Privacy notice
How Kadrio processes personal data, under Articles 13 and 14 GDPR.
1. Controller
Alexey Naumov
Nikolastraße 35, 84034 Landshut, Germany
Phone: +49 1573 9690304
Email: hallo@kadrio.de
No data protection officer has been appointed; § 38(1) BDSG does not require one.
2. Two roles: controller and processor
Kadrio is software for photographers (“studios”): website, client galleries and client management. There are two kinds of data:
- Studios’ data (account, sign-in, billing) and visitors to kadrio.de. We are the controller; this notice applies.
- Data studios process in Kadrio: photos, galleries, visitors to the studios’ galleries and websites, enquiries through their contact forms, client records. The studio is the controller; we process this data only on its behalf under Article 28 GDPR (see section 9). Ask the studio about it; its privacy notice is on its website.
3. Hosting and location
Kadrio runs on servers and object storage of Contabo GmbH, Aschauer Straße 32a, 81549 Munich, in data centres in the European Union: the application, the database, the photos and the encrypted backups. A data processing agreement under Article 28 GDPR is in place. Hosting involves no transfer to a third country. Fonts, images and scripts are served only from our own servers; there is no content delivery network.
4. Visiting the website, and logs
Your IP address is needed to deliver pages of kadrio.de, the dashboard and the studios’ websites and galleries. Our logs contain method, path (without access keys or query parameters), status, size, duration and a random request id — but neither your IP address nor your browser. Logs are rotated by size and overwritten.
To prevent abuse (e.g. too many sign-in attempts) we count requests per IP address, storing only a keyed hash that expires with the time window. Gallery views are counted for the studio’s statistics with a daily-changing, irreversible hash of IP address and browser, which is aggregated and deleted after 72 hours.
Legal basis: Article 6(1)(f) GDPR (secure and stable operation).
5. Cookies and local storage
kadrio.de sets no cookies and uses no analytics, tracking or advertising, so no consent banner is needed. The dashboard and galleries use only strictly necessary cookies (§ 25(2) no. 2 TDDDG):
- __Host-kadrio_session
- Dashboard sign-in; ends after 7 days unused, at most after 30 days.
- __Host-kadrio_pending
- A sign-in waiting for the two-factor code; 5 minutes.
- __Host-kadrio_oidc
- Only with “Sign in with Google”: security values of the sign-in; 10 minutes.
- __Host-kadrio_device
- Remembers that this browser has signed in before, so strangers’ failed attempts cannot lock you out; 365 days.
- __Host-kadrio_g_…
- Access to a gallery you opened by link, password or code; up to 30 days.
- NEXT_LOCALE
- The language you chose in a gallery or in the dashboard; 1 year.
- kadrio_nav
- Only if you collapse the dashboard menu: that it stays collapsed; 1 year.
Your browser’s local storage holds only preferences: light or dark theme, filter and sort of the gallery list, and the name you gave when uploading guest photos, so you need not type it again. These stored preferences are not sent to us; the name is sent only with a photo (see section 9).
6. Account and sign-in
For an account we process your email address, your password (only as an argon2id hash, additionally encrypted), your studio’s name and address, your language, the two-factor secret if enabled (encrypted), and for each session the IP address and browser, so you can recognise and end open sessions. Legal basis: Article 6(1)(b) GDPR (contract).
To protect your account we log security events (sign-in, Google sign-in, two-factor changes, email confirmation, new password) with time and IP address. The IP address is removed from this log after 90 days; the entry itself stays as account history until the account is deleted. For links to confirm your address or reset your password we keep the IP address of the request until the link is used or expires (at most 24 hours). Legal basis: Article 6(1)(f) GDPR (preventing misuse).
An unconfirmed account is deleted after 7 days. A deleted account can be restored for 14 days; then all data, photos and galleries are erased. Encrypted backups keep data for at most another 30 days. Before deleting you can export all your data (Article 20 GDPR).
Sign in with Google
If you choose “Sign in with Google”, you are sent to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We receive your Google id and verified email address and store no Google tokens. Google may transfer data to the USA; Google is certified under the EU–US Data Privacy Framework (Article 45 GDPR). Legal basis: Article 6(1)(b) GDPR. Signing in with Google is optional; nothing connects to Google unless you click.
7. Emails
We send only emails that belong to the service (address confirmation, password reset, security notices, payments, exports, gallery notifications) — no newsletter. Our provider is AhaSend B.V., the Netherlands, which processes and stores email only in the EU under a data processing agreement. It receives the recipient address and the message. Legal basis: Article 6(1)(b) GDPR.
8. Payment
Paid plans are billed through Stripe; the contracting party is Stripe Payments Europe, Limited, Dublin, Ireland. You enter payment details on our order page in a form embedded from Stripe; they go straight to Stripe and we never receive them. Stripe’s software (Stripe.js) is loaded for this on that page only. We send Stripe your studio’s name, your language, an internal id, your account’s email address (for Stripe’s receipts and payment messages) and, if you order as a business and we charge VAT, your VAT id (for the right taxation). From Stripe we keep the customer and subscription id, plan, period and status, and for promotions what is set out below. A free trial without payment details is also kept at Stripe as a subscription; for it, Stripe receives your studio’s name, language and internal id. Stripe may transfer data to Stripe, Inc. in the USA; Stripe is certified under the EU–US Data Privacy Framework and has also concluded standard contractual clauses (Articles 45, 46(2)(c) GDPR). Stripe is partly a controller itself (e.g. for fraud prevention); see stripe.com/privacy. Legal basis: Article 6(1)(b) and (c) GDPR. Invoices are kept for eight years from the end of the year they were issued in, as § 147 AO and § 14b UStG require. Deleting an account also deletes the customer at Stripe, except what Stripe must keep itself.
Cancellation and withdrawal
Through the “Cancel contracts here” and “Withdraw from contract” forms we process your name, the email address for the receipt, what identifies the contract and, for a cancellation, its kind, reason and date. They go out as emails to you and to our mailbox. They are not put in Kadrio’s databases; only the email dispatch holds them until they are delivered (at most seven days). To limit abuse your IP address (one hour) and the email address you give (24 hours) are counted as encrypted keyed values, not stored in clear. For an ordinary cancellation without a date of its own we match the email address you give against the accounts: if it is the sign-in address of the owner of exactly one studio, and that studio has a running plan, the receipt names the day the contract ends; that day is not told to any other address, and in every other case we confirm it separately. Legal basis: Article 6(1)(c) GDPR together with sections 312k and 356a BGB. We keep the email in our mailbox as proof until the limitation period ends (three years from the end of the year, section 195 BGB).
Orders, promotions and promotion codes
When you order a plan, we keep as proof of the contract the text shown to you above the button “Zahlungspflichtig bestellen” (order with obligation to pay), the time of your click and your request that the plan start at once (Article 6(1)(b) and (c) GDPR, sections 312j and 356 BGB). This stays as long as your account does; orders where the button was not clicked are deleted after 90 days.
When you enter a promotion code, we keep the code, your studio and the result of the check for 90 days to detect abuse (Article 6(1)(f) GDPR). The use of a promotion (promotion, plan, discounts given, dates) is kept as part of our books for eight years from the end of the year it ended in (section 147 AO, section 14b UStG; Article 6(1)(c) GDPR); if your account is deleted, it stays without a link to your account. To see whether the same payment card or bank account (SEPA direct debit) uses a promotion at several studios, we keep with a use a check value formed with a secret key (HMAC) of the mark by which Stripe recognises a card or account — never the card or account details, which cannot be recovered from it. It only prompts our staff to look; no software decides anything (Article 6(1)(f) GDPR; our legitimate interest is that a promotion for new customers is not used several times).
9. Data in studios’ galleries and websites
The studio is the controller of the following; we process it on its behalf (Article 28 GDPR) only to provide the service:
- Gallery photos, the couple’s access (email and one-time codes that expire after 15 minutes), favourites lists with comments, downloads (without IP address; the link to a person is removed after 12 months), photo removal requests (deleted 90 days after being settled).
- Guest photos: the name and greeting given. Location and other metadata are stripped from every uploaded photo.
- Enquiries through a studio website’s contact form (name, email, phone, date, message), deleted automatically after 12 months. The IP address is kept only as a hash, against abuse.
- Reviews the studio asks for; they appear only once the studio approves them.
If a studio’s paid plan ends and its galleries take more storage than the free plan offers, after 30 days only the galleries that fit into that storage stay reachable. The others stay stored for the studio and are deleted, with all their photos, favourites, guests’ photos and statistics, no earlier than six months after the plan ended and after the studio was told at least 30 days before (terms § 5(3a)). Encrypted backups keep them for at most another 30 days.
The forms’ spam protection (ALTCHA) runs on our own servers without third parties. Videos on studios’ websites (YouTube in privacy-enhanced mode, Vimeo with “Do Not Track”) load only after you click; only then is data sent to the provider, which may also store data in your browser.
10. Retention at a glance
- Sessions: 7 days unused, at most 30 days
- Unconfirmed accounts: 7 days; deleted accounts: final after 14 days
- Galleries that no longer fit into the storage after a paid plan ended: no earlier than six months after the plan ended
- Backups: 30 days
- IP addresses in the security log: 90 days
- Exports and ZIP archives: 7 days
- Contact form enquiries, download names, guests’ email addresses: 12 months
- Settled removal requests, unanswered review requests, payment events: 90 days
- Cancellations and withdrawals: three years from the end of the year
- Invoices: eight years from the end of the year they were issued in
- Promotion codes entered: 90 days; promotions used: eight years from the end of the year they ended in
- Proof of an order: as long as the account exists; orders without a click: 90 days
11. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection (Articles 15–18, 20, 21 GDPR) and may withdraw consent at any time with effect for the future (Article 7(3) GDPR). A message to hallo@kadrio.de is enough. For data in a studio’s galleries or website, contact the studio; we forward requests to it.
You may also complain to a supervisory authority (Article 77 GDPR). Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
12. Security
All connections use TLS. Passwords are stored only as argon2id hashes, access keys only as hashes, confidential fields encrypted (AES-256-GCM), backups encrypted. Studios’ data is kept apart in the database. Two-factor sign-in is available to every account.
13. No automated decisions, no AI training
There is no automated decision-making or profiling (Article 22 GDPR). We do not use studios’ or their clients’ photos and data for our own purposes — neither for advertising nor to train AI models.
14. Changes
We update this notice when our processing or the law changes. The version on this page applies.