Etikettwerk: Privacy Policy
Etikettwerk: label data and label purchases
Etikettwerk has no user accounts, advertising or analytics. Editing, checking and approving run in your browser. Product and supplier data, drafts, the job and history are stored in localStorage under etikettwerk.state.v3. Before a purchase, etikettwerk.purchases.v1 stores the approved label snapshot, local approval fingerprint and time; the purchase reference is added on return from Stripe. This separate entry contains at most the latest 100 label states and is not included in data backups.
This data remains in your browser until overwritten or until you clear site data. Deleting local product data in the application does not remove purchase references. Damaged entries may remain as local recovery copies with a .corrupt suffix. The sessionStorage entry etikettwerk.checkout.v1 contains only the local fingerprint and time to match the return from checkout to the correct tab. It is removed after successful purchase verification, otherwise when the tab closes. The portable offline file does not use purchase references or send any data to a server.
When buying a label, the browser sends the complete approved label snapshot to the Etikettwerk server. The server validates the data and creates the Stripe Checkout session. To verify a purchase and provide the SVG file, the browser sends the snapshot and purchase reference to the server again, including on return from Stripe or when reopening a purchased label. The server verifies payment with Stripe and generates the SVG file in memory. Neither the snapshot nor the SVG is stored there permanently; there is no label or payment database.
The purchase and output API does not log request bodies or purchase references. However, on unhandled errors the shared server logs the HTTP method, URL path and error object. If an error message contains data from a request, that data may appear in the error log. The server does not automatically write the request body to the log. General information about server logs is set out below.
Payment redirects to Stripe Checkout. Stripe Payments Europe, Ltd., Ireland, processes payment, contact and billing data and creates the invoice. You enter this data directly with Stripe. Our application stores no card details. Label content is bound to the purchase only through a SHA-256 fingerprint in Stripe metadata; Stripe receives no label text or supplier data from the label. Stripe also receives the language, fixed price, product identifier and purchase terms version. Billing data entered with Stripe is separate from this.
Processing to enter into and fulfil the label purchase, including payment verification and output, is based on Art. 6(1)(b) GDPR. Invoices are retained to meet statutory retention obligations under Art. 6(1)(c) GDPR for the statutory retention periods. Stripe retains payment data under its own retention rules. For further information about Stripe's processing, including international data transfers, see Stripe's privacy policy.
1. Privacy at a Glance
The following information provides a simple overview of what happens to your personal data when you visit our websites. Personal data is any data that can be used to personally identify you.
The controller responsible for data processing on these websites is: Twelve Digital GmbH Steinheilstr. 19 80333 Munich Germany Email: info@twelve-digital.de
2. Hosting and Server Log Files
Our websites run on a server of Hetzner Online GmbH in its data centre in Nuremberg, Germany. To deliver a page, the server necessarily processes your IP address and the information your browser sends with every request (for example the address requested, the browser identifier and the language).
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, processes this data on our behalf. We have concluded a data processing agreement with it under Art. 28 GDPR; under this agreement it processes the data only in the EU or the EEA.
Of this, the following is stored: - The web server that accepts the connections keeps no access log. IP addresses and browser information are not stored there. - When individual files (such as images, scripts or stylesheets) or addresses that do not exist are requested, the application writes a line with the time, request method, address including parameters and response status to its log, without the IP address and without browser information. Requests for the pages themselves and requests to our interfaces are not logged this way. - Error messages of the applications are written to the same log.
The logs are kept on the same server. The log of each application is limited to three files of 10 MB each; when it is full, the oldest entries are overwritten. Regardless of this, entries are deleted after 14 days at the latest.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to deliver the pages, find errors and prevent misuse.
3. Cookies and Storage in Your Browser
Etikettwerk uses no advertising or analytics services. There are no user accounts or sign-in cookies. The browser data described above supports the functions you request. The shared imprint page may also store your language choice and cookie settings.
You can delete all entries in your browser settings (clear site data, or cookies and site data).
Storing these entries on your device and reading them is based on Section 25(2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act), because they are strictly necessary for the service you asked for. The purchase uses the legal basis stated above. Respecting your language choice and cookie settings is based on Art. 6(1)(f) GDPR; our legitimate interest is to respect your choice and your language.
4. Your Rights as a Data Subject
You have the following rights with respect to your personal data: - Right of access (Art. 15 GDPR) - Right to rectification (Art. 16 GDPR) - Right to erasure (Art. 17 GDPR) - Right to restriction of processing (Art. 18 GDPR) - Right to data portability (Art. 20 GDPR) - Right to object (Art. 21 GDPR)
To exercise your rights, please contact: info@twelve-digital.de
5. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data, including the authority of the EU member state where you live or work (Art. 77 GDPR). The supervisory authority responsible for us is: Bavarian State Office for Data Protection Supervision (BayLDA) Promenade 18 91522 Ansbach
6. Changes to This Privacy Policy
We reserve the right to update this privacy policy to ensure it always complies with current legal requirements or to implement changes to our services. The updated privacy policy will apply to your next visit.