Privacy, security and transparency

Privacy should be understandable, not hidden behind legal language.

This Privacy Policy explains how MT Digital Studio handles personal data when you visit our website, contact us, subscribe to the newsletter, use an account or client portal, submit a review, rent one of our software products, or work with us on a development, automation or consulting project.

Our approach is simple: collect only what we need, use it for a defined purpose, protect it proportionately, keep it only for as long as necessary, and make it clear how you can exercise your rights.

01Data minimisation

We aim to collect only data that is genuinely needed for the requested function or business relationship.

02Purpose limitation

Personal data is used for clear purposes such as responding to enquiries, providing services, account access or sending a requested newsletter.

03Control stays with you

Where processing is based on consent, you can withdraw that consent. GDPR rights remain available independently of our interface.

01

Scope and who this policy is for

This Privacy Policy applies to the public website mt-digitalstudio.com and to digital interactions that are directly connected to MT Digital Studio, including contact forms, newsletter registration, account or client-portal functions, testimonials, project enquiries, support communication and the standard SaaS products offered through the Rent Projects area.

It also explains the distinction between situations in which MT Digital Studio determines why and how personal data is processed and situations in which we process personal data only on documented instructions from a business client. That distinction matters because the GDPR assigns different obligations to a controller and to a processor.

Separate contractual privacy terms, a data processing agreement under Article 28 GDPR, a project-specific security appendix or a product-specific privacy notice may supplement this policy where the nature of a service requires more detailed rules.

02

Controller and contact details

For processing connected with this website, our own marketing, enquiries, contracts and account administration, the controller is the legal operator of MT Digital Studio.

Legal entityMT Digital Studio — legal operator: Coming soon
Registered addressRegistered business address: Coming soon
General and privacy enquiriescontact@mt-digitalstudio.comNewsletter mattersnewsletter@mt-digitalstudio.com
TelephoneComing soon

If a data protection officer is legally required or voluntarily appointed in the future, the officer’s contact details will be published here. Until then, privacy requests can be sent to the general contact address above with the subject “Privacy / Datenschutz”.

03

What personal data we may process

The exact categories depend on how you use the website and which service you request. We do not collect every category from every visitor.

  • Identity and contact data: name, business name, job role, email address, telephone number and other contact details you provide.
  • Enquiry and communication data: message content, project requirements, attachments, support questions, correspondence history and preferred contact method.
  • Newsletter data: email address, language preference, consent timestamp, confirmation status, confirmation token metadata and unsubscribe status.
  • Account and portal data: account identifier, login email, authentication information, role/permission data, support tickets and account activity where these functions are enabled.
  • Contract and project data: quotations, scope information, project contacts, technical requirements, billing references, delivery records and communications necessary to perform a contract.
  • Technical and usage data: IP address, request timestamp, URL/path requested, browser or user-agent information, referrer information where provided, error/security events and device-related technical information contained in normal server logs.
  • Preference data stored in the browser: language, theme, cookie-consent choice and other settings required to remember choices you explicitly make.
  • Review data: rating, review text, selected service, account identity and publication metadata when a logged-in user submits a testimonial.
  • SaaS/service data: user profiles, business records and operational content entered into a rented application or custom system, subject to the contractual role allocation described below.
04

Purposes and legal bases under Article 6 GDPR

We process personal data only where a legal basis applies. The relevant basis depends on the purpose, the relationship with you and the service involved.

PurposeTypical legal basisWhy it is needed
Answering project or service enquiriesArt. 6(1)(b) GDPR for pre-contractual steps; Art. 6(1)(f) GDPR where the enquiry is not contract-relatedTo understand the request, respond, prepare a quotation and organise follow-up communication.
Performing contracts and delivering servicesArt. 6(1)(b) GDPRTo build, configure, host, support or maintain the agreed website, application, automation or SaaS service.
Newsletter subscriptionArt. 6(1)(a) GDPRTo send marketing/newsletter emails only after consent and, where implemented, double opt-in confirmation.
Security, abuse prevention and reliable operationArt. 6(1)(f) GDPRTo detect attacks, troubleshoot errors, prevent misuse and keep services technically available.
Accounting, invoicing and statutory retentionArt. 6(1)(c) GDPRTo comply with German commercial and tax-law documentation and retention obligations.
Optional analytics or marketing technologiesArt. 6(1)(a) GDPR together with the consent requirements applicable to terminal-equipment accessTo measure or market only where the user has actively allowed the relevant optional category.
05

Website access, server logs and technical delivery

When a browser requests a page, the hosting infrastructure necessarily receives technical information required to deliver the website. Depending on the server configuration, this may include the IP address, date and time, requested resource, response status, transferred data volume, referrer, browser/user-agent and security-related events.

These data are used to deliver content, diagnose technical faults, defend against attacks, investigate abuse and maintain the confidentiality, integrity and availability of the website. The legal basis is generally Article 6(1)(f) GDPR, based on our legitimate interest in secure and reliable operation.

Server-log retention is limited according to operational and security needs and the configuration of the hosting environment. Retention periods are kept proportionate to those purposes and are reviewed when infrastructure or security requirements change.

06

Contact forms, email enquiries and auto-replies

If you contact us through the website, we process the data you enter — currently name, email address, optional telephone number, requested service category, preferred reply method and message — so that we can receive, assess and answer the enquiry.

The contact form may generate an automatic acknowledgement from no-reply@mt-digitalstudio.com. That confirmation exists only to tell you that the request reached our system; it is not a marketing subscription and it does not change the legal basis for the underlying enquiry.

For enquiries aimed at entering into a contract, the primary legal basis is Article 6(1)(b) GDPR. For general business communication that is not pre-contractual, processing may rely on Article 6(1)(f) GDPR. If an enquiry becomes part of a contractual or legally relevant business record, statutory retention obligations may apply.

07

Newsletter and double opt-in

Newsletter messages are sent only to people who actively request them. The current implementation is designed around a separate newsletter consent and a double opt-in process: after submitting an email address, the recipient receives a confirmation link and is added to the active mailing list only after that link is used.

For evidence of consent, we may store the email address, requested language, date/time of registration and confirmation, technical confirmation metadata and the consent version. The legal basis for the newsletter itself is Article 6(1)(a) GDPR. Evidence required to demonstrate valid consent may additionally be retained on the basis of Article 6(1)(c) or Article 6(1)(f) GDPR where necessary to establish compliance or defend legal claims.

You may unsubscribe at any time using the unsubscribe function in the email or by contacting newsletter@mt-digitalstudio.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. We do not interpret acceptance of website cookies as newsletter consent; these are separate choices.

08

Accounts, client portal and testimonials

Where account or client-portal functions are enabled, we process the information necessary to create and maintain the account, verify access, assign permissions, deliver support and document account activity relevant to security or contract performance. Production authentication must use appropriate server-side controls; browser-only demonstration sessions are not treated as a production security model.

If an authenticated user submits a testimonial or review, the rating, review text, selected service and account identity may be processed for moderation and publication. We may refuse, edit only with permission, or remove reviews where necessary for legal compliance, confidentiality, security, relevance or abuse prevention.

The legal basis is Article 6(1)(b) GDPR where the account is needed for a contract, Article 6(1)(f) GDPR for secure account administration and abuse prevention, and Article 6(1)(a) GDPR where publication of optional personal profile details requires consent.

09

Client projects, custom development and our GDPR role

During consulting, web development, app development, automation, integration or support work, we may receive business contact data and technical information from the client. Where we decide the purposes and essential means of processing for our own contract administration, invoicing, project communication or legal compliance, MT Digital Studio acts as controller.

Where a client gives us access to personal data contained in the client’s CRM, HR system, database, website, support system, files or application solely so that we can build, migrate, host, maintain or troubleshoot a service on the client’s documented instructions, the client will normally remain controller and MT Digital Studio may act as processor within the meaning of Article 28 GDPR.

Where required, the parties should enter into an appropriate data processing agreement before such production data is made available. The agreement should define subject matter, duration, categories of data and data subjects, instructions, confidentiality, security, subprocessors, assistance with data-subject rights, deletion/return and audit obligations.

10

Rented applications and business data

For standard rented products such as CRM, employee-management or inventory systems, the customer generally determines which employee, customer, supplier or operational data is entered and why it is used. For that product content, the business customer will normally be the controller and MT Digital Studio will process the data to provide, host, secure, maintain and support the application according to contract.

The exact role, hosting environment, retention, backup rules, user management, exports, deletion at termination and any subprocessors should be documented in the applicable SaaS agreement and, where necessary, a data processing agreement. Customers remain responsible for ensuring that they have a lawful basis for the personal data they enter into the system and for configuring user access appropriately.

11

Cookies, local storage and consent management

The website uses browser storage technologies to remember choices and provide requested functions. This includes the cookie-consent decision, theme preference and global language preference. Depending on enabled features, other necessary local-storage values may be used for account/session demonstrations or interface state.

Under Section 25 TDDDG, storing information on or accessing information from a user’s terminal equipment generally requires informed consent unless an exception applies, including where the storage/access is strictly necessary to provide a digital service expressly requested by the user. GDPR requirements apply in addition where the information is personal data.

Our consent interface separates necessary, preference, analytics and marketing categories. Optional categories remain disabled until the user allows them. After a choice is saved, the banner disappears and a fixed cookie icon in the lower-left corner allows the settings to be reopened and changed at any time.

Storage / categoryPurposeStatus
mt_cookie_consentStores the consent decision and category choices so the banner does not ask again on every page.Necessary consent record
mt_language / language cookieKeeps the selected EN/DE/RO language consistent across the site.Necessary/preference depending on implementation
mt_themeRemembers light or dark appearance selected by the user.Preference
Analytics / marketing technologiesMeasurement, campaign attribution or advertising functions if such tools are added.Disabled until consent

More detailed cookie information is available in the separate Cookie Policy and through the cookie-settings icon.

12

Hosting and infrastructure in Germany

The current hosting strategy uses ALL-INKL.COM infrastructure for website and related server services where technically appropriate. ALL-INKL.COM states that its data centres are located in Dresden, Germany, and that customer data is stored on servers in Germany.

Hosting necessarily involves processing technical connection data and, depending on the service, stored website, database or email content. Where the hosting provider processes personal data on our behalf, the relationship must be governed by the applicable processor terms / data processing agreement in accordance with Article 28 GDPR.

Server location alone does not replace security governance. We combine provider-level safeguards with application-level controls such as access restriction, secure configuration, updates, secret management, backup planning and minimisation of production access.

13

Recipients, service providers and subprocessors

We do not sell personal data. We also do not disclose personal data to unrelated third parties for their own advertising simply because you contacted us. Data may, however, be provided to service providers where this is necessary to operate the website, communicate, deliver a contract, secure systems or comply with law.

  • Hosting and infrastructure providers, currently including ALL-INKL.COM where used for the production environment.
  • Email infrastructure required to receive contact messages and send transactional or newsletter emails.
  • Professional advisers such as accountants, tax advisers, lawyers or auditors where necessary and legally permitted.
  • Technical subcontractors or specialists used for a specific client project, but only where contractually permitted and with appropriate confidentiality/data-protection arrangements.
  • Public authorities, courts or other legally authorised recipients where disclosure is required by applicable law or a binding order.

A production processor register should be maintained internally and this policy must be updated if material new processors or categories of recipients are introduced.

14

International transfers outside the EEA

Our core hosting strategy is intended to keep website infrastructure in Germany. Nevertheless, a third-country transfer can arise if a future integration, cloud service, communication tool, analytics product or project-specific provider processes personal data outside the European Economic Area or allows access from such a country.

Where such a transfer is necessary, we will use a lawful transfer mechanism under Chapter V GDPR, for example an adequacy decision under Article 45, appropriate safeguards such as Standard Contractual Clauses under Article 46, or another legally available mechanism. Where required, supplementary technical or organisational measures and transfer-risk assessments will be considered.

We will not describe a service as “EU-only” or “Germany-only” unless the actual technical and contractual configuration supports that statement.

15

How long we keep personal data

We do not keep all information for one universal period. Retention depends on purpose, contractual need, security requirements, legal claims and statutory obligations.

Data typeTypical retention logic
Unsuccessful/general enquiriesKept only as long as reasonably necessary to answer and follow up, then deleted or minimised unless a legal reason requires longer retention.
Contract/project communicationsRetained for the contract and an appropriate period afterwards where needed for warranty, claims, documentation or legal obligations.
Invoices and accounting recordsRetained for the statutory periods applicable under German tax/commercial law; certain accounting records and invoices are currently subject to eight-year retention periods, while other categories can be six or ten years.
Newsletter subscriptionUntil withdrawal/unsubscribe for active delivery; limited evidence of consent may be retained afterwards where necessary to demonstrate compliance or defend claims.
Account dataFor the active account and then according to contract, security and legal-retention needs; data not required afterwards should be deleted or anonymised.
Server/security logsFor the period necessary for operational security and troubleshooting according to the production configuration; longer only where a security incident or legal obligation requires it.
Client data processed as processorAccording to the client’s documented instructions, contract/DPA and agreed deletion or return process.

Deletion can be suspended where data must be preserved due to a statutory retention obligation, a legal hold, an ongoing dispute or the establishment, exercise or defence of legal claims. In those cases, processing is restricted to the relevant purpose where appropriate.

16

Your GDPR rights

Subject to the legal conditions and possible statutory limitations, you have the following rights in relation to your personal data.

Art. 15

Right of access

You can ask whether we process personal data about you and request the information and copy required by Article 15 GDPR.

Art. 16

Right to rectification

You can request correction of inaccurate personal data and completion of incomplete data where appropriate.

Art. 17

Right to erasure

You can request deletion where the legal conditions are met, including where data are no longer necessary or consent has been withdrawn and no other legal basis applies.

Art. 18

Right to restriction

You can request restriction of processing in the situations specified by Article 18 GDPR.

Art. 20

Right to data portability

For qualifying processing based on consent or contract and carried out by automated means, you can request data in a structured, commonly used and machine-readable format and, where technically feasible, transmission to another controller.

Art. 21

Right to object

You can object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f). Direct-marketing objections are treated separately and must be honoured.

Art. 7(3)

Withdrawal of consent

Where processing is based on consent, you can withdraw it at any time for the future without affecting prior lawful processing.

Art. 77

Right to complain

You may lodge a complaint with a competent data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.

To exercise a right, email contact@mt-digitalstudio.com and describe the request clearly. We may need information reasonably necessary to verify identity and prevent disclosure of data to an unauthorised person. GDPR requests are handled within the applicable statutory timeframe.

17

Objection to legitimate-interest processing and direct marketing

If processing is based on Article 6(1)(f) GDPR, you have the right under Article 21 GDPR to object on grounds relating to your particular situation. We will then stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for legal claims.

If personal data are processed for direct marketing, you may object at any time to processing for that purpose. Once such an objection is received, the data will no longer be processed for direct marketing. Newsletter unsubscribe mechanisms are intended to make this especially easy.

18

Technical and organisational security measures

Article 32 GDPR requires security appropriate to risk. No internet system can promise absolute security, but we design our systems so that personal data are not treated as an afterthought.

  • TLS/HTTPS for production web traffic and secure transport for supported email/server connections.
  • Access control based on least privilege and separation of administrative access from normal user access where appropriate.
  • Strong authentication and secure password handling for production systems; passwords must not be stored in plaintext.
  • Secrets such as SMTP passwords, API keys and application secrets kept outside publicly accessible source files wherever the hosting environment supports it.
  • Regular security updates, dependency maintenance and removal or disabling of unnecessary services.
  • Input validation, anti-spam controls, rate limiting and server-side authorisation for production forms and protected functions.
  • Backups and recovery procedures appropriate to the service, with access to backup data limited to authorised purposes.
  • Logging and incident investigation proportionate to the risk, while avoiding unnecessary logging of confidential content.
  • Confidentiality commitments and processor agreements where external personnel or service providers can access personal data.
  • Data minimisation in development and testing, including preference for synthetic or anonymised data instead of unnecessary copies of production personal data.

Security measures are reviewed and adapted as technology, services and risks change. If a personal-data breach occurs, we assess notification obligations under Articles 33 and 34 GDPR and document the incident appropriately.

19

Automated decision-making, AI and profiling

The public MT Digital Studio website does not currently use solely automated decision-making that produces legal effects or similarly significant effects on visitors within the meaning of Article 22 GDPR.

If an AI, scoring, recommendation or automation feature is introduced that materially affects individuals, the applicable contract and privacy information must explain the role of automation, relevant logic, safeguards and any right to obtain human intervention where required. We do not treat the generic use of automation as permission to make high-impact decisions about people without an appropriate legal and governance framework.

20

Children and sensitive data

Our website and B2B services are directed primarily at businesses and professional users, not at children. We do not intentionally request children’s personal data through general project or newsletter forms.

Special-category data under Article 9 GDPR — for example health, biometric, religious or trade-union data — should not be sent through ordinary contact channels. If a client project genuinely requires processing of such data, it must be assessed separately and protected under a suitable legal basis, contract and security model before production processing begins.

21

Changes to this Privacy Policy and how to contact us

We may update this Privacy Policy when the website, services, processors, legal requirements or technical architecture change. The date shown at the top indicates the current version. Material changes should be reflected before or when the relevant new processing begins.

For privacy questions, data-subject requests or concerns about the handling of personal data, contact us at contact@mt-digitalstudio.com. Newsletter-specific unsubscribe or subscription questions can also be sent to newsletter@mt-digitalstudio.com.

We would rather answer a precise privacy question clearly than hide behind vague language. If something in this policy does not match the way a specific MT Digital Studio service is being used, ask us before sending sensitive or production data.