Privacy Policy

Introduction

This notice explains how MHD App ("we", "our") processes your personal data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

2.0 • Last updated: 13 July 2026

Controller (Art. 4 No. 7 GDPR; § 5 DDG)

mhdapp

Lorik Sadiku (Sole Proprietorship)

Am Leonhardspark 3

90439 Nürnberg

Germany

Contact

Tel.: +49 176 262 208 30

E-Mail: datenschutz@mhdapp.com

Legal Information

Handelsregister: Not registered (§ 2 HGB – Small business)

USt-IdNr.: DE368866029

EU Representative (Art. 27 GDPR)

Not applicable – the Controller is established in Germany.

Privacy Contact (Art. 37 GDPR)

No formal Data-Protection Officer is required. Nevertheless, we have designated an internal contact point: Data protection contact – datenschutz@mhdapp.com | +49 176 262 208 30 A written assessment documenting why Art. 37 (1) GDPR / § 38 BDSG do not apply is on file and reviewed yearly.

Categories of Personal Data

CategoryDescription
Account DataName, e-mail, password hash, avatar colour
Subscription & Payment DataStripe customer, subscription and invoice IDs and the subscription status. Card data is processed solely by Stripe; we neither collect nor store it.
Usage DataIP address and browser user-agent (server logs), selected language, login timestamps. We do not analyse your usage behaviour.
Log & Error DataRequest ID, error trace, rate-limit identifier
Content DataInventory items, product details you create
CommunicationsSupport tickets, in-app messages, e-mails
Cookie / Device IDsSession token, CSRF token, cookie-consent ID

Purposes, Legal Bases & Balancing Test

  1. 1.Operate user account & app – Contract Art. 6 (1)(b)
  2. 2.Subscriptions, invoices, payments – Contract Art. 6 (1)(b); Legal obligation Art. 6 (1)(c) GDPR; §§ 257 HGB / 147 AO
  3. 3.Transactional messages – Contract Art. 6 (1)(b)
  4. 4.Expiry reminders and notifications about your own products by email – Performance of the contract, Art. 6 (1)(b) GDPR. These reminders are the core service, and are therefore enabled by default; you can switch them off at any time in your account settings. We send no marketing emails.
  5. 5.Barcode look-ups via Open Food Facts API – Contract Art. 6 (1)(b)
  6. 6.Fraud-prevention & IT-security – Legitimate interest Art. 6 (1)(f)

Cookies & Similar Technologies (§ 25 TDDDG)

We use exclusively technically necessary cookies and necessary storage on your device (§ 25(2) no. 2 TDDDG): for secure login, CSRF protection, the interface language and colour scheme you select, and to record your cookie decision. We use no analytics, statistics or marketing cookies and embed no third-party tracking. The legal basis for the subsequent processing is Art. 6(1)(b) and (f) GDPR (provision of the requested service, IT security). We record your cookie decision server-side with a truncated IP address, browser identifier, timestamp and the selected categories (Art. 7(1) GDPR).

Cookie NamePurposeDurationType
__Secure-next-auth.session-tokenAuthentication (login session)30 daysnecessary
__Host-next-auth.csrf-tokenCSRF protectionSessionnecessary
__Secure-next-auth.callback-urlRedirect after loginSessionnecessary
NEXT_LOCALEInterface language1 yearnecessary
cookieConsent (localStorage)Stores whether you have made a cookie decisionUntil you delete itnecessary
cookiePreferences (localStorage)Stores your selected cookie preferencesUntil you delete itnecessary
theme (localStorage)Selected colour scheme (light/dark)Until you delete itnecessary
consentSessionId / consentLogs (localStorage)Proof of your cookie decision (Art. 7(1) GDPR)Until you delete itnecessary
accountState_<user ID> (localStorage)Remembers your most recently used workspace after loginUntil you delete itnecessary

Recipients & International Transfers

RecipientPurposeLocationLegal Basis
Hetzner Online GmbHHosting & PostgreSQL databaseGermanyDPA (Art. 28 GDPR)
Stripe Payments Europe, Ltd.Payment processing & invoicingIreland (EU); intra-group transfer to the USA possibleDPA (Art. 28) + EU-US Data Privacy Framework / SCCs
Brevo SAS (formerly Sendinblue)Transactional email delivery (registration, invitations, reminders)France (EU) – no third-country transferDPA (Art. 28 GDPR)
Open Food Facts (incl. Open Products Facts, Open Beauty Facts, Open Pet Food Facts)Barcode lookup of product data (only barcodes are transmitted, no personal data)France (EU)Contract Art. 6 (1)(b)
Mistral AI SASOptional AI reading of photographed product labels (name, quantity, best-before date) when a barcode is not found. The photo is not stored and not used for AI trainingFrance (EU) – no third-country transferDPA (Art. 28 GDPR)

We never sell personal data. Standard Contractual Clauses are kept on file as a contingency should a recipient leave the DPF.

Data Processing Agreement (Art. 28 GDPR)

If you use MHD App for business purposes, we process personal data — such as your employees’ accounts — on your behalf. Art. 28 GDPR requires a contract between you and us for this. You conclude it during registration; the acceptance is recorded with a timestamp and the version. No signature is required (Art. 28(9) GDPR).

View the Data Processing Agreement

YouTube video (two-click solution)

On the "Awareness" page we embed a video. Simply opening the page establishes NO connection to Google. Only when you actively click the preview image is the video loaded via youtube-nocookie.com. Your IP address and device information are then transmitted to Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland); a transfer to the USA is possible, which Google bases on the EU-US Data Privacy Framework. The legal basis is your consent given by clicking (§ 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR). If you do not click the video, no transfer takes place.

Data Retention

Data CategoryRetention Period
User account & contentUntil account deletion; at most a further 14 days in encrypted backups
Payment & invoice records10 years
Server security logs7 days
Support requests & routine e-mails3 years
Contract-relevant e-mails (e.g. termination)10 years
Consent records (cookie consent)3 years

Backups are stored AES-256 encrypted at Hetzner (Germany) and automatically deleted after 14 days.

Security Measures (Art. 32 GDPR)

  • Encrypted transport: all connections exclusively over TLS/HTTPS
  • Passwords are never stored in plaintext, only as bcrypt hashes
  • AES-256 encrypted backups (daily, 14-day retention, restore tested)
  • Role-based access control per workplace (Owner, Admin, Editor, Viewer)
  • The database is reachable only locally and is not exposed to the internet
  • Hosting with Hetzner Online GmbH in Germany; Hetzner’s data centres are ISO/IEC 27001 certified (the provider itself holds no such certification)
  • Payment data is processed exclusively by Stripe (PCI-DSS Level 1) and never reaches our systems
  • Two-factor authentication is mandatory for the provider's admin access; it is not currently available for regular user accounts
  • The full technical and organisational measures, including the known limitations, are disclosed in Annex III of the Data Processing Agreement

Children's Data (Art. 8 GDPR)

MHD App is aimed at individuals 16 years or older. We do not knowingly process data of children; please notify us if you believe otherwise so we can delete it.

Automated Decision-Making / Profiling

We do not conduct automated decision-making that produces legal effects within the meaning of Art. 22 GDPR. Stripe Radar fraud checks may block a payment, but a manual review is always possible.

Your Rights (Art. 15 – 22 GDPR)

You can exercise at any time and free of charge: Access, Rectification, Erasure, Restriction, Portability, Objection to legitimate-interest processing, Withdrawal of consent. We respond within one month (Art. 12 (3) GDPR). Identification may be required. Contact: datenschutz@mhdapp.com. Obligation to provide data: Fields marked "required" in our forms are contractually necessary. Without them we cannot open or maintain your account; all other fields are optional.

Right to Lodge a Complaint (Art. 77 GDPR)

You may complain to any supervisory authority. Our lead authority is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de

Changes to This Privacy Policy

We may update this notice to reflect legal, technical or business developments. You will be informed at least 14 days in advance via an in-app banner and e-mail. Where a change affects consent-based processing we will request renewal of consent beforehand.

2.0 • Last updated: 13 July 2026