Skip to content
kofel studio
Deutsch Log in

Privacy Policy

Last updated: 2026-09-20 · Version 2026.09

Privacy Policy

Information pursuant to Art. 13 and 14 GDPR. We process as little personal data as possible and use no analytics or advertising tracking services. The German-language version is the authoritative basis.

1. Controller

The controller is Alexander Leonhartsberger-Schrott, 6065 Thaur, Dörferstrasse 26c, Österreich. Privacy enquiries: hello@kofel.io.

2. Waitlist

When you request access to the beta, we process your name, email address and — if provided — your reasoning. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure at your request). We use the data solely to contact you and set up access, and delete it once the request is handled or you demand deletion. The form is protected against automated submissions using Cloudflare Turnstile; in doing so, Cloudflare, Inc. (USA) processes technical data of your request (Art. 6(1)(f) GDPR, legitimate interest in abuse prevention).

3. Account and Use of the Application

For an account we process name, email address, password (stored encrypted) and the content you create in the application. Legal basis: Art. 6(1)(b) GDPR (performance of the usage agreement). For issuing invoices and fulfilling tax obligations we process the required billing data (Art. 6(1)(b) and (c) GDPR).

4. Content and Data of Your Customers

When you process data about your own customers, contacts and projects in your studio (customer records, receipts, bank transactions, notes), this happens on your behalf: you are the controller, we are the processor. The basis is the Data Processing Agreement (DPA), which is concluded before use. Categories and measures are set out in its annexes.

5. AI Features (optional)

AI features (assistant, receipt recognition, evaluations) are optional and only activated after your explicit consent. They send the affected content of your studio — including your customers' data — for processing to AI providers (currently OpenAI, LLC, USA; alternatively OpenRouter). These providers act as sub-processors and are listed in the sub-processor list. Legal basis is your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time; without it, all other features remain fully usable. You ensure that the processing is also agreed with your own customers before you apply AI features to their data.

6. Banking Integration

If you activate a banking integration, it is provided through our service provider Lunch Flow (lunchflow.app): you authorise access to your accounts directly with your bank (Payment Services Directive PSD2). We and Lunch Flow receive account balances and transactions in order to display them in your studio; access credentials are stored encrypted. Legal basis: Art. 6(1)(b) GDPR (contractual performance requested by you); vis-à-vis your bank you are the authorising customer.

7. Receipt Intake by Email

If you set up a receipt inbox address, we poll the mailbox you designate and process sender, subject and content of incoming messages as well as attachments in order to generate receipts. Legal basis: Art. 6(1)(b) GDPR. Credentials are stored encrypted; processing is limited to the mailboxes you configure.

8. Server Logs

When you access the site, technical log data is collected: IP address, timestamp, requested address, browser identification. Legal basis: Art. 6(1)(f) GDPR (operational security and troubleshooting). Logs are retained for short periods and then deleted.

9. Cookies and Local Storage

We use a technically necessary session cookie as well as local storage entries in your browser (e.g. for theme preference and UI controls). Both are required for operation and are not analysed. There is no analytics, tracking or advertising; a cookie banner is therefore not required.

10. Hosting

The service is operated at Hetzner Online GmbH, server location Falkenstein, Deutschland (EU). A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.

11. Recipients, Sub-processors and Third-Country Transfers

Recipients of your data are the service providers named in the sub-processor list. Disclosures to providers outside the EU only take place with the safeguards described there.

Transfers to Third Countries

Where service providers based outside the EU process personal data (in particular providers based in the United States), the transfer takes place only on one of the following bases:

  • an adequacy decision of the EU Commission, in particular the EU-US Data Privacy Framework (DPF), where the respective provider is certified; or
  • the EU Commission's Standard Contractual Clauses (Decision 2021/914) supplemented by additional measures (including encryption, data minimisation); or
  • explicit consent (Art. 49(1)(a) GDPR), where none of the above bases applies.

The current overview of providers and the safeguards applied is available in the sub-processor list.

12. Data Retention

Your data remains stored for as long as your account exists. After the end of the agreement, the DPA's deletion rule applies (deletion at the latest 90 calendar days after the end of the agreement, with export possible beforehand). Receipts and accounting data subject to statutory retention obligations (in Austria generally seven years, § 132 BAO) are retained for the duration of the obligation; your export right remains unaffected. Log data is deleted after short periods.

13. Your Rights and Complaints

Your Rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object (Art. 21). Consents may be withdrawn at any time without giving reasons. To exercise these rights, a simple message to hello@kofel.io suffices; we respond within one month.

Right to Lodge a Complaint

If you believe that the processing of your personal data infringes the GDPR, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is in particular the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, Wickenburggasse 8, 1080 Wien (https://www.dsb.gv.at).

14. Changes

We adapt this privacy policy when processing changes. Changes are published on this page with an updated date; in the case of material changes we will additionally notify you in the application.

Version 2026.09 — Terms of Use — Imprint

kofel studio · © 2026 · Run your studio. All in one place. Imprint Privacy Terms Contact