Yasal
Gizlilik politikası
Bu sayfa Almanca (hukuken bağlayıcı) ve İngilizce dillerinde mevcuttur. İngilizce sürümünü okuyorsun.
İşletmecinin bazı bilgileri henüz girilmedi ve burada yer tutucu olarak görünüyor.
1. Controller
The controller for data processing on this website (engineer-factory.studio) and in the Engineer Factory desktop software is:
Engineer Factory
Lessingstraße 8
76684 Östringen
Deutschland
Email: kontakt@engineer-factory.de
Phone: 017662803535
2. In short
- We process personal data only as far as your account, your purchase and the use of our products require.
- There are no third-party advertising or tracking services, no social-media plugins and no external fonts: everything is served from our own server.
- Only strictly necessary cookies are set. No consent is required for them.
- Your audio files stay on your computer, and the AI functions run there. The software never uploads audio or project names to us; anonymised measurements and parameter decisions only if you expressly consent (section 9).
3. Legal bases
Depending on the purpose we process on the basis of Art. 6 (1) (b) GDPR (performance of a contract and pre-contractual steps), Art. 6 (1) (f) GDPR (legitimate interest in a secure, working service) and Art. 6 (1) (c) GDPR (statutory retention duties). We rely on consent (Art. 6 (1) (a) GDPR) only where we expressly ask for it.
4. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). You may withdraw consent at any time with effect for the future. You may also lodge a complaint with a data protection supervisory authority.
An informal message to kontakt@engineer-factory.de is enough to exercise your rights. You can also delete your account yourself at any time in the account settings.
5. Hosting and server log files
The website and the licence server run on servers operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, server location Deutschland. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
When the website is opened and whenever the software contacts the licence server, the information your browser or the software transmits is stored in server log files: IP address, date and time, the address requested, the amount of data transferred, browser or software identifier and operating system. This data serves technical delivery, stability and the prevention of attacks and is not merged with other data. The legal basis is Art. 6 (1) (f) GDPR. Log files are deleted after a short period.
6. Cookies and local storage
This website sets only strictly necessary cookies:
- __Host-mm_session (formerly mm_session) keeps you signed in. It is set only after login, is httpOnly, is transmitted only over an encrypted connection and expires after 30 days; for administrator accounts after 12 hours without activity and after 7 days at the latest. It contains nothing but a random session identifier; the session data is held on our server.
- __Host-mm_reauth is set only for administrator accounts, after the password was entered again for a security-relevant change, and expires after 10 minutes.
- mm_locale remembers your language choice, lifetime one year.
In addition, your browser stores locally (localStorage, not a cookie, never leaves your browser) whether you chose light or dark mode and whether you dismissed the cookie notice.
The legal basis for storing information on your device is § 25 (2) no. 2 TDDDG (strictly necessary); for the subsequent processing, Art. 6 (1) (b) and (f) GDPR. No cookies are set for analytics or advertising.
7. Account
For an account we process your name, email address, a password you choose (stored only as a bcrypt hash, never in plain text), your language choice and the time at which you accepted the terms and acknowledged the withdrawal notice. After registration we send you an email to confirm your address; confirmation serves account recovery and is not a precondition for use. The legal basis is Art. 6 (1) (b) GDPR. The data is stored until you delete your account.
8. The Engineer Factory desktop software
The analysis of your audio files and the AI functions run entirely on your computer. Audio data and file, project, track or plugin names are never transmitted to us; measurements only with your consent and only in the form described in section 9.
Apart from that, the software talks to our server only to verify your account and licence and to provide updates. In doing so we process:
- Sign-in: your email address and password when you log in inside the software; afterwards a random access token issued per device, stored with us only as a hash and revocable at any time.
- Devices: a non-reversible device identifier derived on your computer from stable machine properties (the properties themselves never leave the computer), a device name, the operating system and the times of activation and of the last licence check. This is how the limit of 3 simultaneously active devices is enforced.
- Licence check: the status, plan and term of your licence. The software requests them at start and periodically afterwards and receives a signed confirmation that lets it keep working for a limited time without an internet connection.
- Licence events: activation, deactivation, the start and end of a subscription and other licence events are logged with a timestamp so that questions about payments and access can be answered later.
- Updates: on start the software asks our server whether a newer version exists, which produces the log data described in section 5. We hand out the installer only to accounts with a valid licence; for this the software sends its access token.
The legal basis for sign-in, devices, licence checks and updates - including the device identifier and the periodic validation - is Art. 6 (1) (b) GDPR (provision of the licensed software), supplemented by Art. 6 (1) (f) GDPR (protection against licence abuse). You can remove devices at any time in your account or inside the software.
9. AI functions and model improvement
The AI functions of Engineer Factory ("AI Mixing", "AI Mastering", "Mixing + Mastering") measure your material and compute their proposals on your computer. No audio is uploaded for this; there is no data flow for audio.
Voluntary contribution to model improvement. Only if you expressly consent - inside the software or in your account under "AI data & privacy" - does the software send a small record to our server after an AI proposal that you apply, partly apply, undo or dismiss, so that we can improve the AI Engineer. It contains only:
- anonymised technical audio measurements of the tracks concerned (loudness, true peak, crest factor, loudness range, side-to-mid level, correlation, energy in six fixed frequency bands) - numbers only, rounded to one decimal;
- anonymised parameter decisions of the AI Engineer (kind of processor, EQ shape, frequency, gain, Q, ratio and further values from a fixed list) and whether the proposal was applied, partly applied, undone or dismissed;
- counts from a validation run (how many targeted values improved, stayed the same or got worse);
- terms from fixed lists that give the numbers meaning: track role, track kind, workflow mode, kind of request, application version and interface language.
Never transmitted - not even with consent - are passwords, payment data, information about your identity (email address, name, account ID, IP address, device identifier), audio content, names of any kind (files, folders, projects, tracks, plugins) and text you type. The software and the server accept only records with exactly this structure; anything else is discarded.
Pseudonymisation and separation from the account. A contribution is stored without account ID, email address, IP address, software or browser identifier and device identifier, separately from the account data. It carries only a pseudonym that our server derives from a random key held solely in your account and a server secret. The server log files described in section 5 are also produced by this transmission; they are not combined with the contributions.
Legal basis, withdrawal and erasure. The legal basis is your consent (Art. 6 (1) (a) GDPR). It is voluntary, not given by default, and use of the software does not depend on it. You can withdraw it at any time with effect for the future - inside the software or in your account. On withdrawal we delete all contributions stored under your pseudonym and replace the key, so later contributions cannot be linked to earlier ones. The same happens when you delete your account. If we change what is collected, we ask for your consent again; until then nothing is transmitted.
Retention. Contributions are deleted after 24 months at the latest, and immediately on withdrawal or deletion of the account.
10. Course and learning progress
While you use the course we store which lessons you have opened and completed and, for video lessons, the last playback position reached. This lets us show your progress and resume the last lesson. The legal basis is Art. 6 (1) (b) GDPR. The data is stored until you delete your account.
11. Payment processing via Stripe
Payments - one-off purchases and subscriptions alike - are handled by the payment service provider Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). The payment takes place on a page hosted by Stripe; you enter card or account details directly with Stripe, and we neither receive nor store them. Data transmitted to or processed by Stripe includes name, email address, amount, currency and payment method. From Stripe we receive a customer identifier, transaction and subscription identifiers and the payment status, which we store to match purchases and licences to your account. The legal basis is Art. 6 (1) (b) GDPR. A transfer to the USA may take place; it is safeguarded by the European Commission's adequacy decision on the EU-US Data Privacy Framework or by standard contractual clauses. Details: stripe.com/privacy.
12. Email
Transactional emails (address confirmation, password reset, purchase confirmation, notices about payments and cancellations) are sent via [henüz girilmedi]. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. Your email address and the content of the respective message are processed. The legal basis is Art. 6 (1) (b) GDPR or Art. 6 (1) (f) GDPR (account security). We do not send marketing newsletters.
13. Reach measurement
We measure use of the website exclusively with our own cookieless event log in our database. Recorded are an event name (e.g. "home page viewed", "purchase completed"), possibly your account identifier, the path requested and the language. Not recorded are IP address, browser identifier or other device characteristics; there is no combination into a profile and no transfer to third parties. The legal basis is Art. 6 (1) (f) GDPR. You may object to this processing at any time (section 4).
14. Contacting us
If you contact us by email we process your details to handle the enquiry. The legal basis is Art. 6 (1) (b) GDPR where the enquiry concerns a contract, otherwise Art. 6 (1) (f) GDPR. We delete enquiries once they are settled and no retention obligations apply.
15. Retention
We store account data, learning progress, devices and licence data for as long as your account exists. If you delete your account, sessions, access tokens, activated devices, learning progress, course access and contributions to model improvement are removed immediately and the account is anonymised. Contributions to model improvement are also deleted when you withdraw your consent and after 24 months at the latest (section 9). Information about orders and invoices is retained for up to ten years due to commercial and tax obligations (§ 257 HGB, § 147 AO) - without any link to a person once the account has been deleted.
16. Data security
Transmission is encrypted via TLS. Passwords are stored only as a bcrypt hash, session and access tokens only as hashes. Access to course content, licences and administration functions is checked on the server; security-relevant endpoints are rate-limited against automated attacks.
17. Changes
We adjust this privacy policy whenever changes to processing require it. The version published here applies.
Last updated: 18 Eylül 2026