Privacy Policy
Last updated: October 11, 2026
1. Controller
The controller responsible for data processing on www.ofmate.eu is:
OF Mate
Ort
Deutschland
E-mail: Admin@ofmate.eu
2. What this is about
This website is a closed area in which invited persons can upload images and videos after logging in. There is no public service, no advertising, no tracking and no analytics services. User accounts are created exclusively by us.
3. Accessing the website and server logs
When you access the website, our hosting provider automatically processes technical data transmitted by your browser: IP address, date and time, the page accessed, the amount of data transferred, browser and operating system, and the previously visited page. This data is necessary to deliver the website and to ensure its security (e.g. defending against attacks). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and stable operation of the website. The logs are deleted by the hosting provider after a short period. We have concluded a data processing agreement with the hosting provider (Art. 28 GDPR).
The connection is encrypted using TLS (HTTPS).
4. User account and login
For each user account we store: user name, display name, role, the password solely as a non-reversible hash value, whether the password must be changed at the next login, and the time the account was created. This data is required to provide you with access (Art. 6(1)(b) GDPR). It is deleted as soon as the user account is deleted.
To protect against password guessing, we keep track of failed login attempts. For this purpose the IP address is stored only in encrypted form (as a hash value) and deleted after no more than 15 minutes (Art. 6(1)(f) GDPR – protection of user accounts).
For notifications about new uploads, we store the e-mail addresses entered by us (e.g. those of our team), when they were entered and for which accounts they receive notifications. The notification contains only the name of the account that uploaded something; it is sent via our e-mail provider.
5. Cookies
We use only one technically necessary session cookie (“fotoupload”). It keeps you logged in after login, protects forms against misuse and becomes invalid when you close the browser or after 2 hours of inactivity. No consent is required for this (Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). We do not set cookies for advertising or analytics purposes.
6. Uploaded images and videos
Files that you upload are temporarily stored on our web server during the upload, checked (file type, size) and then transferred to their storage location; the temporary copy is deleted immediately. Depending on the settings of your user account, the storage location is
- an FTP storage operated by us at our hosting provider, or
- the Google Drive of our agency account, in a separate folder for your user account (see section 7).
In addition, for each upload we store the original and the stored file name, the size, the target folder and the time, so that you can view your recent uploads (the last 200 entries per account). Images and videos may contain personal data, in particular depictions of persons and embedded metadata (e.g. time of capture, camera, possibly location). The processing is carried out to fulfil the agreement concluded with you (Art. 6(1)(b) GDPR). The files are stored for as long as necessary for this purpose or as long as statutory retention obligations apply.
7. Google Drive
Our agency can connect one Google account of our agency to the website. Uploads are then stored directly in the Google Drive of this account, in a separate folder for each user account.
What data we receive from Google and store: the e-mail address of the connected Google account (to display which account is connected) and an access key (“refresh token”) that allows the website to upload files to this Google Drive. The key is stored on our server and is not shared with anyone.
Scope of access: The website uses exclusively the
drive.file scope. This means it has access only to the folders and files it has created itself.
The website can neither see nor modify any other content of the Google Drive.
Use: The data is used exclusively to create folders and to store uploaded files. It is not used for advertising, not sold and not transferred to third parties; humans read it only where necessary for support or security purposes or where you have given your consent.
The use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revocation: The connection can be disconnected at any time in the user management; the access key is then deleted and revoked at Google. You can also revoke access yourself at myaccount.google.com/connections. Files that have already been uploaded remain in the Google Drive.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC in the USA; Google is certified under the EU-U.S. Data Privacy Framework. For files stored in Google Drive, the Google Privacy Policy also applies. The legal basis is Art. 6(1)(b) GDPR or, respectively, your consent when connecting (Art. 6(1)(a) GDPR).
To connect an account, the user management (only for our agency) loads a sign-in script from accounts.google.com. In the process, your IP address is transmitted to Google.
7a. Threads
For accounts whose Threads profiles we have connected, we publish images, videos and texts selected by us on these profiles – manually or according to a set schedule. We may import images and videos for this purpose from a Google Drive folder shared via link into our FTP storage. For this purpose we store, for each profile, the user name, the account ID and an access key that is renewed automatically. The files to be published are located on our FTP storage and are made available to Meta for publishing via a secret, time-limited link. The provider is Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland; the Threads Privacy Policy also applies. The connection can be disconnected at any time.
8. Recipients
Your data is transmitted only to the service providers named above (hosting provider, e-mail provider and – for connected accounts – Google or Meta). Within our team, only persons who need access for their tasks have access. Data is not disclosed to any other third parties unless we are legally obliged to do so.
9. Your rights
You have the right of access (Art. 15 GDPR), the right to rectification (Art. 16), the right to erasure (Art. 17), the right to restriction of processing (Art. 18), the right to data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21). You may withdraw any consent you have given at any time with effect for the future (Art. 7(3)). To do so, please contact us at the contact address stated above.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the federal state or Member State of your habitual residence or of our place of business.
10. Data security
We protect your data through encrypted transmission (HTTPS), storing passwords as hash values, protection against password guessing, role-based access restrictions and storing configuration and user data outside the publicly accessible area.