Privacy Policy

How the Dietz Customer Portal processes personal data when you use it to run your projects with Dietz Engineering.

Prepared for Patrick Dietz · Dietz Engineering

This Privacy Policy explains how Patrick Dietz · Dietz Engineering ("we", "us") processes personal data when you use the Dietz Customer Portal. The Portal is available by invitation only. We use it to run projects, meetings, previews, tickets, files, invoices and communication with our business customers.

This Policy applies to the Portal at the portal domain. Our public website dietz-engineering.com is covered by the separate privacy policy published there. In case of doubt, the German version of this Policy prevails.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

You can reach us at the address above for any data protection question.

2. Data we process

We only process the data required to run the Portal and to perform our contract with you:

  • Account and sign-in data. Name, e-mail address, a cryptographically hashed password and, if you use them, two-factor authentication details (TOTP secret, backup codes) or passkeys. Also your membership in your organization and your role in it, invitations, sign-in times, and the time and version of your consent to our terms and this Policy.
  • Project data. Project status, revision rounds, tickets, comments, status changes and the related timestamps.
  • Meetings. Title, date, time, location or video link and agenda of the meetings we arrange with you.
  • Previews. Links to demo and test versions of your project with a title and a note. We do not store access credentials for these versions in the Portal.
  • Files. Files uploaded to a project by you or by us (e.g. schematics, documents, source code), including file name, size and upload time. Files are kept in private, access-controlled storage.
  • Invoice and payment data. Invoices, amounts, due dates and payment status. For online payment, the payment provider collects the payment details directly; the Portal stores no card or account details, only a reference to the payment. For payment by bank transfer we show you our bank details and a GiroCode; this requires no additional data from you.
  • Notifications. Notices in the Portal (bell), the related e-mails and your settings for which e-mails you want to receive.
  • Communication data. Messages you send us through the Portal and our replies.
  • Server and security logs. To secure the Portal we process technically necessary log data (including IP address, time of access, requested address, status code) and counters used to prevent abuse and overload.
  • Performance of the contract (Art. 6(1)(b) GDPR): providing your Portal account, running projects, meetings, previews, tickets, file exchange, invoicing and payment, as well as notifications and communication as part of our work together. This is the main purpose of the Portal.
  • Legitimate interests (Art. 6(1)(f) GDPR): operating, securing and troubleshooting the Portal, in particular security logs, abuse and overload prevention, the malware scan of uploaded files (section 6) and keeping the data of different customer organizations separate. Our legitimate interest is a secure and available Portal that also protects you from malware.
  • Legal obligations (Art. 6(1)(c) GDPR): retaining invoices and tax-relevant records for the statutory periods (section 8).

We do not need your consent to run the Portal. We use no tracking and no profiling and do not use your data for advertising (section 7).

4. Hosting and service providers

The Portal runs on a server in a data center in Germany; the encrypted backups are kept separately in a data center of the same provider in Finland. The database, malware scan and abuse prevention run on that server itself; no data is passed to further providers for them. We use the following service providers as processors (Art. 28 GDPR). A data processing agreement is in place with each of them.

PurposeProviderRegistered inData location
Server, database and file storageHetzner Online GmbHGermanyGermany
Encrypted database backupsHetzner Online GmbHGermanyFinland (EU)
Sending Portal e-mails (invitations, notifications, password)Google Cloud EMEA Limited (Google Workspace)IrelandEU and USA, see section 5
Online payment, only if you choose this payment methodStripe Payments Europe, Ltd.IrelandEU, see section 5

Name resolution (DNS) for the portal domain runs through Cloudflare. Cloudflare only answers at which address the Portal can be reached; traffic between your browser and the Portal does not pass through Cloudflare.

You can request an up-to-date list of our processors at patrick@dietz-engineering.com.

5. Transfers to third countries

Portal data is processed in Germany and the EU. A transfer to a third country can happen in the following cases:

  • Sending e-mails: We send Portal e-mails through Google Workspace. Google processes the recipient address, subject and content of the e-mail and may process this data in the USA. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which Google is certified, and on standard contractual clauses (Art. 45, 46 GDPR). The e-mails contain notices, for invoices also the invoice number and amount, and links into the Portal. Meeting e-mails include a calendar file; project files are never sent by e-mail.

  • Online payment: Stripe Payments Europe may transfer data to Stripe, Inc. in the USA. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework and on standard contractual clauses (Art. 45, 46 GDPR). If you pay by bank transfer, this transfer does not take place.

  • DNS: Cloudflare, Inc. (USA) technically processes the IP address of the querying DNS server during name resolution. Cloudflare receives no content from the Portal. Cloudflare is certified under the EU-US Data Privacy Framework.

6. Malware scan of uploaded files

We scan every file uploaded to the Portal for malware before it is released. The scan runs on our own server (ClamAV); the file does not leave our data center for it. If malware is found or the scan is not possible, we delete the file immediately, it is not released, and you get a message. The security log only records technical identifiers and the name of the detected signature, never file contents.

7. Cookies, tracking and analytics

The Portal uses only technically necessary cookies or similar local storage, for example for your sign-in session, protection against forged requests, and preferences such as language and appearance. They are required to operate the Portal.

We do not use analytics, tracking or advertising cookies. We do not measure usage, do not track you across devices and do not share data for advertising.

Preview links and video links for meetings lead to third-party sites (such as a demo server or a video service). The privacy policy of the respective provider applies there.

8. Retention periods

  • Account data: until your account is deleted (section 10). After that, personal data is deleted or anonymized unless a statutory retention obligation applies.
  • Invoices and tax-relevant records: 10 years (§ 147(3) German Fiscal Code, § 257 German Commercial Code). They are kept after an account deletion until the end of the period; personal references are anonymized as far as possible.
  • Project data, meetings, tickets and files: for the duration of our work together and afterwards until the warranty and limitation periods expire.
  • Notifications: until your account is deleted.
  • Server access logs: 14 days.
  • Backups: The database is backed up daily in encrypted form; each backup is deleted after 14 days. Server images at the hosting provider are overwritten after 7 days. Because the storage clean-up rule runs once a day, deleted data disappears from all backups within 16 days at the latest.

9. Data security

We protect your data with technical and organizational measures in line with the state of the art:

  • Access control: role-based permissions and strict separation between customer organizations. Each organization sees only its own projects, tickets, files and invoices.
  • Sign-in: mandatory e-mail verification, optional two-factor authentication and passkeys; two-factor authentication is mandatory for administrative accounts.
  • Encryption: transport encryption (TLS) for all connections; database backups are encrypted before they are stored, and the key needed to decrypt them is not kept on the server.
  • Confidential files: private storage; downloads only through short-lived links issued after a permission check; malware scan before every release (section 6).
  • Isolated server: the database, malware scanner and internal services cannot be reached from outside; security updates are installed automatically.
  • Abuse prevention: rate limits, for example after repeated failed sign-in attempts.

10. Deleting your account

You can ask us to delete your Portal account at any time; a message to patrick@dietz-engineering.com is enough. We then delete or anonymize your account and usage data and your files, usually within one month. Records we must keep for legal reasons are excluded (in particular invoices, section 8); for these, personal references are removed as far as possible. The data disappears from backups no later than 16 days after deletion.

11. Your rights

Under the GDPR you have the right to:

  • access the data stored about you (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure (Art. 17), unless a retention obligation applies;
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • lodge a complaint with a supervisory authority (Art. 77).

A message to patrick@dietz-engineering.com is enough to exercise these rights. For your protection we may verify your identity, for example through the e-mail address linked to your account.

Our competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg).

Before you use the Portal for the first time, we ask for your consent to our Terms and Conditions and this Privacy Policy. We store the time and version of these documents. If we change them materially, we increase the version and ask for your consent again at your next sign-in.

13. Changes to this Policy

We update this Privacy Policy when the operation of the Portal, the service providers we use or the legal situation change. The version published on this page applies; the date of the last update is shown at the top.

14. Contact

For questions or complaints about data protection, contact us at: