Legal
Privacy Policy
This privacy policy informs you about the nature, scope and purpose of the processing of personal data when visiting this website — in accordance with the General Data Protection Regulation (GDPR).
1. Controller
The controller within the meaning of the GDPR is: Ihsan Uzun, Sandweg 148, 50827 Cologne, Germany. Email: kontakt@izutech.de
2. General information
We only process personal data insofar as this is necessary to provide a functioning website and our content. Processing regularly takes place only with the user’s consent or on the basis of a statutory permission.
3. Hosting
This website is hosted by an external service provider: [Placeholder: name and address of the hosting provider]. Personal data collected on this website is processed on the provider’s servers. Processing is based on our legitimate interest in secure and efficient provision (Art. 6 (1) (f) GDPR). Where required, a data processing agreement (Art. 28 GDPR) is concluded with the provider.
4. Server log files
When you access this website, the hosting provider automatically collects information in so-called server log files that your browser transmits. These are in particular: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and the IP address (shortened or anonymised where possible).
This data is not merged with other data sources. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in the technically error-free presentation and the security of our website. The data is stored for a limited period and then deleted.
5. Cookies
Our website uses technically necessary cookies or comparable technologies only insofar as they are required for the operation of the website and your account: a cookie for the language setting and, after signing in, a session cookie that keeps you logged in during your visit. Neither cookie transmits data to third parties or is used for analytics or marketing purposes. The legal basis for this is § 25 (2) TDDDG in conjunction with Art. 6 (1) (f) GDPR (language) or (b) GDPR (session, performance of a contract).
Non-essential cookies (e.g. for analytics or embedded media) are only set after your explicit consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR). You can withdraw a consent given at any time with effect for the future. We currently do not use any such consent-based cookies; as soon as a consent banner is used in the future, this section will be supplemented with the specific way to withdraw consent.
6. Contact and email
If you contact us by email, the data you provide (e.g. name, email address, content of the message) is processed for the purpose of handling your request. The legal basis is Art. 6 (1) (b) GDPR if your request is related to a contract, otherwise Art. 6 (1) (f) GDPR (legitimate interest in responding to enquiries). A contact form on the website is not currently active; once it is put into operation, the same rules will apply to the data entered there.
Your data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected and no statutory retention obligations conflict with this.
For sending account and system messages (e.g. welcome email, email confirmation, password reset, payment and invoice notifications, trial-period notices, confirmation of an account deletion) we use the email service provider Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany). In doing so, your email address as well as the subject and content of the respective message are transmitted to Brevo. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures), and additionally Art. 6 (1) (f) GDPR (legitimate interest in account security) for security-relevant messages. A data processing agreement (Art. 28 GDPR) is in place with Brevo. Further information can be found in Brevo’s privacy policy at brevo.com/legal/privacypolicy.
7. Analytics and statistics
We currently do not use any analytics or tracking services that require consent. Should such a service be used in the future, this will only take place on the basis of your consent (Art. 6 (1) (a) GDPR); the specific service, provider, purpose, storage period and recipients will be added here before it is used.
8. Embedded content and media
We currently do not embed any third-party content or media (e.g. videos). Should this change in the future, it may result in data being transferred to the respective providers; such embedding will then only take place after your consent or using a privacy-friendly method, and the providers and purposes will be named here.
9. Security
For security reasons and to protect the transmission of confidential content, this website uses TLS/SSL encryption. We also take appropriate technical and organisational measures to protect your data against manipulation, loss and unauthorised access.
10. Customer account, product use and trial
To use our products (IzuTech VPN, IzuTech TV) you create a customer account. In doing so we process your email address, a password stored by us only as a cryptographic hash, the confirmation status of your email address, your subscription and licence data (including the trial and any one-time free extension), your linked devices and security-relevant account events. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract); for security-related logs additionally Art. 6 (1) (f) GDPR.
You can download the data stored for your account as a machine-readable file at any time (Art. 15/20 GDPR) and delete your account yourself (Art. 17 GDPR) — both options are available directly in your account settings. After a deletion request the account is blocked immediately and permanently removed with all associated data after a period of 30 days. Statutory retention obligations (in particular for invoices) remain unaffected.
11. Payment processing (Stripe)
For processing paid subscriptions we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When you take out or manage a subscription, you are directed to a payment or customer portal page operated by Stripe. Your payment data (e.g. card details) is processed exclusively by Stripe and never reaches our systems.
From Stripe we receive the information required to perform the contract — in particular a customer identifier, the subscription and payment status and invoice data (number, amount, currency, date, receipt link) — and store it linked to your account. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract); for retaining invoice data additionally Art. 6 (1) (c) GDPR (statutory retention obligations). A data processing agreement (Art. 28 GDPR) is in place with Stripe. Further information can be found in Stripe’s privacy policy at stripe.com/privacy.
12. Transfers to third countries
Personal data is only transferred to countries outside the EU/EEA insofar as this is necessary for the stated purposes and appropriate safeguards are in place. This concerns in particular the use of Stripe: the contracting party is the Irish entity Stripe Payments Europe, Ltd.; processing by affiliated companies in the USA (Stripe, Inc.) is possible and is safeguarded by EU standard contractual clauses and supplementary measures.
13. Your rights
Under the GDPR you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing (Art. 21).
You can exercise access and data portability as well as the deletion of your account directly yourself for your customer account (see section 10). You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). For all other matters, a message to the email address stated above is sufficient.
14. Withdrawal of consent
Insofar as processing is based on your consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.
15. Validity and changes
This privacy policy will be adjusted as soon as changes to the website or legal requirements make this necessary. The current version published on this page applies in each case.
Last updated: 2026-07-26