|
RReklaio← Home
Privacy

Privacy Policy

Last updated: 2026-08-08-store-v1

1. Controller

KamilunavoInhaber: Piotr KaminskiOtto-Braun-Straße 1440595 DüsseldorfDeutschlandEmail: reklaio@kamilunavo.com

2. Purposes of processing

Reklaio processes personal data to provide user accounts, case files, documents, deadlines, tasks, letters, communication, support, subscriptions, withdrawals, security, backups and optional AI features.

No solely automated decision with legal or similarly significant effects is made. AI results are not applied automatically and letters are not sent without user approval.

3. Website and security logs

When you access the service, we may process the IP address, time, requested address, HTTP status and browser or device information. Limited counters and pseudonymous keys protect sign-in, registration, checkout, contact and withdrawal functions against automated abuse.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are security, stability, error analysis and abuse prevention.

4. Hosting and backups

The application, database and private file storage are operated on a managed system at Hetzner Online GmbH in Deutschland. Database and uploaded files are backed up automatically to non-public storage.

Backups are used to recover from technical failures, loss or security incidents and are deleted after a defined retention period. Deleted data may remain in protected backups until the backup cycle expires. The legal bases are Article 6(1)(b) and (f) GDPR.

5. User account and mobile app

We process your email address, optional display name, password hash, verification and session data, onboarding status, accepted legal versions, plan, subscription status, roles, quotas and any suspension status. Plain-text passwords are never stored.

The mobile app stores a random session token in protected operating-system storage. Biometric features are checked only by the operating system and are not sent to Reklaio. Local deadline notifications are scheduled on the device.

6. Case files, documents and communication

Users can store case details, timeline entries, tasks, provider replies, deadlines, letters, email delivery data and documents. These may contain personal data relating to communication partners. Processing is based on Article 6(1)(b) GDPR. Users may upload only data they are legally entitled to use for their own case.

7. Email delivery

For verification, password recovery, deadline reminders, contract and withdrawal confirmations, and user-initiated letters, we process sender, recipient, subject, delivery and technical delivery data. Email is currently delivered through one.com. The legal basis depends on the message purpose and may be Article 6(1)(b), (c) or (f) GDPR.

8. Contact form and support

We process name, email, subject, message, time, optional account link and a pseudonymous IP key. Processing is based on Article 6(1)(b) GDPR for contract-related requests and otherwise Article 6(1)(f) GDPR.

9. Reklaio Pro on the web and Stripe

Website subscriptions use Stripe. Reklaio sends the account email, internal user and order identifier, selected price, contract metadata and technical checkout data. Stripe processes payment, invoice, tax and transaction data.

Reklaio does not store complete card details. The recipients include Stripe Payments Europe, Limited, Dublin, its affiliates and processors. The legal bases are Article 6(1)(b) and (c) GDPR.

10. Mobile subscriptions through Apple, Google and RevenueCat

iOS subscriptions use Apple In-App Purchase and Android subscriptions use Google Play Billing. Apple or Google process store-account, payment, tax, invoice, device and transaction data under their own policies. Reklaio receives no complete card or bank data.

RevenueCat is used to manage subscription entitlements across platforms. It receives a random internal Reklaio user ID, product and store details, purchase, renewal, cancellation and expiry status, environment and technical event identifiers. The email address is not used as the RevenueCat user ID.

11. Withdrawals and refunds

For online withdrawals, we store name, email, optional contract reference, declaration and processing times, and optionally link the request to an account. Mobile-store refunds are generally requested and handled through Apple or Google. The legal bases are Article 6(1)(b) and (c) GDPR.

12. Optional AI features

AI document analysis and AI letters are optional Pro features. After separate consent, the selected document or confirmed case data and a technical instruction are sent to the OpenAI API.

For users in the EEA, the recipient is generally OpenAI Ireland Ltd., Dublin, including its affiliates and processors. The legal basis is Article 6(1)(a) GDPR and, for special categories of personal data, Article 9(2)(a) GDPR. Consent can be withdrawn for the future.

Under its published API terms, OpenAI does not use API content for model training by default. Reklaio requests disabled application storage where supported.

13. AI quotas and cost control

To enforce plans, we process the type, time and status of AI operations, monthly usage, individual limits and technical error codes. The legal bases are Article 6(1)(b) and (f) GDPR.

14. Administration and system events

Administrators can manage accounts, plans, limits, suspensions, support requests, withdrawals, billing events and system status. Administrative changes are logged. Payment, store-sync, email or backup failures may be stored as system incidents.

15. Cookies, local storage and Google Ads

Reklaio uses essential cookies and local storage for sessions, security and user preferences. With your voluntary consent, Google tags may measure page views, registrations and Pro purchases from Google Ads. Without consent, the Google tag is not loaded. You can change your selection using Cookie settings. The legal basis for optional measurement is Article 6(1)(a) GDPR.

16. Retention and deletion

Account and case data are stored while the account is active and deleted following an effective deletion request unless legal retention or proof obligations apply. Security, contract, billing and audit data may be retained for the applicable statutory period. AI analyses can be deleted separately.

17. Recipients and international transfers

Data is shared only where necessary with hosting, email, payment, store, subscription-management and AI providers. Where data is processed outside the EEA, the applicable adequacy decision, standard contractual clauses or another lawful safeguard is used.

18. Your rights

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent for the future. Contact us at reklaio@kamilunavo.com or through the contact form. You may also complain to a data-protection authority.

19. Security and changes

Safeguards include encrypted transmission, password hashes, random session tokens, access controls, private file storage, protected webhooks, rate limits, backups and administrative audit logs. This policy is updated when features, providers or legal requirements change.

ContactPricingLegal noticePrivacyTermsWithdrawalHelp
ContactPricingLegal noticePrivacyTermsWithdrawalHelp