Privacy Policy & Terms of Use

Beta 1.0 Version for Platform Launch

 

Part A – Privacy Policy

 

1. Introduction

wedium GmbH is committed to protecting your personal data. After all, data protection is one of the key reasons we founded wedium. This Privacy Policy explains how we collect, process, store, and protect personal data when you use our social media platform wedium. Our services are hosted within the European Union, ensuring GDPR compliance and secure data residency.

 

2. Controller

The controller responsible for the processing of personal data in connection with the wedium app, wedium website, associated platform functions, and related services under the General Data Protection Regulation (GDPR) is:

wedium GmbH
Tempelhofer Damm 2
12101 Berlin
Germany

Website: www.wedium.social

Managing Directors: Andreas Hacker, Dr. Nele Meissner, Johannes Meissner, Sebastian Wilke
Commercial Register Number: HRB 282910 B, Local Court of Charlottenburg
VAT ID: [To be inserted]
Email: hello@wedium.social
Contact for Data Protection Inquiries: Sebastian Wilke, datenschutz@wedium.social

 

3. Scope

This Privacy Policy informs you about the nature, scope, and purposes of the processing of personal data when using wedium. It applies to registered users, unregistered visitors, communication partners, complainants, and any other individuals whose data is processed in connection with the use of wedium.

It does not apply to third-party websites or services linked to or mentioned within wedium content. The privacy policies of the respective third-party providers apply to those services.

 

4. Principles of Data Processing

wedium processes personal data in accordance with the principles of lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.

wedium does not store ID data or raw biometric data from verification processes. wedium only receives the verification status, technical reference data (such as hash or token values), and the minimal information required for platform functionality.

 

5. Categories of Personal Data

Depending on the type of use, the following categories of data may be processed:

  • Account data, e.g., name, username, email address, password hash, profile information;
  • Usage and interaction data, e.g., content viewed, likes, shares, comments, dwell time, connections, and other interactions;
  • Content data, e.g., uploaded texts, images, videos, metadata, and community-related feedback;
  • Communication data, e.g., support requests, reports, complaints, objections, and other correspondence;
  • Technical data, e.g., IP address, device information, browser or app version, log data, access timestamps, error messages;
  • Verification data (minimal), e.g., status “verified/unverified,” technical reference ID, verification timestamp, result status;
  • Security and abuse data, e.g., suspicion indicators, block notes, complaint histories, technical security events.

 

6. Purposes and Legal Bases

wedium processes personal data only where there is a legal basis under the GDPR. Processing may be based on the following grounds:

  • Art. 6(1)(b) GDPR, where processing is necessary for the performance of a contract (e.g., providing the platform);
  • Art. 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation;
  • Art. 6(1)(f) GDPR, where wedium pursues legitimate interests, particularly for ensuring security, preventing abuse, enforcing rules, defending against claims, and developing the platform, unless overridden by the interests or fundamental rights of the data subject;
  • Art. 6(1)(a) GDPR, where wedium obtains consent, particularly for optional features, specific location processing, or other voluntary processing.

 

7. Registration and Account Management

When creating an account, wedium processes the registration data provided by the user. This processing is necessary to provide the account and authenticate the user.

Without this data, a user account cannot be created or managed. Users are obligated to provide accurate information and keep it up to date.

 

8. Verification via WebID

Certain active platform functions—such as posting, commenting, liking, or sharing—require successful identity verification via WebID Solutions GmbH, Unter den Linden 10, 10117 Berlin. wedium does not store ID documents, photos, or raw biometric data. It only receives the verification result (e.g., “verified” or “unverified”) and technical reference data for assignment and traceability.

Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (security and integrity).

Verification is voluntary, but without it, certain interactive features of wedium will not be available.

 

9. Platform Use and Personalization

wedium processes usage data to:

  • provide content,
  • enable interactions,
  • prevent abusive use,
  • improve user experience (e.g., feed personalization).

No automated decision-making (Art. 22 GDPR) is currently used by wedium.

 

10. Content, Reports, Complaints, and Moderation

wedium processes content, report, and complaint data to:

  • enforce Community Guidelines,
  • review reported content,
  • remove illegal content,
  • minimize security risks,
  • address objections,
  • comply with Digital Services Act (DSA) requirements (e.g., transparency reports).

This may include documenting reporter details, affected content, timestamps, reasons, internal review results, moderation decisions, and complaint histories.

 

11. Communication and Support

When users contact wedium, the data provided is processed to handle the request, document the matter, and verify communication.

Legal basis: Art. 6(1)(b) or (f) GDPR, depending on the subject matter.

 

12. Security, Abuse Prevention, and Integrity

wedium processes technical and behavioral data (e.g., login attempts, device information) to:

  • ensure platform security,
  • detect and prevent abuse,
  • block bots and spam,
  • defend against attacks on systems, content, and users.

 

13. Cookies, Local Storage, and Similar Technologies

wedium may use cookies, local storage, SDK functions, or similar technologies only if technically necessary or with explicit consent.

  • Necessary technologies are used for authentication, session control, security, error detection, language or display settings, and platform stability.
  • Analytical, comfort, or other non-essential technologies are used only with separate consent.

Use of Cookies on Our Website

To collect usage data on our website, we use the tracking solution Matomo. Matomo is operated by us without cookies. We collect data exclusively in aggregated and anonymized form. We record data such as page views, access times, truncated (and thus no longer identifiable) IP addresses, device data, etc., to measure our reach and optimize our website offerings. We do this on the legal basis of legitimate interest under Art. 6 GDPR. No data is permanently stored on your computer, and no personal data is processed. Usage data is not used across platforms. If you wish to prevent the collection of this data, we generally recommend using a third-party tracking blocker for your online activities. You can disable Matomo tracking on this page with a single click on the following button:

 

14. Recipients and Categories of Recipients

Personal data is disclosed only to entities within wedium that require it for task fulfillment and to trusted third-party service providers:

  • CDN Server: bunny.net, BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia, sales@bunny.net
  • Hosting: Hetzner, Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, info@hetzner.com
  • Verification: WebID Solutions GmbH, Unter den Linden 10, 10117 Berlin
  • Newsletter Mail Provider: rapidmail, Positive Group Deutschland GmbH, Ingeborg-Krummer-Schroth-Straße 18a, 79106 Freiburg, info@rapidmail.de
  • Database Service: Scaleway, Scaleway SAS, 8, rue de la Ville-l’Évêque, 75008 Paris, France, scaleway.com

No commercial disclosure of personal data to third parties for their own advertising purposes.

 

15. International Data Transfers

wedium processes data exclusively within the EU/EEA.

 

16. Storage Period and Deletion

wedium stores personal data only as long as necessary for the respective purposes or as required by legal retention obligations.

  • Account data: As long as the account is active; deletion 3 months after closure.
  • Posts/comments: Until deletion by the user or deactivation.
  • Security and usage logs: Maximum 12 months.
  • Legally relevant data (e.g., accounting): Up to 10 years.

 

17. Rights of Data Subjects

Data subjects have the following rights under the GDPR:

  • Right of access, rectification, erasure, restriction of processing, data portability, and objection.
  • Right to withdraw consent at any time with future effect.
  • Right to lodge a complaint with a supervisory authority.

 

18. Obligation to Provide Data

Certain data (e.g., email, username) is required to create and use an account. Without this data, wedium cannot provide the platform in full.

Verification is not required for read-only access but is necessary for active functions.

 

19. Minors

During the beta test phase, use of the platform is only permitted for individuals over 18 years of age.

In the future, additional restrictions, protective mechanisms, visibility limitations, or moderation measures will apply to protect minors.

 

20. Changes to This Privacy Policy

wedium may update this Privacy Policy if the legal situation, platform functions, data processing, or service providers change. The current version is always available at the time of use. For significant changes, we will inform you via email or directly in the app. The change history will be made transparent.

 

Part B – Terms of Use

 

1. Scope and Subject Matter

These Terms of Usee govern the use of the wedium app, wedium website, and all associated functions, content, and services between wedium GmbH and users.

wedium is a European-developed and hosted social media platform. Our goal is to enable respectful, verified, and trustworthy digital exchange.

 

2. Contract Formation

A contractual relationship is established upon completion of registration or other use of the platform, where possible without registration. A prerequisite for setting up an account is that the user accepts the Terms of Service and provides truthful information.

 

3. Beta Phase

The platform is initially provided as a beta version. During this phase, functions may be limited, changed, added, or removed. Errors, interruptions, changed user guidance, or other deviations may occur.

wedium does not guarantee a specific development status, feature set, or uninterrupted availability in the beta phase. Feedback, error reports, and suggestions for improvement may be used for platform development.

 

4. Registration, Account, and Access Data

Users must:

  • Provide accurate, complete, and up-to-date information during registration;
  • Keep access data confidential;
  • Not transfer, sell, rent, or otherwise provide the account to third parties;
  • Not create multiple accounts to bypass rules or restrictions.

 

5. Minimum Age

Active use of wedium requires users to be at least 18 years old. wedium may block accounts if there is reasonable suspicion that the user is underage or has provided false age information.

 

6. Verification and Function Access

Active functions (e.g., uploading, commenting, liking) require successful identity verification via WebID. wedium does not store ID data or raw biometric data, only the verification status and technical reference data.

There is no entitlement to verification. wedium may refuse, repeat, or revoke verification if there is evidence of abuse, circumvention, false information, or other security risks.

Unverified users can view content within the scope provided by wedium but cannot use all active features.

 

7. User-Generated Content

Users may create, upload, publish, and share content within the platform’s functions. Users are solely responsible for ensuring they have the right to publish content and that it does not violate third-party rights or legal prohibitions.

wedium is not obligated to pre-screen all content but may conduct technical, automated, or human reviews.

 

8. Rights to Content and License

Users retain ownership of their uploaded content but grant wedium a non-exclusive, royalty-free, geographically unrestricted license for the duration of the user relationship to:

  • Host, reproduce, technically process, display, transmit, and make content accessible within the platform.

The license ends upon deletion of the content or account, unless legal obligations, legitimate evidence interests, or technical residual copies prevent this.

 

9. Prohibited Use

It is prohibited to use wedium in a way that is unlawful, abusive, deceptive, or endangers wedium, other users, third parties, or the integrity of the information ecosystem.

Prohibited content and behavior include:

  • Threats of violence, glorification of violence, instructions for criminal acts, or other criminal content;
  • Hate speech, discrimination, dehumanization, or targeted degradation of protected groups;
  • Harassment, bullying, doxxing, intimidation, coordinated attacks, or sexualized degradation;
  • Content promoting self-harm, suicide, eating disorders, or other serious health risks;
  • Sexual exploitation, sexualized content involving minors, grooming, or other content endangering minors;
  • Disinformation, misleading crisis information, manipulative political misinformation, election interference, or health-related false claims with potential for harm;
  • Fake accounts, bots, automated interactions, purchased reach, like-for-like mechanisms, spam, impersonation, or other manipulation;
  • Violations of copyright, trademark, personality, data protection, or other third-party rights;
  • Distribution, marketing, or advertising of prohibited, illegal, or high-risk goods and services, where such content is deemed unacceptable under Community Guidelines;
  • Harmful, deceptive, or unauthorized use of artificial intelligence, particularly realistic deepfakes without disclosure and with intent to deceive or harm.

 

10. Community Rules and Content Categories

In addition to these Terms of Service, the wedium Community Guidelines apply. These specify permissible and impermissible content, behaviors, protection mechanisms, and moderation measures.

wedium may limit the reach of content that violates Community Guidelines or is unsuitable for recommendations, trends, or search surfaces, even if not obviously illegal.

 

11. AI-Generated or Significantly Edited Content

AI-generated, synthetic, or significantly edited content that realistically depicts people, statements, voices, events, or scenes must be clearly labeled if there is a risk of confusion or deception.

wedium may remove, restrict, or label insufficiently labeled or harmful AI content.

 

12. Advertising, Commercial Communication, and Creator Content

Commercial communication, advertising, affiliate content, paid collaborations, or other business communication must be clearly disclosed (e.g., #ad).

Undisclosed advertising, misleading commercial practices, scams, pyramid schemes, unauthorized financial promises, fraudulent offers, or similar content are prohibited.

Creator Monetization:

  • Creators receive 50% of ad revenue.
  • Payouts are made monthly, starting at €20.

 

13. Moderation and Enforcement

wedium may take action against content and accounts if there is a violation of these Terms of Service, Community Guidelines, legal obligations, or wedium’s security interests. Measures may include:

  • Removal or blocking of individual content;
  • Restriction of visibility (e.g., exclusion from recommendations or trends);
  • Functional restrictions (e.g., on comments, uploads, or messages);
  • Warnings;
  • Temporary account suspension;
  • Permanent account suspension or termination;
  • Additional verification steps;
  • Reporting to law enforcement or other authorities, where legally required or permitted.

 

14. Reports and Complaints

wedium provides functions for users to report content, accounts, or behaviors. Reports should be made in good faith and not abusively.

Users against whom measures have been taken may file a complaint within 14 days via the provided functions or contact channels.

wedium may document decisions and retain them to fulfill legal transparency and evidence obligations.

 

15. Public Interest, Exceptions, and Context

wedium may allow content in exceptional cases, even if it is close to a violation, if there is an overriding documentary, journalistic, scientific, artistic, or societal interest in disclosure, and appropriate protective measures (e.g., warnings, reach restrictions, age restrictions) are sufficient.

No exceptions apply to content causing serious harm, such as sexual abuse of minors, severe violence, or concrete dangers.

 

16. Availability and Changes to Services

wedium strives for maximum availability but does not guarantee uninterrupted use. Maintenance, technical adjustments, security measures, outages, capacity limits, or third-party disruptions may lead to restrictions.

wedium may develop or adapt the platform, its functions, security mechanisms, algorithms, Community Rules, and terms for objective reasons (e.g., technical, legal, security, or product-related).

 

17. Liability

wedium is fully liable for intent, gross negligence, and in cases of injury to life, body, or health.

For slight negligence in breach of essential contractual obligations, wedium is liable only for typical and foreseeable damages. Essential contractual obligations are those whose fulfillment enables the proper execution of the contract and on which users regularly rely.

Otherwise, wedium’s liability is excluded to the extent permitted by law.

wedium is not liable for user-generated content, third-party behavior, third-party offers, or outages beyond its control.

 

18. Indemnification

Users shall indemnify wedium from third-party claims and reimburse reasonable legal defense costs if they post illegal content, violate third-party rights, or otherwise negligently expose wedium to third-party claims.

 

19. Term and Termination

The user relationship is indefinite. Users may delete their account at any time.

wedium may terminate or suspend accounts for good cause, particularly in cases of severe or repeated violations, abuse, security risks, false information, legal obligations, or sustained disruption of platform operations.

 

20. Final Provisions

  • Governing Law: German law (excluding the UN Convention on Contracts for the International Sale of Goods, CISG), unless mandatory consumer protection laws apply.
  • Severability: If any provision is invalid, the remainder of the Terms of Service remains in effect.
  • Consumer Rights: Mandatory rights of users’ country of residence remain unaffected.

 

Appendix – Code of Conduct (separate document – see wedium Community Guidelines)

wedium is the first social media platform for real people only