Legal
Privacy Policy
Last updated: 20 July 2026
Translation notice: This English version is provided for convenience. In the event of any discrepancy, the German Privacy Policy is authoritative.
1. Controller
munddigital.de
Benjamin Mund
Bundesstr. 1
23881 Niendorf
Germany
Email for privacy enquiries: datenschutz@munddigital.de
Contact form: General contact form
No data protection officer has been appointed.
2. Principles of processing
We process personal data only insofar as this is necessary to provide the website, handle enquiries, prepare or perform a contract, operate the mail and cloud services offered, ensure IT security, create backups or comply with legal obligations.
Personal data is not processed to create advertising profiles, sold to third parties or collected through deliberately integrated website, open or click tracking. No decision producing legal or similarly significant effects is made solely by automated means.
3. Provision of the website
3.1 Hosting
The website munddigital.de is a static one-page website hosted on a server operated by Hetzner Online GmbH in Germany. Hetzner processes technical data as a processor insofar as this is necessary to operate the server infrastructure. A data processing agreement pursuant to Article 28 GDPR is in place with Hetzner.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and economical provision of our website.
3.2 Server and security logs
When the website is accessed, the following data in particular may be processed:
- the complete IP address and, where applicable, a transmitted proxy IP address,
- the date and time of access,
- the HTTP method, requested address and protocol version,
- the HTTP status code and amount of data transferred,
- the referrer,
- browser and device identification or user agent,
The data is used to deliver the website, analyse errors, protect against attacks and investigate misuse. It is not combined with advertising or usage profiles.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the functionality and security of the systems.
Size-based Docker log rotation is configured for containerised services on the Hetzner server. A maximum of five compressed log files of no more than 10 MB each are retained per container. Because rotation depends on the amount of data generated, this does not correspond to a fixed number of days.
4. General contact form
The general contact form can be used for organisational, technical, legal and privacy-related matters. The email address provided, the optional name, selected topic, message and time of submission are processed.
Responses are stored in Nextcloud Forms on the self-operated Nextcloud described in Section 6. If a person is signed in to a Nextcloud account when submitting the form, the response may be associated with that account or its user identifier. For people who are not signed in, the response is displayed as anonymous in Forms. Irrespective of this, technical connection data may be recorded in the server logs described in Section 6.1.
After submission, an automatic acknowledgement is sent to the email address provided through our own mail server described in Section 7. It does not contain a copy of the message or the other form responses. A separate email containing the complete responses is not sent to the operator; the request is handled within Nextcloud Forms.
Nextcloud may also send the operator an internal activity notification by email. It contains the title of the submitted form and, for signed-in users, the display name stored in their Nextcloud account where applicable. For users who are not signed in, the submission is shown as anonymous. Form responses, free-text content and the email address entered in the form are not included in this internal notification.
Benjamin Mund has access to the stored responses through a dedicated Nextcloud account. Administrative access takes place only insofar as required for administration, security or troubleshooting. No other users, groups or external service providers are granted access to view the responses.
Legal bases:
- Article 6(1)(b) GDPR for contractual or pre-contractual enquiries,
- Article 6(1)(c) GDPR where a legal obligation is concerned,
- Article 6(1)(f) GDPR for other subject-related enquiries. The legitimate interest is handling and documenting the enquiry.
Retention period: The original form response is automatically deleted from Nextcloud Forms after 180 days during the next daily review. Where information is required for an ongoing contractual relationship, legal handling or statutory retention obligations, the necessary information is transferred beforehand to the designated case, customer or contract records. The applicable retention and limitation periods apply to those records.
5. Access request form for mail and cloud services
The access request form is used for the non-binding review of a request, an initial personal conversation, clarification of requirements, scope and suitability, and preparation of a possible contractual relationship. Submitting the form does not create a contract and no account is set up automatically.
Depending on the information entered, the following data in particular may be processed:
- first and last name and an existing email address,
- the type of personal, business, organisational or project-related use,
- interest in mail, cloud or combined services,
- the wish to use a personal domain, intended purpose and description of the planned use,
- expected mail usage and storage requirements,
- desired characteristics of the service,
- availability for a short conversation via Jitsi,
- voluntary additional information and questions,
- confirmation of responsible use, in particular the prohibition of spam, unauthorised bulk sending, unlawful use and sharing login credentials.
As with the contact form, the time of submission and, for signed-in users, the association with their Nextcloud account are also stored. For people who are not signed in, the response is displayed as anonymous in Forms. The forms currently offered do not contain upload fields.
After submission, an automatic acknowledgement is sent to the email address provided through our own mail server described in Section 7. The name entered in the form may be used for the personal salutation. The acknowledgement does not contain a complete copy of the other form responses.
The processing described in Section 4 for internal activity notifications applies accordingly.
Legal bases: Article 6(1)(b) GDPR for pre-contractual measures and Article 6(1)(f) GDPR for reviewing the technical, organisational and security-related suitability of a request.
Retention period: The original form response is automatically deleted from Nextcloud Forms after 180 days during the next daily review. If a contract is concluded, the information required for it may be transferred beforehand to customer and contract documentation and retained for the duration of the contract and within the applicable statutory retention and limitation periods.
Information about a possible Jitsi conversation is used only for preparation and coordination. A conversation takes place only after a separate appointment has been agreed. The specific instance used and the processing involved will be communicated before the appointment.
5.1 Automated deletion and deletion logs
The retention period is checked automatically every day through the Nextcloud Forms interface. The deletion script is configured exclusively for the four fixed form IDs comprising the German and English versions of the contact and access request forms, and verifies ownership before every run. The deletion log contains no names, email addresses or response texts, but only the form name and ID, submission ID, submission time, number of responses reviewed and deletion status. These technical logs are deleted no later than after 180 days. In the event of errors or actual deletions, a status email without form content is sent through our own mail server.
6. Self-operated Nextcloud
The cloud at cloud.munddigital.de is operated on physically controlled hardware in Germany. Data is transmitted over encrypted connections. Cloud content is not analysed for advertising or profiling.
Depending on use, we process the following data in particular:
- master data, contact details, account name and account settings,
- login, session and security data,
- files, folders, metadata, shares and share links,
- calendar, contact, task, form and other app data where the relevant function is used,
- activity data and technical error or security information.
Legal bases: Article 6(1)(b) GDPR for providing and using the service, Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for security, misuse prevention and uninterrupted operation.
6.1 Logs and activity records
Dynamic access to the cloud may be recorded in the Nginx access log. Web server logs are rotated daily and retained for 14 generations. The Nextcloud application log records only warnings, errors and more serious events and is likewise rotated daily with 14 generations retained. Activity records are automatically removed after 90 days.
The log for sending administrative system emails is rotated daily, retained for 30 generations, compressed and stored so that it can be read only by root.
6.2 Deletion, recycle bin and versions
Active account data and content is retained for the duration of use. After the contract ends or account deletion has been confirmed, active data is deleted after a reasonable period for data transfer or export unless legal or contractual reasons require otherwise.
Deleted files may initially remain in the Nextcloud recycle bin and in file versions. The Nextcloud default rule “auto” currently applies; recycle-bin content is generally retained for 30 days and is then removed automatically depending on storage requirements. Users may also empty their recycle bin earlier themselves.
Where content is shared with external persons, they may receive independent copies. We have no control over copies already downloaded or stored outside the cloud.
6.3 Nextcloud backups
A consistent Nextcloud backup is created every day. A local mirror is updated first, a brief maintenance period is then enabled, a final synchronisation is performed and a complete database dump is generated. An encrypted Borg archive is then created and transferred to a Hetzner Storage Box.
The backup is encrypted client-side on our own system; only encrypted archive data is stored on the Storage Box. The decryption keys remain under our control. The backup includes user files, configuration, apps, custom apps, themes, the database, recycle bin and file versions in particular. Regenerable preview files and temporary updater directories are excluded.
Up to seven daily, four weekly and six monthly archive states are retained. Once these retention periods expire, archives no longer required are removed automatically and occupied repository storage is released. A monthly consistency check of the Borg repository is configured. Restoration of test data, including decryption and checksum comparison, has been successfully tested in practice.
Because backups are retained on a time-delayed basis, data already deleted from the active system may remain in encrypted backups until the applicable backup retention period expires. Backups are used solely for restoration, security and evidence purposes and are not made available for routine access.
7. Mail service using mailcow and SOGo
The mail service at mail.munddigital.de is operated using mailcow on a Hetzner server in Germany. SOGo is used as the webmail interface. Connections are encrypted in transit according to the capabilities of the respective other party. End-to-end encryption of messages takes place only where the sender and recipient use it themselves.
The following data in particular is processed to operate the service:
- account data, mail address, aliases and technical account settings,
- login, connection, delivery and security data, including IP addresses and timestamps,
- sender, recipient, subject, message identifiers and delivery status,
- message content and attachments insofar as necessary for acceptance, storage, retrieval, forwarding or delivery,
- data concerning failed deliveries, queues, suspected spam and security events.
Incoming messages are checked by Rspamd, ClamAV and other mailcow components for spam, harmful content and technical anomalies. This checking is necessary for secure operation and is not used to create personality or advertising profiles.
Legal bases: Article 6(1)(b) GDPR for providing the service, Article 6(1)(c) GDPR for legal obligations and Article 6(1)(f) GDPR for system security and protection against spam and misuse. Where specific rules for telecommunications services apply, telecommunications secrecy and the relevant provisions of the TDDDG are also observed.
7.1 Direct delivery to external mail servers
Outgoing messages, including requested acknowledgements, Nextcloud system messages and administrative status notifications, are sent through our own mail server at mail.munddigital.de. No external SMTP relay service is currently used. The mail server delivers messages directly to the mail servers responsible for the respective recipient address. The message and traffic data required for delivery is transmitted to the participating mail servers, mail providers and telecommunications networks.
munddigital.de does not add tracking pixels to outgoing messages to record opens and does not add redirect links to record clicks. Visible images required for presentation may be loaded from servers under munddigital.de; the technical connection data described in Sections 3.2 and 6.1 may be processed in that context. After delivery, further processing by the recipient falls within their area of responsibility.
7.2 Retention period and logs
Messages and mailbox content are retained for the duration of the active account or until deleted by the user. When a mail account is deleted completely, mailcow currently retains the mailbox for five days in a technical recovery area; it is then removed from that area. Statutory retention or evidence obligations may require certain business correspondence to be retained for longer in individual cases.
The size-based Docker log rotation described in Section 3.2 applies to the containerised mailcow services, with no more than five compressed files of no more than 10 MB each per container. The actual period covered depends on the volume of logs generated.
7.3 Mailcow backups
A complete local backup of the mail server is created every day. The backup state is then transferred in encrypted form over an authenticated connection to the self-operated Nextcloud system. Up to 30 backup states are retained there. Transfers, checksums and the atomic completion of each backup run are checked automatically.
Mailcow backups may contain message content, attachments, accounts, settings, databases and other data required for restoration. Data already deleted from the active mail account may therefore remain in backup states until the backup retention period expires. Backups are used solely for restoration and system security.
8. Cookies, sessions and local storage
8.1 Static website
The static one-page website does not use analytics, marketing or advertising cookies and does not include external fonts or social-media content. The current password protection uses the web browser’s HTTP Basic Authentication and does not set its own tracking cookie.
8.2 Nextcloud, Forms and SOGo
Nextcloud, public Nextcloud forms and SOGo use technically necessary session, security and authentication information in cookies or the browser’s local storage. This is used in particular for login, session management, CSRF protection, security, language selection, display preferences and operation of the functions requested by the user.
This storage is necessary for the functions expressly requested. Consent is therefore generally not required under Section 25(2)(2) TDDDG. Non-essential tracking or advertising storage is not used.
9. Recipients and processors
Personal data is transmitted only where necessary or permitted by law. Recipients may include:
- Hetzner Online GmbH as hosting provider for the website and mail server and as provider of the encrypted Storage Box backup infrastructure,
- external mail servers, mail providers and recipients in the course of normal message delivery,
- internet and telecommunications providers insofar as they participate in transmission,
- public authorities, courts or other bodies where there is a legal obligation or this is necessary to pursue legal claims.
The production Nextcloud system is operated on our own hardware and is therefore not an external processor. External administrators or other technical service providers do not have regular access. Should a service provider be used in an individual case, access will be limited to what is necessary and protected in accordance with data protection law.
10. Data security
We use appropriate technical and organisational measures, including encrypted transport connections, access restrictions, separate user accounts, security logging, spam and malware checking, regular updates, automated log rotation, authenticated direct email delivery, encrypted off-site backups and integrity checks. Absolute protection against every risk cannot, however, be guaranteed.
Automated backup procedures are in place for Nextcloud and mailcow. The Nextcloud backup is encrypted client-side, transferred to a separate Hetzner Storage Box and regularly checked for consistency. A practical restoration of Borg test data, including checksum comparison, has been completed successfully. Status notifications do not contain complete cloud, mail or form content.
11. Requirement to provide data
At least one reachable email address is required for a general enquiry. The information marked as required is needed to review an access request and later perform a contract. Without this data, the enquiry may not be processed or the requested service may not be provided. There is no further legal obligation to use the forms.
12. Your rights
Subject to the statutory requirements, you have the following rights in particular:
- access to the personal data processed under Article 15 GDPR,
- rectification of inaccurate data under Article 16 GDPR,
- erasure under Article 17 GDPR,
- restriction of processing under Article 18 GDPR,
- data portability under Article 20 GDPR where applicable,
- objection to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR,
- withdrawal of consent with effect for the future under Article 7(3) GDPR.
To exercise your rights, contact datenschutz@munddigital.de or use the contact form. To protect against unauthorised disclosure of data, we may request suitable proof of identity.
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. For non-public bodies established in Schleswig-Holstein, the following authority is responsible in particular:
State Commissioner for Data Protection
Independent Centre for Privacy Protection Schleswig-Holstein (ULD)
Holstenstraße 98
24103 Kiel
Email: mail@datenschutzzentrum.de
Where data is processed in connection with the commercial provision of telecommunications services and the special jurisdiction under the TDDDG applies, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) is also responsible.
14. Changes to this Privacy Policy
We update this Privacy Policy when services, technical procedures, recipients or the legal situation change. The version published on this page at the relevant time is authoritative.