TheSetting Lab Get Started
Legal

Privacy Policy

Version 1.0 · As of 30 September 2026

This policy explains what personal data we process, why, on which legal basis and for how long – on our website, when we contact businesses, for customer accounts and billing, and when the configurator runs in a customer’s shop.

1. Controller and contact

Benjamin Luis Alessandro Rüger, trading as SAYNT
The Setting Lab
Selma-Lagerlöf-Straße 22, 81829 München, Germany
E-mail: info@settinglab.com · Phone: +49 176 20842185

We have not appointed a data protection officer because we are not legally required to do so (Art. 37 GDPR, § 38 BDSG). For all data protection matters, please write to the e-mail address above.

2. Overview and roles

3. Hosting, delivery and security of the website

Our website and the configurator are delivered via the network of Cloudflare, Inc. (San Francisco, USA), which we use as hosting provider, content delivery network and protection against attacks (DDoS). When you open a page, your browser necessarily transmits connection data: IP address, date and time, requested address, referrer, browser and operating system. Cloudflare processes this data on our behalf to deliver the pages quickly and securely and to fend off attacks.

Legal basis is our legitimate interest in a secure, stable and fast website (Art. 6 (1) (f) GDPR). We do not use connection data to identify you or to build profiles. Technical logs available to us are deleted after 30 days at the latest, unless an individual incident requires longer storage for evidence. For the transfer to the USA see section 13.

4. Fonts and program libraries

Fonts and program libraries (such as the 3D library used by the configurator) are hosted on our own infrastructure. When you visit our website, no connection is established to external font or script servers such as Google Fonts or public CDNs.

5. Cookies, local storage and analytics

Our website does not use tracking or marketing cookies, analytics tools, advertising pixels or social media plugins. We therefore do not display a cookie banner.

We only store or read information on your device where this is strictly necessary to provide a function you have explicitly requested (§ 25 (2) no. 2 TDDDG):

Where personal data is processed in connection with such storage, the legal basis is Art. 6 (1) (b) GDPR (providing the requested function) or Art. 6 (1) (f) GDPR (secure operation).

6. Demo configurator on this website

The configurator on our website runs in your browser. Your design choices (for example teeth, style, metal) can be encoded in the page address so that you can share a link; this contains no personal data. The configurator does not transmit your design to us unless you actively send it to us, for example by e-mail.

7. Contacting us

If you contact us by e-mail or phone, we process your details (name, e-mail address, company, phone number, content of your message) to answer your enquiry and, where applicable, to prepare a contract. Legal basis is Art. 6 (1) (b) GDPR if your enquiry relates to a contract, otherwise our legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR). Our e-mail is hosted by Google Cloud EMEA Limited (Dublin, Ireland) as part of Google Workspace; see section 13 for possible access from the USA.

We delete enquiries when they have been dealt with and no further contact is expected, at the latest after 12 months, unless statutory retention periods apply (commercial letters: 6 years, § 147 AO).

8. Customer accounts and backend

When a business subscribes, we create accounts for the backend. We process: name, business e-mail address, company, role, assigned brand (tenant), password (stored only as a cryptographic hash by the authentication service), login times, IP address and device information for security purposes, and the settings and files you upload (logo, colours, catalog, prices, domains).

We use Firebase services of Google (Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase) provided by Google Ireland Limited / Google Cloud EMEA Limited, Dublin, Ireland. Data is stored in the region [Firestore/Storage region, e.g. europe-west3 (Frankfurt)]; access by Google LLC in the USA cannot be excluded (section 13). Accounts are created only after a paid order – there is no open registration.

Legal basis is the performance of the contract with our customer (Art. 6 (1) (b) GDPR); for staff of our customers who are not themselves party to the contract, our legitimate interest and that of our customer in providing the contractually agreed accounts (Art. 6 (1) (f) GDPR); for security logs, our legitimate interest in protecting the service (Art. 6 (1) (f) GDPR). Account data is deleted after the end of the contract and the data retrieval period (see section 17 of our Terms); security logs after 30 days at the latest.

9. Orders, payment and invoicing

Subscriptions are ordered and paid via Stripe. For customers outside North and South America, the contracting Stripe entity is Stripe Payments Europe, Limited (Dublin, Ireland). Stripe receives the data required for the payment: company name, name of the ordering person, e-mail address, billing address, VAT ID, payment details and transaction data. We do not receive full card numbers. Stripe processes certain data as an independent controller (for example for fraud prevention and to comply with financial regulation) and otherwise as our processor. When you use the checkout, Stripe may set cookies required for payment security on its own pages; Stripe’s privacy policy applies to these.

Legal bases are Art. 6 (1) (b) GDPR (performance of the contract) and Art. 6 (1) (c) GDPR (tax and commercial law obligations). We keep invoices and accounting records for the statutory periods (up to 10 years under § 147 AO, depending on the type of document).

10. Business outreach by e-mail

We contact grillz and jewellery businesses in selected countries by e-mail to introduce our product. We do not send such e-mails to recipients in Germany.

What we process: company name, publicly listed business e-mail address, name and role of a contact person where published by the company, website, public social media business profile, city and country, and the history of our correspondence. Source: publicly accessible sources, in particular the company’s own website and public business profiles. We do not buy address lists and do not use private e-mail addresses.

Purpose and legal basis: direct marketing to businesses whose activity matches our product, based on our legitimate interest (Art. 6 (1) (f) GDPR, recital 47). We limit ourselves to a small number of messages, identify ourselves clearly and include an easy way to object in every e-mail.

Tool: we send outreach e-mails with Instantly (Foo Monk, LLC dba Instantly.ai, Sheridan, Wyoming, USA) as our processor, from a separate outreach domain (thesettinglab.com). We do not use open or click tracking in these e-mails. See section 13 for the transfer to the USA.

Retention: if you do not reply, we delete your data no later than 12 months after our last message. If you object, we store your e-mail address and company name in a blocking list so that we do not contact you again (Art. 6 (1) (c) and (f) GDPR); this list is used for no other purpose.

Right to object: you can object to the use of your data for direct marketing at any time without giving reasons – by replying “unsubscribe” or by writing to info@settinglab.com. We will then no longer use your data for this purpose (Art. 21 (2) and (3) GDPR).

11. End customers using the configurator in a shop

If you use the configurator on the website of one of our customers (a grillz or jewellery brand), that brand is responsible for the processing of your data. We process data such as your configurations, enquiries you send (for example name, e-mail address, message), an end customer account if the brand offers one, and usage statistics on the brand’s behalf and according to its instructions (Art. 28 GDPR). Please contact the brand to exercise your rights; if you contact us, we will forward your request to the brand.

Separately, we process technical connection data (IP address, calling domain, time, license identifier) when the configurator loads, to check that the embedding domain holds a valid license, to deliver protected 3D files via short-lived signed links and to prevent misuse. For this limited purpose we act on the basis of our legitimate interest in protecting our service and intellectual property (Art. 6 (1) (f) GDPR). These logs are not linked to other data, are not used for profiling and are deleted after 30 days at the latest.

12. Recipients

We pass on personal data only to service providers that support us in operating our business and that are bound by contract (in particular hosting, database, e-mail, payment and outreach services), to authorities where we are legally obliged, and to advisers bound by professional secrecy (for example our tax adviser). A list of our service providers is available on our subprocessor page. We do not sell personal data.

13. Transfers to countries outside the EU/EEA

Some of our service providers are based in the USA or may access data from there (Cloudflare, Google, Stripe, Instantly). For the USA, the European Commission has adopted an adequacy decision for companies certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). Where a provider is certified, transfers are based on this decision. In addition, or where a provider is not certified, we have concluded the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) with the provider. You can request a copy of the relevant safeguards from us. For transfers to the United Kingdom, an adequacy decision of the European Commission applies.

14. Retention overview

DataRetention
Technical logs (website, license checks)max. 30 days
Enquiries by e-mailuntil dealt with, max. 12 months; commercial letters 6 years
Outreach contacts without replymax. 12 months after last message
Blocking list after objectionas long as needed to respect the objection
Customer accounts and backend contentterm of contract + data retrieval period (min. 30 days), then deletion; backups max. 35 days later
Invoices and accounting recordsstatutory periods (up to 10 years, § 147 AO)

15. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7 (3)).

Right to object (Art. 21 GDPR): where we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. You can object to direct marketing at any time without giving reasons.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. If you are in the United Kingdom, you can also contact the Information Commissioner’s Office (ICO).

16. Obligation to provide data, automated decisions, security

You are not obliged to provide personal data. Without the data needed to conclude and perform a contract, however, we cannot provide our services. We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. All connections to our website and services are encrypted (TLS).

17. Changes to this policy

We update this policy when our services or the law change. The current version is always available on this page; the version number and date are shown at the top.