Skip to main content
AploIQ — Where information becomes intelligence
Services
All Services

Investigations & Digital Evidence

  • eDiscovery & Document Review
  • Digital & Mobile Forensics
  • Internal Investigations

Cybersecurity & Data Protection

  • Cyber Incident Evidence
  • Data Breach Support
  • Data Subject Access Request (DSAR) Support

Governance, Risk & Controls

  • Risk, Controls & Internal Audit Support

Technology, Data & Automation

  • Workflow Automation
All Services

Investigations & Digital Evidence

  • eDiscovery & Document Review
  • Digital & Mobile Forensics
  • Internal Investigations

Cybersecurity & Data Protection

  • Cyber Incident Evidence
  • Data Breach Support
  • Data Subject Access Request (DSAR) Support

Governance, Risk & Controls

  • Risk, Controls & Internal Audit Support

Technology, Data & Automation

  • Workflow Automation
ApproachExperienceTrustContact
ENEN — EnglishDEDE — DeutschELEL — Ελληνικά
Discuss a matter
  1. Home
  2. /Privacy

Website privacy

Privacy

This page is only about the public AploIQ website. Client work, contracts and project data are handled separately under our engagement terms.

Last updated 24 August 2026.

Who is responsible

AploIQ UG (haftungsbeschränkt), represented by Nikolaos Sarantinos, is responsible for this website. You can reach us at Cecilienstraße 17, 53840 Troisdorf, Germany, or by email at info@aploiq.com.

How the website is used

The AploIQ website application uses no analytics, advertising tracking or tracking pixels, provides no newsletter or contact form, and does not itself set cookies.

The production website is hosted by Render Services, Inc., and the application runs in Render's Frankfurt service region. Render uses Cloudflare to deliver and protect web traffic. When you visit the site, these providers may process technical connection and usage data needed to deliver, secure and troubleshoot it, including IP address, date and time, HTTP method, requested hostname, path or URL, response status, request identifiers, response time, referring source, and browser or device information.

Cloudflare may set strictly necessary security cookies where needed to protect the site, including for bot management, rate limiting or a security challenge. AploIQ does not use these cookies for analytics or advertising. We process technical request data on the basis of our legitimate interest in operating the website securely and reliably (Art. 6(1)(f) GDPR).

Choosing a language

Language versions are provided through separate URLs such as /en/, /de/ and /el/. The public website stores no language preference in browser storage.

If you email us

If you email us, we use the contact details, message content, attachments and related message metadata you provide to respond to and manage the enquiry. Please keep the first message brief and non-sensitive and do not attach evidence or unnecessary personal data.

Email is provided through Microsoft 365 / Exchange Online. GoDaddy participates in the domain's authoritative DNS and Microsoft 365 provisioning or sign-in configuration. The extent of GoDaddy's processing depends on the services configured under the relevant account.

Where an enquiry concerns steps requested before entering into a contract, processing is based on Art. 6(1)(b) GDPR. Otherwise, we rely on our legitimate interest in handling business communications under Art. 6(1)(f) GDPR. Processing required by statutory retention duties is based on Art. 6(1)(c) GDPR.

How long we keep data

The website application does not create visitor profiles or maintain a separate visitor-log database. Technical request and security data can remain available in provider systems for periods governed by the active services, configuration and provider security or legal obligations. Provider dashboard availability is not necessarily the same as physical deletion or anonymisation in provider systems.

We keep email enquiries only for as long as needed to handle the enquiry, any resulting engagement or legal claims. If correspondence becomes part of commercial or tax records, statutory retention may apply: six years for commercial and business correspondence, eight years for invoices and accounting vouchers, and up to ten years for other qualifying records. When no purpose or legal obligation remains, we delete or restrict the data.

Providers and transfers

AploIQ is the controller for the personal data described on this page. Render acts as our processor for website hosting and uses Cloudflare as a subprocessor for traffic delivery and protection. Microsoft acts as our processor for mailbox and correspondence data. These providers may act as independent controllers for limited account, security, abuse-prevention and operational data processed for their own purposes. GoDaddy provides authoritative DNS and participates in the Microsoft 365 account configuration; its precise data-protection role depends on the agreed services and account configuration.

The application runs in Render's Frankfurt service region, and Microsoft's public tenant metadata reports EU scope. These facts do not mean that every provider operation remains in the EEA. Some processing, provider support or subprocessor access may take place outside the EEA, including in the United States. Where GDPR transfer safeguards are required, the relevant provider arrangements include the European Commission's Standard Contractual Clauses. Render and Cloudflare also rely on the EU-US Data Privacy Framework where applicable, while Microsoft applies the Standard Contractual Clauses and supplementary measures.

Your rights

You can ask us to give you access to your personal data (Art. 15), correct it (Art. 16), delete it (Art. 17), restrict its processing (Art. 18), and object to processing based on our legitimate interests (Art. 21). Where Article 20 GDPR applies, you may receive the personal data concerning you that you provided to us in a structured, commonly used and machine-readable format and transmit it to another controller. This applies where processing is based on consent or a contract and is carried out by automated means. You may request direct transmission between controllers where technically feasible. Exercising this right must not adversely affect the rights and freedoms of others. Where we rely on consent, you can withdraw it at any time with effect for the future.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.

AploIQ UG (haftungsbeschränkt)

Back to homepage
AploIQ — Where information becomes intelligence

AploIQ — Where Information Becomes Intelligence

AploIQ UG (haftungsbeschränkt)

Services

Investigations & Digital Evidence

  • eDiscovery & Document Review
  • Digital & Mobile Forensics
  • Internal Investigations

Cybersecurity & Data Protection

  • Cyber Incident Evidence
  • Data Breach Support
  • Data Subject Access Request (DSAR) Support

Governance, Risk & Controls

  • Risk, Controls & Internal Audit Support

Technology, Data & Automation

  • Workflow Automation

Company

ApproachExperienceTrustContact

Legal

ImprintPrivacy

Direct contact

info@aploiq.com