This English version is a convenience translation provided for information; the German version at ppwr-doc.com/datenschutz is the legally binding one.
1. Controller
The controller responsible for data processing on this website is Max Fischer (MXF Labs), Lammersdorfer Straße 2, 52159 Roetgen, Germany, email: [email protected] (see legal notice).
2. What data we process
Packaging data (entries in the generator): The information you enter in the wizard (e.g. company name, packaging description, signatory) is processed to create your PDF document. For single orders, these entries are deleted after the document has been created and are not stored permanently. For bundle and business orders, we store your text entries for the duration of your creation period (12 months) so that you can edit existing declarations and use them as a template for further declarations (Art. 6(1)(b) GDPR); uploaded signature and photo files are not retained in this process. After the creation period expires, the stored entries are deleted automatically.
Order and invoice data: To process your purchase, we store your email address, the selected plan, the payment reference and the invoice amount. This is necessary for the performance of the contract (Art. 6(1)(b) GDPR) and is subject to statutory retention periods (Art. 6(1)(c) GDPR); deletion takes place after these periods expire (6 or 10 years, Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB)).
Generated PDF: Your finished document is kept on our servers in the EU for 30 days so that you can download it again, and is deleted automatically afterwards.
3. Hosting
This website is operated on servers in the EU (Hetzner Online GmbH, data center location EU/Finland). No hosting takes place in third countries. A data processing agreement (DPA) is in place with Hetzner.
3a. Content delivery / protection against attacks (Cloudflare)
This website is delivered via the content delivery network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. In this process, Cloudflare processes technical connection data (e.g. IP address) to protect against attacks and to deliver the content (Art. 6(1)(f) GDPR, security and stability). Cloudflare is certified under the EU-US Data Privacy Framework; in addition, EU standard contractual clauses are in place. Your entries from the generator are processed and stored exclusively on our EU servers.
3b. Cookies and local storage
This website does not use any cookies requiring consent and no tracking technologies; a cookie banner is therefore not required. For the generator to function, we temporarily store your entries in your browser's sessionStorage; this storage is necessary to provide the service (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG)) and is deleted when you close the browser tab. Cloudflare may set technically necessary security cookies.
4. Payment processing (Polar)
Sales are handled by Polar (Polar Software Inc.) as Merchant of Record. To prepare the payment process, we transmit your email address (to pre-fill the payment form) and your IP address (to determine the display currency and tax rate) to Polar (Art. 6(1)(b) GDPR). When you make a purchase, the data required for payment (e.g. email address, billing address, payment details) is processed directly by Polar and its payment service provider (Stripe, including the optional “Link” service). Where data is transferred to third countries in this process, this takes place on the basis of appropriate safeguards (Art. 46 GDPR, EU standard contractual clauses). Further details are set out in the privacy policies of Polar (polar.sh/legal/privacy) and Stripe (stripe.com/privacy). Your packaging data from the generator is not affected by this, it remains on our EU servers.
5. Email delivery (Resend)
To deliver your document and the order confirmation, we use the Resend service (EU region). Your email address is processed for this purpose (Art. 6(1)(b) GDPR). A data processing agreement (DPA) is in place with Resend; delivery takes place via EU infrastructure.
6. Audience measurement (PostHog)
We use cookieless audience measurement with PostHog (PostHog Inc., processing in the EU cloud, data center Frankfurt). No cookies are set, no data is stored in your browser and no personal profiles are created; measurement is session-based and anonymous (Art. 6(1)(f) GDPR, analysis and improvement of our service). “Do Not Track” settings in your browser are respected. There is no tracking by Google or advertising networks.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability. To exercise these rights, please contact [email protected].
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR (e.g. delivery via Cloudflare, abuse protection), you have the right to object at any time on grounds relating to your particular situation.
You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, ldi.nrw.de).