2.0 • Last updated: 13 July 2026
Lorik Sadiku (Sole Proprietorship)
Am Leonhardspark 3
90439 Nürnberg
Germany
Tel.: +49 176 262 208 30
E-Mail: datenschutz@mhdapp.com
Handelsregister: Not registered (§ 2 HGB – Small business)
USt-IdNr.: DE368866029
Not applicable – the Controller is established in Germany.
No formal Data-Protection Officer is required. Nevertheless, we have designated an internal contact point: Data protection contact – datenschutz@mhdapp.com | +49 176 262 208 30 A written assessment documenting why Art. 37 (1) GDPR / § 38 BDSG do not apply is on file and reviewed yearly.
| Category | Description |
|---|---|
| Account Data | Name, e-mail, password hash, avatar colour |
| Subscription & Payment Data | Stripe customer, subscription and invoice IDs and the subscription status. Card data is processed solely by Stripe; we neither collect nor store it. |
| Usage Data | IP address and browser user-agent (server logs), selected language, login timestamps. We do not analyse your usage behaviour. |
| Log & Error Data | Request ID, error trace, rate-limit identifier |
| Content Data | Inventory items, product details you create |
| Communications | Support tickets, in-app messages, e-mails |
| Cookie / Device IDs | Session token, CSRF token, cookie-consent ID |
We use exclusively technically necessary cookies and necessary storage on your device (§ 25(2) no. 2 TDDDG): for secure login, CSRF protection, the interface language and colour scheme you select, and to record your cookie decision. We use no analytics, statistics or marketing cookies and embed no third-party tracking. The legal basis for the subsequent processing is Art. 6(1)(b) and (f) GDPR (provision of the requested service, IT security). We record your cookie decision server-side with a truncated IP address, browser identifier, timestamp and the selected categories (Art. 7(1) GDPR).
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
| __Secure-next-auth.session-token | Authentication (login session) | 30 days | necessary |
| __Host-next-auth.csrf-token | CSRF protection | Session | necessary |
| __Secure-next-auth.callback-url | Redirect after login | Session | necessary |
| NEXT_LOCALE | Interface language | 1 year | necessary |
| cookieConsent (localStorage) | Stores whether you have made a cookie decision | Until you delete it | necessary |
| cookiePreferences (localStorage) | Stores your selected cookie preferences | Until you delete it | necessary |
| theme (localStorage) | Selected colour scheme (light/dark) | Until you delete it | necessary |
| consentSessionId / consentLogs (localStorage) | Proof of your cookie decision (Art. 7(1) GDPR) | Until you delete it | necessary |
| accountState_<user ID> (localStorage) | Remembers your most recently used workspace after login | Until you delete it | necessary |
| Recipient | Purpose | Location | Legal Basis |
|---|---|---|---|
| Hetzner Online GmbH | Hosting & PostgreSQL database | Germany | DPA (Art. 28 GDPR) |
| Stripe Payments Europe, Ltd. | Payment processing & invoicing | Ireland (EU); intra-group transfer to the USA possible | DPA (Art. 28) + EU-US Data Privacy Framework / SCCs |
| Brevo SAS (formerly Sendinblue) | Transactional email delivery (registration, invitations, reminders) | France (EU) – no third-country transfer | DPA (Art. 28 GDPR) |
| Open Food Facts (incl. Open Products Facts, Open Beauty Facts, Open Pet Food Facts) | Barcode lookup of product data (only barcodes are transmitted, no personal data) | France (EU) | Contract Art. 6 (1)(b) |
| Mistral AI SAS | Optional AI reading of photographed product labels (name, quantity, best-before date) when a barcode is not found. The photo is not stored and not used for AI training | France (EU) – no third-country transfer | DPA (Art. 28 GDPR) |
We never sell personal data. Standard Contractual Clauses are kept on file as a contingency should a recipient leave the DPF.
If you use MHD App for business purposes, we process personal data — such as your employees’ accounts — on your behalf. Art. 28 GDPR requires a contract between you and us for this. You conclude it during registration; the acceptance is recorded with a timestamp and the version. No signature is required (Art. 28(9) GDPR).
View the Data Processing Agreement| Data Category | Retention Period |
|---|---|
| User account & content | Until account deletion; at most a further 14 days in encrypted backups |
| Payment & invoice records | 10 years |
| Server security logs | 7 days |
| Support requests & routine e-mails | 3 years |
| Contract-relevant e-mails (e.g. termination) | 10 years |
| Consent records (cookie consent) | 3 years |
Backups are stored AES-256 encrypted at Hetzner (Germany) and automatically deleted after 14 days.
You can exercise at any time and free of charge: Access, Rectification, Erasure, Restriction, Portability, Objection to legitimate-interest processing, Withdrawal of consent. We respond within one month (Art. 12 (3) GDPR). Identification may be required. Contact: datenschutz@mhdapp.com. Obligation to provide data: Fields marked "required" in our forms are contractually necessary. Without them we cannot open or maintain your account; all other fields are optional.
2.0 • Last updated: 13 July 2026