This notice explains how ShieldIT UG (haftungsbeschränkt) processes personal data when you visit or use MadeForMachine. It covers our public websites and APIs, customer workspace, MCP service, support, and related communications.
1. Controller and privacy contact
ShieldIT UG (haftungsbeschränkt)Kastanienstraße 33
15366 Neuenhagen bei Berlin
Germany
Managing Director and data privacy contact: Simon Eichenauer
Email: contact@madeformachine.com
2. Data we process
- Website and API access data: IP address, date and time, requested host and path, request method, response status, referrer, user agent, and related security and diagnostic data.
- Account and workspace data: Kinde user and organization identifiers, name, email address, profile image where provided, workspace name, roles, membership, and authentication and session data. Kinde handles your sign-in credentials; we do not receive your password.
- Service and Customer Content: project names and descriptions, specifications and revision history, rules and policy settings, agent requests, actor attribution, timestamps, MCP client and connection data, and other content you choose to submit.
- Communications: your email address, message, and related correspondence when you contact us.
If your organization provides your account, we may receive account, role, and workspace information from that organization or its administrator. Customer Content may contain personal data about other people if you put it there; you and your organization are responsible for ensuring that this is lawful.
3. Purposes and legal bases
- To create and manage accounts and workspaces, authenticate users and agents, store and version specifications, provide requested API and MCP operations, and support users. The legal basis is Article 6(1)(b) GDPR (contract and pre-contractual steps).
- To secure the Service, prevent abuse, diagnose faults, maintain availability, and keep necessary audit trails. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are operating a secure, reliable, and attributable service.
- To respond to general inquiries and communicate about the Service. The legal basis is Article 6(1)(b) GDPR where the inquiry relates to a contract and otherwise Article 6(1)(f) GDPR (effective business communication).
- To meet tax, accounting, regulatory, and legal obligations and to establish, exercise, or defend legal claims. The legal bases are Article 6(1)(c) and, where applicable, Article 6(1)(f) GDPR.
- Where we expressly ask for consent for an optional purpose, the legal basis is Article 6(1)(a) GDPR. You may withdraw consent at any time without affecting earlier lawful processing.
We do not use Customer Content to make decisions with legal or similarly significant effects about individuals. MadeForMachine does not run server-side model inference on Customer Content as part of the Service's operational path.
4. Cookies and local storage
We use only storage that is necessary to deliver the Service, including authentication and session cookies set through our Kinde integration. We also store your theme preference locally in your browser. Necessary storage is used under § 25(2)(2) TDDDG; related personal-data processing is based on Article 6(1)(b) or 6(1)(f) GDPR.
We currently do not use advertising cookies or third-party analytics on MadeForMachine, and we do not create advertising profiles.
5. Data required to use the Service
You can use the public website and public Atlas interfaces without an account. Identity and workspace data are required to create an account and use authenticated workspace or MCP features; without them, we cannot provide those features. Customer Content is provided at your choice, although particular operations cannot work without the content they are meant to store, validate, or return.
6. Recipients and service providers
Personal data is available only to people and providers who need it for the purposes above. This may include:
- Kinde, which provides identity, authentication, organization, and session services (see Kinde's privacy information);
- hosting, network, database, and backup infrastructure providers, including DigitalOcean for private off-site backup storage;
- email and support infrastructure providers;
- professional advisers, courts, regulators, and public authorities where disclosure is necessary or legally required; and
- a successor in connection with a merger, financing, reorganization, or transfer of the business, subject to appropriate confidentiality and data-protection safeguards.
Providers acting on our instructions are bound by data-processing and confidentiality obligations. We do not sell personal data.
7. International transfers
Some providers or their subprocessors may process data outside the European Economic Area. Where no adequacy decision applies, we use an approved transfer mechanism such as the European Commission's Standard Contractual Clauses and additional safeguards where required. Kinde's own privacy information describes its locations and transfer safeguards.
8. Retention
- Account, workspace, and Customer Content are kept while the account or workspace is active and thereafter only as necessary to complete closure, comply with law, resolve disputes, and protect legitimate interests.
- Revision and attribution records are intentionally durable while a hosted project exists so the project history remains auditable.
- Operational access and security data are kept only as long as needed for security, fault investigation, and abuse prevention.
- Local service backups are normally retained for up to 15 days and private off-site backups for up to 45 days. Deleted data may remain in a backup until that backup expires.
- Business correspondence and records subject to statutory retention duties are retained for the applicable legal period.
You may request account or workspace closure by email. Because hosted specifications include immutable revision and audit history, we will confirm the export, deletion, and legally required retention steps with the workspace administrator before permanently removing a workspace.
9. Security
We use appropriate technical and organizational measures designed to protect personal data, including encrypted transport, tenant-scoped access controls, restricted credentials, isolated service databases, and controlled backups. No internet service can guarantee absolute security. Please contact us promptly if you believe data or an account has been compromised.
10. Your rights
Subject to the GDPR's conditions and exceptions, you may have the right to:
- access your personal data (Article 15);
- correct inaccurate or incomplete data (Article 16);
- request erasure (Article 17);
- restrict processing (Article 18);
- receive portable data you provided (Article 20);
- object to processing based on legitimate interests (Article 21); and
- withdraw consent at any time (Article 7(3)).
To exercise a right, email contact@madeformachine.com. We may need to verify your identity and, for organization-managed accounts, coordinate with the workspace administrator.
11. Complaints
You may complain to a data-protection supervisory authority, in particular in the EU member state of your residence, workplace, or the alleged infringement. Our competent authority is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht BrandenburgStahnsdorfer Damm 77
14532 Kleinmachnow
Germany
lda.brandenburg.de
12. Changes to this notice
We may update this notice when the Service or applicable requirements change. The date at the top identifies the current version. We will provide additional notice where a change materially affects registered users or where law requires it.