Privacy Policy
This is a courtesy translation. The German original is the legally binding version.
Last updated: September 13, 2026
Preamble
With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to as "data") we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our website and in our desktop application Faustica (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Disclosure of Personal Data
- International Data Transfers
- General Information on Data Storage and Erasure
- Rights of Data Subjects
- Sale via Microsoft Store and Apple App Store
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Blog
- Newsletter and Electronic Notifications
- Web Analytics with Matomo
- Changes and Updates
- Definitions
Controller
Christian Böhm
Dorfstraße 80c
07639 Tautenhain
Germany
Email address: faustica@posteo.de
Imprint: faustica.com/en/imprint.html
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Categories of Data Processed
- Basic account/registration data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of Data Subjects
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement (analytics).
- Office and organizational procedures.
- Organizational and administrative procedures.
- Feedback.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Business processes and business management procedures.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or registered office. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) — the data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) — processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) — processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). The BDSG contains special provisions on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Security Measures
In accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the varying likelihood and severity of risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability assurance and segregation relating to it. We have also established procedures to ensure the exercise of data subject rights, the erasure of data, and responses to threats to data. Furthermore, we already take the protection of personal data into account when developing or selecting hardware, software and procedures, in accordance with the principle of data protection through technology design and through privacy-friendly default settings.
Shortening of the IP address: If IP addresses are processed by us or by the service providers and technologies used, and processing of the complete IP address is not required, the IP address is shortened (also referred to as "IP masking"). In this process, the last digits or the last part of the IP address are removed or replaced with placeholders following a period. Shortening the IP address is intended to prevent or significantly impede the identification of a person based on their IP address.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect your data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. If a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL — an indicator that your data is being transmitted securely and in encrypted form.
Disclosure of Personal Data
In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other bodies, companies or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services that are integrated into our online offering (see the respective sections below). In such cases, we comply with the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using the services of third parties (which becomes apparent from the postal address of the respective provider, or where this privacy policy expressly refers to the transfer of data to third countries — for example, with Microsoft and Apple, see below), this is always done in accordance with legal requirements.
For data transfers to the USA, where relevant, we rely on the Data Privacy Framework (DPF), which was recognized as a safe legal framework by an adequacy decision of the EU Commission dated July 10, 2023. Further information on the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce: dataprivacyframework.gov. For data transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, explicit consent, or transfers required by law.
General Information on Data Storage and Erasure
We erase personal data that we process in accordance with statutory provisions as soon as the underlying consents are revoked, or no further legal bases for the processing exist. This applies to cases in which the original purpose for processing no longer applies, or the data is no longer needed. Exceptions to this rule apply where statutory obligations or particular interests require longer retention or archiving of the data — in particular, data that must be retained for commercial or tax law reasons. The specific retention and deletion periods for individual processing activities can be found in the respective sections of this policy.
Where multiple retention or deletion periods are specified for a given piece of data, the longest period is always decisive.
Rights of Data Subjects
As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions.
- Right to withdraw consent: You have the right to withdraw any consent given at any time.
- Right to access: You have the right to request confirmation as to whether data concerning you is being processed, and to receive information about this data as well as further information in accordance with legal requirements.
- Right to rectification: You have the right to request the completion of data concerning you, or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right to request that data concerning you be erased without delay, or alternatively to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transmitted to another controller.
- Complaint to a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR — in particular with a supervisory authority in the member state of your habitual residence or the place of the alleged infringement.
To exercise these rights, please feel free to contact us first at the contact address given above under "Controller".
Sale via Microsoft Store and Apple App Store
The purchase of a Faustica license takes place exclusively through the store platforms of other providers — the Microsoft Store and the Apple App Store. In this context, in addition to this privacy policy, the privacy notices of the respective platform apply, in particular with regard to the processing of the payment transaction. We ourselves do not receive any payment or complete account data, but only confirmation that a license has been purchased for your store account.
- Microsoft Store — Service provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA; Privacy Statement; legal basis: performance of the purchase agreement (Art. 6(1)(b) GDPR); data processing may also take place outside the EU/EEA (see "International Data Transfers" above).
- Apple App Store — Service provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (parent company: Apple Inc., USA); Privacy Policy; legal basis: performance of the purchase agreement (Art. 6(1)(b) GDPR); data processing may also take place outside the EU/EEA.
Provision of the Online Offering and Web Hosting
We process the data of users in order to be able to provide them with our online offering. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online offering to the user's browser or end device.
- Provision on rented storage space: To provide our online offering, we use storage space, computing capacity and software that we rent from an appropriate server provider (web host); legal basis: legitimate interests (Art. 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of "server log files": address and name of the pages/files accessed, date and time of access, amount of data transferred, browser type and version, operating system, referrer URL and, as a rule, the IP address and the requesting provider. The log files serve security purposes (e.g., defense against overload/attacks) and the stability of the servers; legal basis: legitimate interests (Art. 6(1)(f) GDPR). Erasure: Log file information is stored for a maximum of 30 days and is then deleted or anonymized.
- ALL-INKL: Provision of information technology infrastructure and related services (storage space, computing capacity); service provider: ALL-INKL.COM — Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Website, Privacy Policy; legal basis: legitimate interests (Art. 6(1)(f) GDPR); a data processing agreement is provided by the service provider.
Use of Cookies
The term "cookies" refers to functions that store information on users' end devices and retrieve information from them. Cookies can be used for various purposes, such as ensuring the functionality, security and convenience of online offerings, as well as for creating analyses of visitor flows. We use cookies in accordance with legal requirements: where required, we obtain the prior consent of users — specifically via the cookie banner on first visiting the page (see "Web Analytics with Matomo" below). Where consent is not required because storing and retrieving information is essential in order to provide expressly requested content, we rely on our legitimate interests. Consent can be withdrawn at any time via the "Cookie Settings" link in the page footer; we do not store your decision itself in a cookie, but in your browser's local storage (localStorage).
Blog
We operate a blog as a means of online communication and publication. Readers' data is processed only to the extent necessary for displaying the blog and for security reasons (see "Provision of the Online Offering and Web Hosting" above) — the blog currently does not offer a comment function, so no additional data is collected through comments or reader contributions.
Newsletter and Electronic Notifications
We send newsletters only with your consent. To sign up via the form in the "Newsletter" section, only your email address is required. Registration takes place via our own server endpoint and adds your address to a contact list at our mailing service provider Brevo: Brevo SAS, 187–197 Avenue de France, 75013 Paris, France; Privacy Policy. Newsletter content: information about Faustica, news and development updates.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future, or object to further receipt — via the unsubscribe link in every email, or by message to the contact address given above.
Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove previously given consent in the event of a dispute; during this time, processing is restricted to this purpose.
Measurement of open and click rates: Should future newsletters be sent via Brevo, they may contain a so-called tracking pixel that collects technical information (including IP address, browser, and time of retrieval) when the email is opened — a function commonly used by mailing service providers to measure success, which allows us to understand which content is being read. Legal basis: your consent (Art. 6(1)(a) GDPR).
Web Analytics with Matomo
Following your consent given in the cookie banner, we use the self-hosted analytics software Matomo (server: stats.faustica.com) to understand how our online offering is used — for example, which pages are viewed and how often. With the help of this reach measurement, we can, for example, identify at what time our online offering is used most frequently, or which areas require optimization.
Matomo sets a cookie for this purpose to recognize repeat visits; your IP address is shortened before storage (IP masking, see "Security Measures" above). The data collected remains exclusively on our own server; there is no disclosure to third parties and no matching with other services. Further information on Matomo: matomo.org.
The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG — the German Telecommunications- Telemedia Data Protection Act). Without your consent, no Matomo script is loaded and no cookie is set. You can change your decision at any time with effect for the future: Open Cookie Settings. Cookies are stored for up to two years unless you withdraw your consent beforehand.
Changes and Updates
We ask that you regularly inform yourself of the content of this privacy policy. We will adapt it as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your involvement (e.g., consent) or any other individual notification.
Definitions
This section gives you an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their statutory definitions apply; the following explanations are primarily intended to aid understanding.
- Basic account/registration data: Essential information required for identifying and managing contractual partners, user accounts and profiles, e.g., names, contact information and dates of birth.
- Content data: Information generated in the course of creating, editing and publishing content of any kind, including associated metadata.
- Contact data: Information that enables communication with persons or organizations, e.g., telephone numbers, postal addresses and email addresses.
- Meta, communication and process data: Information about the manner in which data is processed, transmitted and managed, e.g., timestamps, persons involved and transmission paths.
- Usage data: Information about how users interact with digital products, services or platforms, e.g., page views, time spent and click paths.
- Personal data: Any information relating to an identified or identifiable natural person.
- Log data: Information about events or activities logged in a system or network, e.g., timestamps, IP addresses and error messages.
- Reach measurement: Analysis of the visitor flows of an online offering, often with the help of pseudonymous cookies, in order to recognize returning visitors.
- Controller: The natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: Any operation carried out in connection with personal data, with or without the aid of automated procedures — from collection through storage to erasure.
- Contract data: Information relating to the formalization of an agreement, e.g., subject matter of the contract, term and payment terms.
- Payment data: Information required for processing payment transactions, e.g., payment amounts, transaction data and invoice information.
Erstellt mit kostenlosem Datenschutz-Generator.de von Dr. Thomas Schwenke (created with the free privacy policy generator by Dr. Thomas Schwenke)
← Back to homepage