Privacy policy
Last updated: September 2026
This is a translation provided for convenience. The German version is the legally binding one.
Preamble
This privacy policy tells you what personal data we process, why, and on what basis, across our website and the services and content reached from it (together, "Kitospace" or "the platform"). Kitospace is a software-as-a-service application for managing properties, reservations and guest communication.
§ 1 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Ruben Hazenbosch (sole proprietorship)
Trading under the brand name: Kitospace
Jungmannstraße 57
24105 Kiel
Germany
E-mail: privacy@kitospace.app
We are not required by law to appoint a data protection officer. The address above reaches us for anything to do with data protection.
§ 2 Overview of processing
The list below summarises the categories of data we process and what we process them for. The people concerned are our customers' staff and users, guests, prospective customers, and visitors to the website.
- Account data: first and last name, e-mail address, password (stored only as a hash), organisation name, and role and permissions within the organisation.
- Reservation data: guest names, contact details, arrival and departure dates, the property and unit booked, booking codes, and the notes and tasks attached to them.
- Usage and metadata: sign-in times, session information, IP address, browser type and operating system, and log entries for security-relevant events.
- Payment data: billing address, payment method details and transaction history for the subscription. We neither collect nor store full card numbers (see § 11).
- Communication data: the content of messages between staff and guests inside the platform, support requests, and anything submitted through the contact form.
§ 3 Legal bases
We process personal data on the following bases under the GDPR. German national data protection rules, in particular the Bundesdatenschutzgesetz (BDSG), may apply alongside them.
- Performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR) — processing is necessary to perform the contract you have with us, or to take steps at your request before entering into one. This covers providing the account, managing reservations and billing.
- Legal obligation (Art. 6(1)(c) GDPR) — processing is necessary to comply with a legal obligation we are subject to, in particular the commercial and tax retention duties in § 147 AO and § 257 HGB.
- Legitimate interests (Art. 6(1)(f) GDPR) — processing is necessary for our legitimate interests or those of a third party, unless your interests or fundamental rights override them. Our legitimate interests are running the platform securely and without interruption, defending against abuse and attack, and improving what we offer.
- Consent (Art. 6(1)(a) GDPR) — where we ask for your consent, we process the data only within the scope of that consent. You may withdraw consent at any time with effect for the future.
§ 4 Security measures
In line with Art. 32 GDPR, and taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, we take appropriate technical and organisational measures to achieve a level of security matched to the risk:
- Encryption in transit: every connection to the platform is encrypted with TLS (HTTPS).
- Password security: passwords are never stored in plain text, only as salted bcrypt hashes.
- Tenant separation: each customer's data is stored and processed in strict logical separation from every other customer's. Access across a tenant boundary is technically prevented.
- Access control: access is role-based and follows the principle of least privilege. Administrative access by our staff to customer data is time-boxed, tied to a specific reason, and logged.
- Logging and review: security-relevant events are logged; the measures in place are reviewed regularly and kept current with the state of the art.
- Data protection by design: privacy-friendly defaults and data minimisation are considered during development (Art. 25 GDPR).
§ 5 Disclosure of personal data
In the course of our processing, data may be transferred to or disclosed to other parties. Those parties are processors within the meaning of Art. 28 GDPR and each has a data processing agreement with us:
- Stripe Payments Europe, Ltd., The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland — payment and subscription processing (see § 11).
- Koyeb SAS, France — hosting of the application and the databases in data centres inside the European Union (see § 8).
- Supabase, Inc., United States — hosting of the database and, as authentication provider, processing of sign-in data (see § 8).
Third-country transfer. Stripe Payments Europe, Ltd. and Koyeb SAS are established in the European Union and process the data exclusively in data centres inside the EU or the European Economic Area. Supabase, Inc. processes the data in a data centre inside the European Union (see § 8) but is itself established in the United States, a third country within the meaning of Art. 44 ff. GDPR. This transfer is covered by the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR, part of Supabase's data processing agreement.
§ 6 Erasure of data
We erase the data we process once the consent permitting the processing is withdrawn or another permission ceases to apply (Art. 17 GDPR). Where data is not erased because it is still needed for other, legally permitted purposes — commercial or tax retention duties in particular — its processing is restricted to those purposes. The following periods apply:
| Category of data | Retention period | Basis |
|---|---|---|
| Account and master data | Term of the contract plus 30 days | Art. 6(1)(b) GDPR |
| Reservation and booking data | Term of the contract plus 30 days (for reversal) | Art. 6(1)(b) GDPR |
| Log and audit entries | 90 days, then erased automatically | Art. 6(1)(f) GDPR |
| Invoices and accounting records | 10 years | § 147 AO, § 257 HGB with Art. 6(1)(c) GDPR |
| Media files (marked deleted) | 30 days until final erasure | Art. 6(1)(f) GDPR |
| Server log files | 7 days | Art. 6(1)(f) GDPR |
| Contact enquiries | 6 months | Art. 6(1)(b) and (f) GDPR |
§ 7 Your rights
As a data subject under the GDPR you have the following rights, which you can exercise against us:
- Right of access (Art. 15 GDPR): you may ask us to confirm whether we process data concerning you, and to give you information about that data and a copy of it.
- Right to rectification (Art. 16 GDPR): you may ask us to complete data concerning you or to correct data that is inaccurate.
- Right to erasure (Art. 17 GDPR): you may ask us to erase data concerning you without undue delay (the "right to be forgotten").
- Right to restriction of processing (Art. 18 GDPR): you may ask us to restrict the processing of your data.
- Right to data portability (Art. 20 GDPR): you may ask to receive data concerning you in a structured, commonly used, machine-readable format, or to have it transmitted to another controller.
- Right to object (Art. 21 GDPR): on grounds relating to your particular situation, you may object at any time to processing of data concerning you that is carried out on the basis of Art. 6(1)(f) GDPR.
- Withdrawal of consent (Art. 7(3) GDPR): you may withdraw consent you have given at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint (Art. 77 GDPR): without prejudice to any other remedy, you may complain to a supervisory authority (see § 14).
An informal message to privacy@kitospace.app is enough to exercise any of them. We answer without undue delay and at the latest within one month of receipt.
§ 8 Hosting
To provide the site securely and efficiently we use a hosting provider, from whose servers the site is served:
In doing so, we and our hosting provider process account, contact, content, contract, usage and metadata belonging to users of the site, on the basis of our legitimate interest in providing it efficiently and securely (Art. 6(1)(f) GDPR) together with a processing agreement under Art. 28 GDPR.
Supabase, Inc.
Database hosting and authentication in a data centre in Frankfurt, Germany (European Union)
Supabase, Inc. hosts the database holding all application data and, as our authentication provider, processes sign-in data, namely e-mail address, password hash and sign-in records, on the basis of our legitimate interest in providing the platform efficiently and securely (Art. 6(1)(f) GDPR) together with a processing agreement under Art. 28 GDPR. Supabase, Inc. is based in the United States. The data processing agreement, part of Supabase's Terms of Service, covers this transfer to the United States under the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
Server log files. The server records data about every request (server log files). Log files contain the IP address, the date and time of the request, the address and name of the page requested, the volume of data transferred, whether the request succeeded, the browser type and version, and the user's operating system. Log file information is kept for 7 days to investigate abuse and fraud and to keep the system secure, and is then erased. Data whose further retention is needed as evidence is exempt from erasure until the incident in question is resolved. The legal basis is Art. 6(1)(f) GDPR.
§ 9 Registration and user account
Users can create an account. Registration collects the details it requires: first and last name, e-mail address, a password of the user's choosing, and the name of the organisation the account is being created for. The password is stored only as a hash and is at no point readable by us in plain text.
We process this data to provide the account, authenticate access, assign permissions within the organisation and send contract-related notifications. The legal basis is Art. 6(1)(b) GDPR. To keep the account secure we also process sign-in times and session information on the basis of Art. 6(1)(f) GDPR.
Users can view and change their details at any time in the profile area. The data is kept for the term of the contract and for a further 30 days, then erased, unless a statutory retention duty says otherwise (see § 6).
Signing in with Google. Users who already have a Kitospace account can also sign in with their Google account. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, then confirms the user's identity and passes on their name, e-mail address and, depending on the account's settings, profile picture. Our authentication provider, Supabase (see § 8), stores these details with the sign-in record. Kitospace uses only the e-mail address, to find the account the sign-in belongs to. Signing in with Google does not create a new account. We never receive the Google password, we request no other access to the Google account, and we do not pass this data on or use it for advertising. The legal basis is Art. 6(1)(b) GDPR. Users can remove the connection at any time in their Google account under Security, Third-party connections, or by deleting their Kitospace account. Google's privacy policy: policies.google.com/privacy
§ 10 Contacting us
When you contact us — through the contact form, by e-mail or by a comparable route — we process what you send: name, e-mail address, company name where given, and the content of the message. We use it only to answer the enquiry and to take any pre-contractual steps it calls for.
The legal basis is Art. 6(1)(b) GDPR where the enquiry is aimed at concluding or performing a contract, and otherwise Art. 6(1)(f) GDPR, on our legitimate interest in answering enquiries. The data is erased 6 months after the enquiry is closed, unless a statutory retention duty applies.
§ 11 Payments
We use the payment provider Stripe to process payments and subscriptions:
Stripe Payments Europe, Ltd.
The One Building, 1 Grand Canal Street Lower
Dublin 2, Ireland
The data processed is account data (name, e-mail address), billing address, details of the payment method chosen, and the transaction and subscription history. Full payment details — a card number, for instance — are entered only in a form provided by Stripe; we neither collect nor store them. From Stripe we receive only what performing the contract requires, in particular the payment status and the last digits of the payment method used.
The purposes are payment processing, subscription billing, invoicing and fraud prevention. The legal basis is Art. 6(1)(b) GDPR (performance of a contract), and Art. 6(1)(c) GDPR as regards retaining invoices. Stripe Payments Europe, Ltd. is established in the European Union and the processing takes place inside the EU/EEA. For more, see the privacy notice published by Stripe.
§ 12 Cookies
We set one technically necessary session cookie and nothing else. Its only job is to recognise a signed-in user for the duration of a session and to secure access to the platform. It holds nothing that could be evaluated for advertising or analytics, and it expires at the end of the session or on sign-out at the latest.
We use no tracking cookies, no web analytics services and no third-party cookies. There is no profiling across sites or across devices, and no data is passed to third parties for advertising.
The legal basis for the session cookie is our legitimate interest in running the platform securely and in working order under Art. 6(1)(f) GDPR together with § 25(2) no. 2 TDDDG, under which storing strictly necessary information on a device needs no consent. A cookie banner is therefore not required, and we deliberately do not use one.
§ 13 Changes to this policy
Please check the content of this policy from time to time. We adapt it as soon as changes to our processing make that necessary. The current version is dated at the top of this page.
Where a change calls for something from you — consent, for instance — or for individual notification, we will also tell you inside the platform and by e-mail to the address held on your account.
§ 14 Supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. The authority responsible for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98
24103 Kiel
Germany