Controller

The controller responsible for data processing on this website is:

Profile Bakery
E-Mail: support@profilebakery.com
Website: https://www.profilebakery.com

General Information on Data Processing

We take the protection of your personal data very seriously. Personal data is treated confidentially and in accordance with statutory data protection regulations as well as this privacy policy.

The use of our website is generally possible without providing personal data. If personal data is collected on our pages (e.g. name, e-mail address, photo uploads), this is always done on a voluntary basis.

Purposes of Processing

We process personal data for the following purposes:

  • Provision and optimization of our services (AI photo creation)

  • Processing of orders and payments

  • Customer communication (e.g. support)

  • Analysis of user behavior (e.g. to improve the service)

  • Marketing purposes (e.g. e-mail newsletters, retargeting)

Legal Bases

Data processing is carried out on the basis of the following legal grounds:

  • Art. 6 para. 1 lit. a GDPR – Consent

  • Art. 6 para. 1 lit. b GDPR – Performance of a contract

  • Art. 6 para. 1 lit. f GDPR – Legitimate interest

  • Art. 6 para. 1 lit. c GDPR – Legal obligation

Data Collected

We collect the following data in particular:

  • Contact details (name, e-mail)

  • Image data (e.g. for the creation of AI images)

  • Payment data (only pseudonymized when using payment service providers)

  • IP address, browser type, device data

  • Usage behavior (e.g. click paths)

Third-Party Providers and Processors

We use carefully selected service providers with whom we have concluded data processing agreements in accordance with Art. 28 GDPR. These include, among others:

  • Payment service providers (e.g. Stripe, PayPal)

  • Cloud hosting (e.g. AWS, Railway)

  • Analytics tools (e.g. Google Analytics)

These providers process your data only on our instructions and not for their own purposes.

Storage and Deletion

Data will only be stored for as long as is necessary for the respective purposes. Thereafter, it will be deleted or anonymized, unless statutory retention obligations prevent this.

Your Rights

You have the right at any time to:

  • Information about the data stored (Art. 15 GDPR)

  • Rectification of inaccurate data (Art. 16 GDPR)

  • Deletion of your data (Art. 17 GDPR)

  • Restriction of processing (Art. 18 GDPR)

  • Data portability (Art. 20 GDPR)

  • Object to processing (Art. 21 GDPR)

  • Withdraw consent granted (Art. 7 para. 3 GDPR)

  • Lodge a complaint with a data protection authority

Data Security

We implement technical and organizational measures (TOM) to protect your data against loss, destruction, access, alteration, or distribution by unauthorized persons.

Cookies and Tracking

We use cookies and similar technologies. You can object to their use or withdraw your consent. Details can be found in our [cookie banner].

Changes to this Privacy Policy

This privacy policy may be updated at any time, for example due to new legal requirements or changes to our services.