KEEP-THE-MOMENTAPP

Privacy

Privacy Policy

This template covers the main processing activities for the KEEP-THE-MOMENT website, web app, PWA and a later app-store launch.

Template notice

Template – final legal review recommended before production launch. Please replace the placeholders with final company data and obtain legal review before production launch.

1. Controller

The controller is [GESCHÄFTSBEZEICHNUNG], [VOLLSTÄNDIGER_NAME], [STRASSE], [PLZ] [ORT], [LAND].

Contact: [E-MAIL] / [TELEFON].

2. Visiting the website and using the web app

When the website or web app is accessed, technically necessary information may be processed in order to deliver content, maintain security and ensure system stability.

This may include in particular IP address, date and time of access, requested resources, browser information, operating system and referrer data.

  • Purposes: technical delivery, stability, misuse detection, system security
  • Legal bases: Article 6(1)(b) and Article 6(1)(f) GDPR
  • Recipients / providers: [HOSTING_PROVIDER], where applicable Cloudflare

3. Account creation and login

If you create an account or sign in, KEEP-THE-MOMENT processes your email address, authentication data, profile language and the account information required for access.

The processing is required to provide your personal account, a protected dashboard and access to orders, memories and uploads.

  • Purposes: contract performance, authentication, account administration
  • Legal basis: Article 6(1)(b) GDPR

4. Uploading photos and videos

If you upload content, KEEP-THE-MOMENT processes the original files as well as generated preview, app and print versions, together with file information such as resolution, size, format and upload time.

The content is processed, stored and displayed only to the extent necessary for contract performance, memory presentation, quality checks and preparation of personalised products.

  • Purposes: contract performance, quality assurance, memory presentation, print preparation
  • Storage provider: Cloudflare R2
  • Legal basis: Article 6(1)(b) GDPR

5. Orders, checkout and payments

In connection with orders, KEEP-THE-MOMENT processes order, package, delivery and communication data. Payment handling is carried out through the configured payment provider.

Processing may be necessary for contract fulfilment, fraud prevention, invoicing and documentation.

  • Payment provider: Stripe
  • Legal bases: Article 6(1)(b), 6(1)(c) and 6(1)(f) GDPR

6. Hosting, storage, CDN and server logs

The website, web app, API endpoints and storage processes may be provided through [HOSTING_PROVIDER], Cloudflare R2 and, where applicable, Cloudflare.

Server logs may in particular contain IP address, access times, status codes, technical error messages and request-related metadata.

  • Purposes: hosting, availability, error analysis, security
  • Legal basis: Article 6(1)(f) GDPR

7. Language settings and technically necessary storage

Local storage entries or technically necessary cookies may be used to remember your language setting and to keep essential site functions available.

Without these technical storage mechanisms, core parts of the website or web app may not function properly.

  • Legal bases: Article 6(1)(b) and 6(1)(f) GDPR
  • The exact implementation should be reviewed before launch.

8. Analytics, tracking and newsletter

Optional analytics and tracking are currently not active by default. If [ANALYTICS_PROVIDER optional] or any other non-essential services are activated later, they should only be used after valid consent has been obtained.

Newsletter or marketing email communication is currently not an essential part of the service. If [NEWSLETTER_PROVIDER optional] or comparable tools are activated later, consent, documentation and withdrawal mechanisms should be implemented.

  • Legal basis for optional analytics or marketing where enabled: Article 6(1)(a) GDPR
  • These parts are included as template placeholders for later activation.

9. Recipients, international transfers and processors

Personal data may be shared with processors and infrastructure providers to the extent necessary to operate the service.

Depending on the provider, processing in third countries, especially the United States, may occur. In such cases the transfer mechanism, for example adequacy decisions or standard contractual clauses, should be checked and documented before launch.

10. Retention periods

Personal data is retained only as long as required for the relevant purpose or as required by statutory retention obligations.

Account data, order information and uploaded content may in particular be retained while the account exists, contracts are being performed or legitimate interests such as documentation, security and legal defence continue to apply.

11. Data subject rights

Data subjects have the right, to the extent provided by law, to access, rectify, erase, restrict processing, data portability and object to certain processing operations.

Where processing is based on consent, that consent may be withdrawn with effect for the future.

12. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates data protection law.

KEEP-THE-MOMENT