Privacy policy
Controller
The controller for data processing on this website within the meaning of Article 4 (7) GDPR is:
Elaman GmbH, Implerstraße 24, 81371 Munich, Germany
Phone: +49 89 24209180 · Email: info@elaman.de
What this website does not do
This website uses no web analytics, tracking or profiling. No third-party services are embedded — no maps, fonts, videos or social media elements loaded from external servers. All fonts are served from our own server.
The public pages set no cookies. Two strictly necessary cookies are set in the customer portal only; they are described below.
This is enforced technically by a content security policy that permits connections to our own domain only. No data is therefore transmitted to advertising networks.
Access data when visiting the website
When you open this website, your browser transmits technically necessary data which is recorded in the log files of our hosting provider: the IP address of the requesting device, the date and time of access, the address requested, the HTTP status code, the volume of data transferred, and details of your browser and operating system.
This processing is necessary to provide the website, keep it stable and detect attacks. The legal basis is Article 6 (1) (f) GDPR; our legitimate interest lies in secure and uninterrupted operation. This data is not combined with other sources and not evaluated for advertising purposes.
Log data is kept only for as long as the secure operation of the website requires and is deleted afterwards. It is retained for longer only where a specific security incident has to be investigated.
Inquiry form
If you use the form on this website, we process the details you enter: first name, email address and your message as mandatory fields, surname, company, telephone number and the topic you select as optional ones. We use this data solely to handle your inquiry and reply to you; we use your telephone number only to call you back about your inquiry.
The legal basis is Article 6 (1) (b) GDPR where the inquiry concerns the conclusion or performance of a contract, and otherwise Article 6 (1) (f) GDPR, our legitimate interest being to answer business inquiries. Providing the data is voluntary; without a first name, email address and message we cannot answer your inquiry.
The form contains a field invisible to you which serves to block automated submissions. We additionally limit the number of submissions for a short period using a value derived from the IP address; that counter is kept only briefly and is deleted after two days at the latest.
Our hosting provider processes the form data in a data centre in Frankfurt am Main, Germany. Your inquiry is delivered to our mailbox by email and kept there for as long as handling it requires. We delete it afterwards unless commercial or tax retention obligations apply.
Customer portal: account and credentials
“Login” leads to a closed portal. Access is granted individually; there is no self-registration. For an account we process: your name, your email address, the authority the account belongs to, the role (Elaman staff or customer), the language of your correspondence, the status of the account and the time of the last sign-in.
The legal basis is Article 6 (1) (b) GDPR: the account serves the initiation or performance of the contractual relationship with your authority. Where we log and limit access in order to protect the portal, we rely on Article 6 (1) (f) GDPR, our legitimate interest being the protection of non-public documents.
Your password is never stored in the clear, only as an scrypt hash. Each time customers sign in, and when they confirm a change to their account, we also send a one-time code to their email address; the code is valid for ten minutes and can be used once, we store it only as a hash and delete it after two days at the latest. Elaman staff sign in with an authenticator app instead, for which a secret is stored; their recovery codes are held as hashes only and cannot be recovered once they have been shown. Nobody at Elaman can read your password or your codes.
If you are a customer and have forgotten your password, we store your request with the time and IP address until we have called you to confirm it and sent the link, or dismissed the request, for seven days at most.
Account data is kept for as long as the access is granted. When an account is disabled it remains in place at first, so that it stays traceable which documents were released to whom; it is deleted when the business relationship ends and no statutory retention obligations apply.
You can delete your account yourself at any time under “Account” in the portal. Your account data, sessions, trusted devices and any recovery codes are then deleted immediately; entries in the access log remain until their twelve-month retention period ends.
Customer portal: cookies and sign-in
The portal sets up to three cookies which are strictly necessary for the service you requested. Under section 25 (2) no. 2 TDDDG no consent is required for them, and they are not evaluated in any way.
“elaman_session” holds a random value identifying your session and expires after eight hours at the latest; the session also ends after an hour without activity. “elaman_login_challenge” exists only between entering your password and entering your code, and expires after two minutes, or after ten minutes for a code sent by email. “elaman_trusted_device” is set only if you choose “Trust this device for 30 days” when signing in; it holds a random value and expires after 30 days. All cookies are set to “HttpOnly” and “SameSite=Lax” and are transmitted over an encrypted connection only.
In the database we store, for a session, only the hash of the value in the cookie, the time of sign-in, the last access, the IP address and the browser identification. The value itself is not stored by us. Expired sessions are deleted.
For a trusted device we likewise store only the hash of the value, together with a label made of browser and operating system, the IP address, the last use and the expiry date. It is deleted after 30 days, as well as with a new password or when you remove it under “Account” in the portal.
Failed sign-in attempts are recorded with the address, the time and the IP address, so that an account can be locked temporarily after ten failures within fifteen minutes. These entries are deleted after two days at the latest.
Customer portal: documents and access log
The portal provides documents which are released to individual authorities. You see only what has been released to your authority. The files are held in non-public storage and are reachable only through a signed link that expires after five minutes.
We keep a log in order to secure this access. It records sign-ins and failed sign-in attempts, changes to accounts and releases, and every retrieval of a document — each with the time, the person acting, the object concerned and the IP address. The legal basis is Article 6 (1) (f) GDPR; our legitimate interest lies in being able to establish who accessed non-public documents.
Log entries are deleted after twelve months. The log is readable by Elaman administrators only and is not evaluated for any other purpose.
Customer portal: requesting access
Through the “Request access” form we process your name, your authority, your work email address and your optional message in order to decide whether to grant access. The legal basis is Article 6 (1) (b) GDPR, or Article 6 (1) (f) GDPR with our legitimate interest in assessing such requests.
If we set up access, you receive an invitation by email. If we decide against it, you receive no message; we merely note internally that the request has been handled. Handled requests are deleted after six months.
Processors
We use service providers for operation and delivery which process data exclusively on our instructions and under a data processing agreement pursuant to Article 28 GDPR:
Website hosting and delivery: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA.
Delivery of emails from the form and the portal: Resend (Plus Five Five, Inc.), 2261 Market Street #5039, San Francisco, CA 94114, USA.
Database and file storage for the portal: Neon Inc., 209 Orange Street, Wilmington, DE 19801, USA. The data is stored in an Amazon Web Services data centre in Frankfurt am Main, Germany (region eu-central-1) and does not leave the European Union in normal operation.
Personal data may be transferred to the USA by these providers, or be accessible to them, even where it is stored in the European Union. Such transfers take place on the basis of the European Commission's standard contractual clauses pursuant to Article 46 (2) (c) GDPR together with supplementary safeguards or, where the provider is certified, on the basis of the adequacy decision for the EU-US Data Privacy Framework pursuant to Article 45 GDPR.
Encryption
This website is delivered exclusively over an encrypted TLS connection, which you can recognise from the “https://” address and the padlock symbol in your browser. The details you submit through the form are therefore protected in transit.
Your rights
You have the right to obtain information about the data we process about you (Article 15 GDPR), to have inaccurate data corrected (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability (Article 20 GDPR).
Where we process data on the basis of a legitimate interest, you may object to that processing under Article 21 GDPR. Please direct any of these requests to the address above or to info@elaman.de.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 27, 91522 Ansbach, Germany.
Status of this policy
October 2026. Should data processing on this website or in the portal change, we will amend this policy accordingly.