RedubIDX

Privacy policy

This notice explains how RedubIDX processes personal data when you use this website, including the contact and demo request form. It does not cover customer processing inside the TDVeriX Med or ToCGeniX Med product platforms, which are governed by customer agreements and separate documentation for institutional buyers.

Last updated: 27 August 2026

1. Data controller

The controller responsible for website personal data is:

Johannes Dubnack (RedubIDX)
Am Herrenberge 16, 07745 Jena, Germany
Email: johannes.dubnack@redubidx.com

Data protection contact: same address and email as above. No separate data protection officer has been appointed. Under the current scope (website with contact and demo requests only; no large-scale processing of special categories under Art. 9 GDPR and no regular and systematic large-scale monitoring under Art. 37(1)(b)–(c) GDPR) the thresholds for mandatory appointment under Art. 37 GDPR are not met. This assessment is reviewed at least annually or when processing activities change.

Full imprint details are on our legal notice. Website use is governed by our terms of use.

2. Scope

This policy covers personal data processed in connection with:

  • Browsing and using this marketing website
  • Submitting a contact or demonstration request
  • Email or other follow-up about those requests
  • Operating, securing, and improving the website

It does not apply to personal data processed on behalf of customers inside TDVeriX Med or ToCGeniX Med (for example technical documentation or assessment work product). That processing is governed by the customer contract and related data-processing terms.

3. Personal data we process

Contact and demo form. When you submit the form we process the details you provide: name, work email, organization, role, organization type, and free-text message. We do not ask for special categories of personal data on this form; please do not include them.

Technical and log data. Our hosting and delivery infrastructure may process standard server and security logs (for example IP address, timestamps, request URL, user agent, and similar connection metadata) to operate and protect the site.

Anti-abuse verification. The contact and demo form uses Turnstile, a spam-protection widget operated by Cloudflare, to verify that submissions come from a human. It processes connection data such as the IP address, user agent, and similar device signals during that verification.

Cookies and similar technologies. See section 8 and our cookie notice.

4. Purposes and legal bases

We process personal data only where a GDPR legal basis applies. For this website:

  • Contact and demo requests: to receive, review, and respond to inquiries; to qualify institutional interest; and to arrange conversations or demonstrations. Legal bases: steps at the request of the data subject prior to entering a contract (Art. 6(1)(b) GDPR) where the request relates to a possible commercial relationship; otherwise legitimate interests (Art. 6(1)(f) GDPR) in responding to professional B2B inquiries and operating our business. We balance those interests against your rights and use work contact details you choose to provide.
  • Website operation and security: to deliver pages, maintain availability, diagnose errors, and protect against abuse. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in running a secure, reliable website; and where applicable legal obligation (Art. 6(1)(c) GDPR).
  • Records and compliance: to keep limited records of business communications where needed for legal claims, accounting, or regulatory duties. Legal bases: legitimate interests (Art. 6(1)(f)) and, where required, legal obligation (Art. 6(1)(c)).

We do not sell personal data. We do not use website form data for automated decision-making that produces legal or similarly significant effects.

Requirement to provide data. Providing the form data is neither a statutory nor a contractual requirement and you are not obliged to do so. Without the required fields (name, work email, organization, message) we cannot receive or answer your inquiry. Optional fields (role, organization type) may be left blank without consequence.

5. Recipients and processors

Personal data is handled by people at RedubIDX who need it to respond to your request or run the site. It may also be processed by service providers acting on our instructions (processors):

  • Vercel Inc. (US) - website hosting, content delivery, and storage of the server and security logs described in section 3.
  • Cloudflare, Inc. (US) - Turnstile anti-spam verification for the contact and demo form.
  • Resend, Inc. (US) - transactional email delivery for contact and demo requests.
  • Upstash, Inc. (US) - server-side rate limiting and request deduplication that protects the contact and demo form against abuse.
  • Sentry (Functional Software, Inc.) (US) - error and performance monitoring of the website.
  • Slack Technologies, LLC (US) - delivery of operational error alerts for the website; alert payloads are designed not to contain personal data.
  • OVHcloud (OVH GmbH) (EU) - hosting of our mailbox for the email correspondence related to contact and demo requests; correspondence is stored within the EU.

Processors are bound by contract to process data only on documented instructions and to implement appropriate security measures. We share data with authorities only when legally required.

6. International transfers

The processors listed in section 5 are based in the United States, with one exception: our mailbox provider OVHcloud (OVH GmbH) is based in the EU and stores correspondence there, so no transfer outside the EEA takes place for mailbox data. For transfers to the US-based processors we rely on the EU-US Data Privacy Framework (and, where applicable, the UK Extension and the Swiss counterpart), which the European Commission recognizes as providing an adequate level of protection; we verify the active certification of each provider under that framework. Where a transfer is not covered by an adequacy decision or a framework certification, we use EU standard contractual clauses together with supplementary measures as needed.

We do not otherwise transfer personal data outside the EEA. A copy of the relevant transfer safeguards can be provided via johannes.dubnack@redubidx.com.

7. Retention

  • Contact and demo requests: retained for as long as needed to handle the inquiry and related follow-up, then for a limited period (typically up to 24 months after last meaningful contact) unless a longer period is required for an active commercial discussion, legal claim, or legal obligation. Where German commercial or tax law requires longer retention (HGB § 257, AO § 147 — e.g. 6 years for business letters, 8–10 years for accounting-relevant correspondence), that statutory period governs case-by-case and overrides the 24-month window.
  • Technical logs: retained for a short operational window appropriate to security and troubleshooting (typically weeks to a few months), unless needed longer to investigate an incident.

8. Cookies and similar technologies

This website is designed to minimize non-essential tracking. We do not use advertising cookies or third-party marketing pixels on marketing pages. Strictly necessary storage required to deliver or secure the site may be used without consent under § 25(2) TDDDG; anything non-essential would only be introduced with prior opt-in consent. Full detail: cookie notice.

9. Your rights

Under the GDPR you may have the right to request access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.

To exercise rights regarding website data, contact johannes.dubnack@redubidx.com or use the contact form. We may need to verify your identity before fulfilling a request.

You also have the right to lodge a complaint with a supervisory authority, in particular in your EU/EEA member state of residence, place of work, or place of the alleged infringement. The competent supervisory authority is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (opens in a new tab), whose contact details are:

Tino Melzer, Häßlerstraße 8, 99096 Erfurt (postal address: Postfach 900455, 99107 Erfurt)
Email: poststelle@datenschutz.thueringen.de · Telephone: +49 (361) 57-3112900
Complaint form and further complaint channels are available at https://tlfdi.de/ (opens in a new tab).

10. Security

We apply technical and organizational measures appropriate to the risk, including encrypted transport (HTTPS) and access limited to people and systems that need the data. No method of transmission or storage is completely secure; please avoid sending sensitive personal data via the public contact form.

11. Children

This website is aimed at professional and institutional audiences. We do not knowingly collect personal data from children.

12. Changes

We may update this notice as our website, providers, or practices evolve. The "Last updated" date at the top will change when we do. Material changes will be reflected on this page.