Privacy Notice
This notice explains how AZ-FIVE Industries processes personal data when you visit the website, contact us or purchase a MicroTool.
1. Controller
AZ-FIVE Industries
Proprietor: Dominik Lippelt
Leonhardstraße 39A
78333 Stockach
Germany
Email: info@az-five-industries.com
Phone: +49 7771 6340037
No data protection officer has been appointed where no statutory obligation to appoint one applies.
2. Website access and hosting
When you access the website, technically necessary connection data may be processed, including IP address, time, requested resource, data volume, referrer, browser/device information and server status. This is needed to deliver pages, maintain stability and defend against abuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are secure, reliable web services. The infrastructure is hosted on servers provided by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany.
3. Privacy-conscious reach measurement
The main website can send page path, time, referrer, device category and existing UTM parameters to an AZ-FIVE/CMC measurement system. An IP address is not retained in plain text as a visitor identifier and may only be processed in pseudonymised or hashed form for approximate repeat-visit counting.
No personal advertising profiles are created and data is not sold to advertising networks. The legal basis is Article 6(1)(f) GDPR; our interest is understanding and improving our own pages. MicroTools pages use no external advertising or analytics trackers.
4. Contact and custom requests
If you contact us by email or phone, we process the contact details and content you provide, related metadata and, where relevant, business and project information. This is used to answer you, prepare a quote, take pre-contract steps and document the communication.
The legal basis is Article 6(1)(b) GDPR where processing relates to a contract or requested pre-contract steps, and otherwise Article 6(1)(f) GDPR for orderly business communication and the establishment or defence of claims.
5. Business eligibility step before checkout
Before redirecting you to the payment service, we process the product, language, business name, business email, country, timestamp and your confirmation that you act for business purposes, are authorised to place the order and accept the identified terms version. A random order reference is generated. We do not collect payment-card or bank details in this step.
This restricts the offer to business customers, records contract formation, selects the correct product and prevents abuse. The legal bases are Article 6(1)(b) and (f) GDPR. Required fields are necessary for online purchase.
6. Payment processing by Stripe and Link
After the business check, you are redirected to a checkout operated by Stripe or Link. It processes information such as name, email, billing address, payment and transaction data, and security/fraud-prevention signals. AZ-FIVE does not receive full card or bank details.
For Managed Payments, Stripe/Link acts as merchant of record for the transaction and handles payment, indirect tax, receipts/invoices, fraud prevention, disputes and transaction support. AZ-FIVE receives the order and status data needed for delivery, product support, bookkeeping and legal claims.
Depending on region, recipients include Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, affiliated Stripe/Link companies and selected payment providers. Their processing is also governed by the Stripe Privacy Policy and Link notices shown at checkout. AZ-FIVE relies on Article 6(1)(b), (c) and (f) GDPR.
7. Payment status, webhooks and downloads
Stripe sends automated transaction status messages (webhooks). These can include a Stripe session/transaction ID, our random order reference, product, payment status, currency, amount and customer email. The message signature is verified and unnecessary raw data is not retained.
After successful payment, we create a time-limited download. Access can be logged with time, order reference, product and technical status to securely deliver the file and investigate abuse. The legal basis is Article 6(1)(b) and (f) GDPR.
8. Cookies and similar technologies
The static MicroTools pages use no tracking cookies. The business checkout uses a short-lived, strictly necessary security cookie to protect form submissions. It is limited to the checkout path and is not used for advertising. The legal basis is section 25(2)(2) TDDDG and Article 6(1)(f) GDPR.
On the external Stripe/Link page, the providers may use security, payment and account technologies required for their service. They provide further information during checkout.
9. Recipients and international transfers
Data is shared only with parties that require it for hosting, communications, payment processing, bookkeeping, legal advice or technical support. Where a provider acts as processor, it is bound under Article 28 GDPR.
Stripe/Link can process information through affiliates and providers outside the European Economic Area. Where required, transfers are based on an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or appropriate safeguards such as EU Standard Contractual Clauses. See Stripe/Link privacy information for details and contact options.
10. Retention
- Technical security data is normally kept only as required for operations and defence, generally no longer than 14 days, or until an incident is resolved.
- Incomplete checkout records and business confirmations are generally deleted after 30 days.
- Download access is generally available for seven days; delivery evidence relevant to contract or security can be retained longer.
- Contract, transaction and accounting records are generally retained for up to eight years under German commercial and tax rules; other contract data can remain until limitation periods expire, normally three years from year-end.
- Enquiries are deleted when no longer needed unless contract, evidence or retention duties require continued storage.
11. Your rights
Subject to the GDPR, you can request access, correction, erasure, restriction and data portability. You can object, on grounds relating to your situation, to processing based on legitimate interests. Consent can be withdrawn at any time for the future.
Contact info@az-five-industries.com to exercise your rights. You can also complain to a supervisory authority, in particular the Data Protection and Freedom of Information Commissioner for Baden-Württemberg.
AZ-FIVE does not make solely automated decisions with legal or similarly significant effects. Stripe/Link may perform automated fraud and security checks under its own responsibility.
12. Security and updates
We apply appropriate safeguards including encrypted transport, access restrictions, signed payment notifications, non-public product storage and time-limited download access.
We update this notice when processing, providers or applicable law changes. The version published here is the current version.
