Data processing and technical measures
This page describes how KONTRIB processes personal data on behalf of its customers. The full data processing agreement under Art. 28 GDPR is provided with the contract and can be requested in advance: mario@kaih.io. The German version is authoritative.
Roles
The customer is the controller for the data of its website visitors and orders. KAIH UG (haftungsbeschränkt) is the processor. Where agencies use KONTRIB for their clients, the agency is the processor of the advertiser and KAIH UG is the sub-processor.
Subject matter and data categories
- Website usage data: page views, events, referrer, UTM parameters, click IDs, coarse geo information from the CloudFront header, user agent, consent status
- Pseudonymous identifiers: random first-party cookie ID (only with ad_storage), session ID, SHA-256 hash of the email address (only with ad_user_data)
- Order and lead data from shop or CRM: order number, status, values, returns, customer segment, email as hash only
- Platform data: cost, impressions and clicks from ad accounts (no personal data)
- Customer user accounts: name, email, role (Amazon Cognito)
Technical and organisational measures
| Area | Measure |
|---|---|
| Location | Exclusively AWS eu-central-1 (Frankfurt). Tag delivery via CloudFront edge locations, storage only in Frankfurt. |
| Consent | Consent Mode v2 with four flags. Without consent no identifier, only aggregated counts. Consent changes take effect immediately. |
| Pseudonymisation | Email addresses are hashed in the collector (SHA-256, normalised); plain text is not stored. IP addresses are not stored in the database. |
| Tenant isolation | Partitioning per tenant and row level security in Postgres. The application connects with a role that only sees the tenant of the signed-in user. |
| Encryption | TLS 1.2+ on all routes, encryption at rest for database, raw data archive and secrets (AWS KMS). |
| Access | Sign-in via Amazon Cognito, roles agency_admin, agency_planner, client_viewer. Administrative access is logged. |
| AI | Claude via Amazon Bedrock in the EU inference profile. Prompts and responses are not stored by AWS and not used for training. The model provider receives no customer data. The AI has read-only SQL access to the respective tenant. |
| Deletion | Raw data is deleted after the agreed period (default 13 months). At contract end, export of all data, then deletion within 30 days. |
| Backups | Automatic database backups with 7 days retention, raw data archive in S3 with versioning. |
Sub-processors
| Company | Purpose | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, streaming, storage, email delivery, AI inference (Amazon Bedrock) | EU, Frankfurt | DPA with EU standard contractual clauses, EU-US Data Privacy Framework |
| Anthropic (Claude model, exclusively via Amazon Bedrock) | Provision of the language model | Executed in the EU by AWS | No data access, no storage, no training |
Additional sub-processors are only engaged after prior notice to the customer with a right to object.
Transfer to advertising platforms
Activation (Google Ads, CM360, Meta in future) sends data only on the customer's instruction and only click IDs, conversion timestamps and values. The customer remains responsible for the legal basis towards the platform. Every activation is disabled by default and tested as a dry run.
Export and return
All tables are available for export as CSV, Excel and JSON at any time. Raw data can be handed over as an archive from S3. There are no lock-in formats.