Privacy Policy

Privacy Policy of PxlShare

We take the protection of your personal data seriously. This Privacy Policy explains what personal data we collect, how we process it, and what rights you have as a user of our platform. Our processing of personal data complies with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable laws.


1. Controller

The controller within the meaning of the GDPR is:

SynthScript Inh. Christoph Kretschmer
Hornisgrindestraße 9
77855 Achern
Germany
Email: privacy@synthscript.com
Phone: +49 7841 627 44 00


2. Data Collected

We process the following categories of personal data:

  • Account data: Name, email address, password (hashed), language preference.
  • Payment data: Billing address, payment details (processed via external payment providers, not stored by us).
  • Content data: Photos, albums, comments, revisions, and related metadata uploaded by you.
  • Usage data: Log files, IP address, browser type, device information, access times.
  • Support requests: Communication with our support team.

3. Purpose of Processing

We process personal data for the following purposes:

  • Provision of the cloud service (storage, album management, sharing functions).
  • Performance of the contract and billing.
  • Communication with users (e.g., support, service updates).
  • Ensuring security and stability of the platform.
  • Compliance with legal obligations (e.g., tax and commercial law retention).

4. Legal Basis

Processing is based on:

  • Art. 6(1)(b) GDPR – performance of a contract (user registration, storage, payment).
  • Art. 6(1)(c) GDPR – compliance with legal obligations.
  • Art. 6(1)(f) GDPR – legitimate interests (ensuring IT security, fraud prevention, service improvement).
  • Art. 6(1)(a) GDPR – consent, where required (e.g., optional newsletters).

5. Data Sharing

We only share data with third parties where legally permitted and necessary:

  • Hosting provider: Our service is hosted in Germany by IONOS SE, Montabaur, ensuring GDPR compliance.
  • Payment providers: Mollie B.V. (and other payment processors, if applicable).
  • IT service providers: For maintenance and technical support.
  • Authorities: Where required by law.

No data is transferred to third countries outside the EU/EEA unless adequate safeguards (Art. 46 GDPR) are in place.


6. Data Retention

  • Account data is stored for the duration of the contractual relationship.
  • Legal retention obligations (e.g., tax documents) apply for up to 10 years.
  • Uploaded photos and albums are stored until you delete them or terminate your account.
  • Log data is typically stored for 7–14 days for security purposes.

7. Data Security

We apply appropriate technical and organizational measures (Art. 32 GDPR) to protect personal data against unauthorized access, loss, or misuse. This includes encryption, access controls, and regular security audits.


8. User Rights

You have the following rights under GDPR:

  • Access (Art. 15 GDPR): Obtain information about stored data.
  • Rectification (Art. 16 GDPR): Correct inaccurate data.
  • Erasure (Art. 17 GDPR): Request deletion of your data.
  • Restriction (Art. 18 GDPR): Limit processing of your data.
  • Portability (Art. 20 GDPR): Receive your data in a machine-readable format.
  • Objection (Art. 21 GDPR): Object to processing based on legitimate interests.
  • Withdrawal of consent (Art. 7(3) GDPR): Revoke consent at any time.

To exercise these rights, contact us at: [privacy@yourcompany.com].


9. Cookies and Tracking

We use cookies and similar technologies to ensure functionality and improve user experience. Essential cookies are necessary for the operation of the platform. Analytics or marketing cookies are only used with your prior consent (Art. 6(1)(a) GDPR).


10. Children’s Data

Our service is not directed at children under 16 years of age. We do not knowingly process children’s personal data without parental consent.


11. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in legal requirements or our services. Users will be informed of significant changes via email or within the platform.