Privacy Policy
Last updated: 2026-07-20
This policy explains what personal data Nazmtec processes when you use Maqal at maqal.blog, why we process it, who we share it with, and the rights the General Data Protection Regulation gives you. It applies to visitors of our platform pages and to customers who run a site with us.
1. Who is responsible for your data
The controller within the meaning of Article 4(7) of the General Data Protection Regulation is Nazmtec, whose full registration details and postal address are set out in our Impressum. For any question about this policy or about how we handle your data, write to privacy@maqal.blog and we will respond within the statutory deadline of one month.
2. What data we process
We process account data that you give us, such as your name, email address, chosen language, and a securely hashed password. We process the content and media you publish, because hosting it is the service. We process technical data automatically, including your IP address, browser and device information, request timestamps, and error logs. For paid plans we process billing metadata such as your customer and subscription identifiers, the plan you hold, and invoice records; full payment card data is handled directly by Stripe and never reaches our servers. We also keep any correspondence you send us for support or abuse reports.
3. Why we process it, and on what legal basis
We process account, content, and billing data to perform our contract with you under Article 6(1)(b). We process technical data, moderation results, and security logs on the basis of our legitimate interests under Article 6(1)(f), namely keeping the platform available, preventing abuse and fraud, and maintaining reliable backups. We retain invoices and accounting records to comply with legal obligations under Article 6(1)(c). Where we ask for your consent, for example before setting any non-essential cookie, we rely on Article 6(1)(a) and you may withdraw that consent at any time with effect for the future.
4. Service providers and international transfers
We use a small number of carefully chosen processors who act only on our instructions under a data processing agreement in line with Article 28. Our hosting and outbound email are provided by Hostinger, with the servers for this platform located in the European Union. Payment processing is provided by Stripe, which may transfer data outside the European Economic Area; such transfers are covered by the European Commission Standard Contractual Clauses and supplementary safeguards. We do not sell personal data and we do not share it for third-party advertising.
5. How long we keep data
We keep account and content data for as long as your account exists. After you close your account we delete your content following a short grace period that allows you to change your mind or export your data. Encrypted backups are rotated automatically and older snapshots expire on a fixed schedule, so residual copies disappear within that window. Invoices and accounting vouchers are kept for the periods required by German commercial and tax law; since the fourth Bureaucracy Relief Act took effect on 1 January 2025 that period is eight years under section 147 of the Fiscal Code, section 257 of the Commercial Code, and section 14b of the Value Added Tax Act. Security and access logs are kept only for the short period needed to investigate incidents.
6. Your rights
You have the right to obtain confirmation of whether we process your data and to receive a copy of it under Article 15, to have inaccurate data corrected under Article 16, to have data erased under Article 17, to have processing restricted under Article 18, to receive your data in a portable format under Article 20, and to object to processing based on our legitimate interests under Article 21. To exercise any of these, write to privacy@maqal.blog. You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence or place of work.
7. Cookies and analytics
We set a session cookie that is strictly necessary to keep you signed in and to protect forms against cross-site request forgery; this requires no consent. We do not use third-party advertising cookies and we do not build cross-site profiles of visitors. Where a customer enables analytics for their own site, we collect only aggregate page-view counts without tracking individuals across sites, and we do so on the basis of our legitimate interest in providing basic audience statistics.
8. Security and data breaches
We protect data in transit with current transport encryption, store passwords only as salted hashes, encrypt our backups, and restrict administrative access to the people who need it. Uploaded media is screened before publication and served without the ability to execute code. Should a personal data breach occur that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two hours in line with Article 33 and inform affected users without undue delay where Article 34 requires it.
Questions about this policy? Contact privacy@maqal.blog.