Privacy Policy – ConfabX
Last updated: January 2026
1. Controller
Niessen GmbH
Industriestr. 2, Eingang 2
65779 Kelkheim, Germany
Email: info@confabx.io
2. Scope
This Privacy Policy applies to the ConfabX mobile application and web services (“ConfabX”).
ConfabX is a cloud-based control and automation platform for live performers.
3. Personal Data We Process
When you use ConfabX, we process the following categories of personal data:
- Account data (email address, user ID, password hash)
- Subscription and billing status
- Affiliate and ambassador program data
- Configuration data (profiles, triggers, routines)
- Form submissions for affiliate and billing verification
- IP addresses and request metadata (for security and logging)
- Email communication related to your account and billing
4. Purpose of Processing
We process personal data to:
- Provide and operate your ConfabX account
- Enable subscriptions and billing
- Operate the affiliate and ambassador program
- Send transactional emails (verification, confirmation, billing, security)
- Ensure system security, stability and fraud prevention
5. Legal Basis (GDPR)
- Art. 6(1)(b) GDPR – performance of contract (providing ConfabX services)
- Art. 6(1)(c) GDPR – legal obligations (billing, accounting)
- Art. 6(1)(f) GDPR – legitimate interest in security and abuse prevention
6. Third Parties and Processors
ConfabX uses technical service providers (e.g. hosting, email delivery, payment and automation services such as Pipedream, Apple, and payment processors).
These providers process data only on our behalf and under data processing agreements.
7. Affiliate & Ambassador Program
If you participate in the ConfabX Affiliate or Ambassador Program, we process additional data such as billing details, payout preferences and verification information.
This data is used exclusively to operate commission payments and legal compliance.
7.1 Referral Attribution (ref parameter)
If you access ConfabX via an Ambassador link, the link may contain a referral parameter (e.g. ref).
We use this parameter to attribute a potential registration to the referring Ambassador.
- Purpose: fraud-resistant attribution of a direct referral for commission handling
- Storage method: we store the referral code and timestamp in first-party cookies (
cx_ref, cx_ref_at) with a limited lifetime (Max-Age) and SameSite=Lax.
- Attribution rule: last-click-wins — if you later open ConfabX with another referral link, the cookies are overwritten and the newest ref applies.
- Storage duration: up to 30 days (or until you register), unless a longer retention is required for accounting/tax obligations
- No disclosure: Ambassadors do not receive access to names, emails, or personal data of referred users. They only see aggregated counts and commission totals.
- No multi-level marketing: ConfabX uses single-tier attribution (direct referrals only). There is no commission for “referrals of referrals”.
8. Data Retention
Personal data is stored as long as your account is active and as required by legal and contractual obligations.
Affiliate and billing records may be retained for statutory accounting and tax purposes.
9. International Transfers
Some service providers may be located outside the EU. Where applicable, appropriate safeguards such as Standard Contractual Clauses are used.
10. Your Rights
You have the right to access, rectify, delete, restrict, and export your personal data and to object to processing.
To exercise your rights, contact: info@confabx.io
11. Children
ConfabX is not intended for children under 13 years of age.
12. Changes
This policy may be updated. The current version is always available at this URL.