1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for operating this website and the FellDesk portal is:
Christopher RichterKirchweg 7a
21244 Buchholz
Germany
Email: hello@felldesk.eu
FellDesk is a service by NordheideStudios.de.
2. Hosting
This website and the portal are hosted by:
STRATO AGOtto-Ostrowski-Straße 7
10249 Berlin
Germany
The servers are located in Germany. Your data is processed and stored exclusively on German servers. A data processing agreement pursuant to Art. 28 GDPR is in place with STRATO AG.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient operation of the website).
3. Data Collected & Purpose
- Registration data – business name, email address, business type (salon or pet sitter), and the password stored exclusively in hashed form. Purpose: providing and managing the user account. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Client, pet and appointment data entered in the portal – name and contact details of pet owners, information about their pets, and appointments. We process this data strictly on instruction on behalf of the respective business; see Section 4.
- Payment data – processed exclusively through our payment provider, Stripe. FellDesk does not store card numbers or other complete payment details, only the customer and subscription identifier assigned by Stripe and the current subscription status. Legal basis: Art. 6(1)(b) GDPR.
- Server log files – IP address, browser type, access time, and the URL requested. Purpose: ensuring secure operation and defending against attacks. Legal basis: Art. 6(1)(f) GDPR. Retention period: maximum 7 days.
4. Data Processing on Behalf of Our Customers
FellDesk is software that dog groomers and pet sitters use to manage their own clients. For all data a business enters in the portal about its pet owners, their pets and appointments, the respective business is the controller within the meaning of the GDPR. FellDesk processes this data strictly on instruction, acting as a processor under Art. 28 GDPR.
The Data Processing Agreement (DPA under Art. 28(3) GDPR) is digitally included directly in our Terms of Service and is automatically entered into upon registration.
If you are a pet owner and would like to know what data is stored about you, please contact the salon or pet sitter whose client you are. We are not permitted to disclose or delete this data without instruction from the business.
5. Cookies & Sessions
- We use only technically necessary session cookies to maintain your login session and to protect against cross-site request forgery.
- No tracking cookies, analytics tools, advertising networks or social media plugins are used.
- No separate consent is required, as only cookies that are strictly technically necessary are used, pursuant to § 25(2) TTDSG.
A cookie banner is therefore not shown.
6. Payment Processing via Stripe
For paid plans we use the payment provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When you book a plan, you are redirected to a payment page operated by Stripe. You enter your payment details directly with Stripe; they are never transmitted to or stored by FellDesk. We only receive information from Stripe about whether a payment was successful and the status of your subscription.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Further information: stripe.com/privacy.
7. Data Sharing
- Data is shared only with STRATO AG (hosting) and Stripe Payments Europe, Ltd. (payment processing).
- We do not sell personal data.
- No data is transferred to third countries outside the European Union. We serve fonts and stylesheets from our own server; no external CDNs are used.
8. Retention Period
- Account data: until the account is deleted by the user or on request.
- Client, pet and appointment data: until deleted by the respective business, at the latest 30 days after cancellation of the account.
- Invoice data: in accordance with statutory commercial and tax retention periods (up to 10 years, § 147 AO).
- Server log files: maximum 7 days.
9. Data Subject Rights
You have the following rights against us:
- Right to information about your stored data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure ("right to be forgotten", Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to lodge a complaint with the competent data protection supervisory authority. For our location, this is the Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.
To exercise your rights, please contact hello@felldesk.eu.
10. Data Security
- Transmission between your browser and our servers is exclusively encrypted via SSL/TLS.
- Passwords are never stored in plain text, only as a hash using PHP's current default algorithm (currently bcrypt).
- Access to client, pet and appointment data requires an authenticated session; every database query is additionally scoped to the respective account.
- Forms are protected against cross-site request forgery.
11. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy if the scope of the service or legal requirements change. The current version is always available at felldesk.eu/legal/datenschutz.php. The version date is shown at the top of this page.