x70
Legal

Privacy Policy

Last updated: 2026-07-18. This Privacy Policy explains how Daniel Ensminger, trading as x70 (“we”, “us”, “our”), processes personal data when you use https://social.x70.one, https://app.social.x70.one, and related x70 Social services, in line with the EU General Data Protection Regulation (GDPR) and applicable German data protection law (BDSG).

1. Controller

The controller responsible for processing is:

Daniel Ensminger
x70

Altheimer Eck 15
80331 München
Germany
Email: contact@x70.one

See also our Imprint (Impressum).

2. Categories of personal data

Depending on how you interact with us, we may process:

  • Account & authentication data: name, email address, password hash or passkey credentials, session and device information, and two-factor authentication settings when you register or sign in.
  • Organization & membership data: organization name, membership, roles, and invitations when you create or join an organization.
  • Social content & feed data: posts, comments, reactions, profile information, and other content you publish or interact with on the platform.
  • Contact & inquiry data: name, email address, message content, and inquiry type submitted via the marketing contact form.
  • Newsletter data: email address and subscription status if you opt in.
  • Payment data: billing email, customer ID, and subscription/invoice status processed by our payment provider (Stripe), where paid plans or subscriptions apply. We do not store full card numbers on our servers.
  • Technical data: IP address, browser type, device information, pages visited, referrer, and approximate location derived from IP, when analytics or security tooling is active.
  • Communications: emails and support messages exchanged with us.

3. Purposes and legal bases

We process personal data for the following purposes:

  • Providing the Social platform — accounts, organizations, feeds, messaging, and related features (Art. 6(1)(b) GDPR — performance of a contract or steps prior to a contract).
  • Responding to contact inquiries (Art. 6(1)(b) GDPR — steps prior to a contract; Art. 6(1)(f) — legitimate interest in answering business and community inquiries).
  • Processing payments and subscriptions via Stripe where applicable (Art. 6(1)(b) GDPR; Art. 6(1)(c) where required for tax/accounting).
  • Sending newsletters only with your consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
  • Security, abuse prevention, and rate limiting (Art. 6(1)(f) GDPR — legitimate interest in protecting our services).
  • Analytics and product improvement (PostHog, Vercel Analytics) only after you consent via our cookie banner (Art. 6(1)(a) GDPR). Session recording, where enabled, masks form inputs.
  • Legal obligations such as bookkeeping and responding to lawful requests (Art. 6(1)(c) GDPR).

4. Cookies and similar technologies

We use strictly necessary cookies and local storage for security, authentication, and remembering your cookie preferences. Optional analytics cookies and similar technologies (including PostHog and Vercel Analytics) are used only if you click “Accept all” on our consent banner. You can change your choice at any time via “Cookie settings” in the site footer.

Theme preference may be stored locally on your device and is not used for tracking.

5. Recipients and processors

We use carefully selected service providers who process data on our behalf under Art. 28 GDPR agreements where applicable:

  • Vercel Inc. — website hosting and edge delivery
  • Convex, Inc. — application database and authentication backend for the Social app
  • Stripe, Inc. / Stripe Payments Europe, Ltd. — payments and subscriptions (where applicable)
  • Resend, Inc. — transactional and newsletter email
  • PostHog, Inc. — product analytics (consent-based)
  • Upstash, Inc. — rate limiting / Redis where configured

We do not sell your personal data. We share data only with processors needed to operate the service, or where required by law. Content you publish on Social may be visible to other users according to the features and visibility settings you use.

6. International transfers

Some providers are based in the United States or other countries outside the EEA. Where transfers occur, we rely on appropriate safeguards such as the EU–US Data Privacy Framework (where the provider is certified) and/or Standard Contractual Clauses (SCCs), plus supplementary measures as required.

7. Retention

  • Contact inquiries: typically up to 24 months after the last meaningful contact, unless a longer retention is required.
  • Newsletter: until you unsubscribe or we delete the list entry.
  • Accounts & platform content: for the duration of your account and thereafter as required for legal claims, accounting, and tax (generally up to 10 years under German commercial and tax law where applicable). You may delete your account or content subject to the product’s capabilities and our legitimate interests (e.g. abuse investigation).
  • Analytics data: according to the configured retention in the analytics tools, and only while consent remains valid.
  • Server logs / security: for short periods needed for security and troubleshooting, unless a longer period is needed to investigate an incident.

8. Your rights

Under the GDPR you may have the right to:

  • Access your personal data (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time without affecting the lawfulness of processing before withdrawal (Art. 7(3))
  • Lodge a complaint with a supervisory authority (Art. 77), in particular Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), or the authority where you live or work

To exercise these rights, email contact@x70.one.

9. No automated decision-making

We do not use personal data for automated decision-making producing legal or similarly significant effects under Art. 22 GDPR.

10. Children

Our services are directed at adults and developers. We do not knowingly collect personal data from children under 16.

11. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be communicated via the website or email where appropriate.

12. Contact

Questions about privacy: contact@x70.one. Related documents: Terms of Service and Imprint.

Join 2,000 other interested people to get notified about updates.

+8.7K

By subscribing you consent to email updates. You can unsubscribe anytime. See our Privacy Policy.