BITBLADE GROUP

LEGAL

Privacy notice

What this site and this application do with data — and what they demonstrably do not do.

The short version. The home page loads nothing from a foreign host, sets no cookies and measures nothing. There are no analytics services, no ad networks, no embedded typefaces, no maps, no video platform. Anyone who only reads the page leaves exactly one trace: the line in the server log that every web server writes.

Anyone who signs in and analyses images leaves more — that is set out below, point by point.

01Controller

Bitblade Solutions UG (haftungsbeschränkt)
Siemensstraße 14
79787 Lauchringen
Germany

Telephone: +49 6927 1470 987
Email: kontakt@bitblade.io

Represented by its managing director, Maurice Sobiera. Further details are in the imprint.

02Where the data sits

Two machines, both within the European Union, both rented:

Application and home page Contabo GmbH, Munich — this is where the web interface, the analysis and the database run.
Sign-in netcup GmbH, Karlsruhe — this is where the sign-in service (Keycloak) runs, at auth.customer.bitblade.io, and where mail is sent from.

Both are processors under Art. 28 GDPR. Beyond these two there are no recipients: no analytics providers, no ad networks, no content delivery network, no transfer to a third country.

03When you merely open the page

The web server writes one line per request. It contains:

  • the IP address of the requesting device,
  • the date and time,
  • the address requested and the HTTP method,
  • the status code and the amount of data transferred,
  • the referring page, if the browser sends one,
  • the browser's identifier (user agent).

This is what makes delivering the page possible at all, and it is our only means of recognising attacks and faults. The legal basis is our legitimate interest in secure operation, Art. 6 (1) (f) GDPR. The logs are rotated daily and deleted after 14 days. They are not combined with other data and are not analysed to recognise anybody.

04What is stored on your device

No consent banner, because there is nothing to consent to. Only what is strictly necessary for the service you explicitly asked for is stored (§ 25 (2) no. 2 TDDDG):

  • The chosen language — one entry in the browser's local storage (finta.lang), so the page is not back in German on your next visit. It holds a language code and nothing else.
  • The session in the application — the sign-in credentials sit in the browser's session storage and are gone when the tab closes. Deliberately not persistent: a credential that outlives the tab is one somebody left behind on a shared machine.
  • Cookies of the sign-in service — Keycloak sets its own session cookies on auth.customer.bitblade.io, without which signing in does not work. They serve the sign-in and nothing else.

05Account and sign-in

An account is optional; without one you can read the whole home page, download the example export and follow the analysis. It is needed for analyses of your own.

When you sign up we process: email address, first name, last name and a password, which is stored only as a check value and cannot be computed back. Added to that are the times of creation and of sign-ins, and the sessions currently open. An email goes to the address you gave, confirming it — before that the account cannot be used. The legal basis is performance of the usage relationship, Art. 6 (1) (b) GDPR.

The account is a shared Bitblade account and applies to other platforms of the group as well. The registration form therefore offers additional, entirely optional fields — salutation, title, telephone and company details down to the VAT ID. Those fields belong to other platforms. FiNTA does not ask for them, does not evaluate them and does not need them: leaving them empty costs you nothing in FiNTA.

After too many failed attempts an account is temporarily locked. The number of failed attempts is noted for that purpose — legitimate interest in protection against password guessing, Art. 6 (1) (f) GDPR.

06Uploaded images and analyses

What is uploaded is stored: the image file itself, its original filename, its size, its checksum and the format detected for it. For every run there are the chosen parameters, the result files, the numbers, the log of the run, the timestamps and the account that started it.

The analysis does not leave this server. FiNTA runs as a program of its own on the same machine the file sits on. There is no analysis service, no third party's programming interface and no model elsewhere that would be shown the image.

Everything sits inside a workspace. Every account has one of its own that only it can see; shared workspaces are opened by group membership in the sign-in service, and whoever is in one sees the runs kept there. There is no reaching across workspaces: the application decides from the sign-in credential which workspaces a request may reach, and a request for someone else's is answered as though it did not exist.

Images and runs are not deleted automatically, because an analysis should remain reproducible. They are deleted when you ask for it — an email is enough. The legal basis is Art. 6 (1) (b) GDPR.

What you upload is your decision. Microscopy images do not usually contain personal data. If you do upload some anyway — in a filename, for instance — you remain responsible for it; in that case, upload nothing you are not entitled to.

07Email

We send email through a mail server of our own on the netcup machine named above, not through a mailing provider. Only messages belonging to the account are sent: confirmation of the address and, if you ask for it, a password reset. There is no newsletter and no advertising.

If you write to us at kontakt@bitblade.io, we process your message in order to answer it — Art. 6 (1) (b) or (f) GDPR. We keep such correspondence for as long as the matter requires, and beyond that only where statutory retention periods apply.

08Your rights

You have the right of access to the data held about you (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to receive it in a portable format (Art. 20). Where we rely on a legitimate interest, you may object to the processing (Art. 21).

An informal message to kontakt@bitblade.io is enough for all of that. You may also complain to a supervisory authority; ours is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

09No automated decisions

There is no automated decision-making and no profiling within the meaning of Art. 22 GDPR. FiNTA measures fibres in images; it does not judge people.

10Changes

When what the application does changes, this notice changes with it. The version available here is the one that applies; the date below it says which that is.

Last updated: 15 August 2026 · Questions about data protection: kontakt@bitblade.io