Controller and contact
The controller for processing within the meaning of the GDPR is Astoria Systems GmbH, Bosenheimer Straße 219, 55543 Bad Kreuznach, Germany.
Email: service@astoria.systems, phone:+49 2821 39 86 20. Further details are in theLegal notice.
We have not appointed a data protection officer; the legal conditions for doing so do not apply. For any data protection matter you can reach us at the address above.
What is processed here – and what is not
This website sets no cookies, embeds no external fonts, video services or social networks, and uses no analytics or advertising tools. Fonts, images and program files come from this same site.
We process no health data through this website. Health data arises solely in the app on your device.
Visiting this website
When you open a page, your browser sends technically necessary connection data to the server: IP address, date and time, the file requested, the transfer status, the volume of data transferred and details of your browser and operating system.
The purpose is delivering the page and keeping the server secure. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the undisturbed and secure operation of the site.
The website runs on a server we operate ourselves. The underlying infrastructure and data centre are provided by netcup GmbH, Daimlerstraße 25, 90441 Nürnberg, Germany. In that respect netcup is a processor under Art. 28 GDPR; a data processing agreement is in place. The servers are located in Germany.
The logs of our web server are rotated daily and deleted after ten generations; they therefore exist for at most about ten days. This data is not combined with any other data source.
Light, dark and language
If you choose light or dark, we store only that display setting in your browser's local storage so that it is still there on your next visit. Without a choice of your own, your system setting applies.
This access to your device is strictly necessary for the service you requested and therefore requires no consent under § 25(2) no. 2 TDDDG. The setting does not leave your device. The language is chosen through the page address and is not stored.
The email waitlist
Signing up is voluntary. We use your email address solely to tell you, after you confirm, that Symtag has launched. It is not an ongoing newsletter.
The legal basis is your consent under Art. 6(1)(a) GDPR. The waiting list needs no health data and is independent of your later diary.
We store your email address, the time of sign-up, the time of confirmation, where the sign-up came from and the version of the consent text shown on the form. These details serve as proof of consent under Art. 7(1) GDPR.
You first receive a confirmation email. Only when you open the link in it are you on the list. Unconfirmed sign-ups are removed after 24 hours. Confirmed entries remain until you unsubscribe, at most 180 days from sign-up.
Delivery runs through our own mail server on the same machine. Your address goes to no newsletter service. The only recipient within the meaning of Art. 13(1)(e) GDPR is therefore netcup GmbH as the operator of the infrastructure.
Providing your address is required neither by law nor by contract. Without it we simply cannot notify you; no disadvantage arises for you.
You can withdraw your consent at any time with effect for the future – through the unsubscribe link in every email or by writing toservice@astoria.systems. The lawfulness of processing up to the withdrawal is unaffected.
To counter automated sign-ups we briefly count requests using an identifier derived from the IP address and a secret key. We do not store the IP address itself. These counters are removed after 24 hours at the latest. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is preventing other people's addresses from being entered without their doing.
The app recordings
The images and videos show the real app with invented sample data only. They sit on this website; no external video player is embedded.
A video starts only when you begin playback. What you watch is neither stored nor analysed. The clock in the status bar shows your local time; it is calculated in the browser and not transmitted.
Your diary in the app
The core functions of the diary work offline and without an account. Your entries sit locally in an encrypted database on your device. The keys are managed by your operating system's secure storage.
For this processing on your device we are not the controller within the meaning of the GDPR: we have no access to your entries and do not receive them. Any online functions you switch on separately are explained there in their own right.
Share reports thoughtfully
An exported PDF report is a readable file. You choose the period, check the content and decide whether and with whom you share it.
Once you pass the file on, its protection depends on the route you choose and on the recipient. We have no influence over that.
Your rights
In relation to us you have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20).
You also have the right to object, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
For all of these a message toservice@astoria.systems.
Independently of that, you can lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate, Hintere Bleiche 34, 55116 Mainz.
Third countries, profiling, changes
Your data is not transferred to any country outside the European Union.
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
If anything changes in the processing described here, we change this page and note it in the date below.
Last updated: September 2026. The details describe the processing actually set up. The retention period given matches the rotation on our web server; if it changes there, it changes here.