Legal

VibeMS Privacy Policy

1. Controller

The controller for the VibeMS website, business account portal, licensing and product support is:

Robin Ringl, trading as rZWEI media
Product brand: VibeMS
Berliner Str. 7
63533 Mainhausen
Germany

Email: privacy@vibems.io

2. Scope

This policy explains processing through vibems.io, the VibeMS account and licence portal at licenses.vibems.io, product downloads, licence activation, update delivery and support. Customer-hosted VibeMS websites are controlled by the respective Customer, not by VibeMS, unless a separate service agreement says otherwise.

3. Data processed

Depending on how the services are used, we process:

  • business contact name, company, business email, telephone and locale;
  • account credentials in hashed form, email verification, multi-factor settings, recovery and security events;
  • accepted legal-document versions and timestamps;
  • Paddle customer, transaction, subscription and adjustment identifiers, purchased plan and transaction status;
  • licence number, encrypted licence key, plan, entitlement dates and status;
  • installation identifier, normalized domain, environment type, CMS version and activation timestamps;
  • release entitlement, requested downloads and security-protected download records;
  • support messages and information voluntarily provided with them;
  • server and security logs such as timestamp, requested resource, response status, browser information and IP address or a keyed IP hash where a full address is not needed.

We do not receive card details through the VibeMS systems. Paddle processes payment details in its checkout.

4. Purposes and legal bases

We process data for the following purposes:

  • Website delivery and security: to deliver pages, prevent abuse and diagnose faults, based on our legitimate interests in a secure and reliable service (Article 6(1)(f) GDPR).
  • Accounts, licences and support: to register business accounts, issue licences, activate installations, deliver updates and provide support, for contract performance and pre-contract steps (Article 6(1)(b) GDPR).
  • Billing synchronization and records: to reconcile Paddle transactions, subscriptions, refunds and entitlements and meet tax, accounting and commercial record duties (Articles 6(1)(b) and 6(1)(c) GDPR).
  • Fraud prevention and audit: to protect customers, licence infrastructure and legal claims, based on legitimate interests (Article 6(1)(f) GDPR).
  • Optional communications: where we request consent for marketing or non-essential technologies, based on consent (Article 6(1)(a) GDPR). Consent may be withdrawn for the future at any time.

Where information relates to representatives or employees of a business Customer rather than the contracting individual, our legitimate interests also include communicating with and performing the contract for that business.

5. Local website content

VibeMS is self-hosted. Ordinary licensing and updates do not upload Customer website pages, CMS users, form submissions, media libraries, local backups, SMTP passwords, MCP tokens or imported source files to the VibeMS Control Center.

The installed CMS sends only information needed for licensing and release access, such as licence credential, installation identifier, normalized domain, environment type and CMS version. Customers remain responsible for privacy compliance on websites they host and edit with VibeMS.

6. Paddle

Paddle acts as authorised reseller and Merchant of Record for purchases. Depending on buyer location, the relevant Paddle entity independently processes checkout, payment methods, invoices, tax details, fraud signals, subscriptions, refunds and buyer support under Paddle's own privacy notice.

VibeMS receives transaction and customer identifiers and status information needed to fulfil the product and administer the licence. Payment-card details are not sent to VibeMS. Paddle may process data in the United Kingdom, United States, Canada and other locations using the safeguards described in its privacy documentation.

Paddle privacy notice: https://www.paddle.com/legal/privacy

7. Hosting and service providers

The website and Control Center are hosted in Germany by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The host processes server and availability data on our instructions under a data-processing arrangement.

Transactional email infrastructure and security or maintenance providers may process the minimum information needed to deliver messages or protect the service. We select providers under appropriate contractual and confidentiality obligations. A current list of material processors can be requested from privacy@vibems.io.

External services embedded by a Customer into a Customer-hosted VibeMS website are not VibeMS Control Center processors and must be disclosed by that Customer.

8. Cookies and similar technologies

The public website and account portal use technically necessary cookies or browser storage for secure sessions, CSRF protection, authentication, language or interface preferences and fraud prevention. Details appear in the Cookie Policy.

We use self-hosted, anonymised visitor analytics to understand aggregate website usage. This analytics does not use cookies, does not collect personal data, does not create individual visitor profiles and is not used for advertising. We do not activate any other non-essential analytics, advertising or embedded third-party media without any legally required consent.

9. Recipients and disclosure

Data is accessible only to persons and providers who need it for the stated purposes. We may disclose data to professional advisers, courts, authorities or law-enforcement bodies where legally required or necessary to establish, exercise or defend legal claims. We do not sell personal data.

10. International transfers

Where data is processed outside the European Economic Area, we use an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism as applicable. Paddle determines safeguards for data it processes independently as Merchant of Record.

11. Retention

We retain data only as long as needed for the relevant purpose:

  • account, licence and activation data while the account or licence is active and afterwards for contractual proof and limitation periods;
  • transaction, invoice-related and legal-acceptance data for applicable commercial, tax and accounting retention periods, typically six to ten years depending on the record;
  • processed webhook payloads in identifiable detail only for the operational period, after which payload content is minimized or redacted where possible;
  • download IP hashes and comparable security metadata for a limited fraud-prevention period;
  • support correspondence for the duration of the request and applicable legal-claim periods;
  • consent records for as long as needed to demonstrate compliance.

Data subject to a legal hold, fraud investigation or active dispute may be retained longer. Backups are overwritten according to the backup cycle and are used only for recovery and security.

12. Security

We use HTTPS, access controls, password hashing, multi-factor authentication for privileged access, encrypted sensitive fields, private signing keys, signed licence certificates and releases, audit logs, data minimization and backups. No internet service can guarantee absolute security. Please report suspected vulnerabilities through the process on the Security page.

13. Rights

Subject to applicable conditions, individuals have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn for the future. An objection to processing based on legitimate interests may be sent with reasons relating to the individual's situation.

Some records cannot be erased immediately where retention is legally required or needed to establish or defend claims. Requests should be sent to privacy@vibems.io. We may request proportionate verification before responding.

Individuals may lodge a complaint with a data-protection supervisory authority. The authority responsible for our establishment is:

The Hessian Commissioner for Data Protection and Freedom of Information
P.O. Box 3163
65021 Wiesbaden, Germany
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de/

14. Automated decisions

Paddle may use automated fraud and risk controls for transactions under its own policies. VibeMS does not use account or licence data for automated decisions producing legal or similarly significant effects independently of the Paddle transaction and documented licence rules.

15. Changes

We update this policy when services, providers or legal requirements change. Material changes are versioned and communicated through the website, account or business email where required.