Privacy Policy

Last updated: March 2026

This is a courtesy translation of the German original. In the event of any discrepancy between the German and English versions, the German version shall prevail. This English translation is provided voluntarily and does not create any legal obligations beyond those established by the German text.

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website and use our services. Personal data is any data that can be used to personally identify you.

Data Collection on This Website

Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice of this website.

How do we collect your data?
Your data is collected in part by you providing it to us. This may include, for example, data you enter during registration or transmit when using our API services.

Other data is collected automatically or with your consent when you visit the website by our IT systems. This is primarily technical data (e.g., internet browser, operating system, or time of page access).

2. Hosting and Infrastructure

We use the following service providers for hosting and operating our services. All data processing takes place on servers within the European Union (location: Frankfurt am Main, Germany), unless otherwise stated.

Amazon Web Services (AWS)

Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy
L-1855 Luxembourg

We use AWS Amplify for hosting our web application, AWS Lambda for running our API services, and AWS ECS (Elastic Container Service) for our API gateway service. Data processing takes place in the AWS region eu-central-1 (Frankfurt).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and performant provision of our services).

Privacy policy: https://aws.amazon.com/de/privacy/

Neon (Database)

Neon Inc.
548 Market St, PMB 68596
San Francisco, CA 94104, USA

We use Neon as a managed PostgreSQL database service. Data processing takes place on servers in the EU (Frankfurt, Germany). Neon has committed to the EU Standard Contractual Clauses.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest).

Privacy policy: https://neon.tech/privacy

Upstash (Cache)

Upstash, Inc.
2261 Market Street #4068
San Francisco, CA 94114, USA

We use Upstash as a managed Redis service for caching and rate limiting. Data processing takes place on servers in the EU (Frankfurt, Germany). Upstash has committed to the EU Standard Contractual Clauses.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in performant data processing).

Privacy policy: https://upstash.com/privacy

3. Payment Processing

Stripe (Payment Service Provider / Merchant of Record)

Stripe Payments Europe, Ltd.
1 Grand Canal Street Lower
Dublin 2, Ireland

The purchase of credits is processed through Stripe acting as the Merchant of Record. Stripe acts as the seller towards the customer and assumes responsibility for calculating, collecting, and remitting all applicable taxes (VAT, GST, Sales Tax) worldwide. On the customer's bank statement, the payee will appear as "LINK.COM*" or "Stripe" — not dbpg.

When using the checkout process, the following data is transmitted to Stripe:

  • Email address (for assignment and invoicing)
  • IP address (for fraud prevention and tax determination)
  • Payment data (credit card, SEPA, etc. — processed exclusively by Stripe and not shared with us)

We do not store any payment data ourselves. Our database only stores a pseudonymous Stripe customer ID to associate subsequent purchases and provide access to the invoice portal.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Privacy policy: https://stripe.com/privacy

4. Third-Party and External Services

As part of our API services, requests are forwarded to external providers depending on the service used. The data transmitted depends on the respective service and your request. We do not permanently store the content of requests, only metadata for billing purposes.

Google

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland

When using image processing services (e.g., Marameo), image data is transmitted to Google and processed using AI. Generated images contain digital watermarks (SynthID). Google processes data both in the EU and the USA. EU Standard Contractual Clauses apply for transfers to the USA.

Privacy policy: https://policies.google.com/privacy

Legal basis: Art. 6(1)(b) GDPR (performance of contract). The use of services occurs at your explicit request by calling the corresponding API endpoints.

5. General Information and Mandatory Disclosures

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the applicable data protection regulations and this privacy policy.

Notice Regarding the Responsible Party

The responsible party for data processing on this website is:

dbpg deutsche Bühnenproduktionsgesellschaft mbH & Co. KG
Turnerstraße 44
81827 München
Email: datenschutz@dbpg.io

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You may revoke any consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority. The competent supervisory authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Email: poststelle@lda.bayern.de

6. Data Collection on This Website

Cookies

Our website uses so-called "cookies." Cookies are small data packets and do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device.

We only use technically necessary cookies for authentication and session management. These cookies are strictly necessary for the operation of the website.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and Art. 6(1)(b) GDPR (performance of contract), insofar as the cookies are necessary for contract processing.

Server Log Files

The provider of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address (anonymized)

This data is not merged with other data sources. Collection is based on Art. 6(1)(f) GDPR.

Registration on This Website

You can register on this website to use our API services. The data entered is used solely for the purpose of using the respective offer or service.

During registration, we collect:

  • Email address (required)
  • Password (stored encrypted)
  • Name (optional)
  • Company name (optional)

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

7. API Usage Data

When using our API, we collect the following data for billing, quality assurance, and abuse prevention:

  • API key (stored as hash only)
  • Time of request
  • Endpoint and service called
  • HTTP method
  • Credits consumed
  • Response time (latency)
  • HTTP status code
  • Error messages (without payload data)

Important: The content of your API requests (e.g., image data for image processing services or location data for weather services) is not permanently stored by us. It is only forwarded to the respective third-party provider for processing.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in abuse prevention and quality assurance).

8. Your Rights

You have the following rights with regard to your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

You can delete your account at any time in the dashboard. In doing so, all your personal data will be deleted, unless statutory retention obligations apply.

To exercise your rights, please contact: datenschutz@dbpg.io

9. Data Security

This site uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://" and by the lock icon in your browser bar.

We employ the following security measures:

  • Passwords are stored encrypted using modern hash algorithms (bcrypt)
  • API keys are stored in hashed form only
  • All data transmissions are encrypted (TLS 1.3)
  • Regular security audits of our systems
  • Access restrictions and logging at infrastructure level

10. Data Retention

Personal data is only stored for as long as is necessary for the purposes for which it is processed:

  • Account data: Until account deletion
  • API usage data: 90 days (for statistics and billing)
  • Transaction data: 10 years (statutory retention obligation under HGB/AO)
  • Server logs: 7 days

11. Data Transfer to Third Countries

Insofar as we process data in a third country (outside the European Union or the European Economic Area) or this occurs in the context of using third-party services, this only takes place:

  • to fulfill our (pre-)contractual obligations
  • on the basis of your consent
  • on the basis of a legal obligation
  • on the basis of our legitimate interests

The transfer takes place in compliance with legal requirements, in particular on the basis of EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or an adequacy decision by the EU Commission.

12. Changes to This Privacy Policy

We reserve the right to amend this privacy policy to ensure it always complies with current legal requirements or to implement changes to our services in the privacy policy. The new privacy policy will then apply to your next visit.