Privacy Policy

This is a convenience translation. Only the German version is legally binding: German version.

Last updated: 7 October 2026

This privacy policy informs you which personal data we process when you use

  • the website manualpass.eu,
  • the application app.manualpass.eu (customer area) and
  • the public scan pages at app.manualpass.eu/p/… (accessed via the QR code on a machine),

for what purposes and on what legal basis, and what rights you have.

1. Controller

Berke Mersin
Digitalagentur Gruppe Digital
Kaiser-Joseph-Str. 254
79098 Freiburg im Breisgau
Germany
Email: support@manualpass.eu

We have not appointed a data protection officer, as we are not required to do so. If you have any questions about data protection, please use the contact details above.

2. Hosting and server log files

The website and the application are operated by TrafficPlex GmbH (lima-city), Konsul-Smidt-Str. 90, 28217 Bremen, Germany. A data processing agreement pursuant to Art. 28 GDPR has been concluded with the host.

Each time a page is accessed, the following data is recorded in server log files for technical reasons: IP address, date and time, requested address, amount of data transferred, status code, referrer address and browser identifier (user agent). This processing is necessary to deliver the website and to ensure its stability and security (legal basis: Art. 6(1)(f) GDPR; our legitimate interest lies in secure operation). The log files are stored only for as long as is necessary for these purposes and are then deleted automatically.

All connections are encrypted using TLS (HTTPS).

3. Website manualpass.eu

The website sets no cookies, uses no analytics or tracking tools and embeds no content from third-party providers. Fonts are loaded from our own server. Beyond the server log files (Section 2), no personal data is processed.

4. Contacting us

If you contact us by email or telephone, we process the information you provide (e.g. name, company, email address, content of the enquiry) in order to handle your request. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry relates to a contract, and otherwise Art. 6(1)(f) GDPR (interest in responding to enquiries). We delete the data once the enquiry has been fully dealt with, unless statutory retention obligations prevent this.

Whitepaper download

If you request a whitepaper, we process your name, company, email address and – voluntarily – your position and country, the selected language, the page you came from, the time, your IP address (to prevent misuse) and whether you opened the link. We send you the download link by email. The legal basis is Art. 6(1)(b) GDPR (providing the requested whitepaper) and Art. 6(1)(f) GDPR (our interest in contacting you once about ManualPass in connection with your request). We only send further emails about the Machinery Regulation and ManualPass if you have ticked the optional box (Art. 6(1)(a) GDPR); you can withdraw your consent at any time by email to support@manualpass.eu. We delete the data no later than two years after the request, or earlier if you withdraw consent or object.

5. Customer account in the application (app.manualpass.eu)

Registration and use. For the use of ManualPass, we process the company name, address, the users' names and email addresses, the password (exclusively as a cryptographic hash), the selected language, and the role and time of last login. The legal basis is Art. 6(1)(b) GDPR (contract, including the free trial period).

Team members. If a customer invites further persons, we process their name and email address in order to set up access. The invitation takes place within the scope of the contract with the customer.

Security. To protect against password guessing, we store failed login attempts with email address, IP address and time for 24 hours. Password reset links are valid for 60 minutes and are deleted after 24 hours at the latest. The legal basis is Art. 6(1)(f) GDPR (protection of accounts).

Change log. ManualPass logs changes (e.g. publication of a document, approvals, dispatch of a paper copy) with the time, the acting person and the IP address. The entries are protected against undetected alteration by a checksum chain. The log serves as evidence vis-à-vis market surveillance authorities and ensures tamper resistance (Art. 6(1)(b) and (f) GDPR). It is stored for the term of the contract; thereafter Section 10 applies.

Uploaded content. Customers upload documents and logos themselves. If these contain personal data, we process it on behalf of the customer (Section 7).

Session cookie. After login, the application sets a technically necessary session cookie that keeps you logged in and protects forms against misuse (CSRF). It becomes invalid when you log out or close the browser. No consent is required for this (§ 25(2) no. 2 TDDDG – Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, German Telecommunications and Digital Services Data Protection Act); the legal basis for further processing is Art. 6(1)(b) or (f) GDPR.

System emails. We send emails relating to the account, paper copy requests, deadlines, approvals, the trial period and invoices via our own mail server at the host (Section 2).

6. Payment and invoices (Stripe)

Paid plans are processed via the payment service Stripe: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. In this context, the company name, billing address, email address, VAT ID where applicable, the selected plan and – for card payments – your card details are processed. Stripe does not pass card details on to us; we only receive the payment status, invoice data and a link to the invoice.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (obligations under tax and commercial law). Stripe also processes data in part as an independent controller, for example for fraud prevention and to comply with its own legal obligations. A transfer to Stripe, Inc. in the USA is possible; it takes place on the basis of the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. Further information: stripe.com/de/privacy.

We retain invoices for the statutory retention periods (§ 147 AO – Abgabenordnung, German Fiscal Code; § 257 HGB – Handelsgesetzbuch, German Commercial Code).

7. Public scan pages and paper copy requests

Accessing a scan page. Anyone who scans the QR code on a machine accesses a public page with the manufacturer's documents. In addition to the server log files (Section 2), the language setting transmitted by the device is used to display the page in a suitable language. For the manufacturer's scan statistics, we increase an anonymous counter per machine type and day (date, machine type, type of view, language); no IP address, cookies, device identifiers or other characteristics that could relate to you are stored. No third-party analytics or tracking tools are used. For the "Request paper copy" form, a technically necessary session cookie is set (protection against misuse; § 25(2) no. 2 TDDDG).

Paper copy request. If you request a free paper copy of the instructions for use via the scan page, we process your name, company (optional), address, email address, serial number (optional), language and time. The data is passed on to the manufacturer or distributor offering the machine so that they can send you the paper copy; you receive an acknowledgement of receipt and a dispatch confirmation by email. To protect against automated mass requests, your IP address is logged with the request.

Reporting a vulnerability. If you report a possible security vulnerability via the form on the scan page, we process your email address, optionally your name, organisation and affected version, as well as your description and the time. The report is forwarded to the manufacturer's security contact so that they can assess it, contact you and fulfil legal obligations (including under Regulation (EU) 2024/2847, the Cyber Resilience Act); you receive an acknowledgement of receipt by email. To protect against misuse, we store your IP address only as a non-reversible hash.

Responsibility. The respective manufacturer or distributor whose details appear on the scan page is the controller for the data from paper copy requests and vulnerability reports. We process this data on their behalf as a processor (Art. 28 GDPR). Please address requests regarding your rights to the manufacturer; we forward any such requests that reach us to them.

8. Recipients

Personal data is received only by: our host (Section 2), Stripe (Section 6), in the case of paper copy requests the respective manufacturer or distributor (Section 7), and authorities where we are legally obliged to disclose it. Data is not passed on for advertising purposes.

9. No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

10. Storage period

We store personal data only for as long as is necessary for the stated purposes. Account and content data is deleted after the end of the contract in accordance with our terms and conditions. Data that we must retain for legal reasons (e.g. invoices) is restricted for the duration of these obligations and deleted thereafter.

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR).

Right to object: Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, or the processing serves the establishment, exercise or defence of legal claims.

To exercise your rights, a message to support@manualpass.eu is sufficient.

Right to lodge a complaint: You may lodge a complaint with a data protection supervisory authority. The authority competent for us is: Die Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de.

12. Changes

We will amend this privacy policy if our processing or the legal situation changes. The version published here at any given time applies.