Privacy Policy
Effective date: July 25, 2026 · version 1.0
1. Controller
[Add the operator name in the Admin Panel]
Germany
Email: boss@mailsdu.com
2. Purpose of the platform
INFEEO is a social network for artists and other creative people. Members can create profiles, publish their own work, follow accounts and hashtags, like and comment on posts, submit reports and send invitations.
3. Categories of personal data
We may process in particular:
- registration and account data, including username, email address, password hash and display name
- optional profile data, including avatar, cover image, biography and website
- published content, including images, videos, text, hashtags and comments
- interaction data, including follows, likes, reports and invitations
- security and log data, including IP address, timestamps, browser information, login records and administrative audit logs
- technical data required for sessions, uploads, PWA functionality and secure operation
4. Purposes and legal bases
Processing is carried out to provide and perform the user agreement, administer accounts, publish requested content, enable communication within the platform and prevent misuse. Depending on the processing activity, the legal bases may include Article 6(1)(b), Article 6(1)(c) and Article 6(1)(f) GDPR. Where explicit consent is requested, Article 6(1)(a) GDPR applies. Consent may be withdrawn at any time with future effect.
5. Hosting and server logs
The platform is hosted by:
When the service is accessed, technically necessary server logs may be generated, including IP address, date and time, requested resource, referrer, browser and response status. This processing supports secure and stable delivery and the detection of attacks. Logs are retained only as long as required for security, troubleshooting or legal obligations.
6. Public profiles and content
Publicly published profiles and posts may be viewed by guests and members. Users decide which works and information they publish. Search engines may index public pages unless indexing is technically restricted. Deleted content may remain temporarily in backups until those backups are overwritten under the regular retention cycle.
7. Invitations
When an invitation is created, the supplied email address is processed to create and deliver a single-use registration link. Invitations expire automatically. The invited person may object to further processing.
8. Moderation, reports and security
Reports, moderation decisions and administrative changes may be logged to enforce the Community Guidelines, respond to unlawful content and protect system security. The processed data may include user ID, relevant content, reasons, IP address and timestamps.
9. Cookies and local storage
The web app uses a technically necessary session cookie with HttpOnly, SameSite and, when HTTPS is used, Secure attributes. It supports authentication, CSRF protection and session management. For the installable PWA, the browser may cache static application files locally. The standard distribution does not use advertising, analytics or tracking cookies. Additional information is available on the “Cookies & Local Storage” page.
10. Recipients and processors
Data is shared with service providers only where necessary for hosting, email delivery, maintenance, security or legal obligations. The operator must enter into appropriate data-processing agreements whenever a service provider processes personal data on the operator’s behalf.
11. International transfers
The standard installation does not integrate external analytics, advertising or social-media tracking services. If the operator later activates services that transfer data outside the European Economic Area, the operator must provide a valid transfer mechanism, appropriate safeguards and updated transparency information.
12. Retention periods
Account and profile data is retained while the account exists. Published content is retained until it is deleted, moderated or the account is removed. Security, consent, audit and report records may be retained longer where necessary to establish, exercise or defend legal claims, meet legal duties or protect the platform. Invitations and temporary upload data are deleted or expire under the configured periods.
13. Your rights
Subject to the applicable legal requirements, data subjects may have rights to access, rectification, erasure, restriction, data portability and objection, as well as the right to withdraw consent. Requests may be submitted through the Privacy Center or to boss@mailsdu.com. Identity verification may be required before a request is fulfilled.
14. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority configured by the operator is:
15. Minors
The configured minimum age is 16. Where consent by a holder of parental responsibility is legally required, the account may be used only after that consent has been obtained. Content that sexually exploits or endangers minors is prohibited.
16. Automated decision-making
The standard installation does not use solely automated decision-making that produces legal or similarly significant effects. Feed ranking uses interaction and visibility signals to order content. Account restrictions are handled through moderation and administrative workflows.
17. Security
The platform uses measures such as password hashing, prepared database statements, CSRF protection, upload validation, access controls, signed media URLs and audit logging. No internet service can guarantee absolute security. Users should choose a unique password and protect access to their email account.
18. Changes to this policy
This policy may be updated when functionality, legal requirements or service providers change. Material changes may require users to confirm a new privacy or terms version.