Privacy notice

How Roadstead handles personal data, under Articles 13 and 14 GDPR. Last substantive change: 26 September 2026.

Controller

Severin Schwanck Birkenau 14 81543 München Deutschland

Data protection enquiries: hello@roadstead.eu

No data protection officer has been appointed: the thresholds in Art. 37 GDPR and §38 BDSG are not met.

Two roles, and which one applies to you

Roadstead is a hosting service for structured content. That splits the responsibility for personal data in two, and which half applies depends on how you arrived:

  • Account holders and visitors to this site. If you hold a Roadstead account — you signed in at this domain, you belong to a workspace — or you are simply visiting this website, the operator named above is the controller for your data. This notice describes that processing.
  • Everyone reaching a customer's workspace. If you were given access to somebody else's workspace, or signed in through an application one of our customers built, that customer is the controller and Roadstead is their processor. We act on their instructions. Their own privacy notice governs, and a request about that data goes to them; if you ask us, we forward it rather than acting on it.

What we process, why, and on what basis

Visiting this website

When your browser asks for a page, our server necessarily receives your IP address and what the browser sends with the request, such as its type and preferred language. They are used to deliver the page and, on some forms, for the abuse limits described below. The web server writes no access log. Art. 6(1)(f) — delivering the site you asked for, and keeping it secure.

Your account

Your email address and the language you chose for the interface. Processed to give you an account and let you sign in, under Art. 6(1)(b) GDPR (performance of a contract). Without an email address there is no account: it is the credential.

Signing in

Roadstead has no passwords. Signing in means we email you a single-use link, so your address is used to send that mail, under Art. 6(1)(b). The link expires after 15 minutes. A session is stored as a hash of its token and nothing else — no device fingerprint, no IP address, no location. A session token expires 14 days after it was issued; while you keep using Roadstead it is replaced with a fresh one every 7 days, so a session in regular use stays signed in.

Invitations

If someone invites you to a workspace, your email address reaches us from them, not from you (Art. 14 GDPR), together with the name they gave you, any message they wrote, and a note of who sent it. We use it to send you the invitation. An invitation that expires unaccepted is deleted the following day; an accepted one is kept for 30 days after acceptance. Art. 6(1)(b), and Art. 6(1)(f) — the inviting workspace's interest in reaching the person it chose.

Content you author

Whatever you put into a workspace: objects, their property values, translations, uploaded files, and the names you give any of it. Processed to provide the service, under Art. 6(1)(b). If you enter somebody else's personal data into your content, you are the controller for that — see Content that names other people below.

Working alongside others

While you have a workspace open, the other members currently in it see that you are there — by your email address — and which object and field you are editing, so that two people do not overwrite each other. This is held in memory for as long as you are connected and is never stored. Your browser also sends its timezone when it connects, so that times are shown in your local time; that is not stored either. Art. 6(1)(b).

The change log

Roadstead is built on an event log: every change to content or to a schema is stored as an event that says what changed and which account did it. This is not an add-on audit trail — the log is the record, and the content you read is folded from it, so events are not deleted as they age. Keeping them is necessary to provide the service (Art. 6(1)(b)) and serves our legitimate interest in security and accountability (Art. 6(1)(f)). An event names an account by internal id only; it never carries an email address, a name or an IP address. On erasure, that id is removed from every event while the events themselves stand.

Applications and API credentials

Where a workspace connects an application, we store the session that application holds: which workspace and account it acts for, the permissions it was granted, when it was first seen and last used, and the browser or client label it sent. No IP address and nothing derived from one. Tokens are stored only as hashes. Art. 6(1)(b).

Uploaded images

Embedded metadata — EXIF, XMP and IPTC in JPEG, PNG and WebP files — is stripped from an image before it is first written to storage, so no stored copy of the file carries it. A file whose structure cannot be read with certainty is stored as uploaded rather than risk corrupting it. A curated subset is read out beforehand and kept in the database — camera, lens, exposure, capture time and its timezone offset, and the credit line and description the file names. GPS coordinates and device serial numbers are never captured. Art. 6(1)(b).

Abuse limits

Requests to sign in, to register, to change an email address, to use the early-access form and to reach the API are counted — per email address, per IP address or per account, depending on the request — to stop this service being used to mail strangers or being flooded. The counters live in memory, keyed per time window, and are discarded when the window passes. Art. 6(1)(f) — our legitimate interest, and everyone else's, in not being the source of that mail.

Server logs

The application writes an operational log of what it did — errors, rejected requests — tagged with a request id, not with an IP address; accounts appear in it by internal id. The operating system rotates this log by size and overwrites the oldest entries as it fills. The database server's own log, which records slow queries without their values, is kept for about ten weeks. Art. 6(1)(f) — keeping the service running and diagnosing faults.

Backups

Everything above is included in database backups. They are encrypted on our server before they are uploaded, so the storage provider holds only ciphertext it cannot read. Art. 6(1)(f) — recovering the service after a failure.

Asking for early access

If you use the early-access form, the email address and any message you type are sent to the operator as a single email and are not written to our database. What happens after that is ordinary correspondence: it sits in the operator's mailbox, hosted by Microsoft (see the processors below), until it is answered or deleted. Art. 6(1)(b) — steps taken at your request before any agreement.

To keep automated spam out, the form asks your browser to solve a small computing puzzle before it sends. The puzzle comes from our own server and the answer goes back to it. No other party is involved, and the puzzle itself contains nothing about you.

Cookies and local storage

Roadstead sets at most two cookies. The first is a signed session cookie, set on your first visit: it holds the security token that protects our forms against forged submissions and the language the pages are shown in, and once you sign in it keeps you signed in. It is deleted when you close your browser. The second is set only if you choose to stay signed in when you sign in: a signed cookie that keeps you signed in. It lapses 14 days after it was last renewed, and is renewed every 7 days while you use Roadstead. Both are strictly necessary for what you asked for, so neither needs consent under §25(2) TDDDG.

Your browser also stores two preferences locally — your light or dark theme choice, and whether the sidebar is collapsed — plus a few technical entries the page framework keeps while you navigate and reconnect, none of which identify you. These never leave your browser and are never sent to us.

There is no analytics, no tracking pixel, no advertising network, no third-party script and no consent banner, because there is nothing here that would need one. Our emails contain no tracking pixel either, so we do not know whether you opened one.

One thing reaches outside: content can refer to an image by its address on another server. When the editor's preview shows such an image, your browser fetches it from that server, which then sees your IP address as it would for any web page. Roadstead neither chooses nor controls those servers.

No marketing email

We send no newsletter and no marketing email. The only mail Roadstead sends you is transactional: a sign-in link, an invitation, a notice about your own account.

Processors we use

Every processor below is engaged under Art. 28 GDPR. All of them process within the EU; the mailbox provider is the one whose group reaches outside it, and its entry says how.

  • netcup GmbH, Germany — the server that runs Roadstead and its database, in an EU data centre. Everything this notice describes is processed on it.
  • Scaleway S.A.S., France — object storage for uploaded files, in a data centre in Amsterdam, Netherlands. A second copy of the same files is kept in a second bucket with the same provider and region.
  • Scaleway S.A.S., France — database backups, encrypted by us before they are sent, so the provider holds ciphertext it cannot read.
  • Scaleway S.A.S., France — the mail relay that delivers sign-in links, invitations and account notices. The relay retains message metadata — recipient, subject and delivery status — under its own retention period. Because sign-in is by emailed link, this relay sits inside the authentication path.
  • Microsoft Ireland Operations Limited, Ireland, through the reseller Host Europe GmbH, Germany — the mailbox behind the contact address above. Early-access requests and anything you write to us arrive there. It is stored in Microsoft's EU data centres, but Microsoft's parent company is in the United States and support staff there may reach it; that transfer rests on the EU–US Data Privacy Framework (Art. 45 GDPR) and Microsoft's standard contractual clauses (Art. 46(2)(c)). Mail the application sends is not routed through it.

AI features are a workspace's own choice. Roadstead holds no AI provider key of its own and provides no AI service. A workspace that wants AI assistance supplies its own key for a vendor it selects, and from then on the field contents it sends go to that vendor under that workspace's own contract with them. If you author content in somebody's workspace, ask them which vendor they configured.

How long we keep things

Data Kept for
Account As long as the account exists; 14 days after a deletion request, then anonymised
Sign-in link Usable for 15 minutes; deleted at the next daily clean-up
Email confirmation link Usable for 3 days; deleted at the next daily clean-up
Browser session 14 days from issue; renewed every 7 days while in use
Application session 30 days from last use
Content and its change log Until you delete it; deleted items are purged 7 days later
Uploaded files 7 days after deletion, then up to 30 days more while storage versions expire
A data export you requested 7 days, then the file is erased and only the record that we answered remains
Invitation Unaccepted: until the day after it expires. Accepted: 30 days after acceptance
Database backups Two to three weeks — two weekly full backups and the changes since — then superseded copies expire within 30 more days
Rate-limit counters The length of one window; never written to the database
Internal job records (for instance the one that sent a confirmation email) 30 days after the job ran
Operational log Until overwritten by size-based rotation; the database server's log about ten weeks

Your rights

You may, at any time:

  • ask what we hold about you and get a copy (Art. 15);
  • have it corrected (Art. 16);
  • have it erased (Art. 17);
  • have its processing restricted (Art. 18);
  • receive it in a portable, machine-readable form (Art. 20) — your account settings page produces this export directly.

Deleting your account starts a 14-day grace period, so that an accidental or coerced deletion can be undone; after it, your personal data is anonymised. If you are the only owner of a workspace, you first hand ownership of it to another member, because the workspace cannot be left without one. Two things survive by necessity and are named here rather than buried: the content you authored in a workspace stays with that workspace, stripped of your authorship, because it is the workspace's record and not yours to withdraw; and the event log keeps its events, stripped of the id naming you. Internal job records that carried your email address — for instance the one that sent a confirmation — expire 30 days after they ran; an erasure does not cut that short.

You may also complain to a supervisory authority — in particular the one for your place of residence or work, or the one competent for the operator: the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

Your right to object

Where we process your data on the basis of legitimate interest (Art. 6(1)(f) GDPR), you may object to that processing at any time, on grounds relating to your particular situation (Art. 21 GDPR). Write to the address above, naming the processing you mean. We then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Content that names other people

If a workspace's content contains a third party's personal data — a name in an article, a photographer's credit in an image file — the workspace that authored it is the controller for that data and decides what happens to it. A request reaching us about such content is passed to that workspace.

Is any of this required?

Only an email address, and only because it is how you sign in. There is no automated decision-making and no profiling, in the sense of Art. 22 GDPR.

Security

Every connection is encrypted with TLS. There are no passwords to steal: sign-in links are single-use, short-lived and stored only as hashes, as are application tokens. Backups are encrypted before they leave our server. Further detail on our technical and organisational measures is available on request.

Changes

This notice changes when the processing it describes changes. The date at the top is the last substantive change; a fixed typo does not move it.

See also the imprint and the terms.