Data Privacy

General information

The kyago web and desktop application (hereinafter referred to as "offer") is an offer from zafaco GmbH (hereinafter referred to as "zafaco"). As part of the service, data is collected in order to be able to make reliable statements regarding the available data transfer rates and net neutrality. The provider's data protection practices comply with the EU General Data Protection Regulation (GDPR). 
The data protection practices of zafaco are in accordance with the EU General Data Protection Regulation (GDPR).

zafaco respects the privacy of the users of its website and has made their protection a top priority when using the website.

This means that zafaco undertakes to treat the information provided by the user with the utmost care and the greatest sense of responsibility at all times. This also applies in particular to co-operation with partners and third parties. zafaco does not, however, accept any liability for third parties unless this is declared separately. Data will not be passed on to third parties for purposes other than the fulfilment of the contract.

Information on the processing of personal data (Art. 13 GDPR):

1. Responsible

zafaco GmbH, Münchener Str. 101/39 in 85737 Ismaning, Germany
e-mail: datenschutz@kyago.de

2. Purpose and legal basis of data processing 

zafaco processes personal data, insofar as this is necessary for the implementation of the offer, on the basis of the following consent of the user (legal basis is Art. 6 para. 1 letter a GDPR):

CONSENT:

I hereby consent to the processing of personal data as described below. This consent can be revoked at any time. Without consent, it is not possible to implement the offer.

Data collected - General:

When using the offer, the following original data, some of which is personal, is collected and stored for each measurement point as part of the measurement procedure for all measurement types:

  • Technology*: LAN, WiFi

  • Geolocation of the end device

  • Public IP address and its DNS name

  • Private IP address*

  • NAT type (local / public)

  • Access network (ASN number)

  • Measurement servers for the respective measurement types and individual tests

  • Date, time

  • Installation ID

  • Test ID

  • Measurement client version

  • Operating system, operating system version, browser type (web application only), time zone, system language

Collected data Measurement type "Speedtest":

When using the offer, the following original data, some of which is personal, is also collected and stored for each measurement point as part of the measurement procedure for the "Speedtest" measurement type: 

  • Measured data transfer rate and data volume in the download

  • Measured data transfer rate and data volume in upload

  • Measured runtime between measurement client and measurement server

  • Protocol information (MTU, MSS)

Collected data "Net neutrality" measurement type:

When using the offer, the original data port, duration of the test and the test result (successful / unsuccessful) are also collected for each individual test as part of the measurement procedure for the "Net neutrality" measurement type, some of which are personalised. In addition, the following individual test-specific data is collected and stored:

  • Video streaming: data transfer rate in upload and download, initial loading time, video quality (resolution), video bit rate, number of quality adjustments, lost video frames

  • Traceroute: number of hops between client and measurement server, routing between client and measurement server, packet runtimes

  • Unchanged content: HTTP header, length of HTTP response

  • UDP: Number of packets received and sent, packet runtimes

For technical reasons, the parameters marked with * are only recorded in the installable desktop application.

Purpose of processing:

The personal data collected as part of the measurement is used by zafaco exclusively to implement the offer.

Anonymisation of the data:

Personal data are the IP address and geolocation used by the user, which are collected as part of the measurement process and which may allow a clear conclusion to be drawn about the identity of the user (personal reference), as well as the data collected during the measurement, as these are assigned to the IP address and geolocation.

For the purpose of validating original data (see above) to raw data, IP addresses are only stored in the raw data as a SHA256 hash, which is generated with a secret salt consisting of 64 randomly generated alphanumeric characters.

The installation ID is assigned once when the desktop application is installed on the user's measurement client and is used to identify all measurements carried out by the user. This ID is removed when the application is uninstalled. When using the web application, the installation ID is stored on the system in the form of a cookie. Deleting the cookie removes this ID from the user's system. If the desktop application is reinstalled on the same measurement client or the web application is called up again, a new installation ID is assigned.

The recording of the routing between the measurement client and measurement server is used to describe the IP path used during the measurement between the user and the measurement remote station. The recorded IP addresses of the routing between the measurement client and measurement server are cleansed of the last octet in order to prevent the possible creation of a personal reference.

Storage duration and deletion:

The original data is deleted a maximum of 3 days after transmission and validation as raw data on the data processing systems.

4. Further processing, recipient of the data

zafaco will merge (aggregate) the raw user data into result data, evaluate it statistically and make it available in anonymised form to the users of the offer or the public and its partners in the form of reports and presentations (e.g. distribution functions, tables). Furthermore, zafaco will visualise raw user data in a map display with the aid of geolocation and make it available to the users of the service, the public and its partners.

The raw data and the aggregated results data will be stored on the data processing systems for the long term.

The aim and purpose is to obtain data with statistical relevance from the raw and results data obtained, which serves as the basis for results reports. This is only possible by storing the raw and results data over a longer period of time. The raw data and results data are also made available to zafaco's partners.

5. Your rights

If the legal requirements are met, you have the following rights:

  • Right to information about the data stored about you and to receive a copy of this data (Art. 15 GDPR)

  • Right to rectification of inaccurate data (Art. 16 GDPR)

  • Right to erasure (Art. 17 GDPR) or to restriction of processing (Art. 18 GDPR) if further processing would not be lawful

  • Right to data portability, i.e. the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller without hindrance from us; where applicable, the right to have us transmit the personal data directly to another controller, where technically feasible (Art. 20 GDPR);

If you believe that we are not processing your personal data in compliance with data protection regulations, you can lodge a complaint with a supervisory authority. The supervisory authority responsible for us is

Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, phone: +49 (0) 981 180093-0, fax: +49 (0) 981 180093-800, e-mail: poststelle@lda.bayern.de