Privacy Policy
Last updated: 31 August 2026
1. Controller
STwo Industries GmbH
Stephan Stapel
Eichenkoppel 19
22399 Hamburg, Germany
Email:
2. Data processing when visiting the website
When you visit this website, your device's browser automatically sends information to our server, which is temporarily stored in server log files. This includes, among other things: IP address (shortened/anonymized), date and time of access, the URL accessed, the referrer URL, and the browser and operating system used.
Purpose: ensuring a smooth connection, system security and stability.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Storage period: log files are deleted after [[7–14]] days.
3. Cookies & consent
We use cookies to provide basic website functionality. A notice banner appears on your first visit. Your choice is stored in the fs_cookie_consent cookie.
- Necessary cookies: e.g. language settings (
fs_lang), session handling. Legal basis: Art. 6(1)(f) GDPR. - Non-essential cookies/tools: only set after you consent. Legal basis: Art. 6(1)(a) GDPR.
You can change your choice at any time via "Cookie settings" in the footer. If you select "Decline", non-essential cookies/tools will not be loaded.
4. Getting in touch (form/email)
If you contact us via a form or by email, we process the information you provide (name, email, message, and any other details you choose to share) in order to handle your inquiry.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual measures) or (f) (legitimate interest in customer communication).
Storage period: until your request has been resolved, or as required by statutory retention obligations.
5. License purchase / contract processing (where applicable)
When you purchase a license, we process account and payment data in order to fulfil the contract. Payment data may be forwarded to payment service providers.
Legal basis: Art. 6(1)(b) GDPR.
Recipients: [[payment service provider, e.g. Stripe/PayPal, registered office, privacy notices]].
6. Customer account, licence checks and use of the portal tools
Customer account. To register you, we process your master data (name, email address, and where applicable company and address details) together with the answers you volunteer in the questionnaire (how you heard about us, what kind of company you are, and when you plan to go live). The questionnaire is optional; you can use your account in full without answering it.
Licence checks. The library verifies your licence against our server. All it transmits are checksums (SHA-256) of the licence key, the machine and, where applicable, the domain, plus the library version in use. We store those values as a daily total per licence and machine. We expressly do not store plain-text values or IP addresses.
Portal tools. When you use the validator, the XML viewer, the visualizer or the PDF toolkit in the customer area, we record which tool you used on which day and how often. The invoices you upload are processed in memory only; we store neither their content nor their file name.
Purpose: performing the licence agreement and guarding against licence misuse, support, improving our tools, and looking after trial customers during their evaluation.
Legal basis: Art. 6(1)(b) GDPR (performance of the usage/licence agreement) and Art. 6(1)(f) GDPR (legitimate interest in a functioning licence model and in customer support that fits the situation).
Storage period: Activity data (licence checks and tool usage) is deleted no later than 24 months after it was collected. Where a trial ends without a licence being purchased, we delete the associated activity data 90 days after the trial expires. Your account data is retained for the duration of the business relationship; statutory retention obligations remain unaffected.
You may object at any time to processing based on legitimate interests (Art. 21 GDPR); you will find the contact details under section 1.
7. Hosting & data processing agreements
This website is hosted by [[hosting/cloud provider, country]]. We have a data processing agreement with the hosting provider in accordance with Art. 28 GDPR.
8. Analytics and marketing tools
Umami (audience measurement). We run Umami on our own server at analytics.factoorsharp.com. Umami sets no cookies, reads nothing from your device and does not store your IP address; it records the page you visited, the referrer and rough details about browser, operating system, device type and country of origin. It is not combined with your customer account, and there is no cross-site recognition. Measurement only starts once you have agreed in the cookie banner; if you decline or make no choice, the script is not loaded. Legal basis: Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect via "Cookie settings" in the footer.
Google Ads tag. To measure how our advertising performs we use the Google Ads tag (Google Ireland Ltd.). It is loaded only after you have given your consent in the cookie banner; until then all Google consent settings remain set to "denied". Legal basis: Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect via "Cookie settings" in the footer. This may involve a transfer of data to the USA; see section 9.
9. Data transfers to third countries
If processing takes place in third countries (outside the EU/EEA), we ensure an adequate level of data protection (e.g. through EU standard contractual clauses). Details are provided by the respective tools/providers.
10. Storage period
We only store personal data for as long as necessary for the purposes described above, or as required by statutory retention obligations.
11. Your rights
- Right to access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent given (Art. 7(3) GDPR)
To exercise your rights, please use the contact details given above.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, for example the authority responsible for your place of residence or for our registered office.
13. Security
We take appropriate technical and organizational measures to protect your data against loss, misuse and unauthorized access (e.g. TLS encryption, access restrictions).
14. Changes to this policy
We update this privacy policy whenever the legal situation, our data processing, or the underlying technology changes. The current version is always available on this page.