Privacy policy
What we store, why, for how long — and who besides us sees it.
As of: 14 September 2026
This text has been prepared with care but has not yet been reviewed by a lawyer. Changes are possible.
This page shows the English version. The German version is the legally binding one.
1. Controller
Zygan Consulting Ltd., Eleftherias 17, 8560 Pegeia, Paphos, Cyprus
Director: Maik Zygan
Email: kontakt@emporion.market
For questions about data protection and to exercise your rights, an email to this address is enough.
2. Principle
Emporion processes as little personal data as possible. We do not sell data, we do not run advertising, and we embed no services that track your behaviour across websites. Fonts and images are held on our own systems; no content is loaded from third-party servers.
3. Which data we process
3.1 When visiting the website
When a page is requested, technically necessary data transmitted by your browser is processed (the address requested, the time, the amount of data transferred, browser and operating system details, IP address). This data is required in order to deliver the page and to keep operations secure.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and uninterrupted operation).
Retention: server and error logs are deleted after 90 days at the latest.
3.2 When registering and signing in
To sign in we need your email address and a password. We store the password exclusively as a cryptographic hash (Argon2id); it is never known to us in plain text. You may optionally provide a display name and a phone number; your country is required so that we can show you the matching listings.
To secure your account you may voluntarily set up two-factor sign-in or passkeys. In that case we store the corresponding secret or the public key of your device.
Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement), for the security measures Art. 6(1)(f) GDPR.
3.3 When publishing listings
Listings you publish — texts, photos, price, place, category — are published on the platform. They are publicly accessible and may be indexed by search engines. What is shown is your display name, not your email address.
Please note: whatever you publish in text or photo is public. Avoid details you do not want to disclose. From uploaded photos we automatically remove the embedded metadata (EXIF), in particular location data.
Legal basis: Art. 6(1)(b) GDPR.
3.4 For messages between users
Messages run exclusively through the mailbox on the platform. Your email address is not passed on to the other party; by email we only send a notification without any message content.
Message contents are not visible to us by default. Only when a message is reported can the conversation in question be inspected for review; that access is logged.
If you have a message translated, its text is transmitted for that purpose to Anthropic in the USA (see section 5). This happens only on your click and for the single message you selected — there is no automatic translation and no setting that switches one on. The translation is stored with the message and shares its retention; the original stays unchanged alongside it.
Legal basis: Art. 6(1)(b) GDPR, for the review of reports Art. 6(1)(f) GDPR and Art. 6(1)(c) GDPR in conjunction with Regulation (EU) 2022/2065.
3.5 For reports and feedback
If you report a listing or send us feedback, we process your details in order to handle the matter. For feedback we additionally record technical details about your device and the page you were on, so that faults can be traced.
3.6 Audience measurement
We use the self-hosted software Umami. It works without cookies, without cross-device recognition, and stores no personal data. The data does not leave our systems. No consent is required for this.
Legal basis: Art. 6(1)(f) GDPR.
3.7 When you sign up for news
On news.emporion.market you can sign up to hear about the launch of Emporion. For this we store your email address, the language of the page on which you signed up, and the times of signing up and of your confirmation. We use the address for a launch message, for updates on our progress (at most one email a month) and to match the promised highlights to you if you later create an account with the same address.
You are only signed up once you confirm: we first send an email with a link. If you do not confirm, we delete the address after seven days. You can unsubscribe at any time with one click from every email; the address is then deleted.
Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw your consent at any time with effect for the future.
4. Cookies
We use technically necessary cookies only:
| Purpose | Duration |
|---|---|
| Signed-in session | until sign-out, at most six months |
| Language choice | up to one year |
| Short-term store for form input | a few minutes |
| Showing the sign-in state in the header | session |
A consent banner is not required because we set no cookies for advertising or analytics purposes.
5. Recipients and processors
We pass data on only as far as it is necessary for operations. Data processing agreements under Art. 28 GDPR are in place with all of the service providers named.
| Service provider | Which data | Purpose |
|---|---|---|
| Anthropic PBC USA (Standardvertragsklauseln) | listing photos, listing texts, buying-advisor questions — and the text of a message if you have it translated | photo-to-listing, translation, buying advisor, message translation on request |
| Brevo (Sendinblue SAS) EU (Frankreich) | email address, subject and content of the message sent | sending confirmation, password and notification emails, and emails to the news list |
| IONOS SE EU (Deutschland) | everything stored on the server: accounts, listings, images, logs | hosting the server |
| Hetzner Online GmbH EU (Finnland) | the nightly backups — that is, the same data as on the server | keeping backups off the server |
No data is transmitted for search: the semantic search runs entirely on our own servers. Neither search queries nor listing texts leave our systems for it.
Not a recipient: technology we run ourselves
This technology runs on our own server. It processes data for us but passes nothing to third parties — which is why it is listed here and not in the table above.
| Technology | Which data | Purpose |
|---|---|---|
| bge-m3 | listing texts and search queries | similarity search — the model runs on our server, not at a provider |
6. Use of artificial intelligence
We use AI systems in four places:
- Listing suggestion from a photo: the photo and your details are transmitted to Anthropic to generate a suggestion. The suggestion is presented to you for review; only what you confirm is published.
- Translation: listing texts are transmitted for translation into the other languages offered.
- Buying advisor: your question and the listings found for it are transmitted in order to answer it. The buying advisor is an AI assistant, not a human; the page says so.
- Translating messages: the text of a message is transmitted for translation — only if you press the translate button, and only for that one message. Without your click no message leaves our systems.
The providers do not use this data to train their models. Further details are on our page AI at Emporion.
7. Retention
- Account data: until the account is deleted.
- Listings: after a sale or removal they remain retrievable as “no longer available”, so that existing links do not lead nowhere; they then contain no personal details any more.
- Messages: as long as both accounts involved exist.
- Sign-up for news: until you unsubscribe; unconfirmed sign-ups seven days.
- Logs of system errors and email delivery: 90 days.
- Reports: permanently, in order to be able to account for decisions; anonymised after an account is deleted.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).
You can delete your account yourself at any time — in your own area under “Settings”. Your personal data is then removed; your listings are anonymised and set to “no longer available”.
You also have the right to lodge a complaint with a supervisory authority. The competent authority is the Commissioner for Personal Data Protection, Cyprus (dataprotection.gov.cy); you may also contact the authority where you live.
9. Data security
The connection to Emporion is encrypted end to end. Passwords are stored exclusively as hashes. Backups are held encrypted with a separate provider in the EU. Access to administrative functions is protected by two-factor sign-in.
10. Changes
We adapt this policy when the service or the legal situation changes. The version published here at the time is the one that applies.