Privacy Policy

How we protect and handle your personal information

Data Controller / Verantwortlicher

Controller Information

Klaus-E. Klingner

Address / Anschrift:
c/o IP-Management #6585
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany

Email: support@kioju.de

Data Protection Officer

No Data Protection Officer required.
Based on the scope and nature of our data processing activities, we are not required to appoint a Data Protection Officer under Art. 37 GDPR.

Supervisory Authority / Aufsichtsbehörde

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany

Phone: +49 (0) 981 180093-0
Email: poststelle@lda.bayern.de
Website: www.lda.bayern.de

Your Rights

You have the right to lodge a complaint with the supervisory authority if you believe your data protection rights have been violated. You may contact us first to resolve any concerns, or contact the BayLDA directly.

Privacy First: Kioju collects only what's necessary to provide our service and never sells your data.

What Information We Collect

Account Information

  • Username and email address
  • Encrypted password (never stored in plain text)
  • Account preferences and settings

Your Content

  • Links you save and share
  • Titles and descriptions you provide
  • Collections you create

Technical Data

  • IP addresses for security purposes
  • Browser information for compatibility
  • Session data for authentication

How We Use Your Information

We use your information only for providing and improving our service:

Service Provision

Managing your links and collections, providing core functionality

Account Management

Authentication, user preferences, and personalized experience

Security & Safety

Protecting against abuse, spam, and unauthorized access

Communication

Sending invitations when you request them, important updates

Legal Basis for Processing (Art. 6 GDPR)

Each processing activity has a specific legal basis under GDPR Article 6:

Data Category Processing Purpose Legal Basis (Art. 6 GDPR) Retention Period
Account Information
Username, email, password
User registration and authentication Art. 6(1)(b) - Contract Performance
Necessary for providing the service you requested
Until account deletion or 3 years after last login
User Content
Links, collections, descriptions
Providing link management service Art. 6(1)(b) - Contract Performance
Core functionality of the service
Until account deletion or user removes content
Technical Data
IP addresses, session data
Security, fraud prevention, system stability Art. 6(1)(f) - Legitimate Interest
Protecting our service and users from abuse
30 days for logs, session duration for session data
Browser Information
User agent, capabilities
Technical compatibility and optimization Art. 6(1)(f) - Legitimate Interest
Ensuring service functionality across devices
Not stored permanently, processed in real-time
Communication Data
Contact form messages, support emails, invitation emails
Responding to inquiries and user-requested communications Art. 6(1)(a) - Consent
When you contact us or request invitations
Until inquiry resolved and reasonable follow-up period (max. 3 years)
Account Preferences
Settings, customizations
Personalizing user experience Art. 6(1)(b) - Contract Performance
Part of the personalized service
Until account deletion or user changes settings

Legitimate Interest Assessment: Where we rely on legitimate interest, we have conducted assessments to ensure our interests don't override your privacy rights. You can object to such processing at any time.

Consent Management & Email Verification

Double Opt-In Process

All email subscriptions (such as waiting list) require double opt-in verification. You must click a verification link sent to your email address to complete subscription.

Explicit Consent

We use separate, unchecked consent checkboxes for different types of communications. Pre-ticked boxes are never used.

Consent Records

We maintain detailed records of when and how you gave consent, including timestamp, IP address, and consent version for GDPR compliance.

Easy Withdrawal

Consent can be withdrawn at any time using unsubscribe links in emails or by visiting our unsubscribe page.

Consent Type Purpose Verification Method Withdrawal Options
Waiting List Join invitation waiting list, receive invitation notifications Double opt-in email verification required Unsubscribe link, unsubscribe page, email us
Contact Form Process and respond to your inquiry, provide requested support Explicit consent checkbox required on contact form Email us to request deletion of your inquiry and our response

GDPR Compliance: Our consent management system meets all GDPR requirements including record-keeping, easy withdrawal, and granular consent options.
What We Don't Do: We never sell your personal information, use tracking cookies, send spam, or share your private data with third parties.

How We Protect Your Data

Encryption

All passwords are securely encrypted using industry-standard hashing. Data transmission uses HTTPS encryption.

Access Control

Limited administrative access with regular security audits and monitoring for unusual activity.

Regular Updates

Security patches and updates are applied promptly to protect against emerging threats.

Data Retention: We retain your data only while your account is active. Request deletion anytime.

Data Processors & Sub-processors (Art. 28 GDPR)

We work with carefully selected service providers to deliver our service. All processors are bound by Data Processing Agreements (DPAs) and meet GDPR requirements.

Service Provider Purpose Data Processed Location DPA Status
Server4You GmbH
Hessen-Homburg-Platz 1
63452 Hanau, Germany
Web hosting, server infrastructure All website data, user accounts, content 🇩🇪 Germany (EU) ✓ DPA Signed
IMPRESSUMPRIVATSCHUTZ GmbH
Ludwig-Erhard-Str. 18
20459 Hamburg, Germany
secure and reliable postal address postal mail sent to us 🇩🇪 Germany (EU) ✓ DPA Signed
PHP Mail Function
Server-based email delivery
Transactional emails (verification, notifications) Email addresses, email content 🇩🇪 Germany (EU) Internal Service

DPA Requirements

All data processors have signed Data Processing Agreements containing:

  • Processing instructions and purpose limitations
  • Technical and organizational security measures
  • Sub-processor authorization and notification
  • Data subject rights assistance obligations
  • Return or deletion of data upon termination

EU-Only Processing

All data processing takes place within the European Union:

  • Primary hosting: Germany (Server4You)
  • Email delivery: Germany (same server)
  • No third-country transfers: All data remains in EU
  • No SCCs needed: No transfers outside EU/EEA

Processor Transparency: We maintain an up-to-date list of all data processors. Any changes to this list will be reflected in this privacy policy and communicated to users as required by GDPR.
No Analytics or Tracking: We do not use Google Analytics, Facebook pixels, or any other tracking/analytics services that would process your data. This minimizes the number of processors and protects your privacy.

Your Rights

You have full control over your data:

Access & Review

View all data we have about you, including account information and saved links

Correct & Update

Modify any incorrect information or update your account details anytime

Delete Account

Permanently delete your account and all associated data whenever you choose

Export Data

Download your data in a portable format for backup or migration

Communication Control

Manage your communication preferences and opt out of emails

Cookies

Essential Cookies Only

We use only essential session cookies for authentication and site functionality. No tracking or analytics cookies.

Automatic Deletion

All session cookies are automatically deleted when you log out or close your browser.

Privacy Questions?

Contact Information

Email: support@kioju.de
Contact: Klaus-E. Klingner
Response time: Within 48 hours

Data Requests

For any privacy-related questions, data access requests, corrections, or account deletion, please contact us using the email above.

Last updated: August, 12 2025

Need Help?

Have questions about your privacy or want to manage your data?