Privacy Policy
Controller
Controller within the meaning of Art. 4(7) GDPR and the Austrian DSG:
Kullisa Labs Alexander Leypold Schmittstrasse 15/10 8720 Knittelfeld Austria Email: info@kullisalabs.com
General Information
- The protection of your personal data is of paramount importance to us. We process your data exclusively on the basis of statutory provisions (GDPR, Austrian DSG, TKG 2021).
- This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data on:
- kullisalabs.com (public landing page)
- The Kullisa Labs Creator Program
- Creator landing pages (wildcard subdomains)
- Customer modules
Data Processing — Creators
What data is collected?
When registering for and using the Creator Program, we collect:
| Data Category | Source | Purpose | Legal Basis |
|---|---|---|---|
| Email address | Google / Microsoft OAuth | Account creation, login, communication | Art. 6(1)(b) GDPR |
| Display name | Google / Microsoft OAuth | Display in Creator Portal | Art. 6(1)(b) GDPR |
| Profile picture URL | Google / Microsoft OAuth | Avatar in Creator Portal | Art. 6(1)(b) GDPR |
| Product name / Wildcard | Creator input | Subdomain, landing page | Art. 6(1)(b) GDPR |
| Stripe Connect account ID | Stripe API | Payment processing | Art. 6(1)(b) GDPR |
| API keys (encrypted) | Creator input | Gateway AI proxy | Art. 6(1)(b) GDPR |
| VAT ID (optional) | Creator input | Invoicing | Art. 6(1)(c) GDPR |
| Transaction data | Stripe webhook | Billing, audit log | Art. 6(1)(b)+(c) GDPR |
Where is the data stored?
All Creator data is stored in a dedicated database, technically and logically separated from the databases in which end customer data is processed. Only essential platform services have write access to Creator data.
Retention period
- Account data: Until the Creator account is deleted
- Transaction data: 7 years pursuant to §132 BAO / §212 UGB (anonymised)
- API keys: AES-256-encrypted, deleted upon account deletion
- Webhook event IDs: Permanent for idempotency verification
Data Processing — Subscription End Customers
What data is collected?
| Data Category | Source | Purpose | Legal Basis |
|---|---|---|---|
| Email address | Google OAuth | Account creation, login | Art. 6(1)(b) GDPR |
| Name | Google OAuth | Display in customer portal | Art. 6(1)(b) GDPR |
| Profile picture URL | Google OAuth | Avatar | Art. 6(1)(b) GDPR |
| Subscription plan | Stripe webhook | Access control | Art. 6(1)(b) GDPR |
| Stripe customer ID | Stripe API | Payment processing | Art. 6(1)(b) GDPR |
| Subscription history | Stripe webhook | Contract evidence | Art. 6(1)(b) GDPR |
Controllership
The Creator is the Controller for this data (Art. 4(7) GDPR). Kullisa Labs acts as a Processor (Art. 28 GDPR) and only processes this data on the documented instructions of the Creator.
Data Processing — Credit End Customers
What data is collected?
| Data Category | Source | Purpose | Legal Basis |
|---|---|---|---|
| Email address | Google OAuth | Account creation, login | Art. 6(1)(b) GDPR |
| Name | Google OAuth | Display in customer portal | Art. 6(1)(b) GDPR |
| Profile picture URL | Google OAuth | Avatar | Art. 6(1)(b) GDPR |
| Wallet balance | Credit purchase, gateway | Balance management | Art. 6(1)(b) GDPR |
| Transaction ledger | Gateway metering | Usage records | Art. 6(1)(b) GDPR |
Controllership
Creator is Controller, Kullisa is Processor.
Data Processing — Landing Page Visitors
- When visiting our public landing pages, we automatically collect the following server log data: anonymised IP address, date and time, browser type/version, operating system, referrer URL, requested URL.
- Purpose: Ensuring technical operation, error analysis, abuse detection. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
- Retention period: Server logs are automatically deleted after 30 days.
- kullisalabs.com is hosted by Microsoft Azure.
- Cookies: The landing page does NOT use tracking cookies.
Disclosure to Third Parties
| Recipient | Data | Purpose | Safeguard |
|---|---|---|---|
| Stripe Inc. (USA) | Email, name, payment amounts | Payment processing | DPF-certified |
| Microsoft Azure (EU) | Anonymised IP | Hosting | Data centres: EU |
| Google Ireland Ltd. | Email address | OAuth | EU-based |
| Microsoft Ireland Ltd. | Email address | OAuth | EU-based |
No further disclosure to third parties takes place unless legally obliged or with explicit consent.
Security (Art. 32 GDPR)
- We implement the following TOMs:
- AES-256 encryption of Creator API keys
- Strict database separation with documented access rights
- HTTPS/TLS for all data transmission
- JWT-based authentication with cryptographic signature
- Automated test suite including security tests
- We do NOT store credit card numbers, CVC codes, bank details, PINs, or other payment authentication data. All payment processing is carried out by Stripe (PCI-DSS Level-1 certified).
Your Rights
- You have the following rights under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure — ‘Right to be forgotten’ (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- To exercise your rights, contact: info@kullisalabs.com. We will process your request within one month (Art. 12(3) GDPR).
- Right to lodge a complaint (Art. 77 GDPR):
Austrian Data Protection Authority Barichgasse 40–42 1030 Vienna, Austria Phone: +43 1 52 152-0 Email: dsb@dsb.gv.at Web: https://www.dsb.gv.at/
- No automated individual decision-making including profiling (Art. 22 GDPR) takes place.
Deletion of Data (Art. 17 GDPR)
- Creator Self-Deletion: The Creator may delete their account via profile settings. Deletion is immediate and irreversible, including all associated records across all databases. Transaction records are retained in anonymised form for 7 years.
- End Customer Deletion: End customers may request deletion. Deletion is carried out by the Creator (as Controller) or upon instruction. Any remaining credit balance is forfeited.
Amendments to This Privacy Policy
We reserve the right to amend this Privacy Policy as necessary. The current version is always available at kullisalabs.com. Material changes will be communicated to registered users by email.