Privacy Policy
Transparency about our data processing
1. Responsible Entity
Responsible for data processing on this website:
SVS - Webdesign Germany UG (haftungsbeschränkt) & Co. KG
Nibelungenplatz 3
60318 Frankfurt am Main
Germany
Represented by the personally liable partner:
SVS - Creative Webdesign UG (haftungsbeschränkt)
represented by the managing director:
Stephano Schuster
Phone: +49 172 6776670
Email: office@webdesign-germany.com
Website: webdesign-germany.com
2. Data Processing Overview
This privacy policy informs you about the type, scope and purpose of processing personal data on our website and our Accessibility Checker service.
What data do we collect?
- Registration data: Name, email address, password, newsletter consent
- Company data: Company name, address, postal code, city, billing notes (optional)
- Website analysis data: URLs of websites to be checked, analysis results
- Payment data: Payment information processed via Stripe
- Technical data: IP address, browser information, session data
- Communication data: Email addresses for reports and notifications
3. Legal Basis for Data Processing
We process your personal data on the following legal bases:
- Art. 6 Para. 1 lit. a GDPR: Consent (e.g. newsletter, marketing emails)
- Art. 6 Para. 1 lit. b GDPR: Contract fulfillment (provision of our services)
- Art. 6 Para. 1 lit. c GDPR: Legal obligation (e.g. retention requirements)
- Art. 6 Para. 1 lit. f GDPR: Legitimate interests (website security, operation)
4. Detailed Data Processing
4.1 User Registration and Account
What data: Full name, email address, encrypted password, newsletter consent, optional: company name, address, postal code, city, billing notes
Purpose: Provision of user account, authentication, billing
Legal basis: Art. 6 Para. 1 lit. b GDPR (contract fulfillment)
Storage duration: Until account deletion or legal retention requirements
4.2 Website Accessibility Analysis
What data: URLs of websites to be analyzed, analysis results, timestamps
Purpose: Conducting accessibility checks, providing reports
Legal basis: Art. 6 Para. 1 lit. b GDPR (contract fulfillment)
Storage duration: 90 days for temporary analysis results, permanently for user reports
4.3 Email Communication and Marketing
What data: Email address, name, communication content
Purpose:
- Sending accessibility reports via email
- Account verification and password reset
- Newsletter and marketing emails (with consent)
- Service notifications
Legal basis: Art. 6 Para. 1 lit. b GDPR (service emails), Art. 6 Para. 1 lit. a GDPR (marketing)
Important Note: By registering or requesting a website report, you consent to receiving marketing emails. You can revoke this consent at any time.
4.4 Payment Processing
What data: Stripe customer ID, subscription information, billing data
Purpose: Processing payments for premium plans
Legal basis: Art. 6 Para. 1 lit. b GDPR (contract fulfillment)
Third party: Stripe Inc. (payment processor) - see section 6
4.5 Session Management and Cookies
What data: Session IDs, login status, user preferences
Purpose: Maintaining login, storing preferences
Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interests)
Storage location: MySQL database (server-side), browser cookies (client-side)
4.6 Plugin Integration
What data: Website domain, plugin configuration, usage statistics
Purpose: Providing the accessibility plugin for your website
Legal basis: Art. 6 Para. 1 lit. b GDPR (contract fulfillment)
5. Technical Data Collection
5.1 Server Logs
Our web server automatically collects the following data:
- IP address of the requesting computer
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Amount of data transferred
- Website from which the request comes
- Browser information
- Operating system and its interface
- Language and version of browser software
Purpose: Ensuring system security and stability
Legal basis: Art. 6 Para. 1 lit. f GDPR (legitimate interests)
5.2 External Resources
Google Fonts: We load fonts from Google Fonts. Google may collect your IP address in the process.
Material Icons: Icons are provided by Google and may include tracking.
6. Data Sharing with Third Parties
6.1 Stripe (Payment Processor)
For payment processing, we use Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA.
Transmitted data: Name, email, payment information, billing address
Purpose: Secure payment processing
Legal basis: Art. 6 Para. 1 lit. b GDPR, Art. 44 ff. GDPR
Privacy policy: https://stripe.com/privacy
6.2 Email Delivery (Mailgun)
For email delivery, we use Mailgun Technologies, Inc.
Transmitted data: Email address, name, email content
Purpose: Reliable email delivery
6.3 Hosting
Our website is hosted externally. The hosting provider may access all data processed on this website.
7. Your Rights
You have the following rights regarding your personal data:
7.1 Right to Information (Art. 15 GDPR)
You can request information about the personal data we process.
7.2 Right to Rectification (Art. 16 GDPR)
You can request the correction of incorrect data or the completion of incomplete data.
7.3 Right to Erasure (Art. 17 GDPR)
You can request the deletion of your personal data, provided there are no legal retention obligations.
7.4 Right to Restriction (Art. 18 GDPR)
You can request the restriction of processing of your data.
7.5 Right to Data Portability (Art. 20 GDPR)
You can request that we provide you with your data in a structured, commonly used and machine-readable format.
7.6 Right to Object (Art. 21 GDPR)
You can object to the processing of your data if it is based on legitimate interests.
7.7 Withdrawal of Consent (Art. 7 Para. 3 GDPR)
You can withdraw given consent at any time. This particularly concerns:
- Newsletter subscription
- Marketing emails
- Cookies (where consent is required)
8. Storage Duration
We store your personal data only as long as necessary for the respective purposes:
- User account data: Until account deletion
- Analysis results: 90 days (temporary), unlimited (saved reports)
- Payment data: 10 years (tax law retention requirement)
- Email communication: 3 years
- Server logs: 30 days
- Session data: 24 hours (or 30 days with "Stay logged in")
9. Data Security
We implement technical and organizational measures to protect your data:
- SSL/TLS encryption for all data transmissions
- Encrypted storage of passwords (bcrypt)
- Secure session management with MySQL backend
- Regular security updates
- Access restrictions on server data
10. Changes to this Privacy Policy
We reserve the right to update this privacy policy to adapt it to changed legal situations or changes to our services. You can always find the current version on this page.
11. Contact and Complaints
For questions about data protection or to exercise your rights, contact:
SVS - Webdesign Germany UG (haftungsbeschränkt) & Co. KG
Nibelungenplatz 3
60318 Frankfurt am Main
Germany
Phone: +49 172 6776670
Email: office@webdesign-germany.com
Website: webdesign-germany.com
Supervisory Authority:
You have the right to lodge a complaint with a data protection supervisory authority about our processing of personal data.