1. Controller
controller within the meaning of the General Data Protection Regulation (GDPR) is:
Michael Höhne, trading under the trade name “Rangsdorfer Software Company”
Sole proprietorship
Akazienweg 13
15834 Rangsdorf
Germany
Email: support@glassdesktopbox.com
Website: https://glassdesktopbox.com ↗
The most current published version of this Privacy Policy is available at https://glassdesktopbox.com/privacy ↗.
2. Scope
This privacy policy applies to:
- the glassdesktopbox.com website including download, pricing, support, FAQ, P2P and cancellation / cancellation features;
- the desktop application Glass Desktop Box™ for the supported operating systems;
- License activation, license verification and usage-based quota management;
- Remote invitations, signaling, direct peer-to-peer connections, and technically required relay/TURN connections;
- Support, contract processing, withdrawal, termination and refunds.
- Desktop Experiences, public experience and animation links, and the selection of external sharing destinations;
Third-party websites and services that are merely linked are not included. The data protection information of the respective provider applies to these.
3. Principles and legal bases
We process personal data for a specific purpose, transparently and limited to the necessary extent. Depending on the processing, we rely on:
- Art. 6 Paragraph 1 Letter a GDPR – Consent;
- Art. 6 Paragraph 1 Letter b GDPR – Initiation or fulfillment of a contract;
- Art. 6 Paragraph 1 Letter c GDPR – Fulfillment of legal obligations;
- Art. 6 Para. 1 lit. f GDPR – legitimate interests, in particular secure operation, error analysis, protection against misuse and fraud as well as legal defense;
- § 25 TDDDG – Storage of information or access to information in the end device, unless absolutely necessary or expressly consented to.
4. Website provision and server logs
The public website glassdesktopbox.com is hosted by Hostinger and delivered through the Hostinger Content Delivery Network (hCDN).
When the website is accessed, Hostinger, the hCDN and the web servers involved process in particular the IP address, date and time, time zone, requested URL and HTTP method, HTTP status, transferred data volume, referrer, browser / user agent information, operating system / device information, Cache and routing information as well as security-related events. The delivered HTTP responses also contain a technical hCDN request identifier. This data is processed for delivery, load balancing, stability, error diagnosis and to detect and defend against attacks.
The legal basis is Article 6 (1) (f) GDPR. Our legitimate interest lies in the secure, fast and trouble-free operation of the website. In its privacy policy, Hostinger describes the processing of IP, browser, device, referrer /Exit, timestamp and clickstream data as well as security and misuse data. Hostinger generally only stores data for as long as is necessary for service provision, security, fulfillment of legal obligations or legal defense; certain misuse data may be retained for up to one year after an account suspension for security reasons. We have not set up any additional storage for our own website analysis or marketing logs.
The public website is delivered through the Hostinger infrastructure described in Section 4. Licence, signalling, TURN/relay and update components additionally use the Hetzner infrastructure described in Section 5.
5. Licence and connection infrastructure at Hetzner
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, is currently used for licence, signalling, TURN/relay and update services. Depending on the service, Hetzner processes data as a processor; for its own legal or security purposes, Hetzner may act as an independent controller.
Connection and server protocols, IP addresses, timestamps, technical session and license data as well as temporarily encrypted data packets for relay connections may be affected. The basis is Article 6 Paragraph 1 Letters b and f GDPR; If necessary, agreements are concluded with processors in accordance with Art. 28 GDPR.
The specific technical configuration of the productive Hetzner project, the contractual order processing regulations, server locations, backups, sub-processors and deletion periods are documented in the internal directory of processing activities and in the technical security documents and updated in the event of changes.
6. Technically required device storage, cookies and similar technologies
The new Next.js website's fully audited proprietary source code currently does not set its own cookies and does not use `localStorage`, `sessionStorage` or IndexedDB. It does not contain its own analytics, reach measurement, advertising, tracking or marketing integration. The Nox support dialog only temporarily keeps the visible conversation history in the memory of the currently open browser page; When the page is closed or reloaded, this local state is lost.
According to the tested development status, simply opening the new Next.js website does not require cookie consent for your own analysis, advertising or marketing purposes. The fonts mentioned in Section 7 are delivered from your own website files. External YouTube content will only be loaded after the express consent described in Section 8.
If a new function saves or reads cookies or other information in the end device in the future, it will be evaluated before use in accordance with Section 25 TDDDG and GDPR. Non-essential technologies will only be activated after consent; This declaration is then supplemented with name, provider, purpose and term.
7. Locally provided fonts
The new Next.js website uses the Inter and Dancing Script fonts through Next.js' built-in font management. When the website is created, the font files are included in your own website files and then delivered by your own web server. When you visit the finished website, no connection is established to Google Fonts or Google servers. No IP addresses or other visitor data are transmitted to Google for the display of the fonts. Consent in accordance with Article 6 Paragraph 1 Letter a GDPR or Section 25 Paragraph 1 TDDDG is not required for this.
8. YouTube videos
Videos from YouTube can be embedded on individual pages. The provider in the EEA is generally Google Ireland Limited. When loading an embedded player, IP address, device and browser data, page accessed, times, cookie identifiers and, for logged in users, account data may be transmitted to Google.
The embedding only takes place with consent in accordance with Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TDDDG. Consent can be revoked in the future.
YouTube videos are integrated via a two-click solution. No YouTube player is loaded before an explicit selection. After consent, the player is loaded from youtube-nocookie.com; consent can be revoked in the future.
External YouTube links do not establish a connection before they are selected. Embedded players remain technically blocked and use a locally hosted poster until voluntary consent is given. Only then is the player loaded from youtube-nocookie.com to play the requested video. Google Ireland Limited may process IP address, device, browser, page, time, cookie identifiers and usage information; transfers outside the EEA cannot be excluded. The legal basis is consent under Article 6(1)(a) GDPR and, where information is stored on or read from the device, Section 25(1) TDDDG. Consent can be withdrawn at any time through the permanently accessible privacy settings. Further information: https://policies.google.com/privacy ↗ · https://www.youtube.com/howyoutubeworks/user-settings/privacy/ ↗
9. External links and social media offers
Links to YouTube, LinkedIn, X or other third-party sites generally do not transmit any data to these providers when they are simply displayed. Users only leave our offer when they click on it; The target provider then processes data under its own responsibility. According to current testing, we do not use any social plugins that transmit data when the page is accessed.
External links from the software
After the user's explicit confirmation, Glass Desktop Box can open the official website https://glassdesktopbox.com ↗ in the default browser. This function does not establish a connection to the website before confirmation and does not transfer files or file contents from any Box.
When the website is opened, the browser sends the connection data technically required for the page request to our web server and hosting provider. This may include the IP address, date and time, requested address, browser and operating-system information and, where applicable, referrer information. The information in this Privacy Policy concerning website operation and server logs applies.
10. Nox Support Assistant
Nox Support Assistant processes the entered question and, if applicable, the previous question to generate an answer from a local knowledge base. No external AI models or AI APIs are addressed. Prompt content, questions, IP assignments, answers and conversation histories are not permanently stored by us or merged into a user profile. The visible messages only exist temporarily in the memory of the opened browser page and are discarded when closed or reloaded. Entries are limited to a technical maximum length.
Please do not enter special categories of personal information, passwords, license keys or sensitive content there. Technical web server and security logs can capture request metadata. The legal basis is Art. 6 Para. 1 lit. b GDPR for product-related inquiries, otherwise Art. 6 Para. 1 lit. f GDPR.
10a. No AI processing in the delivered application
Glass Desktop Box™ and the Nox support assistant do not use a generative AI model, an external AI API, an emotion recognition or a biometric categorization at runtime according to the currently confirmed product status. Nox answers questions based on rules or knowledge from locally provided content. User files, chat messages, and support questions are not used to train general AI models.
AI-supported tools were used in development, text, image and video creation. This does not result in user data being processed by AI within the delivered application. For publicly provided, significantly AI-generated or AI-manipulated media, a separate identification and provenance process will be set up in accordance with Article 50 of Regulation (EU) 2024/1689 from August 2, 2026. Artistic and fictional content is marked in an appropriate manner that does not impair use.
For supplied and publicly displayed media, the provider maintains an internal media and rights inventory with time of creation, tools used, degree of processing, release and chain of rights. To the extent that Article 50 of Regulation (EU) 2024/1689 is applicable, artificially generated or manipulated content will be marked in a suitable, visible and - if technically necessary - machine-readable form from August 2, 2026. The application itself does not process user data using generative AI.
11. Downloads and updates
The Application may retrieve a public version file made available via HTTPS at startup, at defined intervals or upon an express command. The participating web servers process the data required for an ordinary HTTPS request, in particular the IP address, date and time, requested URL and HTTP method, HTTP status, amount of data transferred, HTTP headers or user agent, and routing and security information. The program version, operating system, language, device identifier, user name, licence key, file names, Box contents and user files are not transmitted to the update server in the described request. If a later technical version transmits additional information, this notice will be updated accordingly before that version is used. The legal bases are Article 6(1)(b) GDPR for contractual provision, Article 6(1)(c) GDPR for updates required by law, and Article 6(1)(f) GDPR for secure operation, error analysis and prevention of misuse.
The automatic check for a new version does not give the Provider access to the installed Application. The Provider cannot remotely control or secretly start an update. An installation package is downloaded only after the user expressly selects “Install”; selecting “Later” causes neither a download nor an installation. Box names, files, custom backgrounds, session states, snapshots and licence keys are not part of the update check. No additional telemetry and no personal update history are created for advertising, profiling or behavioural analysis.
Before an installation confirmed by the user, the Application locally checks storage space, file size, the SHA-256 checksum and, in the production Windows channel, the digital signature. It then locally saves Box state, organisation and settings and, where technically provided, creates a local pre-update snapshot. The temporary installer, snapshot, user files, custom media, Box data, settings and licence data remain on the end device and are not transmitted to the Provider or update server as part of the update. Their local retention and deletion follow the documented update, recovery and cleanup logic of the relevant program version.
Once the production channel is commissioned, the public version file will be provided at https://glassdesktopbox.com/updates/stable.json. It may contain the version number, channel, release time, release notes and platform-specific installer metadata including file size and SHA-256 checksum. A package is executed only after a complete download and successful size and checksum verification; the production Windows channel additionally requires a valid digital code signature. If any verification fails, the installer is not started. Until a suitable code-signing certificate is in place, updates are offered only as test installers that must be downloaded manually and expressly. Access logs are processed solely under Section 4 for delivery, security and error analysis and are deleted according to the criteria in Section 27; no separate user-related update history is maintained.
12. Local processing in the desktop application
Box states, positions, display options, selection tabs, local references, recovery information, transfer journals and temporary protection copies are generally processed on the end device. The application is not intended to upload files to a general cloud without a user-triggered remote function.
Local data is under the control of the respective device owner. For shared or company-used devices, the operator is responsible for access rights, backups and the admissibility of the content.
Under Windows, productive user-related configuration, box, session, recovery and license data resides separately from the program folder in the Windows areas for roaming and local application data, respectively, under the application name GlassDesktopBox; Test installations use a separate test area. Temporary update packages are only in the local temporary area. Uninstalling the Program Files does not automatically delete user data unless the user specifically chooses to remove it. macOS and Linux have not yet been published as of this statement; their final storage locations will be supplemented in the respective product documentation and this declaration before they are made available.
12a. Desktop Experiences, animations and sharing function
Desktop Experiences consist of locally supplied or user-selected backgrounds, colors, box arrangements and animations. Applying an experience is generally done locally. The user's own images and videos are not automatically transmitted to Glass Desktop Box or social media platforms.
The share function is currently intended solely for the supplied Desktop Experiences and animations. It creates a public, language-specific link to a page on glassdesktopbox.com and, at the user's request, opens the sharing interface or web address of a third-party service selected by the user, such as WhatsApp, Telegram, Facebook, LinkedIn, X or email. Glass Desktop Box does not sign the user in to that platform, receive access tokens or transmit a recipient list. The selected platform determines which data it processes under its own service.
When the public link is opened, the usual server data in accordance with Section 4 is created on glassdesktopbox.com. As of now, no personalized share codes, recipient profiles, opening, download or purchase assignments are created. A later reach or conversion measurement may only be activated after a separate data protection and consent check.
User-uploaded images or videos will not be branded with Glass Desktop Box or published via this marketing sharing feature. The user can only share media outside the application with the operating system or third-party functions they have chosen and remains responsible for this.
After a conscious selection, the current sharing function opens public sharing channels from WhatsApp, Telegram, Facebook, LinkedIn and X, creates an email or uses the clipboard or the available operating system share. The official experience or animation link and the message text approved by the user are transferred. No platform credentials, OAuth tokens, or recipient lists are sent to Glass Desktop Box. Your own user images and videos are excluded from this official recommendation function.
12b. ProBox animation synchronization
During a shared ProBox session, a technical identifier for an included animation, along with playback speed and loop mode, can be transmitted to the authorized participants in the session. Each participant starts the media file that is already supplied locally on their own device; the large video file is not transferred over the session. When joining, the current animation state can be resubmitted.
Own uploaded videos remain local and are not streamed or copied to ProBox participants. The host receives a message about this; Depending on the version, other participants see a still image, the static box background or no animation. Changes and removals of a supplied animation can be communicated to connected participants as session state.
The legal basis is Article 6 (1) (b) GDPR. Only the technical information required for the shared status as well as session and connection data in accordance with Sections 14 to 18 will be processed; Your own video content is not part of this synchronization.
13. Licence activation and permanent device binding
For activation, device binding, function activation and misuse prevention, the following can be processed:
- cryptographic hash and masked representation of the license key;
- internal customer and license identifier, tariff, status and validity;
- Device identifier and device name reported by the device;
On first successful activation, a single-seat licence is permanently assigned to exactly one device. Transfer to another device, parallel use or self-deactivation for reactivation is not currently provided. Activation and verification events are processed to prevent misuse and maintain a traceable licence status. Support may investigate a demonstrably incorrect technical assignment; this does not create an entitlement to a device change or an additional seat.
- Activation, change and check times;
- Software version, platform and required technical metadata;
- IP address and security-related events;
- Activation events and number of allowed devices.
The legal basis is Article 6 Paragraph 1 Letter b GDPR and Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest is to protect against license abuse and the integrity of the service.
The license level used during activation and the associated quota are managed as contract and authorization status. The technical information required for activation, runtime, device assignment, function release and quota is processed. A single-user license is assigned to exactly one active device; Raw license keys are not stored on the server side, but are managed as a checksum value and masked representation.
14. Remote invitation and signaling
To establish a remote connection, the signaling service processes, depending on the function, in particular:
- Session identifier, role as host or guest and expiration time;
- hashed PIN or hashed session token;
- License and eligibility status;
- Device identifier, device name and optional display name;
- public IP address, connection times and socket /connection status;
- requested function, log messages and error / security events.
The data is used to set up, authorize, maintain and terminate the session as well as to prevent misuse. The legal basis is Article 6 Paragraph 1 Letters b and f GDPR.
15. Direct P2P connections (WebRTC)
As far as technically possible, files and collaboration data are transferred directly between the end devices involved. ICE, STUN, TURN, SDP and RTCPeerConnection can be used for WebRTC. For technical reasons, the public IP address is known to the connection partner or their end device and is processed by signaling /STUN systems.
With a direct connection, our servers generally do not receive the complete file content. Signaling, license, quantity and security metadata can still be processed on the server side. Host and guest decide for themselves what content they share with each other.
Website, license, update and signaling connections are protected via HTTPS and TLS respectively. Supported direct transfers use the transport encryption provided by the WebRTC-/P2P method; If relay is technically required, data packets are only processed for forwarding. This does not promise general zero-knowledge or uniform end-to-end encryption across all functions. The specific protection depends on the function, platform and connection path.
16. TURN/Relay as an alternative connection
If a direct P2P connection is not possible or unstable, encrypted data packets can be temporarily routed via a TURN-/ relay server. The server processes IP addresses, ports, session and authentication data, times, data volume and temporarily the packets to be transported. Permanent cloud file storage is not the purpose of this function.
The legal basis is Article 6 Paragraph 1 Letter b GDPR; Security and capacity protocols are also based on Art. 6 Para. 1 lit. f GDPR.
Relay-/TURN buffers are used exclusively for ongoing transmission and are discarded after forwarding or at the latest when the session ends. No complete transferred files or chat content will be included in server backups. Caddy does not maintain a general file content or download log. The system can generate connection, error and security messages including IP addresses and timestamps; They are stored for a maximum of 14 days and then automatically deleted unless they are still needed due to a specific security incident or legal claim. In this exceptional case, data will only be stored until the investigation has been completed or until the relevant regular limitation period in accordance with Sections 195 and 199 of the German Civil Code (BGB) has expired. Traffic counters include license /billing month and byte quantity, but not file names or file contents. The server is not designed as a permanent storage or decryption archive for user content.
17. Files, chat, workspaces and file metadata
Remote functions allow content such as files, folder structures, file names, sizes, types, modification times, hashes, selection tabs, messages and status messages to be transferred between host and guest. The users involved determine the content and legality. We do not use this content for advertising, profiling or content analysis purposes.
Depending on the connection type, content is transmitted either directly by P2P or temporarily via a relay. It is not intended for permanent storage on our servers.
Users may not transmit unlawful content, malware, unauthorized personal data or content that violates the rights of third parties.
18. Browser-based HTTPS transfer and local protection features
With current browser-based HTTPS transfer, we do not maintain a server-side transfer journal and do not permanently store transferred files, file names, destination paths, or trash contents. Transmission data is only processed for the technical duration of the ongoing connection and is discarded after completion or termination. If the installed desktop application uses local resume, transfer journal or trash functions, this information is located exclusively on the respective device and is not transferred to us. Your local deletion depends on the user-triggered cleanup, restore, or uninstall.
19. Transfer volume and quotas
To bill or enforce tariff-dependent transmission limits, license / customer ID, billing month, tariff and transferred byte quantities can be processed. It is not necessary to save file contents or file names for pure quantity measurement.
According to the currently checked server status, the license-dependent monthly volume is counted exclusively based on the byte quantities forwarded via the relay/TURN service. Direct P2P data is not reported to the license server and does not count toward this relay volume. Before a relay transfer begins, the technically required quantity can be reserved; If the remaining volume is not enough, the relay transfer will not begin. Local organizational functions remain unaffected.
20. Abuse, fraud and attack detection
If necessary, to protect users, systems and licenses, we process IP addresses, timestamps, session, device and license identifiers, failed connection or activation attempts, unusual request sequences, data volumes, rate limit events, blocks and technical error data.
Purposes are in particular:
- Detection and mitigation of automated attacks, brute force attempts and denial of service;
- Prevention of unauthorized license transfer, manipulation and circumvention of quotas;
- Protection against malware transmission and misuse of remote functions;
- Resolving security incidents and preserving evidence;
- Enforcement or defense of legal claims.
The legal basis is Article 6 (1) (f) GDPR; In the case of statutory reporting or information obligations, additionally Art. 6 Para. 1 lit. c GDPR. If there are specific suspicions, data can be transmitted to the necessary extent to security service providers, legal advisors, courts or responsible authorities. There is no general monitoring of the content of private files.
21. Orders and Paddle as Merchant of Record
The sale of paid licenses takes place according to the intended checkout structure via Paddle as merchant of record and contractual partner of the buyer for payment. Paddle processes, under its own responsibility, in particular name, email address, billing address, country, tax /VAT information, shopping cart, price, currency, payment method, transaction, subscription, withdrawal, termination, refund, IP, device and fraud prevention data.
We receive from Paddle only the order, customer, tax, subscription and status data required for contract, license deployment, customer service, quota and entitlement management. We do not receive complete card or PayPal access data.
The Paddle company specified in the specific Paddle checkout, in the order confirmation and on the payment receipt is relevant. The current Buyer Terms linked there and the Paddle Privacy Notice apply to Paddle. The legal basis for our processing is Article 6 Paragraph 1 Letters b and c GDPR and Article 6 Paragraph 1 Letter f GDPR. To the extent that Paddle processes data under its own responsibility, Paddle decides on the relevant purposes, legal bases, recipients and international transfers.
Upon purchase, payment and billing information is processed within Paddle Checkout. Paddle acts as a merchant of record and handles payment collection, tax calculation, invoicing, refunds and chargebacks according to the conditions displayed in the checkout. The Paddle company specified in the respective checkout and receipt is relevant. Glass Desktop Box only receives the transaction, product, status and customer references necessary for license provisioning, contract management, support allocation and accounting; full card or PayPal credentials are not processed on proprietary systems.
22. Payment with PayPal within the Paddle checkout
If the buyer selects PayPal within the Paddle checkout, PayPal processes the account, device, financial and transaction data required for payment, identity / risk verification and legal compliance under its own responsibility. The PayPal Privacy Policy is relevant. We do not receive PayPal passwords and fundamentally no complete payment instrument data.
PayPal can process data worldwide and, according to its own statement, uses, among other things, intra-group agreements, standard contractual clauses or other legal transfer instruments.
23. Withdrawal, termination and refund functions
When you activate a cancellation or termination buttons or a refund request, we process and if necessary Paddle:
- Name, email address and customer /Order number;
- affected license or subscription;
- Explanation, selected action and optionally communicated reason;
- Time, confirmation and delivery status;
- technical evidence such as IP address and log entry, to the extent necessary for secure assignment and evidence;
- Refund, deactivation and communication status.
The purpose is to receive and implement the declaration, license / contract management, fulfill legal obligations and provide evidence. The legal basis is Article 6 Paragraph 1 Letter b and c GDPR and Article 6 Paragraph 1 Letter f GDPR.
For contracts for digital content not supplied on a tangible medium, a paying consumer's right of withdrawal expires under Section 356(6) BGB only where performance has begun after the consumer expressly consented to performance before the withdrawal period ended, acknowledged the resulting loss of that right, and received the contract confirmation required by Section 312f BGB. Acceptance of the Terms or EULA alone is insufficient. The contracting party responsible for the specific purchase retains the necessary checkout and contract evidence under Article 6(1)(b) and (c) GDPR. The Application's device-local EULA acceptance record is separate and is not transmitted to the provider.
Termination ends the contract at the legally relevant time and is not a withdrawal. For consumers, after the initial term the notice period is no more than one month. Advance payments are accounted for under statutory and contractual rules; amounts relating to periods after termination takes effect are not retained merely because Paddle technically uses a longer billing period.
For evidence of electronic contracting, the transaction ID, contract language, UTC timestamp, document versions, SHA-256 hashes and individual consent or acknowledgement events may be stored. No user files, Box names, backgrounds or file contents are processed. Privacy information is recorded as acknowledgement; voluntary marketing consent is recorded separately.
24. Support and email
When we contact you, we process sender and contact details, content and time of the message, associated customer-/License-/ order data as well as voluntarily transmitted screenshots, diagnostic or log files. Please remove any unnecessary personal or sensitive information prior to submission.
The legal basis is Art. 6 Para. 1 lit. b GDPR for contractual reference, otherwise Art. 6 Para. 1 lit. f GDPR. As far as legal evidence is concerned, Art. 6 Paragraph 1 Letter c GDPR applies.
Support and contact inquiries are stored until they are finally processed and then in principle for the duration of possible queries or legal statute of limitations and proof requirements. Purely general inquiries without reference to the contract are regularly deleted no later than twelve months after completion. Contractual, warranty and legal defense documents can be stored for longer until the expiry of the regular statute of limitations, booking or tax-relevant communication in accordance with the statutory retention periods. The email service provider used productively is listed in the internal recipient and processor directory.
24a. Accessibility requests and support needs
If you report a digital barrier or request an accessible alternative, we process your name or alias, contact method, affected page or function, description of the barrier, date and status of processing, and voluntarily provided information about the device, operating system, browser or assistive technology. Screenshots, recordings and diagnostic information will only be processed if you submit them voluntarily and they are necessary for the review.
The purposes are to address and remove barriers, to provide an accessible alternative, to fulfill legal proof and accessibility obligations, and to improve the website, checkout, contract processes and software. The legal basis is Art. 6 Para. 1 lit. c GDPR in conjunction with BFSG and BFSGV, Art. 6 Para. 1 lit. b GDPR for contractual reference and Art. 6 Para. 1 lit.
Accessibility requests are stored until final processing and then generally for twelve months for queries and quality control. If an official procedure, a legal documentation requirement or the defense of legal claims is involved, the necessary data can be retained until the procedure is completed or the statutory limitation period has expired. Reports can be sent to support@glassdesktopbox.com with the subject “Accessibility”.
25. Recipients and roles
Recipients can – only to the extent necessary – be:
- Hetzner and other technical processor;
- Paddle as Merchant of Record and independently controller;
- PayPal if selected as payment method;
- Email, signature, update or security service providers;
- Tax advisors, legal advisors, auditors, banks;
- Authorities and courts in the event of a legal obligation or for legal defense;
- the remote communication partner selected by the user.
When used for operational purposes, the using company is generally responsible for its employee, customer and project data. Host and guest may each bear their own data protection responsibility for the content they select and transmit. If Glass Desktop Box processes personal data on behalf of a business customer, it must be checked before use whether an agreement in accordance with Art. 28 GDPR is required.
For business customers who process personal data of third parties on their own responsibility, an agreement in accordance with Art. 28 GDPR including technical and organizational measures as well as the sub-processors used is provided - insofar as Glass Desktop Box acts legally as processor. Where Glass Desktop Box only enables a direct P2P connection and does not provide access to the content, host and guest remain responsible for the choice, legal basis and content of their transmission.
26. Third country transfers
We prefer processing in Germany or the European Economic Area. Paddle, PayPal, Google/YouTube or their subcontractors may be transferred to the United Kingdom, the USA or other third countries. It only takes place if the requirements of Article 44 ff. GDPR are met, for example due to an adequacy decision, suitable guarantees such as EU standard contractual clauses or a legal exception. Further details can be found in the data protection information of the respective recipient.
27. Storage period
We only store data for as long as the respective purpose exists and there are no legal or legitimate reasons to the contrary:
| Data category | Principle |
|---|---|
| Ephemeral session tokens/PIN-/TURN credentials | until expiration or end of session |
| Active signaling data | basically until the end of the session plus the technically necessary short follow-up time |
| Local box, journal and protection data | until deletion, cleanup or uninstallation by the user according to the local product logic |
| License and contract master data | for contract duration; then according to legal proof and limitation periods |
| Invoice and accounting documents | according to statutory commercial and tax retention periods |
| Support communication | until completion and then after the required proof / limitation periods |
| Proof of cancellation, termination and refund | as long as necessary for legal fulfillment and defense of claims |
| Security and abuse-prevention logs | only as long as necessary for defense, investigation and legal defense |
| Proof of consent | for the duration of use and thereafter as long as proof is legally required |
The following deadlines apply for deletion: volatile session, TURN and relay data will be deleted at the end of the session at the latest; technical connection, caddy, signaling, error and security logs generally after 14 days; Failed activation and misuse lockout data generally after 90 days. In the event of a specific security incident, necessary data may be stored until the investigation or legal defense has been completed. Monthly, content-free quantity meters will be deleted after the end of the contract and the required verification period has expired. Paddle webhook and contract status data are stored for the duration of the contract and then generally for three years to defend claims. Commercial and business letters are stored for six years, accounting documents for eight years and the documents mentioned in Section 147 Paragraph 1 No. 1 and 4a AO for ten years. Support processes not related to contract or security as well as completed accessibility requests are generally deleted twelve months after completion; Proof of withdrawal, consent, termination, reimbursement and contract confirmation are stored for the duration of the contract and then until the expiry of the regular limitation period.
28. Automated decisions and profiling
According to the current product status, we do not make exclusively automated decisions with legal or similarly significant effects and do not create advertising profiles. Technical rate limits or security blocks can be automated; a legitimate review can be requested via support.
Paddle or PayPal may make automated risk, fraud, compliance or payment decisions under its own responsibility. Details and rights can be found in their data protection information.
29. Data security
We use appropriate technical and organizational measures in accordance with Art. 32 GDPR. This may include transport encryption, hashed license / session secrets, ephemeral credentials, access restrictions, security event logging, rate limits, updates and backup measures.
No transmission and no system can guarantee absolute security. Users are jointly responsible for their choice of content, device protection, access data, operating system updates, malware protection and independent data backups.
The technical and organizational measures include, in particular, role- and purpose-related access rights, separate test and production environments, secure management of environment variables and keys, TLS-protected transmission, size and misuse limits, logging of security-relevant events, checksum and signature verification of updates, secured recovery processes, regular updating of components used, and a procedure for receiving, evaluating and resolving reports Vulnerabilities. Details are maintained risk-related in internal security documents.
30. Data breaches
Data protection violations are assessed, documented and - to the extent required by Art. 33 GDPR - reported to the responsible supervisory authority within the statutory deadline. If the risk is expected to be high, affected persons will be informed in accordance with Art. 34 GDPR. Reports of suspected security incidents can be directed to support@glassdesktopbox.com.
30a. Security notifications and the Cyber Resilience Act
For reports of vulnerabilities and security incidents, name or alias, contact details, affected version and platform, technical description, dates, log excerpts and voluntarily submitted evidence may be processed. Please do not submit user files or personal content unless this is absolutely necessary for the review.
The legal bases are Art. 6(1)(c) GDPR for compliance with statutory cybersecurity, documentation and reporting obligations and Art. 6(1)(f) GDPR for secure error analysis, coordinated vulnerability handling, protection of users and the establishment, exercise or defence of legal claims. Where necessary, information may be disclosed to hosting or security service providers, the competent CSIRTs, ENISA, market-surveillance authorities or law-enforcement authorities. Data is retained only for as long as necessary for remediation, evidence, statutory reporting and applicable limitation periods.
The reporting obligations for actively exploited vulnerabilities and serious security incidents in accordance with Article 14 of Regulation (EU) 2024/2847 apply from September 11, 2026; The other main obligations of the regulation generally apply from December 11, 2027. The internal processes will be set up before the respective deadlines.
Security reports can be sent to support@glassdesktopbox.com with the subject “Security Report”. The provider documents receipt, criticality, affected version, remediation actions, and required notifications. The legal reporting processes for actively exploited vulnerabilities and serious security incidents will be converted into a formal coordinated vulnerability disclosure and escalation procedure at the latest when they come into force.
31. Rights of data subjects
Affected persons have the right to:
- Information (Article 15 GDPR);
- Correction (Art. 16 GDPR);
- Deletion (Article 17 GDPR);
- Restriction of processing (Article 18 GDPR);
- Information of recipients (Art. 19 GDPR);
- Data portability (Art. 20 GDPR);
- Objection (Art. 21 GDPR);
- withdrawal consent for the future (Art. 7 Para. 3 GDPR);
- Protection against exclusively automated decisions (Art. 22 GDPR).
Inquiries should be directed to support@glassdesktopbox.com. To prevent unauthorized information, we may request appropriate proof of identity. Rights may be subject to legal restrictions.
32. Special note on objection
If data is processed on the basis of Art. 6 Para. 1 lit. f GDPR, you can object at any time for reasons arising from your particular situation. We will then no longer process the data unless there are compelling legitimate reasons or grounds for asserting, exercising or defending legal claims. According to the current status, direct advertising does not take place; Any use can be objected to at any time without giving reasons.
33. Right of appeal
You can complain to a data protection supervisory authority. The person responsible is in particular responsible for:
The Brandenburg State Commissioner for Data Protection and the Right to Inspect Files
Stahnsdorfer Damm 77
14532 Kleinmachnow
Telephone: +49 33203 356-0
Email: Poststelle@LDA.Brandenburg.de
Website: https://www.lda.brandenburg.de ↗
34. Minors
The offer is not aimed specifically at children. Contracts for paid licenses may only be concluded by persons with legal capacity or with the necessary consent. If we become aware of children's data that has been processed unlawfully, it will be deleted after checking, unless there is an obligation to retain it.
35. No sale or advertising use of file contents
We do not sell personal information. Shared file, chat, or workspace content is not used to build advertising profiles, train general AI models, or provide personalized advertising.
36. Changes
We adapt this statement if functions, service providers or legal situation change. Significant changes will be announced in an appropriate manner. The published version with date is relevant.
37. Contact
Privacy requests: support@glassdesktopbox.com
Michael Höhne
Rangsdorfer Software Company
Akazienweg 13
15834 Rangsdorf
Germany