Privacy Policy
Note: This English version is a courtesy translation and does not replace legal advice; the German original is authoritative.
1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Melchinger Systemhaus UG (haftungsbeschränkt), Eisenbahnstraße 11, 71126 Gäufelden, Germany, app_cardcoaching@melchinger.org
For further details see the legal notice.
2. Principle: data minimisation
This landing page is built so that as little personal data as possible is generated when it is merely accessed. No cookies for analysis or marketing are set, no tracking or analytics services are embedded, and no external resources (e.g. web fonts, CDN scripts, embedded videos, social-media plugins) are loaded from third-party servers. All fonts, scripts and graphics are served from the same server as the page itself.
3. Server log files
When you access the page, the hosting provider processes technically necessary access data that your browser transmits automatically:
- shortened or full IP address
- date and time of access
- requested resource (URL)
- amount of data transferred and HTTP status code
- referrer URL (if transmitted)
- browser type and operating system (user agent)
This processing serves the delivery of the page, system security and error analysis. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure, stable operation). Logs are deleted on a rolling basis, generally after 14 days at the latest, unless a security-relevant event requires longer storage.
Hosting provider: Bieber IT (host-unlimited.de), servers located in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
4. Contact and request form
If you contact us by email or via the request form on this page ("Have your card table set up personally"), we process the details you provide (name, email address and, optionally, your message) to handle your enquiry. The form is transmitted exclusively to our own server (no third party) and delivered from there to us by email; for abuse prevention your IP address and the time are additionally processed. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual or contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in responding). The data is deleted once it is no longer required and no statutory retention obligations apply.
5. Use of the CardCoaching web app
The application itself (behind the login) processes additional data:
5.1 Coach account
Using the service as a coach requires registration. We process name, email address and a password. The password is stored exclusively as a cryptographic hash (scrypt), never in plain text. Legal basis: Art. 6 (1) (b) GDPR (performance of the usage contract).
5.2 Coachee participation without an account
Coachees need no account. They join via a signed invite link (seat token). No registration data is collected about the coachee.
5.3 Content and session data
Decks, cards, card images and almanac texts created by the coach, as well as the session history (which card was drawn when), are stored in a database (SQLite) on the server. Almanac texts are kept technically separate and delivered exclusively to the coach role; the coachee client cannot retrieve them. Legal basis: Art. 6 (1) (b) GDPR.
5.4 Technically necessary tokens
Signed tokens (HMAC-SHA256) are used for login and session participation and held in the browser (sessionStorage). These are strictly necessary for operation; no analysis of user behaviour takes place.
6. Disclosure to third parties
Personal data is only disclosed insofar as this is necessary to perform the contract (e.g. to the hosting provider as a processor) or where there is a legal obligation. Data is not sold.
7. Your rights
Subject to the statutory requirements, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and a right to object (Art. 21 GDPR). To exercise these, please contact the controller named above.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement.
8. Changes
We adjust this privacy policy as soon as the processing or the legal situation changes. The version published on this page at the time applies.
Last updated: 23 July 2026