Privacy Policy for the HuntingtonMod workspace
This policy describes what personal data HuntingtonMod GmbH collects, why, on what legal basis, for how long, and how you can exercise your rights under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
1 — Controller
The data controller within the meaning of Article 4(7) GDPR is HuntingtonMod GmbH, registered at the Amtsgericht München under HRB 285 741 (Amtsgericht München), with head office at Maximilianstraße 34, 80539 München, Germany, represented by its managing director Andrea Weiss. For any privacy question, write to the Data Protection Officer at dpo@huntingtonmod.org. HuntingtonMod is not affiliated with, endorsed by or connected to Huntington Bancshares Incorporated, Huntington National Bank, or Huntington Investment Company, and no personal data is ever shared with those entities.
2 — Data Protection Officer
The Company's independent Data Protection Officer is Dr. Katarina Vollmer, an external counsel appointed under Article 37 GDPR. She may be reached at dpo@huntingtonmod.org or by post at the Munich head office, marked "Data Protection Officer — personal & confidential". Response time to a substantive privacy request is five (5) working days.
3 — Supervisory authority
The competent supervisory authority for HuntingtonMod GmbH is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany. HuntingtonMod GmbH is entered in the BayLDA register under number BY-DSA-2024-08417. You have the right to lodge a complaint with the BayLDA or with the supervisory authority of your habitual residence.
4 — Categories of personal data
We collect and process the following categories of personal data: (a) identity data — first name, last name, country of residence (excluding the United States); (b) contact data — e-mail address, optional mobile telephone number; (c) billing data — SEPA payer name, IBAN, BIC, VAT identification number for business customers; (d) workspace content — journal entries, expense rows, habit checkmarks, mood dots, receipt images, subscription rows, reading log rows, gratitude cards, weekly-review PDFs, and any other content you type or upload; (e) technical data — timestamps of Magic-Link generation, source e-mail domain, first-party analytics counters (bucketed page views only).
5 — Purposes and legal bases
Personal data is processed for the following purposes and on the following legal bases: (i) opening and maintaining a Workspace and issuing invoices — Article 6(1)(b) GDPR (performance of contract); (ii) SEPA collection and accounting record-keeping — Article 6(1)(c) GDPR (legal obligation under §257 HGB and §147 AO); (iii) preventing fraud, spam and abuse of the Magic-Link mechanism — Article 6(1)(f) GDPR (legitimate interest); (iv) first-party analytics limited to bucketed page-view counters — Article 6(1)(f) GDPR (legitimate interest, no user identification); (v) responding to voluntary support requests — Article 6(1)(b) GDPR.
6 — Where your data lives
All Workspace content is stored inside the Subscriber's dedicated storage bucket, hosted at Hetzner Online GmbH, in the FSN1 data centre in Falkenstein (Sachsen) with hot-standby replication to the NBG1 data centre in Nuremberg (Bayern). No customer content is ever transferred to servers located outside the European Union. No customer content is ever shared with any entity in the United States. Backups are encrypted at rest with AES-256 in GCM mode and retained for thirty (30) days.
7 — International data transfers
HuntingtonMod GmbH does not transfer personal data outside the European Union. All sub-processors are EU-established. Where a sub-processor operates a global network — for example an outbound e-mail relay — the specific tenant used by HuntingtonMod is contractually pinned to EU data centres, verified by our DPO on the sixth working day of every calendar quarter.
8 — Sub-processors
Our current sub-processors are: Hetzner Online GmbH (Gunzenhausen, DE) — Workspace bucket hosting; Wildbit LLC / Postmark EU shard (contractually pinned to the Dublin cluster) — transactional e-mail relay; Fastmail Pty Ltd / EU shard — inbound support mailbox; SEPA Union Bayern — SEPA credit-transfer clearing. The list is published in full in the DPA and updated with fifteen (15) days' advance notice.
9 — Retention
Workspace content is retained while the Subscription is active plus a sixty (60) day grace period plus a further sixty (60) day archive period, after which it is deleted with a final receipt sent by e-mail. Accounting records are retained for ten (10) years under §147 AO. Server logs are retained for fourteen (14) days for security purposes and then discarded. Magic-Link records are retained for thirty (30) minutes after the link is issued, then discarded.
10 — Your rights under the GDPR
You have the right to (a) request access to your personal data under Article 15; (b) request rectification under Article 16; (c) request erasure under Article 17; (d) request restriction of processing under Article 18; (e) receive your data in a portable, machine-readable format under Article 20; (f) object to processing based on legitimate interests under Article 21; (g) lodge a complaint with the BayLDA or with the supervisory authority of your habitual residence. You may exercise these rights free of charge by writing to dpo@huntingtonmod.org. We respond within one calendar month.
11 — No automated decision-making
HuntingtonMod does not perform automated decision-making or profiling that produces legal effects concerning you, within the meaning of Article 22 GDPR. In particular, no credit-scoring, fraud-scoring, price-discrimination or content-filtering algorithm operates on Workspace content.
12 — No use of Workspace content for model training
HuntingtonMod commits, contractually and technically, not to use Workspace content — including but not limited to journal entries, receipt images, mood dots and gratitude cards — for the training of machine-learning models, whether proprietary or third-party. This commitment is enforced at the bucket level by an access-control list that forbids read access from any subject other than the Subscriber and the incident-response engineer on duty.
13 — Cookies and analytics
The website itself uses one strictly necessary session cookie ha_session, plus one anonymous first-party analytics counter that records the bucketed page path (never the IP address, never the user-agent string). See the Cookies page for the full list and durations. No third-party analytics platform is loaded. No Google Analytics, no Meta Pixel, no LinkedIn Insight Tag, no advertising cookies of any kind.
14 — Payments
SEPA credit transfers are processed by HypoVereinsbank München. HuntingtonMod only ever sees the payer name, the amount, the reference number and the timestamp; it never sees the payer's card details (there are none) or any other bank movement. The bank retains the transaction for ten (10) years under German commercial law.
15 — Security measures
Technical and organisational measures include: AES-256 encryption at rest for all Workspace buckets; TLS 1.3 for all traffic; Magic Link signed with an Ed25519 key rotated every thirty (30) days; office VPN with hardware token; documented incident-response playbook; annual penetration test by an external firm; two-person integrity control on any privileged database action. The full list is published in the Security Whitepaper.
16 — Children
HuntingtonMod offers services only to persons over the age of sixteen (16). If we become aware that a Workspace has been opened by a person under sixteen without verifiable parental consent, we delete it and refund any Subscription Fees within ten (10) working days.
17 — Data breach notification
In the unlikely event of a personal-data breach that is likely to result in a risk to the rights and freedoms of Subscribers, HuntingtonMod notifies the BayLDA within seventy-two (72) hours and, when required by Article 34 GDPR, notifies affected Subscribers by e-mail without undue delay.
18 — Changes to this policy
Substantive changes to this policy are announced by e-mail at least thirty (30) days before they take effect and are dated at the top of this page. The complete change history is maintained in a Git repository and can be sent to any Subscriber on request.
19 — Complaints and contact
For any question, complaint or exercise of your GDPR rights, please write to dpo@huntingtonmod.org. Postal address for privacy correspondence: HuntingtonMod GmbH, Data Protection Officer, Maximilianstraße 34, 80539 München, Germany. HuntingtonMod is not affiliated with, endorsed by or connected to Huntington Bancshares Incorporated, Huntington National Bank, or Huntington Investment Company; requests concerning US banking data cannot be handled here and must be sent to your bank directly.