The German version of this privacy policy is binding; this English version is provided for convenience.
Privacy Policy
for the StreamMeet website and the customer center
In accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR), this privacy policy explains which personal data we, as the operator of StreamMeet, process under our own responsibility, for what purposes, on what legal basis and for how long, and what rights you have.
1. Controller and contact
The controller is:
Webvines / Christian Schmid
Hofgartenstraße 28a
86551 Aichach
Deutschland\
- Email: support@session.webvines.de
- Telephone: +49 8251 9048076
- Data protection contact: support@webvines.de
2. What this policy covers and what it does not
StreamMeet is a video platform for online meetings of businesses. We distinguish between two kinds of data:
- Data for which we ourselves are responsible (Art. 4(7) GDPR): data when you visit this website and its legal texts, and data of our customers and their contact persons in the customer center, i.e. account, order, contract, payment, connection of the booking system and communication with us. This policy applies to this data.
- Data of participants in online meetings of business customers: we process this data only on behalf of the business that offers the meeting (processing on behalf under Art. 28 GDPR). That business is the controller; it informs you in its own privacy policy. Details are set out in section 12.
- Data of participants in meetings of private customers: if a private individual invites people to a private meeting, their own use falls under the exemption for purely personal or household activity (Art. 2(2)(c) GDPR, recital 18). We then process the data of those participants as a controller, solely in order to run the meeting technically; details are also set out in section 12.
3. Visiting the website
Which data. When you visit this website, our server necessarily processes your IP address, the date and time, the address requested, the request method, status code, amount of data transferred and duration of the request, as well as information sent by your browser (e.g. browser identifier, preferred language, referring page). In the server logs we store the IP address only in shortened form (IPv4 to the first three blocks, IPv6 to the first 48 bits); cookies and credentials are not logged. The application's error logs contain no names and no credentials.
Purpose and legal basis. Delivering the website, security and stability of operation, detecting and averting attacks and errors. The legal basis is our legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR). To protect against misuse we count requests per IP address; for this we store only a hash value for a few minutes.
How long. Server and error logs: 7 days.
The website does not load any content from third-party servers (no external fonts, scripts or content delivery networks) and does not use any analytics, tracking or advertising services.
4. Cookies and browser storage
We only set cookies that are technically necessary to provide the functions you request (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG); no consent is required for this:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | keeps you logged in to the customer center and remembers the chosen language | until 120 minutes after the last activity |
| XSRF-TOKEN | protection against forged requests (cross-site request forgery) | as the session cookie |
| Login cookie (“Stay logged in”) | only if you choose this option: logging in again without a password | until you log out, at most 400 days |
The start page and the legal texts (privacy policy, legal notice, terms, withdrawal instructions) do not set any cookies. The cancellation page (“Cancel contracts here”) sets a technically necessary session cookie and the XSRF-TOKEN, because the form has to be protected against forged requests; both expire when the browser is closed or after 120 minutes. We do not use tracking cookies, third-party cookies or fingerprinting.
5. Customer account
Which data. For an account in the customer center we process your name, email address, password (only as a hash value), language, the time your email address was confirmed and of the last login and, if you set it up, the data for two-factor authentication (secret and recovery codes, encrypted). In the session we store the IP address only in shortened form and the browser identifier. We count failed login attempts per email address and IP address as a hash value to limit attacks. If we invite an existing customer to the customer center, we process the email address of the invited person and the language for this purpose.
Purpose and legal basis. Providing the customer center, preparing and performing the contract (Art. 6(1)(b) GDPR). If you act for a business, the legal basis is our legitimate interest in working with the contact persons of our customers (Art. 6(1)(f) GDPR). If you order as a private individual, you are our contracting party yourself; the legal basis is then Art. 6(1)(b) GDPR throughout. We base the security of the accounts on Art. 6(1)(f) and Art. 32 GDPR.
How long. We delete unconfirmed registrations after 14 days, accounts without an order, acceptance or invitation 365 days after the last login, login data 90 days after the end of the contract, password reset links after 60 minutes and invitations 30 days after they expire or are accepted.
6. Order, contract and acceptance of the contract documents
Which data. The customer's contract details: for business customers the company name with legal form, address, country, authorised representative, data protection contact and VAT identification number, for private customers first and last name, address and country; in addition language and tenant ID; for the order: plan, price, billing period, status and points in time (receipt, approval, payment, cancellation, end of contract). When you accept the terms and the data processing agreement online, we store as evidence the time, the account, the name and email address of the accepting person, the shortened IP address, and the document with the language, version and checksum (SHA-256) of the German and the English version, as well as the contract details filled in. For sole proprietors, the company name itself may be personal data.
Purpose and legal basis. Reviewing and accepting the order, performing the contract, activating and suspending access (Art. 6(1)(b) GDPR); evidence of the conclusion of the contract and of consent (Art. 6(1)(f) GDPR); retention under commercial and tax law (Art. 6(1)(c) GDPR in conjunction with Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO)).
How long. Contract details, orders and acceptances until six years after the end of the calendar year in which the contract ended. Orders that we rejected without a contract being concluded: 180 days after the last rejection.
6a. Withdrawal (private customers only)
What data. If you withdraw from your contract, we store your declaration with the time it reached us, the way it reached us (customer center, email, letter, phone), the link to the contract and the order, the number of days used, the proportionate amount, the refund and the id of the refund at Stripe. An internal note is stored only where it is needed to handle the case.
Purpose and legal basis. Handling the withdrawal and proving it towards authorities and courts (Art. 6(1)(b) and (c) GDPR; Sections 355, 357, 357a BGB), retention under commercial and tax law (Art. 6(1)(c) GDPR).
How long. Like the other contract data (section 6).
6b. Cancellation through the cancellation page
On the page “Cancel contracts here” you can cancel a contract without logging in (Section 312k BGB).
What data. Name, email address, your statement identifying the contract (tenant ID or order number), the type of cancellation with a reason for an extraordinary one, the date on which the contract should end, language, the time it reached us, a receipt number and your IP address shortened to /24 or /48. We also count the attempts per IP address and per email address as a hash value so that the page cannot be misused.
Purpose and legal basis. Receiving and handling the cancellation and the confirmation the law requires (Art. 6(1)(b) and (c) GDPR, Section 312k BGB); protection of the page against misuse (Art. 6(1)(f) GDPR).
How long. If we can match the cancellation to a contract, we keep it like the other contract data (section 6). Cancellations that do not belong to any contract of ours are deleted after 180 days.
7. Payment via Stripe
We process payments via Stripe (Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, both Dublin, Ireland). You enter your payment details (e.g. card number or IBAN) directly on Stripe's pages; we do not receive them. We transmit to Stripe the company name, email address, address, language, VAT identification number and tax classification, plan and price, and an identifier of the order. From Stripe we receive the status of payments and subscriptions, the invoices, and the type and last four digits of the payment method.
- Purpose and legal basis: processing payments, invoicing and dunning (Art. 6(1)(b) GDPR); retention of invoices (Art. 6(1)(c) GDPR).
- Role of Stripe: Stripe processes the data partly on our behalf and partly as a controller in its own right, in particular for fraud prevention and to comply with financial regulatory obligations. Stripe's privacy policy applies to this: https://stripe.com/privacy.
- Third country: Stripe belongs to a group based in the USA; data may be transferred there. Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR); in addition, Stripe uses the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
- How long: Stripe stores data according to its own periods. We keep invoices as accounting records for the statutory periods (Section 147 AO, Section 257 HGB).
Stripe never receives data of participants in online meetings.
8. Emails
We send you emails relating to the account and the contract, for example to confirm your email address, to reset your password, about the receipt, approval and payment of an order, about the end of the contract and notices under the terms. We do not send advertising emails or newsletters.
- Purpose and legal basis: performance of the contract and security of the account (Art. 6(1)(b) and (f) GDPR).
- Service provider: we use an email service as a processor (Art. 28 GDPR) to send emails: SiteGround Spain S.L., Calle de Prim 19, 28004 Madrid, Spanien / Spain. It receives the recipient address, subject, content and the technical sending data.
- How long: our logs only record that an email was sent (7 days). We keep emails that qualify as commercial letters like contract data (section 6).
9. Connecting the booking system
When you connect your booking system to StreamMeet, we process the address (origin) of your booking website, a one-time connection code (only as a hash value, valid for 15 minutes) and the keys for the API (API keys only as a hash value, public signing keys). The purpose is a secure connection (Art. 6(1)(b) GDPR). We store this data for as long as the contract exists; we delete connection codes after they expire.
10. Contact and support
If you write to us by email, we process your details and the content of your message to handle your request (Art. 6(1)(b) GDPR for questions about the contract, otherwise Art. 6(1)(f) GDPR). We delete the messages once the request has been dealt with, unless they must be kept as commercial or business letters (section 6).
11. Licence management, hosting and backups
- Hosting: the website, the customer center and the video platform run on a server of Contabo GmbH (Munich) in the Lauterbourg data centre (France), which is operated by Contabo France SAS. Contabo is our processor (Art. 28 GDPR) and processes the data in the EU. The Contabo group is majority-owned by an investment company based in the USA; it cannot be completely ruled out that authorities of a third country request data via the group structure.
- Backups: we back up the database daily. The backups are encrypted (the key is not stored on the server), are additionally stored in the object storage of Contabo GmbH in the EU and are deleted after 7 days.
- Licence management: for activation, plan and monitoring, the customer center transmits the tenant ID, the company name, the plan, the status and the date up to which payment has been made to our own licence and monitoring system, which we operate with a hosting provider in the EU (Art. 6(1)(b) GDPR). The monitoring of the servers only records technical metrics without personal reference.
12. Participants in online meetings
If you take part in an online meeting via a personal link, we process your data (e.g. display name, pseudonymous identifier, role, connection data, video and audio in real time) — for meetings of business customers — only on behalf of and on the instructions of the business that offers the meeting. If a private individual invites people to a private meeting, we are the controller for the same data ourselves; we process it solely in order to run the meeting technically (Art. 6(1)(b) and (f) GDPR), delete it according to the periods of the plan and use it for no other purpose. That business is the controller; it informs you in its privacy policy about the purposes, legal bases and storage periods. StreamMeet does not receive email addresses of participants, does not store chat, raised hands and reactions and does not use any analytics or tracking services in the lobby and meeting. This also applies if the platform appears under the name and logo of the business.
Please address enquiries about this data to the business that offers the meeting. If they reach us, we forward them there without undue delay.
13. Recipients and transfers to third countries
Your data is only received by the bodies named in this policy: our service providers as processors (hosting and backups, email delivery), Stripe for payments and, where required by law, authorities (e.g. tax authorities) and our tax advisers. A transfer to third countries can only take place at Stripe (section 7). We do not sell personal data.
14. Storage periods at a glance
| Data | Period |
|---|---|
| Server and error logs (IP address shortened) | 7 days |
| Sessions in the customer center (IP address shortened, browser identifier) | 120 minutes after the last activity |
| Counters against misuse (hash values) | a few minutes |
| Unconfirmed registrations | 14 days |
| Accounts without an order, acceptance or invitation | 365 days after the last login |
| Login data after the end of the contract | 90 days |
| Password reset links | 60 minutes |
| Invitations | 30 days after expiry or acceptance |
| Rejected orders only (no contract) | 180 days after the last rejection |
| Cancellations through the cancellation page without a contract with us | 180 days |
| Withdrawals and matched cancellations | like the contract data |
| Contract details, orders, acceptances of the contract documents | 6 years after the end of the calendar year in which the contract ended |
| Invoices and other accounting records | under Section 147 AO and Section 257 HGB |
| Database backups (encrypted) | 7 days |
15. Obligation to provide data
The details for the account, order and payment are required to conclude the contract. Without them we cannot conclude a contract. You are not legally obliged to provide them.
16. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can view and change many details yourself in the customer center. For all requests, a message to support@webvines.de is sufficient. We may ask for proof of your identity if we have reasonable doubts.
Right to object (Art. 21 GDPR): where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
17. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The competent authority for us is the data protection supervisory authority of the German federal state in which we have our registered office.
18. No automated decisions, no advertising, no AI training
We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR and do not create profiles. A human decides on the approval of an order. We do not use your data for advertising and use neither your data nor content from online meetings to train artificial intelligence models.
19. Security
All connections are encrypted (HTTPS). We store passwords only as hash values, keys for the API only as hash values and backups only in encrypted form. Only we ourselves have access to the systems. The measures are described in detail in Annex 2 of our data processing agreement.
20. Changes
We adapt this privacy policy when our processing or the legal situation changes. The version published on this website applies; we inform our customers about material changes by email. This policy is available in German and English; the German version is binding, the English version is provided for convenience.
Version 1.1.0 of 2026-09-20