Privacy notice

This is a translation. The German version is the binding one.

Version 2.0, 27 September 2026 (draft). This is a translation; the German version is the binding one.

1. Controller

Florian Stemmer, scenebright, Huttengrundstr. 22, 36396 Steinau an der Straße, Germany. Email kontakt@scenebright.com, contact form: scenebright.com/en/contact. No data protection officer is appointed because the legal requirements (Art. 37 GDPR, § 38 German Federal Data Protection Act) are not met.

2. Overview

We process personal data only as needed for the website, portal and services, to meet legal obligations, for legitimate interests or with your consent (Art. 6(1)(a), (b), (c), (f) GDPR). Our service is for businesses; personal data mainly concerns sole traders and contacts at our customers. Content that customers upload and publish is processed on the customer’s behalf under a data processing agreement (Art. 28 GDPR); the customer is the controller for that content.

3. Hosting and server logs

Website, portal, database and storage run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, data centre Falkenstein, under a data processing agreement. We log IP address, time, URL, status code, data volume, browser, operating system and referrer to deliver the site, find errors and fend off attacks (Art. 6(1)(f) GDPR). Logs are deleted after 14 days unless needed to investigate a security incident. Fonts and scripts are served from our own server.

4. Cookies

The website uses no cookies, no local storage and no analytics or marketing tools. The portal only uses strictly necessary cookies: a session cookie after login (valid for at most 12 hours, deleted on logout) and a security cookie against forged requests. No consent is required for these under § 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), so there is no cookie banner. At checkout you are redirected to Stripe, which sets its own cookies, e.g. for fraud prevention, under its own responsibility.

5. Contact and contact form

You can reach us by email or via the contact form at scenebright.com/en/contact. The form processes your name, email address and message plus time and IP address of submission and forwards your request by email to kontakt@scenebright.com (sent via Hostinger, section 10). Spam protection uses a hidden check field and a rate limit per IP address, without third-party services or cookies. We process your details to answer (Art. 6(1)(b) or (f) GDPR) and delete them when the matter is closed, unless business correspondence must be retained (up to 6 years). Notices of illegal content under Art. 16 DSA are processed to handle the notice (Art. 6(1)(c) GDPR).

6. Free sample post with double opt-in

6. Free sample post with double opt-in [applies once the sample form is live]. You upload a product photo, choose a style and enter your email address. We send a confirmation link; only after you click it do we create the sample (Art. 6(1)(b) GDPR, pre-contractual request). Requests are rate-limited per IP address without third-party services. Marketing emails (up to 5 in 14 days) are sent only if you tick a separate, optional box and confirm this by clicking the link in the confirmation email (Art. 6(1)(a) GDPR). You receive the sample without that consent. You can withdraw consent at any time via the link in every email. We do not track opens or clicks. As proof we store time and IP address of request and confirmation and the consent wording and version (Art. 6(1)(f) GDPR). Unconfirmed requests are deleted after 48 hours, photo and sample 14 days after delivery, proof of consent 3 years after the last email; after withdrawal we keep a hash of your email address on a suppression list for as long as we send marketing emails. Please do not upload photos showing identifiable people.

7. Orders, trial, payment (Stripe)

Checkout, free trial, payments, invoices, tax calculation and subscription management are handled by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Stripe processes email, name, company, billing address, VAT number, payment and transaction data. Card and account details are entered directly with Stripe and never reach our systems. Legal bases: Art. 6(1)(b) and (c) GDPR. Stripe acts as an independent controller for payment processing, fraud prevention (Stripe Radar) and its own regulatory duties (stripe.com/privacy) and as our processor for subscription management, invoicing and tax calculation. Stripe processes only data of our own customers, not content. Stripe may transfer data to Stripe, Inc., USA, which is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. Invoices and accounting records are kept for 8 years, books and annual accounts for 10 years, business letters for 6 years under German law.

8. Customer portal

Customers log in without a password via a one-time link valid for 15 minutes. As controller we process company name, contact email, portal user accounts, login times, plan, usage and settings (Art. 6(1)(b) GDPR, for contacts at legal entities Art. 6(1)(f)). If a customer adds users or names contacts, we receive their email address and role from that customer. Customer content (photos, brand profile, posts, approvals, connected accounts, metrics) is processed on the customer’s behalf. Monthly totals per customer (number of jobs and posts, costs) document performance and billing; after termination we keep them until the retention period of the related invoice expires, at most 8 years (Art. 6(1)(f) GDPR).

9. AI services

To generate and check images, videos and texts we send product photos, cut-outs, style references and settings (style, mood, brand profile, language), but no contact details, to: Google Ireland Limited, Dublin (Gemini API, processing also by Google LLC, USA; EU-US Data Privacy Framework and SCCs; requests are not stored for follow-up requests and not used for training, Google logs requests for abuse monitoring for a limited period); Anthropic, PBC, USA (contracting entity [per contract]; Claude API for captions, quality checks and content checks; SCCs 2021/914 modules 2 and 3 with a transfer risk assessment; no training; inputs and outputs retained for at most 30 days, longer in case of suspected policy violations); Features & Labels, Inc. (fal.ai), San Francisco, USA (AI video on the Pro plan, fallback image generation; SCCs; model providers behind fal.ai: [list and location]). Further AI providers are used only after this notice has been updated and customers have been informed. Content you enter yourself (e.g. your company name in the brand profile) may be included; contact details from your account are not. For customer content these providers act as our sub-processors. Transfers to the USA are based on the EU-US Data Privacy Framework adequacy decision where the recipient is certified, otherwise on standard contractual clauses (Art. 46(2)(c) GDPR); a copy is available on request.

10. Email delivery (Hostinger)

Login links, approval notices, confirmations and reports are sent from noreply@scenebright.com via Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, under a data processing agreement. Location of processing: [Hostinger mail data centre]. Sent messages are deleted from the mailbox after at most 14 days. Legal basis Art. 6(1)(b) GDPR, for marketing emails Art. 6(1)(a).

11. Connected social accounts

When a customer connects an account, the platform issues an access token that we store in our own publishing software (Postiz, self-hosted on our servers in Germany). We use it only to publish posts and read metrics, never to read messages or contacts. Accounts can be disconnected at any time. Platforms process published posts under their own responsibility.

12. Content checks and records

Before automatic publication, an AI model (Anthropic) checks image and text for clearly impermissible content. Flagged posts go to the customer for approval, and we keep a record with the result, reasoning, checked text and a copy of the image for 365 days after the check, also after the contract ends. If a check fails technically, we keep only time, job identifier and error. Customers permit this in the data processing agreement (§ 2(5)). We are the controller for this record (Art. 6(1)(f) GDPR: documenting misuse and defending claims, Art. 17(3)(e) GDPR). No final decision is made by a machine.

13. Internal operations messages (Telegram)

Error and check messages to the owner are sent via Telegram and contain only a random job identifier and the error reason, no names, contact details, content or links; Telegram cannot link them to customers (Art. 6(1)(f) GDPR).

14. Recipients and third countries

Recipients are the providers named above, the platforms connected by the customer, our tax adviser and authorities where required by law. Transfers outside the EEA occur only with Google, Anthropic, fal.ai and Stripe, with the safeguards described. Telegram messages contain no personal data.

15. Retention

Server logs 14 days; login links 15 minutes, sessions 12 hours; photos and media of completed jobs 90 days after completion; all other customer data, including portal user accounts, 30 to 37 days after termination (weekly deletion run); monthly totals until the retention period of the related invoice expires, at most 8 years; contact requests until resolved, business correspondence up to 6 years; content check records 365 days; backups 14 days; invoices and business records 6 to 10 years; sample post data as in section 6.

16. Your rights

Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), withdrawal of consent (Art. 7(3)). Contact kontakt@scenebright.com.

17. Your right to object (Art. 21 GDPR). Where we rely on Art. 6(1)(f) GDPR (in particular server logs, content check records, communication with contacts, monthly totals, suppression list), you may object at any time on grounds relating to your particular situation. We will then stop processing unless we demonstrate compelling legitimate grounds that override your interests or the processing serves legal claims. You may object to processing for direct marketing at any time without giving reasons; we will then no longer process your data for that purpose. Objections can be sent informally to kontakt@scenebright.com. Requests about a customer’s content are forwarded to that customer as controller.

17a. Complaints

You may lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular ours: Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany. UK residents may also contact the Information Commissioner’s Office (ICO). UK representative under Art. 27 UK GDPR: [name, address, email, if required].

18. No automated decisions

18. No automated decisions with legal or similarly significant effects (Art. 22 GDPR).

19. Required data

A contract requires email, billing details and a payment method; the sample post requires email and a photo. Consent to marketing emails is optional.

20. Changes

We update this notice when services, providers or the law change. The version published on the website applies.