Transparent, explained.
How we process personal data on studio.pemediacorp.com. Structured along Articles 13 and 14 GDPR. The German version is the legally binding one.
Stand: 18 August 2026
1. Controller
Plößl & Ehrl Vertriebs UG (limited liability)Boschstr. 4, 82178 Puchheim, Germany
Email: support@pemediacorp.com
Authorised representatives: Luis Maximilian Plößl, Lorenz Ehrl
2. Data protection officer
We are not obliged to appoint a data protection officer (§ 38 BDSG) because fewer than twenty persons are permanently engaged in the automated processing of personal data at our company. For data protection questions, please contact support@pemediacorp.com.
3. Your rights
You have the right at any time to:
- Access the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consents granted (Art. 7 (3) GDPR)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR)
Competent supervisory authority for our registered office: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
4. Specific processing activities
4.1 Account creation and management
Data: email address, password (Argon2id-hashed), registration timestamp.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual steps and contract performance).
Recipients: Processor ZAP-Hosting GmbH, Gunzenhausen (EU). A data processing agreement is in place.
Retention: Until you delete your account. If you delete it at /en/account/privacy, we remove the account, the profile, all sessions and the logged cookie consents immediately and without a recovery window. There is no bin from which a deleted account could be restored. Statutory retention obligations for invoice-relevant data (e.g. § 147 of the German Fiscal Code) remain unaffected; that data sits in our invoice records and at Stripe.
4.1a Passkeys (optional, WebAuthn)
Data: If you create a passkey in your account, we store the public key, the passkey identifier, a signature counter, technical attributes (device type, whether the passkey is synced via a password manager, the authenticator vendor identifier), the name you chose, and the timestamps of creation and last use. Biometric data (fingerprint, face) never leaves your device and is not processed by us; we only receive the signature.
Legal basis: Art. 6 (1) (b) GDPR (contract performance: secure sign-in to the account). Use is optional; password and email code remain available.
Recipients: None. The data sits in our account database at the processor ZAP-Hosting GmbH (EU).
Retention: Until you remove the passkey at /en/account/security or delete your account. Short-lived sign-in challenges are deleted after five minutes or after a single verification.
4.1b Security notices by email
Trigger: We send you a message from no-reply@pemediacorp.com when a wrong password was entered three times in a row for your account, and when the password of your account was changed. This way you notice foreign access attempts quickly.
Data: time, device and browser (from the user agent), IP address of the request and an approximate location estimated from it (city, region, country). The estimate runs on our server against a locally stored database (DB-IP City Lite); the IP address is not sent to any third party for this. Time, device, IP and location are only written into the email and not stored. What is stored per account is merely a counter of failed sign-ins with timestamps; it is deleted on a successful sign-in and after a password change.
Legal basis: Art. 6 (1) (b) GDPR (account security as part of contract performance) and Art. 6 (1) (f) in conjunction with Art. 32 GDPR (legitimate interest in preventing account takeovers; such notices are standard practice and to be expected by you).
Recipients: Sending runs through our business mailbox (Google Workspace, Google Ireland Limited, processing on our behalf with standard contractual clauses and the Data Privacy Framework for group access from the USA). The location database comes from DB-IP (db-ip.com) but runs locally; no data flows there.
Retention: the counter until the next successful sign-in, at the latest together with the account. The email sits in your inbox.
4.2 Email verification (six-digit code)
Data: email address, short-lived verification code (10 min TTL), send status.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual steps) and Art. 6 (1) (f) GDPR (legitimate interest: confirmation of email ownership).
Recipients: Sending runs through our business mailbox at Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing on our behalf under Art. 28 GDPR with standard contractual clauses and the Data Privacy Framework for group access from the USA). The code is part of the email text and therefore passes through this service; it is generated and verified only on our server.
Retention: Codes are deleted immediately after verification or expiry. Mail send logs 30 days.
4.3 Session management via HttpOnly cookie
Data: Opaque session token in the cookie psp_session. Not identifying personal data without database access.
Legal basis: Art. 6 (1) (b) GDPR and § 25 (2) (2) TDDDG (strictly necessary).
Retention: At most 14 days; after 24 hours without activity the session ends earlier by itself. Deleted immediately on logout.
4.4 License management for Pemediacorp software
Data: license key, device ID (hash of hardware fingerprint), last activation IP, activation timestamp.
Legal basis: Art. 6 (1) (b) GDPR (contract performance).
Recipients: Our own license server (lizenz.pemediacorp.com) on hosting infrastructure in the EU.
Retention: During the contract term. Devices that have not reported in for 90 days are deactivated automatically. After the license ends we pseudonymise the license record on your request; the device hash remains in order to prevent double activations. Automatic pseudonymisation after a fixed period is not yet in place.
Deletion of the Studio account: The license is independent of the Studio account; the desktop app only needs the license key. If you delete your account, the license therefore stays valid until the end of the period you have already paid for and then expires as normal. The retention periods stated above are unchanged.
4.5 Payment via Stripe
For the actual payment we redirect you to a checkout page hosted by Stripe. You enter your payment details there; they never reach our servers.
Data: name, address, email, payment method data (collected by Stripe itself; we only see a masked representation), invoice amount, plus confirmations regarding terms and withdrawal notice with timestamp (as metadata of the payment session as evidence of pre-contractual conduct).
Legal basis: Art. 6 (1) (b) GDPR (contract performance); for evidence preservation additionally Art. 6 (1) (f) GDPR together with Art. 5 (2) GDPR (accountability).
Recipients: for EU customers Stripe Payments Europe Ltd., Dublin, Ireland. For internal corporate data flows Stripe Inc., San Francisco, USA (DPF-certified).
Role: Stripe is an independent controller for payment processing within its own responsibility under Art. 4 (7) GDPR (fraud prevention, anti-money-laundering compliance, own customer records). For the processing attributable to us, a data processing agreement under Art. 28 GDPR is in place (Stripe DPA).
Third-country transfer: Yes. Safeguarded via DPF and SCCs.
Retention: Invoice data 10 years under § 147 of the German Fiscal Code.
Account deletion while a subscription is running: If you delete your Studio account under /en/account/privacy while a subscription is still running, we automatically cancel that subscription at the end of the billing period you have already paid for. A monthly plan therefore ends at the end of the current month, an annual plan at the end of the current year. Until then your license stays usable and nothing further is charged. Account, profile, cookie consents and all sessions are deleted immediately. Only the deletion of your customer record at Stripe is deferred, and only until the end of that term: until then this data is needed to perform the still running contract and to bill it (Art. 6 (1) (b) GDPR). After that we delete the customer record at Stripe. This does not affect the statutory retention periods for invoice data (§ 147 German Fiscal Code, §§ 14, 14a German VAT Act), which Stripe has to meet additionally as its own controller.
4.6 Account profile data (name, address, company, VAT ID, phone)
If you have an account with us, you can store your billing address and personal data under /en/account/profile and /en/account/billing.
Data: first name, last name, optional company, optional VAT ID, street and house number, postal code, city, country, optional phone, Stripe customer ID for linking.
Legal basis: Art. 6 (1) (b) GDPR (contract performance) and Art. 6 (1) (c) GDPR in conjunction with §§ 14, 14a German VAT Act and § 147 German Fiscal Code (tax retention obligations for invoicing).
Recipients: ZAP-Hosting GmbH (EU, processor) for data storage. Additionally, name and address are transmitted to Stripe Payments Europe Ltd. (Ireland) on change so that your invoices can be issued correctly.
Retention: During the contract term. Profile data that is not invoice-relevant is deleted immediately together with the account. Invoice-relevant data is subject to the ten-year retention under § 147 of the German Fiscal Code; it is held in our invoice records and at Stripe, no longer in your account.
4.7 Reach measurement with Umami (analytics.pemediacorp.com)
With your consent (cookie banner, "Statistics" category), we operate our own Umami server for reach measurement. Umami is open source (MIT licence) and runs exclusively on our hosting infrastructure in the EU. No transfer to third parties takes place.
Data: pseudonymous visitor ID (Umami), IP hash (with a salt that rotates daily; the raw value is never stored), user agent, referrer, page URL, time on page. With your consent we also set the cookie studio_session_id (random UUID, 30 days) to link several visits from the same browser.
Custom events: We measure selected conversion events: tier_clicked, checkout_started, checkout_completed, signup_completed, psp_video_played. They help us improve the product offer. They are not linked to your user ID.
Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent). You can withdraw your consent at any time without affecting the lawfulness of the processing carried out beforehand, via the footer link "Cookies" or at /en/account/cookies.
Recipients: None. The Umami server runs on our own infrastructure.
Retention: Aggregated analytics data 12 months, IP hash 1 day, session cookie 30 days.
4.8 Cookie consent management and accountability
We log your cookie choice in order to meet our accountability obligation under Art. 7 (1) GDPR.
Data: anonymous browser UUID (studio_anon_id) or your user ID if you are logged in; chosen categories (necessary, functional, analytics, marketing); consent version; IP hash (salt rotating daily); user agent; timestamp.
Legal basis: Art. 6 (1) (c) GDPR together with Art. 7 (1) GDPR (accountability) and § 25 TDDDG.
Recipients: ZAP-Hosting GmbH (EU, processor).
Retention: Active consent plus 3 years to defend against possible fine proceedings, then anonymised erasure.
4.9 Server log files
Data: IP address (already anonymised at logging time: last octet set to 0 for IPv4, /48 prefix for IPv6), timestamp, requested URL, referrer, user agent, HTTP status.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest: IT security and error analysis).
Recipients: No disclosure, internal only.
Retention: 14 days rolling.
If the website shows the operational status of our own services, for example whether the license server is reachable, that query runs strictly between our own servers. No data about you is transmitted to third parties; only the log entries described here are created.
4.10 Marketing pixels (only after explicit consent)
With your consent to the "Marketing" category, we load third-party tracking pixels to measure the success of our ads and build audience lists for remarketing. Without your consent, neither scripts nor data are transmitted to these providers. You can change or withdraw your choice anytime under /en/account/cookies or via the footer link "Cookie settings".
Common to all four pixels: Legal basis is Art. 6 (1) (a) GDPR and § 25 (1) TDDDG (consent). Conversion value (tier price in EUR) is transmitted on successful purchase. We only load the pixels for which an identifier is configured on our side; if no identifier is configured for a provider, its script is not loaded even after your consent.
Third-country transfer: All four providers also process data in the USA. We base these transfers on Standard Contractual Clauses under Art. 46 (2) (c) GDPR. Where a provider is additionally listed by the US Department of Commerce under the EU-US Data Privacy Framework, the adequacy decision under Art. 45 GDPR applies to that provider in addition. You can look up each provider's entry yourself at dataprivacyframework.gov.
Effect of your withdrawal: If you withdraw the "Marketing" category, we delete those providers' cookies that were set on our own domain and reload the page so that the scripts already loaded stop running. Cookies a provider has set on its own domain cannot be deleted by us; for those, please contact the respective provider whose privacy policy is linked below.
4.10.1 Google Ads (gtag.js)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (EU data flows); Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (corporate data).
Data: Pseudonymous cookie ID, IP address (Google anonymises the last octet), click source URL, browser/device data, conversion events (purchase incl. value in EUR and tier).
Processing: Data processing agreement under Art. 28 GDPR via Google's "Data Processing Terms for Advertising". Retention 30 days to 18 months depending on campaign configuration.
4.10.2 Meta Pixel (Facebook + Instagram)
Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; Meta Platforms Inc., USA.
Data: Pseudonymous browser ID, IP address, page interactions (PageView, Purchase with value in EUR and tier label). Meta links these to your Facebook or Instagram account if you are logged in there.
Role: Joint controllers (Art. 26 GDPR) for the collection via the pixel. The agreement is the Meta Controller Addendum. Retention 180 days rolling (Meta default).
4.10.3 LinkedIn Insight Tag
Provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; LinkedIn Corporation, USA (Microsoft subsidiary).
Data: Pseudonymous cookie ID, IP address, page URL, timestamp, browser/device data, conversion events. For logged-in LinkedIn users, linking to the LinkedIn profile is possible.
Retention: 90 days for pixel data, 180 days for Matched Audience lists (LinkedIn default).
4.10.4 Reddit Pixel
Provider: Reddit, Inc., 548 Market St #16093, San Francisco, CA 94104, USA.
Third-country transfer: We base the transfer to Reddit on Standard Contractual Clauses under Art. 46 (2) (c) GDPR. For Reddit we do not rely on a listing under the EU-US Data Privacy Framework.
Data: Pseudonymous browser ID, IP address, page URL, timestamp, browser/device data, PageVisit and Purchase events. For logged-in Reddit users, linking to the Reddit profile is possible.
Retention: 180 days for pixel data (Reddit default).
4.11 Protection against automated requests (Cloudflare Turnstile)
On forms that attract abuse (login, sign-up, password reset, email verification, launch notification) we use Cloudflare Turnstile. Turnstile checks in the background whether the request comes from a human.
Provider: Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany for data subjects in the EEA; technically involved is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA.
Data: When the widget loads, your browser connects to challenges.cloudflare.com. This involves your IP address, browser and operating system details and interaction characteristics from which Cloudflare forms its verdict. Our server redeems the resulting token with Cloudflare; we transmit the token, not your form entries.
Cookies: We run Turnstile without pre-clearance. In that mode Turnstile neither sets nor reads a cookie of its own, so consent under § 25 (1) TDDDG is not required.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is protecting our forms and mail delivery paths from automated abuse. Without it, mass sign-ups and mail sent to third parties from our address would be possible.
Third-country transfer: Transfer to the USA is possible, safeguarded by the EU-US Data Privacy Framework adequacy decision and by Standard Contractual Clauses under Art. 46 GDPR.
Retention: The token is valid for 300 seconds and can be redeemed once. Retention at Cloudflare follows their privacy policy.
4.12 Launch notification (coming-soon form)
On the home page you can leave your email address to be notified once, as soon as a product becomes available.
Data: email address, timestamp and the IP address of the submitting connection. The entries are currently written to our server log and evaluated there; a separate mailing database does not yet exist.
Legal basis: Art. 6 (1) (a) GDPR (consent), which you give by submitting the form. For logging the IP address additionally Art. 6 (1) (f) GDPR (legitimate interest in abuse prevention).
Recipients: ZAP-Hosting GmbH (EU, processor). No disclosure to third parties, no newsletter service provider.
Retention: Until the single notification is sent or until you withdraw your consent, at most twelve months. The IP address is deleted when the server log expires after 14 days.
Withdrawal: Informally to support@pemediacorp.com. The lawfulness of processing carried out beforehand remains unaffected.
4.13 Cancellations via the cancellation button
At /en/kuendigen you can cancel your subscription without logging in (§ 312k BGB).
Data: type of cancellation, the stated reason in case of an extraordinary cancellation, your name (voluntary), your email address, optionally a license key or invoice number, the requested termination date, your free-text message and the time of receipt.
Legal basis: Art. 6 (1) (b) GDPR (performance of the contract) and Art. 6 (1) (c) GDPR in conjunction with § 312k (4) BGB, which obliges us to confirm and document receipt.
Recipients: Our own license server (lizenz.pemediacorp.com) on hosting infrastructure in the EU, which sends the confirmation email. No disclosure to third parties.
Retention: The record of receipt is kept for three years so that we can evidence receipt and timing of the cancellation. Invoice-relevant data remains subject to § 147 of the German Fiscal Code.
4.14 Log of license operations (audit log)
Our license server logs the operations performed on a license so that we can trace activations and detect misuse.
Data: type of operation (for example activation, deactivation, validation, denied activation), the first eight characters of the license key (the full key is not logged), device ID, IP address, user agent, timestamp and a short note about the operation.
Legal basis: Art. 6 (1) (b) GDPR (contract performance, because the license is bound to one device) and Art. 6 (1) (f) GDPR (legitimate interest in detecting abusive multi-use) together with Art. 32 GDPR.
Recipients: None. The log sits on our own license server in the EU and is readable only through a protected administration access.
Retention: For the duration of the license relationship. After that we delete the entries as soon as they are no longer needed for abuse prevention and evidence. Automatic deletion after a fixed period is currently being set up; until then we delete on request unless evidence obligations require otherwise.
4.15 Data processing inside the Preview Studio Pro application
This section describes what the Preview Studio Pro application on your computer transmits. The sections above cover the website, this one covers the application.
(1) Activation. When you enter the license key, the application transmits the following to our license server: the license key, a device fingerprint, the device name (computer name and operating system) and the platform. The fingerprint is a SHA-256 hash of the operating system device UUID (macOS IOPlatformUUID, Windows MachineGuid), the CPU designation and a fixed additional value. The underlying values are neither transmitted in clear text nor stored. The server additionally logs the IP address and the time.
Purpose: license check and device binding.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
Recipients: our license server in Germany, running on servers of ZAP-Hosting GmbH as a processor.
(2) Recurring license confirmation. The application confirms the license online at regular intervals, about every 24 hours while a connection exists. It transmits the license key and the fingerprint hash. Without an internet connection the application stays usable for up to seven further days; after that a single connection is needed. Legal basis and recipients as under (1).
(3) Deactivation. When you release a device, the application transmits the license key and the fingerprint hash. Legal basis and recipients as under (1).
(4) Update check. The application fetches the update manifest from lizenz.pemediacorp.com (Tauri updater). This technically involves the IP address and the application identifier (user agent); when calling the channel /api/updates/check it also sends the installed version and the platform. No further payload is transmitted.
Legal basis: Art. 6 (1) (b) GDPR (supply of updates, § 327f BGB).
Recipients: as under (1).
(5) Cloud AI (optional). The connection to Claude (Anthropic), Gemini (Google) or Codex GPT (OpenAI) only works with your own API key, which you obtain from the provider yourself and store in the application. If you use it, the code in question, your selection and the chat history go directly from the application to the provider you picked. No server of ours is involved and we do not see this content. For that transfer you are the provider's own contractual partner; their terms and their privacy notices apply, including a transfer to the USA. Your API keys are held in the macOS keychain or the Windows Credential Manager and are never transmitted to us.
(6) Local AI (optional). To run local models, the application downloads llama.cpp from the releases at github.com/ggml-org/llama.cpp and model files from huggingface.co, on your request. Those providers see your IP address in the process. No content from your projects is transmitted; the models then run on your own machine.
(7) Data stored locally. Chat histories, session recovery and settings live in your user profile (on macOS and Linux in ~/.psp, on Windows in the application data). They do not leave your computer. The application collects no telemetry, no usage statistics, and sends no automatic crash reports.
(8) Storage periods. We keep activation data until the device is released or the license ends; after that we pseudonymise the record on your request. Invoice data is retained for ten years under § 147 AO and § 14b UStG.
(9) Your rights. Access, rectification, erasure, restriction, data portability, objection and the right to lodge a complaint with a supervisory authority apply to these processing activities as well. The details and the competent authority are in section 3.
5. Overview of cookies and browser storage in use
We use the following cookies and browser storage mechanisms:
psp_session: HttpOnly session cookie after login. Strictly necessary (§ 25 (2) (2) TDDDG). Lifetime at most 14 days; after 24 hours without activity the session ends earlier.studio_consent_v1: stores your cookie choice. Strictly necessary (§ 25 (2) (2) TDDDG). Lifetime 12 months.studio_anon_id: anonymous browser UUID linking your cookie choice in the audit log. Strictly necessary (Art. 7 (1) GDPR). Lifetime 24 months.studio_session_id: analytics session cookie for Umami, set only after your consent in the "Statistics" category. Lifetime 30 days.- Marketing pixels: Google, Meta, LinkedIn and Reddit each set their own cookies as soon as you consent to the "Marketing" category. Without your consent, none of their scripts is loaded and no cookie is set. On our own domain these are
_fbpand_fbc(Meta),_gcl_au,_gcl_aw,_gcl_dc,_gac_*,_ga,_ga_*and_gid(Google),li_sugrandli_gc(LinkedIn), and_rdt_uuidand_rdt_em(Reddit). Their lifetime is set by the respective provider and stated in its privacy policy linked under 4.10. If you withdraw the category, we delete these cookies and reload the page. Cookies a provider has set on its own domain cannot be deleted by us. Details are in section 4.10 above. - Cloudflare Turnstile runs without pre-clearance. In that mode Turnstile neither sets nor reads a cookie (see 4.11).
- Stripe sets its own cookies on the hosted checkout domain
checkout.stripe.comfor payment processing and bot detection. Those are governed by Stripe's privacy policy and do not apply to our domain.
We currently set no functional cookies. The category still appears in the selection dialog so that you can opt out in advance if we add a convenience feature later.
You can change or fully withdraw your cookie choice at any time via the footer link "Cookie settings" or at /en/account/cookies.
6. Fonts (self-hosted)
We use the typefaces Instrument Sans, Bricolage Grotesque and JetBrains Mono. They are served exclusively from our own server (build-time bundling via Next.js). No connection to Google Fonts takes place.
7. Contact by email
If you contact us by email, we process your email address and the content of your message in order to handle your enquiry. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in communication). Retention: until the conversation is concluded, then the retention periods under commercial law apply.
8. Automated decision-making
We do not carry out any solely automated decisions within the meaning of Art. 22 GDPR, and no profiling within the meaning of Art. 4 (4) GDPR. Marketing pixels are used only after your explicit consent, for aggregated reach and conversion measurement, and never to make an automated decision about you. Stripe may perform its own fraud-prevention checks; this falls under Stripe's own controller responsibility.
9. Changes to this policy
We may amend this privacy policy from time to time to reflect changes in our processing activities or legal requirements. The current version is always available at this page; significant changes will be communicated separately to logged-in users.