This policy applies to customers, employees and other authorized users of our JD Mail, JD Partner and JD Leads platforms.
Version 0.7 · Last updated 22 September 2026
1. Controller
JD Media GmbH, Nördliche Münchner Straße 9c, 82031 Grünwald
Local Court of Munich HRB 235687, Managing Director: Jasmin Jasko Demic
E-mail: datenschutz@jd-media.net
You can contact our external data protection officer by e-mail at datenschutzbeauftragter@er-secure.de.
For general questions regarding data protection, you can continue to reach us at datenschutz@jd-media.net.
2. What this policy covers and what it does not
This policy applies to the use of our platforms JD Mail, JD Partner and JD Leads by our customers and their staff, to visitors of the associated websites, and to contact persons at external companies invited as guest publishers to a specific campaign on JD Partner. Where reference is made below to “the platform”, the statement applies to all three platforms; where a statement applies to only one of them, this is indicated.
This policy does not cover the processing of the recipient and participant data that our customers manage within the platform. As a rule, the respective customer is responsible for that processing; we process the data predominantly on his behalf pursuant to Art. 28 GDPR. Limited processing for our own purposes, in particular platform-wide suppression lists, abuse prevention and spam trap analysis, as well as the special allocation of roles on JD Partner and JD Leads, are described in the data processing agreement (processing on behalf, Art. 28 GDPR). Participants in a prize draw operated via JD Leads receive the privacy policy applicable to them from the respective organiser within the generator. Recipients of an e-mail sent via JD Mail or on the basis of a JD Partner booking should address their concerns to the sender named in the respective e-mail; the unsubscribe and information pages provided there are available to them.
3. Visiting our websites
Each time our websites are accessed, data is stored in a log file: IP address, date and time, address accessed, volume of data transferred, notification of whether the retrieval was successful, referring page as well as information on browser and operating system.
- Purpose: establishing the connection, stability and security of the systems, prevention and investigation of attacks
- Legal basis: Art. 6(1)(f) GDPR; the legitimate interest is secure operation
- Duration: 14 days, longer storage only in the event of a specific security incident
4. Registration and user account
For registration we process: last name, first name, position, user name, e-mail address, password (stored only as a hash value), company name, address, country, VAT identification number, bank details as well as the contact addresses for data protection and accounting.
- Purpose: establishment and performance of the usage contract, invoicing, details that appear externally in sent e-mails and statements of account
- Legal basis: Art. 6(1)(b) GDPR if you are personally a party to the contract. If you act for a company as an employee, corporate body or other authorised representative, the legal basis is Art. 6(1)(f) GDPR; our legitimate interest and that of the company consist in initiating, performing and settling the company contract and administering its authorised users.
- Duration: for the term of the contract; thereafter until expiry of the applicable retention periods under commercial and tax law. Accounting vouchers are generally retained for eight years, commercial books and annual financial statements for ten years and commercial letters for six years. Where several periods apply, the longer period prevails.
5. Login and account security
We log logins and logouts with time, IP address and details of the device used, and we count failed login attempts in order to make attacks on accounts more difficult. You can view this information in your account.
- Purpose: protection against unauthorised access, traceability
- Legal basis: Art. 6(1)(f) GDPR
- Duration: 90 days
When you switch between our platforms, we generate a single-use, short-lived login key so that you do not have to log in again.
6. Use of the platform
We log changes to ad spaces, campaigns, suppression lists and accounts with time, operation and the account that triggered them.
- Purpose: traceability of changes, troubleshooting, abuse prevention
- Legal basis: Art. 6(1)(b) and (f) GDPR
- Duration: for the term of the contract
Where we provide a customer or partner with API access, we process the name and hash value of the API key, assigned advertising spaces, permissions, request times and rate limits. Where IP binding has been agreed, we additionally process the permitted IP addresses; for rejected access attempts, we also process the time, IP address, requested endpoint and details of the requesting program.
- Purpose: provision and protection of the interface, authorization control, limitation of automated requests and prevention of abuse
- Legal basis: Art. 6(1)(b) GDPR where you are yourself a party to the contract, otherwise Art. 6(1)(f) GDPR based on the legitimate interest in secure and traceable interface operation
- Duration: access data and permissions for the duration of API access; access and rejection logs only for as long as required for security, troubleshooting and prevention of abuse
7. Cookies and similar technologies
We use a session cookie that keeps you logged in. Without selecting “stay logged in”, the login expires after 30 days at the latest. If you select “stay logged in”, the lifetime is up to 365 days. For file downloads, a technical cookie indicating completion of the download may additionally be set for a maximum of 60 seconds.
Your language selection is stored for up to 365 days in a technically necessary cookie. In your browser's local storage, we also retain only functional settings and working states, such as open sections, notification settings, hidden help content and local drafts. This information remains stored until it is changed, deleted by the relevant function or cleared from the browser, and is not used for audience measurement or advertising.
These cookies are strictly necessary for the operation of the platform; consent is therefore not required pursuant to Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). The legal basis for the subsequent processing is Art. 6(1)(b) GDPR if you are personally a party to the contract; otherwise it is Art. 6(1)(f) GDPR, based on the legitimate interest in providing authorised company users with secure platform access.
We do not use analytics or advertising cookies on the platform.
8. Integrated third-party services
On JD Mail, the fonts and program libraries we use are delivered from our own servers. On JD Partner and JD Leads, individual pages may retrieve fonts or program libraries directly from Google Fonts, cdnjs or Cloudflare, jsDelivr or StackPath. During retrieval, the respective provider technically receives, in particular, your IP address, the time and destination of the request and browser information. The purpose is the technically reliable and consistent display of the platform. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and economical provision of these components. Where a provider processes data outside the EU or the EEA, this takes place only subject to the requirements of Art. 44 et seq. GDPR. Content inserted by customers into campaigns or previews may contain further links or images from external providers. The respective customer is responsible for selecting and integrating such customer content in compliance with data protection law.
9. Communication and support
If you contact us by e-mail or telephone, we process your details in order to handle your enquiry (Art. 6(1)(b) and (f) GDPR). We delete the correspondence once it is no longer needed and no retention obligation exists.
10. Domain order
If you order a domain via the platform, we transmit the details required for registration to the registry and to the commissioned registrar. The legal basis is Art. 6(1)(b) GDPR if you are personally a party to the contract; otherwise it is Art. 6(1)(f) GDPR, based on the legitimate interest in carrying out the registration commissioned by the company.
11. Lead shop
If you order data records via the lead shop, we transmit your order and company data to the respective supplier so that the supplier can deliver and invoice. The legal basis is Art. 6(1)(b) GDPR if you are personally a party to the contract; otherwise it is Art. 6(1)(f) GDPR, based on the legitimate interest in performing and settling the order initiated by the company.
12. Generators and sponsor orders on JD Leads
If you operate a generator on JD Leads, we process your generator, domain, form, message, sponsor, order and billing settings as well as the participant legal texts you maintain. In the case of multi-step forms, technical draft and access logs are created. As a rule, we process personal participant data on your behalf; details are governed by the data processing agreement.
If you assign a sponsor or a receiving customer to a generator, we transmit to the parties involved the company, contact, order and provisioning data required for order performance, proof, delivery and billing. The brokered contract and the payment are concluded directly between the companies involved.
- Purpose: operation and embedding of the generators, performance of the confirmation procedure, administration of sponsor orders, technical lead delivery and billing between the parties involved
- Legal basis: Art. 6(1)(b) GDPR if you are personally a party to the contract; if you act for a company, Art. 6(1)(f) GDPR, based on the legitimate interest in performing and settling the company contracts. Art. 6(1)(f) GDPR additionally applies to security, consent and authorisation logs.
- Duration: settings and contract data for the term of the usage contract, thereafter in accordance with the statutory retention and limitation periods; incomplete participant form drafts are deleted as order data at the latest 24 hours after the last editing
13. Brokered contracts and guest publishers on JD Partner
On JD Partner we broker contracts between our customers: one customer offers an advertising placement (publisher), another books it (advertiser). The advertising contract is concluded directly between the two. We do not become a party to this contract and are not involved in the payment between the parties.
So that both sides can conclude the contract and settle accounts with each other, we pass on details about you to the other side: the company and contact details of your account including the details of the person acting for you, the requests, counter-offers, acceptances and rejections with their content, the events and evaluations recorded for a booking, the details required for invoicing, in particular the invoicing address and VAT identification number, so that the other side can issue its invoice itself, and finally complaints, formal warning letters (Abmahnungen) and official enquiries relating to a delivered campaign.
- Purpose: initiation, conclusion and performance of the brokered advertising contract as well as the settlement of accounts between the parties involved
- Legal basis: Art. 6(1)(b) GDPR if you are personally a party to the contract; if you act for a company, Art. 6(1)(f) GDPR, based on the legitimate interest in initiating, performing and settling the company contract. Art. 6(1)(f) GDPR additionally applies to forwarding complaints, formal warning letters (Abmahnungen) and official enquiries; the legitimate interest is the clarification of such matters between the parties involved.
- Duration: We retain event-related data and sub-identifiers until expiry of the cancellation, subsequent-labelling and objection periods and until pending objections have been settled, at the longest in accordance with § 16 paragraph 11 of the data processing agreement. Beyond that, we retain booking master data and billing records only insofar as obligations under commercial or tax law exist or they are required for the assertion or defence of claims.
Invoices arising from the brokered contract are issued by the parties themselves; we do not issue them in their name and do not accept any payments. The other side processes the details received under its own responsibility; there is no processing on our behalf pursuant to Art. 28 GDPR in this respect. You decide yourself which details are stored in your account; without the details required for invoicing, a booking cannot be settled between the parties involved.
If an advertiser invites a company not yet registered as a publisher to a specific campaign as a guest publisher, we receive from the advertiser the company name, the name of the contact person, the business e-mail address and campaign-related details. The source of this data is the inviting advertiser. We initially process it on the advertiser's behalf in order to transmit the specific invitation, provide campaign-related guest access and technically process the booking. Details are set out in § 16 paragraph 12 of the data processing agreement.
In direct connection with this invitation, we may notify the guest publisher once about free registration as a publisher and offer registration. For this registration notice, we act as an independent controller. The advertiser warrants to us that the contact person has previously expressly consented to receive the specific invitation and this one-time notice by e-mail. Any further advertising communication takes place only where we have our own statutory permission or consent.
- Purpose: transmission and processing of the specific campaign invitation and a one-time offer of free publisher registration
- Legal basis: Art. 6(1)(a) GDPR for sending the invitation and the one-time registration notice on the basis of the consent documented by the advertiser; additionally Art. 6(1)(f) GDPR for technical provision and abuse prevention, based on the legitimate interests in securely carrying out the requested initiation of a business relationship and protecting the platform
- Information pursuant to Art. 14 GDPR: As the contact details originate from the advertiser, we provide this information no later than with the first communication to the guest publisher.
- Duration: If neither a guest booking nor a registration takes place, we delete the contact details no later than 90 days after the invitation, unless we require them to document consent, withdrawal or an objection until the expiry of statutory limitation periods. If a booking or registration takes place, the periods stated for it in this policy and in the data processing agreement apply.
- Withdrawal and objection: Consent may be withdrawn at any time with effect for the future. An objection or withdrawal ends any further registration notice; we may retain the required suppression information to prevent renewed contact.
14. Recipients of your data
| Recipient | Purpose |
|---|---|
| Other customers of the platform (publisher or advertiser) | Conclusion, performance and settlement of an advertising contract brokered on JD Partner (No. 13) |
| Invited guest publishers or inviting advertisers | Transmission and processing of a specific guest-publisher invitation and booking on JD Partner (No. 13) |
| Suppliers in the lead shop | Delivery and billing of ordered data records (No. 11) |
| Sponsors, suppliers and receiving customers on JD Leads | Performance, proof, delivery and billing of a sponsor or lead order (No. 12) |
| Registries and registrars | Registration of ordered domains (No. 10) |
| easyname GmbH, Vienna, Austria | Provision and housing of the servers |
| Nessus GmbH, Vienna, Austria | Operation of the data centre and the network |
| IONOS SE, Germany | Backup copies |
| Providers of externally loaded fonts and program libraries: Google Fonts, cdnjs or Cloudflare, jsDelivr and StackPath | Delivery of the components referred to in No. 8 |
| Tax advice and accounting | statutory obligations |
| Legal advice, collection of our own receivables, courts and authorities | where necessary or legally required |
Where service providers process personal data on our behalf, the requirements of Art. 28 GDPR apply. Recipients who use the details for their own purposes, in particular other customers of the platform, suppliers in the lead shop as well as registries and registrars, are themselves responsible for their processing.
15. Storage period
We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention periods exist. Insofar as operational backup copies exist, the data contained therein is no longer actively processed until it is overwritten as scheduled and is deleted thereafter. Individual backups may be retained for longer if this is necessary for restoration after a security incident or to fulfil statutory evidence and retention obligations; they are deleted once that purpose ceases to apply. No fixed backup frequency or retention period is promised in this privacy policy.
16. Your rights
You have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) as well as to object to processing based on legitimate interests (Art. 21 GDPR). You may withdraw consent given at any time with effect for the future.
You may also lodge a complaint with a supervisory authority. The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA, Bavarian Data Protection Authority), Promenade 18, 91522 Ansbach.
17. Obligation to provide data
The details provided at registration are required for the conclusion of the contract. Without them we cannot provide the platform.
18. Automated evaluation of accesses
Whether a recorded event such as a delivery, an open or a click counts as billable is assessed by us on a rule-based basis. The characteristics of the accessing network, technical identifiers of the retrieving program and temporal patterns are taken into account. Accesses which on that basis do not originate from humans are marked separately and are not billed. The assessment concerns the individual access and the resulting billing, not you as a person.
You may object to the result: for the measured values the procedure under § 7 paragraph 7 of our General Terms and Conditions applies, and for the release and cancellation of individual events on JD Partner § H4. We examine the objection and reply in text form stating the decisive reasons; a human decides on the objection.
Beyond that, we do not take any decision based solely on automated processing in an individual case which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). No profiling for advertising purposes takes place.
19. Changes to this policy
We adapt this policy if the processing or the legal situation changes. The version published on the platform at the relevant time applies.
As of: 22.09.2026
