Privacy Policy
Controller
The controller responsible for processing personal data on this website is BauCloud GmbH (see Legal Notice).
Data protection officer
We have not appointed a data protection officer because Article 37 GDPR does not require us to. Direct any data-protection inquiries to datenschutz@baucloud.com.
Server logs and hosting
When you access this website, our hosting provider Fly.io, Inc. (2045 West Grand Avenue, Chicago, IL 60612, USA) automatically records your IP address, user agent, request path, and timestamp in server log files. Logs are retained for up to 30 days (source: Fly.io Logging Overview). Processing takes place in the EU regions Frankfurt, Amsterdam, and Paris.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in operating and securing the service). International data transfer: EU-U.S. Data Privacy Framework (Fly.io is an Active Participant — see Fly.io’s DPF Privacy Policy) plus EU Standard Contractual Clauses (SCCs) as a fallback safeguard.
Reach measurement
We use Plausible Analytics for anonymous reach measurement, operated by Plausible Insights OÜ, Sepapaja 6, 15551 Tallinn, Estonia — an EU processor; no third-country transfer. The Plausible script and the event endpoint are served from our own domain; your browser therefore makes no connection to plausible.io. We forward events to Plausible server-to-server.
Plausible uses no cookies and no localStorage; Section 25 TDDDG (German Telecommunications and Digital Services Data Protection Act) does not apply because no information is read from or stored on your device. A session-identification hash is computed from IP, user agent, and a daily salt, and the IP is discarded immediately. Aggregate statistics are retained for 24 months. Legal basis: Article 6(1)(f) GDPR. Details: plausible.io/data-policy.
Error and performance monitoring
Error and performance telemetry is processed by AppSignal (AppSignal B.V., Rietwaard 4, ’s-Hertogenbosch, Netherlands — an EU processor; no third-country transfer). Legal basis: Article 6(1)(f) GDPR (legitimate interest in stability and bug fixing). Retention: standard retention as described in appsignal.com/privacy-policy.
AppSignal also processes data within the scope of the Librario service contract; that processing is governed by the DPA and the sub-processor list rendered there.
Email communication
Inbound and outbound email is processed by two providers, depending on the purpose of the message:
- Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) — for general correspondence and data-protection inquiries (
datenschutz@baucloud.com). - HubSpot (HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany) — as our CRM for sales and support communication (e.g. messages to
support@librario.de).
Legal basis: Article 6(1)(b) GDPR (pre-contractual measures, contract negotiation and performance) or Article 6(1)(f) GDPR (efficient handling of general inquiries), as applicable. Retention: until the inquiry has been resolved, plus statutory retention periods. International data transfer: EU Standard Contractual Clauses under each provider’s data-processing agreement; additional safeguards through the DPF certification of the US parent companies.
Cookies and local storage
This website uses no cookies and no localStorage for tracking or analytics purposes. Logged-in customers reach Librario at their own subdomain (YOUR-COMPANY.mylibrar.io); strictly necessary session cookies for the authenticated area are set exclusively on that subdomain and are exempt from consent under Section 25(2)(2) TDDDG.
External resources
All fonts, scripts, and images are served directly from our own domain. We embed no Google Fonts CDN, no YouTube/Twitter embeds, and no third-party scripts. Your browser establishes no connections to third parties that would transmit personal data when you visit this website.
Automated decision-making
We do not engage in automated decision-making, including profiling, within the meaning of Article 22 GDPR.
Voluntary data provision
Providing your data when visiting this website is voluntary. There is no statutory or contractual obligation to provide it.
Rights of data subjects
You have the right at any time to object (Article 21 GDPR) to the processing of your personal data where it is based on Article 6(1)(f). Send objections to datenschutz@baucloud.com.
You are further entitled to the rights under Articles 15-20 GDPR — access, rectification, erasure, restriction of processing, and data portability. Send any such request to the same address.
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority for BauCloud GmbH (registered seat in Munich) is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27, 91522 Ansbach, Germany www.lda.bayern.de