Privacy
As at 27 July 2026 · Deutsche Fassung
In short: this website loads nothing from third-party servers, sets no cookies and measures no behaviour. The service itself stores what operation and accountability require — and if you run the relay yourself, we receive none of it.
1Controller
Martin Stemplinger & Tobias Aufschläger
Ilztalstraße 5, 94116 Hutthurm, Germany
E-mail: info@browserdesk.de
We are not legally required to appoint a data protection officer; please send enquiries to the address above.
2Visiting the website
This website embeds no third-party content — no external fonts, no map, video or analytics services, no content delivery network. It sets no cookies and measures no behaviour.
One exception, so that the statement holds: if you switch the language to English at the top right,
the page remembers that choice in your browser’s local storage (entry bd-lang).
This happens only in response to your action, contains no identifier relating to you and serves
solely the display you asked for — which makes it permissible without consent under
section 25(2) no. 2 TTDSG. You can remove the entry by clearing website data in your
browser.
Retrieving a page creates the technically unavoidable server logs: IP address, time, file requested, volume transferred, browser identification. The purpose is secure operation and defence against attacks; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in undisrupted operation). These logs are overwritten automatically after 14 days.
3Using the service
If you use BrowserDesk through our relay, we process the following data. The legal basis is Art. 6(1)(b) GDPR (performance of the usage relationship), and for security and log data additionally Art. 6(1)(f).
| Category | Content and purpose |
|---|---|
| Device | Name, platform, version, tags, time of first and last check-in, plus a device certificate — so a device can prove who it is. |
| Session | Target device ID, IP addresses of both sides, start and end. The content of the session (picture, input, files) is not stored and is encrypted between the endpoints. |
| Audit log | Who triggered which action and when — hash-chained, so later changes become visible. |
| Consent | Which consent was given for which capability, by whom, and for how long it applies. |
| Script runs | Script name, the person who triggered it, exit code and duration. Parameters passed in are stored masked. |
| Accounts | User name and a hash of the password (PBKDF2 with salt). Passwords are never held in clear text — device access passwords included. |
| Requests | For a subdomain request: the name requested, e-mail, organisation and the IP address of the request — for processing and against misuse. |
4Preview and recording
Screen previews and session recordings are off by default. They are created only where they have been expressly enabled for a device. Whoever switches such recording on is responsible for informing the people affected and — where required — for involving the works council. Recordings sit on the relay and can be deleted there.
5Self-hosting
If you run the relay yourself — via Docker, as a Windows service or as a Linux package — then we process none of the data above. It stays entirely on your server, and you are the controller under the GDPR. The only thing still reached from us is the update feed, whose retrieval creates the usual server logs (section 2).
6Recipients and place of processing
The service runs on a server of IONOS SE in Germany; IONOS is bound as a processor. E-mails (notifications or replies to enquiries) are also sent via IONOS. No transfer to third countries takes place. Beyond this we pass on no data unless we are legally obliged to.
Where we act as a processor for our customers, our data processing agreement under Art. 28 GDPR applies — including the list of sub-processors and the technical measures. It takes effect as soon as you request it; on request we will also sign it.
7Retention
- Server logs: 14 days, then overwritten automatically.
- Session data and device logs: 30 days. A nightly run deletes older entries automatically.
- Device and account data: for as long as the usage relationship lasts. We delete earlier on request; statutory retention duties remain unaffected.
- Database backups: the most recent 14; older ones are discarded.
- Recordings: until you delete them — they are yours.
- E-mail enquiries: until the matter is settled, then six months at most.
8Your rights
You may request access to your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object to processing based on a legitimate interest (Art. 21). Consent once given may be withdrawn at any time with effect for the future.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 27, 91522 Ansbach, Germany.
No automated decision-making or profiling takes place.
This English text is provided for convenience. In case of doubt, the German version prevails.