StreamMeet

The German version of this privacy policy is binding; this English version is provided for convenience.

Privacy Policy

for the StreamMeet website and the customer center

In accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR), this privacy policy explains which personal data we, as the operator of StreamMeet, process under our own responsibility, for what purposes, on what legal basis and for how long, and what rights you have.

1. Controller and contact

The controller is:

Webvines / Christian Schmid
Hofgartenstraße 28a
86551 Aichach
Deutschland\

2. What this policy covers and what it does not

StreamMeet is a video platform for online meetings of businesses. We distinguish between two kinds of data:

3. Visiting the website

Which data. When you visit this website, our server necessarily processes your IP address, the date and time, the address requested, the request method, status code, amount of data transferred and duration of the request, as well as information sent by your browser (e.g. browser identifier, preferred language, referring page). In the server logs we store the IP address only in shortened form (IPv4 to the first three blocks, IPv6 to the first 48 bits); cookies and credentials are not logged. The application's error logs contain no names and no credentials.

Purpose and legal basis. Delivering the website, security and stability of operation, detecting and averting attacks and errors. The legal basis is our legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR). To protect against misuse we count requests per IP address; for this we store only a hash value for a few minutes.

How long. Server and error logs: 7 days.

The website does not load any content from third-party servers (no external fonts, scripts or content delivery networks) and does not use any analytics, tracking or advertising services.

4. Cookies and browser storage

We only set cookies that are technically necessary to provide the functions you request (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG); no consent is required for this:

Cookie Purpose Duration
Session cookie keeps you logged in to the customer center and remembers the chosen language until 120 minutes after the last activity
XSRF-TOKEN protection against forged requests (cross-site request forgery) as the session cookie
Login cookie (“Stay logged in”) only if you choose this option: logging in again without a password until you log out, at most 400 days

The start page and the legal texts (privacy policy, legal notice, terms, withdrawal instructions) do not set any cookies. The cancellation page (“Cancel contracts here”) sets a technically necessary session cookie and the XSRF-TOKEN, because the form has to be protected against forged requests; both expire when the browser is closed or after 120 minutes. We do not use tracking cookies, third-party cookies or fingerprinting.

5. Customer account

Which data. For an account in the customer center we process your name, email address, password (only as a hash value), language, the time your email address was confirmed and of the last login and, if you set it up, the data for two-factor authentication (secret and recovery codes, encrypted). In the session we store the IP address only in shortened form and the browser identifier. We count failed login attempts per email address and IP address as a hash value to limit attacks. If we invite an existing customer to the customer center, we process the email address of the invited person and the language for this purpose.

Purpose and legal basis. Providing the customer center, preparing and performing the contract (Art. 6(1)(b) GDPR). If you act for a business, the legal basis is our legitimate interest in working with the contact persons of our customers (Art. 6(1)(f) GDPR). If you order as a private individual, you are our contracting party yourself; the legal basis is then Art. 6(1)(b) GDPR throughout. We base the security of the accounts on Art. 6(1)(f) and Art. 32 GDPR.

How long. We delete unconfirmed registrations after 14 days, accounts without an order, acceptance or invitation 365 days after the last login, login data 90 days after the end of the contract, password reset links after 60 minutes and invitations 30 days after they expire or are accepted.

6. Order, contract and acceptance of the contract documents

Which data. The customer's contract details: for business customers the company name with legal form, address, country, authorised representative, data protection contact and VAT identification number, for private customers first and last name, address and country; in addition language and tenant ID; for the order: plan, price, billing period, status and points in time (receipt, approval, payment, cancellation, end of contract). When you accept the terms and the data processing agreement online, we store as evidence the time, the account, the name and email address of the accepting person, the shortened IP address, and the document with the language, version and checksum (SHA-256) of the German and the English version, as well as the contract details filled in. For sole proprietors, the company name itself may be personal data.

Purpose and legal basis. Reviewing and accepting the order, performing the contract, activating and suspending access (Art. 6(1)(b) GDPR); evidence of the conclusion of the contract and of consent (Art. 6(1)(f) GDPR); retention under commercial and tax law (Art. 6(1)(c) GDPR in conjunction with Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO)).

How long. Contract details, orders and acceptances until six years after the end of the calendar year in which the contract ended. Orders that we rejected without a contract being concluded: 180 days after the last rejection.

6a. Withdrawal (private customers only)

What data. If you withdraw from your contract, we store your declaration with the time it reached us, the way it reached us (customer center, email, letter, phone), the link to the contract and the order, the number of days used, the proportionate amount, the refund and the id of the refund at Stripe. An internal note is stored only where it is needed to handle the case.

Purpose and legal basis. Handling the withdrawal and proving it towards authorities and courts (Art. 6(1)(b) and (c) GDPR; Sections 355, 357, 357a BGB), retention under commercial and tax law (Art. 6(1)(c) GDPR).

How long. Like the other contract data (section 6).

6b. Cancellation through the cancellation page

On the page “Cancel contracts here” you can cancel a contract without logging in (Section 312k BGB).

What data. Name, email address, your statement identifying the contract (tenant ID or order number), the type of cancellation with a reason for an extraordinary one, the date on which the contract should end, language, the time it reached us, a receipt number and your IP address shortened to /24 or /48. We also count the attempts per IP address and per email address as a hash value so that the page cannot be misused.

Purpose and legal basis. Receiving and handling the cancellation and the confirmation the law requires (Art. 6(1)(b) and (c) GDPR, Section 312k BGB); protection of the page against misuse (Art. 6(1)(f) GDPR).

How long. If we can match the cancellation to a contract, we keep it like the other contract data (section 6). Cancellations that do not belong to any contract of ours are deleted after 180 days.

7. Payment via Stripe

We process payments via Stripe (Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, both Dublin, Ireland). You enter your payment details (e.g. card number or IBAN) directly on Stripe's pages; we do not receive them. We transmit to Stripe the company name, email address, address, language, VAT identification number and tax classification, plan and price, and an identifier of the order. From Stripe we receive the status of payments and subscriptions, the invoices, and the type and last four digits of the payment method.

Stripe never receives data of participants in online meetings.

8. Emails

We send you emails relating to the account and the contract, for example to confirm your email address, to reset your password, about the receipt, approval and payment of an order, about the end of the contract and notices under the terms. We do not send advertising emails or newsletters.

9. Connecting the booking system

When you connect your booking system to StreamMeet, we process the address (origin) of your booking website, a one-time connection code (only as a hash value, valid for 15 minutes) and the keys for the API (API keys only as a hash value, public signing keys). The purpose is a secure connection (Art. 6(1)(b) GDPR). We store this data for as long as the contract exists; we delete connection codes after they expire.

10. Contact and support

If you write to us by email, we process your details and the content of your message to handle your request (Art. 6(1)(b) GDPR for questions about the contract, otherwise Art. 6(1)(f) GDPR). We delete the messages once the request has been dealt with, unless they must be kept as commercial or business letters (section 6).

11. Licence management, hosting and backups

12. Participants in online meetings

If you take part in an online meeting via a personal link, we process your data (e.g. display name, pseudonymous identifier, role, connection data, video and audio in real time) — for meetings of business customers — only on behalf of and on the instructions of the business that offers the meeting. If a private individual invites people to a private meeting, we are the controller for the same data ourselves; we process it solely in order to run the meeting technically (Art. 6(1)(b) and (f) GDPR), delete it according to the periods of the plan and use it for no other purpose. That business is the controller; it informs you in its privacy policy about the purposes, legal bases and storage periods. StreamMeet does not receive email addresses of participants, does not store chat, raised hands and reactions and does not use any analytics or tracking services in the lobby and meeting. This also applies if the platform appears under the name and logo of the business.

Please address enquiries about this data to the business that offers the meeting. If they reach us, we forward them there without undue delay.

13. Recipients and transfers to third countries

Your data is only received by the bodies named in this policy: our service providers as processors (hosting and backups, email delivery), Stripe for payments and, where required by law, authorities (e.g. tax authorities) and our tax advisers. A transfer to third countries can only take place at Stripe (section 7). We do not sell personal data.

14. Storage periods at a glance

Data Period
Server and error logs (IP address shortened) 7 days
Sessions in the customer center (IP address shortened, browser identifier) 120 minutes after the last activity
Counters against misuse (hash values) a few minutes
Unconfirmed registrations 14 days
Accounts without an order, acceptance or invitation 365 days after the last login
Login data after the end of the contract 90 days
Password reset links 60 minutes
Invitations 30 days after expiry or acceptance
Rejected orders only (no contract) 180 days after the last rejection
Cancellations through the cancellation page without a contract with us 180 days
Withdrawals and matched cancellations like the contract data
Contract details, orders, acceptances of the contract documents 6 years after the end of the calendar year in which the contract ended
Invoices and other accounting records under Section 147 AO and Section 257 HGB
Database backups (encrypted) 7 days

15. Obligation to provide data

The details for the account, order and payment are required to conclude the contract. Without them we cannot conclude a contract. You are not legally obliged to provide them.

16. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can view and change many details yourself in the customer center. For all requests, a message to support@webvines.de is sufficient. We may ask for proof of your identity if we have reasonable doubts.

Right to object (Art. 21 GDPR): where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

17. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The competent authority for us is the data protection supervisory authority of the German federal state in which we have our registered office.

18. No automated decisions, no advertising, no AI training

We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR and do not create profiles. A human decides on the approval of an order. We do not use your data for advertising and use neither your data nor content from online meetings to train artificial intelligence models.

19. Security

All connections are encrypted (HTTPS). We store passwords only as hash values, keys for the API only as hash values and backups only in encrypted form. Only we ourselves have access to the systems. The measures are described in detail in Annex 2 of our data processing agreement.

20. Changes

We adapt this privacy policy when our processing or the legal situation changes. The version published on this website applies; we inform our customers about material changes by email. This policy is available in German and English; the German version is binding, the English version is provided for convenience.

Version 1.1.0 of 2026-09-20