Privacy policy
English (en-GB)
Controller
Where Licko acts as controller, the controller is the Licko operator identified in the Imprint. Send data-protection requests using the contact details published in the Imprint.
Roles
Some data we do not collect directly from you. For example, payment data may come from the payment provider, and data about a team member from the person who invited them. Those sources are named in this policy.
When you store other people’s personal data in Licko, for example mailing contacts, you are typically the controller of that data, and Licko processes it on your instructions.
We as controller. We determine purposes and means for account registration, authentication, billing and tax records, security and abuse prevention, product improvement of our SaaS, and (if used) public-page analytics.
You as controller / we as processor. When you store address-book entries or recipient data that identify other people, you typically determine the purpose of that processing (your mailing operations). In that context we process such data on your instructions as a processor under Article 28 of the General Data Protection Regulation (GDPR), subject to a data processing agreement if one is required.
Access to protected data. Licko may access protected data when that is needed for a function you requested. Access by Licko’s team to that content is not an ordinary part of running the service and normally requires your explicit permission. Without that permission, access is possible where it is necessary to keep the service secure or to meet a legal requirement.
Data
The account’s email address and identification data are necessary to perform the contract. Without them we cannot create or operate the account.
Licko processes recipient data, postal parameters, and materials you separately store in Licko in order to prepare and execute a sending. Addresses, generated print files, and uploaded designs are distinct from the mailing document you prepare for posting; Licko does not receive that document’s content.
Images, designs and other materials you choose to upload to Licko are stored as data of the relevant workspace. Print files Licko generates for a sending are created by Licko. They are not the mailing document.
Depending on how you use Licko, we process:
- Account — email address, account identifiers, and authentication data;
- Contract and payments — subscription, payment, invoice, and tax data needed to conclude and perform the contract and to end the contractual relationship;
- Teams — team membership and invitations;
- Postal data — sender and recipient addresses, sending parameters, purchased postage marks, and information about the sending;
- Uploaded materials — images, designs, and other materials you store in Licko;
- Print files — files Licko creates to prepare a sending;
- Settings — the Licko settings you choose;
- Technical and security data — technical logs, security events, and backup data;
- Support — your requests to us and related information.
If you choose to store postal-provider login details, we keep them for that workspace until you delete them or they are no longer valid.
Licko separates data by workspace. You may use a personal workspace or a team workspace. Members of a team workspace can access that workspace’s postal data and stored materials according to membership and permissions. Workspaces are not public profiles.
Purposes
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.
| Purpose | Data categories | Legal basis |
|---|---|---|
| Providing and securing Licko | Account; Technical and security data | Contract – Art. 6(1)(b) GDPR; legitimate interests in security – Art. 6(1)(f) GDPR |
| Evidence of legally significant interactions | Contract and payments; Technical and security data | Contract – Art. 6(1)(b) GDPR; legitimate interests in establishing, exercising and defending legal claims – Art. 6(1)(f) GDPR |
| Concluding, performing and ending the subscription | Contract and payments | Contract – Art. 6(1)(b) GDPR; legal obligation where it applies – Art. 6(1)(c) GDPR |
| Invoices and tax | Contract and payments | Contract – Art. 6(1)(b) GDPR; legal obligation – Art. 6(1)(c) GDPR |
| Team collaboration | Teams | Contract – Art. 6(1)(b) GDPR |
| Preparing and performing postal operations | Postal data; Uploaded materials; Print files | Contract – Art. 6(1)(b) GDPR; for data we process on your instructions, you as controller determine the legal basis |
| Preventing fraud and keeping the service secure | Technical and security data | Legitimate interests – Art. 6(1)(f) GDPR |
| Analysing use of public pages | Technical and security data | Legitimate interests – Art. 6(1)(f) GDPR |
| User support | Support; Account | Contract – Art. 6(1)(b) GDPR; legitimate interests – Art. 6(1)(f) GDPR, depending on the request |
| Meeting legal obligations and defending legal claims | Relevant data categories | Legal obligation – Art. 6(1)(c) GDPR; legitimate interests – Art. 6(1)(f) GDPR |
Legitimate interests. When we rely on Art. 6(1)(f) GDPR, the interests are: preventing fraud (including payment abuse); ensuring network and information security; establishing, exercising or defending legal claims; preventing circumvention of a block of the account; and understanding use of Licko’s public pages in order to improve the service. Those records are limited to what is necessary for those purposes. You may object under Art. 21 GDPR. A block of the account is not erasure of stored data.
Providers
After we transmit data to the postal operator, the operator processes it to provide the postal service under its own terms and privacy information.
| Provider | Role |
|---|---|
| Hetzner | Hosting of Licko and data storage in Germany |
| Stripe | Subscription payments, payment data and invoices |
| Cloudflare | Access to public pages and sending of service emails |
| Databuddy | Usage statistics of public pages |
| The postal operator you choose | Performance of the selected postal service |
Analytics
Databuddy is not used to identify users, for advertising, or to create profiles. It is not loaded on product and workspace pages and therefore does not observe activity you perform in them.
For analytics we do not use cookies and we do not send Databuddy account data, postal contacts, or other Licko content.
Location
Licko uses Hetzner infrastructure in Nuremberg for its primary data storage.
Transfers to countries outside the EEA are handled under the applicable GDPR transfer mechanism. Depending on the destination and circumstances, this may include an adequacy decision or Standard Contractual Clauses.
Retention
Retention periods differ by category of data and by the purpose for which the record is kept. The periods applicable in Germany are set out below.
Germany — how long we keep what
Where a period follows from German statutory retention requirements, we cite the statute by its usual abbreviation: UStG (VAT Act), AO (Fiscal Code), HGB (Commercial Code), BGB (Civil Code).
| Data | Retention | Basis |
|---|---|---|
| Postal and workspace data — addresses, uploaded materials, generated print files | Deleted from active use when you delete them in Licko. Permanently erased when they are no longer needed for the relevant workspace. Closing a personal account may end use of that personal workspace, but leaving a shared team workspace does not by itself delete its data. These data are not kept for tax records. | Storage limitation — Art. 5(1)(e) GDPR |
| Archived contractual correspondence we send (for example contract confirmation) | 6 years, counted from the end of the calendar year of sending | § 147 AO; § 257 HGB |
| Invoices, supporting accounting documents, and purchased postage marks | 8 years, counted from the end of the calendar year of issue | § 14b UStG; § 147 AO; § 257 HGB |
| Interactions with legal documents — which version you accepted or acknowledged | Kept while the account is open. After the account is closed, 3 years from the end of that calendar year | Regular limitation regime — §§ 195–199 BGB |
| Login sessions | 7 days from issue | Storage limitation — Art. 5(1)(e) GDPR |
| Short-lived security tokens (password reset, verification, and similar) | 1 hour to 48 hours from issue | Storage limitation — Art. 5(1)(e) GDPR |
| Stored postal-provider login | Until you delete it or it is no longer valid | Storage limitation — Art. 5(1)(e) GDPR |
| Support requests | Kept while the account is open. After the account is closed, they follow the same retention rules as the remaining account data | Follows the remaining account data |
| Disaster-recovery backups | Up to 90 days after deletion from live systems | Operational disaster-recovery bound; not a German statutory archive period |
Where invoices remain relevant for taxes with an unexpired assessment period, statutory retention may continue beyond the base period under § 14b UStG and § 147 AO.
If a dispute or legal claim exists or is reasonably anticipated, relevant records may be kept as long as needed to establish, exercise or defend that claim.
Security
Protection follows the purpose of each record. Account, contract, payment, membership and other operational data remain available to Licko as needed to run the service, keep it secure, and perform the contract.
Protected workspace data — in particular postal addresses, uploaded materials, generated print files, and stored postal-provider login — is stored encrypted. Licko may decrypt it when that is needed for a function you requested, but access to that content is not an ordinary part of running the service and normally requires your explicit permission, except where access is necessary to keep the service secure or to meet a legal requirement.
Storage needed for login and security is used only where necessary to operate the requested service.
The cryptographic keys required to access protected data are managed separately from the encrypted data. If the required key material becomes permanently unavailable, the affected data may be technically impossible to recover, including from an encrypted backup.
Encryption of protected data is preserved in backups. Where access can be restored, we will take reasonable technical measures to recover it. Decrypted protected data is not stored in the browser.
Rights
Under the GDPR you may access your data, have it rectified, request its erasure or restriction of processing, receive it in a portable format, and object to processing in the cases provided by law.
To exercise your rights, use the functions available in Licko or contact us using the details in the Imprint. We will consider your request within the period required by the GDPR. If the request concerns other people’s personal data that you process through Licko, we may deal with you as controller of that data.
You may contact us even when access to your account is restricted or blocked. If processing is based on legitimate interests under Article 6(1)(f) GDPR, you may object under Article 21 GDPR.
The right to erasure does not apply where further storage is required by law or needed to establish, exercise or defend legal claims. Certain data needed to prevent fraud and keep the service secure may also be kept where there is a corresponding legal basis.
You also have the right to contact a competent data protection supervisory authority directly. The data protection supervisory authority for Licko in Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
Deutschland
datenschutz-berlin.de