Privacy Policy for the Maty App

What you need to know when you use Maty.

How do we handle your data and your customers' data?

Let's get started:

1. All collected data serves to fulfil our shared business.

2. None of your data is resold to strangers or third parties.

3. We use third-party providers to run our business, for example server infrastructure to store your data, which also makes your data accessible from anywhere.

4. None of your customer data is visible to outside third parties; you have an individually password-protected area on our database that only you can access.

We handle your data responsibly.

You're able to use Maty largely anonymously. You don't have to enter your personal data, though you can if you'd like, for example to have an invoice created. Below we've laid everything out for you as precisely as possible. Of course you can delete your data, and you can also have your account deleted irrevocably.

We want Maty to help you manage your customers efficiently and easily. At the same time, we want to make sure that access to your data is kept secure within a sensible framework. This principle guides everything we do. We hope to give you, with the greatest possible care, an overview of how we handle your data responsibly.

Privacy policy

This policy supplements our general privacy policy at matyapp.de/en/datenschutz with the data processing that takes place within the Maty software. Terms, legal bases, retention periods and your rights as a data subject are explained there in detail and apply here accordingly. For the processing of your customers' data (e.g. pet owner data) that you have us process on your behalf when using Maty, we additionally conclude a separate data processing agreement (DPA) with you pursuant to Art. 28 GDPR.

Controller

DigiVET UG (haftungsbeschränkt)
Sandra Reinheckel
Bergedorfer Str. 13
27726 Worpswede
Germany

TEL: 04792 9879035
E-Mail: info@digiVET-solutions.de
Webseite: matyapp.de

Data Protection Officer

Our Data Protection Officer is:
Vanessa Auferkamp
DigiVET UG (haftungsbeschränkt)
Bergedorfer Str. 13
27726 Worpswede
Germany

Tel.: 04792 9879035
E-mail: hello@matyapp.de

If you have any questions or concerns about data protection, you can contact our Data Protection Officer directly at any time.

Registration Function

You can create a user account. As part of registration, the required mandatory information is communicated to you and processed on the basis of Art. 6(1)(b) GDPR for the purpose of providing the user account. The data processed includes, in particular, the login information (name, password, and an email address). When you log in and use the account, we also store the IP address and time of the action to protect against misuse; the IP address is anonymized or deleted after 7 days at the latest.

If you terminate your user account, your data relating to the account will be deleted, subject to statutory retention obligations. It is your responsibility to back up your data before the end of the contract.

Contact

When you contact us (e.g. via contact form, email, or phone), we process your information to handle the request on the basis of Art. 6(1)(b) or (f) GDPR. We delete inquiries once they are no longer needed.

Hosting of the Maty Software

The Maty software is operated and hosted at DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA, in data centers within the European Union. DigitalOcean processes the data as a processor on the basis of a data processing agreement pursuant to Art. 28 GDPR, including the EU Standard Contractual Clauses; DigitalOcean, LLC is also certified under the EU-U.S. Data Privacy Framework. Access from the USA, for example for maintenance or support purposes, cannot be ruled out in individual cases. The legal basis is Art. 6(1)(b) GDPR (performance of contract) as well as Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation).

For a clear disclosure of the storage, use, purpose, and retention period of your data in the interest of compliance with the European GDPR, we have listed below the database fields that are populated with personal data or are related to personal data.

We have translated the names of the database fields into understandable terms and tried to add a purpose and a description so that the background of the data storage becomes clear to you. Please contact us with any questions or comments; you can refer to the numbers when doing so.

Here we go:
No. 01
Table Name: 
Users
Field Name: Customer ID
Purpose: A unique user identification number is stored for each user, which serves to uniquely identify the user.
Description, Addition, Handling: Generated automatically upon registration.
Storage Duration: Maximum 10 years after the last update.

No. 02
Table Name: 
Users
Field Name: Email
Purpose: The email is required for registration and login. The email address is the element to which a new registration is assigned.
Description, Addition, Handling: The email is a required field. It is requested and must be confirmed during the registration process.
Storage Duration: Maximum 10 years after the last update.

No. 03
Table Name: 
Users
Field Name: Password
Purpose: The password is part of registration and login. The combination of email and password allows identification as an authorized person.
Description, Addition, Handling: The password is also a required field; it is stored encrypted according to current standards and requested during login. The password can be changed at any time.
Storage Duration: Maximum 10 years after the last update.

No. 04
Table Name: 
Users
Field Name: Remember Token
Purpose: "Remember Token": This token is not stored for authentication processes, but is only used for detecting and identifying malware.
Description, Addition, Handling: Method for protecting against malware
Storage Duration: Maximum 10 years after the last update.

No. 05
Table Name: 
Users
Field Name: Email Verification Token
Purpose: We store an email verification token in order to implement the two-step registration process and make it more secure.
Description, Addition, Handling: During registration, this token is sent both to the user's email address and stored in the system, and is then matched during email address validation.
Storage Duration: Maximum 10 years after the last update.

No. 06
Table Name: 
Users
Field Name: Confirmed Status
Purpose: We store the status of whether an email has been verified/validated or not. This status is part of the registration or login process running in the background.
Description, Addition, Handling: The default value is null and is set to 1 upon email validation. As soon as the email is considered verified, the verification prompt disappears during login.
Storage Duration: Maximum 10 years after the last update.

No. 07
Table Name: 
Users
Field Name: User Role
Purpose: We assign certain user roles to registered persons, which govern their rights and different types of access. This role is also essentially used and checked with the payment function.
Description, Addition, Handling: There are various roles, e.g. the role of "Administrator", regular "User", or "Test User". Test users, for example, only have limited access to the video course material, e.g. following a referral or as part of marketing campaigns.
Storage Duration: Maximum 10 years after the last update.

No. 08
Table Name: 
Users
Field Name: IP Address
Purpose: We store users' IP addresses to ensure identification and, in particular, to be able to trace offensive or illegal comments.
Description, Addition, Handling: In accordance with current GDPR requirements, the IP address is stored only in encrypted or shortened form.
Storage Duration: Maximum 10 years after the last update.

No. 09
Table Name: 
Users
Field Name: Activity Status
Purpose: We store a status indicating whether a user, test user, or administrator is active or inactive. This makes it possible to temporarily or permanently deactivate users, test users, or administrators without deleting their data. Deactivation can be used to first clarify the behavior of users or administrators if it appears questionable. For example, a deactivation can occur in the event of a failed payment or if the order for the product was returned.
Description, Addition, Handling: Activation occurs automatically upon registration; deactivation or reactivation can be carried out by the operator of the portal or by the administrator, and represents a preliminary step toward the complete deletion of the data.
Storage Duration: Maximum 10 years after the last update.

No. 10
Table Name: 
Users
Field Name: Referred-By Status
Purpose: The "Referred By" field serves the customer-refers-a-customer function, i.e., the referral function. It records when a user was referred by another user. This makes it possible to ensure that a referrer can receive recognition, attention, or compensation for their referral, if applicable.
Description, Addition, Handling: The online school offers this option as a customer-refers-a-customer function, i.e., a referral function.
Storage Duration: Maximum 10 years after the last update.

No. 11
Table Name: 
Users
Field Name: Deactivated On
Purpose: The soft-delete status (deactivation) shows a timestamp of when a user's status was deactivated, in order to document this process.
Description, Addition, Handling: A soft delete does not delete the data, but rather deactivates it.
Storage Duration: Maximum 10 years after the last update.

No. 12
Table Name: 
Users
Field Name: Created On
Purpose: "Created On" is a timestamp that stores the time of registration, so that functions can be derived from it. For example, individual lessons with time-controlled content can only be unlocked at certain points in time, in order to offer a progressive, purposeful, and effective learning experience.
Description, Addition, Handling: The "Created On" entry is created upon initial registration and is automatically executed by the "Save" function.
Storage Duration: Maximum 10 years after the last update.

No. 13
Table Name: 
Users
Field Name: Updated On
Purpose: "Updated On" is a timestamp that stores the time of the last changes, so that functions can be derived from it and made traceable.
Description, Addition, Handling: The "Updated On" entry is automatically executed by the "Save" function, so this does not need to be done manually.
Storage Duration: Maximum 10 years after the last update.

No. 14
Table Name: 
User Meta Information
Field Name: First Name
Purpose: The first name is also requested during registration and is used for personal address.
Description, Addition, Handling: This allows users to be addressed personally, e.g. in emails, etc.
Storage Duration: Maximum 10 years after the last update.

No. 15
Table Name: 
User Meta Information
Field Name: Last Name
Purpose: Providing the last name is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is only needed to generate an invoice, if one is requested.
Description, Addition, Handling: If no invoice is required, this field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 16
Table Name: 
User Meta Information
Field Name: Company
Purpose: Providing the company name is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is only needed to generate an invoice, if one is requested.
Description, Addition, Handling: If no invoice is required, this field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 17
Table Name: 
User Meta Information
Field Name: Phone Number
Purpose: Providing the phone number is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is needed if the customer wants to allow the operator to call back in service cases.
Description, Addition, Handling: This field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 18
Table Name: 
User Meta Information
Field Name: Address
Purpose: Providing the address is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is only needed to generate an invoice, if one is requested.
Description, Addition, Handling: If no invoice is required, this field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 19
Table Name: 
User Meta Information
Field Name: Postal Code
Purpose: Providing the postal code is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is only needed to generate an invoice, if one is requested.
Description, Addition, Handling: If no invoice is required, this field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 20
Table Name: 
User Meta Information
Field Name: City
Purpose: Providing the city is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is only needed to generate an invoice, if one is requested.
Description, Addition, Handling: If no invoice is required, this field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 21
Table Name: 
User Meta Information
Field Name: Country
Purpose: Providing the country is voluntary; since the European GDPR came into effect, it is no longer stored as mandatory, but only voluntarily. This information is only needed to generate an invoice, if one is requested.
Description, Addition, Handling: If no invoice is required, this field can be left blank; providing it is voluntary.
Storage Duration: Maximum 10 years after the last update.

No. 22
Table Name: 
Payment System
Field Name: All Fields
Purpose: For payment transactions, we use the payment service provider Digistore24 GmbH as reseller and payment processor; no more data than necessary is stored on our own server. Details can be found in our general privacy policy (matyapp.de/datenschutz, section 12).
Description, Addition, Handling: This field is part of the payment function via the payment provider.
Storage Duration: Maximum 10 years after the last update.

As of: September 2026