Legal
Privacy Policy
Privacy policy for the ocatis coming-soon website and waitlist signup flow. Effective date: 2026-06-19.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
itcv Gesellschaft mit beschränkter HaftungSolmsstr. 71
60486 Frankfurt
Germany
Phone: +49.69.24742919-0
Email: info@itcv-software.com
Privacy requests (access, deletion, objection, etc.): info@itcv-software.com
2. Scope
This policy applies to the ocatis coming-soon website at ocatis.com (and the demo/staging hostname when used), the waitlist form, optional profile details after confirmation, and the related first-party API endpoints that handle signup, confirmation, unsubscribe, and abuse protection.
Separate ocatis product environments on other domains are only governed by this policy if they explicitly reference it.
3. Waitlist form and related processing
When you submit the waitlist form or update optional profile details, the application processes the information you provide:
- name, if you provide it
- work email address
- company, if you provide it
- consent confirmation and selected locale
- optional profile details after email confirmation
- technical request metadata such as IP address and user-agent for abuse prevention
Purpose: handling the waitlist signup, sending launch and early-access updates, managing preview outreach, operating confirmation and unsubscribe links, validating your email address via double opt-in, and protecting the form against abuse.
Legal bases: Art. 6(1)(a) GDPR for the waitlist signup and consent-based launch emails (you give consent by submitting the form; you may withdraw consent at any time under Art. 7(3) GDPR). Art. 6(1)(f) GDPR for technical request metadata (IP address, user-agent) used for abuse prevention and for secure website operation.
4. Website delivery and security logs
When you open the website, technical request data is processed by the hosting infrastructure to deliver pages and maintain security. Typical categories include:
- IP address
- date and time
- requested path or resource
- HTTP status
- user-agent
- referrer, if sent by the browser
Purposes: website delivery, system stability, security, and abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interests). This data is not combined with other sources to profile you.
5. Theme preference storage
The website uses next-themes to remember your selected light or dark mode in your browser's local storage on your device. Nothing is sent to the server. Legal bases: Art. 6(1)(f) GDPR and Section 25(2) no. 2 TDDDG (storage strictly necessary for the requested display functionality).
6. Recipients and processors
Waitlist submissions are persisted in a SQLite database on the application server. Transactional email (confirmation, resend, team notification) is delivered via SMTP using Microsoft Azure Communication Services as the configured mail provider. Processing by these providers is governed by data processing agreements where legally required.
7. International transfers
If a selected processor processes data outside the European Economic Area, transfers rely on a valid GDPR transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or another mechanism under Chapter V GDPR.
8. Storage and retention
Waitlist records are stored in a SQLite database hosted on the same server as the application. The database file is created with owner-only filesystem permissions and is not accessible from the public web. The database holds:
- subscriber email, optional name, optional company, locale, consent status, and signup timestamp
- a confirmation token used to validate the email address; the token expires 7 days after issuance
- request metadata (IP address, user-agent) for abuse prevention
- a short-lived rate-limit log keyed by IP address, pruned automatically after the rate-limit window expires
Confirmed subscribers remain on the list until they unsubscribe via the link in every email or request deletion from info@itcv-software.com. Unconfirmed subscriptions whose token has expired may be deleted at any time. Hosting security logs are retained only as long as necessary for the purposes stated above unless longer retention is required by law.
9. Your rights
You have the right to:
- access your personal data (Art. 15 GDPR)
- request rectification (Art. 16 GDPR)
- request erasure (Art. 17 GDPR)
- request restriction of processing (Art. 18 GDPR)
- data portability where applicable (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent at any time for future launch emails (Art. 7(3) GDPR)
- lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, contact info@itcv-software.com.
10. Supervisory authority (Germany)
Given the controller's seat in Frankfurt am Main, the competent authority is generally:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)Postfach 3163, 65021 Wiesbaden, Germany
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
You may also contact another competent authority in your EU country of residence or work.
11. Tracking and third-party scripts
This website does not load analytics, advertising tags, or third-party tracking scripts. The waitlist form is handled by first-party API routes on the same site.
12. Automated decision-making
No automated decision-making with legal or similarly significant effects under Art. 22 GDPR is implemented on this website.
13. Changes
We may update this policy to reflect legal, technical, or organizational changes. The latest version will be published on this page with an updated effective date.
For provider details pursuant to Section 5 DDG, see our Impressum.
The German and English versions of this privacy policy are legally authoritative. Translations into other languages are provided for convenience only; in case of discrepancies, the German version prevails.