Legal
Privacy Policy
Privacy Policy for GALLERYDOCK Last updated: June 29, 2026
This English translation is provided for convenience. If it differs from the German original, the German version controls. View the legally controlling German original
1. General information
The protection of personal data is important to us. In this Privacy Policy we inform you about which personal data is processed when using GALLERYDOCK, for what purposes this happens and what rights those affected have. GALLERYDOCK is a web-based software solution for photographers, filmmakers, studios, agencies and other entrepreneurs to create, manage, store, present and deliver media galleries. The offer is aimed exclusively at entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB) and not at consumers.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is: GALLERYDOCK Edmond Rätzel Karmarschstraße 16 30159 Hannover Germany Email: info@gallerydock.de VAT identification number: DE 306 256 380
3. Data protection officer
A data protection officer has not currently been named. Data protection inquiries can be directed to info@gallerydock.com.
4. Terms
Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, email address, IP address, account data, payment data, image data, video data, customer data and usage data. Processing means any handling of personal data, for example collection, storage, transmission, modification, provision, deletion or evaluation. Customer means the corporate user of GALLERYDOCK, in particular photographers, filmmakers, studios, agencies or companies. End customer means persons to whom a customer grants access to a gallery, files, downloads or other content.
5. Principles of processing
We only process personal data to the extent necessary to provide GALLERYDOCK, to fulfill the contract, for communication, for security, for payment processing, to fulfill legal obligations or based on legitimate interests. The processing is carried out in particular on the basis of: Art. 6 Paragraph 1 Letter b GDPR for the implementation of pre-contractual measures and for the fulfillment of the contract Art. 6 Paragraph 1 Letter c GDPR to fulfill legal obligations Art. 6 Paragraph 1 Letter f GDPR to protect legitimate interests Art. 6 Para. 1 lit. a GDPR, if consent is required
6. Use of the website and server log files
When you access our website or platform, technically necessary data is processed. These can include: IP address Date and time of access page or file accessed Browser type and browser version Operating system Referrer URL amount of data transferred Status codes technical safety information This data is processed to provide the website and platform, ensure security, analyze errors, prevent misuse and ensure the stability of the systems. The legal basis is Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in the safe, stable and functional operation of GALLERYDOCK.
7. Registration and Account
When a customer creates an account or uses GALLERYDOCK, we process in particular: name Email address Company name Billing information Login and account details Tariff information Storage and Usage Data technical usage data Support and communication data This data is processed to provide the account, fulfill the contract, manage plans, create invoices, provide support and operate the platform securely. The legal basis is Article 6 Paragraph 1 Letter b GDPR. If there are statutory retention obligations, the legal basis is Article 6 (1) (c) GDPR.
8. Login, session and technically necessary cookies
GALLERYDOCK uses technically necessary cookies or comparable technologies to provide login, session, security, language settings and platform functions. These cookies are necessary to enable users to stay logged in, use protected areas and manage galleries securely. The legal basis is Art. 6 Para. 1 lit. b GDPR, insofar as the cookies are necessary for the use of the platform, as well as Art. 6 Para. 1 lit. f GDPR for security and protective measures.
9. No tracking and marketing services in version 1
In the production version of GALLERYDOCK described here, we do not use marketing tracking services such as Google Analytics, Meta/Facebook Pixel, TikTok Pixel or comparable advertising tracking services. This version does not use third-party advertising trackers to track users for marketing purposes. If we later introduce analytics, tracking, remarketing or marketing services, we will update this Privacy Policy and obtain prior consent where required.
10. Contact and support
If you contact us via email, support function or other means, we process the data you provide, in particular: name Email address Company Message content technical information about the request Attachments, if submitted The processing takes place to process the request, for communication, for documentation and to improve our support. The legal basis is Article 6 (1) (b) GDPR, as long as the request is related to a contract or the initiation of a contract. In other cases, the legal basis is Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in processing and documenting inquiries.
11. Uploads, Galleries, Images, Videos and Customer Data
Customers can use GALLERYDOCK to upload, store, process, present images, videos, texts, files, logos, watermarks, customer data and other content and make them accessible to end customers. Personal data may be processed, in particular: Pictures and videos of people Names of end customers Email addresses of end customers Gallery and access links Selection and download information Comments, tags or favorites technical access data File names and metadata, if available The customer is generally responsible for the content, galleries and end customer data that he processes via GALLERYDOCK. GALLERYDOCK usually processes this data as a processor on behalf of the customer. The details of order processing are regulated in a separate Data Processing Agreement. The customer is responsible for properly informing his end customers, depicted persons and other data subjects about the data processing and for obtaining the necessary legal bases, consents and rights.
12. Public or Shared Galleries
When an end customer or visitor accesses a gallery shared by the customer, personal data may be processed, in particular: IP address Date and time of access Browser and device information Gallery accessed Download or selection actions Use of a password or access code Comments, favorites or selection marks, if enabled This processing is required to provide the gallery, control access, maintain security, display media, enable downloads and provide the gallery features requested by the customer. Where GALLERYDOCK processes this data on the customer's behalf, the processing is governed by the Data Processing Agreement. Where GALLERYDOCK processes data for security, error analysis or technical delivery, the legal basis is Article 6(1)(f) GDPR.
13. Storage and processing of media
Uploaded images, videos and other files are technically stored and processed to provide the functions of GALLERYDOCK. These include in particular: Storage of original files Creation of preview images Creation of web variants Creation of thumbnails Creation of video posters, if technically required Provision to authorized users and end customers Security and access controls Error analysis and technical processing
14. Payment Processing
For paid plans, we process payment and billing data. These can include: name Company Billing address Email address VAT identification number Tariff Payment status Billing information Transaction data Payment method We use Stripe for payment processing. Payment data is processed to process payments, create invoices, fulfill tax obligations, manage subscriptions and deal with payment defaults. When using the shop function, order, invoice, payment status and provision data are also processed. This may include, but is not limited to, name, email address, billing information, payment status, purchased content, order references and download delivery information. This data is processed to process orders, enable payments via the payment service provider, provide invoices or proof of payment, deliver digital content after successful payment, process support cases and fulfill legal proof or retention obligations. The legal basis is Article 6 Paragraph 1 Letter b GDPR for contract fulfillment and Article 6 Paragraph 1 Letter c GDPR for statutory retention and tax obligations.
15. Service providers and sub-processors used
To provide GALLERYDOCK, we use technical service providers and infrastructure providers. These are used to the extent necessary for hosting, database operation, storage of media, payment processing, security, error analysis, provision of the platform or contract fulfillment. For the salable version 1 of GALLERYDOCK we use the following services in particular: Vercel for hosting, deployment and execution of the application Neon for PostgreSQL database Cloudflare R2 for media and file storage Stripe for payment processing, invoices and subscription management GitHub for technical development and version management To the extent that these providers process personal data on our behalf, they are used as processors or sub-processors. If providers process personal data for their own legal or regulatory purposes, they may be independently responsible.
16. Vercel
We use Vercel for hosting, provisioning, deployment and execution of the application. The following data in particular can be processed: IP address Date and time of access Pages viewed and API requests Browser and device information technical log data Error and performance data Session and security information transmitted request content, insofar as this is technically necessary to process the respective request Vercel is used to provide GALLERYDOCK online, to technically execute the platform, to make protected areas accessible, to analyze errors, to detect attacks and to ensure the stability and security of the application. The legal basis is Article 6 (1) (b) GDPR, insofar as processing is necessary to fulfill the contract. The legal basis for security, error analysis, stability and misuse prevention is Article 6 (1) (f) GDPR. Our legitimate interest lies in the safe, stable and functional operation of GALLERYDOCK.
17. Neon
We use Neon for the GALLERYDOCK database. In particular, the following data can be stored and processed in the database: Account details Names and email addresses Company and billing information Roles and permissions Gallery data Media metadata Upload and processing status Storage and plan information Payment and subscription status technical protocol and status data End customer data, insofar as it is processed by customers via gallery functions Neon is used to provide GALLERYDOCK's core functionality, including securely storing and retrieving accounts, galleries, media allocations, upload statuses, permissions, rates and platform data. The legal basis is Article 6 (1) (b) GDPR, insofar as processing is necessary to fulfill the contract. If there are legal retention or proof obligations, the legal basis is Article 6 (1) (c) GDPR. The legal basis for security, integrity and abuse prevention is Art. 6 Para. 1 lit. f GDPR.
18. Cloudflare R2
We use Cloudflare R2 to store uploaded media and files. In particular, the following data can be stored and processed: Images videos other uploaded files Thumbnails Web variants Thumbnails Video posters, if technically possible File and media metadata Storage information technical access information Security and log data Cloudflare R2 is used to store and technically provide the media and files uploaded by the customer. The saved original files and internal storage paths are not public. Media is accessed via the authorization, gallery and delivery mechanisms provided by GALLERYDOCK. GALLERYDOCK does not use uploaded images, videos and files for its own advertising purposes, AI training, resale or other purposes outside of the fulfillment of the contract, unless the customer has expressly consented to this separately. The legal basis is Article 6 (1) (b) GDPR, insofar as processing is necessary to fulfill the contract. The legal basis for security, technical provision, error analysis and misuse prevention is Article 6 (1) (f) GDPR.
19. Stripe
We use Stripe for payment processing, invoicing, subscription management and payment status. The following data in particular can be processed: name Company Email address Billing address VAT identification number Tariff Payment status Billing information Transaction data Payment method Order references and purchased digital content when using the shop function Download delivery data and payment status data for digital purchases technical payment and security information Stripe processes payment data to process payments, manage subscriptions, provide invoices, handle payment defaults, prevent fraud, and comply with legal obligations. For store sales, Stripe may also process payment, invoice, order and payout data associated with the customer's connected Stripe account. Stripe may process personal data partly as a processor and partly as an independent controller, in particular to the extent that Stripe fulfills its own legal, regulatory, security or compliance obligations. The legal basis is Article 6 Paragraph 1 Letter b GDPR for contract fulfillment and payment processing. The legal basis for statutory retention, tax and proof obligations is Article 6 (1) (c) GDPR. The legal basis for fraud prevention, security and receivables management is Art. 6 Para. 1 lit. f GDPR.
20. GitHub and technical development
We use GitHub for development, version management and management of the source code. GitHub is not intended to store customer content, end customer data, images, videos, galleries, payment data or other productive personal data. Personal data from customers or end customers should not be uploaded to the source code, issues, commits, logs or other development areas. If, as part of error analysis or support, it is exceptionally necessary to process personal data in development processes, this will only be done to the extent that this is necessary for error correction, security, documentation or contract fulfillment. The legal basis is Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in the safe technical development, maintenance and troubleshooting of GALLERYDOCK.
21. Email Communications
When communicating via email, personal data is processed, in particular email address, name, content of the message, time of communication and technical shipping data. Email communications may contain security risks. Complete protection against third-party access cannot be guaranteed for electronic communication. A suitable secure transmission path should be used for particularly confidential information.
22. Abuse Reports and Legal Reports
Illegal content, data protection violations, security risks, rights violations or other misuse can be reported via support@gallerydock.com. For such reports, we process the data of the reporting person, the reported content, technical information, communication data and all information required for verification. Processing is carried out for auditing, documentation, defense of claims, fulfillment of legal obligations and to protect the platform, customers, end customers and third parties. The legal basis is Article 6 Paragraph 1 Letter c GDPR, insofar as legal obligations exist, and Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in checking and processing reports as well as protecting against legal violations and misuse.
23. Recipients of personal data
Personal data may be transmitted to the following categories of recipients: Hosting and infrastructure provider Cloud storage provider Database provider Payment service provider Email and support providers IT service provider Tax advisor and accounting Legal advisor Authorities, courts or other bodies, to the extent required by law Customers or end customers, to the extent this is provided for by gallery or platform functions Data will only be passed on to the extent that this is necessary for contract fulfillment, technical provision, payment processing, security, fulfillment of legal obligations or to protect legitimate interests.
24. Third Country Transfers
Some service providers may be based or process data outside the European Union or European Economic Area. If personal data is transferred to third countries, this will only be done on the basis of appropriate guarantees, in particular adequacy decisions, EU standard contractual clauses, Data Privacy Framework certifications or other mechanisms provided for by law.
25. Storage period
We only store personal data for as long as necessary for the respective purposes. Account and contract data are stored for the duration of the contract. Invoice and accounting data is stored in accordance with legal retention requirements. Support requests are stored for as long as necessary for processing and documentation. Uploaded content, galleries and media data are generally stored for the duration of the customer contract or until deleted by the customer, provided there are no conflicting legal obligations, security reasons or legitimate interests. After the end of the contract, content, galleries, uploads, variants, preview images and other account data can be deleted after a reasonable period of time, provided that there are no legal retention obligations or legitimate interests to the contrary.
26. Data Security
We take technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration, disclosure or destruction. This includes, in particular, access restrictions, role and authorization concepts, encrypted transmission, private storage of media, server-side access controls and technical protective measures. However, complete protection against all risks cannot be guaranteed.
27. No archiving or backup solution
GALLERYDOCK is not an archiving, long-term preservation or sole backup solution for original files, images, videos or other content. Customers are responsible for maintaining their own backup copies of their original files and business-critical data outside of GALLERYDOCK. Uploading to GALLERYDOCK does not replace the customer's own data backup.
28. Data Subject Rights
Affected persons have the following rights in accordance with the legal requirements: Right to information Right to rectification Right to deletion Right to restriction of processing Right to data portability Right to object Right to revoke consent given Right to complain to a data protection supervisory authority Inquiries can be directed to info@gallerydock.de. If a request relates to data that a customer processes as a controller via GALLERYDOCK, we may, if necessary, forward the request to the respective customer or support it within the framework of the Data Processing Agreement.
29. Right to object
To the extent that we process personal data on the basis of Article 6 Paragraph 1 Letter f of the GDPR, the processing can be objected to for reasons arising from the particular situation of the data subject. In the event of a justified objection, we will no longer process the data concerned unless we can demonstrate compelling legitimate reasons for the processing or the processing serves to assert, exercise or defend legal claims.
30. Revocation of consent
If processing is based on consent, this consent can be revoked at any time with future effect. The lawfulness of processing until revocation remains unaffected.
31. Right to lodge a complaint with a supervisory authority
Data subjects have the right to complain to a data protection supervisory authority if they believe that the processing of their personal data violates data protection law. In particular, the data protection supervisory authority of your own place of residence, place of work or the place of the suspected violation may be responsible.
32. No automated decision making
Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place in version 1 of GALLERYDOCK.
33. Changes to this Privacy Policy
We can adapt this Privacy Policy if the legal situation, the platform, the service providers used, functions or data processing change. The current version is available on the GALLERYDOCK website. As of: June 29, 2026