Stage
Privacy
How stage.dev processes data.
Controller
SKYYWARE UG, Aichenbachstraße 27, 73614 Schorndorf, Germany, represented by Sascha Dobrochynskyy, is responsible for personal data processing on stage.dev. Contact office@skyyware.com for privacy enquiries.
Public pages
Reading the public website requires no account. These pages set no cookies and store no browser preferences. There are no analytics or advertising services. Fonts and other page resources are served by this website. Links to GitHub, Packagist, and other websites are ordinary links; their operators receive a request when you follow them.
The server processes request data to deliver and protect the website. Access logs contain the IP address, time, HTTP method, path without query parameters, protocol version, response status, and byte count. They omit User-Agent and Referrer. Error logs may contain technical errors and related IP addresses or request details.
The legal basis is Article 6(1)(f) GDPR: our legitimate interest in secure, reliable operation and diagnosing faults. The two server logs rotate daily. In addition to the current file, at most 14 daily archives per log are retained; older archives are deleted at the next rotation. Operators and technical service providers access these data where necessary for hosting and operation. Technical request data are necessary to deliver the requested page.
Protected administration
The /admin workspace is for authorised operators. Opening its login page sets the necessary stage_cms session cookie. It associates requests with a session and protects sign-in and administration. It has an eight-hour maximum age, is removed at logout, and uses Secure, HttpOnly, and SameSite=Lax.
Storage is necessary for the administration service explicitly requested by the user under § 25(2)(2) TDDDG. Processing is based on Article 6(1)(f) GDPR and our legitimate interest in securing and managing the site. Sign-in does not work without this cookie.
The owner account stores a name, email address, and password hash. Failed sign-ins are counted against a hashed IP address for rate limiting. Counters have a 15-minute validity window; this is not a promise that their database records are deleted after 15 minutes. Sessions are valid for up to eight hours; expired sessions are removed when a new session is created. Account data remain while the account exists.
Agent connections store their name, token hash, permissions, expiry, creation time, last-use time, and revocation state. The raw token is shown only at creation. Content revisions record the editing identity and time so operators can review and recover changes. Private drafts and operational backups remain restricted to authorised operators.
Email enquiries
If you email us, we process your address, message, and supplied information to answer. The legal basis is Article 6(1)(b) GDPR for contract-related enquiries, otherwise Article 6(1)(f) and our legitimate interest in responding. We retain this information as long as needed for the enquiry, subject to statutory retention obligations.
Your rights
Where the legal conditions apply, you may request access, rectification, erasure, restriction, and data portability. You may object to processing based on legitimate interests for reasons arising from your situation. You may complain to a competent supervisory authority; the controller's local authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.
This website does not use automated decision-making or profiling.
Last reviewed: 3 October 2026. Legal notice · German privacy notice.