Privacy Policy – EMVI Media

Privacy Policy

Last updated: August 2026

1. Privacy at a Glance

General Information
The following information provides a simple overview of what happens to your personal data when you visit our website (including all associated subdomains) or use our Progressive Web App (PWA) for premium in-store audio systems. Personal data is any data with which you can be personally identified.

Data Controller
Data processing on this website and within the streaming systems is carried out by the website operator:

Emir Vildić
EMVI Media
Leopoldstraße 31
80802 Munich
Germany
Phone: +49 89 99857895
Email: privacy@emvimedia.de

Data Protection Officer
A statutory data protection officer is not required for our company according to Section 38 BDSG. For questions regarding data protection, you can contact the responsible party directly at the email address provided above.

2. Hosting and IT Infrastructure

We use various hosting providers to deliver our online offering and streaming services. The hosters are used for the purpose of fulfilling the contract with our customers (Art. 6 Para. 1 lit. b GDPR) and in the interest of a secure, fast, and efficient provision of our B2B online offering by professional providers (Art. 6 Para. 1 lit. f GDPR).

Website Hosting (Hostinger)
Our main website and domain are hosted by an external service provider. The personal data collected during a mere visit to this website (especially IP addresses and metadata) are stored on the servers of this hoster. Our hoster for the website is:

Hostinger, UAB
Švitrigailos str. 34
03230 Vilnius
Lithuania

Audio Streaming Server (Hetzner Cloud)
Our audio streaming infrastructure is hosted by a separate service provider. The data generated in the streaming system (e.g., stream logins, zone assignment, IP addresses of the end devices when accessing the stream) are processed on these servers. Our hoster for the streaming services is:

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany

Data Processing Agreement (DPA)
To ensure processing compliant with data protection regulations, we have concluded a Data Processing Agreement (DPA) according to Art. 28 GDPR with both of the above-mentioned providers (Hostinger and Hetzner).

SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, this site and our streaming services use SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

3. Provision of the Progressive Web App (PWA) and Local Storage

Use of the PWA via Access Link
Our audio streams are provided via a Progressive Web App (PWA). When you open the access link provided by us, the PWA is loaded in the browser of your end device.

Service Workers and Local Storage according to TDDDG
To ensure the functionality of the PWA, smooth audio playback, and offline capabilities (e.g., caching of the user interface), we use so-called “Service Workers” and the “Local Storage” of your browser. Technically necessary data (e.g., session IDs, login status, assigned stream zones for the multi-zone license) are stored locally on your end device.

The use of these technologies and the storage of information in the end user's terminal equipment is strictly necessary to provide the telemedia service explicitly requested by you. The legal basis for this is Section 25 (2) No. 2 TDDDG (technical necessity) and Art. 6 Para. 1 lit. b GDPR (contract fulfillment). No tracking of your user behavior for advertising purposes takes place.

4. Data Collection in the Streaming System and Abuse Control

Server Log Files
The provider of the pages and our streaming system automatically collect and store information in so-called server log files, which your browser or end device automatically transmits to us. These are in particular:

  • IP address used
  • Date and time of the server request
  • Simultaneous system logins
  • Information on the accessed stream (data volume, zone assignment)

Purpose, Legal Basis, and Storage Duration
The collection of this data is based on Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in the technically error-free presentation and optimization of our services as well as in the mandatory abuse control of the assigned package and multi-zone licenses. The automated analysis of IP addresses and parallel logins serves exclusively to protect against unauthorized use of the streams at non-contractually agreed locations. For security reasons, these server log files are stored for a maximum of 14 days and then automatically deleted, unless concrete evidence of illegal use requires further retention for evidence purposes.

5. Contract Fulfillment, B2B Customer Management, and E-Invoices

We process inventory data (e.g., names, company names, addresses) and contract data (e.g., used service packages: Starter, Pro, Premium; number of locations; payment information) to fulfill our contractual obligations according to Art. 6 Para. 1 lit. b GDPR. Our offer is aimed exclusively at B2B customers.

Statutory Retention Obligations and Statutory E-Invoicing Obligation
Due to commercial and tax law requirements (especially the Fiscal Code AO and the Commercial Code HGB) as well as to fulfill the statutory e-invoicing obligation in the German B2B sector, we are obliged to store invoice data (in a structured format such as ZUGFeRD or XRechnung standard) for a period of 10 years. Processing and storage are based on Art. 6 Para. 1 lit. c GDPR.

6. Payment Providers (Automated Billing)

We offer the option of fully automated payment processing for our subscription models. If you choose an automatic payment (e.g., SEPA direct debit mandate or credit card payment), your payment data will be processed accordingly and transmitted to the commissioned payment service provider. The transmission of your data is based on Art. 6 Para. 1 lit. b GDPR (contract fulfillment). We use the following payment service provider:

Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. We use Stripe, among other things, to process credit card payments and SEPA direct debits. Data transmission to the USA is legally secured by the EU-US Data Privacy Framework (DPF) and by standard contractual clauses of the European Commission. Details on data processing can be found in Stripe's privacy policy: https://stripe.com/privacy.

7. Web Fonts (Hosted Locally)

Google Web Fonts
This page uses so-called web fonts provided by Google for the uniform display of fonts. However, these are hosted locally on our servers. A connection to Google's servers does not take place. This ensures that your IP address is not transmitted to Google in the USA.

8. Contact Form

If you send us inquiries via the contact form, your details from the form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.

We use the “Contact Form 7” plugin to provide the form. This plugin does not store the data you enter in our website's database, but forwards your inquiry directly to our inbox as an email.

The processing of the data entered in the contact form is based on your explicit consent (Art. 6 Para. 1 lit. a GDPR), which you gave by checking the corresponding box before sending. You can revoke this consent at any time. An informal message by email to us is sufficient. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.

The data you entered in the contact form will remain with us (in the form of received emails) until you request us to delete it, revoke your consent for storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions – especially retention periods – remain unaffected.

9. Automated Decision-Making

Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place on our website or within our streaming services.

10. Your Rights (Data Subject Rights)

Within the framework of the applicable legal provisions, you have the right at any time to:

  • Free information about your stored personal data, its origin and recipients, and the purpose of data processing (Art. 15 GDPR).
  • Correction of incorrect or incomplete data (Art. 16 GDPR).
  • Deletion of your stored data (Art. 17 GDPR), provided this does not conflict with any statutory retention periods.
  • Restriction of data processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR).
  • Objection to processing (Art. 21 GDPR).

For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time at the email address provided in the imprint or above. Furthermore, you have the right to lodge a complaint with the competent supervisory authority:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Website: www.lda.bayern.de

error: