Updated 18 July 2026

Privacy notice

1. Controller

Tiamat UG (haftungsbeschränkt)
An der Strusbek 12
22926 Ahrensburg
Deutschland
Email: mail@tiamat-labs.com

2. Visiting this website

This website is delivered as static files. It does not use analytics or advertising cookies and does not embed social-media content. When you visit, the delivery infrastructure processes technically necessary connection data, particularly your IP address, request time, requested address, transferred data volume and browser and operating-system information. This is necessary to provide the website securely and is based on Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.

To protect the public forms against abuse, the backend combines the IP address with a secret key to create an HMAC verification value. The raw IP address is not stored in the form database. The verification value and attempt time are deleted after one hour.

3. Early access

When you request early access, we process your email address, selected language, consent version and the times of the request and confirmation. We first send a single-use confirmation link (Double Opt-in). The address is not enabled for early-access information before confirmation. The confirmation secret is stored encrypted, additionally matched by a hash when used, and expires after 24 hours. Expired confirmation requests are deleted; the “requested” and “confirmed” events remain as consent evidence.

We use this information only to contact you about Nixa testing opportunities and launch. The legal basis is your consent under Article 6(1)(a) GDPR.

We retain the information until you withdraw your consent or the early-access purpose ends. Withdrawal applies to future processing and can be sent by email to mail@tiamat-labs.com. Statutory retention duties remain unaffected.

4. Online cancellation

When you cancel online, we process the account email address, contract reference, cancellation type and, where applicable, the reason, the requested end date, and the date and time of receipt. We also record the technical processing and delivery of the receipt. The purpose is to receive, process and confirm the cancellation. The legal bases are Article 6(1)(b) and (c) GDPR in conjunction with section 312k of the German Civil Code. The declaration and receipt are retained for the applicable statutory evidence and retention periods.

The secret receipt key appears only in the fragment of the confirmation address and is exchanged on opening for a secure cookie session transmitted only via HTTPS. The cookie is inaccessible to JavaScript, lasts 30 minutes and is used only for the current receipt. The receipt key expires after 30 days. The receipt page does not use analytics or advertising cookies.

5. Recipients and transfers

Within our operation, access is limited to people who need the information for this purpose. Early-access and cancellation data is stored in the configured PostgreSQL database. To send the Double Opt-in link and cancellation receipt in text form, we transmit the email address and message content to Brevo (Sendinblue GmbH/Brevo SAS) as a processor. Brevo documents that its databases and servers are stored within the European Union.

When a cancellation can be assigned unambiguously to an active subscription using the non-guessable contract number, we transmit the subscription identifier and cancellation instruction to Stripe Payments Europe, Limited (“Stripe”), our payment service provider. Stripe processes payment and contract data under the privacy terms and safeguards applicable to the payment service. No change is sent to Stripe without a secure assignment. The data is not shared with advertising or analytics services.

6. Your rights

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time with effect for future processing.

You may also complain to a data-protection supervisory authority, particularly in the country of your habitual residence, place of work or the place of the alleged infringement.

7. Requirement to provide data

You do not need to provide personal data to view the website. Without an email address, however, we cannot send early-access information or assign and confirm an online cancellation.

8. Automated decisions

We do not use decisions based solely on automated processing or profiling in connection with the website, waitlist or online cancellation.

Back to the home page