Legal
Privacy Policy
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Faris Hamacher
Ignaz-Taschner-Strasse 2
85221 Dachau
Germany
Email: contact@kasdor.com
Phone: +49 152 0896 1014
2. General Information on Data Processing
We process personal data of users of our website only to the extent necessary to provide a functional website and our content and services. The processing of personal data takes place regularly only with the consent of the user or where the processing is permitted by law.
3. Legal Basis
Where we obtain consent for the processing of personal data, Art. 6 (1)(a) GDPR serves as the legal basis.
Where the processing of personal data is necessary for the performance of a contract to which you are a party, Art. 6 (1)(b) GDPR serves as the legal basis. This also applies to processing operations necessary to take steps prior to entering into a contract.
Where the processing of personal data is necessary to comply with a legal obligation to which we are subject, Art. 6 (1)(c) GDPR serves as the legal basis.
Where processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, and these interests are not overridden by your interests or fundamental rights, Art. 6 (1)(f) GDPR serves as the legal basis.
4. Data Collection When Visiting Our Website
When you visit our website for purely informational purposes, our hosting provider's server logs the personal data that your browser transmits as part of the HTTP request. This is technically necessary to display our website to you and to ensure stability and security. The following data is logged by our hosting provider (Vercel):
- IP address (used transiently to route the request; not retained by us)
- Date and time of the request
- Content of the request (specific page)
- HTTP status code
- Data volume transferred
- Referrer (the website from which the request comes)
- Browser type and version
- Operating system
The legal basis for this processing is Art. 6 (1)(f) GDPR. Our legitimate interest lies in ensuring the proper functioning, stability, and security of our website.
Retention is governed by our hosting provider's policy; we do not store these access logs in our own systems. We do not store IP addresses of waitlist signups (see Section 7).
5. Data Processors
We use the following processors to operate this website and the waitlist signup flow. Each acts on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Transfers to non-EU countries (in particular the United States) are based on the EU-U.S. Data Privacy Framework or, where applicable, on Standard Contractual Clauses pursuant to Art. 46 (2)(c) GDPR.
- Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) — hosting and content delivery for kasdor.com. Privacy policy: vercel.com/legal/privacy-policy.
- Supabase Inc. (970 Toa Payoh North, #07-04, Singapore 318992, with operations in the United States and the EU) — database hosting and Edge Function compute for the waitlist signup endpoint. Waitlist data is stored in the EU region (Frankfurt). Privacy policy: supabase.com/privacy.
- Slack Technologies LLC (500 Howard Street, San Francisco, CA 94105, USA) — internal team notifications for new waitlist signups. Privacy policy: slack.com/trust/privacy/privacy-policy.
- Resend Inc. (2261 Market Street #4677, San Francisco, CA 94114, USA) — transactional email delivery for internal waitlist notifications. Privacy policy: resend.com/legal/privacy-policy.
- Cal.com Inc. (548 Market St, San Francisco, CA 94104, USA) — booking widget embedded on the homepage for scheduling a demo call. Loads when you visit the site and may set first-party cookies on its iframe domain. Privacy policy: cal.com/privacy.
- Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — Google Fonts loaded on every page (Inter, Inter Tight, Fraunces, Space Grotesk, JetBrains Mono). When fonts are loaded, your IP is transmitted to Google. Privacy policy: policies.google.com/privacy. Legal basis: Art. 6 (1)(f) GDPR (typography for content presentation).
6. Cookies and Local Storage
This website itself does not set any cookies. We use only the following client-side storage mechanisms:
- Browser localStorage — to remember your selected language and visual palette across sessions. Stored locally in your browser only; never transmitted to us. Cleared when you clear your browser storage.
- Cal.com embed cookies — when the Cal.com booking widget loads (homepage), it may set first-party cookies on its embed iframe for session and analytics purposes. These are under Cal.com's control, not ours. See their cookie policy linked in Section 5.
The legal basis for both is Art. 6 (1)(f) GDPR. Our legitimate interest is providing the language/palette preference experience and offering a demo-booking option. The localStorage entries are technically necessary for the corresponding features and are not analytics or marketing cookies.
7. Waitlist Signup
When you submit our waitlist form at /signin, we collect and process the following personal data:
- Email address — required, used to contact you when early access is available
- Locale — your browser's language setting (e.g. "en", "de-DE")
- Referrer — the URL of the website that linked you to us (if any)
- User agent — your browser type and version, for debugging purposes
We do not store your IP address with your waitlist entry. Your IP address is used only transiently in our Edge Function to apply per-IP rate limiting (preventing automated submissions); it is never persisted to our database and never forwarded to our notification processors.
Purpose: waitlist management and notification when the Kasdor product becomes available to you.
Legal basis: Art. 6 (1)(a) GDPR (your consent, given by actively submitting the form) and, where applicable, Art. 6 (1)(b) GDPR (steps taken prior to entering into a contract).
Storage location: Supabase (EU region — Frankfurt). See Section 5 for processor details.
Storage duration: until you withdraw your consent or the Kasdor product becomes generally available and you decline to convert to a user account, whichever is sooner. You can request deletion of your waitlist entry at any time by emailing contact@kasdor.com.
Recipients: when you submit the form, your email and the fields above are forwarded to our Slack workspace (for internal team notification) and to our email-notification address via Resend. Both are listed in Section 5. The information is used solely to operate the waitlist and is not used for any other purpose.
8. Contact by Email
If you contact us by email, the personal data you provide (name, email address, content of your message) will be stored by us for the purpose of processing your enquiry and in case of follow-up questions. The legal basis for processing is Art. 6 (1)(f) GDPR (legitimate interest in responding to enquiries) and, where applicable, Art. 6 (1)(b) GDPR (steps taken prior to entering into a contract).
We delete the data arising in this connection once storage is no longer necessary, unless we are subject to legal retention obligations, in which case we restrict processing accordingly.
9. Recipients of Personal Data
Beyond the processors listed in Section 5, we disclose personal data to third parties only where we are legally obliged to do so, where you have consented, or where it is necessary for the performance of a contract.
10. Your Rights
You have the following rights regarding the personal data we process about you:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7 (3) GDPR)
To exercise any of these rights, please contact us using the contact details provided in section 1.
11. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority concerning our processing of your personal data. The supervisory authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
https://www.lda.bayern.de
12. Data Security
We use appropriate technical and organisational measures to protect your personal data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.
13. Changes to This Privacy Policy
We reserve the right to amend this privacy policy at any time to ensure it always complies with current legal requirements or to reflect changes to our services. The new privacy policy will then apply to your next visit.