Privacy Policy

Last updated: September 2026

1. Data Controller

The data controller is the studio owner operating through the StudioFlow platform. For data protection inquiries, please contact the organization administrator via the email address configured in the organization's settings.

2. What Data We Collect

Account Data

Name, email address, and phone number of team members who use the platform.

Client Data

Client names, email addresses, phone numbers, project details, and communication history — entered by the studio team to manage their business.

Photo & File Data

Images uploaded to galleries, including EXIF metadata (camera model, date taken, GPS coordinates if present), file metadata (size, dimensions, format), and associated admin/client notes.

Gallery Visitor Data

When gallery visitors interact with public galleries: email address (if entered for favorites functionality), a client identification token, and IP address (recorded for contract and offer acceptance timestamps).

Technical Data

Browser user agent (for push notification subscriptions), device type, and standard web server access logs.

Usage Data

Activity logs within the platform for audit and security purposes.

3. Legal Basis (GDPR Art. 6)

  • Legitimate interest (Art. 6(1)(f)): Processing client data to operate and manage the photography business.
  • Contract performance (Art. 6(1)(b)): Providing the service to registered team members.
  • Consent (Art. 6(1)(a)): Gallery visitors who voluntarily enter their email address for the favorites feature.

4. Data Processing Purposes

We process personal data for the following purposes:

  • Studio and project management
  • Client scheduling and communication
  • Invoicing, offer, and contract generation
  • Photo gallery delivery and client review
  • Team collaboration and task management
  • Calendar synchronization
  • Platform security and abuse prevention

5. Data Storage & Location

  • Application database: Hetzner VPS, Germany (EU) — encrypted in transit via TLS.
  • Photo & video storage: Backblaze B2 object storage, EU region (eu-central) — encrypted at rest and in transit.
  • Content delivery: Cloudflare CDN serves cached photo and video assets from edge locations. Cloudflare acts as a pass-through caching layer; it does not persistently store your content beyond standard CDN cache TTLs.
  • Backups: Server filesystem on the same Hetzner VPS (Germany, EU) — daily XLSX exports of the application database with 30-day rolling retention. Backup files never leave the EU. Photo and video master files are not included in the application backup; see the Terms & Conditions, Section 5.5.

6. Data Retention

  • Active data: Retained for the duration of the organization's existence on the platform.
  • Soft-deleted data: Retained for up to 30 days to allow recovery, then permanently removed.
  • Backups: Daily backups retained for 30 days; monthly archives for 2 years.
  • Audit logs: Retained for 12 months.

7. Third-Party Processors

  • Hetzner Online GmbH — Server hosting (Germany, EU)
  • Backblaze, Inc. — Photo and video object storage (B2, EU region)
  • Cloudflare, Inc. — Content delivery network (CDN) for cached photo/video delivery; also provides DNS and TLS termination at the edge. No persistent storage of customer content.
  • Google LLC — Calendar synchronization only (via the organization owner's own Google account; no backup data is sent to Google)
  • Web Push services — Browser push notification delivery (via browser vendor endpoints)

8. Your Rights

Under the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG / FADP), you have the following rights:

  • Right of access (Art. 15 GDPR): Request a copy of your personal data.
  • Right to rectification (Art. 16): Request correction of inaccurate data.
  • Right to erasure (Art. 17): Request deletion of your data. Organization owners can delete their entire organization via the "Delete Organization" feature in Settings.
  • Right to data portability (Art. 20): Export your data in a structured format (XLSX backup export is available).
  • Right to object (Art. 21): Object to processing based on legitimate interest.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
  • Right to lodge a complaint: With the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or the relevant supervisory authority in your EU member state.

9. Cookies & Local Storage

StudioFlow does not use tracking cookies, analytics scripts, or third-party advertising. We use browser localStorage solely for:

  • Authentication tokens (JWT) for maintaining your login session
  • Client identification tokens for gallery favorites
  • UI preferences (theme, sidebar state)

10. Data Breach Notification

In accordance with GDPR Art. 33/34 and Swiss FADP Art. 24, we will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms. Affected individuals will be notified without undue delay when the breach is likely to result in a high risk.

11. Children

StudioFlow is not directed at individuals under the age of 16. We do not knowingly collect personal data from children.

12. Swiss Federal Act on Data Protection (nDSG / FADP)

As the platform is operated from Zürich, Switzerland, the Swiss Federal Act on Data Protection (nDSG, in force since 1 September 2023) applies in addition to the GDPR. This means:

  • We maintain a register of processing activities as required by Art. 12 nDSG.
  • Cross-border data transfers comply with Art. 16-17 nDSG (all data remains in the EU/Switzerland).
  • Data breach notifications follow the requirements of Art. 24 nDSG.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email to the organization owner. The updated policy will be posted on this page with a revised "Last updated" date.

14. Contact

For data protection inquiries, requests to exercise your rights, or any questions about this Privacy Policy, please contact the organization administrator at the email address listed in the platform's Settings page.

15. Language

This Privacy Policy is published in English and in German. The English version is the reference version; the German version is provided for convenience only. In the event of any conflict, inconsistency, or difference of interpretation between the two, the English version prevails. The German version is available at /de/privacy.