GDPR Compliance
Your data protection rights and our commitment to privacy under the General Data Protection Regulation
Last updated: 8/14/2025
Your Rights Under GDPR
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
Right to Information
Be informed about how your personal data is collected and used.
Right of Access
Request access to your personal data and information about its processing.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data under certain circumstances.
Right to Restrict Processing
Request limitation of processing of your personal data.
Right to Data Portability
Receive your personal data in a structured, machine-readable format.
Data Processing Activities
Account Management
Purpose: User registration, authentication, and account management
Legal Basis: Contract performance and legitimate interests
Data Types: Name, email address, profile information
Service Provision
Purpose: Providing 3D storytelling platform services
Legal Basis: Contract performance
Data Types: Usage data, project files, collaboration data
Analytics and Improvement
Purpose: Service improvement and analytics
Legal Basis: Legitimate interests
Data Types: Usage statistics, performance metrics
Marketing Communications
Purpose: Newsletter and promotional communications
Legal Basis: Consent
Data Types: Email address, communication preferences
Data Protection Measures
Technical Safeguards
- • End-to-end encryption
- • Secure data transmission (TLS)
- • Regular security audits
- • Access controls and authentication
Organizational Measures
- • Staff training on data protection
- • Data processing agreements
- • Privacy by design principles
- • Regular compliance reviews
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- • Account data: Until account deletion or 3 years of inactivity
- • Project data: As long as the account is active
- • Analytics data: Aggregated and anonymized after 24 months
- • Marketing data: Until consent is withdrawn
- • Legal compliance: As required by applicable laws
International Data Transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure adequate protection through:
- • Standard Contractual Clauses (SCCs)
- • Adequacy decisions by the European Commission
- • Binding Corporate Rules where applicable
- • Additional safeguards as required by law
Exercising Your Rights
To exercise any of your GDPR rights, please contact us:
Email: privacy@kulimo.com
Data Protection Officer: dpo@kulimo.com
Response Time: Within 30 days of receipt
You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
Contact Information
Data Controller
KULIMO
Berlin, Marzahn 12679
Deutschland
EU Representative
KULIMO GmbH
Berlin, Marzahn 12679
Deutschland