Avensio logoAvensio
EcosystemDocumentationJSON-LD DebuggerContact

Last updated: July 3, 2026

Privacy Policy

This privacy policy explains how personal data is processed in the Avensio software ecosystem, including the Avensio websites, documentation, Nuxt JSON-LD Debugger subscriptions, licence access and related billing processes.

This privacy policy applies to the websites and online services operated by Armin Kunkel under the following domains:

  • https://www.avensio.de
  • https://jsonld.avensio.de
  • https://docs.avensio.de

Avensio is a software ecosystem for developer tools, documentation and paid software subscriptions. In particular, this policy covers the Nuxt JSON-LD Debugger, licence keys, Pro features, package access, Stripe payments, subscription management, cancellation requests, withdrawal declarations, contact requests and server logs.

1. Controller

The controller within the meaning of data protection law is:

Armin Kunkel

Ludwigshafener Str. 17

76187 Karlsruhe

Germany

Phone: +49 (0) 176 7698 3011
Website: https://www.avensio.de
Email: support@jsonld.avensio.de

2. Accessing our Websites

When visitors access avensio.de, jsonld.avensio.de or docs.avensio.de, technical access data is processed to deliver the requested pages and static files, keep the websites stable, troubleshoot errors and protect the services against misuse and automated attacks. Depending on the request, this includes IP address, date and time, requested URL, referrer where transmitted, browser information, status code and transferred data volume.

The websites are hosted by Manitu GmbH. According to the hosting provider, IP addresses in server logs are stored in fully anonymized form. Log data is generally stored for approximately 30 days and then deleted, unless a security incident or misuse requires longer retention. The processing is based on Art. 6(1)(f) GDPR; the legitimate interest is secure and stable operation of the websites.

Technically required cookies and server-side sessions are used where they are needed for language preferences, secure forms, checkout-related requests or CSRF protection. This includes the language cookie i18n_redirected, a server session cookie such as PHPSESSID and short-lived CSRF tokens. Storing or accessing technically required information on the visitor's device is carried out under Section 25(2) TDDDG where this is strictly necessary to provide the requested digital service. Subsequent processing of personal data is based on Art. 6(1)(b) GDPR where it is required for contract initiation or contract performance, and otherwise on Art. 6(1)(f) GDPR for secure forms, secure API calls and stable website operation.

The documentation includes a local search function. The static search index is loaded into the visitor's browser and searched there. Avensio does not receive search terms, does not receive search result clicks and does not create server-side search logs for this local search. The general information about server logs applies only to the technical request for loading the documentation page and its static files.

Avensio does not use advertising trackers or analytics tools on these websites unless this is explicitly stated elsewhere.

3. Contact

If visitors or customers contact Avensio by email or through a contact, feedback or support form, the submitted information is processed to receive, answer and document the request. This includes the email address, name if provided, subject, message content, selected language or category and technical email or request metadata.

Feedback and bug reports can also contain information about the affected developer tool, such as the source of the report, the relevant DevTools area and package or framework versions. This information is used to investigate reported defects, improve Avensio developer tools and reply to the sender where required.

If a request relates to an order, subscription, licence key, cancellation or withdrawal declaration, the message can be assigned to the relevant customer, subscription or licence process. Contract-related requests are processed on the basis of Art. 6(1)(b) GDPR. Other contact and support requests are processed on the basis of Art. 6(1)(f) GDPR; the legitimate interest is handling incoming requests and maintaining support records.

4. Orders and Subscriptions

When a customer starts or completes an Avensio software subscription, the data required for the order, contract, payment, invoice, provision and subscription management is processed. This includes customer and billing details such as name, email address, billing address, company information where provided, tax information, selected plan, billing period, order number, payment status, licence and access status and technical records required to process the subscription.

For business purchases, company name and tax identification information can be processed to classify the order correctly for tax purposes. For consumer purchases, tax location evidence is processed where required for correct taxation. Location evidence is derived from billing information, checkout information, payment information and locally evaluated GeoIP information. The GeoIP lookup uses local GeoLite2 data from MaxMind; the IP address is not sent to MaxMind for this lookup and is not permanently stored for this purpose.

Order and subscription processing is carried out to perform the contract, provide licence-based access, administer active billing periods, document payment events, comply with accounting and tax duties and protect the service against misuse. The legal bases are Art. 6(1)(b) GDPR for contract performance, Art. 6(1)(c) GDPR for legal accounting and tax obligations and Art. 6(1)(f) GDPR for payment troubleshooting, fraud prevention and service security.

5. Payments and Stripe

Payments and subscriptions for commercial Avensio products are processed through Stripe. Payment data is entered and processed in the Stripe checkout. Available payment methods depend on the country, currency and checkout configuration.

Avensio receives the payment and subscription information required to process the order, manage the subscription, provide licence-based access, send confirmations and handle billing-related communication. This includes payment and subscription identifiers, order numbers, payment status, payment method labels, receipt information and billing-related customer data, but not full card details.

Payment provider is Stripe Payments Europe Ltd., Ireland. Stripe's privacy information is available at stripe.com/privacy.

6. Invoices and Transactional Emails

Avensio sends transactional emails related to orders, subscriptions, licence access, invoices, cancellation requests, withdrawal declarations and support. This includes the order confirmation (H1), the provision and activation email with the licence key (H2), the authoritative Avensio invoice by email, cancellation confirmation emails, withdrawal receipt confirmations and support or administration emails.

These emails are required to perform and document the subscription contract, provide access, comply with accounting and tax duties and handle customer requests. Documents or views in the Stripe customer portal can show payment-related information, but the authoritative Avensio invoice is the invoice sent by Avensio by email.

7. Licence Keys and Pro Access

Licence keys are used to activate and verify access to paid Avensio Pro features. Access depends on the active subscription status and the relevant licence and entitlement status. When Pro features or the JSON-LD Debugger DevTools client are used, technical licence checks are performed to verify whether access is currently permitted.

The processed records include licence and access status, order and subscription references, active billing period, cancellation status, payment failure information, access limits and technical verification records. Full licence keys are used only for validation in requests. Persistent lookup is based on protected licence records. Invalid, expired, revoked or replaced licence keys can be blocked to prevent unauthorized access.

Licence and access processing is based on Art. 6(1)(b) GDPR because it is required to provide the paid software access. Security checks, misuse prevention and technical protection of the software are also based on Art. 6(1)(f) GDPR.

8. Package Registry

Avensio packages can be made available through a package registry that is publicly reachable via Avensio infrastructure. Package metadata and package files can be requested without this registry acting as the licence enforcement point. This also applies to packages that contain Pro-related module code.

When package metadata or package files are requested, technical access data is processed to deliver the requested package, operate the registry endpoint, investigate errors and prevent misuse. This includes IP address, time of request, package name, package version, request path and technical response information.

Access to paid Pro functionality is enforced separately through licence checks for the JSON-LD Debugger DevTools client.

9. Customer Portal and Subscription Management

Customers can access the Stripe customer portal through a link from the activation email. The link first leads through the Avensio backend. After validating the request, Avensio creates a short-lived Stripe portal session.

Depending on the portal configuration, customers can manage payment methods, billing details and subscription-related settings in the Stripe customer portal. Plan changes are governed by the information on the website and the Terms. The portal link is not a permanent direct Stripe portal URL.

10. Cancellation Requests

If a customer requests cancellation through the website, Avensio processes the information required to assign the request to the subscription and secure the confirmation process. This includes email address, order number, licence key or subscription information.

Submitting the form does not cancel a subscription by itself and does not reveal whether a matching subscription exists. For security reasons, Avensio sends a confirmation email to the email address associated with the subscription. After confirmation, the cancellation is processed and documented for the end of the current paid subscription period.

11. Withdrawal Declarations

If a consumer submits a withdrawal declaration where this function is available and applicable, Avensio processes the information required to receive, confirm, review and document the declaration. This includes email address, name where provided, order number, subscription information, message content, confirmation records and review status.

The receipt of a withdrawal declaration can be confirmed by email. The declaration is reviewed according to applicable law and the status of performance. Submitting a withdrawal declaration does not automatically mean that the withdrawal is accepted or that a refund is issued.

12. External Links

Avensio pages contain normal links to related Avensio services, Stripe, GitHub, documentation pages and public package registries. Merely loading an Avensio page does not transmit data to these external providers through such links. If a visitor opens an external link, the external provider is responsible for the processing that takes place there.

13. Retention

Personal data is deleted when it is no longer required for the relevant purpose and no statutory retention duties, limitation periods or overriding legitimate interests require further storage. Contract, order, payment, invoice and tax records are retained for as long as required for contract handling, evidence, accounting and tax obligations.

Support and contact requests are retained for as long as required to process the request, maintain support history and defend or establish legal claims. Technical logs are deleted according to the server log rule described above. Confirmation tokens and temporary administration links expire according to their technical validity and are invalidated or marked as used after their purpose has been fulfilled.

14. Your Rights

Subject to the statutory requirements, data subjects have the right to obtain access to their personal data, rectification of inaccurate data, erasure, restriction of processing, data portability where applicable and objection to processing based on legitimate interests. Where processing is based on consent, consent can be withdrawn with effect for the future.

Data subjects also have the right to lodge a complaint with a competent data protection supervisory authority if they believe that the processing of personal data infringes data protection law.

15. Contact

Questions about this privacy policy or requests concerning data protection rights can be sent to support@jsonld.avensio.de.

Avensio logoAvensio

Avensio is a software ecosystem for structured web development.

DocumentationJSON-LD Debugger
ContactLegalPrivacyTerms