Privacy Policy

Last Updated: July 3., 2025

1. Data Controller Information

Data controller: KWILA Technology KG, 1190 Vienna, Kahlenberger Str. 82/5

Contact Information:
Email: contact@kwila.art
Website: https://kwila.art

What Personal Data We Collect?

User Accounts

  • Profile information you provide (username, email address, profile details)
  • Account preferences and settings
  • Login credentials (encrypted passwords)

Technical Data

  • IP addresses
  • Browser information and device identifiers
  • Login timestamps and session data
  • Screen display preferences

Media Upload Data

  • Images and media files you upload
  • Metadata associated with uploaded files (we recommend removing location data before upload)

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Legitimate Interest: For providing our core service, security, technical functionality, and improving user experience
  • Consent: Where explicitly requested (e.g., for optional features)
  • Legal Obligation: When required by law or regulatory requirements

4. How We Use Your Data

Primary Uses

  • Enable user account functionality and authentication
  • Allow voting on displayed pictures
  • Provide website functionality and user experience
  • Maintain website security and prevent abuse

What We Do NOT Do

We do NOT use your data to:
– Send promotional materials or newsletters
– Contact you for marketing purposes
– Share information with business partners for their marketing
– Sell your data to third parties

5. Data Retention Periods

  • User profile data: Retained while your account is active, plus 30 days after account deletion
  • Login cookies: 2 days (standard), 2 weeks (with “Remember Me” option)
  • Technical cookies: Up to 1 year for screen options
  • IP addresses: 30 days for security and technical purposes
  • Technical logs: 12 months for system maintenance and security
  • Uploaded media: Retained until you delete it or close your account

6. Cookies and Technical Data

Technical Cookies

  • Session cookies: Temporary cookies to verify browser functionality
  • Authentication cookies: Login cookies (2 days standard, 2 weeks with “Remember Me”)
  • Preference cookies: Screen options and display settings (1 year)

IP Addresses

Your IP address may be:

  • Included in password reset emails for security verification
  • Logged for security and technical maintenance purposes
  • Retained for 30 days

7. Third-Party Content and Data Sharing

Embedded Content

Our posts may include embedded content (videos, images, articles) from third-party websites. When you interact with this content, those websites may:

  • Collect data about you according to their own privacy policies
  • Use their own cookies and tracking technologies
  • Monitor your interactions if you’re logged into their services

Data Sharing Limitations

We do not share your personal data with third parties except:

  • When required by law or valid requests from public authorities
  • To protect our rights, property, or safety, or that of our users
  • With your explicit consent

8. International Data Transfers

If we transfer your data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:

  • Adequacy decisions by the European Commission
  • Standard contractual clauses
  • Other legally recognized transfer mechanisms

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

Access and Portability

  • Right of access: Request a copy of your personal data
  • Right to data portability: Receive your data in a structured, machine-readable format

Correction and Deletion

  • Right to rectification: Correct inaccurate personal data
  • Right to erasure: Request deletion of your personal data (with some exceptions)

Control Over Processing

  • Right to restrict processing: Limit how we use your data
  • Right to object: Object to processing based on legitimate interests

How to Exercise Your Rights

  • Account data: Access, view, edit, or delete through your user profile
  • Data export: Contact us at contact@kwila.art to request your data
  • Account deletion: Contact us to permanently delete your account and associated data

Response Time: We will respond to your requests within 30 days.

Note: Some data may be retained for administrative, legal, or security purposes even after deletion requests.

10. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or significantly affects you.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

12. Children’s Privacy

Our service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware of such data collection, we will take immediate steps to remove the information.

Parents/Guardians: If you believe your child has provided us with personal data, please contact us immediately at contact@kwila.art.

13. Your Right to Complain

If you’re not satisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority.

For EU residents, you can find your local authority at: https://edpb.europa.eu/about-edpb/board/members_en

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the “Last Updated” date
  • Notify users of significant changes via email or website notice
  • Maintain previous versions for your reference

15. Contact Information

For privacy-related questions or requests:
Email: contact@kwila.art
Subject: “Privacy-related Request”

For exercising your GDPR rights:
Email: contact@kwila.art
Subject: “GDPR Request”