Privacy Policy
Updated: September 21, 2026
1. Controller
Controller within the meaning of the GDPR:
Thiel, Thomas und Gerhold, Frank GbR
Mariendorfer Str. 7, 34127 Kassel, Germany
Email: kontakt@mdo-beratung.de
Tel: +49 163 8907380
2. Principles of data processing
We process personal data only to the extent necessary to provide our services. We do not sell personal data or use it for third-party advertising purposes.
3. Data we process
3.1 Account data (on registration)
Upon registration we store:
- Email address (required for authentication)
- WhatsApp number (optional, to extend the Pro trial by 7 days to 14 days total)
- Login timestamps and method (Magic Link, Google)
- Licence tier (Free / Plus / Pro)
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
3.2 Constellation boards (content data)
Your boards are stored locally in your browser (IndexedDB) and are not transmitted to servers. We have no access to your constellation content.
3.3 Technical log data
When you access our website, the hosting provider Cloudflare automatically records: IP address, date/time, requested URL, browser type, operating system, referrer. Legal basis: Art. 6(1)(f) GDPR.
3.4 Theme and language preferences
Your choice of light/dark mode and preferred language is stored in your browser's localStorage (keys: syslia-theme, systembrett-settings). This data remains locally on your device.
3.5 Chat assistant (landing page)
The chat assistant in the bottom-right corner answers questions without requiring sign-in and without storing a conversation history on our side. So that follow-up questions are understood, your browser sends the most recent messages of this conversation with each message; they are kept only in the page's memory (not in cookies or local storage) and disappear when you close or reload the page. Your message together with this history is transmitted to MiniMax for the purpose of answering it (see section 4). To prevent abuse, each message undergoes a security check (Cloudflare Turnstile) and the number of messages per visitor is counted for a short time — for this, your IP address is irreversibly encrypted (hashed) with a secret additional value and automatically deleted after a few hours; it cannot be traced back to your actual IP address. Legal basis: Art. 6(1)(f) GDPR (abuse prevention).
If a question cannot be answered with confidence, you may voluntarily leave an email address so our team can get back to you. If you forward your question to our team, we also store the chat history so far with your request so the team knows the context; this only happens when you trigger it and is shown to you beforehand. This information is used exclusively to respond to your request. Legal basis: Art. 6(1)(b) GDPR.
3.6 Backlink exchange program (voluntary participation only)
Customers on the Standard plan or higher may voluntarily join the backlink exchange program in their profile. If you participate, we publish the site name and website address you provide on syslia.de/unsere-kunden. The address you provide is checked automatically and regularly (currently monthly) to confirm it still links back to syslia.de. If no backlink is found any more, you receive an email after internal review and the listing is removed. You may leave the program at any time in your profile. Legal basis: Art. 6(1)(a) GDPR (consent).
3.7 Device management (one active access per licence)
Each licence allows use on one device at a time (further concurrent access via additional licences). To implement this, we store for each signed-in device a randomly generated device identifier (in your browser’s local storage), a rough device label from browser and operating system (e.g. “Chrome · Windows”), the identifier of the sign-in session and the times of sign-in and last activity. While in use, the app contacts the server about once per minute for this purpose. You can see this information yourself in your profile under “Access & additional licences”. It is deleted together with your account. Legal basis: Art. 6(1)(b) GDPR (performance of contract – compliance with the licence terms).
4. Third-party services
Supabase Inc. — EU servers in Frankfurt am Main (AWS eu-central-1). Purpose: user management, authentication, licence management. DPA concluded. supabase.com/privacy
Cloudflare Inc., USA. Certified under EU-US Data Privacy Framework. Purpose: website and app delivery. cloudflare.com/privacypolicy/
Cloudflare Inc., USA. Checks in the background whether a request comes from a human, without a visible captcha in most cases. cloudflare.com/privacypolicy/
Nanonoble Pte. Ltd. (MiniMax), Singapore. Purpose: answering your chat messages based on our knowledge base. Your message is transmitted for processing but is not permanently linked to your identity. platform.minimax.io/protocol/privacy-policy
When using this optional sign-in method, your name and email are transferred. Legal basis: Art. 6(1)(b) GDPR.
Paddle.com Market Limited, Ireland — Merchant of Record. On purchase, name, email and payment data are transmitted to Paddle. We do not receive credit card data. Legal basis: Art. 6(1)(b) GDPR. paddle.com/legal/privacy
5. Cookies and local storage
We use no tracking cookies and no analytics tracking. Technically necessary storage:
- localStorage (syslia-theme): Theme preference — no server access
- localStorage (systembrett-settings): Language preference — no server access
- IndexedDB (systembrett-*): Boards locally — no server access
- Supabase Auth Cookies: JWT (1h) + refresh token — technically necessary
Legal basis: Art. 6(1)(f) GDPR, § 25(2) TDDDG.
6. Retention periods
- Account data: Until account deletion
- Boards (local): Until manual deletion
- Auth tokens: JWT 1h, refresh until logout
- Server logs: Max. 30 days
- Chat abuse-prevention (IP hash): A few hours, automatic
- Payment data: 10 years (§ 147 German Fiscal Code)
7. Your rights (Art. 15–22 GDPR)
You have the right of access, rectification, erasure, restriction, data portability and objection. To exercise your rights: kontakt@mdo-beratung.de or our GDPR request form.
You also have the right to lodge a complaint with a supervisory authority: bfdi.bund.de
8. Data security
All transmissions are exclusively via HTTPS (TLS 1.3). Passwords are not stored (passwordless authentication via Magic Link).
9. Minors
Our service is intended for adults. We do not knowingly collect data from persons under 16 years of age.
10. Changes
We reserve the right to update this policy. The current version is always available at syslia.de/datenschutz.
Updated: September 21, 2026 · Imprint · Disclaimer · GDPR Request