Privacy Policy

Last updated: March 4, 2026

1. Introduction

This Privacy Policy explains how Kaeso ("we", "us", "our"), a product of Devin Oldenburg, Logicplanes, processes personal data when you visit kaeso.ai. We are committed to protecting your privacy in accordance with the GDPR, the German BDSG, and the TDDDG.

2. Controller

Devin Oldenburg, Logicplanes

Mozartstr. 23, 67269 Grünstadt, Germany

Email: [email protected]

3. Data We Collect

3.1 Server Log Data

When you visit our website, our hosting provider automatically collects: IP address (anonymised where possible), date/time, requested URL, HTTP status code, browser type, operating system, referrer URL.

Legal basis: Art. 6(1)(f) GDPR - legitimate interest in website security. Retention: 14 days.

3.2 Hosting

Our website is hosted by Vercel (US/EU). Data is processed under a DPA pursuant to Art. 28 GDPR. Vercel participates in the EU-US Data Privacy Framework and has implemented Standard Contractual Clauses.

3.3 Fonts

We use the Inter font, which is self-hosted via Next.js. No requests are made to Google servers.

3.4 No Cookies, Analytics, or Tracking

Our website currently:

  • Does not use cookies (no first- or third-party cookies)
  • Does not use analytics tools (no Google Analytics, Matomo, etc.)
  • Does not use tracking pixels, retargeting, or advertising scripts
  • Does not use social media plugins that load external resources

3.5 Contact / Communication

If you contact us by email, we process your email address, name (if provided), and message content. Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR. Retention: 12 months after inquiry is resolved.

3.6 Newsletter / Email Subscription

If you subscribe to our newsletter, we collect and process:

  • Your email address
  • Subscription date and time
  • IP address at time of subscription (for consent documentation)
  • Subscription topics/preferences

We use a double opt-in process: after you enter your email, we send a confirmation email with a verification link. Your subscription is only activated after you click this link. This ensures that the owner of the email address has consented to receiving our newsletter.

Legal basis: Art. 6(1)(a) GDPR - your explicit consent via double opt-in.

Email delivery: Emails are sent via our self-hosted mail server (Postal) operated by Logicplanes. No third-party email marketing services are used.

Withdrawal of consent: You can unsubscribe at any time by clicking the "Unsubscribe" link in any email, by visiting our email preferences page, or by contacting us at [email protected].

Retention: Your subscription data is retained until you unsubscribe. After unsubscription, we retain proof of your original consent (email address, date, IP) for up to 3 years to comply with documentation obligations under Art. 7(1) GDPR.

4. Data Sharing

We do not sell, rent, or trade your personal data. Data may be shared only with our hosting provider (for website operation), our self-hosted mail server (for newsletter delivery, operated by Logicplanes), and legal authorities if required by law.

5. Your Rights (GDPR)

Right of accessArt. 15 GDPR
Right to rectificationArt. 16 GDPR
Right to erasureArt. 17 GDPR
Right to restriction of processingArt. 18 GDPR
Right to data portabilityArt. 20 GDPR
Right to objectArt. 21 GDPR
Right to withdraw consentArt. 7(3) GDPR

To exercise your rights: [email protected]

6. Right to Complain

You have the right to lodge a complaint with a supervisory authority. The competent authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (LfDI)

Postfach 30 40, 55020 Mainz, Germany

datenschutz.rlp.de

7. Data Protection Officer

Not applicable - no DPO appointment required under Art. 37 GDPR.

8. Changes to This Policy

We may update this Privacy Policy from time to time. The date of the last update is shown at the top of this page.