Legal
Privacy Policy
Last updated: 30 July 2026
This Privacy Policy explains how the Kaleido web application (“Kaleido”, the “Platform”, “we”, “us”) collects, uses and protects personal data. We are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection law.
1. Who we are
Kaleido is published and coordinated by the Development Center of Vojvodina (Razvojni centar Vojvodine, “RCV”), a non-governmental, non-profit organization registered in Serbia (the “Platform Owner”), together with its partner cultural organizations across Europe. RCV is the data controller for the personal data described in this policy.
- Registered address: Fruškogorska 109, 22406 Irig, Vojvodina, Republic of Serbia
- Legal representative: Marko Kelember, President
- Contact: privacy@kaleido-eu.com
For any privacy question or to exercise your rights, contact us at the email above.
2. Who this policy covers
- Visitors — anyone who browses the public site, scans a Kaleido plaque or QR code, and listens to the audio guides. Visitors do not create an account.
- Administrators and partner staff — people from partner organizations who sign in to add and manage location content.
3. What data we collect
Visitors
- Technical data— when you load a page, listen to audio or view a map, your device’s IP address and basic request information (browser type, time of request) are processed in server logs and by the third-party services that deliver those features (see Section 6). This is standard for any website and is used to serve content and keep the Platform secure.
- On-device preferences— your light/dark theme choice and whether you dismissed the “install app” prompt are stored in your browser’s local storage. This information stays on your device and is never sent to us. See the Cookie Policy.
We do not use analytics, advertising, tracking pixels or social-media trackers, and we do not build profiles of visitors.
Administrators and partner staff
- Account and profile data — email address, first and last name, display name, country, city, municipality and phone number.
- Login codes — we send a one-time sign-in code to your email. It is stored only in hashed form and expires within 10 minutes.
- Content you upload — location text, images and generated audio you create for the Platform.
4. Why we process it, and our legal bases
- To operate the Platform (serving pages, audio and maps) — legitimate interest in providing a functioning, secure service.
- To manage administrator accounts and let partners publish content — performance of our agreement with the partner organization and our legitimate interest in running the partnership.
- To secure the Platform and prevent abuse — legitimate interest in security, and compliance with legal obligations where applicable.
5. Cookies and local storage
Kaleido uses only a strictly-necessary sign-in cookie (for administrators) and a small amount of functional on-device storage for visitor preferences. We set no analytics or advertising cookies, so no cookie-consent banner is required. Full details are in the Cookie Policy.
6. Service providers and recipients
We rely on a small number of trusted providers who process data on our behalf:
- Supabase — database, authentication and audio/file storage (hosted in the EU).
- Vercel — application hosting and server logs (hosted in the EU).
- Resend — sends administrator sign-in emails (processes administrator email addresses only).
- Google (Gemini API) — translates and narrates administrator-entered content into audio. Only content text is sent; no visitor data.
- OpenStreetMap and unpkg — provide map tiles and map icons; your IP address is visible to them when a map is displayed.
We do not sell personal data and do not share it with third parties for their own marketing.
7. International transfers
Our database, file storage and application hosting are located in the European Union. Some providers (for example email delivery and the content translation/narration service) may process limited data outside the European Economic Area. Where that happens, the transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
8. How long we keep data
- Administrator profile data — kept while the account is active and deleted within 90 days after the account is closed or the partnership ends.
- Sign-in codes — expire within 10 minutes and are then removed.
- Server logs — retained for up to 90 days for security and troubleshooting, then rotated.
- Uploaded content — kept while published and removed within 90 days of the partnership ending.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing;
- receive your data in a portable format;
- lodge a complaint with a supervisory authority — for visitors in the EU, this is your national data protection authority.
To exercise any of these rights, email privacy@kaleido-eu.com. We will respond within the time limits set by law.
10. Security
We take reasonable technical and organizational measures to protect personal data, including hashing of sign-in codes, encrypted connections and access controls that limit administrator content to its owner.
11. Children
Kaleido is a general-audience cultural and tourism guide and is not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time. The current version is always available on this page, with the “Last updated” date shown above.
13. Contact
Questions about this policy or your personal data: privacy@kaleido-eu.com.