Privacy policy
Version 2026-10-11 · Effective 11 October 2026 · Applies to www.kalmanfat.com
Your project content remains yours. We do not sell your project data, photos or documents, publish them for advertising, or provide them to unrelated customers. Access is limited to your authorised collaborators and the people and service providers needed to operate, protect and support the service, subject to the exceptions explained below.
Acknowledging this notice confirms that you have received it. It does not give blanket consent to processing and does not waive your privacy rights.
1. Who is responsible and how to contact us
Kalman Control UG (haftungsbeschränkt) is the controller for the operation of Kalman FAT Suite, account administration, service communications and legal compliance.
Kastanienstr. 5, 47269 Duisburg, Germanyinfo@kalmancontrol.de
+49 174 9648159
Use this email for privacy questions, access or deletion requests, security concerns and requests for a copy of applicable transfer safeguards. Further company information is in our Imprint.
When a business or organisation determines why personal data is placed in its projects, that organisation normally acts as controller and we process that content on its instructions. Our Data Processing Agreement governs that relationship. The organisation is responsible for informing the people whose data it uploads and choosing its lawful basis. We remain controller for our own account, security and compliance processing.
2. Information we process and its purposes
| Information | Purpose | Legal basis for our controller processing |
|---|---|---|
| Network and request information, such as IP address, time, requested resource, browser and technical error details. | Deliver pages, detect abuse, secure the website and diagnose faults. | Article 6(1)(f) GDPR: our legitimate interests in a reliable and secure service, balanced against visitors’ rights. |
| Email address, account identifier, authentication information and account status. Optional profile details include name, company, job title, phone, country, city, website and notes. | Create and manage accounts, authenticate users, recover access and provide requested profile functions. | Article 6(1)(b) GDPR for an individual’s contract; Article 6(1)(f) for administering authorised users of an organisation’s contract. |
| Project names and customer details, procedures, test results, comments, names and contact details of participants, audit history, uploaded photos, documents and their file metadata. | Store and synchronise projects, manage authorised access, support testing, and generate the exports and reports you request. | Article 6(1)(b) where we provide the service directly to an individual controller. For organisational content we act as processor under Article 28; that controller determines the applicable basis. |
| Policy version, account identifier, acceptance and acknowledgment status, and time of acceptance. | Record the agreement, apply access requirements and establish which documents were provided. | Article 6(1)(b) and Article 6(1)(f): contract administration and evidence for resolving disputes. |
| Support messages, contact details and information you choose to send us. | Answer requests and resolve service or privacy issues. | Article 6(1)(b) for contractual enquiries; Article 6(1)(f) for other correspondence and service support. |
| Records required for legal obligations, lawful requests and the establishment or defence of legal claims. | Comply with law and protect legal rights. | Article 6(1)(c) where a legal duty applies; Article 6(1)(f) for legitimate legal claims. |
Passwords are handled by the authentication provider; we do not require you to send us your password in correspondence. Account confirmation and password recovery emails are service messages. We do not use uploaded project content to train AI models or for behavioural advertising.
Data comes from you, people you authorise to collaborate, your organisation and technical requests made by your browser. Photos and files can contain personal information or embedded metadata; review and minimise them before uploading. Do not upload passwords, access keys, special-category personal data under Article 9 GDPR, criminal-offence data under Article 10, or highly sensitive material requiring additional safeguards unless we have separately agreed the necessary conditions.
3. Browser storage, offline copies and cookies
The application uses necessary browser storage for your sign-in session, account recovery, requested project work, navigation preferences and offline recovery. This includes local storage, session storage and the service worker’s application cache. The authentication session can remain until you sign out or it expires. Local project drafts and preferences may remain until you delete them or clear this website’s storage.
Offline drafts can contain the complete project, photos and document contents on your device. They are not an independent cloud backup and are not protected by application-level end-to-end encryption. Use a trusted device, protect your operating-system account, and remove local copies when no longer needed. Signing out prevents normal account access but does not necessarily erase all locally stored project copies. Before clearing site data, export and verify any unsynchronised work.
Storage or access that is strictly necessary to provide a service you expressly request is based on section 25(2) TDDDG. Associated personal-data processing uses the purposes and GDPR bases described above. We do not operate optional analytics, advertising cookies, advertising pixels or cross-site profiling in this version. If optional tracking is introduced, it will require a separate choice before it runs; acceptance of the Terms will not authorise it.
4. Confidentiality, collaboration and recipients
- Your project collaborators: people given access by the project owner or authorised managers can see content within their assigned permissions. Invitations, role changes and reports can disclose data to those selected people. Review permissions regularly. We cannot retrieve copies they have legitimately exported outside the service.
- Our authorised personnel: access is limited to legitimate operation, security, support and legal needs. Platform administration is a privileged role and is not the same as ordinary customer access.
- Service providers: hosting, authentication, database operation, transactional email and technical support require providers to process relevant information. They are not unrelated recipients for their own advertising. Processing agreements and appropriate confidentiality and security obligations apply where required.
- Legal recipients: we may disclose information when a binding legal requirement applies, to competent authorities, or to professional advisers where necessary for legal claims. We limit disclosure to the information required and notify affected customers where lawful and appropriate.
We do not promise that no provider ever processes your data. Providing the service requires this processing. Project content is not made publicly accessible by default. You control the reports and files you export or share outside the service and must protect those copies.
5. Providers, locations and international transfers
Supabase provides authentication and the project database. The configured project database region is Ireland (EU). Supabase’s contracting entity and some provider support or subprocessor operations may be outside the European Economic Area. EU database hosting does not mean that all provider processing occurs only in the EU. See Supabase’s Data Processing Addendum and subprocessor list.
Vercel provides website delivery and application hosting. The application deployment is configured in US East (Northern Virginia); network delivery and provider operations can also use other locations. It processes network and request information and information necessary for server-side application functions. See Vercel’s Data Processing Addendum and subprocessor list.
Account verification and password recovery messages are sent through the authentication service’s configured transactional email delivery. Your email address and message delivery information are processed for this purpose. Contact us for the current provider and the processing details applicable to your account.
Where personal data is transferred to a country without a relevant EU adequacy decision, appropriate safeguards must apply, normally the European Commission’s Standard Contractual Clauses with any supplementary measures required by the transfer assessment. A provider’s location alone does not establish an adequacy decision. You can request information about the mechanism applicable to a transfer and a copy of the relevant safeguards, with confidential commercial or security details redacted where necessary.
6. How long information is kept
- Accounts and profiles: for the active account and then only as needed to complete closure, comply with law or resolve outstanding claims. You may request account closure by email.
- Project content: while the authorised customer stores it in the service. Owners and other permitted roles can remove content using the available controls; contact us where assistance is needed. Removing your account does not automatically remove projects belonging to another organisation or all lawful records of your contributions.
- Audit and agreement records: for the relevant project or contractual relationship, and afterwards for applicable limitation or legal retention periods where needed. We restrict retained records to the relevant purpose rather than keeping all project content indefinitely.
- Support and technical records: until the request, diagnosis or security need is resolved, then only where a continuing legal or security reason justifies retention. Provider logs and backups follow the applicable provider service configuration and retention cycle.
- Historical activity records: earlier versions recorded page views, activity events and presence, potentially including account email, identifiers, paths, project identifiers, timestamps and browser information. Collection is disabled in this version. Existing records are reviewed for deletion or anonymisation when no longer necessary for a specific security, support or legal purpose; they are not an ongoing permission to profile you.
- Device and exported copies: these remain until you, your organisation or the recipient removes them. Cloud deletion does not erase files you downloaded, collaborator exports or browser copies on another device.
Deletion from the active system does not necessarily cause immediate deletion from isolated provider backups. Residual copies are restricted from ordinary use until overwritten or erased under the applicable backup cycle, unless legal retention is required. If a backup is restored, relevant deletion instructions must be reapplied. We can provide the retention information applicable to a particular request.
You should review stored data regularly, export and archive the records you must keep in a secure location, and delete content you no longer need. Your backup and data-minimisation duties do not remove our own GDPR obligations.
7. Security and its limits
We use HTTPS, authentication and project-based access controls, and take appropriate technical and organisational measures for the risks involved. Ordinary customers do not obtain access to other customers’ private projects simply by holding an account. Security also depends on your credentials, authorised collaborators, device protection and the handling of exports. No online system can guarantee absolute security or uninterrupted availability. This statement does not exclude our mandatory legal responsibilities.
Report suspected unauthorised access promptly to info@kalmancontrol.de. Do not attach additional sensitive evidence to an ordinary email unless necessary; ask for an appropriate transfer method.
8. Your rights and choices
Subject to the applicable GDPR conditions, you can request access and a copy of your personal data, rectification, erasure, restriction of processing and portability. Where processing depends on consent, you may withdraw that consent at any time without affecting earlier lawful processing. No blanket processing consent is required by this notice.
You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We must stop unless the legal conditions for continuing apply. You can object to direct marketing at any time; we do not conduct behavioural advertising through the service.
Send requests to our contact email. We may ask for proportionate verification to protect your data and will normally respond within one month; lawful extensions will be explained. For project data controlled by your organisation, contact that organisation first; we assist it and forward relevant requests rather than independently overriding its lawful instructions.
You can complain to a supervisory authority, particularly in the EU country where you live, work or where a suspected infringement occurred. Our local authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany; poststelle@ldi.nrw.de. You do not have to contact us first.
9. Required information and automated decisions
An email address, authentication information and the recorded contractual acceptance are necessary to operate an account; without them we cannot provide access. Optional profile fields and project uploads are your choice, although some requested functions need the data you enter. We do not use solely automated decisions producing legal or similarly significant effects, and we do not build advertising profiles from project content.
10. Updates
We update this notice when the service or applicable processing changes. The version and effective date appear above. Material changes will be brought to your attention. Acknowledging an updated notice confirms receipt; any processing that legally requires consent will still require a separate, freely given choice.