datenschutz

Privacy

Privacy notice for Resistro and Resistro Cloud.

Provider identification is available on the separate Legal Notice page.

Data Controller

Alexander Renz, UUXO, Germany. Email: hello@resistro.org

What Data We Collect

  • Account data: email address, name, hashed password
  • Billing data: processed by Paddle. We do not store credit card numbers.
  • Technical data: database names, backup metadata, agent hostname and version, IP addresses in access logs
  • Backup data: encrypted with your key. We cannot read it.
  • Performance of a contract under Art. 6(1)(b) GDPR: account management and service delivery
  • Legitimate interest under Art. 6(1)(f) GDPR: security logging and abuse prevention; and postal and electronic business development outreach (B2B direct marketing) to commercial contacts
  • Consent under Art. 6(1)(a) GDPR: marketing emails on an opt-in basis only

For postal and electronic outreach to prospective business contacts (B2B direct marketing), we process company name, business address, and, where available, a publicly listed business contact email address, on the basis of legitimate interest under Art. 6(1)(f) GDPR. Recital 47 GDPR expressly names direct marketing as a possible case of legitimate interest. Contact data originates from publicly available sources (e.g. the company website), processing is limited to B2B business development, no profiling takes place, and an objection can be raised at any time without formalities. This balancing shows that our interest in targeted business development does not override the protection-worthy interests of the contact persons.

You have the right to object at any time to the processing of your data for direct marketing purposes under Art. 21(2) GDPR, without giving reasons; upon receipt of an objection, your data will no longer be processed for this purpose. Objections can be raised informally by email to hello@resistro.org.

Data Processing

  • Hosting: Hetzner Online GmbH, Germany/EU. The default storage path uses Hetzner data centers in Germany/EU; roles, subprocessors, and transfers are reviewed in the privacy/AVV package.
  • Payments: Paddle.com Market Ltd, United Kingdom. Paddle acts as Merchant of Record.
  • Email: SMTP via our own infrastructure (hosted in the EU).

Retention Period

  • Account data: until account deletion plus 30 days
  • Backup data: per retention policy, maximum 30 days after cancellation
  • Access logs: 90 days
  • Billing records: 10 years under German tax law

Your Rights

Under the GDPR, you have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing, and the right to lodge a complaint with a supervisory authority.

To exercise these rights, contact us by email at hello@resistro.org.

Cookies

We use only technically necessary cookies via the session token stored in local storage. No tracking cookies, no analytics tools, no third-party scripts.

Security

All connections use TLS 1.3. Passwords are hashed with bcrypt. Backup data is stored with AES-256-GCM encryption; the key remains on the customer side. The default storage path uses Hetzner data centers in Germany/EU.