Privacy Policy
1. Controller
The controller responsible for data processing on this website and in the dotts app is:
Leon Eikmeier
Timmerbergstraße 48
32602 Vlotho
Germany
E-mail: leon@dotts.se
Phone: +49 175 8790619
2. General information on data processing
We process personal data only where this is necessary to provide a functional website and our content and services, or where you have given your consent. Depending on the case, the legal basis is Art. 6(1)(a) (consent), (b) (contract), (c) (legal obligation) or (f) (legitimate interest) GDPR.
Note on transfers to third countries (in particular the USA): some of the services listed below process data in the USA or may transfer data there. Under EU law, the USA is not considered to provide an adequate level of data protection in all cases. Where a transfer takes place, it is based on the EU Commission's Standard Contractual Clauses or, where the respective provider is certified, on the EU-US Data Privacy Framework.
3. Hosting
This website and the app are hosted by Netlify. Provider: Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. When the site is accessed, technical access data (e.g. IP address, date and time, requested resource, browser and operating system) is processed in server logs. Legal basis: Art. 6(1)(f) GDPR (secure and efficient provision). We have concluded a data processing agreement with the provider.
4. Audience measurement with Pirsch Analytics
We use Pirsch Analytics to evaluate website usage statistically. Pirsch works without cookies and without creating personal profiles; analysis is anonymized and is not intended to identify individuals. Provider: Emvi Software GmbH, Nickelstraße 1b, 33378 Rheda-Wiedenbrück, Germany.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimizing audience measurement). As Pirsch operates without cookies and without accessing terminal device information within the meaning of Sect. 25 TDDDG, in our assessment no consent is required.
5. User account and app features (Firebase)
We use Firebase (Authentication, Firestore, Storage) for registration, login and storage of your projects, comments, uploads and settings. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, where applicable with processing by Google LLC, USA.
Data processed includes your e-mail address, login data, content you create (projects, comments, uploaded files) and technical usage data. Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement) and, for security and stability, additionally Art. 6(1)(f) GDPR. A data processing agreement is in place with the provider.
6. Payment processing (Stripe)
We process payments via Stripe. Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, where applicable with processing by Stripe, Inc., USA.
When you make a purchase, the data required for payment (e.g. name, e-mail address, payment data, billing data) is processed. Full card details are processed directly by Stripe; we do not receive them. Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR (tax and commercial law obligations).
7. Product analytics (PostHog)
We use PostHog with hosting in the European Union to improve our website and our app. Provider: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA; data hosting takes place in the EU.
We use PostHog without cookies and without a persistent identifier and collect usage and event data to improve the product, as well as, where applicable, anonymized session recordings. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the service).
8. E-mail delivery (Loops)
We use Loops for transactional and, where applicable, marketing e-mails. Provider: Astrodon Corporation (Loops), USA. Data processed includes your e-mail address and, where applicable, your name, as well as delivery and interaction data.
Legal basis: for transactional e-mails (e.g. account, password reset, invoices) Art. 6(1)(b) GDPR; for marketing e-mails Art. 6(1)(a) GDPR (consent), which you can withdraw at any time.
9. Proxy feature (reviewing third-party pages)
With dotts you can load third-party websites for commenting. For this, our proxy service (proxy.app.dotts.se) retrieves the target page you specify server-side and displays it within dotts. Technical connection data is processed in the process. For password-protected target pages, you enter the password yourself; dotts does not permanently store third-party credentials. You as the user are responsible for the lawfulness of loading a third-party page. Legal basis: Art. 6(1)(b) GDPR (provision of the feature you requested).
10. Contacting us
If you contact us by e-mail or phone, we process your details in order to handle your request. Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR.
11. Storage period
We store personal data only for as long as necessary for the stated purposes or as required by statutory retention periods (in particular under tax and commercial law). We delete account data after the account is deleted, unless retention obligations prevent this.
12. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority, for us presumably the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
13. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://".
14. Cookies and Sect. 25 TDDDG
We use only technically necessary cookies or comparable technologies required for login and operation of the app (legal basis Sect. 25(2) TDDDG, Art. 6(1)(f) GDPR). Based on our current assessment, consent via a cookie banner is not required as long as no non-essential cookies or tracking technologies are used.