kapitel
kapitel
Sign inCreate account

Privacy Policy

Last updated: [DATE] · Version: 1.0

1. Data controller

[COMPANY NAME ApS]
CVR no.: [CVR-NO]
Address: [ADDRESS]
Email: gdpr@kapitel.app

2. What personal data do we collect?

CategoryExamplesSource
Account dataEmail, display name, password (encrypted)You provide at registration
PreferencesLanguage, favourite genres, reading formatYou provide at registration and in settings
Book club dataClub memberships, role, invitationsCreated through use of the service
Technical dataIP address, browser (user agent), session cookiesAutomatically during use

We do not collect payment information, national ID numbers or precise location data.

3. Purposes and legal basis

PurposeLegal basis (GDPR)
Create and maintain your accountArt. 6(1)(b) — necessary to provide the service
Display your book clubs, preferences and contentArt. 6(1)(b) — necessary to provide the service
Send transactional emails (confirmations, invitations)Art. 6(1)(b) — necessary to provide the service
Security and abuse preventionArt. 6(1)(f) — legitimate interest
Send newsletters and recommendationsArt. 6(1)(a) — your consent (can be withdrawn at any time)

4. Who do we share data with?

We never sell your data. We use the following data processors to operate the service:

ProviderPurposeLocation
Supabase Inc.Database, authentication, file storageEU (Frankfurt)
Vercel Inc.Frontend hostingUSA / EU edge
Railway Corp.Backend and queue hostingUSA

Transfers to the USA are based on the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (SCC).

5. Retention

DataRetention period
Account dataAs long as you have an active account
Book club dataAs long as you have an active account
PreferencesAs long as you have an active account
Technical log filesMax 90 days

When you delete your account, your data is anonymized (email is replaced, name is removed). Data required by law (e.g. bookkeeping obligations) may be retained for up to 5 years.

6. Your rights

You have the following rights under GDPR:

  • Access — obtain a copy of your data (Art. 15)
  • Rectification — correct inaccurate data (Art. 16)
  • Erasure — have your data deleted (Art. 17)
  • Restriction — restrict processing (Art. 18)
  • Data portability — receive your data in a structured format (Art. 20)
  • Objection — object to processing based on legitimate interest (Art. 21)
  • Withdraw consent — at any time, without affecting the lawfulness of prior processing (Art. 7)

You can export and anonymize your data directly in account settings. For other requests: gdpr@kapitel.app. We respond within 30 days.

7. Cookies

We only use technically necessary cookies:

CookiePurpose
sb-*Supabase session (authentication)
NEXT_LOCALEYour selected language

8. Children

The service is not directed at children under 13. We do not knowingly collect data from children under 13. If we discover an account belonging to a child under 13, we will delete it.

9. Changes

We may update this policy. For material changes we will notify you via email or in the service. The current version is always available at kapitel.app/privacy.

10. Complaints

If you believe we are processing your data unlawfully, you may lodge a complaint with:

Danish Data Protection Agency (Datatilsynet)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
datatilsynet.dk

If you reside in another EU/EEA country, you may also contact your local supervisory authority.

[COMPANY NAME ApS] — CVR [CVR-NO][ADDRESS]gdpr@kapitel.app