Brio-IO Communication Server

Privacy policy

The German version of this privacy policy is legally authoritative; this English translation is provided for convenience only.

This privacy policy explains the nature, scope, and purpose of the processing of personal data when you visit the website brio-io.com.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Zygan Consulting Ltd.
Eleftherias 17
8560 Pegeia, Paphos – Cyprus
Email: contact@brio-io.com

The authorised representative and register details can be found in the legal notice.

2. Hosting and server log files

The website is hosted by IONOS SE (Elgendorfer Str. 57, 56410 Montabaur, Germany). When the website is accessed, the web server automatically records access data in so-called server log files, which your browser transmits:

  • anonymised or shortened IP address
  • date and time of access
  • URL / file accessed
  • amount of data transferred and HTTP status code
  • referrer URL and the browser/operating system used (user agent)

This processing serves the secure, stable operation as well as error and attack analysis. The legal basis is the legitimate interest in a functional and secure web offering (Art. 6(1)(f) GDPR). The logs are deleted after 7 days at the latest and are not merged with other data sources. A data processing agreement pursuant to Art. 28 GDPR is in place with IONOS.

3. Web analytics with Umami (cookieless)

To statistically analyse website usage, we use Umami — a self-hosted, data-minimising analytics software operated on our own infrastructure at stats.brio-io.com.

  • No cookies and no cross-device recognition — a cookie consent banner is therefore not required.
  • Only aggregated data that cannot be traced back to an individual is collected: pages visited, referrer (source), device category, browser, operating system, approximate country of origin, screen resolution, and language.
  • No storage of your IP address and no individual visitor profiles; a page view is assigned to a visit via an anonymous hash value that changes daily.
  • No sharing with third parties — the data does not leave our infrastructure. In particular, there is no transfer to third countries.
  • Umami respects your browser's “Do Not Track” setting: if it is enabled, no measurement takes place.

The legal basis is the legitimate interest in data-minimising, cookieless web analytics to improve our offering (Art. 6(1)(f) GDPR). Since no information is stored on or read from your device, no consent under § 25 TDDDG is required.

4. Contact by email

If you contact us by email (contact@brio-io.com), we process the information you provide (e.g. name, email address, content of the message) solely to handle your enquiry. The legal basis is our legitimate interest in responding to your enquiry (Art. 6(1)(f) GDPR) or — where the enquiry aims at concluding a contract — Art. 6(1)(b) GDPR. The data is deleted as soon as it is no longer required to achieve the purpose and no statutory retention obligations prevent this.

5. Demo instance and your own test data

At demo.brio-io.com we run a publicly accessible, disposable demo instance of the Brio-IO Communication Server. Authenticated users can load their own test files (formats .hl7, .txt, .xml, .json, max. 1 MB) into a connector's test mode via the “Load from file” function, send them through processing, and view and download the result within the application. The data does not leave the application in the process.

  • Test data only: The function is intended exclusively for artificial test data. Processing real personal data — in particular health/patient data — is prohibited. We prominently ask users not to use real data.
  • Automatic deletion: Data entered or loaded and generated results are completely and irretrievably deleted within 2 hours at the latest by an automatic reset of the demo instance. No permanent storage takes place.
  • No sharing, no egress: The demo instance is network-isolated; entered content does not leave the environment and is not transmitted to third parties.
  • Access protection: The demo instance is only reachable after authentication (personalized demo access).

The legal basis is our legitimate interest in providing a meaningful product demonstration (Art. 6(1)(f) GDPR). Should users enter personal data despite our request, it is automatically deleted by the 2-hour reset.

6. Recipients and third-country transfer

Personal data is not shared with third parties, except with the hosting provider named under section 2 within the scope of data processing. No transfer to third countries outside the EU/EEA takes place.

7. Your rights as a data subject

You have the following rights vis-à-vis the controller:

  • access to the data processed (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on a legitimate interest (Art. 21 GDPR)

An informal message to contact@brio-io.com is sufficient to exercise these rights. Independently of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

8. Currency of this policy

This privacy policy will be updated as soon as the data processing changes (for example through new website features).

Note: This draft is not legal advice. A final legal review before the production launch is recommended.