Privacy & Data Protection

Privacy Policy.

This Privacy Policy explains how UINEXA collects, uses, stores and protects personal data when you visit the website, create an account, purchase a membership or use digital resources.

Controller Danny Hamann
Website uinexa.io
Last Updated 13 July 2026
01
General Information

Scope of this Privacy Policy

This Privacy Policy applies to the website uinexa.io and the services provided through it, including the public snippet library, downloadable resources, user accounts, paid memberships, account administration and payment processing.

Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data, including collection, storage, use, disclosure, restriction or deletion.

We process personal data only where this is necessary for operating the website, fulfilling contractual obligations, complying with legal requirements, protecting legitimate interests or where you have given valid consent.

03
Website Access

Hosting, Server Log Files and Technical Data

When you access UINEXA, the web server automatically processes technical information required to establish the connection, deliver the requested content and maintain the security and stability of the service.

This information may include:

  • IP address of the requesting device;
  • date and time of access;
  • requested page, file or resource;
  • referrer URL, where transmitted;
  • browser type, browser version and operating system;
  • HTTP status code and transferred data volume;
  • technical error, firewall and security events.

The processing is necessary for website delivery and is based on Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient provision of the website, the prevention of misuse and the investigation of technical or security incidents.

Hosting, server administration, backup, security and email providers may process this information on our behalf as processors under Article 28 GDPR. Server logs are deleted or anonymised when they are no longer required for the stated purposes, unless a longer retention period is necessary to investigate a specific incident or comply with law.

04
Security

Encrypted Transmission and Protective Measures

UINEXA uses encrypted HTTPS connections to protect information transmitted between your browser and the website. You can normally recognise an encrypted connection by the lock symbol and the use of “https” in the browser address bar.

We use appropriate technical and organisational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include access controls, password hashing, software updates, backups, security monitoring, restricted administrator access and encrypted transmission.

No method of transmission or storage can guarantee absolute security. Users are responsible for selecting a strong password and keeping their login credentials confidential.

05
Device Storage

Cookies and Similar Technologies

UINEXA uses cookies and comparable browser storage where necessary to provide login sessions, account security, membership functions, payment flows, language or display settings and consent preferences.

Technically necessary cookies may include WordPress test, authentication, security and logged-in session cookies. Depending on your selection, login cookies may be session cookies or remain stored for a limited period when “Remember Me” is used.

Access to information stored on your device or the storage of information on your device is based on Section 25(2) TDDDG where it is strictly necessary to provide a service you requested. The subsequent processing of personal data is generally based on Article 6(1)(b) or Article 6(1)(f) GDPR.

Non-essential cookies or similar technologies, including optional analytics, advertising or externally embedded services, are used only where legally required consent has been obtained. In that case, the legal basis is Section 25(1) TDDDG together with Article 6(1)(a) GDPR.

You may delete cookies through your browser settings. Blocking technically necessary cookies may prevent login, checkout, account management or other website functions from working correctly.

06
User Accounts

Registration, Login and Account Administration

When you create or use an account, we process the information required to register you, authenticate login attempts, provide account functions and manage access to free or paid content.

Depending on the information entered and the account configuration, this may include:

  • username and display name;
  • first and last name, where provided;
  • email address;
  • password stored in cryptographically hashed form;
  • account role and access permissions;
  • registration date and account status;
  • login, password-reset and security metadata;
  • IP address in security-relevant situations.

The legal basis is Article 6(1)(b) GDPR. Security logging, abuse prevention and the defence of legal claims may also be based on Article 6(1)(f) GDPR.

If you request a password reset, WordPress may include the requesting IP address in the password-reset email as a security measure.

You can view and update certain account information through the account area. Usernames may not be changeable due to technical account-identification requirements.

07
Paid Member Subscriptions

Memberships, Subscription Status and Access Control

UINEXA uses the WordPress plugin Paid Member Subscriptions to create member accounts, administer subscription plans, restrict premium content and manage membership access.

In addition to account data, the following membership and transaction-related information may be stored in the UINEXA WordPress database:

  • selected subscription plan;
  • membership start, renewal and expiry dates;
  • membership status, such as active, pending or expired;
  • billing cycle and subscription amount;
  • selected payment gateway;
  • payment and transaction reference numbers;
  • payment status and related administrative notes;
  • records of upgrades, renewals, cancellations or refunds.

This data is processed to perform the membership agreement, provide or restrict access to premium resources, maintain payment records, support account administration and respond to member inquiries. The legal bases are Article 6(1)(b) GDPR and, for legally required records, Article 6(1)(c) GDPR.

Paid Member Subscriptions runs within the WordPress installation. The use of the plugin does not by itself mean that member data is transferred to the plugin developer. Data may nevertheless be transmitted to payment providers, hosting providers, email providers or other services where required for the selected function.

08
Payment Processing

PayPal

Payments for UINEXA memberships may be processed through PayPal. The provider for users in the European Economic Area is:

PayPal (Europe) S.à r.l. et Cie, S.C.A. 22–24 Boulevard Royal
L-2449 Luxembourg

When you select PayPal, payment-related information is transmitted to PayPal or collected directly by PayPal. Depending on the transaction, this may include your name, email address, account identifiers, billing details, payment amount, currency, transaction reference, device and security information.

UINEXA generally receives only the information required to assign and document the payment, such as the payer name or email, amount, currency, transaction ID, payment status and subscription reference. We do not receive your complete PayPal login credentials or full payment instrument data.

The transfer is necessary to process the selected payment and perform the membership agreement under Article 6(1)(b) GDPR. Accounting and compliance records may be processed under Article 6(1)(c) GDPR. Fraud prevention and transaction security may be based on Article 6(1)(f) GDPR.

PayPal processes personal data under its own responsibility and may use group companies and service providers in other countries. PayPal describes its international transfer safeguards, recipients, retention practices and data subject rights in its own privacy statement.

Read the PayPal Privacy Statement
09
Digital Resources

Snippet Access, Downloads and Usage Records

When you browse, access or download snippets, cheat sheets, files or other digital resources, the website may process technical request data, account identifiers, membership permissions and the requested resource.

This processing is necessary to deliver the requested file, verify whether premium access is available, protect paid content against unauthorised access, prevent abuse and diagnose failed downloads.

The legal basis is Article 6(1)(b) GDPR for contractual or account-based access and Article 6(1)(f) GDPR for security, misuse prevention and service optimisation.

We do not use download activity to create advertising profiles unless this is expressly stated and valid consent has been obtained.

10
Communication

Email, Support and Contact Requests

If you contact us by email or through a contact or support function, we process the information you provide in order to respond to your request. This may include your name, email address, account information, message content, attachments, transaction references and technical details relevant to a support issue.

The legal basis is Article 6(1)(b) GDPR where the request relates to a contract, membership or pre-contractual inquiry. Other inquiries are processed under Article 6(1)(f) GDPR based on our legitimate interest in responding to communications and documenting support processes.

Email and hosting providers may process communication data on our behalf. Messages are retained only for as long as necessary to resolve the matter, document the communication or comply with statutory obligations.

Support messages are not used for unrelated email marketing without a separate legal basis.

11
Profile Images

WordPress Avatars and Gravatar

The UINEXA member area may display an account avatar using the Gravatar service operated by Automattic. To check whether an avatar is associated with your email address, WordPress may send an anonymised string generated from the email address, also called a hash, to Gravatar.

When a Gravatar image is loaded, the service can also receive technical connection data such as your IP address, browser information, requested image URL and time of access.

The purpose is to provide visual account identification and a consistent profile image. The processing is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in a user-friendly member interface. You may use the account without creating a Gravatar profile.

Automattic may process information outside the European Economic Area and describes applicable safeguards and data practices in its own privacy policy.

Read the Automattic Privacy Policy
12
External Services

Embedded Content and Third-Party Websites

UINEXA may link to or embed content from third-party websites, such as documentation, videos, code repositories or external resources. A normal external link does not transmit data to the destination provider until you follow the link.

Embedded content may behave as though you visited the provider directly. The provider may process your IP address, device information, cookies, account identifiers and interactions with the embedded content.

Where an embedded service is not technically necessary and requires access to information on your device or processes data for analytics or marketing, it will be activated only after consent where required. The relevant provider’s privacy information applies in addition to this Privacy Policy.

13
Recipients

Service Providers and Disclosure of Data

We do not sell personal data. We disclose personal data only where this is necessary for the purposes described in this Privacy Policy, where you have requested the disclosure or where we are legally required to do so.

Recipients or categories of recipients may include:

  • web hosting and server administration providers;
  • backup, security and maintenance providers;
  • email and communication providers;
  • payment providers, particularly PayPal;
  • WordPress-related services such as Gravatar;
  • tax advisers, accountants and legal advisers;
  • public authorities, courts or enforcement bodies where required by law;
  • other recipients where you have instructed or consented to the disclosure.

Providers acting on our behalf are bound by data-processing agreements where required. Independent providers such as payment institutions may process data as separate controllers under their own privacy policies.

14
International Processing

Transfers Outside the EEA

Some service providers or their sub-processors may process personal data outside the European Union or European Economic Area. This may apply, for example, to global payment, infrastructure or avatar services.

Where data is transferred to a country without an adequacy decision, the transfer may be protected through European Commission standard contractual clauses, binding corporate rules, additional technical and organisational safeguards, or another lawful transfer mechanism under Articles 44 to 49 GDPR.

Details concerning a provider’s international processing are available in the provider’s privacy documentation linked in the relevant section of this policy.

15
Storage Periods

How Long We Retain Personal Data

Personal data is retained only for as long as necessary for the purpose for which it was collected, unless statutory retention obligations or the establishment, exercise or defence of legal claims require longer storage.

Server and security logs For the period necessary to operate and secure the website, usually a limited period, unless an incident requires longer investigation.
Account data For the duration of the account and afterwards where required to settle the contractual relationship, prevent abuse or comply with law.
Membership and transaction data For the duration of the membership and applicable statutory accounting, tax and commercial retention periods.
Invoices and accounting records In accordance with statutory German retention requirements, which may require storage for six, eight or ten years depending on the document type.
Support and contact messages Until the inquiry has been resolved and for an appropriate documentation period, unless longer storage is legally required.
Consent records For as long as necessary to demonstrate that valid consent was obtained and to comply with limitation periods.

When a retention period expires, data is deleted or anonymised unless further processing remains legally permitted or required.

16
Data Subject Rights

Your Rights under the GDPR

Subject to the applicable legal requirements, you may have the following rights:

  • Right of access: obtain confirmation and information about personal data processed concerning you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion where no legal ground for continued processing exists.
  • Right to restriction: request limitation of processing in the circumstances provided by law.
  • Right to data portability: receive data provided by you in a structured, commonly used and machine-readable format where the legal conditions are met.
  • Right to object: object to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR on grounds relating to your particular situation.
  • Right to withdraw consent: withdraw consent at any time with effect for the future.
  • Right to lodge a complaint: contact a competent data protection supervisory authority.

To exercise your rights, contact: kontakt@official-marketing.de . We may request information necessary to verify your identity before responding.

Rights may be limited where continued storage or processing is required by law, necessary for legal claims or otherwise permitted under the GDPR.

17
Article 21 GDPR

Special Information about Your Right to Object

Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to that processing.

We will then stop processing the affected personal data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims.

Where personal data is processed for direct marketing, you have the right to object at any time without giving reasons. The data will then no longer be processed for direct marketing.

18
Supervisory Authority

Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, place of work or place of the alleged infringement.

The supervisory authority responsible for the controller’s location is:

Sächsische Datenschutz- und Transparenzbeauftragte Maternistraße 17
01067 Dresden
Germany
Phone: +49 351 85471-101
Email: post@sdtb.sachsen.de
Visit the Supervisory Authority
19
Decision Making

Automated Decisions and Profiling

UINEXA does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

Automated technical checks may be used to verify membership status, grant access to premium content, detect failed payments, prevent abuse or protect login security. These checks implement contractual and security rules and do not constitute prohibited automated decision-making.

Independent providers such as PayPal may carry out their own fraud, risk, compliance or automated decision processes under their own responsibility. Details are available in the provider’s privacy information.

20
Age Requirements

Children and Minors

UINEXA is directed primarily at developers, designers, freelancers and business users and is not intentionally directed at children.

Persons who are not legally capable of entering into a paid membership agreement must obtain the consent or involvement of a parent or legal guardian where required by applicable law.

If you believe that personal data of a child has been provided without a sufficient legal basis, please contact us so that the matter can be reviewed.

21
Updates

Changes to this Privacy Policy

We may update this Privacy Policy where website functions, service providers, legal requirements or processing activities change.

The current version is published on this page. Material changes affecting registered members may also be communicated through the website, account area or email where appropriate.

You should review this Privacy Policy periodically. The date shown at the top indicates when this version was last updated.