Privacy Policy
Version 1.0 · As of 30 September 2026
This policy explains what personal data we process, why, on which legal basis and for how long – on our website, when we contact businesses, for customer accounts and billing, and when the configurator runs in a customer’s shop.
1. Controller and contact
Benjamin Luis Alessandro Rüger, trading as SAYNTThe Setting Lab
Selma-Lagerlöf-Straße 22, 81829 München, Germany
E-mail: info@settinglab.com · Phone: +49 176 20842185
We have not appointed a data protection officer because we are not legally required to do so (Art. 37 GDPR, § 38 BDSG). For all data protection matters, please write to the e-mail address above.
2. Overview and roles
- Website visitors of settinglab.com – we are the controller.
- Business contacts and prospects whom we contact or who contact us – we are the controller.
- Customers and their staff using our backend, ordering and paying – we are the controller.
- End customers of our customers who use the configurator in a customer’s shop – the customer (the shop) is the controller and we act as its processor (Art. 28 GDPR). Please see section 11 and the privacy policy of the shop concerned.
3. Hosting, delivery and security of the website
Our website and the configurator are delivered via the network of Cloudflare, Inc. (San Francisco, USA), which we use as hosting provider, content delivery network and protection against attacks (DDoS). When you open a page, your browser necessarily transmits connection data: IP address, date and time, requested address, referrer, browser and operating system. Cloudflare processes this data on our behalf to deliver the pages quickly and securely and to fend off attacks.
Legal basis is our legitimate interest in a secure, stable and fast website (Art. 6 (1) (f) GDPR). We do not use connection data to identify you or to build profiles. Technical logs available to us are deleted after 30 days at the latest, unless an individual incident requires longer storage for evidence. For the transfer to the USA see section 13.
4. Fonts and program libraries
Fonts and program libraries (such as the 3D library used by the configurator) are hosted on our own infrastructure. When you visit our website, no connection is established to external font or script servers such as Google Fonts or public CDNs.
5. Cookies, local storage and analytics
Our website does not use tracking or marketing cookies, analytics tools, advertising pixels or social media plugins. We therefore do not display a cookie banner.
We only store or read information on your device where this is strictly necessary to provide a function you have explicitly requested (§ 25 (2) no. 2 TDDDG):
- Saved designs in the demo configurator are stored in your browser’s local storage only when you click “save”. They stay on your device and are not transmitted to us. You can delete them at any time in the configurator or via your browser settings.
- Login session in the customer backend (see section 8): the authentication service stores a session token in your browser so that you stay logged in. It is deleted when you log out.
Where personal data is processed in connection with such storage, the legal basis is Art. 6 (1) (b) GDPR (providing the requested function) or Art. 6 (1) (f) GDPR (secure operation).
6. Demo configurator on this website
The configurator on our website runs in your browser. Your design choices (for example teeth, style, metal) can be encoded in the page address so that you can share a link; this contains no personal data. The configurator does not transmit your design to us unless you actively send it to us, for example by e-mail.
7. Contacting us
If you contact us by e-mail or phone, we process your details (name, e-mail address, company, phone number, content of your message) to answer your enquiry and, where applicable, to prepare a contract. Legal basis is Art. 6 (1) (b) GDPR if your enquiry relates to a contract, otherwise our legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR). Our e-mail is hosted by Google Cloud EMEA Limited (Dublin, Ireland) as part of Google Workspace; see section 13 for possible access from the USA.
We delete enquiries when they have been dealt with and no further contact is expected, at the latest after 12 months, unless statutory retention periods apply (commercial letters: 6 years, § 147 AO).
8. Customer accounts and backend
When a business subscribes, we create accounts for the backend. We process: name, business e-mail address, company, role, assigned brand (tenant), password (stored only as a cryptographic hash by the authentication service), login times, IP address and device information for security purposes, and the settings and files you upload (logo, colours, catalog, prices, domains).
We use Firebase services of Google (Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase) provided by Google Ireland Limited / Google Cloud EMEA Limited, Dublin, Ireland. Data is stored in the region [Firestore/Storage region, e.g. europe-west3 (Frankfurt)]; access by Google LLC in the USA cannot be excluded (section 13). Accounts are created only after a paid order – there is no open registration.
Legal basis is the performance of the contract with our customer (Art. 6 (1) (b) GDPR); for staff of our customers who are not themselves party to the contract, our legitimate interest and that of our customer in providing the contractually agreed accounts (Art. 6 (1) (f) GDPR); for security logs, our legitimate interest in protecting the service (Art. 6 (1) (f) GDPR). Account data is deleted after the end of the contract and the data retrieval period (see section 17 of our Terms); security logs after 30 days at the latest.
9. Orders, payment and invoicing
Subscriptions are ordered and paid via Stripe. For customers outside North and South America, the contracting Stripe entity is Stripe Payments Europe, Limited (Dublin, Ireland). Stripe receives the data required for the payment: company name, name of the ordering person, e-mail address, billing address, VAT ID, payment details and transaction data. We do not receive full card numbers. Stripe processes certain data as an independent controller (for example for fraud prevention and to comply with financial regulation) and otherwise as our processor. When you use the checkout, Stripe may set cookies required for payment security on its own pages; Stripe’s privacy policy applies to these.
Legal bases are Art. 6 (1) (b) GDPR (performance of the contract) and Art. 6 (1) (c) GDPR (tax and commercial law obligations). We keep invoices and accounting records for the statutory periods (up to 10 years under § 147 AO, depending on the type of document).
10. Business outreach by e-mail
We contact grillz and jewellery businesses in selected countries by e-mail to introduce our product. We do not send such e-mails to recipients in Germany.
What we process: company name, publicly listed business e-mail address, name and role of a contact person where published by the company, website, public social media business profile, city and country, and the history of our correspondence. Source: publicly accessible sources, in particular the company’s own website and public business profiles. We do not buy address lists and do not use private e-mail addresses.
Purpose and legal basis: direct marketing to businesses whose activity matches our product, based on our legitimate interest (Art. 6 (1) (f) GDPR, recital 47). We limit ourselves to a small number of messages, identify ourselves clearly and include an easy way to object in every e-mail.
Tool: we send outreach e-mails with Instantly (Foo Monk, LLC dba Instantly.ai, Sheridan, Wyoming, USA) as our processor, from a separate outreach domain (thesettinglab.com). We do not use open or click tracking in these e-mails. See section 13 for the transfer to the USA.
Retention: if you do not reply, we delete your data no later than 12 months after our last message. If you object, we store your e-mail address and company name in a blocking list so that we do not contact you again (Art. 6 (1) (c) and (f) GDPR); this list is used for no other purpose.
Right to object: you can object to the use of your data for direct marketing at any time without giving reasons – by replying “unsubscribe” or by writing to info@settinglab.com. We will then no longer use your data for this purpose (Art. 21 (2) and (3) GDPR).
11. End customers using the configurator in a shop
If you use the configurator on the website of one of our customers (a grillz or jewellery brand), that brand is responsible for the processing of your data. We process data such as your configurations, enquiries you send (for example name, e-mail address, message), an end customer account if the brand offers one, and usage statistics on the brand’s behalf and according to its instructions (Art. 28 GDPR). Please contact the brand to exercise your rights; if you contact us, we will forward your request to the brand.
Separately, we process technical connection data (IP address, calling domain, time, license identifier) when the configurator loads, to check that the embedding domain holds a valid license, to deliver protected 3D files via short-lived signed links and to prevent misuse. For this limited purpose we act on the basis of our legitimate interest in protecting our service and intellectual property (Art. 6 (1) (f) GDPR). These logs are not linked to other data, are not used for profiling and are deleted after 30 days at the latest.
12. Recipients
We pass on personal data only to service providers that support us in operating our business and that are bound by contract (in particular hosting, database, e-mail, payment and outreach services), to authorities where we are legally obliged, and to advisers bound by professional secrecy (for example our tax adviser). A list of our service providers is available on our subprocessor page. We do not sell personal data.
13. Transfers to countries outside the EU/EEA
Some of our service providers are based in the USA or may access data from there (Cloudflare, Google, Stripe, Instantly). For the USA, the European Commission has adopted an adequacy decision for companies certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Where a provider is certified, transfers are based on this decision. In addition, or where a provider is not certified, we have concluded the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) with the provider. You can request a copy of the relevant safeguards from us. For transfers to the United Kingdom, an adequacy decision of the European Commission applies.
14. Retention overview
| Data | Retention |
|---|---|
| Technical logs (website, license checks) | max. 30 days |
| Enquiries by e-mail | until dealt with, max. 12 months; commercial letters 6 years |
| Outreach contacts without reply | max. 12 months after last message |
| Blocking list after objection | as long as needed to respect the objection |
| Customer accounts and backend content | term of contract + data retrieval period (min. 30 days), then deletion; backups max. 35 days later |
| Invoices and accounting records | statutory periods (up to 10 years, § 147 AO) |
15. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7 (3)).
Right to object (Art. 21 GDPR): where we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. You can object to direct marketing at any time without giving reasons.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. If you are in the United Kingdom, you can also contact the Information Commissioner’s Office (ICO).
16. Obligation to provide data, automated decisions, security
You are not obliged to provide personal data. Without the data needed to conclude and perform a contract, however, we cannot provide our services. We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. All connections to our website and services are encrypted (TLS).
17. Changes to this policy
We update this policy when our services or the law change. The current version is always available on this page; the version number and date are shown at the top.