Data Protection
How we process personal data — explained transparently.
Privacy Policy of the United Creatives Platform
Translation of the German original — Stand: 11. September 2026 · Version 1.1
Non-binding convenience translation. Only the German version („Datenschutzerklärung der United Creatives Plattform“) is legally binding; in the event of discrepancies, the German version prevails.
Jurisdiction: Germany/EU (GDPR, BDSG, TDDDG). Primary platform operation: self-operated platform components on hosting infrastructure in Germany; external recipients are named below.
Contents
- Controller and data protection contact
- General information, terms, legal bases
- Rights of data subjects and right to lodge a complaint
- Hosting and server log files
- Cookies, local storage and consent (§ 25 TDDDG)
- Registration, user account and authentication
- Contract processing, billing and payment
- Image search and monitoring
- Marketplace purchases
- Contact, sales and email communication
- Support chat
- Customer and licence data, data processing on behalf
- Partner and referral program
- External recipients and services
- Transfers to third countries
- Storage period and deletion
- Automated decision-making
- Changes to this privacy policy
1. Controller and data protection contact
The controller within the meaning of the GDPR is:
United Creatives UG (haftungsbeschränkt) Flughafenallee 28, 28199 Bremen, Germany Represented by: Thorben Schmidt Register court: Amtsgericht Bremen (Local Court of Bremen), HRB 42520 · VAT ID: DE461490250 Email: info@unitedcreatives.art
Data protection contact: Please direct data protection enquiries to info@unitedcreatives.art.
2. General information, terms, legal bases
(1) We process personal data exclusively in accordance with the GDPR, the BDSG (German Federal Data Protection Act) and the TDDDG (German Telecommunications Digital Services Data Protection Act). Personal data is any information relating to an identified or identifiable natural person.
(2) Legal bases. Depending on the processing, we rely on:
- Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures, in particular account, subscription, provision of the Platform, payment and contract processing;
- Art. 6(1)(a) GDPR – consent, insofar as a processing operation is expressly based on consent;
- Art. 6(1)(f) GDPR – legitimate interests, in particular IT security, fraud prevention, stability and functionality of the Platform, support and enforcement of legal claims;
- Art. 6(1)(c) GDPR – legal obligations, in particular retention obligations under commercial, tax and regulatory law.
(3) Insofar as we process personal data on behalf of our users, we act to that extent as a processor on the basis of a data processing agreement.
(4) Insofar as personal data is required for registration, user account, conclusion of contract, use of the Platform, payment processing, marketplace purchases, partner program or support, the affected functions or services cannot be provided, or cannot be provided in full, without this data. Voluntary information and consent-based processing operations are recognisable as such or follow from the respective function.
3. Rights of data subjects and right to lodge a complaint
(1) Where the legal requirements are met, you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and the right to object to processing based on legitimate interests (Art. 21 GDPR).
(2) You may withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of the processing carried out until withdrawal remains unaffected. If personal data is processed for the purpose of direct marketing on the basis of legitimate interests, you may object to this processing at any time.
(3) To exercise your rights, a message to info@unitedcreatives.art is sufficient.
(4) You have the right to lodge a complaint with a data protection supervisory authority, in particular with the supervisory authority responsible for us, the Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen (State Commissioner for Data Protection and Freedom of Information of the Free Hanseatic City of Bremen): https://www.datenschutz.bremen.de.
4. Hosting and server log files
(1) We operate the Platform and the components required for its operation, in particular application servers, databases, object storage, authentication, upload, support, background and search components, ourselves on hosting infrastructure in Germany. External recipients and services are named in the following sections.
(2) When the Platform is accessed, technically necessary access data is processed, in particular IP address, date and time, requested resource, status code, amount of data transferred, referrer and browser and operating system information. This serves the delivery of the Platform, ensuring stability and security, and error analysis. The legal basis is Art. 6(1)(f) GDPR. Access log files are regularly deleted or anonymised after 7 days, unless security-relevant events, error analysis or legal obligations require longer retention.
5. Cookies, local storage and consent (§ 25 TDDDG)
(1) The Platform uses cookies and comparable local storage technologies insofar as this is necessary for operation, security, login, language and display settings, shopping cart, subscription and order functions, functions of the partner and referral program and for Platform functions expressly used. Access to information in the end device takes place to that extent on the basis of § 25(2) no. 2 TDDDG. The subsequent processing of personal data is governed by the respectively applicable legal bases of the GDPR, in particular Art. 6(1)(b) and (f) GDPR.
(2) Technically or functionally necessary storage includes in particular session and security identifiers, shopping cart and order assignments, language and display settings, temporary selection and process data and the assignment of a referral link used in the partner and referral program. The storage period depends on the respective purpose; session-related storage regularly ends with the session, function-related storage regularly remains until the purpose is achieved, the setting is changed or it is deleted in the browser.
(3) Non-essential cookies or comparable technologies, in particular for web analytics, reach measurement, marketing, campaign measurement or external advertising/tracking services, are activated only after prior consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). Consent given can be withdrawn or changed at any time with effect for the future.
(4) To obtain, manage and document consent, we use CCM19 Cloud. The provider is Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, Germany, which acts as a processor for us; hosting takes place in Germany or the EU. CCM19 stores your decision in a technically necessary consent cookie (ucid, duration 12 months; § 25(2) no. 2 TDDDG). To prove consent, the consent status, time of the decision, technical identifiers, an anonymised IP address (24-hour rollover) and browser and device information are also processed, insofar as this is necessary for storing and proving consent. The legal bases are Art. 6(1)(c) GDPR (obligation to demonstrate consent, Art. 7(1) GDPR) and Art. 6(1)(f) GDPR. You may withdraw or change consent given at any time with effect for the future via the "Cookie settings" link in the page footer.
(5) If analytics or marketing services are used, we inform you before activation about the services used, purposes, storage periods and any transfers to third countries. Service-specific information is added to this privacy policy as soon as the respective services are determined and activated.
(6) For the technical integration and consent-compliant control of such analytics and marketing services, we use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing by Google LLC in the USA may take place. Google Tag Manager is loaded only after you have consented to its use; before consent, no connection to Google is established and in particular no IP address is transmitted to Google. After consent has been given, the Tag Manager receives the consent status via Google Consent Mode v2 and activates integrated services exclusively to the extent of your respective consent. The legal bases are § 25(1) TDDDG and Art. 6(1)(a) GDPR (consent); you may withdraw consent at any time with effect for the future via the "Cookie settings" link in the page footer. For transfers to third countries, see Section 15.
6. Registration, user account and authentication
(1) A user account is required to use the Platform. Registration and login take place via our self-operated authentication and session component. Insofar as optional third-party logins are offered, users may use them voluntarily.
(2) Upon registration, login and use of the user account, we process in particular name, email address, authentication and session data, language settings, account-related settings and confirmations given regarding entrepreneur status, acceptance of the Terms and consents granted. The legal basis is Art. 6(1)(b) GDPR; for security- and evidence-related processing additionally Art. 6(1)(f) GDPR and, insofar as legal obligations exist, Art. 6(1)(c) GDPR.
(3) To defend against automated and abusive access to registration, authentication and content reporting forms, we carry out self-operated technical security checks. In doing so, browser and device signals as well as random, time-based and derived security identifiers are processed briefly. The raw data is discarded after the check; the short-lived identifiers serve only single use and rate limiting of requests. The legal bases are § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR.
(4) Insofar as a login via Google is offered and selected by the user, the data required for authentication is exchanged between us and Google. For users in the European Economic Area, the service is provided by Google Ireland Limited, Ireland. Processing by Google LLC in the USA may take place. Use of the Google login is voluntary; login without Google remains possible. Further information is contained in Google's privacy policy. For transfers to third countries, see Section 15.
7. Contract processing, billing and payment
(1) To process paid subscriptions, add-ons, marketplace purchases and other chargeable services, we process the contract, billing and payment data required for this purpose, in particular selected services, billing period, amount, currency, payment status, invoicing data and Stripe-related customer, subscription, payment and invoice identifiers. The legal basis is Art. 6(1)(b) GDPR and, for statutory retention obligations, Art. 6(1)(c) GDPR.
(2) Payment processing takes place via Stripe. For users in the European Economic Area, the service is provided by Stripe Payments Europe, Limited, Ireland; processing by affiliated Stripe companies, in particular Stripe, Inc. in the USA, may take place. Depending on the transaction, payment data, payment method information, billing address, tax data, amount, currency and payment status are transmitted to Stripe or collected directly by Stripe. Complete card data is not stored by us. Further information is contained in Stripe's privacy notices. For transfers to third countries, see Section 15.
8. Image search and monitoring
(1) If users upload image files, we process the image files and the technical image and management data required for upload, storage, display, management, duplicate detection, image search and monitoring. This may also include image versions derived from the image files.
(2) Embedded GPS and location data is removed upon upload and is not permanently stored in the Platform.
(3) For the technical web location search, we use Google Cloud Vision API Web Detection (WEB_DETECTION). In doing so, the image file is transmitted to Google Cloud Vision in order to identify publicly accessible web references, matching or similar images, page references and comparable web locations. For users in the European Economic Area, the service is provided by Google Cloud EMEA Limited, Ireland; processing by Google LLC in the USA may take place. Further information is contained in the Google Cloud privacy and contract information. For transfers to third countries, see Section 15.
(4) We process the search-run, hit and web-location data arising in the course of the image search insofar as this is necessary for the provision, display, management and quota allocation of the image search.
(5) The legal basis is Art. 6(1)(b) GDPR. Insofar as technical security, evidence or abuse-prevention interests are concerned, we additionally base the processing on Art. 6(1)(f) GDPR.
9. Marketplace purchases
(1) For purchases via the marketplace, we process the buyer, order, licence and billing data required for conclusion of contract, licence provision, payment, settlement, invoicing and evidence. This includes in particular name, email address, company, invoicing and tax data where applicable, purchased content, licence conditions, order and payment status and associated receipt and invoice data.
(2) Insofar as licence terms are electronically signed or confirmed in the marketplace, we process the signature and evidence data required for this purpose, in particular signature data, time, language/version and assignment to the order or licence.
(3) For buyers, we provide an access-restricted area or time-limited access links. For this purpose, we process email address, order and licence assignments, access tokens and expiry time. The access serves the retrieval of acquired licences, contract documents, invoices and downloads.
(4) The legal basis is Art. 6(1)(b) GDPR. For statutory retention obligations, in particular retention under commercial and tax law, the legal basis is Art. 6(1)(c) GDPR. For evidence, security and abuse-prevention interests, we additionally base the processing on Art. 6(1)(f) GDPR.
(5) We are the controller for the operation of the marketplace, checkout, payment and settlement processes, buyer access and Platform evidence. The respective selling user or licensor is the controller for their licence relationship with the buyer and the further use of the buyer data in their seller or licence area. Insofar as we process data for the selling user within the Platform, Section 12 applies in addition.
(6) For marketplace sellers, we also process the identity, company, tax and payout data and their settlement preferences required for participation, tax classification, settlement and payout. Stripe Connect onboarding under Section 13(3) is also required without participation in the referral program. If the same user participates in both roles, the Connect account, tax master data and set-off and payout preferences are shared. The legal bases in paragraph 4 apply.
10. Contact, sales and email communication
(1) If you contact us, take part in sales or information meetings, or we maintain business contacts with potential B2B customers, we process the contact, company, communication and case data required for this purpose. The legal basis is Art. 6(1)(b) GDPR insofar as enquiries or pre-contractual measures are concerned, and Art. 6(1)(f) GDPR for B2B contact management, direct approach, documentation and follow-up.
(2) We send emails insofar as this is necessary for the provision of the Platform, account and security functions, contract processing, subscriptions, payments, marketplace purchases, licence processes, support and legally or contractually required notices. In doing so, we process in particular recipient address, sender details, subject, content, time of dispatch, dispatch status and associated case identifiers.
(3) Automated Platform emails are sent via our own SMTP server. For individual communication with United Creatives, in particular contact, sales, contract and support communication, Microsoft 365 may be used as email infrastructure.
(4) We send promotional emails only on the basis of consent or insofar as this is legally permissible. Consent given can be withdrawn at any time with effect for the future; processing for direct marketing purposes on the basis of legitimate interests can be objected to at any time. Insofar as external dispatch or marketing service providers are used for this purpose, we provide separate information about this in this privacy policy and, where necessary, as part of the consent.
(5) Insofar as users send or trigger emails to their own customers via the licence tool or customer management, we process this data on the instructions of the user; Section 12 applies in addition.
(6) The legal basis is Art. 6(1)(b) GDPR insofar as the email communication is necessary for the performance of the contract or for the provision of requested functions, Art. 6(1)(c) GDPR in the case of legal obligations, Art. 6(1)(a) GDPR in the case of consent and Art. 6(1)(f) GDPR for operational, sales-related, security-related and evidence-related communication.
(7) For reports of allegedly illegal content, we process the contact details, content information, explanations and confirmed declaration provided in order to review the report, acknowledge its receipt and communicate decisions. The legal basis is Art. 6(1)(c) GDPR in conjunction with the Digital Services Act. The statutory option to submit a report without a name or email address remains available for reports concerning child sexual abuse or sexual exploitation. For technical abuse prevention, see Section 6(3).
11. Support chat
(1) We offer a self-operated support chat (Chatwoot). The chat runs on our own hosting infrastructure in Germany; no transmission to third-party providers or to third countries takes place as a result. When used, the content you submit and – for logged-in users – identifier, name and email address are processed in order to handle your enquiry.
(2) The chat widget is loaded only when you expressly open the chat via the chat button. Without this request, no chat resources are loaded and no chat cookies are set. The legal basis for access to your end device is § 25(2) no. 2 TDDDG (service expressly requested by you).
(3) The legal basis for handling your enquiry is Art. 6(1)(b) GDPR insofar as the enquiry relates to the use of the Platform or a contractual relationship, and Art. 6(1)(f) GDPR for general support and security interests.
12. Customer and licence data, data processing on behalf
(1) Insofar as users have personal data of third parties processed in the licence tool or in customer management, in particular customer, contact, contract, licence, communication, documentation or signature data, the user is the controller and United Creatives is the processor within the meaning of Art. 28 GDPR.
(2) We process this data exclusively on the instructions of the user on the basis of a data processing agreement (DPA).
(3) Data subjects whose data a user processes via the Platform should primarily contact the respective user as controller to exercise their rights.
13. Partner and referral program
(1) When participating in the partner and referral program, we process the personal data that the user provides in the course of participation and that arises during participation, referral attribution, commission calculation, settlement, payout, set-off, evidence and abuse prevention. The legal basis is Art. 6(1)(b) GDPR; insofar as statutory retention or evidence obligations exist, Art. 6(1)(c) GDPR.
(2) If a person follows a referral link, we store a time-limited referral attribution in the browser for 30 days in order to be able to attribute a later registration to the referring user. The legal basis is our legitimate interest in the correct attribution of referrals and in abuse prevention (Art. 6(1)(f) GDPR).
(3) Active participation in the partner and referral program and as a marketplace seller requires Stripe Connect onboarding. For this purpose, we create a Stripe Connect account or start the onboarding and transmit the basic and assignment data required for this to Stripe. The user provides identity, verification, bank and tax data directly to Stripe. Stripe transmits to us the information required for participation, payout, settlement and evidence. The legal basis is Art. 6(1)(b) GDPR and, insofar as legal obligations are concerned, Art. 6(1)(c) GDPR. For transfers to third countries, see Section 15.
(4) To prevent abusive referrals, we check, on the basis of the unambiguous UC user account and referral attribution and the payment, refund, chargeback and cancellation statuses confirmed by Stripe, whether a referral is commissionable under the program terms. Payment method data or identifiers are not used or compared for this check. Different registered user accounts are not treated as identical for this purpose on the basis of identical or similar names, addresses, email addresses or IP addresses. The legal basis is Art. 6(1)(f) GDPR.
14. External recipients and services
(1) We transmit personal data to external recipients only insofar as this is necessary for the purposes described in this privacy policy, a legal obligation exists or consent has been given.
| Recipient / service | Purpose | Note |
|---|---|---|
| IP-Projects GmbH & Co. KG | Hosting, server, network and data centre services for the Platform | see Section 4 |
| Stripe Payments Europe, Limited; affiliated Stripe companies | Payment, settlement and payout processing including Stripe Connect | see Sections 7, 13 and 15 |
| Papoo Software & Media GmbH | Consent management via CCM19 Cloud (processor, hosting in Germany/EU) | see Section 5 |
| Google Cloud EMEA Limited; Google LLC | Google Cloud Vision API Web Detection (WEB_DETECTION) for web location search and monitoring | see Sections 8 and 15 |
| Google Ireland Limited; Google LLC | Google Tag Manager (loaded only after consent, controlled via Consent Mode) and optional login via Google, where offered | see Sections 5, 6 and 15 |
| Microsoft Ireland Operations Limited; affiliated Microsoft companies | Individual email communication with United Creatives, insofar as Microsoft 365 is used for this purpose | see Sections 10 and 15 |
(2) Insofar as external service providers are used as processors, we conclude contracts pursuant to Art. 28 GDPR. Insofar as external recipients bear their own responsibility under data protection law, their privacy notices apply in addition.
15. Transfers to third countries
Processing of personal data outside the EU/EEA may take place in particular in connection with Stripe, Google Cloud Vision API Web Detection (WEB_DETECTION), the optional login via Google, Google Tag Manager and individual email communication via Microsoft 365.
Insofar as the respective recipient is certified under the EU-US Data Privacy Framework, we base the transfer on the adequacy decision of the European Commission for the EU-US Data Privacy Framework (Art. 45 GDPR). Insofar as a transfer cannot, or cannot fully, be based on this, we use appropriate safeguards, in particular the standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR), where applicable including supplementary measures.
Information on the transfer mechanisms used and, where applicable, copies or excerpts of the standard contractual clauses are available via the data protection contact.
Further transfers to third countries take place only insofar as they are described in this privacy policy or are added accordingly before further services are activated.
16. Storage period and deletion
(1) We process personal data only for as long as this is necessary for the respective purposes, statutory retention obligations exist or legitimate security or legal defence interests require further storage.
(2) In particular, the following storage periods apply:
- Account and contract data: for the duration of the user account and the contractual relationship. After account deletion, this data is deleted or anonymised insofar as no statutory retention obligations, open claims or legal defence interests stand in the way.
- Subscription, payment, invoice and tax data: for the duration of contract processing and thereafter in accordance with statutory retention obligations under commercial and tax law, regularly up to 10 years.
- Customer, contact, licence and contract data of the user: until deletion by the user, account deletion or until a legally required deletion applies. Insofar as this data is processed on behalf of the user, the DPA applies in addition.
- Images, search-run, hit and web-location data: for the duration of the provision of the image search and monitoring. After deletion of an image, account deletion or discontinuation of the capacity booked for this purpose, the associated data is deleted or anonymised insofar as no statutory retention obligations or licence, sales, settlement, dispute or legal defence connections stand in the way.
- Excess images upon downgrade or end of an add-on: excess images are no longer monitored from the time the reduction takes effect and do not trigger new search runs. After expiry of the clean-up period governed by the Terms, they are removed from active image management insofar as they are not to be retained separately because of a licence, sales, settlement, dispute or legal defence connection.
- Export files: export files provided remain retrievable for at least 30 calendar days and are subsequently deleted insofar as no legal obligation stands in the way.
- Session and authentication data: regularly up to 30 days; further information on cookies and comparable storage is contained in Section 5.
- Consent cookie and consent evidence: the consent cookie
ucidis stored for 12 months; consent evidence is stored for the period necessary to demonstrate consent, in accordance with the settings stored in CCM19. - Server log files: regularly 7 days, unless security-relevant events, error analysis or legal obligations require longer retention.
- Support enquiries and support chat: for the handling of the enquiry and thereafter insofar as this is necessary for documentation, follow-up, performance of the contract or legal defence.
- Partner and referral program: for the duration of participation and processing of the program. Settlement, payout, set-off and evidence data is stored in accordance with statutory retention obligations. The time-limited referral attribution in the browser is stored for 30 days.
- Signature and licence evidence: for the duration of the demonstrability of the respective licence agreement plus statutory retention periods.
17. Automated decision-making
(1) No decision based solely on automated processing within the meaning of Art. 22 GDPR that produces legal effects concerning data subjects or similarly significantly affects them takes place.
(2) The Platform uses rule-based technical checks, in particular to enforce booked quotas, for access and subscription management, for payment and settlement processing, for security and for abuse prevention. Such checks are based on contractual, technical or security-related criteria and serve the provision and protection of the Platform.
(3) This also includes rule-based checks in the partner and referral program, in particular to determine whether a referral is commissionable under the program terms. In case of questions or objections, the user may contact support.
18. Changes to this privacy policy
(1) We update this privacy policy when our data processing operations, services used, legal bases or statutory information obligations change.
(2) The current version is made available in the Platform and/or on the website. We inform users of material changes in an appropriate manner.
(3) Insofar as a new or changed processing operation requires consent, we obtain it before activating the processing concerned.
Stand (version date of the German original): 11 September 2026
