Privacy Policy
Last Update: 31. July 2026
The German version serves as the reference version for content maintenance and consistency checks. The English version provides the information in full and with equivalent substance.
This Privacy Policy applies exclusively to the curalbum.app website and the processing operations described there. Use of the Curalbum Android app is covered by the separate App Privacy Policy. If the App Privacy Policy is accessed through the website, that access is itself use of the website and is therefore covered by this Website Privacy Policy; the processing operations of the app and its associated platform services are instead described in the App Privacy Policy.
Table of contents
- Controller
- Overview of processing operations
- Relevant legal bases
- General Information on Data Retention and Deletion
- Rights of Data Subjects
- Sign-up for the one-off release notification
- Website provision, hosting and local browser functions
- Changes and Updates
- Contact by email, telephone or post
Controller
René Böhres
Ludwig-Erhard-Straße 15
63512 Hainburg, Germany
E-mail address: hello@curalbum.app
Legal Notice: https://curalbum.app/en/imprint.html
Overview of processing operations
The following table summarises the types of data processed, the purposes for which they are processed and the concerned data subjects.
Relevant legal bases
Relevant legal bases according to the GDPR: In the following, you will find an overview of the legal basis of the GDPR on which we base the processing of personal data. Please note that in addition to the provisions of the GDPR, national data protection provisions of your or our country of residence or domicile may apply. If, in addition, more specific legal bases are applicable in individual cases, we will inform you of these in the data protection declaration.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations apply to data protection in Germany. This includes in particular the Law on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act - BDSG). In particular, the BDSG contains special provisions on the right to access, the right to erase, the right to object, the processing of special categories of personal data, processing for other purposes and transmission as well as automated individual decision-making, including profiling. Furthermore, data protection laws of the individual federal states may apply.
Relevant legal bases under the Swiss Federal Act on Data Protection: If you are located in Switzerland, we process your data in accordance with the Swiss Federal Act on Data Protection (FADP). Unlike the GDPR, the FADP does not contain a general catalogue of legal bases that must be stated for every processing operation. Processing must nevertheless be lawful, carried out in good faith and proportionate (Article 6(1) and (2) FADP). Furthermore, we collect personal data only for a specified purpose that is recognisable to the data subject and process it only in a manner compatible with that purpose (Article 6(3) FADP).
Reference to the applicability of the GDPR and the Swiss DPA: This privacy policy is intended to provide information in accordance with both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). Where references are made to concepts such as the processing of personal data, legitimate interests, or special categories of data, these references are to be understood in accordance with the applicable data protection laws. Within the scope of application of the Swiss FADP, the legal interpretation of these terms is determined exclusively by Swiss law.
General Information on Data Retention and Deletion
We delete personal data that we process in accordance with legal regulations as soon as the underlying consents are revoked or no further legal bases for processing exist. This applies to cases where the original purpose of processing is no longer applicable or the data is no longer needed. Exceptions to this rule exist if statutory obligations or special interests require a longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data specifically applicable to certain processing processes.
In cases where multiple retention periods or deletion deadlines for a date are specified, the longest period always prevails.
Data that is no longer stored for its originally intended purpose but due to legal requirements or other reasons are processed exclusively for the reasons justifying their retention.
Data Retention and Deletion: The following general deadlines apply for the retention and archiving according to German law:
- 10 Years - Fiscal Code/Commercial Code - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheet as well as the necessary work instructions and other organisational documents (Section 147 Paragraph 1 No. 1 in conjunction with Paragraph 3 of the German General Tax Code (AO), Section 14b Paragraph 1 of the German VAT Act (UStG), Section 257 Paragraph 1 No. 1 in conjunction with Paragraph 4 of the German Commercial Code (HGB)).
- 8 years - Accounting documents, such as invoices, booking and expense receipts (Section 147 Paragraph 1 No. 4 and 4a in conjunction with Paragraph 3 of the German General Tax Code (AO), Section 257 Paragraph 1 No. 4 in conjunction with Paragraph 4 of the German Commercial Code (HGB))
- 6 Years - Other business documents: received commercial or business letters, copies of dispatched commercial or business letters, and other documents to the extent that they are significant for taxation purposes, for example, hourly wage slips, operating accounting sheets, calculation documents, price tags, as well as payroll accounting documents, provided they are not already accounting vouchers and cash register tapes Section (Section 147 Paragraph 1 No. 2, 3, 5 in conjunction with Paragraph 3 of the German General Tax Code (AO), Section 257 Paragraph 1 No. 2 and 3 in conjunction with Paragraph 4 of the German Commercial Code (HGB)).
- 3 Years - Data required to consider potential warranty and compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on previous business experiences and common industry practices, will be stored for the duration of the regular statutory limitation period of three years. This period begins at the end of the year in which the relevant contractual transaction took place or the contractual relationship ended in the case of ongoing contracts (Sections 195, 199 of the German Civil Code).
Data Retention and Deletion: The following general retention and archiving periods apply under Swiss law:
- 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balances, accounting vouchers and invoices, as well as all necessary working instructions and other organizational documents (Article 958f of the Swiss Code of Obligations (OR)).
- 10 years - Data necessary to consider potential claims for damages or similar contractual claims and rights, as well as for the processing of related inquiries based on previous business experiences and usual industry practices, will be stored for the statutory limitation period of ten years, unless a shorter period of five years is applicable, which is relevant in certain cases (Articles 127, 130 OR). Claims for rent, lease, and interest on capital, as well as other periodic services, for the delivery of food, for board and lodging, for innkeeper debts, as well as for craftsmanship, small-scale sales of goods, medical care, professional services by lawyers, legal agents, procurators, and notaries, and from the employment relationship of employees, expire after five years (Article 128 OR).
Rights of Data Subjects
Rights of the Data Subjects under the GDPR: As data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to Object: You have the right, on grounds arising from your particular situation, to object at any time to the processing of your personal data which is based on letter (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Right of withdrawal for consents: You have the right to revoke consents at any time.
- Right of access: You have the right to request confirmation as to whether the data in question will be processed and to be informed of this data and to receive further information and a copy of the data in accordance with the provisions of the law.
- Right to rectification: You have the right, in accordance with the law, to request the completion of the data concerning you or the rectification of the incorrect data concerning you.
- Right to Erasure and Right to Restriction of Processing: In accordance with the statutory provisions, you have the right to demand that the relevant data be erased immediately or, alternatively, to demand that the processing of the data be restricted in accordance with the statutory provisions.
- Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, common and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
- Complaint to the supervisory authority: In accordance with the law and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State where you habitually reside, the supervisory authority of your place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
Rights of the data subjects under the Swiss DPA:
As the data subject, you have the following rights in accordance with the provisions of the Swiss DPA:
- Right to information: You have the right to request confirmation as to whether personal data concerning you are being processed, and to receive the information necessary for you to assert your rights under the Swiss DPA and to ensure transparent data processing.
- Right to data release or transfer: You have the right to request the release of your personal data, which you have provided to us, in a common electronic format, as well as its transfer to another data controller, provided this does not require disproportionate effort.
- Right to rectification: You have the right to request the rectification of inaccurate personal data concerning you.
- Right to object, deletion, and destruction: You have the right to object to the processing of your data, as well as to request that personal data concerning you be deleted or destroyed.
Sign-up for the one-off release notification
You may voluntarily sign up to receive exactly one email announcing that Curalbum has been released. This is neither an ongoing newsletter nor ongoing advertising. We process in particular the email address entered in the form as the relevant category of personal data, the selected form language or source de or en, the version of the consent wording in effect when the form is submitted, and the timestamps needed for registration, confirmation and status management. The email address may have been entered by you or by another person. If it was entered by someone else, we obtained it indirectly from the person who entered it via the release sign-up form on curalbum.app. We do not know the identity of the person who entered it unless that identity is otherwise apparent from the specific circumstances. As a matter of operator policy, this service is available only to persons aged 16 or over.
By submitting the form after receiving this information, you consent to processing for this one-off purpose. We then send a purely functional double opt-in email to the address provided. This functional email is our first communication with the affected mailbox. The registration becomes active only when you expressly confirm it; without confirmation, it is not activated and no further release notification is sent. Confirmation serves to verify control of the specified mailbox and to document consent. Double opt-in is our chosen verification and evidence procedure and is not presented as a form prescribed by law.
To protect the registration process, the email address is stored in encrypted form. We also use a non-reversible comparison value to identify duplicate entries. To protect against automated or excessive abusive registration attempts, a pseudonymous value that is not intended to permit reverse calculation is derived from the IP address during the relevant request for a fixed ten-minute window. The raw IP address is not stored persistently in the Curalbum database. This abuse-prevention processing serves a separate purpose and is not based on your consent to the release notification.
Unconfirmed registrations remain valid for no more than 72 hours and are then deleted. Confirmation information is retained only until confirmation or expiry; time-limited unsubscription information remains necessary until unsubscription or completion of the one-off dispatch. After confirmation, we retain the encrypted email address, comparison value, source, consent version, and creation, confirmation and status details only until unsubscription or the one-off release. You may unsubscribe free of charge at any time before the release by using the unsubscribe link; the entire record is then deleted and no history of consent withdrawal is created.
We use ALL-INKL in Germany as a processor for the database and email delivery. The functional confirmation email and, later, the one-off release notification are delivered to the mailbox you selected and its mail server. The release notification is sent only to previously confirmed addresses. For the manual dispatch, we use the BCC field so that other recipients cannot see the addresses of the other addressees. Immediately after this one-off dispatch, we delete the export file, the sent-message copy and the confirmed records. We maintain neither a suppression list nor a persistent personal database evidencing consent or dispatch.
For persons within the scope of the GDPR, processing for sign-up and dispatch is based on your consent under Article 6(1)(a) and Article 7 GDPR; the one-off advertising email is also subject to Section 7 of the German Act against Unfair Competition (UWG) and Article 13 of Directive 2002/58/EC. The confirmation and status details provide limited evidence of consent. Separately, protection against abusive registration attempts is based on our legitimate interests under Article 6(1)(f) GDPR in protecting the operation and security of the service. Withdrawal of consent takes effect for the future and does not affect the lawfulness of processing carried out before the withdrawal.
For persons in Switzerland, we do not transpose the catalogue of legal bases in Article 6 GDPR into the Swiss system. Relevant provisions include the processing principles and the requirements for freely given and informed consent under Article 6 of the Federal Act on Data Protection (FADP), and Article 3(1)(o) of the Federal Act against Unfair Competition (UCA) for the release notification. Double opt-in remains a chosen evidence and protection procedure in this context as well, not a form prescribed by law. Under Swiss law, a minor's ability to consent depends on their capacity of judgement; the age threshold of 16 is our stricter operator rule and not a general statutory age threshold.
Website provision, hosting and local browser functions
We provide curalbum.app, including its locally embedded content, using webspace at ALL-INKL in Germany. Requests to curalbum.de and curalbum.com are redirected to curalbum.app. A request generates the request data technically required for delivery and redirection, in particular the IP address, time, requested host and path, the query string where applicable, transmitted protocol and header data, and the response status. The requested path may include /de/ or /en/. ALL-INKL processes these data for us as a processor. Where required for the website operations, we also use SQLite and email infrastructure there.
When the root page is first accessed, your browser evaluates navigator.languages or, as a fallback, navigator.language locally. If the browser language is German, the German version at /de/ is selected initially; otherwise, the English version at /en/ is selected. Curalbum does not transmit the browser language list itself to the server as a separate field. However, the language path selected from it is visible to us and ALL-INKL when the subsequent page is requested. You can change the language at any time using the normal language links. This manual change is not stored, and Curalbum does not create a persistent language preference.
The browser or operating-system setting prefers-reduced-motion is likewise evaluated only locally to adjust motion and transition effects. Curalbum does not persist either this preference or the language preference. Based on the confirmed technical state, we do not use cookies for these functions and do not use analytics, tracking or advertising services on the website. We also do not automatically embed external fonts, content delivery networks or other third-party resources. This statement concerns functions controlled by Curalbum and does not categorically exclude ordinary browser or HTTP caches.
The Curalbum website does not separately store ordinary request data on a persistent basis. The access statistics and access logs that we can control within the hosting service are disabled. This does not assert that the internal ALL-INKL infrastructure is entirely free of logs. If temporary residual data arise there for compelling technical reasons, we do not specify particular data fields or a fixed retention period because no such details have been confirmed. Deletion and limitation in this respect depend on the relevant technical purpose and the applicable legal requirements.
For persons within the scope of the GDPR, the technically necessary provision, redirection and protection of the website are based on our legitimate interests under Article 6(1)(f) GDPR in delivering the website reliably and securely in the requested language version. The local language evaluation and reduced-motion evaluation do not create persistent storage on terminal equipment controlled by Curalbum; the local raw values must be distinguished from the language path subsequently visible to the server.
For persons in Switzerland, we do not transpose the catalogue of legal bases in Article 6 GDPR into the Swiss system. The processing principles in Article 6 of the Federal Act on Data Protection (FADP) apply and, where justification is required, in particular the overriding private interest in reliable and secure website provision under Article 31 FADP. The local browser evaluation and the visible language path are also assessed under Article 45c letter b FMG, concerning processing involving users' terminal equipment, and under the Swiss FADP. Curalbum's processing at ALL-INKL takes place in Germany; under Swiss data protection law, Germany is considered a country with an adequate level of data protection.
Changes and Updates
We kindly ask you to inform yourself regularly about the contents of our data protection declaration. We will adjust the privacy policy as changes in our data processing practices make this necessary. We will inform you as soon as the changes require your cooperation (e.g. consent) or other individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, we ask you to note that addresses may change over time and to verify the information before contacting us.
Supervisory authority competent for us:German supervisory authority responsible for the controller:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
Wilhelmstraße 7
65185 Wiesbaden, Germany
Swiss data protection supervisory authority:
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Berne, Switzerland
Contact by email, telephone or post
You may contact us voluntarily by email at hello@curalbum.app, by telephone or by post. We do not provide a general contact form. We process the data that you choose to provide with your enquiry. For emails, these data include in particular the sender and recipient addresses, subject, content, sending and receipt times, and any names, callback details or attachments provided voluntarily. For telephone calls, the transmitted telephone number, time, a stated name and the content of the conversation arise only to the extent that they are communicated during the call. For postal correspondence, we process sender and return details, the contents of the letter and any enclosures provided voluntarily. Enquiries may also contain information about other persons. The source of such indirectly obtained information is the person contacting us, through their email, telephone call or postal correspondence. The categories may include in particular names, contact details and other information about the person mentioned in the message content or voluntary attachments. We do not collect special categories of personal data regularly or purposefully in this context.
We use these details to handle your enquiry, clarify follow-up questions and respond to you. Information about persons mentioned in an enquiry is not copied into a separate record, used for unrelated purposes or used to contact them without an objective reason. Third-person data that are not required are not used further and are deleted together with the enquiry in accordance with the criteria described below. Emails are stored in the associated ALL-INKL mailbox in Germany and handled through its web interface; ALL-INKL acts as our processor in this context.
For persons within the scope of the GDPR, the legal basis depends on the actual purpose of the enquiry. We handle general questions and support on the basis of our legitimate interests in communicating and responding under Article 6(1)(f) GDPR. Article 6(1)(b) GDPR applies only where you request pre-contractual steps or the communication is necessary for a contract. Article 6(1)(c) GDPR applies only where a specific legal obligation is relevant. Where storage is necessary for the establishment, exercise or defence of specific legal claims, we rely on Article 6(1)(f) GDPR. Before contacting a person mentioned in an enquiry on our own initiative, disclosing their data or otherwise processing their data independently, we assess the timing and content of the information required under Article 14 GDPR. As a rule, the information is provided within a reasonable period and no later than one month, or, where the data are used to communicate with that person, no later than the first communication, or, where disclosure is intended, no later than the first disclosure. We do not assume an exception under Article 14(5) GDPR generally; we assess and document it for the specific case.
For persons in Switzerland, we do not transpose these GDPR legal bases into the Swiss system. The processing principles in Article 6 of the Federal Act on Data Protection (FADP) apply and, where justification is required, Article 31 FADP, in particular consent, an overriding private interest or a legal basis. Where information is obtained indirectly, we also provide the categories of personal data being processed in accordance with Article 19(3) FADP. The information under Article 19(2)–(4) FADP is generally provided no later than one month after the data were obtained as required by Article 19(5) FADP; if the data are disclosed before that time, we provide the information no later than at the time of disclosure. We interpret the exceptions in Article 20 FADP narrowly and apply them only after assessing and documenting the specific case. For the handling of contact emails, ALL-INKL is a processor under Article 9 FADP; the processing takes place in Germany.
We delete ordinary enquiries once the matter has been substantively resolved and no further need for follow-up questions can reasonably be expected. We retain them for longer only where their specific content is in fact subject to a statutory retention obligation or is necessary to preserve specific claims or evidence. We therefore do not retain every contact for a blanket period of six, eight or ten years, nor do we derive an automatic retention period for all contacts from statutory limitation periods. We do not claim that individual third-person data can be removed technically and immediately from an email that has already been received; data that are not required are not used further until the enquiry is deleted. Deletion from the mailbox as part of our operational process is not equated with unsubstantiated complete deletion of any internal technical remnants at ALL-INKL; we state no fixed period for such unconfirmed provider details.