DSGVO steht für General Data Protection Regulation (DSGVO). Ein neues, von der EU erlassenes Gesetz zum Schutz der persönlichen Daten von Endnutzern. Dieses Gesetz regelt verschiedene Aspekte der Datensicherheit. Hier möchten wir dir einen Leitfaden an die Hand geben, wie wir deine Daten schützen, was unsere Verantwortung ist und was deine Verantwortung ist. Wir empfehlen dir dringend, unsere Dokumentation oder andere Artikel über die DSGVO zu lesen und dann zu entscheiden, ob du unsere Anwendung nutzen möchtest oder nicht. Wir sind nicht verantwortlich für Nachlässigkeit oder Fehler beim Datenschutz auf deiner Seite oder auf der Seite Dritter. Nimm dir die Zeit, die Dokumentation zu lesen und handle weise, um sicher zu sein.
Alle Daten, die einer Person gehören, sind ihre persönlichen Daten. Das können der Name, das Bild, die E-Mail-Adresse, die Adresse, der Social Media-Post, der Standort, die IP-Adresse des Computers usw. sein. Das Eigentum an den persönlichen Daten der Nutzer/innen ist absolut. Das heißt, wo und wie auch immer die Daten gespeichert werden, sie gehören ausschließlich dem Nutzer. Der Datensammler oder Datennutzer (Facebook, Youtube) darf die persönlichen Daten des Nutzers ohne dessen ausdrückliche oder stillschweigende Zustimmung nicht anzeigen, speichern, weitergeben oder anderweitig verwenden. Wenn ein Nutzer die Erlaubnis erteilt, seine Daten für eine bestimmte Aktion zu verwenden (Daten speichern, Daten anzeigen usw.), kann der Administrator der Anwendung diese Daten verwenden. Um dies zu veranschaulichen, stelle dir eine hypothetische Situation vor. Du postest einen Status auf Social Media. Hier hast du die implizite Erlaubnis erteilt, den Beitrag deinen öffentlichen oder privaten Kontakten zu zeigen. Der Administrator der Anwendung ist nicht verantwortlich für missbräuchliche Kommentare, die deine Kontakte zu deinem Beitrag abgeben. Das heißt, wenn du deine Daten öffentlich gemacht hast, bist du dafür verantwortlich. Die Anwendungsadministration ist jedoch für die Weitergabe von Daten an Dritte verantwortlich. Wenn Daten weitergegeben werden, muss dies im Voraus ausdrücklich erwähnt werden. Wir sehen also, wie das Hochladen und Anzeigen von Daten sowohl vom App-Administrator als auch vom Nutzer abhängt. Weitere Details erfährst du, wenn du die vollständige Dokumentation liest.
The safeguard of user personal data on application back end is the responsibility of developer. Developer is responsible for how the user data (name, telephone no. email etc ) and other info ( like logs of user interaction with application ) is stored on database and server. We will describe in detail how the data you submit directly (name, email etc.) and indirectly (browser name, computer IP etc.) are saved on database and server. Once any data uploaded to server the security of data depends on security of server and sometimes the admin of application. User will be notified about all the temporary (cookie and session) and permanent (data saved to database) data saving. User will get the option of all his or her personal data erasing permanently upon account deletion or service cancellation. We assure you that we do not keep logs of user activity and any other backdoor to extract user data. Sometime cpanel access and other credential of app admin is needed by the developer to support and maintaining of the application for short time before the application goes full online. We strongly recommend to app admin to change these credential after the job get done. Developer cannot be held responsible for any credential leak on this ground. Developer also cannot be held responsible for any unwilling security glitch on the application. After all, data shared online always has the risk of getting leaked. So we strongly suggest not to share any data that can compromise you any other individual.
Der Anwendungsadministrator hat uneingeschränkten Zugriff auf die persönlichen Daten der Nutzer. Der Administrator kann auf die Datenbank, die Serverprotokolle und alle anderen Informationen zugreifen, die für den Administrator zugänglich sind. Der Anwendungsadministrator kann die in der Datenbank und auf dem Server gespeicherten Daten einsehen und kopieren. Der App-Administrator kann die persönlichen Daten der Nutzer/innen an Dritte weitergeben. Wie die Daten der Nutzer/innen verwendet werden, muss der App-Administrator vor der Nutzer/innenregistrierung ausdrücklich bekannt geben. Der App-Administrator darf niemandem erlauben, offen oder getarnt durch Umfragen, das Ausfüllen von Formularen oder auf andere Weise Daten zu sammeln. Der App-Administrator genießt die meisten Privilegien in der Anwendung. Daher trägt er die größte Verantwortung für die sichere Aufbewahrung der persönlichen Daten der Nutzer/innen.
It’s all depends on user. If user do not submit data then there will be no data breach. But this is not an option. The top most priority of user is to read all the documentation from both app developer and app admin then submit the data. Safe keeping of user’s own credential is sole responsibility of user. Password and username may be encrypted on database but a dictionary word or too predictable password for a specific user can give easily access to user’s account to hacker. Change your credential on any suspicious activity by unauthorized person or in case of you share your credential to other for some inevitable reason. Always think before submit.
Adios, Applikation: Wenn du dein Abo kündigst oder dein Konto löschst, bieten wir dir die Möglichkeit, alle bestehenden oder mit deinem Konto verbundenen Daten zu löschen. Beachte, dass diese Aktion nicht rückgängig zu machen ist. In dem Moment, in dem du die Löschung bestätigst, werden alle deine Daten für immer aus der Datenbank und vom Server gelöscht. Du kannst deine Daten vor dem Löschen sichern, falls du dich neu anmelden oder registrieren möchtest.
Secrecy is my right: We encrypt most of your personal data on database. If any bad things occur (data breach) then the hacker will get encrypted hash not your personal on plain text. So your secrecy will intact even in case of data breach. Note that, some data cannot be encrypted because we need to show it upon login to account (like username). We will hide all your personal data as much as possible.
No cookie and session saving: We will give option to save or do not save cookie and session. Even if you save cookie and session these will be destroyed after logout. We strongly suggest you not save your credential in browser. Please memorize your credential or use tools like lastpass to manage your credential.
Fußabdrücke vernichten: Wir speichern oder verfolgen keine deiner Aktivitäten zu kommerziellen Zwecken. Wir können deine Anmeldezeit oder IP-Adresse nur zu Sicherheitszwecken speichern. Wenn du dein Konto löschst, werden alle deine Daten vom Server gelöscht.
Social engineering is bad: We do not record any of your personal activity on the application. Recording user’s personal activity, analyzing it and try to sell a product or motivating user to pursue a certain thought upon analyzed data is becoming a malpractice. We do not do such things.
Notify me: Get notified about all your activity relating to your account (account creation, password change) by email. We suggest you to change your credential if any unusual things occur.
Policy Update notification: You will get notified on any privacy policy or disclaimer updates. Read your email regarding to this matter and decide your action. Feel free to consult on this matter.
Connect without worry: We enforced HTTPS everywhere. Data sniffing is not possible on this case. Even possible, the sniffer will get encrypted hash. So feel safe to use our application.
No data collecting: We do not collect any data of user. No backdoor, No hidden option to collect data. Once the application is uploaded to server even we cannot enter to application without app admin password. So do not worry about any hidden data leak.
Data breach policy: We implement all the security to store your data carefully on database (data encryption, MySQLi, SQL injection prevention, input checking etc.). But we do not take any responsibility of data breaches from server. Because it is total responsibility of app admin and server admin to secure your data from breaching. Any weak or too predictable password of app admin or server admin could compromise database. Any inherent fault on database config can give away the database (MongoDB security fault). Any security flaw on server can lead to data leaking. Please contact your app admin on this regard.