Javascript is disabled on your device. Please enable to use the full site.

Privacy Policy

Datenschutzerklärung

Last updated: 24 August 2026

1. Controller

The controller responsible for the processing of personal data on this website and in connection with our software products is:

QubiCast GmbH, Am alten Sportplatz 32, 52511 Geilenkirchen, Germany. Commercial register: Local Court (Amtsgericht) of Aachen, HRB 27630. Managing directors: Philipp Haller, Mitja Schmakeit. Email: contact@qubicast.com

We have not appointed a data protection officer, as we are not legally required to do so. For all questions about data protection, you can contact us at the address above.

2. General Information

We process personal data only where a legal basis under Art. 6(1) GDPR permits it. The legal basis for each processing activity is stated in the respective section below. Unless a specific retention period is stated, we store personal data only for as long as it is needed for the stated purpose, and afterwards only where statutory retention obligations (in particular under German commercial and tax law, Section 257 HGB and Section 147 AO: six or ten years for business records) require it.

This website uses TLS encryption for all connections.

3. Hosting

Our website (qubicast.com), our content management system, and the servers for our software products (including account, licensing, and diagnostics services) are operated on servers we rent from Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany. All of this infrastructure is located in Germany. Contabo processes the data handled on these servers on our behalf on the basis of a data processing agreement pursuant to Art. 28 GDPR. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the secure and reliable provision of our website and services.

4. Server Log Files

When you access our website or our product services, the web server automatically records log entries: the requested page or file, date and time of the request, transferred data volume, HTTP status, browser type and version, operating system, referrer URL, and the IP address of the requesting device. We use these logs solely to operate the services securely and reliably, to diagnose faults, and to defend against abuse; we do not merge them with other data sources to identify visitors. Log data is deleted or overwritten by rotation after a short period, unless an entry must be preserved as evidence of a specific security incident until that incident is resolved. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the technically error-free and secure provision of our services (see also Recital 49 GDPR).

5. Cookies and Local Storage

Our public website works without tracking cookies and without a consent banner, because we only use storage on your device that is strictly necessary to provide the service you request (Section 25(2) no. 2 TDDDG — German Telecommunications Digital Services Data Protection Act):

  • a functional cookie (valid for up to seven days) used only in a password-protected internal area of the site (it stores no personal data);
  • a local storage entry that remembers, on your device only, that you accepted the beta terms when signing up for a beta program;
  • when you log in to our products, the authentication state of your session is stored on your device so that you stay signed in.

These entries are not used for tracking and are not shared with third parties. Legal basis for the associated processing: Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR where the storage is needed to provide a service you have requested.

6. Web Analytics (Umami)

We use Umami, a privacy-focused web analytics service, in its hosted version operated by Umami Software, Inc. (USA), to understand in aggregate how our website is used. Umami works without cookies, does not store identifiers on your device, and does not track you across websites. When you visit a page, the following is transmitted to Umami: the page URL, referrer, browser, operating system, device type, screen size, and your country (derived from your IP address). According to the provider, IP addresses are not stored; visitors are counted using a short-lived hash that cannot be traced back to a person. Because the measurement requests are sent to Umami's servers, your IP address is technically processed by Umami in transit, which may involve a transfer to the USA.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in reach measurement and improving our website using an analytics tool designed for data minimization. You can object to this processing at any time (see section 15); the easiest way to prevent it is to use a content blocker, which Umami respects, or to disable JavaScript for our site.

7. Contact Form and Email Contact

If you use our contact form or email us, we process the information you provide (name, email address, message) to handle your inquiry. Contact form submissions are not stored in a database; they are delivered to our mailbox as an email. Our company email (including these messages) is operated through Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) as our processor; see section 13 on transfers.

To protect the form against abuse, our server performs automated spam checks (including short-term, in-memory rate limiting based on your IP address); IP addresses from these checks are held only briefly in memory, though rejected requests may additionally be recorded in our server logs (see section 4).

Legal basis: Art. 6(1)(b) GDPR where your inquiry relates to a contract or pre-contractual steps, otherwise Art. 6(1)(f) GDPR — our legitimate interest in handling inquiries addressed to us. We keep correspondence for as long as needed to deal with your inquiry and any follow-up questions, and beyond that only as required by statutory retention duties.

8. Newsletter

If you subscribe to our newsletter, we store your email address together with a confirmation status in our self-hosted content management system. We use a double opt-in procedure: the subscription only becomes active when you confirm it via the link we email to you, and we record that confirmation as proof of your consent. Newsletter and confirmation emails are sent via our Google Workspace email infrastructure (see sections 7 and 13).

Legal basis: Art. 6(1)(a) GDPR — your consent. You can withdraw your consent at any time with effect for the future by emailing contact@qubicast.com or, where a newsletter contains an unsubscribe link, by using that link. After withdrawal, your address is deleted from the newsletter list.

9. Customer Accounts and Authentication

When you create an account for our software products (QubiSet, QubiResponder), we process your email address, a password (stored only in cryptographically hashed form), your email verification status, and the licensing and entitlement data associated with your account. Account data is stored on our own servers in Germany (see section 3).

For sign-in we additionally use Firebase Authentication, a service of Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), as our processor. Firebase Authentication processes your email address, password, and technical data such as IP addresses and user agents for security purposes; according to Google, IP addresses are retained by Firebase Authentication for a few weeks, and account data of deleted accounts is removed within about 180 days. See section 13 on transfers.

Each installation of our products that is linked to an account receives an installation credential (a random installation ID and token) so that we can associate licensed devices with your account.

Legal basis: Art. 6(1)(b) GDPR — performance of the contract with you.

10. Payments and Subscriptions (Stripe)

Payments and subscriptions are processed by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; together with its affiliates including Stripe, Inc. in the USA — "Stripe"). When you purchase a subscription, we transmit your email address and an internal customer identifier to Stripe; you enter your payment details (such as card number and billing address) directly on Stripe-hosted pages — they never reach our servers. Stripe also operates the hosted customer portal in which you can manage your subscription, update your payment method, view invoices, and update your billing address and tax ID.

Stripe acts partly as our processor and partly under its own responsibility as an independent controller, in particular for fraud prevention, regulatory compliance, and the improvement of its services. Details are available in Stripe's privacy policy at stripe.com/privacy. We receive from Stripe the status of your payments and subscription and store it with your account, together with invoicing data we must retain under commercial and tax law.

Legal basis: Art. 6(1)(b) GDPR — performance of the contract; Art. 6(1)(c) GDPR for statutory retention of billing records (Section 257 HGB, Section 147 AO: six or ten years). See section 13 on transfers.

11. Transactional Email (Postmark)

Emails relating to your account and subscription — such as email verification, password reset, email change confirmation, and subscription notifications — are delivered via Postmark, a service of AC PM, LLC (an ActiveCampaign company), 1 North Dearborn Street, Chicago, IL 60602, USA, acting as our processor. Postmark processes the recipient address, the message content, and delivery metadata. See section 13 on transfers. Legal basis: Art. 6(1)(b) GDPR — performance of the contract.

12. Data Processing in Our Software Products

Update check

Our desktop applications periodically contact our servers to check for updates. This request includes the installed version, operating system type and version, system architecture, the computer's host name, and — when you are signed in — your account ID and email address, together with the IP address inherent in any internet request. We use this to provide the correct updates, to keep the products secure, and to understand which versions are in active use. Operational notifications derived from service events (such as account sign-up and sign-in, email verification, password changes, email changes, and update checks) are relayed into our internal messaging workspace operated through Google Workspace (see section 13); these notifications can include your email address, account ID, IP address, and browser/user-agent information. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the installed software up to date and secure, and in monitoring the operation of our services.

Crash reports and diagnostics (opt-in)

Our products include a diagnostics system that we operate ourselves ("QubiSink", based on the open-source Bugsink project) on our own servers in Germany — no third-party error-tracking provider is involved. Diagnostic data is only collected if you expressly consent in the app; nothing is sent before you do, and you can change your choice at any time in the app's settings.

If you enable diagnostics, the app uploads: crash reports with stack traces; application session log files; network packet captures recorded by the app during its operation (typically lighting-control protocol traffic such as Art-Net, sACN, LLRP, and RDMnet); and system information about your machine, including operating system and hardware details (CPU, GPU, mainboard, memory, and storage device identifiers such as serial numbers, and network interfaces including MAC addresses and local IP addresses). Uploads are associated with a random installation ID and, if you are signed in, with your account ID, email address, and username. Log files and packet captures can incidentally contain personal data that appears on your system or network — for example file names, device names, or network traffic content, potentially including data of third parties on your network. Please consider this before enabling diagnostics.

If you send us feedback through the app, we process the name and email address you provide, your message, and any screenshots or diagnostic snapshots you choose to attach. Feedback is transmitted even without diagnostics consent, but in that case it is limited to the information you actively submit.

We use diagnostic data exclusively to diagnose and fix faults and to improve the stability and security of our products, and we delete it when it is no longer needed for that purpose; stored diagnostic data is also rotated out by storage limits. Legal basis: Art. 6(1)(a) GDPR — your consent, which you can withdraw at any time in the app settings with effect for the future; for feedback you submit actively, Art. 6(1)(b) or (f) GDPR.

13. Recipients and International Transfers

We share personal data only with the processors and recipients named in this policy: Contabo GmbH (hosting, Germany), Google Ireland Limited (Google Workspace including our company email and internal messaging, and Firebase Authentication), Stripe (payments), AC PM, LLC / Postmark (transactional email), and Umami Software, Inc. (web analytics, see section 6) — and beyond that only where we are legally obliged to do so.

Google, Stripe, AC PM, LLC, and Umami Software, Inc. are or belong to corporate groups headquartered in the USA, so personal data can be transferred to the USA. These transfers are safeguarded by the EU-US Data Privacy Framework (Art. 45 GDPR) — Google LLC, Stripe, Inc., and AC PM, LLC are certified under it — and additionally by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) agreed in the respective data processing agreements; for Umami, whose analytics service is designed not to store personal data, any transient processing of IP addresses is likewise safeguarded by the EU Standard Contractual Clauses. You can obtain a copy of the relevant safeguards by contacting us at contact@qubicast.com.

14. Your Rights

You have the right, under the conditions of the GDPR, to:

  • access the personal data we process about you (Art. 15 GDPR);
  • have inaccurate data rectified (Art. 16 GDPR);
  • have data erased (Art. 17 GDPR);
  • have processing restricted (Art. 18 GDPR);
  • receive the data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Art. 20 GDPR);
  • withdraw any consent you have given, at any time with effect for the future (Art. 7(3) GDPR).

To exercise these rights, contact us at contact@qubicast.com. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany), but you may contact any supervisory authority.

15. Right to Object (Art. 21 GDPR)

Where we process your personal data on the basis of Art. 6(1)(f) GDPR (legitimate interests), you have the right to object at any time, on grounds relating to your particular situation, to that processing. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims. If personal data is processed for direct marketing, you can object at any time without giving reasons, and the data will no longer be processed for that purpose. To object, an email to contact@qubicast.com is sufficient.

16. No Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Please note that Stripe, as an independent controller, performs automated fraud screening of payment transactions; details are described in Stripe's privacy policy.

17. Changes to this Privacy Policy

We update this privacy policy when our services or the legal requirements change. The current version is always available at qubicast.com/privacy.