Privacy policy
Last updated: 14 August 2026
This privacy policy explains which personal data is processed when you visit this website or use its functions.
1. Controller
LotStage AI
Andreas Giese
Schlesische Str. 4a
82538 Geretsried, Germany
Email: info@lotstage.de
2. Accessing the website and hosting
Technically necessary connection data is processed when you access this website. This may include your IP address, date and time, requested URL, amount of data transferred, HTTP status, referrer, and browser and operating system information. Processing is necessary to deliver the website, maintain its stability and security, and prevent misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our website. Security and error data is retained only for as long as necessary for the respective purpose.
Hosting provider
This website is hosted on servers operated by IONOS SE, Elgendorfer StraΓe 57, 56410 Montabaur, Germany. IONOS processes technical data on our behalf under a data processing agreement pursuant to Article 28 GDPR.
3. Contact enquiries and contact form
If you contact us using the form or by email, we process the details you submit. The form requests your name, email address and message, with auction house or company and telephone number available as optional fields. Your IP address is also processed briefly to limit abusive requests but is not stored with the contact enquiry.
Where an enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR. Other enquiries are processed pursuant to Article 6(1)(f) GDPR; our legitimate interest is to process and respond to your enquiry. Form submissions are sent through our SMTP provider to info@lotstage.de.
We delete enquiries once they have been fully dealt with, unless statutory retention duties or overriding legitimate grounds require further storage. If correspondence forms part of a business transaction, statutory retention for up to six years may apply.
4. Login, customer account and session cookie
The login area is intended for customers whose accounts have been set up in advance. We process the email address, internal customer identifier and, where applicable, contract and subscription status. When a login link is requested, we store a non-reversible hash of the one-time token, language, creation and expiry times, time of use and requesting IP address. The link sent by email is valid for 15 minutes and can be used only once.
After a successful login we set the strictly necessary__Host-session cookie. It contains a signed session token, is transferred only over HTTPS, cannot be accessed by JavaScript (HttpOnly), is restricted to this website and expires after no more than 14 days. It is used solely for authentication and account security, and therefore does not require consent.
The legal basis is Article 6(1)(b) GDPR and, for protection against misuse, Article 6(1)(f) GDPR. Account and contract data is stored for the duration of the customer relationship and subsequently in accordance with statutory retention duties. Expired magic-link records, including the IP address stored with them, are deleted automatically no later than 30 days after the link expires. Other security data is deleted once it is no longer needed for protection and evidential purposes.
5. Subscription management and Stripe
If you use paid subscription or billing functions, we work with Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Data processed may include email address, Stripe customer identifier, subscription identifier, plan, status and billing period. Payment details are processed directly by Stripe and are not stored on our web server.
Processing is necessary for contract performance under Article 6(1)(b) GDPR and compliance with legal obligations under Article 6(1)(c) GDPR. Stripe may transfer data to affiliated companies and service providers outside the European Economic Area. According to Stripe, such transfers rely in particular on adequacy decisions and EU Standard Contractual Clauses. Further information is available in Stripeβs privacy policy.
6. Recipients and processors
Personal data is disclosed only to parties that need it for the purposes described. In addition to IONOS and, where billing functions are used, Stripe, this may include technical providers for email delivery, maintenance and IT security. Where required, providers are contractually bound under Article 28 GDPR. We do not sell personal data or disclose it for third-party advertising purposes.
7. No analytics or marketing cookies
This website currently uses no web analytics, tracking or marketing services and no related cookies. External fonts are not loaded from third-party providers. If this changes, we will update this policy before introducing the relevant technology and obtain consent where required.
8. Data security
Data is transmitted using TLS encryption. We use appropriate technical and organisational measures to protect data against loss, alteration and unauthorised access. These include access restrictions, secure session cookies, time-limited one-time links and request rate limits.
9. Your data protection rights
Subject to the applicable statutory conditions, you have the following rights:
- access to your processed data (Article 15 GDPR),
- rectification of inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR), and
- objection to processing based on Article 6(1)(f) GDPR (Article 21 GDPR).
To exercise your rights, email info@lotstage.de. You also have the right to lodge a complaint with a data protection supervisory authority. Our competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany,www.lda.bayern.de.
10. Requirement to provide data and automated decisions
Providing data through the contact form is not a statutory or contractual requirement. Without the required fields, however, we cannot process your enquiry. Certain data is necessary for established customers to log in and receive contracted services. This website does not make solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.
11. Changes to this privacy policy
We update this policy when functions, service providers or legal requirements change. The version published on this page at the relevant time applies.
