

We use Fastmail Pty Ltd as our email service provider for sending transactional emails (e.g., registration confirmations, password resets, purchase receipts). Fastmail processes the recipient email address and message content on our behalf.

Legal basis: Art. 6(1)(b) GDPR — performance of a contract / pre-contractual measures.

Privacy Policy: https://www.fastmail.com/privacy/

8. Data Transfers Outside the EU

Some of the third-party services listed above (Stripe, Cloudflare, NOWPayments) may process data outside the European Economic Area (EEA). These transfers are safeguarded by:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission where applicable
  • The provider's certification under relevant data protection frameworks

9. Your Rights Under the GDPR

As a data subject, you have the following rights:

  • Right of access (Art. 15 GDPR) — request a copy of your personal data
  • Right to rectification (Art. 16 GDPR) — request correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) — request deletion of your data, subject to legal retention obligations
  • Right to restriction of processing (Art. 18 GDPR) — request limited processing under certain conditions
  • Right to data portability (Art. 20 GDPR) — receive your data in a structured, machine-readable format
  • Right to object (Art. 21 GDPR) — object to processing based on legitimate interest
  • Right to withdraw consent (Art. 7(3) GDPR) — withdraw consent at any time, without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at [email protected]. We will respond within one month.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for XENNTEC UG is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
https://www.lda.bayern.de

10. Children's Privacy

Our services are not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at [email protected] and we will promptly delete it.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • HTTPS/TLS encryption for all connections
  • Hashed password storage
  • Access controls and authentication
  • Regular security updates

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of our services after changes constitutes acceptance of the updated policy.

13. Governing Law

This Privacy Policy is governed by the laws of the Federal Republic of Germany and the European Union, in particular the General Data Protection Regulation (GDPR).

14. Contact

For any questions, requests, or complaints regarding this Privacy Policy or your personal data:
E-Mail: [email protected]

×
×
  • Create New...

Important Information

By using this site, you agree to our Privacy Policy and accept We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..