Privacy Policy
Last updated: 6 September 2026
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Bostrot Inh. Eric Trenkel
Kölner Str. 71
50259 Pulheim, Germany
Email: [email protected]
Phone: +49 2405 4079440
We have not appointed a data protection officer, as we are not required to do so under Art. 37 GDPR in conjunction with § 38 BDSG.
2. Hosting and server log files
This website is hosted on GitLab Pages, a service of GitLab Inc., 268 Bush Street #350, San Francisco, CA 94104, USA. When you visit the site, the hosting provider automatically collects and stores information transmitted by your browser in server log files: IP address, date and time of the request, the page requested, referrer URL, browser type and version, and operating system.
This processing is based on our legitimate interest in operating and securing the website (Art. 6 (1) (f) GDPR). Transfers to the USA are safeguarded by the EU-US Data Privacy Framework and/or standard contractual clauses under Art. 46 GDPR. See GitLab’s privacy statement.
3. Cookies and local storage
This website itself sets no cookies and stores no information on your device beyond what is technically required to display the page. No consent banner is therefore required under § 25 TDDDG.
If you proceed to checkout, Stripe sets its own cookies on Stripe’s domain to process the payment and prevent fraud. That processing is governed by Stripe’s privacy policy, linked in section 5.
4. Analytics (Plausible)
We use Plausible Analytics, which we host ourselves on our own infrastructure at analytics.bostrot.com. Plausible is cookieless, does not store any information on your device, does not create cross-site or cross-device profiles, and does not store IP addresses. Page views are aggregated into anonymous statistics that cannot be traced back to an individual.
The legal basis is our legitimate interest in understanding how the site is used and improving it (Art. 6 (1) (f) GDPR). Because no information is stored on or read from your device, no consent under § 25 TDDDG is required. No data is transferred to third parties.
5. Purchases and payment processing (Stripe)
Payments are handled by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. When you buy a licence you are redirected to a checkout page hosted by Stripe.
Stripe processes the data you enter there: your email address, name, billing address, payment method details and, for commercial licences, your business name. We never receive or store your card details. We receive from Stripe your email address, name, country, the purchased product, the amount, and a customer and transaction identifier, so that we can issue the licence and the invoice.
The legal basis is the performance of the contract with you (Art. 6 (1) (b) GDPR) and, for the statutory retention of accounting records, compliance with a legal obligation (Art. 6 (1) (c) GDPR). Stripe may transfer data to Stripe, Inc. in the USA on the basis of the EU-US Data Privacy Framework and standard contractual clauses. See Stripe’s privacy policy.
6. Licence issuing and validation
Licence keys are generated and stored on our own server at n8n.aachen.dev, located in Germany. We store the following for each licence: email address, Stripe customer and checkout identifiers, the licence key, the plan, the number of seats and, for commercial licences, the business name.
When the WSL Manager application checks whether a licence is valid, it transmits the licence key to that server; your IP address is necessarily processed as part of that request. This is required to perform the contract and to prevent misuse of licences (Art. 6 (1) (b) and (f) GDPR).
7. Retention
We keep licence data for as long as the licence is valid and you may need support for it. Invoices and other accounting records are retained for eight years and commercial correspondence for six years, as required by § 147 AO and § 257 HGB. After those periods the data is deleted or anonymised.
8. Your rights
You have the right to obtain access to your personal data (Art. 15 GDPR), to have inaccurate data rectified (Art. 16), to have data erased (Art. 17), to have processing restricted (Art. 18), to data portability (Art. 20), and to withdraw consent at any time with effect for the future.
You also have the right to object under Art. 21 GDPR to processing based on Art. 6 (1) (f) GDPR on grounds relating to your particular situation. To exercise any of these rights, contact us at the address in section 1.
You may also lodge a complaint with a supervisory authority. The authority responsible for us is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
9. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
10. Changes to this policy
We may update this policy to reflect changes to the service or to legal requirements. The version published here, with the date shown above, always applies.