MSAIDIO · Updated: 18 September 2026
Privacy notice
- Controller and contact
- Website and enquiries
- Applications and project records
- Access and necessary cookies
- Service providers and recipients
- International projects
- Retention and security
- Your rights
Controller and contact
The controller for this website, enquiries to MSAIDIO and its own business administration is Hans-Dieter Allgaier (sole trader), Im Lontel 51, 71254 Ditzingen, Germany. Email: info@msaidio.com. This notice covers msaidio.com, www.msaidio.com and the technical operation of app.msaidio.com.
Website and enquiries
Visiting the website involves processing connection information, including your IP address, time, requested address and information transmitted by your browser. This enables delivery, troubleshooting and protection against misuse. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in operating a secure, functioning service. For email enquiries we process sender details, contact information and message content to respond. Article 6(1)(b) applies to enquiries concerning a contract with you or steps requested before entering one; other enquiries are handled under our legitimate interest in communication under Article 6(1)(f). We may be unable to respond without the necessary contact details.
Applications and project records
The funding organisation determines the purposes, legal bases and retention of project ideas, applications, budgets, contact details, bank details, contracts, receipts, photographs and reports. MSAIDIO provides the technical platform. Authorised staff or project partners may also supply information. Processing steps and previous versions are stored for traceability. Drafts are also stored on the server when the relevant save actions are used. Ask the organisation that invited you for its privacy information and to exercise your rights; we can help identify the organisation. This general notice does not replace its information. Provide only necessary information, particularly avoiding unnecessary beneficiary names, health information or identifiable photographs.
Access and necessary cookies
The public information website uses no analytics or advertising cookies. Fonts and images are served locally. The app requires cookies for login, form protection and status messages: sessionid (normally up to 14 days; a partner session opened through an invitation link lasts one hour), csrftoken (up to 364 days), and, where needed, messages (temporary messages until displayed or the browser session ends). The app language is stored in the session. Lifetimes may restart when the service is used again. These functions rely on section 25(2)(2) TDDDG; subsequent processing serves secure operation under Article 6(1)(f) GDPR or the relevant contractual service. Blocking necessary cookies may prevent login and form use. No advertising tracking or personalised advertising analysis is embedded.
Service providers and recipients
The website and app run on a server provided by netcup GmbH. Email is provided by ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich. The data required for hosting or sending messages is processed by those providers; invitation emails contain personal access links. Project content is accessible according to permissions to the relevant organisation, assigned partners and administrators as required for operation. Uploaded files are scanned for malware on the server. Exchange rates are fetched without transmitting application content. Personal data is not sold.
International projects
Access by invited partners abroad depends on the organisation and project. Before sharing data or granting access, the organisation must determine the recipients and countries involved and the requirements for transfers outside the EEA. Ask the inviting organisation about applicable safeguards and project-specific information. Worldwide availability of the website does not provide blanket permission to disclose project information.
Retention and security
Contact and business information is retained as required for handling enquiries, fulfilling contracts, statutory retention duties or establishing or defending claims. Technical error information is used for troubleshooting and security review; there is currently no fixed time-based deletion schedule for all technical logs. Project records and versions are managed according to the responsible organisation’s instructions; no general automatic deletion period is currently configured. You can request deletion using the contact above. Local backups retain the latest 14 successful backup sets. Deleted information may remain until those sets rotate; 14 sets do not necessarily mean 14 days if backups fail. Connections use HTTPS. Roles and access restrictions protect project information; bank details are additionally encrypted within the application.
Your rights
Subject to the applicable legal requirements, you have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time for future processing. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. Contact info@msaidio.com, or the responsible organisation for project information. You may complain to a supervisory authority, particularly where you live or work or where an alleged infringement occurred. The operator’s regional authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg. Authorised people decide on funding; the platform does not make solely automated decisions producing legal or similarly significant effects.