Meld® ID
Back to MeldID
Privacy Policy
This Privacy Policy explains how DigiMeld UG processes personal data when you use MeldID, its website, web interface, and related identity and security services.
Last updated: July 29, 2026
1. Controller
The controller responsible for processing personal data is:
DigiMeld UG (haftungsbeschränkt)
Lehrberger Str. 19
91567 Herrieden
Germany
Privacy requests: TicketMeld
Company information: DigiMeld imprint
2. What MeldID does
MeldID provides a central identity layer for MELD® products. It supports account creation, email verification, sign-in, profile management, consent management, OAuth connections, TOTP authentication, and approval of sign-in requests.
Connected products receive only the information and permissions approved for that connection. Your MeldID password is not shared with connected products.
3. Personal data we process
The data processed depends on the features you use and the information you choose to provide. This may include:
- Account and authentication data Email address, identity identifier, email verification status, account status, account timestamps, and authentication settings. Passwords are processed in protected form and are not disclosed to connected products.
- Optional profile data First name, last name, display name, phone number, profile language, date of birth, country, postal code, city, address, recipient name, company name, VAT ID, and tax ID, if you choose to save them in your profile.
- Consents and connected products The products you connect, requested OAuth scopes, consent decisions, and the dates of granting or revoking consent.
- TOTP data TOTP entries and their secrets are stored in a protected encrypted vault associated with your MeldID account. TOTP secrets are used to generate one-time codes and are not provided to connected products.
- Device and security data Device identifier, platform, app version, device name, device status, last-seen information, push-notification token data when push notifications are enabled, and security-attestation data where required for protected operations.
- Technical and audit data IP address, approximate country derived from the IP address where available, browser or app user-agent, request path, request status, timestamps, request identifier, and security or authentication events. We use this information for security, troubleshooting, and audit purposes.
- Support and deletion requests Email address, language, request details, and technical metadata that you provide when you contact support or request account deletion.
4. How we use personal data
We use personal data to:
- create and maintain your MeldID account;
- verify your email address and provide account recovery;
- authenticate you and return you to a connected MELD® product;
- show and manage consent choices and profile information;
- store and synchronize your protected TOTP vault;
- send and process sign-in approval requests;
- protect the service, detect abuse, and investigate security incidents;
- provide support and process deletion requests;
- comply with legal obligations and enforce our agreements.
5. Legal bases
Depending on the processing activity, we rely on the following legal bases under the GDPR:
- Performance of a contract or steps at your request for account creation, authentication, connected-product access, TOTP, and support requested by you.
- Legitimate interests for service security, fraud and abuse prevention, debugging, operational logs, and protection of our systems and users.
- Consent for optional profile sharing, optional access settings, and other processing where consent is required. You can withdraw consent for future processing through the available account settings or by contacting us.
- Legal obligations where processing is required by applicable law.
6. TOTP and sign-in approval
Integrated TOTP authenticator
MeldID can store TOTP entries in a protected vault and generate time-based one-time codes. The vault is associated with your MeldID account, and its protected contents are not shared with the connected service for which a code is generated.
Sign-in approval
If you enable sign-in approval, MeldID processes the details needed to show a pending sign-in request on your registered device and to record your approval or rejection. Push notifications are a delivery mechanism; the server remains the source of truth for the decision. Push payloads are designed not to contain your password, access token, authorization code, or full email address.
7. Cookies and browser storage
The MeldID web interface uses strictly necessary session cookies to keep you signed in, protect authentication flows, and maintain security settings. These cookies are not used for advertising or cross-site tracking.
The web interface may also use browser storage for language preferences and temporary authorization-flow data. Temporary authorization values are not intended to be used as an advertising or analytics identifier.
8. Sharing and service providers
We do not sell personal data and do not use MeldID for targeted advertising. We may share or make data available only as necessary to provide the service, including with:
- connected MELD® products, limited to the data and scopes you approve;
- email delivery providers, to send verification, registration, and recovery messages;
- PushMeld or comparable push-delivery infrastructure, when push notifications are enabled;
- TicketMeld or comparable support infrastructure, when you contact support or request deletion;
- hosting, database, security, and infrastructure providers that process data on our behalf.
Service providers may process personal data only to provide the contracted service and must apply appropriate confidentiality and security protections. We may also disclose information where required by law, to protect rights and safety, or in connection with a corporate transaction.
9. International transfers
If personal data is transferred outside the European Economic Area, we do so only where permitted by applicable data-protection law and with appropriate safeguards, such as an adequacy decision or Standard Contractual Clauses where applicable.
10. Retention
We retain account, profile, consent, TOTP, and device data for as long as needed to provide the service, maintain your account, protect the service, and meet legal obligations. When an account is deleted, we delete or anonymize associated personal data unless a longer period is required or permitted by law.
Registration, verification, password-reset, OAuth, and sign-in-approval artifacts are temporary and are invalidated or deleted after expiry, use, revocation, or the applicable operational period. Operational request logs and identity security events are retained for limited, status-based periods and are routinely deleted. Support records may be retained for as long as needed to resolve the request, document the deletion, or meet legal obligations.
11. Your rights
Subject to the applicable legal requirements, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time for future processing where processing is based on consent.
You also have the right to lodge a complaint with a competent data-protection supervisory authority, in particular in the country where you live, work, or believe that an infringement occurred.
12. Account and data deletion
You can request deletion of your MeldID account and associated personal data through the available account-deletion flow or by contacting support. We may need to verify the request to protect the account from unauthorized deletion.
Please send deletion requests through TicketMeld. We normally process verified requests within 30 days, unless a longer period is required by law or necessary to resolve a dispute.
13. Children
MeldID is not directed to children. We do not knowingly collect personal data from children in violation of applicable law. If you believe that a child has provided us with personal data, please contact us so that we can review and delete it where appropriate.
14. Security
We use technical and organizational measures designed to protect personal data, including encrypted connections, protected storage for sensitive account and TOTP data, access controls, and security monitoring. No method of transmission or storage can be guaranteed to be completely secure.
15. Changes to this policy
We may update this Privacy Policy when our services, legal requirements, or data-processing practices change. The latest version will be published on this page with a new “Last updated” date.
16. Contact
For questions about this Privacy Policy or MeldID data processing, contact us through:
TicketMeld support
DigiMeld UG (haftungsbeschränkt), Lehrberger Str. 19,
91567 Herrieden, Germany