DEEN

Privacy notice

The short version first: this site sets no cookies, embeds nothing from third parties and measures nothing. It asks for no data – there is no form, no sign-up, no newsletter. What remains is what every web server records while delivering a page.

This is a courtesy translation. The legally binding version is the German privacy notice. Where the two differ, the German wording applies.

Controller

Sven Melchior
Waldstr. 2c
85521 Ottobrunn
Germany
Email: kontakt@nupplo.com

What is processed when you open this site

Technically necessary data is processed on retrieval: IP address, time, the address requested, the volume of data transferred, browser type and operating system. Without these details a page cannot be delivered. The legal basis is Art. 6(1)(f) GDPR – the legitimate interest in secure and error-free operation.

Hosting

This site is operated with Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. The server logs named above are processed there, which involves a transfer to the USA. The basis for this is the European Commission’s standard contractual clauses together with a data processing agreement.

Email to us

Mail to kontakt@nupplo.com is forwarded to a private mailbox through Cloudflare Email Routing. In doing so, Cloudflare processes the sender, recipient, subject and content of the message for delivery. Your message and your address are used only to answer you and are not passed on. The legal basis is Art. 6(1)(f) GDPR.

No cookies, no measurement

This site sets no cookies and uses no analytics services, no tracking and no counting pixels. That is also why there is no consent banner – there is nothing to consent to.

No third-party content

The typeface, the images and the stylesheet are served from the same server. In particular, no Google Fonts, no libraries from foreign networks and no embedded videos are loaded. Opening this site therefore establishes no connection to third parties.

The site does link to external offerings: GitHub, Docker Hub, melle79.dev and – at the coffee button in the footer – buymeacoffee.com. These are only called up when you click a link; the respective provider’s privacy terms then apply. Whether anyone gives anything there, and who, is not something this site learns.

The software itself

Nupplo is run by each person themselves. Whoever installs it processes collection, lists and user accounts on their own server – I receive none of it, and the app itself needs no account with me. For those installations I am not the controller within the meaning of the GDPR; that is whoever operates them.

There are two exceptions. Both are voluntary, and in both cases data goes to a service I run (a “hub”, also at Cloudflare, see above). For that data I am the controller.

The trading network

Whoever connects their installation to the trading network – which is only possible with an invitation – sends the hub:

This is visible to the other members of the network as far as it is meant for them (offers, profile, shown wishes), and to me as the administrator. The legal basis is Art. 6(1)(b) GDPR – taking part in the network, which you asked for.

If you haven't been around for a while, the hub hides your offers and wishes until you come back. If you leave, your offers, wishes and profile are deleted at once. What remains is the display name and the key data of conversations, so the other side keeps its history and the administration can see that you left. On request to the address above I delete that too.

Crash reports

If the app crashes in the browser, it offers to send a report to the hub – only if the operator of the installation has a key from me for it, and only at the explicit press of a button. You see word for word what goes out beforehand: times, memory use, how many pictures were loaded, which views were open last and what happened last (such as a scan with the recognised catalogue number), plus the app version and device type. I collect the reports, after which they are deleted from the hub, and evaluate them on my own hardware to fix bugs. The legal basis is Art. 6(1)(f) GDPR.

Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may also lodge a complaint with a supervisory authority; for Bavaria this is the Bayerisches Landesamt für Datenschutzaufsicht (Bavarian Data Protection Authority).

Status

September 2026.