Legal
Privacy Policy
Last updated 13 August 2026
Draft. Not yet legally reviewed.
This document is a working template with placeholder company details. It is not legal advice and must be reviewed by a qualified lawyer before launch.
This policy explains what personal data puka.studio [LEGAL FORM — TODO] (“Puka”) processes as a data controller, the legal bases we rely on, and the rights you have under the EU General Data Protection Regulation (GDPR). Puka Cloud is hosted in the European Union.
1. Controller
The controller responsible for your personal data is puka.studio [LEGAL FORM — TODO], [Street and number — TODO], [Postal code, City — TODO], Austria. For privacy matters, contact privacy@puka.cloud.
2. What we process
Account data
Name, email address, password hash, profile image, and organization details you provide. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Content data
Podcasts, episodes, audio and video files, artwork, and show metadata you upload. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Billing data
Subscription status and billing identifiers. Card details are handled directly by Stripe and never stored on our servers. Legal basis: performance of a contract and compliance with legal obligations (Art. 6(1)(b), (c) GDPR).
Usage and analytics data
Product analytics (pages visited, features used) processed within the EU to improve the Service, and aggregated podcast download statistics. Legal basis: our legitimate interest in operating and improving the Service (Art. 6(1)(f) GDPR), or your consent where required.
Technical data
IP address, user agent, and log data necessary to deliver and secure the Service. Legal basis: legitimate interest in security and reliability (Art. 6(1)(f) GDPR).
3. Processors and international transfers
We use the following processors to operate the Service. Where data is processed outside the EU/EEA, transfers are safeguarded by EU Standard Contractual Clauses and/or an adequacy mechanism.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing and subscription billing | Ireland / USA | EU Standard Contractual Clauses; EU-U.S. Data Privacy Framework |
| Resend (Plover, Inc.) | Transactional email delivery (verification, invitations, notifications) | USA | EU Standard Contractual Clauses |
| PostHog (EU Cloud) | Product and usage analytics | European Union (Frankfurt, Germany) | Processed within the EU |
| [Hosting provider — TODO: confirm] | Application hosting and object storage (audio, images) | Austria / European Union | Processed within the EU |
4. Retention
We keep personal data for as long as your account is active and as needed to provide the Service. After account deletion, data is removed within a reasonable period, except where we must retain records to comply with legal obligations (e.g. invoicing and tax records).
5. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time, without affecting prior processing.
You can export your data at any time from within the app. To exercise any right, contact privacy@puka.cloud. You also have the right to lodge a complaint with a supervisory authority — in Austria, the Datenschutzbehörde (dsb.gv.at).
6. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and EU-based hosting. No system is perfectly secure; we work continuously to protect your data.
7. Changes
We may update this policy. Material changes will be communicated through the Service or by email. The date above reflects the latest version.