Home

Privacy Policy

1. Controller

Niklas Kappes
Freiherr-von-Drais Str 36
69429 Waldbrunn
Germany

Email: contact@dynsvg.io

2. Overview of data processing

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. The use of our website is generally possible without providing personal data.

3. Hosting

This website is hosted by Vercel Inc., 440 N Baxter St, Coppell, TX 75019, USA. When you visit our website, certain information is automatically stored in server log files that your browser transmits automatically. This includes:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • IP address of the accessing device
  • Time of the server request

Data transfer to the USA is carried out on the basis of the EU-US Data Privacy Framework. The legal basis for data processing is Art. 6(1)(f) GDPR (legitimate interest in the stable and secure provision of the website).

For more information, please refer to the Vercel Privacy Policy.

4. Local storage (localStorage)

We use your browser's localStorage to save the following settings locally on your device:

  • Theme preference (light/dark) — to display your preferred view
  • Colour palette — custom colours in the editor
  • Cookie consent record (key dynsvg-consent) — your decision from the consent banner, with version and timestamp

This data is stored exclusively in your browser and is not transmitted to us or any third parties. The legal basis is § 25(2) Nr. 2 TDDDG (storage strictly necessary for the service explicitly requested by you) and Art. 6(1)(f) GDPR (legitimate interest in a user-friendly presentation and in documenting your consent decision).

5. Cookies and consent management

This website does not set tracking cookies. We do, however, store information on your device for analytics purposes (see sections 6 and 7) for which we obtain your prior consent through a banner shown on your first visit, in accordance with § 25(1) TDDDG and Art. 6(1)(a) GDPR.

The consent banner offers two categories:

  • Strictly necessary — always active, no consent required (§ 25(2) Nr. 2 TDDDG). Covers the items listed in section 4 and, once you are signed in, the session cookie described in section 8.
  • Analytics & usage statistics — disabled by default, enabled only with your explicit consent. Covers Vercel Analytics (section 6) and our own editor usage statistics (section 7).

Your decision is stored as a JSON record in localStorage under the key dynsvg-consent for up to 12 months. After that period, or if we materially change this policy (which bumps the consent version), the banner will appear again so you can confirm your choice.

Withdrawing consent: You can change or withdraw your consent at any time with effect for the future via the "Cookie preferences" link in the footer (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Vercel Analytics

This website uses Vercel Analytics, a privacy-friendly, cookieless web analytics service provided by Vercel Inc., 440 N Baxter St, Coppell, TX 75019, USA. Vercel Analytics does not use cookies and does not collect personal data that could identify individual visitors. The following aggregated data is collected:

  • Page URL and referrer URL
  • Browser and operating system
  • Device type
  • Country of origin (derived from IP address, which is not stored)

Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent). Vercel Analytics is loaded only after you have given your consent via the cookie banner.

Data transfer to the USA is carried out on the basis of the EU-US Data Privacy Framework. For more information, please refer to the Vercel Privacy Policy.

7. Editor usage statistics

When you use the in-browser editor to load an SVG/SVGHMI file or export a .svghmi file, we log an anonymized event to our own server (Upstash Redis, hosted in the EU) so that we can measure aggregate usage of the editor. The following data is stored:

  • Event type (upload or export) and server-side timestamp
  • A random session identifier (UUID generated in your browser, kept only in sessionStorage and discarded when you close the tab)
  • On upload: the file extension (.svg or .svghmi), file size in bytes, and a SHA-256 hash of the file name (the original name is never stored)
  • On export: the number of bindings, a count per binding type, and the SHA-256 hash of the exported file name
  • The time between upload and export within the same session (to measure editing duration)

We do not store IP addresses, user agents, or the SVG content itself. Because file names are hashed, we cannot recover them. Your session UUID is not linked to any other identifier.

Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent). Without your consent, no events are sent to our server and no session ID is stored.

7.1 Activity records linked to your account

Exporting a .svghmi file, viewing the generated XML and running the simulation require a user account. When you carry out one of these actions while signed in, we store a record linked to your account in our database (Supabase, EU region — see section 8). The following data is stored:

  • Your user ID
  • The action carried out (export, XML view or simulation)
  • The number of bindings in the widget at that moment
  • A server-side timestamp

We use these records to understand how many registered users actively use DynSVG and how often. Neither the SVG content, nor the file name, nor the exported file is transmitted to or stored on our server — the file is generated entirely in your browser.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to measure the actual use of the product in order to decide on its further development. Unlike the anonymized statistics described above, these records are not based on consent and are therefore also created if you have declined analytics cookies. They are only created when you actively export a file, view the XML or open the simulation.

Erasure: These records are tied to your account and are deleted automatically and in full when you delete your account (see section 8).

8. Your user account

Using the editor does not require an account. Exporting a .svghmi file, viewing the generated XML and running the simulation do (see section 7.1). We do not use passwords: you enter your email address and receive a one-time sign-in link by email ("magic link").

Data stored for your account:

  • Your email address — required, and the identifier of your account
  • An optional display name, which you can enter and change yourself
  • Your plan (free or Pro), its status, and the end of the current billing period
  • Your Paddle customer and subscription identifiers, once you have taken out a subscription (see section 9)
  • Whether you have consented to marketing email (see section 10)
  • The date your account was created and last updated

To send the sign-in link and to keep you signed in, your email address is processed by our authentication and database provider, Supabase Pte. Ltd., 65 Chulia Street, #38-02/03 OCBC Centre, Singapore 049513. A session cookie is stored in your browser and refreshed on every request; it contains the session token only. That cookie is strictly necessary for the signed-in area to work and is therefore not subject to consent (§ 25(2) Nr. 2 TDDDG).

Supabase processes this data on our behalf as a processor, under a data processing agreement pursuant to Art. 28 GDPR. The database is operated in the European Union, in the region eu-central-1 (Frankfurt). Supabase Pte. Ltd. is itself established in Singapore, however: your data is stored in the European Union, but the processor is established in a third country for which the European Commission has issued no adequacy decision, so a transfer within the meaning of Chapter V GDPR takes place. It is safeguarded by the standard contractual clauses adopted by the European Commission (Module Two, controller to processor, Implementing Decision (EU) 2021/914), which form part of Supabase's data processing addendum; that addendum applies automatically under Supabase's terms of service and needs no separately signed agreement. Supabase may engage sub-processors; the current list and the safeguards for any transfer to a third country are published by Supabase and can be consulted there.

Legal basis: Art. 6(1)(b) GDPR — the account is necessary to provide the functions you have requested (export, XML view and simulation) and, for a Pro subscription, to perform the contract. The record of your marketing decision is kept on the basis of Art. 6(1)(f) GDPR (legitimate interest in being able to demonstrate that consent).

Retention and erasure: We store this data for as long as your account exists. You can delete your account yourself at any time: sign in, open the account page and use "Delete account" in the "Danger zone" section. Deletion takes effect immediately and cannot be undone — any active subscription is cancelled, your contact record at Brevo is erased, and your account together with your profile and the activity records described in section 7.1 is deleted.

9. Payment processing (Paddle)

Paid plans are not yet available, so no payment data is processed at present: the checkout cannot be reached and no payment provider receives data about you. This section describes the processing that will take place from the moment paid plans become available, and applies from that date. Payment data is then only processed if you actually take out a paid Pro subscription. Payments are handled by Paddle.com Market Limited, acting as reseller and Merchant of Record. Paddle, not we, is the seller of the subscription: Paddle concludes the purchase with you, issues your invoice and collects and remits value added tax (VAT / USt).

Checkout takes place in an overlay loaded from Paddle. You enter your payment details directly with Paddle — we never receive or store your card or bank details. Paddle processes in particular your name, email address, billing address and country, any VAT identification number, your means of payment and the transaction data.

Paddle notifies us of subscription events (created, activated, updated, cancelled, payment completed) via a webhook. From these notifications we store, linked to your account, your Paddle customer and subscription identifier, your plan and its status, and the end of the current billing period. We also store the identifier and the content of the notification itself, so that a repeated delivery is not processed twice and changes to your billing state remain traceable.

Every change to your plan is additionally recorded as a separate entry, whether it comes from such a notification, from the automatic expiry of a lapsed subscription or from a manual correction. Each entry holds your user ID, your plan and subscription status before and after the change, the time of the change and a note of what caused it. We use this to be able to reconstruct how many accounts hold a paid plan over time; no individual entry is displayed anywhere in the product. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in traceable billing state and in measuring the take-up of the paid plan). These entries are deleted together with your account (see section 8).

Legal basis: Art. 6(1)(b) GDPR (performance of the subscription contract) and Art. 6(1)(c) GDPR (compliance with statutory invoicing and retention obligations) Invoices and the associated accounting records are retained for ten years from the end of the calendar year in which they arose (§ 147 AO, § 257 HGB); this is why billing data outlives the deletion of your account..

In its role as Merchant of Record, Paddle decides on its own responsibility how it processes your payment data and is therefore an independent controller for that processing, not our processor. Paddle may engage sub-processors; the current list and the safeguards for any transfer to a third country are published by Paddle and can be consulted there.

10. Email and contact management (Brevo)

We use Brevo (Sendinblue SAS), 106 boulevard Haussmann, 75008 Paris, France as our email and contact-management provider. Brevo processes this data on our behalf as a processor, under a data processing agreement pursuant to Art. 28 GDPR. Brevo itself is based in the European Union. Brevo may engage sub-processors; the current list and the safeguards for any transfer to a third country are published by Brevo and can be consulted there. For more information, please refer to the Brevo Privacy Policy.

Two separate things happen at Brevo, on two different legal bases. Only the second — marketing email — depends on your consent.

10.1 Your plan data as a contact record

When you sign in, and whenever your subscription changes, we write the following to your contact record at Brevo:

  • Your email address
  • Your plan (free or pro)
  • The end of the current billing period, if you have a subscription
  • Your Paddle customer identifier, if you have one
  • The date you registered

This synchronisation is one-way: data flows from our database to Brevo and never back. It also takes place if you have not consented to marketing email. In that case a contact record exists at Brevo but is not on any mailing list, and you receive no marketing email from us.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest is to keep one consistent record of the customer relationship and to be able to contact you about your own subscription.

Erasure: Deleting your account (section 8) also erases your contact record at Brevo.

10.2 Newsletter and Pro waitlist

If you subscribe to our newsletter or join the Pro waitlist, your email address will be used to send you information about DynSVG, product updates and launch notifications. We use a double opt-in process: after submitting your email address you will receive a confirmation email, and your subscription is only activated once you click the confirmation link.

If you have consented to marketing email, we additionally place your contact on the mailing list that matches your plan and remove it from the other one, so that we do not send Pro offers to people who already have Pro. Only this list membership depends on your consent — the contact attributes described in section 10.1 do not.

Data collected: email address, together with the attributes listed in section 10.1

Legal basis: Art. 6(1)(a) GDPR (consent). You can unsubscribe at any time using the unsubscribe link in every email or by contacting us directly. Withdrawal does not affect the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).

11. SSL/TLS encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser bar.

12. Your rights as a data subject

You have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR) — right to obtain information about your stored data
  • Right to rectification (Art. 16 GDPR) — right to correct inaccurate data
  • Right to erasure (Art. 17 GDPR) — right to have your data deleted; for your account you can do this yourself and immediately (see section 8)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR) — right to object to the processing of your data

Exercising your rights: Write to contact@dynsvg.io. The right to erasure for your account does not require a request: sign in, open the account page and use "Delete account" in the "Danger zone" section (see section 8).

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The competent supervisory authority depends on your place of residence or the registered office of the controller.

13. Changes to this privacy policy

We reserve the right to amend this privacy policy to ensure that it always complies with current legal requirements or to implement changes to our services. The new privacy policy will then apply for your next visit.

Privacy Policy | DynSVG