Privacy Policy
1. Introduction and Scope
The protection of your personal data is important to us. This privacy policy informs you in accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR) and § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) about which personal data we collect, how we process it, and what rights you have.
This privacy policy applies to the website circuitdoc.de and the web application at circuitdoc.de/app.
2. Data Controller (Art. 4 No. 7 GDPR)
The data controller within the meaning of the GDPR is:
John-Jeffrey Lühs
(Operator of CircuitDoc)
Breslauer Straße 7
49393 Lohne
Germany
E-Mail: info@circuitdoc.de
3. Principles of Data Processing
We process personal data only if a legal basis under Art. 6 GDPR exists. Specifically, we rely on the following legal bases:
- Art. 6 Abs. 1 lit. a DSGVO – Consent of the data subject (e.g. optional cookies)
- Art. 6 Abs. 1 lit. b DSGVO – Performance of a contract or pre-contractual measures (e.g. app usage, registration)
- Art. 6 Abs. 1 lit. c DSGVO – Compliance with a legal obligation
- Art. 6 Abs. 1 lit. f DSGVO – Protection of legitimate interests (e.g. server log files for IT security)
Personal data is deleted or blocked as soon as the purpose of storage ceases to apply. Storage may also occur if provided for by European or national legislators in EU regulations, laws, or other provisions.
4. Website Access and Server Log Files
Each time our website is accessed, our web server automatically collects information transmitted by your browser. These so-called server log files contain:
- IP address of the requesting device (anonymised or complete)
- Date and time of access
- Name and URL of the retrieved file
- Website from which access was made (referrer URL)
- Browser used and, if applicable, the operating system and the name of your access provider
- HTTP status code and amount of data transferred
| Attribute | Details |
|---|---|
| Purpose | Ensuring technical operation, defence against attacks, error analysis |
| Legal basis | Art. 6 Abs. 1 lit. f DSGVO (legitimate interest: IT security and stable operation) |
| Retention period | Typically 7–14 days, then automatically deleted |
| Disclosure | No disclosure to third parties except the hosting provider (processor, see Section 5) |
The temporary storage of the IP address by the system is technically necessary to enable the website to be delivered to the user's computer. For this purpose, the IP address must remain stored for the duration of the session.
5. Web Hosting
Our website and app are hosted by an external hosting provider. Personal data collected on this website is stored on the host's servers. This may include IP addresses, contact requests, meta and communication data, and other data generated via a website.
The hosting provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; the server is located in Berlin, Germany. The provider is used on the basis of Art. 6(1)(f) GDPR; a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is in place.
5.1 Database
Application data is stored in a managed PostgreSQL database operated by Supabase Inc., 970 Toa Payoh North, Singapore. The server location is Frankfurt am Main, Germany (region eu-central-1); in regular operation the data does not leave the European Union. Supabase acts as a processor pursuant to Art. 28 GDPR; a Data Processing Agreement is in place. For access from third countries by the provider we rely on the EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
5.2 E-Mail Delivery
We send confirmation and password reset e-mails via our own mail server (mailcow), which we operate ourselves on our server at the hosting provider named in Section 5. No external e-mail service provider is involved. Your e-mail address, your user name and the content of the respective message are processed; for delivery, the message is transmitted to the mail server of your e-mail provider. The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement).
6. Cookies and Similar Technologies (§ 25 TDDDG)
Our website uses cookies and similar technologies (such as the browser's local storage). Pursuant to § 25(1) TDDDG, storing information on users' end devices or accessing already stored information is only permitted with their consent – unless the storage is strictly necessary to provide a service explicitly requested (§ 25(2) TDDDG).
6.1 Technically Necessary Cookies
These cookies are strictly necessary for the technical operation of the website and cannot be disabled. They do not store personal data and are not used for advertising or tracking.
| Name | Purpose | Duration | Provider | Legal basis |
|---|---|---|---|---|
cd_cookie_consent |
Stores your cookie consent and settings (local storage) | until cleared in the browser | CircuitDoc | § 25 Abs. 2 Nr. 2 TDDDG |
cd_consent_set |
Records server-side that the cookie notice has been answered (cookie, SameSite=Lax) | 365 days | CircuitDoc | § 25 Abs. 2 Nr. 2 TDDDG |
cd_session |
Keeps you signed in: access and refresh token, user name, e-mail address (local storage). Only after sign-in. | until sign-out | CircuitDoc | § 25 Abs. 2 Nr. 2 TDDDG |
cd_username, cd_email |
Displays your name and address in the interface without another server request (local storage) | until sign-out | CircuitDoc | § 25 Abs. 2 Nr. 2 TDDDG |
.AspNetCore.Antiforgery.* |
Protection against cross-site request forgery in forms | session | CircuitDoc | § 25 Abs. 2 Nr. 2 TDDDG |
6.2 Statistics Cookies (optional)
These cookies enable analysis of website usage in order to improve our service. They are only set with your explicit consent. Currently no statistics cookies are in use. Should such cookies be used in future, this privacy policy will be updated accordingly.
| Name | Purpose | Duration | Provider |
|---|---|---|---|
| No statistics cookies currently in use. | |||
6.3 Marketing Cookies (optional)
Marketing cookies serve to deliver personalised advertising and measure campaign success. They are only set with your explicit consent. Currently no marketing cookies are in use.
| Name | Purpose | Duration | Provider |
|---|---|---|---|
| No marketing cookies currently in use. | |||
6.4 Consent Management and Withdrawal
When you first visit our website, a cookie banner will be displayed through which you can grant or refuse consent for optional cookie categories. Your consent is voluntary. Refusing optional cookies has no impact on the usability of the website.
You can adjust your cookie settings or withdraw your consent at any time via the "Cookie Settings" link in the footer of this website. Withdrawal applies to the future and does not affect the lawfulness of processing carried out prior to withdrawal.
7. Contact
When you contact us by e-mail, the data you provide (e-mail address, and any name and message content) will be stored in order to process your enquiry.
| Attribute | Details |
|---|---|
| Data collected | E-mail address, name if provided, message content |
| Purpose | Processing your enquiry |
| Legal basis | Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries) |
| Retention period | Until the enquiry is finally resolved. Where statutory retention obligations apply, the retention period is extended accordingly. |
| Disclosure | None |
8. Use of the CircuitDoc App (circuitdoc.de/app)
The CircuitDoc app at circuitdoc.de/app requires registration to use. The following personal data is collected and processed:
| Data category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | E-mail address, password (stored exclusively as a BCrypt hash) | Registration and authentication | Art. 6 Abs. 1 lit. b DSGVO |
| Usage data | Project data, cable data, board data | Provision of the service | Art. 6 Abs. 1 lit. b DSGVO |
| Technical data | IP address, timestamps, device information | Security, abuse prevention | Art. 6 Abs. 1 lit. f DSGVO |
9. Disclosure of Personal Data to Third Parties
Your personal data is generally not transferred to third parties, unless:
- You have given your explicit consent pursuant to Art. 6(1)(a) GDPR,
- the disclosure is necessary for the performance of a contract pursuant to Art. 6(1)(b) GDPR,
- there is a legal obligation to disclose under Art. 6(1)(c) GDPR,
- the disclosure is necessary pursuant to Art. 6(1)(f) GDPR for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data, or
- they are processors (Art. 28 GDPR) acting under a concluded data processing agreement (e.g. hosting providers).
10. Transfer to Third Countries
Where possible, data is processed exclusively within the European Union (EU) and the European Economic Area (EEA). Should a transfer to a third country be required, we rely on appropriate safeguards pursuant to Art. 46 GDPR – in particular the standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR) – or on an adequacy decision by the EU Commission pursuant to Art. 45 GDPR.
11. Retention Period and Deletion
Personal data is stored only for as long as necessary for the respective processing purpose or as required by statutory retention obligations. Once the storage purpose ceases to apply, the data is routinely deleted.
| Data category | Retention period | Reason |
|---|---|---|
| Server log files | 7–14 days | Technical necessity, IT security |
| Cookie consent (local storage) | 365 days | Proof of consent |
| Contact requests by e-mail | Until enquiry resolved; longer if legally required | Contract performance / legitimate interest |
| User account data (app) | Until account deletion; extended by retention obligations if applicable | Contract performance |
Please note that statutory retention obligations (e.g. commercial and tax law obligations under §§ 147 AO, 257 HGB) may require storage for up to 10 years.
12. Your Rights as a Data Subject
As a data subject, you have the following rights under the GDPR:
Right of access
You have the right to request confirmation as to whether we process personal data about you. If so, you have the right to access this data and further information (purposes, categories, recipients, retention period, etc.).
Right to rectification
You have the right to request the immediate rectification of inaccurate or the completion of incomplete personal data.
Right to erasure
You have the right to request the erasure of your personal data, provided that processing is not necessary to comply with a legal obligation, to establish or defend legal claims, or for other reasons listed in Art. 17(3) GDPR.
Right to restriction of processing
You have the right to request restriction of the processing of your data, e.g. if you contest the accuracy of the data or the processing is unlawful but you oppose erasure.
Right to data portability
You have the right to receive personal data concerning you in a structured, commonly used and machine-readable format and to transmit it to another controller, provided that the processing is based on consent or a contract and is carried out by automated means.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you based on Art. 6(1)(e) or (f) GDPR. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests.
Right to withdraw consent
Where processing is based on your consent, you have the right to withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data (see Section 13).
info@circuitdoc.de . We will respond to your request within one month of receipt (Art. 12(3) GDPR).
13. Right to Lodge a Complaint with the Supervisory Authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
www.bfdi.bund.de – Federal Commissioner for Data Protection and Freedom of Information
14. Automated Decision-Making and Profiling
We do not use automated decision-making processes including profiling pursuant to Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
15. Data Security
We take appropriate technical and organisational security measures (TOMs) pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorised access. Our security measures are continuously improved in line with technological developments.
Data transmission between your browser and our servers is encrypted using TLS/SSL (HTTPS). Passwords are stored exclusively as a BCrypt hash – we do not know them in plain text and cannot recover them. One-time tokens for e-mail confirmation (valid 7 days) and for password reset (valid 2 hours, single use) are likewise stored only as hashes.
16. Currency and Amendment of this Privacy Policy
This privacy policy is currently valid and dated March 2026. As our website and services develop, or due to changes in legal or regulatory requirements, it may be necessary to amend this privacy policy.
In the event of material changes affecting your rights as a data subject, we will inform you in an appropriate manner (e.g. by a notice on our website). We recommend checking this privacy policy regularly to stay informed about the current version.