Privacy Policy Codixio FAQs Everywhere
1. Controller
Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany. Phone +49 39059 974988. E-mail general support@codixio.com, e-mail data protection/legal legal@codixio.com. Legal form: sole proprietorship (no commercial register entry), operating under the trade name Codixio. VAT identification number pursuant to Sec. 27a UStG: DE296346917. Tax status: small business under Sec. 19 UStG.
2. Scope and Allocation of Roles
This privacy policy covers the Shopware app Codixio FAQs Everywhere and its backend at sw-codixiofaqseverywhereapp.api.codixio.com. Two roles apply. For the merchant's registration, contract and plan data as well as for the technical server logs of the backend, Codixio acts as an independent controller within the meaning of Art. 4 No. 7 GDPR. Where the app processes data on behalf of the merchant (in particular the delivery of the FAQ content maintained by the merchant), the merchant is the controller and Codixio acts as processor; the data processing agreement at https://legal.codixio.com/apps/faqs-everywhere-shopware/dpa.en applies.
3. Processing upon App Registration and Operation
When the app is installed, the merchant's shop exchanges technical registration data with the backend, which is stored there: the shop identifier assigned by Shopware, the shop URL, and the secrets and credentials required for signed communication and API access. The purpose is the authentication and protection of the communication between shop and app. The legal basis is Art. 6(1)(b) GDPR to the extent any personal reference exists at all; the data constitutes technical contract data of the merchant. The data is stored for the duration of the installation and deleted automatically upon uninstallation.
4. Plan Management (In-App Purchases)
To control the booked feature scope, the backend stores per shop the active plan tier, the time of the last verification and the plan identifier transmitted by Shopware. The plan information originates from a proof signed by Shopware whose signature is verified against the public key service of Shopware AG (api.shopware.com). These are pure contract and product identifiers without personal reference. Legal basis: Art. 6(1)(b) GDPR. Deletion upon uninstallation.
5. FAQ Content
The questions and answers maintained by the merchant are stored exclusively within the merchant's Shopware environment. The backend does not store FAQ content. On each request in the shop, the backend retrieves the content via the merchant shop's API, filters it by plan tier, sanitises it technically and passes it through to the visitor's browser. Processing is transient for the duration of the request only. Via its declared permissions the app reads only what is technically required: the assignment of FAQs to products and categories (read:product, read:category, used solely as filter criteria without reading product or category data) and the app configuration (read:system_config). The permission delete:system_config serves solely to clean up the configuration upon uninstallation.
6. Retrieval in the Shop (Visitors)
When FAQs are displayed, the visitor's browser sends a request to the backend containing only the technical shop identifier, the page type and the identifier of the product or category. No cookies are set, no information is stored on or read from the end device, and no personal data of visitors is processed or analysed in the application. No consent requirement under Sec. 25 of the German TDDDG arises.
7. Server Logs
At infrastructure level, access logs arise for technical reasons during backend operation and may contain the IP address of the requesting device. These logs serve solely operational security and error diagnosis, are not analysed in the application and are retained only briefly within the scope of ordinary server operation. Legal basis: Art. 6(1)(f) GDPR; the legitimate interest lies in ensuring secure and stable operation. The right to object under Art. 21 GDPR applies to this processing.
8. Recipients and Processors
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Activity: hosting provider for application servers and Postgres database. Processing locations: data centres Falkenstein (DE) and Nuremberg (DE). Third-country transfer: no. In addition, Coolify is used as a self-operated open-source container orchestration on Hetzner, not an external service provider. To verify plan proofs, the public key service of Shopware AG (Germany) is queried. No further external services are used: no mailing providers, no AI services, no analytics or tracking services, no external content delivery networks.
9. No AI, No Automated Decision-Making
The app does not use artificial intelligence and does not transmit data to AI providers. Transparency obligations under Art. 50 of the AI Regulation (EU) 2024/1689 do not apply. No automated decision-making within the meaning of Art. 22 GDPR takes place.
10. Rights of Data Subjects
Data subjects have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). No processing is based on consent. To exercise these rights, a message to legal@codixio.com is sufficient. There is also the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Competent supervisory authority: Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg, Germany. Phone +49 391 81803-0. E-mail poststelle@lfd.sachsen-anhalt.de. Website datenschutz.sachsen-anhalt.de.
11. Version
Last updated: 30 August 2026. The version published at https://legal.codixio.com/apps/faqs-everywhere-shopware/privacy.en applies.