1. Controller
Abdallah Kawji, Durlacher Straße 6, 10715 Berlin, Germany
Email: contact@abdallah.dev
No data protection officer has been appointed because the statutory appointment requirements currently do not apply.
2. Scope and roles
This notice applies to visitors, account holders, invited reviewers, and people whose personal data appears in uploaded videos. For account administration, payments, website security, and our direct customer relationship, we act as controller.
When a customer uploads a video, adds reviewer contact details, or collects comments and approvals for their own purposes, that customer generally determines why the information is processed. In that context, the customer is responsible for having a lawful basis and for providing any additional notices required to participants; we process the information to provide the platform.
3. Website access and security logs
When the service is accessed, technically necessary request data may be processed, including IP address, date and time, requested URL, referrer, browser or user-agent information, and response status. Processing is necessary to deliver the website and is based on Article 6(1)(f) GDPR, our legitimate interest in secure and reliable operation. Security logs are retained only as long as required for troubleshooting, abuse prevention, and legal claims.
4. Google sign-in and Firebase
Account holders sign in using Google through Firebase Authentication. We receive and store account identifiers such as Google/Firebase user ID, name, email address, profile image, authentication tokens, and technical security data. Firebase may process IP addresses and user-agent information for authentication and abuse prevention.
Project records—including titles, reviewer email addresses, share links, comments, timestamped ranges, and approval records—are stored in Google Cloud Firestore. The legal basis is Article 6(1)(b) GDPR for providing the requested service and Article 6(1)(f) GDPR for authentication and security. Google generally acts as our processor for these services. Firebase Authentication is operated from US data centers; applicable transfer safeguards include the EU–US Data Privacy Framework and contractual protections.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information: Firebase privacy and security.
5. Video processing with Mux
Uploaded videos are transmitted to and processed by Mux for upload, transcoding, storage, thumbnails, and playback. Depending on the content, videos may themselves contain personal data. Mux also processes playback access data such as IP address, user agent, and approximate location derived from the IP address.
Processing is based on Article 6(1)(b) GDPR where required to provide the service and, for customer-directed content, under our data-processing arrangement with the customer. Mux acts as processor or sub-processor. Processing may occur in the United States and other countries using the EU–US Data Privacy Framework and, where required, Standard Contractual Clauses.
Provider: Mux, Inc., 50 Beale Street, 9th Floor, San Francisco, CA 94105, USA. Further information: Mux Privacy Policy.
6. Payments through Stripe
If you purchase a video review, payment is processed by Stripe. Stripe may receive contact and billing details, payment method information, transaction amount, purchased service, IP address, device data, and fraud-prevention signals. We do not receive full card details.
Processing is based on Article 6(1)(b) GDPR to process the payment, Article 6(1)(c) GDPR for accounting and tax obligations, and Article 6(1)(f) GDPR for fraud prevention and payment security. Stripe may act as both processor and independent controller for parts of its regulated payment and compliance services.
Provider: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Further information: Stripe Privacy Policy.
7. Review links, comments, and consent records
Invited reviewers provide an email address and project password to access a private review. We process their email address, comments, timestamped feedback, approval status, and submission time. This is necessary to provide the review and record service requested by the customer (Article 6(1)(b) or 6(1)(f) GDPR, depending on the relationship).
The platform records a reviewer’s statement and associated metadata; it does not determine whether that statement is a legally sufficient release for every intended use. The customer remains responsible for the appropriate legal basis and scope of any publication.
8. Local storage and cookies
We do not currently use advertising or audience-measurement cookies. The application uses technically necessary browser storage for Google/Firebase authentication. Reviewer email addresses and project passwords are not saved in persistent browser storage.
Authentication storage is used only to provide an expressly requested sign-in function and is therefore treated as strictly necessary under § 25(2) no. 2 TDDDG. If optional analytics or marketing technologies are introduced, they will not be activated without any consent required by law.
9. Retention and deletion
- Account and project data is retained while the account or relevant project remains active.
- Project owners can delete projects, review links, reviewer records, and comments in the platform.
- Authentication data is retained according to Firebase’s deletion and backup cycles.
- Payment and invoice data is retained for the periods required by tax and commercial law.
- Data may be retained longer where necessary to establish, exercise, or defend legal claims.
To request deletion of an account or other personal data, email contact@abdallah.dev. Deletion from processor backup systems may take additional time.
10. Recipients and international transfers
Data is disclosed only where necessary to hosting and infrastructure providers, Google/ Firebase, Mux, Stripe, professional advisers, public authorities where legally required, and persons authorized by the relevant customer. Transfers outside the EEA rely on an adequacy decision, the EU–US Data Privacy Framework, Standard Contractual Clauses, or another lawful transfer mechanism, as applicable.
11. Your rights
Subject to the legal requirements, you may have the right to:
- access your personal data and receive a copy;
- rectify inaccurate or incomplete data;
- request erasure or restriction of processing;
- receive data you provided in a portable format;
- object to processing based on legitimate interests; and
- withdraw consent at any time where processing is based on consent.
You also have the right to lodge a complaint with a supervisory authority. Our local authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany: datenschutz-berlin.de.
12. Automated decisions and required data
We do not make decisions producing legal or similarly significant effects through automated decision-making. Data marked as required is necessary to provide the relevant account, review, consent-record, or payment function; without it, that function cannot be provided.
13. Changes to this notice
We may update this notice when the service, processors, or legal requirements change. Material changes will be highlighted in an appropriate way. The date above identifies the current version.