Privacy Policy (Web, PWA & App)

Privacy Policy (Web, PWA & App)

Scope. These notices apply to websites, Progressive Web Apps (PWAs) and, where provided, native apps (collectively “Services”) operated by the provider named in the imprint. Functions may vary per project. For privacy requests, always provide the exact URL/name of the affected website/app.

1. Controller & Contact

The controller under the GDPR is the provider named in the imprint. Contact: mail@heuken-webservice.com

2. Legal Bases (Overview)

TTDSG (§25 Germany): Strictly necessary technologies (e.g., session, service-worker cache) are permitted without consent.

3. Processing (Purpose, Legal Basis, Retention, Recipients)

3.1 Server Log Files

Purpose: operation, security, debugging. Data: (anonymised) IP, timestamp, URL/file, referrer, HTTP status, user agent. Basis: Art. 6(1)(f) GDPR. Retention: typically 7 days (longer in incidents). Recipients: hosting/infrastructure processors.

3.2 PWA Caching / Service Worker / LocalStorage

Purpose: offline capability, performance. Basis: TTDSG §25(2)(2) with Art. 6(1)(f) GDPR (strictly necessary). Retention: until update/invalidation or manual deletion. Recipients: none (client-side). Protected resources are not cached.

3.3 Contact Forms & E-Mail

Purpose: communication/handling inquiries. Data: contact details, message content, metadata. Basis: Art. 6(1)(b) or (f) GDPR. Retention: 6–24 months. Recipients: IT/support processors.

3.4 Newsletters (if offered)

Purpose: information/updates. Data: email, optional name; double opt-in. Basis: Art. 6(1)(a) GDPR (withdrawal anytime). Retention: until withdrawal; suppression list to enforce it (Art. 6(1)(f)).

3.5 Reach Measurement (privacy-friendly)

Preferably self-hosted, cookie-less, Do-Not-Track respected, IP anonymised. Basis: Art. 6(1)(f) GDPR. Retention: up to 13 months. Recipients: none (when self-hosted) or processors.

3.6 User Accounts/Authentication (if applicable)

Purpose: access control, sessions, roles. Data: registration/profile, hashed credentials, session tokens, security logs. Basis: Art. 6(1)(b)/(f) GDPR. Retention: account lifetime; logs 90–180 days. Recipients: hosting/IT processors.

3.7 Push Notifications (optional)

Purpose: message delivery. Data: push tokens/subscriptions, delivery metadata. Basis: Art. 6(1)(a) GDPR; revocable in app/browser/OS. Retention: until withdrawal/invalidation. Recipients: push infrastructure processors.

3.8 App Permissions (optional, per feature)

Purpose: functionality (e.g., camera, microphone, files, location, notifications). Basis: Art. 6(1)(a) GDPR (consent) or (f) (strictly necessary). Retention: only as required. Recipients: no third parties.

3.9 File Uploads & Malware Scanning (optional)

Purpose: IT security. Data: file/hash/metadata. Basis: Art. 6(1)(f) GDPR. Third-country transfers: External scanners (e.g., VirusTotal) may involve transfers outside the EU/EEA (incl. US); safeguarded by Art. 46 GDPR (SCC) plus technical/organisational measures. Retention: system-side e.g., up to 90 days/until deletion; scanner per its policy.

4. Mandatory Provision

Without required data, the requested service cannot be provided (e.g., session, contact details).

5. Recipients & Processors

We use carefully selected processors (Art. 28 GDPR) under data-processing agreements; no disclosure to third parties without a legal basis.

6. International Transfers

For transfers outside the EU/EEA, we implement Art. 46 GDPR safeguards (notably SCC), supplementary measures and TIAs. Copies available on request.

7. Retention & Deletion

We retain data only as long as needed for the purpose, then delete/anonymise unless statutory retention applies.

8. Security

TLS/HTTPS, role-based access, system hardening, security logging, organisational safeguards.

9. Data Subject Rights

Access, rectification, erasure, restriction, portability, objection (Art. 21), withdrawal of consent (Art. 7(3)). Contact: mail@heuken-webservice.com.

10. Complaints

You may lodge a complaint with a supervisory authority. EU overview: EDPB members.

11. Minors

Not directed at children unless explicitly stated. App permissions are used only as required and based on consent.

12. Changes

We update these notices when technical/legal changes occur; the version published at the time of visit applies.

13. Version

Version: – Build 1