The following privacy policy ("Datenschutzerklärung") applies as of February 11, 2025.
"App Store Metadata API" is a (cloud-)service of kula app GmbH (short kula), FN 584452 p, Taubstummengasse 11, in 1040 Vienna, Austria, with a web client and application interface endpoint (hereinafter referred to as "ASM API") available at https://app-store-metadata-api.kula.app. The purpose of the ASM API is to provide a stable and reliable interface to public metadata about apps in the Apple App Store.
Before detailing our comprehensive privacy policy, here is a legally non-binding summary at your convenience:
LEGAL BASIS FOR DATA PROCESSING
We process your personal data based on:
Contract performance (Art. 6(1)(b) GDPR) for service provision
Legal obligations (Art. 6(1)(c) GDPR) for compliance requirements
Legitimate interests (Art. 6(1)(f) GDPR) for service improvement and security
Consent (Art. 6(1)(a) GDPR) where specifically requested
CATEGORIES OF PERSONAL DATA PROCESSED
Account Information
Email address (required for authentication and communication)
Password (stored using industry-standard encryption)
API keys and associated usage metrics
Technical and Usage Data
API request logs and usage patterns
Error reports and performance metrics via Sentry
IP addresses and access timestamps
Browser and device information for security purposes
Cookies and similar technologies as detailed in our Cookie Policy
Payment Information
Payment processing is handled by Stripe. We do not store payment instrument details but retain transaction records for accounting purposes.Communications and Support
Emails and customer support inquiries
Logs of service interactions
PURPOSES OF DATA PROCESSING
We process your data to:
Provide and maintain our API service pursuant to our contractual obligations
Monitor and optimize service performance and reliability
Distribute essential service updates and legally required notifications
Process payments and manage subscription lifecycle
Implement technical and organizational security measures
Comply with legal and regulatory obligations
Establish, exercise, or defend legal claims
DATA STORAGE AND SECURITY MEASURES
AWS Infrastructure
Your primary data is stored in AWS data centers located in the European Union, ensuring compliance with EU data protection regulations.International Data Transfers
Where our service providers process data outside the EU, such transfers are safeguarded by SCCs and other compliance mechanisms.Technical and Organizational Measures
State-of-the-art encryption for data in transit and at rest
Regular security audits and vulnerability assessments
Role-based access controls and multi-factor authentication
Continuous security monitoring and intrusion detection
DDoS protection and Web Application Firewall via Cloudflare
Regular staff training on data protection and security
DATA PROCESSORS AND THIRD-PARTY SERVICES
Sentry
We utilize Sentry for error tracking and performance monitoring under a data processing agreement. Transfers to the US are protected by SCCs.Cloudflare
We use Cloudflare for security and content delivery. Traffic data is processed under EU data protection requirements.Stripe
Payment processing is conducted by Stripe, adhering to EU data protection standards.YOUR RIGHTS AS A DATA SUBJECT
Under GDPR, you have the right to:
Access your personal data (Art. 15 GDPR)
Rectification of inaccurate data (Art. 16 GDPR)
Erasure of your data ("right to be forgotten") (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Object to processing (Art. 21 GDPR)
Withdraw consent at any time (Art. 7(3) GDPR)
Lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde)
DATA RETENTION PERIODS
We retain personal data only for as long as necessary. Account data is retained while active and for 3 years thereafter. API logs are stored for 12 months, and payment records for 7 years.LEGAL DISCLOSURES AND LAW ENFORCEMENT REQUESTS
We may disclose personal data as required by Austrian, EU, and international law or law enforcement agencies.CHILDREN'S DATA
Our services are not intended for children under 16. If we process such data, we will delete it.AMENDMENTS TO THIS POLICY
We may update this privacy policy as needed. Significant changes will be communicated to users via email or website notice.For inquiries regarding this privacy policy or to exercise your data subject rights, please contact our data protection coordinator at legal@kula.app.
© 2025 kula app GmbH. All rights reserved