This translation is for information only. The German version is legally binding.
Privacy Policy
Last updated: October 2026
1. Controller
Web Tools IT – Inh. Raffael Rump
Finkenweg 22
87439 Kempten
Germany
Email: [email protected]
We have not appointed a data protection officer, as the legal requirements for doing so are not met. Please send privacy enquiries to the email address above.
2. Overview
We process personal data only as far as necessary to operate castreon.net, your customer account, billing, support and the licensing of the Castreon software. We do not use analytics, tracking or advertising services. Fonts are loaded from our own server.
3. Hosting and delivery of the website
Hosting. castreon.net runs on a dedicated server operated by WorldStream B.V., Naaldwijk, the Netherlands. Data is stored in the European Union. A data processing agreement under Art. 28 GDPR is in place with the provider.
Cloudflare. All requests to castreon.net pass through the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare protects the website against attacks and speeds up delivery. In doing so, it processes in particular your IP address and the technical details of your request. Cloudflare is certified under the EU-US Data Privacy Framework; the European Commission's standard contractual clauses apply in addition. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
4. Server log files
For every request, the web server stores: IP address, date and time, requested address, referrer, browser and system information, and the status code. Log files are used for security and troubleshooting and are deleted after 14 days. The legal basis is Art. 6(1)(f) GDPR.
5. Cookies and local storage
We only use technically necessary cookies:
- castreon_session — keeps your session (sign-in, selected language); becomes invalid when the session ends.
- XSRF-TOKEN — protects forms against forged requests.
- remember_web_… — only if you choose “Remember me” when signing in.
In the customer account, your display preference (light, dark, system) is also stored in your browser's local storage. No consent is required for this strictly necessary storage (§ 25(2) no. 2 TDDDG).
6. Customer account
For your account we process: name, company, email address, country, postal code, city, phone number (optional), VAT ID and its validation result, preferred language, an encrypted password and — if you enable it — two-factor sign-in data. To protect your account, we store the time and IP address of your last sign-in. At registration and when subscribing, we store your confirmation that you are acting as a business, and the date and version of the accepted terms.
The legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in account security (Art. 6(1)(f) GDPR). The data is kept as long as your account exists and is then deleted, unless statutory retention obligations apply.
7. Payments
Payments are processed by Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, the Netherlands. You enter your card details directly with Mollie; we do not receive them. From Mollie we receive a customer and payment identifier, the payment status, and the card type, last four digits and expiry date. Mollie also processes data under its own responsibility, for example to prevent fraud; see https://www.mollie.com/privacy. The legal bases are Art. 6(1)(b) and (c) GDPR.
8. VAT ID validation
If you provide a VAT ID, we validate it through the European Commission's VAT Information Exchange System (VIES). The country code and number are transmitted. The legal bases are Art. 6(1)(c) and (f) GDPR (correct VAT treatment).
9. Invoices and retention
Invoices contain your name, company, address and, where applicable, your VAT ID. We keep invoices and accounting records for the statutory periods (in particular § 147 AO, § 257 HGB). The legal basis is Art. 6(1)(c) GDPR.
10. Support
When you open a support ticket, we process your messages and uploaded attachments to handle your request. The legal basis is Art. 6(1)(b) GDPR. Tickets are deleted together with your account unless retention obligations apply.
11. Emails
We send system messages (for example account confirmation, password, invoices, ticket replies) through Postmark, a service of ActiveCampaign, LLC, 1 N Dearborn St, Chicago, IL 60602, USA. Your email address and the content of the message are transmitted. ActiveCampaign is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. The legal basis is Art. 6(1)(b) GDPR.
12. License checks and software updates
The Castreon software installed on your server regularly checks its license online with our license server, currently about every six hours, and asks for available updates. The following is transmitted: license identifier, a device identifier (a one-way hash of hardware characteristics of the server), the installed version and the server's IP address. The purpose is license validation, protection against misuse and the provision of updates. The legal bases are Art. 6(1)(b) and (f) GDPR.
We have no access to the content, channels and viewer data you process with Castreon on your own server. You are responsible for that data yourself.
13. Recipients and transfers to third countries
Your data is only shared with the service providers named in this policy and with authorities where we are legally required to do so (for example the tax office). Transfers to the USA only go to providers certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.
14. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw any consent at any time with effect for the future.
Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.