Privacy

Controller

Responsible for data processing on MIDIpad:
Stephen Mitchell
c/o flexdienst – #21659
Kurt-Schumacher-Straße 76
67663 Kaiserslautern
Germany
E-Mail: contact@stevemitchell.music

Hosting and server logs

This site is hosted on servers operated by Hetzner Online GmbH in Germany. When you visit, the web server processes your IP address, user agent, and request timestamps in server logs for operating and securing the service (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Logs are retained for 7 days. DNS for this domain is provided by Cloudflare, Inc., which also stores and serves the application downloads.

Anything you send us is stored in a single database on that server. It is backed up daily to Cloudflare R2, encrypted before it leaves our server with a key we do not share with them, so the backups are unreadable to whoever stores them. Backups are kept for 30 days and then deleted.

Contact form and email

If you use the contact form, we process the details you provide (name, email address, message) to answer your enquiry (legal basis: Art. 6(1)(b) or (f) GDPR). Messages are stored on our own server at Hetzner rather than passed to a third-party helpdesk, and are retained for 12 months. If you email us instead, our mail provider is Proton AG (Switzerland).

Purchases

Purchases are processed by Polar Software Inc. as merchant of record. Polar is the contractual seller and processes your name, email address, and payment details in that role, under its own privacy policy: polar.sh/legal/privacy.

Licence provisioning is ours. When Polar confirms your order, our licensing service creates your licence key and stores it together with your email address and the order reference (legal basis: performance of a contract, Art. 6(1)(b) GDPR). The key is emailed to you via Postmark (ActiveCampaign, LLC). We keep this purchase record for as long as your licence is active, so we can verify your licence and resend your key if you lose it. If a purchase is refunded, the key is revoked and the record is deleted ninety days after the refund. You can ask us to remove the email address from your purchase record at any time; your licence keeps working, but we can then no longer resend the key by email.

The MIDIpad application

MIDIpad runs on your own computer and does not send us your musical input or what you play. Nothing leaves your machine except what is described here:

Licence activation. When you activate a licence key, the app sends three things to our licensing service (legal basis: performance of a contract, Art. 6(1)(b) GDPR):

  • The licence key itself.
  • A label for the machine: its model, and a short code the app makes up at random the first time you activate. It is there so you can tell your activations apart when you come to free one up. Your computer's own name is not sent.
  • A machine tag: a one-way hash of your Mac's hardware identifier, salted so it cannot be matched against any other product. We receive only the hash and cannot recover the identifier from it. It exists so that a licence stays tied to the machines you activated it on.

Your IP address is visible to the service in the process. The key, the machine tag and that label are recorded by our licensing service against your licence. Afterwards the app verifies the licence on your own machine and works fully offline.

Update checks. The app asks our update server whether a newer version exists, which involves your IP address and the version you are running (legal basis: legitimate interest in shipping fixes, Art. 6(1)(f) GDPR). Updates and downloads are served from storage operated by Cloudflare, Inc., so those requests reach their servers rather than ours.

Sending feedback. The app has a feedback form. Nothing is sent until you press Send; when you do, what you wrote goes to our own server in Germany — the same database that holds the site's contact messages (legal basis: Art. 6(1)(b) or (f) GDPR). An email address goes with it only if you typed one in, and is used only to answer you. The form's "Include diagnostics" switch — on by default, and yours to turn off before sending — attaches a snapshot of the app's state: its version, your operating system version, the connected controllers, the state of the MIDI outputs, your licence tier (never the licence key), and the instrument's current key, settings and recent log lines. Log lines can incidentally include file paths — an imported drum sample's, for instance — which on some systems contain your username. Your IP address is visible in the process, is used to rate-limit submissions, and falls under the same short-lived server logs described above. Feedback is retained for 12 months.

Beyond what is described here, MIDIpad contains no analytics and no crash reporting. If that changes, it will be opt-in and described here first.

Newsletter

You can ask to hear from us by email about new releases, new instruments and betas. We use it a few times a year at most (legal basis: your consent, Art. 6(1)(a) GDPR). The mailing list runs on our own server in Germany — the same one that holds the messages described above — and the emails themselves are delivered by Postmark.

Signing up takes two steps. When you enter your address we send one email asking you to confirm it, and nothing else is ever sent until you press the button in that email. This is partly the German norm and partly practical: anyone can type someone else's address into a form, and the second step means only the person who owns the mailbox can put it on the list. If you never confirm, the address is deleted after seven days.

What we keep. Your email address, the date you signed up, which page you signed up from, and which version of the wording above you agreed to. That last pair is our record that you asked for this, which Art. 7(1) GDPR requires us to be able to show. We do not store your IP address, we do not record whether you open anything or click anything, there are no tracking pixels in the emails, and we build no profile of you.

Leaving. Every email has an unsubscribe link at the bottom, and your mail app's own unsubscribe button works too. Using either deletes your address outright rather than marking it inactive — there is no suppression list with you on it afterwards. You can also withdraw consent by emailing us, with effect for the future.

Analytics

We use Umami, which we host ourselves on the same German infrastructure as this site. It is cookieless, does no cross-site tracking, builds no profiles, and does not store IP addresses — it records only aggregate counts of pages and a small number of named actions (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Because nothing is stored on or read from your device, no consent banner is required under § 25 TDDDG. No data is shared with any third party.

Cookies

There are no tracking, profiling or advertising cookies on this site, and nothing here is shared with an advertising network. The site does not use your browser's local storage. One thing can be stored on your device, only because it is needed to give you what you asked for, which is why § 25(2) TDDDG requires no consent banner for it.

If you have been given a preview link to parts of this site that are not public yet, following it sets a cookie that keeps you signed in to that preview for 30 days; it records nothing about you beyond the fact that the link was used.

Your rights

You have the right to access, rectification, erasure, restriction of processing, and data portability. Where processing rests on consent, you may withdraw it at any time with effect for the future.

You have the right to object. Where we process your data on the basis of our legitimate interests — server logs, and the aggregate analytics described above — you may object at any time on grounds relating to your particular situation, and we will stop unless we can show compelling legitimate grounds that override your interests. Email us and it is done.

Nothing here involves automated decision-making or profiling in the sense of Art. 22 GDPR. We build no profiles and make no decisions about you by machine.

You also have the right to lodge a complaint with a data protection supervisory authority — for us, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Recipients and processors

Processors under Art. 28 GDPR: Hetzner Online GmbH (hosting), Cloudflare, Inc. (DNS, and delivery of application downloads), Proton AG (email), and flexdienst (Matthias Dully, Kaiserslautern), which receives and forwards post sent to the address in our Impressum, together with ActiveCampaign, LLC (Postmark), which delivers licence key emails and the mailing list. Licence and activation data is processed on our own licensing service, hosted at Hetzner. Data processing agreements: all six are in place.

Polar Software Inc. is additionally the merchant of record for the sale itself. In that role it is the seller and a controller in its own right rather than acting on our instructions, and its own privacy policy governs what it does with your purchase.

Transfers outside the EU

Hetzner is in Germany, so its processing involves no transfer at all. Proton AG is in Switzerland, which the European Commission has recognised as providing an adequate level of protection, so no further safeguard is required.

Cloudflare, Inc., Polar Software Inc. and ActiveCampaign, LLC (Postmark) are in the United States, so data does leave the EU. These transfers are covered by the European Commission's Standard Contractual Clauses (Decision 2021/914/EU), incorporated into their respective data processing terms. Cloudflare additionally certifies under the EU–US Data Privacy Framework.