Last updated: 7 September 2026

Privacy Policy

1. Controller

Ersan Yüksel operating under the business name WTDM, Gothaerstraße 10, 27755 Delmenhorst, Germany. Email: support@vikkisky.com.

2. Scope

This policy describes how personal data is processed when you visit this website, create an account, purchase a digital product, or contact us. We only process personal data where a legal basis under the GDPR applies.

3. Hosting and Delivery

This website is hosted on infrastructure operated by Lovable and delivered via Cloudflare Workers. When you visit the site, connection data such as IP address, browser type, operating system, requested page, and timestamp is processed to deliver content securely. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Processing locations can depend on the provider, the specific service and technical routing. The section "Third-Country Transfers" explains how we describe processing outside the EU/EEA.

4. Accounts and Authentication (Supabase)

Accounts, sessions and application data are managed through Supabase. When you register or sign in, Supabase processes your email address, an authentication identifier, and session tokens. If you sign in with Google, the sign-in is initiated through Lovable's OAuth broker, which facilitates the sign-in exchange before the resulting account and session data is used with Supabase, and Google transfers your name, email and profile picture to Supabase to create the session. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(a) GDPR (consent for social sign-in).

5. Payments (Stripe)

Payments are processed by Stripe Payments Europe, Ltd. (Ireland). When you buy a digital product, Stripe processes your name, email address, billing address, country, payment method data and transaction data. We never see or store full card details. Legal basis: Art. 6(1)(b) GDPR (contract execution) and Art. 6(1)(c) GDPR (statutory retention and tax obligations). Questions about international processing by Stripe are addressed in the section "Third-Country Transfers".

6. Purchases, Access and Contract Evidence

When you purchase the digital product, we store a purchase and contract-evidence record. Depending on the transaction, this record contains: your internal user identifier; the contract name and email address used for the purchase; the Stripe checkout-session, customer and payment-intent identifiers; the payment environment, payment status, amount, currency, tax amount and the related timestamps; your access and entitlement state; refund amounts, refund status and refund timestamps; dispute identifiers, dispute status and dispute timestamps; the exact checkout declarations shown to you and whether each one was accepted; the legal-document versions together with the full retained document texts in force at that moment and their SHA-256 hashes; the product, classification and offer version, the locale and the checkout environment; your IP address stored only as a hash, your user agent and the server timestamp; and the delivery state of the contract confirmation.

Purposes: completing and documenting the purchase; granting and administering access to the purchased content; generating and, where requested, resending the original contract confirmation; documenting the statutory declarations and the contract terms in force at the time of purchase; handling refunds, payment disputes and chargebacks; and fraud and security investigation as well as legal, tax and commercial recordkeeping.

Legal basis, depending on the purpose: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal, tax and commercial recordkeeping obligations), and Art. 6(1)(f) GDPR (security, fraud prevention and the establishment, exercise or defence of legal claims).

7. Electronic Withdrawal Requests

If you submit the electronic withdrawal form, we store: your name and email address; the order or contract reference or purchase email you type in for matching; your withdrawal declaration and free-text statement; the locale, the server timestamp and a non-guessable submission reference; your IP address stored as a hash and your user agent; the matching or reconciliation result or code; and the delivery state of the acknowledgment email.

Purposes: receiving, documenting and processing your withdrawal declaration; matching it to a purchase without publicly confirming whether an order exists; providing and documenting the electronic acknowledgment; and handling any later reimbursement or access decision separately.

Submitting the form documents your declaration. It does not by itself automatically trigger a refund or revoke access; those steps are handled separately.

Legal basis: Art. 6(1)(b) GDPR (processing the contractual declaration), Art. 6(1)(c) GDPR (statutory withdrawal and evidence obligations), and Art. 6(1)(f) GDPR (secure non-enumerating processing and reconciliation).

8. Browser Storage and Cookies

No analytics, advertising or cross-site tracking storage is currently used by this application. Browser storage is used only for the technically necessary sign-in and checkout functions described below.

Supabase authentication: Supabase uses browser localStorage to persist your authenticated session and to refresh authentication tokens, so that an existing signed-in session can be restored and maintained.

Optional Google sign-in: during optional Google OAuth sign-in, Lovable's OAuth broker and Google may use technically necessary cookies or comparable browser storage to conduct the redirect, the sign-in exchange, and security and session handling.

Stripe checkout: Stripe Embedded Checkout is loaded only when you open checkout. Stripe may then use technically necessary cookies or comparable browser storage for payment processing, security and fraud prevention. A service-specific summary is available in our Cookie Notice.

Server-side legal evidence: legally required checkout declarations and contract evidence (for example your consent to immediate delivery of digital content under § 356 Abs. 6 BGB) are stored on the server as part of your purchase and legal record, not as analytics or consent-preference data in your browser.

9. Contact by Email and Contact Form

If you contact us by email or through the contact form on this website, we process the name, email address and message content you provide in order to answer your request; contact-form messages are delivered to our support mailbox through the transactional email infrastructure described below.

If you contact us by email, we process the data you provide to answer your request. Legal basis: Art. 6(1)(b) GDPR when your request relates to a contract, otherwise Art. 6(1)(f) GDPR.

Transactional and legally required messages, such as purchase confirmations, withdrawal acknowledgments and operational account messages, are processed through Lovable's email infrastructure and delivered using Sinch Email / Mailgun. The data processed for this purpose is your recipient email address, sender and recipient metadata, subject and message content, delivery identifiers and status, retry and error information, and bounce, complaint and unsubscribe events where applicable. Purposes: delivering transactional and legally required communications, and documenting delivery status and handling failed or suppressed delivery. Legal basis: Art. 6(1)(b) GDPR for contract-related communications, Art. 6(1)(c) GDPR for legally required confirmations and records where applicable, and Art. 6(1)(f) GDPR (legitimate interest in reliable and secure email delivery, abuse prevention and operational troubleshooting).

Separately from the provider infrastructure above, this application keeps its own operational delivery records for such messages: the recipient email address; the message purpose and template identifier; queue, message and provider identifiers; the delivery state and its timestamps; the number of send attempts, the retry state and error information; bounce, complaint and unsubscribe events; and the suppression state and reason. Purposes: delivering and retrying transactional and legally required messages; avoiding duplicate sends; documenting whether a required confirmation was queued, sent or failed; preventing further delivery to suppressed recipients; and security, abuse prevention and troubleshooting. Legal basis: Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f) GDPR, depending on the message purpose.

10. Account Administration and Activity

For account administration we may process: your account identifier and email address; your application role and information about role changes; a last-seen or comparable account-activity timestamp; an administrative support note where an authorised administrator records one; the timestamp and status of an account deactivation or anonymisation; and, where applicable, a legal-hold indicator, information about the retained record categories and a deactivation audit record.

Purposes: authentication and access control; customer support and account administration; security and misuse prevention; documenting privileged administrative actions; and anonymising account identifiers while preserving those records that must remain for legal or transactional purposes.

Administrative notes are not created automatically and are not shown to you in your account; they are written only by an authorised administrator. Where a legal hold applies, account identifiers are anonymised while the underlying purchase and legal records are preserved.

Legal basis: Art. 6(1)(b) GDPR for account and access administration, Art. 6(1)(c) GDPR where records must be preserved by law, and Art. 6(1)(f) GDPR for security, support, auditability and misuse prevention.

11. Private Product Media and Signed Access

Prompt and workflow product media is stored in a private storage bucket and is not publicly accessible. When an authorised user or administrator opens this content, the server issues a time-limited signed URL to retrieve the individual file. These signed URLs expire and do not make the underlying storage bucket public.

Purpose: securely delivering purchased and private product content to authorised users.

Legal basis: Art. 6(1)(b) GDPR (delivery of the purchased product) and Art. 6(1)(f) GDPR (access security and prevention of unauthorised distribution).

12. Recipients and Processors

Personal data is only disclosed to service providers required to operate this website and deliver the product:

  • Lovable AB — hosting and delivery of the web application, OAuth brokering and transactional-email orchestration
  • Cloudflare, Inc. — edge delivery and DDoS protection
  • Supabase Inc. — authentication, database and file storage
  • Google Ireland Ltd. — optional Google OAuth sign-in
  • Sinch Email / Mailgun — transactional email delivery and processing of delivery events such as bounces, complaints and unsubscribes
  • Stripe Payments Europe, Ltd. — payment processing

The precise legal role of each provider, the applicable contractual arrangement and any international-transfer safeguard depend on the service and current configuration. Current information can be requested at support@vikkisky.com.

13. Third-Country Transfers

Some of the providers listed above, or companies within their corporate group, may process personal data outside the EU/EEA. The actual processing location and the transfer mechanism depend on the provider, the specific service and the current configuration. This Privacy Policy does not state a specific transfer mechanism where it has not been verified. If you would like current information about a specific provider, its processing location, the safeguard applied and how to obtain further information or a copy where available, please contact support@vikkisky.com.

14. Retention and Deletion Criteria

Personal data is retained only for as long as it is needed for the purpose it was collected for, for applicable legal obligations, for security and fraud prevention, or for the establishment, exercise or defence of legal claims. The applicable period depends on the record category, the state of the transaction, legal obligations, the systems of the providers involved, and whether a legal hold or an unresolved dispute applies.

  • Accounts and authentication: account, profile and access-control data is retained while it is needed to provide and secure your account. When the implemented deactivation and anonymisation process is used, direct account identifiers are anonymised or disabled as implemented, while purchase, legal, tax, payment, withdrawal, dispute and delivery-evidence records may remain separately where their purposes or legal duties continue. This means not every linked record can be deleted.
  • Purchases, payments and legal evidence: purchase, payment, refund, dispute, checkout-declaration, legal-snapshot, withdrawal and contract-confirmation records are retained for as long as needed to perform and document the contract and to satisfy applicable tax, commercial, consumer-protection and evidence obligations. These records may remain after an account has been anonymised.
  • Transactional email and suppression: queue, delivery, retry, error, bounce, complaint, unsubscribe and suppression records are retained while needed to deliver and document legally required messages, to avoid duplicate or prohibited sends, to troubleshoot delivery problems and to protect against abuse. Suppression information may need to remain in place to prevent renewed delivery to a suppressed address.
  • Support, administrative and security records: support correspondence, authorised administrator notes, role and audit records, last-seen or comparable activity information and server or security logs are retained only while needed for support, access control, operational security, auditability, abuse prevention or legal claims. Log retention on the provider side may differ and depends on the provider configuration.
  • Legal hold and unresolved matters: an active legal hold, a refund or dispute, a withdrawal matter, a tax or commercial duty, a regulatory request or a legal claim may extend retention for the affected records. Once the relevant purpose and obligation end, records are deleted or anonymised where this is feasible.

The application currently uses account deactivation and anonymisation together with operational or legal review rather than a single automatic time-based deletion schedule for every data category.

15. Your Rights

To exercise your rights, email support@vikkisky.com.

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent at any time (Art. 7(3) GDPR)

16. For Non-EU Residents (United Kingdom, United States and Other Countries)

This product is offered worldwide, and the rights and information described throughout this notice apply to you regardless of where you are located.

United Kingdom: if you are located in the UK, the UK GDPR and the Data Protection Act 2018 apply to this processing in addition to, or in place of, the EU GDPR where relevant. You may lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

United States: if you are a resident of California, Virginia, Colorado, Connecticut, Utah or another U.S. state with comparable privacy legislation, you may have rights to know and access, delete, correct, port, and limit the use of your personal information, and to opt out of its sale or of targeted advertising. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use personal information for targeted advertising.

Other countries: certain records, in particular purchase, payment, tax, contract-evidence and withdrawal records, must be retained where a legal obligation applies; a deletion request cannot override those obligations. Where the mandatory law of your own country of residence grants you further rights, those rights remain unaffected.

To exercise these rights, email support@vikkisky.com or use the contact form at https://talking-head-system.vikkisky.com/contact. We may need to verify your request, for example by confirming control of the email address associated with your account or purchase. You may use an authorised agent where the law permits; we may ask for proof of authorisation.

17. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your residence, workplace, or the place of the alleged infringement. UK residents may additionally contact the Information Commissioner's Office (ICO).

18. Changes to This Policy

We may update this privacy policy when the website, the services used or the legal situation changes. The current version is always available on this page.