Privacy Policy
1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Triple-A Soft UG (haftungsbeschränkt)
Danzigerstraße 3
88250 Weingarten
Germany
Phone: +49 (0) 751 951 264 03
Email: kontakt@aaa-soft.net
2. Principles of Data Processing
We process personal data only where permitted by law or where you have given your consent. We collect only data that is necessary for the respective purpose (data minimization).
3. Hosting
Our website and the Neleto service are hosted on servers operated by Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany). Hetzner is a GDPR-compliant European provider. We currently use server locations in the EU (Nuremberg and Falkenstein, Germany). Server locations in the USA and Asia are planned; once available, customers choose their server location when creating an instance.
For server locations outside the EU, data transfers are secured using EU Standard Contractual Clauses (SCCs). A data processing agreement (DPA) in accordance with Art. 28 GDPR has been concluded with Hetzner.
4. Access Data and Server Logs
When you visit our website, the following data is automatically stored in server log files:
- Browser type and version
- Operating system
- Referrer URL
- Hostname of the accessing computer (IP address)
- Time of the server request
This data cannot be attributed to specific individuals and is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing the service securely). Logs are deleted after a maximum of 30 days.
5. Web Analytics with Umami
To statistically analyze visits to our website, we use Umami, a privacy-friendly open-source analytics tool that we host ourselves on our own servers (Hetzner, EU). It sets no cookies and stores or reads no information on your device. Consent under Section 25 TDDDG is therefore not required.
Umami collects the following data in pseudonymized form, in particular:
- pages visited, plus date and time of access
- referring page (referrer)
- browser, operating system, and device type
- screen resolution
- the country of origin derived from your IP address
Your IP address is not stored permanently; it is only used to generate a non-traceable, daily-rotating visitor identifier (hash). The collected data does not leave our servers and is not shared with third parties.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the needs-based and economical design of our website). You may object to this processing at any time on grounds relating to your particular situation (Art. 21 GDPR). Analytics data is deleted after no more than 14 months.
6. Registration and User Account
When you register for Neleto, we collect:
- Name
- Email address
- Billing address (for paid plans)
- Selected plan and server region
The legal basis is Art. 6(1)(b) GDPR (contract performance). This data is necessary to set up your account, issue licenses, and provide the service.
7. Payment Processing (Stripe)
Payments are processed via Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). Stripe acts as an independent data controller. We transmit your order data (name, email, amount, selected plan) to Stripe to process the payment. Credit card data is stored exclusively by Stripe — we do not receive or store payment card details.
Stripe processes your data in accordance with Stripe's privacy policy: https://stripe.com/en/privacy. The legal basis is Art. 6(1)(b) GDPR.
8. Contact
When you contact us by email, the transmitted data (name, email address, message content) is stored for the purpose of processing your request. We do not share this data without your consent. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
9. Cookies
Our website only uses technically necessary cookies (e.g., session cookies for authentication). These cookies are required for the operation of the service and are set without consent (Art. 6(1)(f) GDPR). We do not use tracking or marketing cookies.
10. Embedded Videos (YouTube)
In our documentation we embed individual videos from the YouTube platform. The provider is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), part of the Google group of companies (Google LLC, USA).
We use what is known as a two-click solution. When you open a page containing a video, only a preview image stored locally on our own servers is shown at first. As long as you do not actively start the video, no connection to YouTube or Google is established and no cookies are set.
Only when you click the play button, and thereby consent, is the video loaded from YouTube. In doing so, personal data (in particular your IP address as well as information about your browser and device) is transmitted to YouTube or Google, and YouTube may set cookies on your device. We use the enhanced privacy mode (the youtube-nocookie.com domain), which according to YouTube reduces data collection.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG, which you give by clicking the button. You can withdraw your consent at any time with effect for the future by leaving or reloading the page without starting the video again.
Playback may involve a transfer of data to the US. Google LLC is certified under the EU-U.S. Data Privacy Framework, so an adequacy decision by the EU Commission applies to such transfers. Google additionally relies on the EU Standard Contractual Clauses.
For more information, please see Google's privacy policy: https://policies.google.com/privacy.
11. Newsletter
If we offer a newsletter, we process your email address based on your explicit consent (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time.
12. Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): What data we have stored about you.
- Rectification (Art. 16 GDPR): Correction of inaccurate data.
- Erasure (Art. 17 GDPR): Deletion of your data, unless statutory retention obligations apply.
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR): Objection to processing based on legitimate interests.
- Withdrawal of consent (Art. 7(3) GDPR)
- Complaint to the competent supervisory authority (Art. 77 GDPR)
Competent supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Königstraße 10a, 70173 Stuttgart, Germany.
To exercise your rights, please contact: kontakt@aaa-soft.net
13. Data Security
We use SSL/TLS encryption for the transmission of sensitive data (indicated by https:// in the address bar). Data you transmit to us cannot be read by third parties.
14. Retention Period
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention periods (e.g., 10 years for invoices under German tax law).
15. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in law or changes to our service. The current version is always available on this page.
Last updated: September 2026