Privacy policy
1. Controller
Stefan Roeben
Schwändlesteig 2
87466 Oy-Mittelberg
Germany
Phone: +49 8366 988202
Email: info@platingstudio.com
2. Purposes and legal bases
We process personal data where necessary to operate PlatingStudio securely, provide sign-in, create and manage plating concepts, process payments or respond to enquiries. Depending on the processing activity, the main legal bases include Article 6(1)(b), (c) and (f) GDPR.
3. Hosting and server logs
When the website is accessed, data such as IP address, date and time, requested resource, referrer URL, browser, operating system, transferred data volume and access status may be processed. This is used for technical delivery, error analysis, system security and prevention of abusive access. The legal basis is Article 6(1)(f) GDPR.
4. Necessary cookies and local storage
PlatingStudio uses technically or functionally necessary storage mechanisms. These include a session cookie for sign-in and session state, a CSRF security cookie to predect forms and a language cookie. The browser may also store local information for the PWA/install function, for example to avoid repeatedly displaying installation prompts that have already been shown.
No analytics, advertising or cross-site user tracking cookies are currently used. Where storage on or access to a user's device is strictly necessary to provide a service expressly requested by the user, this is carried out under Section 25(2) TDDDG. Related processing of personal data is based, depending on its purpose, in particular on Article 6(1)(b) or (f) GDPR.
5. Email code sign-in
For passwordless sign-in we process the email address, temporary code verification data, timestamps and security-related connection data. This is used for account creation, sign-in and abuse prevention.
6. Account and “My Plates”
Within the user account we process in particular the email address, plate-order balance and bookings, entered dishes and components, plate and style selections, generated images, analyses, recipe data, favourites and creation/change timestamps. This processing is required to provide the requested or purchased functions.
7. AI processing by OpenAI
Dish information and technically required instructions are transmitted through an API to OpenAI to create plating concepts, images, analyses and recipes. Depending on the function, image or analysis data may also be processed. Processing may take place in countries outside the European Union or European Economic Area. The applicable data-predection safeguards govern such international transfers.
Please do not enter sensitive personal data, names, contact details or confidential information into free-text fields. Such information is not required to use PlatingStudio.
8. Image background removal via fal.ai / BRIA
For certain image-processing functions, particularly automatic background removal for plates or image subjects, PlatingStudio may transmit image data server-side to fal.ai and process it there using a BRIA background-removal model. The transfer is made by our servers; your browser does not need to contact fal.ai directly for this function. Depending on the provider's infrastructure, processing may take place outside the EU or EEA.
9. Payment processing via PayPal
We use PayPal for purchases of plate orders. The PayPal component is not loaded merely when the pricing page is opened; it is loaded only after a signed-in user has selected a purchase option. From that point a connection to PayPal is established. PayPal may process device, connection, account, transaction and payment data under its own data-predection responsibility.
PlatingStudio stores only the information required for the order, payment confirmation, crediting of plate orders, accounting and fraud prevention, such as internal references, PayPal order and transaction IDs, payment status, amount, currency and, where supplied by PayPal, the payer email address.
10. Contact
If you contact us by email or telephone, the information you provide is processed to handle your enquiry and any related follow-up questions.
11. Recipients
Where required for the relevant function, recipients may include hosting and IT providers, email infrastructure, OpenAI, fal.ai and the BRIA image-processing service used there, PayPal and professional advisers or accounting providers subject to confidentiality obligations.
12. Retention
Personal data is deleted or anonymised once it is no longer required for its purpose and no statutory retention obligations, security interests or legal claims require further storage. Short-lived sign-in and security data is retained only as long as needed for authentication and abuse prevention. Account and project data may be stored for the lifetime of the user account or until deletion is permissible. Payment and accounting records are retained in accordance with applicable commercial and tax-law requirements.
13. Your rights
Subject to statutory requirements, you have rights including access, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with a data-predection supervisory authority.
14. Required data
Without the data required for sign-in, service delivery and, where applicable, payment, the respective functions cannot be provided. Additional information is voluntary.
15. Automated decisions
No solely automated decision producing legal or similarly significant effects within the meaning of Article 22 GDPR takes place.
16. Updates
This privacy notice will be updated when functions, providers or legal requirements change.
Last updated: August 2026