Privacy
The German version of this page is legally binding.
1. Responsible Party
The party responsible for data processing on this website is:
Chi Khang Nguyen
Sascha Nguyen
Wandsbeker Chaussee 224
22089 Hamburg
Germany
Email: info@hiyu.eu
Phone: +49 176 61477117
The two people named above run Hiyu together and jointly decide the purposes and means of the processing. They are therefore joint controllers within the meaning of Art. 26 DSGVO. In an agreement they have set out who handles which duties: informing data subjects and dealing with requests about your rights is done by Chi Khang Nguyen. The central point of contact for all questions about data protection and about exercising your rights is info@hiyu.eu. Regardless of this division, you can assert your rights under the GDPR against either of the two controllers (Art. 26 Abs. 3 DSGVO).
A data protection officer is not required by law and has therefore not been appointed.
2. Your Rights
You have the right at any time to access (Art. 15 DSGVO), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), as well as the right to object to processing (Art. 21). You may withdraw any consent you have given at any time with effect for the future (Art. 7 Abs. 3 DSGVO); the lawfulness of the processing carried out until the withdrawal remains unaffected.
For most matters, a single click is enough: every one of our emails contains a link to unsubscribe and one to delete your data. If you have given us voluntary information about your situation, you can withdraw it via the corresponding link in the associated emails or at any time by message to info@hiyu.eu. For any other matter, you can also write to us at info@hiyu.eu.
3. Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 20459 Hamburg
datenschutz-hamburg.de
4. Accessing the Website (Server Log Files)
When you access our website, our hosting provider processes technically necessary access data: IP address, the date and time of access, the page accessed, the amount of data transferred, notification of successful retrieval, the referrer, as well as the browser type and operating system. The purpose is the technical delivery, stability, and security of the website. The legal basis is our legitimate interest in secure and reliable operation (Art. 6 Abs. 1 lit. f DSGVO). This data is stored only for as long as is necessary for these purposes and is then deleted.
5. Waiting List (Double-Opt-In)
When you sign up for the waiting list, we process your email address and the language you have chosen. To confirm, we send you an email with a confirmation link (Double-Opt-In). To document your consent, we store the time of registration and confirmation. Your IP address is not stored for this proof.
To prevent automated misuse, we limit the number of sign-up attempts. For this purpose, we derive a pseudonymous check value (HMAC) from your IP address and store it briefly; the IP address readable in plain text is not stored for this. This check value is automatically deleted after 24 hours at the latest. The legal basis is our legitimate interest in misuse-free operation (Art. 6 Abs. 1 lit. f DSGVO).
The purpose is to add you to the waiting list and to inform you as soon as Hiyu is available. The legal basis is your consent (Art. 6 Abs. 1 lit. a DSGVO); the logging of consent is based on our legitimate interest in being able to provide proof (Art. 6 Abs. 1 lit. f DSGVO).
You can unsubscribe at any time via the unsubscribe link in every email. After you unsubscribe, we delete your data; to ensure that you receive no further emails, your address may remain stored in the form of a pseudonymous check value (HMAC) on an internal blocklist (Art. 6 Abs. 1 lit. f DSGVO). Unconfirmed sign-ups are deleted at the latest 30 days after registration. We store your confirmed waiting list data only for as long as this is necessary to notify you about the launch of Hiyu, and delete it at the latest three months after the public launch, but no later than 31 December 2026 if the launch has not taken place by then.
6. Voluntary Information About Your Situation
After registering, you can voluntarily answer a few questions about your situation and your needs. These include: who you want to use Hiyu for, in which situations official mail causes you difficulties, your age range, your payment preference, how you have handled such tasks so far, as well as an optional free-text field. This information is stored together with your email address.
The legal basis is a separate, voluntary consent (Art. 6 Abs. 1 lit. a DSGVO). We use this information to improve Hiyu and to demonstrate the need in aggregated, statistical form — including to potential investors. No personal individual details are passed on in the process. You can withdraw this consent at any time with effect for the future via the corresponding link in our emails or by message to info@hiyu.eu.
Please do not enter any special categories of personal data within the meaning of Art. 9 DSGVO into the free-text field (such as information on health, religion, ethnic origin, or political opinions). We do not need such data.
7. Contacting Us
If you contact us by email, we process your details in order to handle your request. The legal basis is our legitimate interest in responding to your matter (Art. 6 Abs. 1 lit. f DSGVO). We delete this data as soon as it is no longer required.
8. Recipients and Processors
To provide our service, we use carefully selected service providers as recipients of your data:
- Hosting: IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The server location is Germany. IONOS processes the data exclusively on our behalf and according to our instructions (processing on behalf pursuant to Art. 28 DSGVO).
- Email delivery: Brevo GmbH (vormals Sendinblue GmbH), Köpenicker Straße 126, 10179 Berlin, Germany. The confirmation and information emails are sent via servers within the EU. Brevo processes the data exclusively on our behalf and according to our instructions (processing on behalf pursuant to Art. 28 DSGVO).
- Protection against spam and bots: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. To protect our sign-up form against automated misuse, we use the Cloudflare Turnstile service. In doing so, technical signals (including your IP address as well as browser and interaction characteristics) are processed in order to distinguish humans from bots; no tracking cookies are set for this. In providing this service, Cloudflare acts on our behalf (Art. 28 DSGVO). Insofar as Cloudflare additionally uses the same signals to improve its own bot and threat detection, Cloudflare is an independent controller for that purpose; the details are governed by the Cloudflare Turnstile Privacy Addendum. The legal basis for its use is our legitimate interest in misuse-free operation (Art. 6 Abs. 1 lit. f DSGVO).
9. Transfer to Third Countries
Your core data (waiting list and email delivery) is processed within Germany or the European Union. One exception is the bot protection of the sign-up form: Cloudflare, Inc. processes the technical signals arising in this context in the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the EU Commission); in addition, standard contractual clauses pursuant to Art. 46 DSGVO are in place. No further transfers to countries outside the EU or the EEA take place.
10. Cookies and Local Storage
This website itself sets no cookies and, during normal use, stores no information on your device and does not access any either. We use no advertising, tracking, or reach-measurement tools and no advertising profiling. Your language choice is held solely in the page address (for example /de/ or /ar/) — no storage is needed for that.
One exception is the protection of the sign-up form against bots (Cloudflare Turnstile, see section 8): this is only loaded when you use the sign-up form, and not already when you merely open the page. In doing so, Turnstile may read technical information from your device and evaluate browser and interaction characteristics in order to distinguish humans from bots. This access serves exclusively the misuse-proof sign-up requested by you; we base it on § 25 Abs. 2 Nr. 2 TDDDG (strictly necessary for an explicitly requested service). A consent banner is not required for this.
Only in the operator's password-protected administration area is a technically necessary session cookie set; under § 25 Abs. 2 Nr. 2 TDDDG this is permitted without consent.
11. No Automated Decision-Making
Automated decision-making or profiling within the meaning of Art. 22 DSGVO does not take place.
12. Security
For security reasons, this website uses TLS/SSL encryption. You can recognize an encrypted connection by the "https://" in the address bar of your browser.
13. Currency and Changes
This privacy policy is dated July 2026. Due to the further development of Hiyu or as a result of changed legal requirements, it may become necessary to adjust this policy.