Privacy Policy
Information on the processing of personal data on bspmarket.de
1. Controller
The controller for data processing on bspmarket.de is:
Nexthosting – Friedl & Friedl GbRVetschauer Straße 19
01237 Dresden
Germany
Phone: 03522 3523525
Mobile: +49 152 59511637
E-mail: support@nexthosting.net
Data protection requests can be made by e-mail with the subject “Datenschutz / bspmarket.de”.
2. Principles of processing
We process personal data only insofar as this is necessary for operating the platform, providing user accounts, handling purchases and downloads, running creator functions, communication, security, fulfilling legal obligations or safeguarding legitimate interests.
The legal bases are in particular Art. 6 (1) (b) GDPR for contract performance and pre-contractual measures, Art. 6 (1) (c) GDPR for legal obligations, Art. 6 (1) (f) GDPR for legitimate interests and Art. 6 (1) (a) GDPR for consent.
3. Website access and server logs
When the website is accessed, technically necessary access data is processed. This may include the IP address, date and time of access, requested URL, referrer, user agent, browser/device information, HTTP status, amount of data transferred and security events.
The purposes are delivery of the website, stability, error analysis, attack detection, abuse prevention and evidence of technical processes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the secure and reliable operation of the platform.
Server logs are only stored for as long as necessary for the stated purposes. Security-relevant logs may be kept longer where specific incidents, attacks, suspected fraud or legal claims are concerned.
4. Cookies and local storage
bspmarket.de currently uses only technically necessary cookies and local storage required for login, cart, security, cookie choice and usability of the platform. Marketing, tracking or analytics cookies are not currently active.
The legal basis for technically necessary cookies and comparable storage is § 25 (2) TDDDG. The subsequent processing of personal data takes place, depending on the purpose, on the basis of Art. 6 (1) (b), (c) or (f) GDPR.
| Name / storage location | Purpose | Storage period | Type |
|---|---|---|---|
sid | Session cookie for login, cart, CSRF protection and secure account functions. Contains no plain-text profile data, only a technical session identifier. | until logout, expiry or technical cleanup; regularly max. 14 days | necessary |
| CSRF token in the server-side session | Protection against unauthorised form and API requests. | for the duration of the session | necessary |
bspmarket_cookie_consent_v2 in local storage | Stores that the cookie notice was displayed and acknowledged. | until deleted by the user or the consent logic changes | necessary |
promo-strip-hidden in session storage | Remembers for the current browser session whether a notice banner was closed. | until the end of the browser session | necessary / convenience |
lang | Stores the chosen interface language (de/en) for the language switcher and automatic language selection. | up to 12 months | necessary / convenience |
The cookie banner informs about this necessary storage. As no optional analytics or marketing cookies are currently active, no separate tracking consent is obtained. Should optional services be integrated in the future, they will be described in the cookie banner and in this privacy policy before activation.
During payment processes via Stripe, Stripe's own cookies or comparable technologies may be used on Stripe's pages or systems. These are outside our direct control and are governed by Stripe's privacy and cookie notices.
5. User account and Discord login
Registration currently takes place via Discord OAuth. When you sign in, we process the data provided by Discord, in particular the Discord ID, username, avatar URL and technical OAuth data. Where OAuth tokens must be stored, they are stored in a technically protected manner.
The purposes are registration, login, account assignment, abuse protection, display of the profile, purchase and download management, creator functions and support. The legal basis is Art. 6 (1) (b) GDPR and Art. 6 (1) (f) GDPR for security and abuse protection.
Discord is an external service. When using the Discord login, Discord's privacy information additionally applies. This may involve data processing outside the European Union or the European Economic Area.
6. Optional Steam link
Users may voluntarily link a Steam profile. This may in particular process the SteamID64, profile name, avatar URL, profile URL and technical linking data.
The purposes are profile display, licence and account assignment, creator/buyer verification, abuse prevention, account protection and use of certain map, scanner or protection functions. The legal bases are Art. 6 (1) (b) GDPR, Art. 6 (1) (a) GDPR for voluntary linking and Art. 6 (1) (f) GDPR for security and evidence interests.
The Steam link can be removed in the account, unless overriding legal, contractual or security-related grounds prevent this.
7. Purchases, orders, invoices and downloads
For purchases and downloads we process data such as the user account, product, order number, purchase time, payment status, price, currency, tax information, download times, download status, licence assignment, product version, hash values and technical download logs.
The purposes are order processing, payment assignment, provision of digital content, proof of licence, support, warranty, withdrawal, abuse prevention, fraud prevention and legal retention. The legal bases are Art. 6 (1) (b), (c) and (f) GDPR.
Download and licence data may be stored for the duration of the licence and beyond within statutory limitation, evidence and retention periods.
8. Payment processing via Stripe
For paid purchases, coin packages, protection passes, subscriptions and other chargeable services we use Stripe as the payment service provider. The provider is in particular Stripe Payments Europe, Limited, Ireland, and affiliated Stripe companies where necessary for the respective payment processing, fraud prevention, security, billing or technical provision.
When a checkout starts, we transmit the information necessary for payment processing to Stripe, or Stripe collects it directly at checkout. This may include: e-mail address, customer/account reference, order or checkout ID, product or package name, amount, currency, payment status, billing and tax information, payment method, truncated payment references, transaction and fraud prevention data, IP address, device/browser data, timestamps and technical security information.
We do not store complete credit card or payment instrument data on our servers. Complete payment data is processed by Stripe. We store only the payment and status information required for order, licence, credit, support, evidence, accounting and legal retention, for example the Stripe checkout session ID, payment intent ID, payment status, amount, currency, order number and webhook events.
The purposes of processing are payment handling, contract performance, provision of digital content, crediting of BSP Credits or protection passes, subscription management, invoicing and accounting, fraud prevention, abuse defence, support, refunds, chargebacks and legal evidence.
The legal bases are Art. 6 (1) (b) GDPR for payment processing and contract performance, Art. 6 (1) (c) GDPR for statutory retention, tax and accounting obligations, and Art. 6 (1) (f) GDPR for secure payment processing, fraud prevention, abuse defence and legal defence.
Stripe may also process data under its own responsibility and use service providers, sub-processors or affiliated companies. This may involve transfers to countries outside the EU or EEA. According to its own information, Stripe bases such transfers on appropriate safeguards such as standard contractual clauses, adequacy decisions or other legally provided mechanisms.
Further information is provided by Stripe at https://stripe.com/privacy, on the Data Processing Agreement at https://stripe.com/legal/dpa and on service providers/sub-processors at https://stripe.com/legal/service-providers.
9. Creator functions, uploads and product management
For creator functions we process in particular application data, creator status, profile details, payment/payout data, tax details, product data, uploads, file names, hash values, scan results, approval decisions, admin comments, product versions, sales data, payout data and support/communication data.
The purposes are review and approval of creators, product publication, rights and security review, sale, payout, billing, abuse prevention, compliance with legal obligations and platform operation. The legal bases are Art. 6 (1) (b), (c) and (f) GDPR.
Where legally required, tax-relevant creator data may be retained or transmitted to the competent authorities.
10. Protection functions, fingerprints, obfuscation and scanner
For licence protection, evidence and abuse prevention, technical protection data may be processed. This includes in particular the product ID, creator ID, buyer ID, order ID, licence ID, protection ID, file hashes, product version, download time, fingerprint/carrier metadata, review results, evidence files, IP hash values and audit logs.
With buyer fingerprinting enabled, a delivered file may be provided with a secret, non-publicly visible proof that can enable later assignment to an order or licence. The proof does not serve ongoing surveillance but licence assignment, fraud prevention, account security and securing evidence in the event of unauthorised redistribution.
The legal bases are Art. 6 (1) (b) GDPR for licence-related contract performance and Art. 6 (1) (f) GDPR. Our legitimate interest lies in protecting digital content, defending against fraud, platform security and enforcing legitimate claims.
11. Reviews, comments, reports and DSA/abuse procedures
When users post reviews, comments, reports or other content, we process the entered content, account data, timestamps, affected products, processing status, moderation decisions and communication data.
The purposes are platform communication, quality assurance, reporting and reviewing illegal content, abuse prevention, enforcement of platform rules and compliance with legal obligations. The legal bases are Art. 6 (1) (b), (c) and (f) GDPR.
12. Support and communication
When users contact us, we process the data provided, contact data, message content, attachments, account data, order/product references and processing notes. The purposes are handling the request, contract performance, evidence, quality assurance and abuse prevention.
The legal bases are Art. 6 (1) (b), (c) and (f) GDPR.
13. Recipients and processors
Personal data is only transmitted to third parties where necessary or legally permitted. Recipients may in particular be hosting/server providers, payment service providers, e-mail/support providers, tax advisers, legal advisers, authorities, courts, security service providers and external login or platform services such as Discord, Steam and Stripe.
Where service providers process personal data on our behalf, we conclude the necessary data processing agreements. Where third parties act on their own responsibility, their privacy information additionally applies.
14. Third-country transfers
When using external services, in particular Discord, Steam, Stripe or other international providers, processing may take place in countries outside the European Union or the European Economic Area. Where necessary, providers base such transfers on adequacy decisions, standard contractual clauses or other legally provided safeguards.
15. Storage period
We store personal data only for as long as necessary for the respective purposes or as legally required. Decisive factors are in particular contract performance, licence duration, statutory retention periods, tax and commercial law obligations, limitation periods, security interests and ongoing disputes.
| Data category | Regular storage period / criterion |
|---|---|
| Session data | until logout, session expiry or technical cleanup |
| Server and security logs | regularly short-term; longer for security incidents, attacks or legal claims |
| Account data | for the duration of the account; afterwards deletion, blocking or anonymisation unless obligations prevent this |
| Order, invoice and payment data | according to statutory retention periods, in particular tax and commercial law requirements |
| Licence, download and fingerprint evidence | for the duration of the licence and for defending and enforcing claims within statutory limitation periods |
| Creator and payout data | for the duration of creator participation and statutory billing/retention periods |
| Support and abuse communication | as long as necessary for processing, evidence and legal defence |
Account deletion requests are generally reviewed and processed within 48 hours. Complete deletion of individual data may be excluded where statutory retention obligations, open contracts, payment records, licence records, security interests or legal claims prevent it.
16. Data subject rights
Subject to the statutory conditions, data subjects have the following rights:
- information about the personal data processed,
- rectification of inaccurate data,
- erasure of personal data,
- restriction of processing,
- data portability,
- objection to processing based on legitimate interests,
- withdrawal of consent given, with effect for the future,
- complaint to a data protection supervisory authority.
A message to support@nexthosting.net is sufficient to exercise these rights.
17. Right to complain to the supervisory authority
Data subjects may complain to a data protection supervisory authority. The authority likely responsible for us is:
Saxon Data Protection and Transparency CommissionerMaternistraße 17
01067 Dresden
Germany
Phone: +49 351 85471-101
Data subjects may also contact any other competent data protection supervisory authority.
18. Security
We take technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and unauthorised disclosure. These may include access restrictions, encryption, hashing, role/permission concepts, logging, backups and security reviews.
19. Minors
The platform is not specifically aimed at children. Minors may only use the platform where legally permitted and where the required consent of a legal guardian is present. We reserve the right to block accounts or request evidence if there are doubts about the permissibility of use.
20. Changes to this privacy policy
We may amend this privacy policy if platform functions, data processing, the legal situation or technical processes change. The version available on the platform at the relevant time applies.