Privacy Policy
Last updated: April 20251. Controller
Sebastian MartensJürgen-Töpfer-Strasse 8
22763 Hamburg
Germany
kontakt@kuechenvisualisierung.de
2. Data collected and purposes
Registration and user account
When you register, we collect your name, email address, and password (stored as a secure hash). This data is required to provide the service (Art. 6(1)(b) GDPR).
Uploaded images and processing jobs
Images you upload are stored on our server and transmitted to the Google Gemini API for AI-assisted processing (see section 6). Processing jobs including the parameters used are stored in our database. The retention period for images depends on your account type. After the retention period expires, images are deleted automatically. Legal basis: Art. 6(1)(b) GDPR.
Technical access data
When you visit our website, your browser automatically transmits technical data (IP address, browser type, operating system, date/time, page accessed). This data is captured in the hosting provider's server log and deleted after a maximum of 30 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security).
Cookies and session data
We use the following cookies:
- lang — stores your language preference (technically necessary, 1 year)
- auth_token — for authentication after login (technically necessary, 30 days)
Legal basis: Art. 6(1)(b) GDPR (auth_token) and Art. 6(1)(f) GDPR (language cookie). No third-party tracking cookies are set. Matomo operates in cookieless mode and sets no cookies.
3. Retention and deletion
If you delete your account, all personal data (account details, images, processing jobs) will be deleted immediately and completely. Exceptions apply only where we are legally required to retain data (e.g. tax record-keeping obligations).
4. Hosting
The service is hosted by:
all-inkl.com — neue Medien Münnich
Hauptstraße 68, 02742 Friedersdorf, Germany
Provider's privacy information
All data is stored exclusively on servers in Germany. A data processing agreement (DPA) pursuant to Art. 28 GDPR exists with the hosting provider.
5. Email delivery
For transactional emails (e.g. confirmation emails on registration) we use the SMTP service of our hosting provider all-inkl.com. No third-party email service providers are used. Only the data required for delivery (email address, name) is transmitted.
6. Google Gemini API
For AI-assisted image processing we use the Google Gemini API provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Images you upload are transmitted to and processed by Google's infrastructure.
Google LLC is certified under the EU-US Data Privacy Framework. The transfer to the USA is based on Art. 45 GDPR (adequacy decision) and/or Art. 46 GDPR (standard contractual clauses). A data processing agreement exists with Google.
Further information: Google Privacy Policy, Google Gemini API Terms.
7. Web analytics with Matomo
This website uses Matomo, an open-source web analytics platform. Matomo is self-hosted — all analytics data stays on our server at all-inkl.com and is never shared with third parties.
Matomo collects: IP address (anonymised before storage), pages visited, time on site, browser and OS type, country of origin. Identification of individual persons is not possible.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in anonymised usage analysis to improve the service). You can opt out of Matomo tracking by enabling the "Do Not Track" setting in your browser — Matomo respects this setting.
8. Payment processing
For paid features we use Creem (creem.io), a payment service provider acting as Merchant of Record. This means Creem is legally responsible for payment processing and for collecting and remitting applicable taxes (e.g. VAT).
When you make a purchase, the following data is transmitted to and processed by Creem: name, email address, billing address, payment data (e.g. credit card number), and IP address. Payment data is stored exclusively with Creem — not on our servers. Creem processes this data for purchase fulfilment, fraud prevention, and tax compliance.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Further information: Creem Privacy Policy.
9. Your rights
You have the following rights regarding your personal data:
- Access — Art. 15 GDPR: what data we hold about you
- Rectification — Art. 16 GDPR: correction of inaccurate data
- Erasure — Art. 17 GDPR: deletion of your data (you can delete your account yourself at any time)
- Restriction — Art. 18 GDPR: restriction of processing
- Data portability — Art. 20 GDPR: receive your data in a machine-readable format
- Objection — Art. 21 GDPR: object to processing based on legitimate interests
To exercise your rights, contact us at: kontakt@kuechenvisualisierung.de
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Hamburg is:
Der Hamburgische Beauftragte für Datenschutz und InformationsfreiheitLudwig-Erhard-Str. 22, 20459 Hamburg
www.datenschutz.hamburg.de