Last updated: August 2026
Sekkain
Last updated: 5 August 2026
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation is:
Kerem SariliBeethovenstr. 873760 OstfildernGermanyEmail: info@sekkain.tech
We process personal data only to the extent necessary to provide and securely operate Sekkain, perform contracts, communicate with users, or comply with legal obligations.
Processing is carried out, in particular, on the basis of:
Where processing is based on legitimate interests, these interests include, in particular, the secure, stable, and economically viable operation of Sekkain, the prevention of misuse and security risks, error analysis, the needs-based improvement of our services, and the establishment, exercise, or defence of legal claims.
Depending on how Sekkain is used, we may process the following categories of personal data:
As a rule, we do not process complete credit card or bank account details on our own systems. Such data is processed directly by the payment service provider used for the relevant payment transaction.
When Sekkain is accessed, technically necessary data is processed in order to deliver the platform to the user's device and operate it securely.
This may include, in particular:
The processing is carried out to provide Sekkain, ensure technical stability, diagnose errors, prevent attacks and misuse, and maintain the functionality of the service.
Legal basis: Article 6(1)(f) GDPR.
Our legitimate interest lies in the secure and reliable operation of our digital platform.
We use services provided by Vercel for the hosting, delivery, and technical provision of Sekkain.
As part of this provision, Vercel may process IP addresses, connection data, browser and device data, accessed resources, access times, and technical error and security information.
Depending on the specific processing activity, Vercel may process personal data as a processor acting on our behalf or as an independent controller.
The processing is carried out to provide, secure, and optimise the technical infrastructure of Sekkain.
Legal basis: Article 6(1)(f) GDPR.
Where Vercel processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement.
The creation of a user account is required in order to use certain Sekkain functions.
In this context, we process, in particular:
The processing is carried out to create, manage, and secure the user account, authenticate the user, and provide account-related functions.
Legal basis: Article 6(1)(b) GDPR.
We use Supabase for authentication, database functions, and other backend functions.
The following data may be processed through Supabase:
Sekkain's primary project and database data is processed in the Supabase project region West EU - Ireland, within the European Union.
The processing is carried out for registration and authentication, the provision of the user account, the storage of user-related data, permission management, and the secure technical operation of Sekkain.
Legal basis: Article 6(1)(b) GDPR, where processing is necessary to provide the user account or perform the contract.
The processing of security logs, error diagnostics, and data for the prevention of misuse is based on Article 6(1)(f) GDPR.
Where Supabase processes personal data on our behalf, such processing is carried out on the basis of a data processing agreement.
To allow users to remain logged in and use their user accounts, technically necessary authentication and session information is stored on the user's device.
Where Supabase Auth is integrated on the client side using its standard configuration, access tokens and refresh tokens may, in particular, be stored in the browser's Local Storage. Depending on the technical configuration, session information may instead or additionally be stored in technically necessary cookies.
This information is used, in particular, for:
The storage of or access to information on the user's device is necessary in order to provide the digital service and user account expressly requested by the user.
Legal basis for the processing of personal data: Article 6(1)(b) GDPR.
Legal basis for storing or accessing information on the user's device: Section 25(2), no. 2 TDDDG.
Technical and contractual emails may be sent in connection with a user account.
These may include, in particular:
For this purpose, the email address, reason for the message, time of sending, and technical delivery information may be processed.
The processing is carried out through Supabase Auth or the technical email delivery infrastructure used by Supabase for this purpose.
Legal basis: Article 6(1)(b) GDPR.
Where a message serves exclusively to protect the security of the user account, the processing may additionally be based on Article 6(1)(f) GDPR.
When users access audio content through Sekkain, we process the data required to provide the relevant functions.
This may include, in particular:
This data is processed to provide audio content, save playback progress, verify premium access rights, and provide the technical functions of the service.
Legal basis: Article 6(1)(b) GDPR.
We may process certain usage and technical data for internal statistical evaluations, error detection, the improvement of Sekkain, and the analysis of how our content is used.
This may include, in particular:
The analysis is not intended to track users outside Sekkain or create personal advertising profiles.
Legal basis: Article 6(1)(f) GDPR.
Our legitimate interest lies in improving our service, detecting technical problems, optimising content and functions, and preventing misuse.
Where information is stored on or accessed from the user's device for such analysis and this is not strictly necessary to provide the service expressly requested by the user, the relevant technology will only be activated after prior consent has been obtained pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.
When users purchase or manage a premium subscription, we process, in particular:
The processing is carried out to perform and manage the premium subscription, activate premium content, process billing, and handle cancellations.
Legal basis: Article 6(1)(b) GDPR.
Data required under tax and commercial law is processed on the basis of Article 6(1)(c) GDPR.
We use Stripe to process payments and manage premium subscriptions.
The Stripe payment form is embedded directly into Sekkain. Payment data required for the transaction is collected and processed directly by Stripe within the embedded Stripe payment form.
Depending on the selected payment method, the following data may be processed:
As a rule, Sekkain does not receive complete card or bank account details. We receive information regarding whether a payment was successful and the customer, transaction, and subscription identifiers required to manage the subscription.
Depending on the specific processing activity, Stripe processes personal data partly as our processor and partly as an independent controller. As an independent controller, Stripe may process data, in particular, for payment processing, fraud prevention, compliance with legal obligations, and the security of its payment services.
Legal basis for payment processing relating to the contract: Article 6(1)(b) GDPR.
Where Stripe processes data to comply with its own legal obligations, Stripe independently determines the applicable legal basis.
Stripe may use automated risk assessment systems as part of payment processing and fraud prevention. Further information regarding this processing is provided by Stripe in its own privacy notices.
Sekkain uses cookies, Local Storage, and, where applicable, comparable technologies.
Technically necessary technologies may be used, in particular, to:
Where the storage of or access to information is strictly necessary in order to provide a digital service expressly requested by the user, it is carried out on the basis of Section 25(2), no. 2 TDDDG.
The related processing of personal data is carried out, depending on the relevant purpose, on the basis of Article 6(1)(b) or Article 6(1)(f) GDPR.
Technologies that are not technically necessary, in particular technologies used for optional analytics, convenience, or marketing purposes, are only used after prior consent has been obtained.
Legal basis: Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR.
Consent may be withdrawn at any time with effect for the future through the provided privacy or consent settings.
When users contact us by email or through another provided contact method, we process the submitted data in order to handle the request.
This may include, in particular:
Legal basis: Article 6(1)(b) GDPR, where the request relates to a contract or pre-contractual measures.
General enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in appropriately handling enquiries and communicating with users.
Personal data is only disclosed where this is necessary to provide Sekkain, perform the contract, comply with legal obligations, or protect legitimate interests.
Recipients or categories of recipients include, in particular:
Where a recipient processes personal data on our behalf, a data processing agreement is concluded where required by law.
Sekkain's primary Supabase project and database data is processed in the project region West EU - Ireland, within the European Union.
However, when using Supabase, Vercel, Stripe, and their subcontractors, personal data may nevertheless be processed outside the European Union or European Economic Area, or may be accessed from a third country.
Such transfers only take place where the applicable legal requirements are met.
The relevant safeguards may include, in particular:
Information concerning the safeguards used in each case may be requested using the contact details provided in Section 1.
We store personal data only for as long as necessary for the relevant processing purpose or for as long as statutory retention obligations apply.
In particular, the following criteria and periods apply:
Account data such as the email address, user ID, nickname, and account master data is generally stored for the duration of the user account.
After the user account has been deleted, this data is deleted or anonymised unless statutory retention obligations or legitimate reasons require continued storage.
Streaming, listening history, and playback progress data is generally stored for the duration of the user account, insofar as this is required to provide the relevant functions.
Where the relevant functionality is available, users may reset or delete individual history or progress data.
Raw usage data used for internal evaluations, error analysis, and product improvement is generally stored for up to 90 days.
Data may be stored for longer where this is necessary to investigate a specific security incident, misuse case, or technical error.
Technical access, error, and security logs are stored only for as long as necessary for secure operation, error analysis, and the prevention of misuse.
The specific storage period may depend on the service used, the applicable service plan, and the type of log.
Data from support and contact requests is generally stored until the request has been fully handled.
Where necessary for documentation purposes, the defence against claims, or compliance with statutory obligations, the data may generally be stored for up to three years after the matter has been concluded.
Contractual, invoice, payment, and tax-related documents are stored in accordance with the applicable statutory retention periods.
Depending on the type of document, these periods may be six, eight, or ten years.
Information relating to consent given, refused, or withdrawn is stored for as long as necessary to demonstrate the relevant consent decision and defend against possible legal claims.
Deleted data may remain contained in technically necessary backups for a limited period. Such data is no longer used for normal business operations and is overwritten or deleted at the end of the relevant backup cycle.
Users may delete their user account through the function provided for this purpose or request deletion using the contact details provided in Section 1.
When a user account is deleted, the personal data associated with the account is deleted or anonymised provided that:
Data that is subject to statutory retention obligations is restricted from further use and deleted after expiry of the relevant retention period.
We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access, and other unlawful processing.
Such measures may include, in particular:
Despite appropriate security measures, complete protection of data transmitted and processed via the internet cannot be guaranteed.
Subject to the applicable legal requirements, data subjects have, in particular, the following rights:
Data subjects may exercise these rights at any time by contacting us using the details provided in Section 1.
Consent may be withdrawn at any time with effect for the future.
The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Consent may be withdrawn through the provided privacy or consent settings or by using the contact details provided in Section 1.
Where we process personal data on the basis of Article 6(1)(f) GDPR, data subjects have the right to object to such processing at any time on grounds relating to their particular situation.
Following an objection, we will no longer process the relevant data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or the processing is required for the establishment, exercise, or defence of legal claims.
Data subjects have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data.
The supervisory authority responsible for us is, in particular:
The State Commissioner for Data Protection and Freedom of Information of Baden-WürttembergHeilbronner Straße 3570191 StuttgartGermany
The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
The provision of certain personal data is required in order to:
Without the required data, the relevant functions or services cannot be provided or cannot be provided in full.
The provision of optional data is voluntary. Voluntary information will be marked accordingly where necessary.
According to the current configuration, Sekkain does not make decisions based solely on automated processing which produce legal effects concerning users or similarly significantly affect them.
As part of payment processing, Stripe may use automated systems for fraud prevention and risk assessment. This processing is carried out under Stripe's responsibility in accordance with its applicable privacy information and legal obligations.
Sekkain does not currently create automated advertising or personality profiles.
Sekkain may also be used by minors within the limits permitted by law.
Where the processing of personal data is based on consent and the service is offered directly to a child, the child's own consent is generally valid in Germany only from the age of 16.
For younger users, the consent or authorisation of their legal guardians is required unless another legal basis applies to the processing.
Minors may only purchase paid subscriptions where the contract can be validly concluded in accordance with the applicable legal provisions. In particular, the consent of a legal guardian may be required.
We may amend this Privacy Policy with effect for the future where this is necessary due to technical, legal, organisational, or business changes.
The version currently published on Sekkain applies.
Registered users will be informed appropriately of material changes where required by law.