Privacy policy
Last updated: October 2026 · Controller: Fwdia (see imprint)
The short version
- We collect only what running Fwdia requires - nothing is sold, rented or shared for advertising.
- Public micro-sites set no cookies and use no tracking scripts.
- Site statistics are anonymous, aggregated day-level counters. Visitor hashes rotate daily and are deleted.
- You can export or erase all your data yourself, at any time, from your account.
1. What we process, and why
Account holders
- Account data (email, name, password hash) - to operate your account. Legal basis: contract (GDPR art. 6(1)(b)).
- Content you create (micro-sites, uploads, QR settings) - to publish it as you instruct. Basis: contract.
- Billing data - processed by Paddle as Merchant of Record; we store only plan status and Paddle references, never card numbers. Basis: contract & legal obligation.
- Security logs (login events with salted IP hashes) - to protect accounts. Basis: legitimate interest (art. 6(1)(f)).
- Marketing emails - only with your opt-in, revocable anytime. Basis: consent (art. 6(1)(a)).
Visitors of micro-sites
- Standard technical data (IP, user agent) is processed transiently to deliver the page and prevent abuse.
- For statistics we store a one-way daily-rotating hash - it cannot be reversed to identify you and is deleted after the day ends. Only aggregate counters (views per day, clicks per link, visits per source) are kept.
- To show owners where visits come from, we count the name of the referring website or app (for example "instagram" or "google"), or a source tag in the link you followed (such as
?src=newsletter). Only that name is added to a daily counter - never the full address you came from, and never linked to you. - Form submissions you send go to the micro-site's owner, who is the controller for that data; we process it on their behalf (see DPA).
- Embedded videos/maps load from YouTube/Vimeo/OpenStreetMap only after you tap them - nothing loads from third parties before that.
2. Processors we use
Hosting (EU data center), Paddle (payments, Merchant of Record) and our transactional email provider. Each is bound by a data processing agreement. We transfer no personal data outside the EU/EEA except where the processor provides adequate safeguards (SCCs).
3. Retention
- Account & content: while your account exists, plus a 30-day recovery window after deletion.
- Visitor hashes: max 24 hours. Aggregate stats: as long as the site exists.
- Security & audit logs: 12 months.
- Invoicing records (held by Paddle): statutory retention periods.
4. Your rights
Access, rectification, erasure, restriction, portability, objection - exercise them self-service under Account, or contact us (contact form). You may also complain to your local supervisory authority. Details: Your GDPR rights.
5. Security
TLS in transit, Argon2id password hashing, encrypted 2FA secrets, least-privilege access, and audited administrative actions. See our terms for responsible disclosure.
6. Changes
We announce material changes by email and at this page 14 days in advance.