Privacy
This is about the data of the person reading it — a visitor, or somebody with an account. What happens to the data your AI agents record is a different document: that is the Data Processing Agreement, where you are the controller and we are the processor.
Who is responsible
Kyoomee GmbH, FN 682788a, Peggau, Austria. Contact: hello@tallwright.com. Full company details are in the Impressum.
Visiting this site
No analytics, no advertising trackers and no cookie banner, because there is nothing to consent to: this site sets no cookie of its own. Our host, Vercel, keeps ordinary server logs for operating the service and defending against abuse. On the plan this site runs on those logs are visible to us for one day and we copy them nowhere; for the infrastructure logs Vercel keeps as our processor it publishes no fixed period, only that it keeps data for the minimum its own obligations require.
Signing up and signing in
There is no password. You give an email address, we send a link to it, and pressing it proves the address is yours. We keep that address, the name you choose to give, when you were last seen, and which browser you signed in from — the last so that you can end a session on a device you no longer have.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for an account, and legitimate interest (Art. 6(1)(f)) for keeping the service secure. Kept while the account exists, and for thirty days after it is closed — the same thirty days in which what you stored is still exportable — and then deleted.
Paying
Card details are entered on Stripe’s own pages and never reach us — we hold no card number and there is no field for one anywhere in the product. We hold what an invoice needs: a company name, a billing address, a VAT id, and which of our customer records belongs to which of Stripe’s.
Kept for the seven years Austrian bookkeeping law requires (§ 132 BAO).
What your agents record
Where you run the software yourself, none of it reaches us. Where we host it, what we hold is set by the tier you chose and by the Data Processing Agreement, and it is deliberately narrow: on the base tier what sits on our disk is hashes, a chain and countersignatures — no content, no key, and nothing that identifies a person your agent spoke to.
Who else touches it
These are the sub-processors. This list is the same one in the Data Processing Agreement, and it is here because a list a customer has to ask for is a list nobody reads.
We name no transfer mechanism we have not seen in place. We have not read these providers’ own data protection terms, so we assert neither the European Commission’s Standard Contractual Clauses nor any other safeguard for them, and we do not state their legal entity or parent domicile as a fact. What we can state is where the processing happens, because we measured it: the column above, on the dates in the sub-processor list.
What you can ask for
Access, correction, deletion, restriction, portability, and objection to processing based on legitimate interest — Articles 15 to 21 GDPR. Write to the address above and we will answer within a month. You may also complain to the Austrian data protection authority (dsb.gv.at).
One limit worth stating plainly: evidence you asked us to witness is designed not to be quietly changeable, including by us. A deletion request for an archive is answered by closing and destroying it on a stated schedule, not by editing what it says.
Changes
This notice is dated 10 September 2026. If it changes materially we tell account holders by email rather than by editing the page quietly.