Privacy Policy
This policy informs about which personal data is processed when using kapnula.de, for what purposes, and what rights affected individuals have.
1. Controller
Vladimir Caplun
Kapnula
Willy-A.-Kleinau-Weg 30
14480 Potsdam
Germany
Phone: +49 1573 3981069
Email: vladimir.caplun@gmail.com
A data protection officer is currently not appointed. Data protection inquiries can be sent directly to the email address above or via the contact form.
2. Hosting and Server Logs
The website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. IONOS processes technical data as part of providing and securing the web hosting.
When accessing the website, IP address, date and time, requested URL, data volume, referrer URL, browser, operating system and status code may be processed in server logs. Processing serves secure and stable provision, error analysis and defense against abusive access.
Legal basis: Art. 6 para. 1 lit. f GDPR. The legitimate interest is the safe, reliable and technically error-free operation of the platform.
Security log: To defend against attacks and abuse, the platform keeps an internal security log. For security-relevant events (e.g. rate-limit violations, automated attack patterns or bot detection) it stores timestamp, IP address, requested URL and user agent. The log is used solely for attack detection, blocking malicious IPs and forensic analysis by the operator. It is not publicly accessible and is retained for a limited time only (rotating log file, max. approx. 512 KB per file).
3. Registration, Account and Profile
During registration, username, email address, password in cryptographically protected form and technical security data are processed. Voluntarily, additional profile information such as name, residence, profile picture or description can be provided.
This data is used to provide the account, enable logins, prevent abuse and send account-related notifications.
Legal basis: Art. 6 para. 1 lit. b GDPR for providing the account; Art. 6 para. 1 lit. f GDPR for security and abuse prevention.
4. Listings, Images and Public Content
For a listing, the content entered by the user is processed: title, description, category, price, condition, location, contact details, images and category-specific data. Published listings and public profile information are visible to platform visitors and may be indexed by search engines, unless the page is excluded from indexing.
Users should not publish unnecessary sensitive data, identity documents, full private addresses or data of uninvolved third parties.
Legal basis: Art. 6 para. 1 lit. b GDPR for publishing and managing the listing; Art. 6 para. 1 lit. f GDPR for moderation, fraud prevention and enforcement of platform rules.
5. Messages, Contact Form and Support
When using internal messaging or the contact form, sender data, recipient, message content, time and technically required metadata are processed. The data serves transmission, processing of inquiries, conflict resolution and abuse prevention.
Legal basis: Art. 6 para. 1 lit. b GDPR where communication is necessary for using the platform; otherwise Art. 6 para. 1 lit. f GDPR. Legally required retention is based on Art. 6 para. 1 lit. c GDPR.
6. Moderation, Reports and Security
To detect and handle spam, fraud, illegal content, security incidents and violations of terms, account, content, communication and log data may be evaluated. Reported content may be documented and temporarily preserved if necessary.
Kapnula also operates an automated content filter that screens submitted listings, comments and messages for prohibited content (including adult content, narcotics, weapons, forged documents and typical fraud patterns). On detection, a violation record is stored containing username, IP address, timestamp, affected content, matched rule and the action taken. Additionally, the IP address and technical device signature are stored when each listing is submitted and may be mapped to an approximate region via the Geo-IP service ip-api.com for abuse prevention.
Legal basis: Art. 6 para. 1 lit. f GDPR; for legal reporting, information or retention obligations, Art. 6 para. 1 lit. c GDPR.
8. OpenStreetMap Maps
A map is only loaded after the user clicks the corresponding button. A connection to OpenStreetMap services is established; in particular, the IP address may be transmitted. OpenStreetMap is the responsibility of the OpenStreetMap Foundation, UK. More information: OpenStreetMap Foundation Privacy Policy.
Without the user's active request, the external map is not loaded. Alternatively, the location can be used without an embedded map.
9. Recipients and Transfers
Data is only received by parties that need it for the respective purpose: hosting provider IONOS, technical service providers within the framework of commissioned processing, communication partners within the platform, and authorities or courts where legally required. For abuse prevention, IP addresses may also be transmitted to the Geo-IP service ip-api.com (USA) for approximate region determination.
Paid transfer of personal data for advertising purposes does not occur. When external services outside the EEA are deliberately accessed, their privacy policies and applicable transfer mechanisms apply additionally.
10. Retention Period
Data is stored only as long as necessary for the respective purpose, platform security, processing of open matters or legal obligations. Account data is processed until account deletion. Public listings are stored until deletion, deactivation or expiry. Security and evidence data may be retained beyond this point if necessary for defending or enforcing claims or by law.
Specifically: the content filter violation log is deleted automatically after 90 days. IP assignments to listings are deleted when the listing is removed, and no later than 90 days after removal. The Geo-IP cache is cleared after 12 months. Where an official or judicial proceeding is pending, individual records may be placed under legal hold and excluded from automatic deletion.
11. Rights of Affected Individuals
Affected individuals have the right to access, correction, deletion, restriction of processing, data portability and objection. Given consent can be revoked at any time with effect for the future.
Objection to processing based on Art. 6 para. 1 lit. f GDPR can be made for reasons arising from the particular situation of the affected person. Requests can be sent to vladimir.caplun@gmail.com. To protect the account, proof of identity may be required.
No exclusively automated decision-making with legal or comparably significant effect takes place.
12. Right to Complain to a Supervisory Authority
Affected individuals can complain to a data protection supervisory authority. For the controller's seat, the following is responsible:
The State Commissioner for Data Protection and the Right to Access Documents Brandenburg
Stahnsdorfer Damm 77
14532 Kleinmachnow
Germany
Phone: +49 33203 356-0
Email: poststelle@lda.brandenburg.de
Online complaint form
13. Security and Changes
Kapnula uses HTTPS and appropriate technical and organizational measures to protect data from unauthorized access, loss and manipulation. Absolute protection cannot be guaranteed for electronic communication.
This privacy policy is adjusted when functions, providers or legal requirements change. The current version is available at kapnula.de/datenschutz.html.