Effective 5 May 2026 · Last updated 5 May 2026
The data controller responsible for the personal data processed through klauspicks.com is:
ROȘATĂ PATRICIU PERSOANĂ FIZICĂ AUTORIZATĂ
CUI (Tax ID): 47322797
VAT ID: RO49762921
Registration: F40/6397/2022
Address: Bd. Bucureștii Noi 136, et. Parter, ap. 5, Sector 1, București, Romania
Privacy contact: privacy@klauspicks.com
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
We collect different categories of personal data depending on how you interact with the platform:
A. Account Registration
B. Secret Santa Events
C. Wishlists
D. Usage & Analytics Data
E. Support & Contact Communications
F. Guest Visitors (No Account)
We do not sell, rent, or trade your personal data to any third party for their own marketing purposes.
For EU/EEA residents, we process personal data on the following lawful bases under GDPR Article 6:
For participant email addresses entered by event organisers: the organiser acts as a data controller in their own right for the purpose of organising the gift exchange and warrants (per our Terms of Service) that they have a lawful basis for sharing those addresses. KlausPicks processes participant emails as a data processor on behalf of the organiser for the limited purpose of sending the event emails.
We use the following third-party services. Each is bound by a Data Processing Agreement (DPA) and appropriate transfer safeguards where applicable:
Supabase
Purpose: Database, authentication, real-time presence, file storage
Location: EU (AWS eu-central-1, Zurich, Switzerland)
All primary user data is stored within the EU/EEA. Supabase DPA is in place.
Resend
Purpose: Transactional email delivery (Secret Santa reveals, invitations, notifications)
Location: United States
Data transfer covered by Standard Contractual Clauses (SCCs). Resend only processes email addresses and message content strictly for delivery.
Google Analytics 4 / Google Tag Manager
Purpose: Web analytics, traffic analysis, user behaviour measurement
Location: United States
Activated only with user cookie consent. IP anonymisation enabled. Data transfer covered by SCCs and Google's EU-US Data Privacy Framework certification.
Google Search Console / Bing Webmaster Tools
Purpose: Search engine indexing and performance monitoring (no personal user data sent)
Location: United States / Global
No personal data of platform users is shared with these tools.
Buy Me a Coffee
Purpose: Optional voluntary donation processing
Location: United States
An independent third-party platform. Only users who click the donation button interact with Buy Me a Coffee. Their privacy policy governs any data they collect.
We retain personal data only as long as necessary for the stated purpose:
You may request early deletion of your personal data at any time (see Section 8). Note that certain data may be retained beyond the above periods if required by a legal obligation (e.g., Romanian accounting law requires retaining financial records for 10 years).
Your primary data is stored in the European Union (Supabase / AWS eu-central-1, Zurich, Switzerland). Switzerland is recognised by the European Commission as providing an adequate level of data protection.
Some of our processors (Resend, Google) are based in the United States. We ensure appropriate safeguards are in place for any transfers of personal data to these processors, including:
You may request a copy of the relevant transfer safeguards by contacting us at privacy@klauspicks.com.
If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation:
Right of Access (Art. 15)
Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data ('right to be forgotten'), subject to legal retention obligations.
Right to Restriction (Art. 18)
Request that we restrict processing of your data in certain circumstances.
Right to Data Portability (Art. 20)
Receive your personal data in a structured, machine-readable format and, where technically feasible, have it transferred to another controller.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling. You may also object to direct marketing at any time.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@klauspicks.com. We will respond within 30 days. Identity verification may be required before we process the request.
You also have the right to lodge a complaint with the competent supervisory authority. In Romania, this is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Bd. G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, Romania
Website: dataprotection.ro
Phone: +40.318.059.211
The Service is not directed to children under 13 years of age (or 16 for EU residents), and we do not knowingly collect personal data from children below these thresholds without verifiable parental consent.
If you are a parent or guardian and believe your child has provided personal data to us without appropriate consent, please contact us at privacy@klauspicks.com and we will delete that information as soon as practicable.
Note that children may appear as participants in family Secret Santa events organised by an adult. In such cases, the adult organiser is responsible for ensuring that sharing the child's name and email (if applicable) is appropriate and compliant with parental responsibility obligations.
We may update this Privacy Policy periodically. When we do, we will update the "Last updated" date at the top of this page. For material changes that affect your rights, we will make reasonable efforts to notify registered users via email.
Your continued use of the Service after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
For any privacy-related questions, requests, or complaints, please contact our privacy point of contact:
Privacy Contact — KlausPicks
Email: privacy@klauspicks.com
Postal: ROȘATĂ PATRICIU PFA, Bd. Bucureștii Noi 136, et. Parter, ap. 5, Sector 1, București, Romania
Response time: within 30 calendar days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP) — see Section 8 above.