Controller & contact
The controller is the operator identified in the Imprint. Until the private operator form is completed and published, M2 GRID remains in pre-launch status. Privacy requests can be submitted through the support ticket system. The published contact email in the Imprint will also be available after launch.
Data we process
Account email, password hash, public profile, consent records, package rights, support messages, moderation requests, security logs and, with analytics consent, a pseudonymous visitor identifier and outbound-click events.
Purposes & legal bases
We process account and service data to perform the requested service; security and abuse prevention for legitimate interests; required records for legal obligations; and optional analytics or marketing only with consent. Consent can be withdrawn at any time.
Recipients, transfers & retention
Hosting, database, object storage, transactional email and Google sign-in providers receive only data needed for their service. Provider and transfer details will be updated before public launch. Sessions last up to 30 days; verification and reset tokens expire quickly; account and moderation records are kept while necessary for service, disputes and legal duties.
Your rights
You may request information, access, correction, deletion, restriction, portability or object to processing, and complain to a supervisory authority. Requests are normally answered within one month. M2 GRID does not make solely automated decisions with legal or similarly significant effects.
Security & minors
Passwords are salted and hashed; session tokens are stored as hashes and sent in secure HTTP-only cookies. M2 GRID is not intended for children under 16 without valid parental authorization where required.