JAMADON
Privacy notice
Updated:
SZB (Sagdullaev Zwei Brüder) UG (haftungsbeschränkt)
Windthorststraße 20, 48153 Münster, Deutschland
hr-management@szb-nrw.de
Website and hosting
The company identified above is the controller. Connection data such as IP address, access time, requested URL, and browser details is processed to deliver and protect the site. Our legitimate interest in secure operation is the basis under GDPR Article 6(1)(f).
This private website is provided through OpenAI Sites. For protected access, the platform also processes ChatGPT account sign-in and authorization information. ChatGPT privacy terms additionally apply to those platform functions.
Retention of server logs and backups depends on the specific operational and security purpose, necessary incident investigation, and hosting-contract settings. Platform data may have different retention periods from the application records described below. Contact us for information about the recipients and periods relevant to a particular request.
Device storage and the personal planner
Your chosen favorites are kept in your browser’s local storage under fit-recipes-favorites until you remove them or clear the site’s browser data. This storage provides the favorites list you use. Height, weight, age, and menu-planning goals are processed only in your browser, not sent to our server or OpenAI.
The application has no analytics, profiling, or advertising-tracking scripts. The essential administrator session and requested favorites storage support their respective functions; strictly necessary device access is addressed by Section 25(2)(2) TDDDG. Adding services that require consent would require a separate prior choice.
Menu downloads and license records
For a download we record a random acceptance reference, time, language, and the license version expressly accepted. That record contains no name, email address, or IP address. Hosting connection data is processed separately.
The record documents the download agreement and, if necessary, helps address legal claims, under GDPR Article 6(1)(b) or (f) where personal data is involved. Records remain in the database until deleted. Download fulfillment, outstanding disputes, and applicable limitation periods guide review of continued necessity; no fixed automatic deletion period is currently configured.
Protected administration
Administrator access uses an essential HttpOnly session cookie, fit_admin_session. It expires after eight hours and can be ended by signing out. Changing the password invalidates previous sessions. Only salted password hashes and hashes of session tokens are stored on the server. Expired sessions are removed at a new sign-in. Abuse protection allows eight attempts per 15-minute window; old entries are removed at the next attempt. The basis is GDPR Article 6(1)(f).
For the administrator account, we store the email address, password hash, password version, and update time for as long as the access is needed. The private Sites version additionally verifies the platform identity and binds access to its account identifier. Editorial requests, status, and articles are stored in the protected application database. Articles can be deleted in administration; job histories currently have no automatic deletion period. Their continued necessity is assessed against active jobs, troubleshooting, and legitimate recordkeeping purposes.
AI editorial tools and OpenAI
After an API project is connected, editors can send instructions, proposed topics, existing headlines, and selected recipe text and ingredients to the OpenAI API to create articles. This feature does not send ordinary page visits or personal planner entries to OpenAI. Editorial inputs should not contain personal or confidential information.
For EEA customer data, OpenAI’s data processing addendum names OpenAI Ireland Ltd as processor. The addendum must be associated with the business API agreement at setup. International processing, including in the United States, is possible; this application does not enforce EU data residency. OpenAI’s addendum describes safeguards including adequacy decisions and standard contractual clauses. You may request a copy of applicable safeguards through our contact.
The feature uses stored responses. OpenAI documents a default retention period of at least 30 days for these responses and generally up to 30 days for abuse-monitoring logs, with exceptions such as legal or security requirements. This feature is not configured for Zero Data Retention. Under OpenAI’s contractual terms, API content is not used for model training unless the customer expressly agrees.
If a permitted editorial request includes personal data, its legal basis must be assessed against its purpose, such as legitimate editorial interests under GDPR Article 6(1)(f) following a balancing assessment. Calling a task editorial does not supply a missing legal basis. Special-category personal data is not intended for this feature.
An API key saved through administration is encrypted on the server and decrypted only for requests to OpenAI. Articles are stored locally. Deleting a local article or key does not automatically erase previously processed OpenAI data or backups.
OpenAI data processing addendumOpenAI API data controlsOpenAI Services Agreement
Contact and advertising
Email contact details and message content are processed to address your inquiry, under GDPR Article 6(1)(b) for steps toward a contract, or our legitimate interest in communication under Article 6(1)(f) otherwise. Messages are deleted after resolution and the end of outstanding recordkeeping needs, unless legal retention duties require otherwise.
Advertisements are labeled. The current application does not create advertising profiles or sell visitor data. Loading an externally hosted banner image can disclose your IP address to its image provider. We therefore prefer locally hosted advertising assets. Following an external link starts a visit subject to the destination’s own privacy terms; the presence of a link alone does not initiate that visit.
Your privacy rights
Subject to the applicable conditions, you may request access, correction, deletion, restriction, or portability. You may object to processing based on GDPR Article 6(1)(f) on grounds relating to your particular situation. Where consent is used, it may be withdrawn for the future.
You may contact us or a supervisory authority, including LDI North Rhine-Westphalia. We request only the details needed to handle your request. No automated decision with legal or similarly significant effects is made about visitors; the local planner provides adjustable suggestions only. Mandatory privacy rights under other applicable laws remain unaffected.
LDI North Rhine-WestphaliaGeneral Data Protection Regulation