Privacy policy

The German version of this document is legally binding. This translation is provided for convenience only.

As of: 12 August 2026


1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Yannick Stein
Auf’m Bruch 6
59929 Brilon
Email: [email protected]

2. Overview of processing operations

This privacy policy provides information about the processing of personal data when using the website notenarchiv.com as well as the web-based platform and mobile app “Notenarchiv” (hereinafter jointly referred to as the “Service”).

3. Data collected

3.1 Visiting the website (notenarchiv.com)

This website is a static information page. No forms are used for data collection. When visiting the website, technically necessary server log files are recorded (see section 4).

In addition, we use Google Ads on this website to measure how effective our advertisements are (see section 6.5). This sets cookies and transmits data to Google. This only happens after your explicit consent, which we obtain via a consent banner. If you do not give consent, no advertising cookies are set and no identifiers are transmitted to Google.

To measure reach we use Umami, analytics software that we host ourselves on a server in Germany (see section 6.2). It records the page visited, the referring page, the approximate origin (country, region and city, derived from the IP address), device type, screen size and browser language. Umami sets no cookies and stores nothing permanently on your device. Your IP address is not stored; it is used only transiently, together with your browser signature and a random value that changes daily, to derive a counting value — once that random value rotates, you can no longer be recognised. No data is transmitted to third parties; the analysis never leaves our own server. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in the needs-based design of our offering). You may object to this processing under Art. 21 GDPR (see section 10).

Neither advertising nor audience measurement takes place in the web platform or the mobile app.

3.2 Registration and account management (app)

  • Club name
  • First name, surname and email address of the contact person
  • IP address and user agent at registration (proof of agreement to the terms)
  • Role within the club (admin, librarian, member)
  • Assigned instruments

3.3 Use of the Service (app)

  • Uploaded files (sheet music as PDF)
  • Metadata of the sheet music (title, composer, category, etc.)
  • Access logs (timestamps, pages visited)

3.4 Authentication (app)

  • WebAuthn/passkey credentials (public key, credential ID)
  • Magic link tokens (temporary, valid for max. 15 minutes)
  • JWT tokens (in the user’s browser storage)

3.5 Subscription and billing (app)

  • Selected plan and subscription status
  • Billing address (if provided)
  • Payment information (invoice number, payment status)

4. Server log files

The hosting provider (Cloudflare) automatically collects and stores information in so-called server log files, which your browser transmits automatically. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • IP address
  • Time of the server request

This data is not merged with other data sources. The collection of this data is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and provision of its website.

The analytics instance stats.notenarchiv.com runs on our own server at Hetzner in Germany (see section 6.2). Server log files containing the same details, in particular your IP address, are also created there when the counting script is retrieved and when measurements are transmitted. These logs serve solely for secure operation and troubleshooting. They are not merged with the analytics data described in section 3.1 and are deleted after the period stated for access logs in section 8. The legal basis is Art. 6 (1) lit. f GDPR.

ProcessingLegal basis
Registration and account managementArt. 6 (1) lit. b GDPR (performance of a contract)
Use of the ServiceArt. 6 (1) lit. b GDPR (performance of a contract)
AuthenticationArt. 6 (1) lit. b GDPR (performance of a contract)
BillingArt. 6 (1) lit. b GDPR (performance of a contract)
Access logsArt. 6 (1) lit. f GDPR (legitimate interest in security)
Logging agreement to the termsArt. 6 (1) lit. f GDPR (legitimate interest in proof)
Email notificationsArt. 6 (1) lit. b GDPR (performance of a contract)
Advertising measurement with Google Ads (website only)Art. 6 (1) lit. a GDPR (consent) in conjunction with sec. 25 (1) TDDDG
Audience measurement with Umami (website only)Art. 6 (1) lit. f GDPR (legitimate interest in needs-based design)

6. Processors and integrated third-party providers

We use the following service providers:

6.1 Cloudflare, Inc.

  • Purpose: Hosting the website, bot protection during registration (Cloudflare Turnstile)
  • Data: IP address, browser information (anonymised)
  • Storage: No permanent storage of personal data
  • Location: Worldwide, standard contractual clauses pursuant to Art. 46 (2) lit. c GDPR
  • Info: https://www.cloudflare.com/privacypolicy

6.2 Hetzner Online GmbH

  • Purpose: Hosting the application and storing the data (servers and S3 object storage), and running our self-hosted analytics instance (stats.notenarchiv.com)
  • Location: Germany (data centres in Nuremberg and Falkenstein)
  • Data protection: Data processing agreement concluded pursuant to Art. 28 GDPR
  • Info: https://www.hetzner.com/legal/privacy-policy

6.3 Resend Inc. (where activated)

  • Purpose: Sending emails (login links, notifications)
  • Data: Email address, first name
  • Location: USA, standard contractual clauses pursuant to Art. 46 (2) lit. c GDPR
  • Info: https://resend.com/legal/privacy-policy

6.4 OpenAI, LLC (only when AI recognition is activated)

  • Purpose: AI-powered instrument recognition on PDF pages
  • Data: Individual PDF page images are temporarily transmitted to the OpenAI API
  • Storage: OpenAI does not permanently store data transmitted via the API for training purposes in accordance with its own Data Usage Policy (for API usage)
  • Location: USA, standard contractual clauses pursuant to Art. 46 (2) lit. c GDPR
  • Note: AI recognition is deactivated by default and is only activated at the customer’s request. The customer can deactivate its use at any time in the settings.
  • Info: https://openai.com/policies/privacy-policy
  • Purpose: Measuring the effectiveness of our advertisements (Google Ads conversion tracking and remarketing) on notenarchiv.com
  • Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
  • Data: IP address, browser and device information, pages visited, referrer URL, advertising click identifiers (e.g. gclid), cookie identifiers
  • Legal basis: Art. 6 (1) lit. a GDPR (consent) in conjunction with sec. 25 (1) TDDDG
  • Role: Google processes part of this data not as a processor but as an independent controller. Details are governed by the Google Ads Data Processing Terms.
  • Third-country transfer: Transfer to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; standard contractual clauses pursuant to Art. 46 (2) lit. c GDPR apply in addition.
  • Consent Mode: We use Google Consent Mode v2. As long as you have not consented, all consent signals (ad_storage, ad_user_data, ad_personalization, analytics_storage) are set to “denied”. Google then receives no identifiers, at most anonymous, cookieless signals.
  • Withdrawal: at any time via “Cookie settings” in the footer of every page
  • Info: https://policies.google.com/privacy and https://policies.google.com/technologies/ads

7. Data transfer

Personal data is only passed on to third parties:

  • to the service providers named in section 6
  • to Google as part of the advertising measurement described in section 6.5, provided you have consented
  • where we are legally obliged to do so (e.g. by order of a court)

No transfer for advertising purposes beyond this takes place. In particular, the contents of your sheet music archive as well as account and usage data from the app are never transmitted to advertising networks.

8. Storage period

DataStorage period
Account and usage dataFor the duration of the contract
After the end of the contract30 days (data available for download)
After the 30 days have elapsedIrreversible deletion
Billing data10 years (statutory retention period pursuant to § 147 AO)
Agreement to the terms (proof)3 years after the end of the contract (limitation period)
Access logs90 days
Audience data (Umami)14 months

9. Cookies and local storage

  • Local storage (localStorage): JWT authentication tokens and the selected organisation are stored in the browser. This data is technically necessary for the functionality of the Service.
  • Consent cookie na_consent: Stores your decision on the consent banner (value granted or denied, lifetime 6 months). Without this cookie we would have to ask you again on every page view. It is therefore necessary under sec. 25 (2) TDDDG and does not itself require consent. It contains no identifier that makes you recognisable.
  • Audience measurement (Umami): sets no cookie and creates no entry in browser storage on its own. The only value read is umami.disabled. If your browser has “Do Not Track” enabled, we do not count you at all. Independently of that, you can exclude yourself permanently by running localStorage.setItem('umami.disabled', 1) in this page’s developer console — that entry stays in your browser and is never read out or transmitted by us.

If you consent, Google Ads sets cookies to measure advertising performance:

CookiePurposeLifetime
_gcl_auAttributing ad clicks to conversions90 days
other _gcl_*Click identifiers for conversion measurementup to 90 days
Google/DoubleClick cookiesRecognition for remarketingup to 24 months

These cookies are not set before you consent.

9.3 Withdrawal

You can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer of every page. You can also delete cookies that have already been set in your browser settings. The lawfulness of processing carried out up to the withdrawal remains unaffected (Art. 7 (3) GDPR).

10. Rights of data subjects

Every data subject has the following rights:

  • Access (Art. 15 GDPR): You can request information about the data we have stored about you.
  • Rectification (Art. 16 GDPR): You can request the rectification of inaccurate data.
  • Erasure (Art. 17 GDPR): You can request the erasure of your data, provided there are no statutory retention obligations.
  • Restriction (Art. 18 GDPR): You can request the restriction of processing.
  • Data portability (Art. 20 GDPR): You can receive your data in a common, machine-readable format.
  • Objection (Art. 21 GDPR): You can object to the processing of your data.

To exercise your rights, please contact the email address named in section 1.

11. Right to lodge a complaint

In the event of breaches of the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent supervisory authority is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf
https://www.ldi.nrw.de

12. Security measures

We take appropriate technical and organisational measures to protect your data:

  • Encrypted data transmission (HTTPS/TLS)
  • Passwordless login via WebAuthn/passkeys (phishing-resistant)
  • Tenant separation (multi-tenant architecture with strict data isolation)
  • Regular security updates
  • Access controls and role-based permissions

13. Contacting us by email

If you contact us by email, your enquiry including all personal data resulting from it (name, email address, content of the enquiry) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.

The processing of this data is based on Art. 6 (1) lit. b GDPR, provided your enquiry is connected with the performance of a contract or is necessary for carrying out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6 (1) lit. f GDPR).

14. Changes to this privacy policy

We reserve the right to adapt this privacy policy in order to bring it into line with changed legal situations or changes to the Service. The respective current version can be viewed on this page and in the app.