Rechtsdokument

Privacy Notice

Stand: 22 August 2026

This English-language notice describes Next Gen Social Media's current processing and identifies functions that have not yet been enabled. The German-language version is available at /datenschutz. Both versions describe the same processing. Next Gen Social Media is being developed for international operation, but no country is enabled for restricted functions merely by this notice. Restricted functions remain unavailable until the relevant country or region, provider, transfer safeguards and legal requirements have been approved.

1. Controller and privacy contact

Best IT-Solutions GmbH
Otto-Hahn-Straße 25
61381 Friedrichsdorf
Germany

Represented by managing director Julian Wehe.
Telephone: +49 174 269 89 85
Email: mail@bestitgmbh.de

Privacy requests and objections may be sent to these details. Before large-scale age, identity or special-category processing, we will assess whether a data protection officer or representative must be appointed and publish any required contact before processing begins.

2. Current service status

The current production state permits approved, non-age-restricted content only. External age, identity, creator-KYC and payment providers, and the publication or delivery of 18+ content, are disabled. Before activation we will document the provider and product version, approved territories, subprocessors, data regions, legal bases, retention and transfer safeguards. Unknown or unapproved territories will fail closed for restricted content.

3. Service delivery, security and local settings

We process connection and security data such as IP address, time, requested resource, status code, browser and device information, and rotating derived security identifiers. We use this to deliver and protect the service, diagnose faults and rate-limit abuse. For people protected by the GDPR, the bases are Article 6(1)(b) and our legitimate interest in a secure service under Article 6(1)(f). A theme preference may be stored locally. A country code supplied by the delivery network may select a display currency; it is not proof of residence, tax status or age.

4. Accounts, authentication and essential storage

We process account and display names, roles, optional or federated email addresses, password verification values, passkey public keys and counters, recovery-code verification values, session and CSRF values, security events, and acknowledged legal-document versions. If Google sign-in is chosen, we receive the authorised OpenID account identifier, email and basic profile claims. Essential session, CSRF and sign-in cookies secure the account and are not used for advertising. Under the GDPR, the bases are Article 6(1)(b), supplemented by our security interest under Article 6(1)(f). Without required account and security data, an account cannot be provided. An email delivery provider remains disabled until contract approval.

5. Profiles, social features and communications

Depending on the features used, we process profiles, privacy choices, posts, media, categories, audiences, follows, friendships, communities, lists, reactions, comments, private saves, messages, invitations, live-room and matching metadata, and notifications. Public profiles may use a pseudonym, and public profiles or intentionally public posts may be visible without an account. Private content is delivered only after a server-side authorisation check. Under the GDPR, Article 6(1)(b) supports requested features and Article 6(1)(f) supports rights control and abuse prevention.

6. Audience measurement

A creator profile view is counted at most once per viewer or pseudonymous network identifier, creator and day. A daily rotating HMAC prevents recovery of the originating IP address. Raw count events are deleted after 45 days; daily aggregates contain no directly identifying viewer value. Under the GDPR, this is based on our legitimate interest in reliable, duplicate-resistant statistics under Article 6(1)(f). We currently use no third-party advertising tracker and do not sell personal data or share it for cross-context behavioural advertising. Objections may be sent to the contact above.

7. Managed pages, campaigns and billing

Managed-page processing may include ownership, team roles, permissions, responsibilities, invitations and transfers. Campaign records may include parties, briefs, terms, versions, acceptances and advertising disclosures. Platform invoices may contain billing contacts and addresses, VAT identifiers, service, tax, payment and bank-reconciliation data, plus immutable invoice snapshots. Under the GDPR, the bases are Article 6(1)(b) for performance, Article 6(1)(c) for legal accounting duties and Article 6(1)(f) for access control and evidential integrity. Statutory accounting records are retained for the applicable legal period. External live payment processing is not enabled.

8. Age and identity checks — not yet enabled

Once approved, a specialist provider may process an identity document, selfie or video, liveness signals, document authenticity, an age attribute, device data and fraud signals. Depending on the method, the provider may process biometric data to establish a unique match. A separate gateway minimises and normalises the provider response and sends Next Gen Social Media only opaque provider-subject, holder-binding and trace references. Next Gen Social Media processes those values transiently and stores only purpose-separated pseudonymous HMAC evidence. Next Gen Social Media otherwise retains only an over-18 result and binding evidence such as provider, profile, transaction reference, issue and expiry time, issuer, audience, nonce and status. Next Gen Social Media's product database, normal logs, analytics and support tickets will not retain names, exact dates of birth, document numbers, document images, selfies, video or biometric templates.

Age assurance, person binding, provider-side liveness or document matching, and re-registration prevention are separate purposes. Before activation, each market and method requires a lawful-basis assessment, any required condition for biometric processing, a DPIA, provider due diligence, processing terms, accessible alternatives, human review, retention and transfer approval. Technical uncertainty, an invalid document or liveness failure is not treated as proof that a person is underage.

9. Pseudonymous re-registration restriction — not yet enabled

For a proportionate five-year account sanction, Next Gen Social Media intends to transform the provider-specific subject using a versioned secret HMAC. The resulting restriction identifier is pseudonymous personal data, not anonymous data. We retain only provider, key version, HMAC, sanction reference, status, start, expiry and revocation. It remains separate from the profile during the sanction even if the former account is deleted or anonymised, so that changing an email address does not bypass the sanction. Once expired it is no longer used to deny access and must be deleted or cryptographically destroyed after the approved operational and backup interval.

A match must not be treated as infallible identification. The current appeal route covers only a sanction attached to a signed-in account. Before re-registration prevention is enabled, a securely claimant-bound human-review route must also exist for a newly rejected account, mistaken identity, identity misuse and false age outcomes; a successful appeal must revoke the restriction. The five-year period, legal basis, balancing assessment, error handling and automated deletion must also be approved.

10. Uploads, 18+ content and participants — not yet enabled

Current uploads are limited to approved non-age-restricted material and enter private quarantine first. Before 18+ uploads can be enabled, uploaders must be verified adults. Every identifiable participant will also require separate evidence of adulthood, identity, rights, informed consent, permitted use and a withdrawal or takedown process. Verifying the uploader does not verify other participants.

Adult material may reveal sex life, sexual orientation, health or other specially protected information under Article 9 GDPR. The necessary Article 6 legal basis and Article 9 special-category condition will be determined before activation; general account terms are not sufficient. Illegal, underage, non-consensual or unauthorised material remains prohibited.

11. Moderation, reports, sanctions and appeals

We may process the reporter, reported content or account, reason, statement, evidence, rule and model version, classification label and confidence, case state, reviewer identifier, outcome, sanction and appeal. Reporter and victim information is not disclosed to the reported person unless legally required. For people protected by the GDPR, the bases are Article 6(1)(c) where processing is necessary for a legal duty and Article 6(1)(f) for our legitimate interests in platform safety, enforcement, evidence and defence. Automated systems may prioritise or quarantine material; serious final measures are reviewable, and five-year or permanent sanctions require independent second approval. Evidence is retained only for the proceeding, repeat-abuse assessment, required reporting or documented legal defence.

12. Recipients and international transfers

Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, acts as processor for VPS application, database and log infrastructure intended for Germany or the EU. The selected server region and the Hetzner DPA concluded in the customer account govern that processing.

Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA, acts as processor for D1, R2 and edge database, private media, network, security and log data depending on the runtime. Its global network may involve third-country access. The current Cloudflare DPA, incorporated EU Standard Contractual Clauses for restricted transfers and any necessary supplementary measures apply. The exact account configuration, subprocessors and transfer impact assessment must be documented before production.

If Google sign-in is voluntarily selected, Google Ireland Limited generally provides the Google account service in the EEA and Switzerland and Google LLC generally does so elsewhere, acting independently for that service; Next Gen Social Media controls the OpenID claims it receives. See the Google Privacy Policy. Other identity, age, email, moderation or payment providers remain disabled until their entity, role, subprocessors, locations, deletion and transfer mechanism are documented.

Transfers outside the EEA require an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses and necessary supplementary measures. Executed contracts, account configuration and transfer assessment are operational requirements; links to provider terms alone do not satisfy them.

13. Retention and account closure

Short-lived sign-in, challenge and reservation data expires technically; raw profile-view events are deleted after 45 days. Account data and content are generally retained until deletion or account closure. After that they are deleted or anonymised unless a statutory invoice record, active re-registration restriction, moderation evidence hold, claim, reporting duty or legal defence requires separate limited retention. A complete self-service deletion and export path is still in development; requests can be sent to the contact above. Restricted features will not launch until provider, backup and automated deletion procedures are tested.

14. Sources, required information and automated decisions

Account data comes from the person, technical data from the device or delivery network, Google data only after chosen sign-in, and future verification results from the approved provider. Required fields are identified; without them the relevant function cannot be provided. Age or restriction decisions may significantly affect access. Alternative verification, clear statuses, human review and appeal are therefore activation requirements. Before using solely automated decisions with legal or similarly significant effects, we will explain the principal criteria, significance and consequences.

15. Your rights

Where the GDPR applies, rights may include access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus a complaint to a competent supervisory authority. Other regions may grant additional rights to know, correct or delete data, limit sensitive-data uses, opt out of sale or behavioural-advertising sharing, and receive non-discriminatory treatment. Next Gen Social Media currently does not sell personal data or share it for cross-context behavioural advertising. These rights are considered even where the general interface is globally reachable; necessary regional supplements and request methods must be added before collecting additional regional or restricted-function data.

16. Changes and new territories

We update this notice when providers, purposes, data categories, retention, transfers or legal requirements materially change. Registration displays the current privacy version; existing users will be notified or asked for consent where required. This notice does not itself activate any country or external verification provider.