Privacy Policy

Version 1.0
Effective Date: August 11, 2026

This Privacy Policy explains how Hanko GmbH (“Hanko”, “we”, “us”) processes personal data when you visit our website, create or use a Hanko Cloud account, communicate with us, request support, or otherwise interact with Hanko.

Hanko Cloud is intended exclusively for business and professional use. However, personal data relating to individual users, employees, representatives, customers, prospects and other contacts remains protected under applicable data protection law.

1. Controller

The controller responsible for the processing described in this Privacy Policy is:

Hanko GmbH
Ringstraße 19
24114 Kiel
Germany

General contact: info@hanko.io
Privacy contact: privacy@hanko.io

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed by Hanko as a controller in connection with:

  • our website at hanko.io;
  • Hanko Cloud and the Hanko Cloud Console at cloud.hanko.io;
  • Hanko Cloud account administration;
  • billing and payments;
  • product analytics;
  • service and product communications;
  • support;
  • sales and customer relationship management;
  • email, calendar and business communications; and
  • other direct interactions with Hanko.

This Privacy Policy does not govern personal data that Hanko processes solely on behalf of Hanko Cloud customers through Hanko Auth or Hanko Passkey API.

For such data, the relevant Hanko Cloud customer is normally the controller and Hanko acts as a processor or subprocessor under the Hanko Cloud Data Processing Agreement (“DPA”).

If you are an End User of an application that uses Hanko and have questions about your authentication or account data, you should normally contact the operator of that application. Hanko assists its customers with data subject requests as required under the DPA.

3. Legal Bases

Depending on the processing activity, we process personal data on one or more of the following legal bases:

  • Article 6(1)(b) GDPR: where processing is necessary to enter into or perform a contract with you personally;
  • Article 6(1)(c) GDPR: where processing is necessary to comply with a legal obligation; and
  • Article 6(1)(f) GDPR: where processing is necessary for our legitimate interests or those of a third party and those interests are not overridden by your rights and interests.

Because Hanko Cloud is a business service, the individual using Hanko Cloud is often acting on behalf of a company or other organization and is not personally a party to the contract. In those cases, we generally rely on our legitimate interests in establishing, administering and securing the business relationship rather than Article 6(1)(b) GDPR.

4. Visiting Our Website

4.1 Website delivery

Our website is created and hosted using Webflow.

When you visit our website, technical information required to deliver and secure the website may be processed, including:

  • IP address;
  • date and time of the request;
  • requested page or resource;
  • browser type and version;
  • operating system;
  • referring page;
  • device and network information; and
  • technical error and security information.

We process this information to:

  • deliver the website;
  • maintain its stability and security;
  • detect technical problems;
  • prevent abuse and attacks; and
  • protect our systems and users.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the reliable, secure and efficient operation of our website.

Technical information is retained only for as long as reasonably necessary for website operation, security and troubleshooting, subject to the applicable retention settings of our service providers.

4.2 Cloudflare security functionality

Infrastructure used to deliver and protect our website includes Cloudflare functionality.

Cloudflare sets the _cfuvid cookie as part of its security and rate-limiting functionality. The cookie allows requests from different visitors who share the same IP address to be distinguished for rate-limiting purposes.

The cookie is used for security and traffic management. We do not use it for advertising or website analytics.

The associated processing is based on Article 6(1)(f) GDPR. Our legitimate interest is protecting our website and infrastructure against abuse and ensuring reliable service delivery.

4.3 Webflow Forms

We use Webflow Forms for certain contact, support and sales inquiries.

If you submit a form, we may process:

  • your name;
  • business email address;
  • company or organization;
  • job title or role, where provided;
  • the content of your request;
  • information you voluntarily provide; and
  • technical information associated with the submission.

Depending on the nature of the request, this information may subsequently be processed through our support, CRM or business communication systems described below.

We process form submissions to respond to your request and manage our business relationship.

The legal basis is:

  • Article 6(1)(b) GDPR where you personally request steps prior to entering into a contract or are personally the contracting party; or
  • Article 6(1)(f) GDPR where you communicate with us on behalf of an organization or for another business purpose.

Our legitimate interest is communicating with prospective and existing customers and responding to business inquiries.

5. Website Analytics with Plausible

We use Plausible Analytics to understand how our website is used and to measure overall website traffic.

Plausible provides aggregate website statistics without using cookies, browser local storage or persistent visitor identifiers.

Information used to generate these statistics may include:

  • page URL;
  • referrer;
  • browser;
  • operating system;
  • device type; and
  • approximate geographic information.

Plausible does not store raw IP addresses or create persistent identifiers that allow visitors to be recognized across different days or websites.

We use Plausible exclusively to measure website visits and understand general usage patterns.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are understanding and improving the performance, content and usability of our website while minimizing the amount of data processed.

Plausible analytics data is processed and stored in the European Union.

6. Hanko Cloud Accounts and Console

When you create or use a Hanko Cloud account, we process personal data relating to you as an account holder, administrator or Authorized User.

This may include:

  • email address;
  • internal account and user identifiers;
  • authentication and session information;
  • IP address;
  • browser, device and platform information;
  • timestamps;
  • account roles and permissions;
  • organization information, where provided;
  • projects associated with your account;
  • plan and subscription information;
  • Hanko Cloud Console activity;
  • security events; and
  • communications relating to your account.

We use this information to:

  • create and administer your Hanko Cloud account;
  • authenticate you;
  • provide access to Hanko Cloud;
  • manage projects, roles and permissions;
  • administer subscriptions;
  • provide customer support;
  • communicate important service information;
  • maintain the security of Hanko Cloud;
  • prevent fraud, misuse and unauthorized access; and
  • comply with legal obligations.

The legal basis is:

  • Article 6(1)(b) GDPR where you personally contract with Hanko;
  • Article 6(1)(f) GDPR where you use Hanko Cloud on behalf of an organization; and
  • Article 6(1)(c) GDPR where processing is required by law.

Our legitimate interests include providing and administering Hanko Cloud, managing our business relationships and protecting our services, customers and infrastructure.

Hanko Cloud infrastructure is currently provided using service providers including Amazon Web Services, Hetzner and adesso as a service.

Personal data that Hanko processes through Hanko Auth or Hanko Passkey API on behalf of a Customer is governed by the DPA rather than this Section.

7. Product Analytics with PostHog

We use PostHog Cloud EU for product analytics within the Hanko Cloud Console.

We use PostHog to:

  • understand how Hanko Cloud is used;
  • understand which functions are useful to our customers;
  • identify usability problems;
  • identify technical problems; and
  • improve and prioritize development of the product.

Analytics data may include:

  • a pseudonymous internal Hanko user identifier;
  • product events and feature usage;
  • pages or areas of Hanko Cloud used;
  • timestamps;
  • browser and device information;
  • technical event metadata; and
  • information relating to interaction with the Hanko Cloud Console.

We configure PostHog without persistent browser storage for analytics. We do not use PostHog analytics cookies, local storage or session storage to persist a PostHog-generated user identifier on your device.

Instead, Hanko provides its own internal UUID to PostHog so that product events relating to the same Hanko Cloud user can be associated with one another.

We do not use your name or email address as the analytics identifier.

The UUID is pseudonymous rather than anonymous because Hanko can associate it with the corresponding Hanko Cloud account.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are:

  • understanding how our product is used;
  • improving usability and functionality;
  • prioritizing product improvements;
  • identifying technical problems; and
  • maintaining and improving Hanko Cloud.

PostHog Cloud EU stores the analytics data in Frankfurt, Germany.

You may object to this processing as described in Section 18.

8. Cookies and Browser Storage

We do not use cookies for advertising or cross-site tracking.

We also do not use analytics cookies for Plausible or, under our current configuration, PostHog.

The following cookies and browser storage may nevertheless be used for functional and security purposes.

8.1 Hanko Cloud

Hanko Cloud may use cookies or browser storage where technically necessary to:

  • authenticate users;
  • maintain secure sessions;
  • preserve authentication or security-related state;
  • remember settings required to provide requested functionality; or
  • protect Hanko Cloud against misuse.

8.2 Cloudflare

Our website infrastructure sets the _cfuvid cookie through Cloudflare functionality.

Its purpose is to support security and rate limiting, including distinguishing different visitors who share the same public IP address.

We do not use this cookie for advertising or analytics.

8.3 Chatwoot

We use a Chatwoot support widget on our website.

When the Chatwoot widget is loaded, Chatwoot sets the cw_conversation cookie. This cookie is used to maintain a support conversation when a visitor navigates between pages or returns to the website later.

The cookie may therefore be set before you actively open or start a support conversation.

If you use the support chat, additional information may be associated with the conversation as described in Section 11.

We use cw_conversation only to provide and maintain the support functionality. It is not used by Hanko for advertising, product analytics or website analytics.

9. Service and Product Communications

We use the email address associated with your Hanko Cloud account to send communications relating to the operation and use of Hanko Cloud.

These communications may include:

  • welcome and onboarding information;
  • security notices;
  • service incidents and important operational information;
  • material product changes;
  • breaking changes;
  • feature deprecations;
  • required migrations;
  • changes affecting continued use of Hanko Cloud;
  • changes to contractual or privacy documentation; and
  • other important information relating to the Services.

We use Loops to deliver these communications.

These messages are service and product communications. We do not use this communication channel for promotional newsletters, discounts or unrelated advertising.

The legal basis is:

  • Article 6(1)(b) GDPR where a communication is necessary for a contract with you personally; or
  • Article 6(1)(f) GDPR for communications with representatives of our business customers and other service-related product communications.

Our legitimate interests are operating Hanko Cloud, keeping customers informed about relevant changes and helping customers use the Services securely and effectively.

Certain security, contractual and operational communications are necessary for maintaining a Hanko Cloud account and cannot be disabled while the account remains active.

Loops is operated from the United States. International transfers are addressed in Section 16.

10. Billing and Payments

If a Customer subscribes to a paid Hanko Cloud plan, we process information required to manage subscriptions, billing and payments.

This may include:

  • name;
  • company name;
  • billing address;
  • email address;
  • VAT or tax information;
  • subscription and plan information;
  • invoice information;
  • transaction information;
  • payment status; and
  • identifiers associated with the payment transaction.

We use Stripe for payment processing and billing.

Payment card information may be submitted directly to Stripe rather than being stored by Hanko.

We process billing information to:

  • provide paid subscriptions;
  • collect and account for payments;
  • issue invoices;
  • manage upgrades, downgrades and cancellations;
  • handle billing questions and disputes; and
  • comply with accounting and tax obligations.

The legal basis is:

  • Article 6(1)(b) GDPR where you personally enter into the paid contract;
  • Article 6(1)(f) GDPR for administration of our business customer relationships; and
  • Article 6(1)(c) GDPR for statutory accounting and tax obligations.

Stripe may process certain information for its own payment-processing, regulatory and fraud-prevention purposes under its own responsibility.

Billing and accounting information is retained for the statutory retention periods applicable to Hanko.

11. Support with Chatwoot

We use Chatwoot Cloud to manage technical support requests and customer conversations.

When you use our support chat or otherwise contact support through Chatwoot, we may process:

  • name, where provided;
  • email address, where provided;
  • company or organization;
  • Hanko Cloud account information;
  • support conversation content;
  • timestamps;
  • technical information relevant to your request; and
  • files or other information that you voluntarily provide.

Our support is intended primarily for technical and product-related questions concerning Hanko and Hanko Cloud.

Please do not send us:

  • passwords;
  • private keys;
  • TOTP secrets;
  • authentication tokens;
  • unnecessary personal data relating to your End Users; or
  • other sensitive information

unless we specifically request it and provide an appropriate secure method for transmission.

We process support data to:

  • respond to questions;
  • troubleshoot technical issues;
  • understand and resolve product problems; and
  • maintain our customer relationships.

The legal basis is:

  • Article 6(1)(b) GDPR where you personally contract with Hanko; or
  • Article 6(1)(f) GDPR for support provided to representatives of business customers and other business contacts.

Our legitimate interests are providing effective technical support and maintaining reliable customer relationships.

Chatwoot Cloud involves processing in the United States. International transfers are addressed in Section 16.

12. Customer Relationship Management and Sales

We use Attio as our customer relationship management (“CRM”) system.

We may process business contact information including:

  • name;
  • business email address;
  • company or organization;
  • job title or role;
  • business contact information;
  • requests and areas of interest;
  • communication history;
  • meeting and interaction information;
  • sales and customer relationship status; and
  • internal notes relating to the business relationship.

We use this information to:

  • respond to sales inquiries;
  • manage prospective and existing customer relationships;
  • keep track of communications and agreed next steps;
  • prepare offers and agreements;
  • manage commercial relationships; and
  • maintain appropriate business records.

The legal basis is:

  • Article 6(1)(b) GDPR where the processing relates to steps requested by you before entering into a contract or to a contract with you personally; or
  • Article 6(1)(f) GDPR for business relationship management involving representatives and contacts of organizations.

Our legitimate interests are efficiently managing prospective and existing business relationships and maintaining relevant business records.

Attio may involve processing outside the European Economic Area. International transfers are addressed in Section 16.

13. Email, Calendar and Business Collaboration

13.1 Google Workspace

We use Google Workspace for business email, calendar, document collaboration and related business processes.

Personal data processed through Google Workspace may include:

  • name and business contact information;
  • email content and metadata;
  • calendar invitations and meeting information;
  • files and documents;
  • contractual and business communications; and
  • information you voluntarily provide to us.

We use Google Workspace to communicate with customers, prospective customers, suppliers and other business contacts and to manage our business operations.

Depending on the context, the legal basis is Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR.

13.2 Slack

We use Slack for internal team communication and collaboration.

In the course of our work, Slack may contain limited personal data relating to customers, prospective customers and other business contacts, including:

  • names;
  • company names;
  • business contact information;
  • excerpts or summaries of business communications;
  • support or operational context; and
  • information necessary for internal coordination.

We do not use Slack as a primary repository for Hanko Cloud End User authentication data.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is efficient internal communication and collaboration.

Google and Slack operate globally and may involve processing outside the European Economic Area. International transfers are addressed in Section 16.

14. Other Recipients

We disclose personal data only where necessary for the purposes described in this Privacy Policy.

Categories of recipients may include:

  • cloud and infrastructure providers;
  • website hosting and content delivery providers;
  • security providers;
  • analytics providers;
  • payment and billing providers;
  • email and communication providers;
  • CRM providers;
  • customer support providers;
  • professional advisers such as lawyers, accountants and auditors;
  • authorities and courts where disclosure is legally required; and
  • parties involved in a corporate transaction where necessary and legally permitted.

Service providers used for the processing described in this Privacy Policy currently include:

  • Webflow;
  • Cloudflare;
  • Plausible Analytics;
  • PostHog;
  • Loops;
  • Stripe;
  • Attio;
  • Google Workspace;
  • Slack;
  • Chatwoot;
  • Amazon Web Services;
  • Hetzner; and
  • adesso as a service.

Where a provider acts as a processor on our behalf, we require it to process personal data in accordance with applicable data protection law and appropriate contractual obligations.

15. Personal Data Processed on Behalf of Hanko Cloud Customers

Hanko Cloud customers may use Hanko Auth and Hanko Passkey API to process personal data relating to their own End Users.

For this processing:

  • the Hanko Cloud customer is normally the controller or a processor acting for another controller;
  • Hanko acts as a processor or subprocessor;
  • Hanko processes the personal data according to the Customer’s documented instructions; and
  • the processing is governed by the Hanko Cloud DPA.

The DPA describes, among other things:

  • the types of Customer Personal Data processed;
  • processing purposes;
  • technical and organizational measures;
  • authorized Subprocessors;
  • processing locations;
  • export and deletion; and
  • assistance with data protection obligations.

This Privacy Policy does not replace the privacy notice that a Hanko Cloud customer must provide to its own End Users.

16. International Data Transfers

We prefer European processing locations where reasonably available. However, some service providers used for the processing described in this Privacy Policy are established outside the European Economic Area or use infrastructure, personnel or subprocessors located outside the EEA.

Personal data may therefore be transferred to or accessed from third countries, including the United States, in connection with providers such as:

  • Webflow and its infrastructure providers;
  • Cloudflare;
  • Loops;
  • Stripe;
  • Attio;
  • Google;
  • Slack;
  • Chatwoot; and
  • other providers where applicable.

Where a transfer outside the European Economic Area requires additional safeguards under applicable data protection law, we use an appropriate transfer mechanism.

Depending on the recipient and transfer, this may include:

  • an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework where the recipient is appropriately certified;
  • Standard Contractual Clauses approved by the European Commission; and
  • supplementary contractual, technical or organizational safeguards where required.

PostHog product analytics is configured to use PostHog Cloud EU, with analytics data stored in Frankfurt, Germany.

Plausible website analytics data is processed and stored in the European Union.

The processing of Customer Personal Data through Hanko Auth and Hanko Passkey API is subject to the separate data-location provisions of the Hanko Cloud DPA.

You may contact privacy@hanko.io for additional information about safeguards applicable to a particular international transfer.

17. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, unless we are legally required or entitled to retain it for longer.

Retention periods depend on the type of information and the context of the processing.

In particular:

  • Hanko Cloud account and administration data is generally retained while the account exists and afterwards for as long as reasonably necessary for account closure, security, dispute resolution or legal obligations;
  • billing, accounting and contractual records are retained for applicable statutory retention periods;
  • support communications are retained for as long as reasonably necessary to resolve the request, maintain the customer relationship and establish or defend legal claims;
  • CRM information is periodically reviewed and deleted or updated when it is no longer reasonably relevant to the prospective or existing business relationship;
  • business communications are retained according to their relevance to the ongoing business relationship and applicable legal obligations;
  • product analytics data is retained only for as long as reasonably necessary for product analysis and improvement; and
  • website analytics is retained in aggregate form according to our analytics configuration.

Personal data subject to a legal preservation obligation or reasonably required for the establishment, exercise or defense of legal claims may be retained for the relevant period.

Customer Personal Data processed by Hanko on behalf of Hanko Cloud customers is retained and deleted according to the DPA.

18. Your Rights

Subject to the requirements and limitations of applicable data protection law, you may have the right to:

  • obtain confirmation as to whether we process personal data relating to you;
  • obtain access to your personal data;
  • have inaccurate personal data corrected;
  • request deletion of your personal data;
  • request restriction of processing;
  • receive personal data you provided to us in a structured, commonly used and machine-readable format where the right to data portability applies;
  • object to processing based on Article 6(1)(f) GDPR;
  • withdraw consent at any time where a particular processing activity is based on consent; and
  • lodge a complaint with a competent data protection supervisory authority.

Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation.

If you object, we will stop processing the relevant personal data unless:

  • we demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms; or
  • the processing is necessary for the establishment, exercise or defense of legal claims.

To exercise your rights, contact:

privacy@hanko.io

We may request information reasonably necessary to verify your identity before processing a request.

You also have the right to lodge a complaint with a data protection supervisory authority, including the authority responsible for your place of residence or work or the supervisory authority responsible for Hanko in Schleswig-Holstein, Germany.

19. Automated Decision-Making

We do not use personal data covered by this Privacy Policy for decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

20. Security

We implement appropriate technical and organizational measures designed to protect personal data against:

  • unauthorized access;
  • unlawful disclosure;
  • accidental or unlawful loss;
  • alteration;
  • destruction; and
  • other unlawful processing.

Our measures include, as appropriate:

  • access controls;
  • authentication controls;
  • encryption;
  • logging and monitoring;
  • vulnerability and security management;
  • incident response processes; and
  • organizational safeguards.

No internet-based service can guarantee absolute security. We therefore review and improve our security measures based on relevant risks and technical developments.

21. Changes to this Privacy Policy

We may update this Privacy Policy where necessary to reflect:

  • changes to our services;
  • changes to our processing activities;
  • changes to service providers;
  • legal or regulatory developments; or
  • improvements to transparency and clarity.

The current version is published on our website together with its Effective Date.

Where a change materially affects how we process personal data relating to Hanko Cloud account users, we may also notify affected users by email or through Hanko Cloud.

22. Contact

For questions about this Privacy Policy or the processing of your personal data, contact:

Hanko GmbH
Ringstraße 19
24114 Kiel
Germany

Privacy: privacy@hanko.io
General contact: info@hanko.io