Skip to main content

Privacy Policy for the Website multidoc-converter.com

Version 2.0 dated 13.09.2026

This Privacy Policy informs you which personal data is processed when visiting the website multidoc-converter.com, during downloads, when using the contact form, and when using other website functions.

For the use of the software MultiDoc Offline Converter in the FREE and PRO variants, the separate Privacy Policy for MultiDoc Offline Converter also applies.

1. Controller

The controller responsible for data processing in connection with this website is:

Pawel Idzikowski
trading as Polenter - Software Solutions
Hans-Kalscheuer-Str. 45
51149 Köln
Deutschland

Email: info@multidoc-converter.com
Privacy contact: privacy@multidoc-converter.com
Website: https://multidoc-converter.com

2. No Data Protection Officer

No data protection officer has been appointed because, according to the current assessment, there is no legal obligation to appoint a data protection officer.

3. Competent Supervisory Authority

The competent data protection supervisory authority is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

4. Scope of this Privacy Policy

This Privacy Policy applies to the website multidoc-converter.com and the website functions associated with it.

This includes in particular:

  • visiting the website,
  • accessing individual web pages,
  • downloading installation and ZIP files,
  • accessing static files,
  • the contact form,
  • email communication,
  • external links,
  • YouTube links or two-click solutions,
  • local storage of the theme selection in the browser.

Downloads may be provided via the domain assets.polenter.com. The contact form may be technically processed via contact.wincognito.eu.

The separate Product Privacy Policy applies to the use of the MultiDoc Offline Converter software itself.

5. Technical Provision of the Website

The website multidoc-converter.com is a static website. It is generated with Docusaurus.

The website is hosted as multisite web hosting by OVH. The website may be delivered via a CDN that is part of the OVH multisite package.

Only local content, fonts, and assets provided on the controller's own hosting are used to display the website. No external fonts, external tracking scripts, or external analytics services are loaded when the website is merely accessed.

For the technical provision of the website, server log data may be processed when the website is accessed. This may include in particular:

  • IP address,
  • date and time of access,
  • requested file or URL,
  • amount of data transferred,
  • referrer URL, if transmitted by the browser,
  • browser user agent,
  • HTTP status code,
  • technical connection and security information.

These data are processed to deliver the website, ensure technical security, analyze errors, and prevent misuse.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable, and functional provision of the website.

6. OVH Hosting, CDN, and Server Logs

The website is hosted by OVH. Server logs may be generated as part of OVH hosting.

These may include in particular:

  • IP address,
  • date and time of access,
  • requested file or URL,
  • amount of data transferred,
  • referrer URL, if transmitted by the browser,
  • browser user agent,
  • HTTP status code,
  • technical connection and security information.

These data are processed to deliver the website, ensure technical security, analyze errors, and prevent misuse.

According to the current state of knowledge, these logs may be stored for up to twelve months as part of the OVH standard service. The controller has only limited influence over the deletion of these standard logs by OVH insofar as they arise within the standard service.

OVH may also provide server statistics based on raw data from server logs. The controller does not create its own personal visitor profiles from these statistics and does not perform its own tracking analysis of individual visitors.

A data processing agreement is in place with OVH.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in hosting, technical security, error analysis, and misuse prevention.

7. Downloads via assets.polenter.com

Downloads of large files, such as .exe or .zip files, may be provided via dedicated static hosting under the domain assets.polenter.com.

When download files are accessed, server log data may be generated for technical reasons. This may include in particular:

  • IP address,
  • date and time of the download,
  • requested file,
  • amount of data transferred,
  • referrer URL, if transmitted,
  • user agent,
  • HTTP status code.

These data are processed to provide the download files, ensure technical security, analyze errors, and prevent misuse.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and reliable provision of downloads.

8. No Cookies

This website does not use cookies.

In particular, no session cookies, tracking cookies, or analytics cookies are used.

No cookie or consent banner is used as long as no cookies, trackers, or external content requiring consent are loaded before the user's consent.

9. LocalStorage for Theme Selection

When the website is visited for the first time, the website does not store anything in the user's browser.

If the user uses the light/dark theme switch, the website may store the selected theme setting locally in the browser. Only a text value such as dark or light is stored.

This storage serves exclusively to retain the website display selected by the user for the next visit.

The legal basis for any processing of personal data is Art. 6(1)(f) GDPR. The legitimate interest lies in a user-friendly presentation of the website.

Insofar as information is stored on or read from the user's terminal device, this is done to provide the display expressly requested by the user. The legal basis for this storage on the terminal device is Section 25(2) No. 2 TDDDG.

10. Contact Form

A contact form may be provided on the website. The contact form is technically operated via the domain contact.wincognito.eu. contact.wincognito.eu is the controller's own technical domain and not an external service provider.

The mandatory fields of the contact form are:

  • sender email address,
  • message,
  • acknowledgment of the privacy policy.

A file attachment is optional.

When the contact form is submitted, the data entered by the user are processed. This may include in particular:

  • email address,
  • message text,
  • optional file attachment,
  • time of the request,
  • technical processing data, insofar as required for transmission, security, and error analysis.

The form data are transmitted to the form backend in encrypted form (TLS). The form backend processes the data exclusively to generate the request as an email and forward it in encrypted form (via TLS) to the controller's own email server. The requests are not stored or kept permanently in a web database on the web server.

When the contact form is submitted, no IP address is deliberately evaluated and permanently stored with the request. Likewise, no additional technical metadata such as user agent or referrer are deliberately stored with the support request unless this becomes necessary for security, error analysis, or misuse prevention reasons.

Contact requests are processed to answer the request, provide support, analyze errors, or conduct pre-contractual or contractual communication.

The legal basis is Art. 6(1)(b) GDPR insofar as the request is related to a contract, a license, a purchase, or pre-contractual measures. In all other cases, the legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in handling requests and communicating with users.

11. File Attachments in the Contact Form

Users may voluntarily submit file attachments if the contact form permits this.

File attachments may contain personal data. Users are asked not to submit sensitive or particularly protected data unless these are strictly necessary for processing the request. This includes in particular health data, passwords, access credentials, credit card data, or other confidential information.

The maximum size of a file attachment is currently 20 MB.

Incoming emails and attachments may be automatically checked by the email server using antivirus software for known malware signatures. Beyond this, no automatic server-side content, file type, or format inspection of attachments currently takes place.

After downloading an email with an attachment, the controller may additionally open the attachment in an isolated test environment and scan it locally with antivirus software.

File attachments are stored for as long as this is necessary to process the request.

The legal basis is Art. 6(1)(b) GDPR insofar as the attachment is necessary to process a contract-related request. In all other cases, the legal basis is Art. 6(1)(f) GDPR.

12. Email Communication

Support and other communication may take place by email.

During email communication, the data transmitted by the user are processed. This may include in particular:

  • email address,
  • name, if provided,
  • content of the message,
  • times of communication,
  • attachments,
  • technical email metadata insofar as they arise during email transport.

The email client communicates with the controller's own email server via TLS. During communication with other email servers, transport encryption depends on whether the respective external mail server supports TLS.

No external ticketing system such as GitHub, GitLab, Trello, Jira, or Zendesk is used for support requests.

The legal basis is Art. 6(1)(b) GDPR insofar as the communication is necessary for contract performance, license management, or a pre-contractual request. Otherwise, the legal basis is Art. 6(1)(f) GDPR.

13. YouTube Videos and Two-Click Solution

The website may contain embedded players and links to YouTube videos. The controller operates its own YouTube channel.

YouTube videos are not embedded automatically when the website loads. Instead, simple links or a two-click solution may be used.

With the two-click solution, self-hosted screenshots or preview images are used. Before the user clicks, no YouTube content should be loaded and no connection to YouTube or Google should be established.

Only when the user clicks a YouTube link or actively opens a YouTube video can a connection to YouTube or Google be established. Personal data may then be processed by YouTube or Google. The controller has no influence over this processing.

The privacy policies of the respective provider apply to processing by YouTube or Google.

The legal basis for providing YouTube links or a two-click solution is Art. 6(1)(f) GDPR. The legitimate interest lies in the user-friendly provision of product information, tutorials, and supplementary content.

The website may contain links to external websites, including:

  • YouTube,
  • antivirus providers,
  • Microsoft documentation,
  • sales and marketing partners,
  • other external information pages.

When the user clicks an external link, they leave the controller's website. The respective provider is responsible for data processing on the linked websites.

The controller has no influence over which personal data are processed by the operators of external websites.

15. Website Statistics

OVH may provide server statistics as part of the hosting package, based on raw data from server logs.

The controller does not use its own analytics or tracking services such as Google Analytics, Matomo, Plausible, or comparable services.

The controller occasionally accesses the server statistics provided by OVH for technical error analysis and to check the availability of the website, but does not create personal visitor profiles or behavioral tracking of individual visitors from them.

The legal basis for the use of technical server statistics is Art. 6(1)(f) GDPR. The legitimate interest lies in technical error analysis, security monitoring, and improving the website.

16. Contact Form Backend, Servers, and Backups

Servers and hosting infrastructure may be used for website-related services.

The following services in particular may be operated on servers at Hetzner:

  • contact form backend,
  • mail server,
  • license server,
  • database,
  • API,
  • backups.

The server location is Germany. A data processing agreement is in place with Hetzner.

Contact requests and support emails are generally retained only for as long as necessary for processing. The current retention period is generally approximately three months or until the matter is completed, unless statutory retention obligations or legitimate interests in longer storage exist.

Full backups are maintained for the mail server and retained as a rolling buffer with a lifespan of approximately seven days.

Data for other services are backed up. These backups are stored encrypted in a Hetzner Storage Box and may be retained for up to twelve months in a ring buffer before being overwritten.

Backups may contain personal data that have already been deleted from the production systems. Backups are not used to specifically restore individual deleted requests or data unless this is exceptionally necessary for security, evidence, or recovery reasons.

Targeted deletion of individual data records from backups is technically not possible. Data may remain in backups until the next overwrite cycle.

17. Technical and Organizational Measures

The controller uses technical and organizational measures to protect personal data.

These include in particular:

  • HTTPS/TLS for the website and relevant server communication,
  • TLS communication between the contact form backend and the controller's own email server,
  • TLS communication between the email client and the controller's own email server,
  • SSH-key-based administrative access,
  • firewall,
  • encryption of backups,
  • LUKS encryption of the disk containing the license server,
  • local encryption of certain accounting data,
  • role- and purpose-based access to personal data,
  • regular backups.

18. Retention Period

Personal data are stored only for as long as necessary for the respective purposes.

The following principles apply in particular:

  • Server logs at the hosting provider OVH are stored for twelve months for IT security and error analysis reasons.
  • Contact requests and support communication are generally stored for approximately three months after completion of the matter and then deleted, unless longer storage is required.
  • File attachments are stored for as long as necessary to process the request.
  • Email communication is generally stored for approximately three months after completion of the matter, unless statutory retention obligations or legitimate interests in longer storage exist.
  • Tax-relevant documents are stored in accordance with statutory retention obligations.
  • Mail server backups are retained as a rolling buffer with a lifespan of approximately seven days.
  • Backups of other services may be retained for up to twelve months in a ring buffer.
  • Data in backups are overwritten on a regular cycle.

If statutory retention obligations exist or storage is required for the establishment, exercise, or defense of legal claims, longer storage may take place.

19. Recipients of Personal Data

Depending on the processing operation, personal data may be transmitted to or processed by the following recipients or categories of recipients:

  • OVH as hosting and CDN service provider for the website, downloads, and static files,
  • Hetzner as hosting and server service provider,
  • email service or email infrastructure,
  • tax advisors in connection with tax and accounting obligations,
  • Microsoft or PayPro Global insofar as a website request or support request is related to an order, refund, chargeback, or license management,
  • authorities, courts, or legal advisors insofar as this is legally required or necessary for legal defense.

Personal data are not disclosed to third parties for third-party advertising purposes.

20. Transfers to Third Countries

When merely visiting the website, no targeted transfer of personal data to third countries is carried out by the controller.

If the user opens external links, in particular YouTube or Google services, data processing may be carried out by the respective providers. The controller has no influence over this.

Insofar as a website request or support request is related to an order through PayPro Global (PAYPRO GLOBAL, INC., 225 The East Mall, Suite 1117, Toronto, Ontario, Canada, M9B 0A9), PayPro Global may be involved. PayPro Global is based in Canada. An adequacy decision by the European Commission exists for Canada insofar as the relevant processing falls within its scope.

If the software is purchased through the Microsoft Store, purchase processing, payment processing, and, where applicable, licensing are handled through infrastructure provided by Microsoft. In this context, Microsoft may process personal and technical data under its own responsibility. Depending on the systems and service providers used by Microsoft, personal data may also be processed outside the European Union or the European Economic Area. Such processing is subject to Microsoft's applicable privacy policies and terms. The controller does not itself initiate any targeted transfer of personal data to a third country in connection with a purchase through the Microsoft Store.

In addition, transfers to third countries may occur during email communication if the user is located outside the European Union or the European Economic Area or uses corresponding communication services.

21. No Automated Decision-Making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

22. No Disclosure for Advertising Purposes

The controller does not sell personal data to advertisers and does not disclose personal data for third-party advertising purposes.

The website may display references to the controller's own products, offers, or events. No individual tracking of website visitors takes place in this context.

23. Rights of Data Subjects

Data subjects have the following rights in accordance with the statutory requirements:

  • right of access,
  • right to rectification,
  • right to erasure,
  • right to restriction of processing,
  • right to data portability,
  • right to object to processing based on legitimate interests,
  • right to withdraw consent given with effect for the future,
  • right to lodge a complaint with a data protection supervisory authority.

To exercise these rights, the user may contact the controller at privacy@multidoc-converter.com.

24. Objection to Processing Based on Legitimate Interests

Where personal data are processed on the basis of Art. 6(1)(f) GDPR, the user has the right to object to this processing on grounds relating to their particular situation.

The controller will then no longer process the personal data unless there are compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the user, or the processing serves the establishment, exercise, or defense of legal claims.

25. Obligation to Provide Certain Data

For a mere visit to the website, the user does not have to actively enter any data. However, technically required server log data are generated when the website is accessed.

To use the contact form, at least an email address and a message are required so that the request can be processed and answered.

Without these details, a contact request cannot be processed or can be processed only to a limited extent.

26. Changes to this Privacy Policy

This Privacy Policy may be updated if the website, the services used, the data processing, the technical processes, or the legal requirements change.

The current version is available online at:

https://www.multidoc-converter.com/legal/privacy/

27. Relationship to the Product Privacy Policy

This Privacy Policy applies to the website multidoc-converter.com and the associated website functions.

For the use of the software MultiDoc Offline Converter, in particular local processing, license activation, license server, PRO license, news and update retrieval from the software, and product-related support cases, the separate Product Privacy Policy also applies.

It is available at:

https://www.multidoc-converter.com/legal/msstore-product-privacy/