Privacy Policy

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit our website or use our service. Personal data is any data that can be used to personally identify you.

Data Collection on Our Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find the contact details in the imprint of this website.

How do we collect your data?

Your data is collected when you provide it to us. This may be data that you enter in a contact form or when registering for our newsletter.

Other data is collected automatically by our IT systems when you visit the website. This is mainly technical data (e.g. internet browser, operating system or time of page access). This data is collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior, particularly within the email marketing service.

What rights do you have regarding your data?

You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking or deletion of this data. For this purpose and for further questions on the subject of data protection, you can contact us at any time at the address given in the imprint.

2. Hosting and Content Delivery

Hosting in Germany

This website and the entire email marketing service are hosted in Germany. All personal data is stored and processed exclusively on servers in Germany.

3. General Information and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

When you use this website or our email marketing service, various personal data is collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

Responsible Party

The responsible party for data processing on this website is:

Andre Lommel
Heidenkampsweg 58
20097 Hamburg
Germany
Email: info@einfach-news.de

The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent you have already given at any time. An informal email notification is sufficient. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

SSL and TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.

Information, Blocking, Deletion

Within the framework of the applicable legal provisions, you have the right to free information about your stored personal data, its origin and recipient and the purpose of data processing and, if applicable, a right to correction, blocking or deletion of this data at any time. For this purpose and for further questions on the subject of personal data, you can contact us at any time at the address given in the imprint.

4. Data Collection on Our Website

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of server request
  • IP address

This data is not merged with other data sources. The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.

Cookies

The website uses cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.

Most of the cookies we use are so-called "session cookies". They are automatically deleted after your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser on your next visit.

Registration on This Website

You can register on our website to use additional functions on the site. We only use the data entered for this purpose to use the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration.

5. Newsletter and Email Marketing

Newsletter Registration (Double Opt-In)

If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the specified email address and agree to receive the newsletter.

We use a double opt-in procedure. This means that after your registration we will send you a confirmation email to the specified email address, in which we ask you to confirm that you wish to receive the newsletter. Only after your confirmation will your email address be actively added to our newsletter distribution list.

Data Stored During Newsletter Registration

The following data is stored during newsletter registration:

  • Email address (encrypted with AES-256)
  • Optional: First and last name (encrypted with AES-256)
  • Time of registration
  • Time of confirmation (double opt-in)
  • IP address at the time of registration and confirmation
  • Opening and click behavior (for statistical evaluations)

All personal data (email addresses, names) is stored in our database with AES-256 encryption.

Legal Basis and Revocation

Processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.

Every newsletter email contains an unsubscribe link. Alternatively, you can contact us by email at any time.

Storage Duration

The data stored with us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after you cancel the newsletter. Data that is stored with us for other purposes remains unaffected.

Newsletter statistics (openings, clicks) without personal reference can be retained for analytical purposes. You can configure retention periods in your team settings (default: 24 months).

6. Email Marketing Platform

Platform Functionality

Einfach-News is a self-hosted email marketing platform. As a customer, you can:

  • Manage recipient lists
  • Create and send newsletter campaigns
  • Create email templates
  • View delivery statistics
  • Configure multiple SMTP providers

Responsibility for Newsletter Recipients

If you send newsletters to your recipients as a customer of our platform, you are the controller within the meaning of the GDPR for the processing of recipient data. We act as a processor in accordance with Art. 28 GDPR.

You are obligated to:

  • Only contact recipients who have explicitly consented
  • Use the double opt-in procedure
  • Provide an easy unsubscribe option in every newsletter
  • Provide your own privacy policy

Encryption of Sensitive Data

All email addresses and names in recipient lists are stored in the database with AES-256 encryption. Encryption is performed automatically by Laravel Encryption.

No Transfer to Third Parties

We do not use external analytics services or tracking tools. All data remains on our servers in Germany. No transfer to third parties takes place, except:

  • You configure your own SMTP providers for email delivery
  • There is a legal obligation to disclose

SMTP Providers

You can configure your own SMTP providers (e.g. Amazon SES, SendGrid, Mailgun). Email delivery is then carried out via these providers. Please note the respective privacy policies of your providers.

7. Data Retention and Deletion

Retention Periods

You can configure in your team settings how long campaign data should be retained (default: 24 months). After this period expires, the following data is automatically deleted:

  • Delivery statistics (openings, clicks) with personal reference
  • Log entries for individual email delivery processes

Deletion Upon Account Termination

If you delete your account, all your data will be irreversibly deleted, including:

  • Recipient lists
  • Campaigns and templates
  • Delivery statistics
  • Team data

8. Data Security

We use technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. These include:

  • SSL/TLS encryption for all connections
  • AES-256 encryption for email addresses and names in the database
  • Redis-based session management
  • Regular security updates
  • Access restrictions at database level