Privacy Policy
Deutsche Version: Datenschutzerklärung · Last updated: 2 September 2026
1. Controller
The controller responsible for data processing on this website is:
Dzmitry Yuzepchuk (mdsoft.dev)Arkadius-Geirhos-Straße 1c
89250 Senden, Germany
Email: [email protected]
2. Hosting and server log files
This is a static website. When you visit it, our hosting provider automatically processes technical data that your browser transmits: IP address, date and time of the request, requested URL, referrer URL, browser type and version, and operating system. This data is processed in server log files to deliver the website, ensure its stability and security, and detect abuse.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of the website). Log files are deleted by the hosting provider according to its retention schedule and are not merged with other data sources.
The website is hosted by DigitalOcean, LLC with the hosting region set to Frankfurt, Germany. DigitalOcean App Platform includes a built-in content delivery network operated on Cloudflare's infrastructure, so a page is normally answered by the Cloudflare edge server closest to you rather than by the Frankfurt origin directly. Cloudflare, Inc. therefore processes the same technical connection data described above, as a processor on our hosting provider's behalf; the cookie it sets for bot protection is described in section 5 below.
Because that network is global, a request may be answered outside the EU — for visitors located there, in the USA. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, so such transfers are covered by the European Commission's adequacy decision of 10 July 2023.
3. Contact by email
This website contains no contact forms. If you contact us by email — for example, to request support for one of our extensions — we process the personal data contained in your message (your email address, name if provided, and the content of the correspondence, which may include configuration details or log excerpts you choose to share).
This data is processed to handle your request. The legal basis is Art. 6(1)(b) GDPR where the request relates to a contract (e.g. support for a purchased extension) and Art. 6(1)(f) GDPR otherwise (legitimate interest in answering inquiries). Correspondence is retained as long as needed to handle the request and to comply with statutory retention obligations.
Please do not send us more personal data than necessary and remove sensitive data from logs before sharing them.
Email for the mdsoft.dev domain — both the messages you send us and those we send you — is operated on our behalf by Spaceship, Inc., 4600 East Washington Street, Suite 300, Phoenix, AZ 85034, USA, as a processor under Art. 28 GDPR. Because that company is established in the United States, this involves a transfer to a third country. The transfer is covered by the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module Two, controller to processor), which form part of our data processing addendum with them.
4. Purchases and payment processing
We do not process payments ourselves. A Buy link takes you to account.mdsoft.dev, a page of ours whose only purpose is to open a checkout operated by Paddle.com Market Limited, 30 Old Bailey, London EC4M 7AU, United Kingdom (company number 8172165) — for buyers in the United States Paddle.com Inc., and in Canada Paddle.com (Canada) Ltd — who act as our reseller and Merchant of Record. Paddle is the seller of record for the transaction: they collect your payment and billing details, calculate and remit the applicable VAT, and issue your invoice. No payment data reaches this website or our servers, and we neither see nor store your card details.
When a purchase completes, Paddle passes us the data we need in order to supply the product: your email address, your Paddle customer identifier, and the status and paid-through date of your subscription. We process this to issue your Composer access credentials, supply the extension you purchased and keep your subscription entitlement current, and to send you installation instructions and service messages about your subscription. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
We keep this data for as long as your subscription entitles you to downloads, and afterwards for as long as statutory retention periods require. Paddle's own privacy policy governs everything that happens on their checkout pages; it is available at paddle.com/legal/privacy.
The systems holding this data run on virtual servers we rent from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in their Falkenstein data centre in Germany. The purchase confirmation and the service messages about your subscription are sent through the email provider described in section 3. Both act as processors on our instructions under Art. 28 GDPR.
5. Cookies and tracking
This website embeds no external fonts and no other third-party content; all resources are served from this domain. Without your consent, no data is transmitted to any third party. This includes the checkout: the Buy link is an ordinary link, so nothing is loaded from Paddle while you are on this website.
Following it takes you to account.mdsoft.dev, a separate page of ours that exists only to open the checkout. That page loads Paddle's checkout script from cdn.paddle.com, which in turn loads further resources of Paddle's own, and displays Paddle's payment form. The script is strictly necessary to carry out the purchase you asked for, so it rests on § 25(2) no. 2 TDDDG rather than on consent. Paddle's own cookie and privacy policies apply to the payment form and to everything you enter into it.
Google Analytics — only with your consent
With your consent we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use it to understand how this website is used — which pages are visited, and where visitors arrive from.
Google Analytics stores information on your device (cookies) and processes, among other things, your truncated IP address, details about your browser and device, and the pages you view. The legal basis for storing data on your device is § 25(1) TDDDG, and for the subsequent processing Art. 6(1)(a) GDPR — in both cases, your consent.
Until you consent, nothing is loaded. Google's script is only requested after you agree; if you decline or make no choice, no connection to Google takes place and nothing is stored.
Google may also process the collected data in the USA. Google LLC is certified under the EU-US Data Privacy Framework, so transfers to the USA are covered by the European Commission's adequacy decision of 10 July 2023. In addition, we have concluded a data processing agreement with Google. For details of how Google handles data, see policies.google.com/privacy.
User-level data held by Google is deleted automatically after 14 months.
Withdrawing your consent
You may withdraw your consent at any time with effect for the future, using the Cookie settings link at the foot of every page. Withdrawing is as easy as giving consent. Your decision itself is stored locally in your browser (localStorage) so that we can honour it; that storage does not require consent under § 25(2) no. 2 TDDDG, as it is strictly necessary to give effect to your choice. We ask again after twelve months.
Your consent covers audience measurement only. The data is not used for advertising, remarketing or personalised ads; the corresponding Google signals remain switched off.
Technically necessary cookies
The content delivery network used by our hosting provider (Cloudflare) sets one technically necessary cookie, __cf_bm, to distinguish automated traffic from human visitors and protect the site against bots. It expires after 30 minutes and is not used for tracking, profiling, or advertising. Storing it does not require your consent under § 25(2) no. 2 TDDDG, as it is strictly necessary to provide the service you requested; the associated processing is based on Art. 6(1)(f) GDPR (legitimate interest in protecting the website against abuse).
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15),
- rectification of inaccurate data (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on Art. 6(1)(f) GDPR (Art. 21).
To exercise these rights, contact us at the address above. You also have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach, Germany.
7. Changes to this policy
We may update this Privacy Policy when the website or legal requirements change. The current version is always available at https://www.mdsoft.dev/privacy/.