Privacy

Controller

Responsible for data processing on MIDIpad:
Stephen Mitchell
c/o flexdienst – #21659
Kurt-Schumacher-Straße 76
67663 Kaiserslautern
Germany
E-Mail: contact@stevemitchell.music

Hosting and server logs

This site is hosted on servers operated by Hetzner Online GmbH in Germany. When you visit, the web server processes your IP address, user agent, and request timestamps in server logs for operating and securing the service (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Logs are retained for 7 days. DNS for this domain is provided by Cloudflare, Inc., which also stores and serves the application downloads.

Contact form and email

If you use the contact form, I process the details you provide (name, email address, message) to answer your enquiry (legal basis: Art. 6(1)(b) or (f) GDPR). Messages are stored on my own server, and are retained for 12 months. If you email me instead, my mail provider is Proton AG (Switzerland).

Purchases

Purchases are processed by Polar Software Inc. as merchant of record. Polar is the contractual seller and processes your name, email address, and payment details in that role, under its own privacy policy: polar.sh/legal/privacy.

The licence itself is issued by me, not Polar. When Polar confirms your order, my licensing service creates your licence key and stores it together with your email address and the order reference (legal basis: performance of a contract, Art. 6(1)(b) GDPR). The key is emailed to you via Postmark (ActiveCampaign, LLC). I keep this purchase record for as long as your licence is active, so I can verify your licence and resend your key if you lose it. If a purchase is refunded, the key is revoked and the record is deleted ninety days after the refund. You can ask me to remove the email address from your purchase record at any time; your licence keeps working, but I can then no longer resend the key by email.

The MIDIpad application

MIDIpad runs on your own computer and does not send me your musical input or what you play. Nothing leaves your machine except what is described here:

Licence activation. When you activate a licence key, the app sends three things to my licensing service (legal basis: performance of a contract, Art. 6(1)(b) GDPR):

  • The licence key itself.
  • A label for the machine: its model, and a short code the app makes up at random the first time you activate. It is there so you can tell your activations apart when you come to free one up. Your computer's own name is not sent.
  • A machine tag: a one-way hash of your Mac's hardware identifier, salted so it cannot be matched against any other product. I receive only the hash and cannot recover the identifier from it. It exists so that a licence stays tied to the machines you activated it on.

Your IP address is visible to the service in the process. The key, the machine tag and that label are recorded by my licensing service against your licence. Afterwards the app verifies the licence on your own machine and works fully offline.

Update checks. The app asks my update server whether a newer version exists, which involves your IP address and the version you are running (legal basis: legitimate interest in shipping fixes, Art. 6(1)(f) GDPR). Updates and downloads are served from storage operated by Cloudflare, Inc., so those requests reach their servers rather than mine.

Sending feedback. The app has a feedback form. Nothing is sent until you press Send; when you do, what you wrote goes to my own server in Germany — the same database that holds the site's contact messages (legal basis: Art. 6(1)(b) or (f) GDPR). An email address goes with it only if you typed one in, and is used only to answer you. The form's "Include diagnostics" switch attaches a snapshot of the app's state: its version, your operating system version, the connected controllers, the state of the MIDI outputs, your licence tier (never the licence key), and the instrument's current key, settings and recent log lines. Log lines can incidentally include file paths which on some systems contain your username. Your IP address is visible in the process, is used to rate-limit submissions, and falls under the same short-lived server logs described above. Feedback is retained for 12 months.

Usage data. By default MIDIpad sends my own server anonymised data of how it is used in order to help me improve the app, comprising of operating system name and version number, whether the app is running in Demo Mode or not, game controller make and model, and key settings. It does not send any game controller input or MIDI output data, nor any account, device or license identifier. A random session number groups one run's events and is forgotten after an hour, and your IP address is reduced to a country before it is dropped (legal basis: my legitimate interest in improving the app, Art. 6(1)(f) GDPR).

Newsletter

You can ask to hear from me by email about new releases, new instruments and betas. I use it a few times a year at most (legal basis: your consent, Art. 6(1)(a) GDPR). The mailing list runs on my own server in Germany and the emails themselves are delivered by Postmark.

What I keep. Your email address, the date you signed up, which page you signed up from, and which version of the wording above you agreed to. That last pair is my record that you asked for this, which Art. 7(1) GDPR requires me to be able to show. I do not store your IP address, I do not record whether you open anything or click anything, there are no tracking pixels in the emails, and I build no profile of you.

Leaving. Every email has an unsubscribe link at the bottom. This deletes your address outright rather than marking it inactive. You can also withdraw consent by emailing me, with effect for the future.

Analytics

I use Umami for website analytics, which I host myself. It is cookieless, does no cross-site tracking, builds no profiles, and does not store IP addresses (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Because nothing is stored on or read from your device, no consent banner is required under § 25 TDDDG. No data is shared with any third party.

Cookies

There are no tracking, profiling or advertising cookies on this site, and nothing here is shared with an advertising network or any other third parties.

Your rights

Under the General Data Protection Regulation you have the rights:

  • To access the personal data I hold about you (Art. 15 GDPR)
  • To rectify inaccurate data (Art. 16 GDPR)
  • To request deletion of your data (Art. 17 GDPR)
  • To restrict processing (Art. 18 GDPR)
  • To data portability (Art. 20 GDPR)
  • To object to processing (Art. 21 GDPR)
  • To lodge a complaint with a supervisory authority (Art. 77 GDPR)

The supervisory authority for this site is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Recipients and processors

Processors under Art. 28 GDPR: Hetzner Online GmbH (hosting), Cloudflare, Inc. (DNS, and delivery of application downloads), Proton AG (email), and flexdienst (Matthias Dully, Kaiserslautern), together with ActiveCampaign, LLC (Postmark), which delivers licence key emails and the mailing list. Licence and activation data is processed on my own licensing service, hosted at Hetzner.

Polar Software Inc. is additionally the merchant of record for the sale itself. In that role it is the seller and a controller in its own right rather than acting on my instructions, and its own privacy policy governs what it does with your purchase.

Transfers outside the EU

Proton AG is in Switzerland, which the European Commission has recognised as providing an adequate level of protection, so no further safeguard is required.

Cloudflare, Inc., Polar Software Inc. and ActiveCampaign, LLC (Postmark) are in the United States, so data does leave the EU. These transfers are covered by the European Commission's Standard Contractual Clauses (Decision 2021/914/EU), incorporated into their respective data processing terms. Cloudflare additionally certifies under the EU–US Data Privacy Framework.