AnnexGroup

Legal

Privacy policy

Last updated: 6 October 2026

Working translation. The German version of this text is legally binding.

This site uses cookies for analytics and advertising only with your consent. Without consent, only technically necessary cookies are used. We embed no external fonts, maps or scripts, and we transmit no data to third parties beyond the purposes stated below.

1. Controller

ma-kom agentur UG (haftungsbeschränkt)
Managing director: Pascal Sanwald
Merkelbach 12, 74541 Vellberg, Germany
Phone: +49 7907 4090918
E-mail: mail@annexserver.com

We have not appointed a data protection officer because there is no statutory obligation to do so.

2. Server log files

When you access this site, our hoster automatically processes transmitted data: IP address, date and time, the requested address, the amount of data transferred, browser type and operating system. The legal basis is our legitimate interest in secure and stable operation (Art. 6 (1) lit. f GDPR). The data is not merged with other sources and is deleted after seven days at the latest: the access logs are rotated daily and at most seven files are kept. Our application also keeps its own application log (error messages and, for logins to the administration, the IP address); we delete entries after 30 days. In addition, our server counts per day, page and language how often a page was viewed (with the campaign tag, e.g. “kanal=flyer”, if the address carries one) — without IP address, without browser identifier, without cookie; the figure cannot be attributed to a person.

3. Hosting

This site is operated on a server in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. The provider is Webspace-Verkauf.de ISP e.K., Lichtenfelser Straße 17a, 96271 Grub am Forst, Germany. We send e-mail through our own mail server on that server, not through a mailing service.

4. Support requests

When you use the support form or write to us, we process the details you provide:

  • E-mail address — so we can reply
  • Subject, category and description of your concern
  • Licence number and server version, if you provide them
  • Time of the request and the further course of the ticket
The legal basis is Art. 6 (1) lit. b GDPR where the request serves to initiate or perform a contract, otherwise Art. 6 (1) lit. f GDPR — our legitimate interest in handling requests traceably. We keep support tickets for as long as they are needed for processing and follow-up questions, but no longer than three years after closure; after that, we delete them. Excluded are tickets that concern a transaction — such as a complaint, a correction to an invoice or a withdrawal. These are business letters, and we keep them for six years from the end of the calendar year in which the ticket was closed (§ 257 HGB, § 147 AO; legal basis Art. 6 para. 1 lit. c GDPR). During that time they are locked: we use them only to fulfil this obligation and delete them afterwards. You can check the status of your ticket at /en/support/ticket with the ticket number and e-mail address. We do not create a user account for this.

5. Protection against automated submissions

The support form contains a field invisible to you and a verification token set via JavaScript. No personal data is transmitted to third parties in the process; no external service is used. The legal basis is our legitimate interest in defending against abusive use (Art. 6 (1) lit. f GDPR).

6. Purchasing a licence

On purchase, we process the data required to perform the contract (name or company, e-mail address, billing address, VAT identification number where applicable) as well as the issued licence number. The legal basis is Art. 6 (1) lit. b GDPR. We also need the billing address and the VAT identification number because VAT law requires them for the invoice (§ 14 UStG); to that extent, the legal basis is Art. 6 (1) lit. c GDPR. Consent is not required for this, and we do not request it. Payment is processed by Stripe Payments Europe, Ltd., Dublin, Ireland; payment data is processed there and never reaches us in plain text. We keep invoices and booking records for eight years, in each case from the end of the calendar year in which they arose (§ 147 AO, § 257 HGB). While this period is running, we exempt the purchase data from deletion and lock it against any other use; afterwards we delete it. Stripe may transfer data to Stripe, Inc. in the USA; the basis is the adequacy decision on the EU-US Data Privacy Framework, to which Stripe adheres, supplemented by standard contractual clauses. The checkout offers the payment methods enabled in our Stripe account, depending on country and amount: card (including Apple Pay and Link), PayPal, Klarna, SEPA direct debit, as well as Bancontact, EPS and Amazon Pay. For PayPal and Klarna, your payment is additionally processed by PayPal (Europe) S.à r.l. et Cie, S.C.A. or Klarna Bank AB (publ), each acting as a separate controller; their privacy notices then apply in addition.

7. The server itself

AnnexGroup runs on your own hardware. We have no access to the data you process with it — not to messages, appointments, contacts or user accounts. For that data you are the controller as operator; we are neither controller nor processor for it as long as you give us no access to your installation. Licence verification runs entirely locally, and no telemetry is built in. The only regular connection to us is the update check: if self-update is switched on (the default), your server queries the public update feed at annexserver.com/api/update about once a day. We receive your server’s IP address as a technical necessity (server logs, section 2); no installation identifier, version number or licence is transmitted. If your server downloads an update, that also comes from annexserver.com. Legal basis is our legitimate interest in delivering security updates (Art. 6(1)(f) GDPR). You can switch the query off in the configuration (section update: enabled, auto_check). On the first start under macOS, the operating system checks once with Apple whether the program is notarized. That query is made by Apple, not by us; it can be disabled at system level.

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). For this, contact mail@annexserver.com. You may also lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg. Right to object under Art. 21 GDPR: Where we process data on the basis of legitimate interests (Art. 6(1)(f)), you may object at any time on grounds relating to your particular situation. You may withdraw any consent you have given at any time with effect for the future. The details given when purchasing and in support are required for the contract or for handling your request; without them we cannot deliver or reply. There is no automated decision-making, including profiling.

9. Cookies and analytics

This site uses Google Analytics 4 to analyse usage and, if applicable, Google Ads to measure the success of advertising campaigns. Both services are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data processing takes place only with your consent; until then, no analytics or marketing cookies are set. You can grant or withdraw your consent at any time via the “Cookie settings” link in the footer. The legal basis is Art. 6 para. 1 lit. a GDPR. A transfer to Google LLC in the USA is possible; the basis is the European Commission’s adequacy decision on the EU-US Data Privacy Framework, to which Google LLC adheres.

10. Your choices

When you first visit the site, you can choose between “Only necessary”, “Allow analytics” and “Allow all”. Your choice is stored locally in your browser; we do not create a user profile before consent. If you delete your browser data, the banner will be shown again.

11. Migration check and prospect list

When you enter your address in the migration check, we create an entry in our prospect list:

  • email address
  • your language
  • your answers from the check
  • the channel you came through (for example flyer or LinkedIn)
  • the wording of the consent text with its version and the time of entry
  • your postal address, if you provide one
We use this data exclusively to send you the report with your result, to reply to your enquiries and, if you provide a postal address, to send you a letter about the EWS deadline. We do not send marketing mails. The legal basis is your consent (Art. 6 para. 1 lit. a GDPR), which you can revoke at any time. We delete confirmed entries 24 months after the last contact, immediately via the deletion link in the mail, or upon an informal message to mail@annexserver.com. We automatically delete unconfirmed entries after 30 days.

12. Withdrawal

If you withdraw from a contract using the withdrawal form or in any other way, we process your name, your e-mail address, the identification of the contract, a reason if you provide one, and the date and time of receipt. We need this information to confirm receipt, to unwind the contract and to be able to prove the withdrawal later. The legal basis is Art. 6 para. 1 lit. c GDPR in conjunction with §§ 355, 357 BGB. A withdrawal is a business letter: we keep it for six years from the end of the calendar year in which it was received (§ 257 HGB, § 147 AO); if it leads to a refund, the booking record of that refund for eight years. During that time the data is locked; afterwards we delete it.