picdeo

Privacy Policy

Last updated: July 10, 2026 · Version 1.0

This English version is provided for convenience only. The German version is the legally binding version.

This Privacy Policy explains which personal data we process on the Picdeo platform (www.picdeo.de), for which purposes, and which rights you have. Picdeo is a B2B platform: travel-industry suppliers provide official media material, travel agencies use it for client consultation and marketing.

1. Controller

Controller within the meaning of the EU General Data Protection Regulation (GDPR):

Picdeo
Owner: Benjamin Bindewald, sole proprietor

Bahnhofstraße 12

61200 Wölfersheim

Germany

Email: benny@besserurlauben.de
Phone: +49 6036 9047960

A data protection officer has not been appointed, as the statutory requirements for such an appointment are not currently met.

2. Overview: processing principles

  • We process personal data only to the extent necessary to operate the platform, to perform our contracts, or to comply with legal obligations — or where you have given consent.
  • We do not sell personal data and do not share it with third parties for advertising purposes.
  • Picdeo is directed exclusively at businesses. We primarily process business contact and account data of the individuals acting on their behalf (e.g. name, business email address, organization membership).
  • Depending on the operation, the legal bases are: Art. 6(1)(b) GDPR (performance of a contract), (c) (legal obligation), (f) (legitimate interest) and (a) (consent).

3. Hosting and infrastructure

We use the following service providers as processors (Art. 28 GDPR) to operate the platform:

3.1 Vercel (application hosting)

The web application is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel processes technically necessary connection data (IP address, request data). A data processing agreement is in place with Vercel; transfers to the USA are safeguarded by the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses.

3.2 Supabase (database, authentication, media storage)

The database, the login system and media storage run with Supabase Inc. (970 Toa Payoh North #07-04, Singapore) in an EU project region (Frankfurt, eu-central-1). Stored data includes account data, organization data, uploaded media files and the usage data described in this policy. A data processing agreement based on the EU Standard Contractual Clauses is in place with Supabase.

3.3 Media storage (S3-compatible object storage)

Uploaded media files (images, videos, PDFs) are stored in S3-compatible object storage in the EU (Frankfurt). Files are retrieved via time-limited, signed URLs — media files are not publicly accessible unless the provider has published them.

Legal basis for hosting and storage: Art. 6(1)(b) GDPR (provision of the contractually owed platform) and (f) (legitimate interest in secure, efficient operation).

4. Server logs

When you access the platform, log data is processed automatically: IP address, date and time, page accessed, referrer URL, browser type and version, operating system. This data is technically required to deliver the website and serves stability, error analysis and attack detection.

Legal basis: Art. 6(1)(f) GDPR. Log data is generally deleted or anonymized after no more than 30 days, unless it is needed longer to investigate specific incidents.

5. Cookies and local storage

We use strictly necessary cookies and local storage entries only — no tracking, no advertising cookies.

TypePurposeDuration
Auth cookiesLogin session (Supabase Auth, sb-*)Session/refresh
Local storageInterface preferences (e.g. view settings, dismissed hints)Until deleted

Legal bases: Section 25(2) no. 2 of the German TDDDG (strictly necessary) and Art. 6(1)(b) GDPR. Details: Cookie Policy.

6. Registration, login and user accounts

A user account is required to use the platform. Upon registration we process: name, business email address, password (stored only as a cryptographic hash), organization membership and role, time of registration, and the version of the accepted contractual terms. Team invitations involve processing the invitee's email address and a time-limited invitation link. For the password-reset feature we send a time-limited reset link to the email address on file.

Legal basis: Art. 6(1)(b) GDPR (account management as part of the platform contract).

7. Organizations: providers and travel agencies

Accounts belong to organizations (provider or travel agency). For organizations we process company data (name, type, country, city, description, website, logo/cover image, social media links) and verification status. Provider profiles may be publicly visible — they contain company data, not mandatory personal data. Company data of legal entities is generally not personal data; for sole proprietorships it may be.

Legal basis: Art. 6(1)(b) GDPR; for the public display of provider profiles, additionally the settings chosen by the provider.

8. File uploads and AI-assisted keywording

Providers upload media files (images, videos, PDFs, copy) together with metadata (title, description, rights holder, destination, tags, validity). For each upload we additionally store technical data: file size, file type, SHA-256 checksum (integrity assurance), timestamp and uploading user account (traceability within the organization, change history).

AI-assisted keywording (optional): At the provider's request, we analyze uploaded images automatically to generate keywording suggestions (tags, categories). For this purpose the image is transmitted to Anthropic PBC (San Francisco, USA) acting as our processor. Only the image data and factual metadata are transmitted — no account data. Transfers to the USA are safeguarded by the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework. Anthropic does not use this content to train AI models.

Legal bases: Art. 6(1)(b) GDPR (upload as a contractual service), (f) (integrity assurance, abuse prevention); AI keywording is performed only upon the provider's active request.

9. Downloads, license records and download history

When a travel agency downloads a media asset, a licensing transaction is created. We record: the downloading organization and user account, the asset and its version, license type, date and time, the download/license number, and the SHA-256 checksum of the file. On this basis we issue the license record (PDF certificate with a verification QR code); its authenticity can be verified publicly at picdeo.de/lizenz/[number] — the public verification page shows license-related information only, no personal data of the downloading employee.

This record-keeping is at the core of the platform: it creates legal certainty for both sides and enables aggregated download statistics for providers.

Legal bases: Art. 6(1)(b) GDPR (license administration), (f) (record-keeping, abuse prevention), (c) in conjunction with statutory commercial and tax retention obligations.

10. Email communication and notifications

We send transactional emails: registration and invitation emails, password resets, license confirmations to travel agencies and — depending on the chosen setting — download notifications to providers (immediate, daily or weekly digest; can be disabled). We send marketing newsletters only with separate consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time.

For sending we use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as our processor. Data processed includes recipient address, subject line and delivery data. Transfers to the USA are safeguarded by the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework; emails are sent via an EU sending domain.

11. Contacting us

If you contact us via a form or by email, we process the information you provide (name, email address, inquiry) in order to handle your request. Legal basis: Art. 6(1)(b) or (f) GDPR. We delete inquiry data once the matter has been resolved, unless statutory retention obligations apply.

12. Analytics and internal statistics

We currently use no external analytics or tracking services (no Google Analytics, no advertising pixels). For providers we compile platform-internal statistics (e.g. views and downloads per asset) based on transaction data that arises anyway; evaluation is organization-based or aggregated. Should we introduce a privacy-friendly analytics tool in the future, we will update this policy beforehand.

13. Fonts (hosted locally)

We use web fonts (including Google Fonts) that are hosted locally on our servers. No connection to Google servers is established when you visit our pages.

14. YouTube embeds (optional, two-click)

Individual pages may embed YouTube videos (e.g. provider profile videos). Where used, videos are embedded in privacy-enhanced mode (youtube-nocookie.com) and load only after an active click: before that click, no connection to YouTube is established. Once played, Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) processes connection and usage data, potentially with transfers to the USA (Google LLC), safeguarded by the EU-U.S. Data Privacy Framework.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent through active click).

15. Future services: Stripe and Pipedrive

The following services are not currently active. This policy will be updated before they are introduced:

15.1 Stripe (payment processing — planned)

For future paid provider services we plan to process payments via Stripe (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). Stripe will then process payment and invoicing data, partly under its own responsibility. Legal basis: Art. 6(1)(b) GDPR.

15.2 Pipedrive (customer relationship management — planned)

To manage business contacts we plan to use Pipedrive (Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia) as a processor. Business contact data and communication notes will then be processed. Legal basis: Art. 6(1)(f) GDPR.

16. Recipients and transfers to third countries

Recipients of personal data are exclusively the processors named in this policy and — where legally required — public authorities. Within the platform, providers see information about downloads of their media (organization, time, asset); travel agencies see providers' published content and profiles.

For service providers established or processing outside the EU/EEA (Vercel, Resend, Anthropic, Google where applicable), transfers are based on adequacy decisions (EU-U.S. Data Privacy Framework) and/or the EU Standard Contractual Clauses (Art. 44 et seq. GDPR).

17. Retention periods

  • Account and organization data: for the duration of platform use; after account deletion, data is deleted or anonymized unless retention obligations apply.
  • Licensing transactions and license records: for the duration of statutory retention periods (German Commercial Code/Fiscal Code) and beyond, to the extent required to evidence the license chain.
  • Deleted content: media is first deactivated and subsequently removed permanently through a defined process; existing license records remain unaffected.
  • Server logs: see section 4.

18. Your rights

You have the following rights with respect to your personal data:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

An informal message to benny@besserurlauben.de is sufficient to exercise these rights.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is: The Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, www.datenschutz.hessen.de.

19. Data security

We implement technical and organizational measures pursuant to Art. 32 GDPR, including: TLS encryption of all connections, password hashing, role-based access control with tenant isolation at database level (row level security), signed and time-limited download URLs, SHA-256 integrity verification of media files, and logging of security-relevant events.

20. Changes to this Privacy Policy

We update this policy when the platform, the services we use, or the legal situation change. The version published on the website applies; we will notify registered users of material changes in an appropriate manner.