Information under Art. 13 and 14 of the General Data Protection Regulation (GDPR) on the processing of personal data when using KanDooo (web application and mobile apps). Last updated: September 2026.
This is a translation of our German-language Datenschutzerklärung provided for your convenience. In case of any discrepancy, the German version prevails and is the only legally binding version.
E-mail for privacy inquiries: office@bitfeder.at
Signing in and managing your account is handled centrally through our customer portal Bitfeder One, operated by the same provider. We process: your e-mail address, name (company or individual), and password (stored only as a hash, never in plain text), as well as an internally assigned customer number. The legal basis is performance of the usage agreement (Art. 6(1)(b) GDPR).
After registration we send a confirmation e-mail with a verification link. If the e-mail address is not confirmed within 72 hours, access is locked; unconfirmed accounts are automatically deleted after 7 days at the latest.
As part of ordinary product use, we process the content you or your team create yourselves: tasks, projects, kanban boards, comments, attachments, calendar entries, and optional reference data such as departments or cost centers. This data belongs to you or your company; we process it solely to provide the agreed service (Art. 6(1)(b) GDPR). If you invite members to a team, we process their e-mail address and, where applicable, their name.
KanDooo uses only strictly necessary cookies — no advertising or tracking cookies, and no third-party cookie-consent tooling. Specifically, we set:
Both are strictly required to operate the application (Art. 6(1)(f) GDPR, legitimate interest in secure operation) — a consent banner is not required for these. We do not use any cookies on the public website (landing page, pricing, imprint).
The KanDooo app stores your credentials (access and refresh tokens) encrypted, exclusively on your own device (Android Keystore or iOS Keychain), and never transmits them anywhere other than our own servers. Communication with our servers is functionally identical to the web application (sections 2–3).
Voice capture / dictation: If you use the dictation feature to capture tasks by voice, processing is performed on-device wherever your device supports it. Where on-device speech recognition is not available, the respective platform provider instead processes the audio recording to convert it to text (Apple on iOS, Google on Android) — this processing is outside our control and is subject to Apple's or Google's own privacy terms. The feature is entirely optional and is only triggered when actively used.
If you use AI-assisted capture to have tasks automatically recognized from freely entered text (or the result of the dictation feature), our servers send the text you entered to Anthropic PBC (provider of the "Claude" AI model, San Francisco, USA) for processing. The API key for this is held exclusively on our servers; the app itself never contacts Anthropic directly. This transmission only happens when you actively use the feature, based on our legitimate interest in a working core feature of the product (Art. 6(1)(f) GDPR). As Anthropic is located outside the EU/EEA, we base this transfer on the European Commission's Standard Contractual Clauses.
Plan bookings and payment processing are handled through our customer portal Bitfeder One and our payment provider Stripe (Stripe Payments Europe, Limited, Ireland). Payment data (e.g. card details) is processed exclusively by Stripe and never reaches our own servers. Stripe's own privacy policy additionally applies.
For registration confirmations, password resets, and optional task reminders, we send e-mails through our own mail infrastructure. This processes your e-mail address, name, and the respective message content (Art. 6(1)(b) GDPR).
KanDooo is hosted and developed on our own server infrastructure operated within the EU. We do not routinely transfer your usage data to third countries, other than the specific, function-related cases described in sections 6 and 7 above.
We store personal data for as long as necessary to provide our service, or as required by statutory retention periods (e.g. tax-law retention obligations for invoice data). Unconfirmed registrations are automatically deleted after 7 days (see section 2). After your account is cancelled, your data remains readable for a further 30 days so you can export it (see our Terms and Conditions, section 11); afterwards we delete or anonymize it, unless a statutory retention obligation requires otherwise.
Within the limits set by law, you have the right to:
Simply reach out, no particular form required, to office@bitfeder.at.
You have the right to lodge a complaint with the competent supervisory authority:
We update this privacy policy whenever the legal situation or our data processing changes. The current version is always available at this address.