Privacy
Last changed 2026-08-12
This is a draft. It was written alongside the product rather than by a lawyer, and Not important B.V. has not had it reviewed. It is published because it should be possible to read what happens to your data before you hand any over, and because a page that is honestly marked as a draft is more use than an empty page.
Kadrenta is production software for small film and CGI studios, operated by Not important B.V. in the Netherlands. If anything below is wrong, unclear, or does not match what you see the product doing, write to support@kadrenta.com and it will be corrected.
Who is responsible for what
Not important B.V. is the controller for the data of the people who hold a Kadrenta account: your name, your email address, and how you use the product.
For everything a studio puts into Kadrenta — its projects, its shots, its files, and the contact details of its clients and freelancers — the studio is the controller and Not important B.V. is the processor. The studio decides what goes in, who may see it, and how long it stays. If you are a client or a contact of a studio and you want your details changed or removed, the studio is who to ask; we will help them do it, and the tools for it are described below.
There is no data processing agreement on offer yet. That is one of the things this draft is honest about rather than quiet about: it is on the list before anyone pays.
What is collected
Two kinds of thing, and it is worth keeping them apart.
- From you, because you signed up: your name, your email address, whether you have confirmed that address, and your password — stored only as a hash, never as the password. If you upload a profile photo, that too.
- From your browser, because a session has to work: a session record with the address you connected from and the browser you used. It expires after thirty days and is deleted when you sign out or reset your password.
- What your studio puts in: projects, shots, tasks, files, comments, review versions, and an address book of the people the studio works with. Some of those people have no account here and never will — a client who leaves a comment on a review link is recorded by the name they gave.
- What you connect yourself: if you link a Discord account, your Discord id and display name are stored so notifications can reach you. No Discord token is kept. If you connect your own Claude, the calls it makes are logged by name of the tool and nothing else — never the question and never the answer.
- An email address you leave on the front page, if you do, and whether you have confirmed it. Nothing else, and see below for what happens to it.
What is deliberately not collected
There is no analytics on this product. No Google Analytics, no Plausible, no PostHog, no pixel, no tag, no third-party script of any kind. There is nothing to opt out of, which is also why there is no cookie banner.
Where a log is needed, it is built to hold as little as it can. The record of which emails were sent stores a one-way hash of the address rather than the address, and never the subject or the body. The counter that stops password guessing stores a hash of the connecting address rather than the address. The log of what your own Claude asked for stores the name of the tool and nothing about the request.
Cookies
Four, all set by this site itself, all strictly necessary, and none of them used to follow anybody anywhere.
- A session cookie, so you stay signed in. Thirty days.
- A share link cookie, remembering which review links this browser has already typed the passphrase for. Twelve hours. It is not what grants access — the link is checked against the database on every request, so revoking one takes effect immediately.
- A review visitor cookie, so a client's comments on a review link stay attached to them. Twelve hours.
- A view-as cookie, used by a studio administrator checking what somebody else can see. One hour.
Where it is stored
In the European Union, by choice and not by accident.
| What | Where |
|---|---|
| The database | Neon, Frankfurt (Germany). Chosen deliberately; the region cannot be changed afterwards without recreating the project. |
| Files, images and video | Cloudflare R2, with the bucket created under the European Union jurisdiction. That is a commitment at the storage layer that the files do not leave the EU. |
| The application itself | Cloudflare Workers. Code runs at the edge; the data it reads stays in the two places above. |
| Outgoing email | Resend, in their eu-west-1 region (Ireland), which uses Amazon SES underneath. |
| Incoming email to support@ | Zoho Mail, in their European datacentre. |
Who else is involved
These are the only companies that touch anything. Each of them is here because the product cannot work without it, and each is named so the list can be checked against reality.
- Cloudflare — hosting, file storage, and the network in front of it.
- Neon — the database.
- Resend — outgoing email: confirmations, password resets, invitations, notification digests.
- Zoho — the mailbox that receives mail sent to the support address.
- Discord — only for a studio or a person who connects it, and only for the notifications they asked to receive there.
- Anthropic — only if you connect your own Claude to your studio. The connection runs the other way from what people expect: your Claude asks this product for things, using your own Anthropic subscription. Nothing is sent to Anthropic by this product on its own, and there is no AI feature in it.
How long it is kept
A studio's work is kept for as long as the studio keeps it. Nothing is deleted on a schedule, because a deletion schedule for somebody's production archive would be a surprise and not a service.
Four things do expire on their own: sessions after thirty days, the counters that stop password guessing after five days, half-finished uploads as soon as a later upload notices them, and an email address left on the front page that nobody ever confirmed, after thirty days.
The email address on the front page
If you leave an address on the front page, one message is sent to it: the one asking whether it really was you. Nothing else is sent to an address that has not answered that, and nothing is sent to the list at all today — Kadrenta has no newsletter and no campaigns, and both are deliberately out of the first version.
Every message to that list carries a link to a page with a button that takes the address off, and taking it off deletes the row rather than marking it. The list is not shown anywhere in the product and cannot be listed from it.
Your rights, and what the product can actually do
You can ask for a copy of your data, for it to be corrected, or for it to be deleted. The honest description of what happens then is below, because this product distinguishes two things that most describe as one.
- Removing somebody takes them out of a studio's address book and ends their memberships. The history keeps their name: who made a shot, who approved a version, who was assigned a task.
- Erasing somebody does all of that and overwrites the name in the history as well. What is left reads as *Erased person*, and the email address, phone number and notes are cleared. This is what a real request under the GDPR gets.
- Erasing is a best effort on old activity records. Where a name was written into a log line as text before ids were used everywhere, it is matched and overwritten as a whole value. It is described here as best effort because that is what it is.
- Erasing is refused while somebody still owns a project. That is not a refusal of the request — it is a step in it. The projects are named on screen so they can be handed over first, which is a thing that can be done in minutes, rather than a project silently left with no owner.
What is not there yet
This section exists because a privacy policy that only lists what works is not a description of anything.
- There is no self-service delete button. Removing and erasing are done by an administrator of the studio, on a page built for it. If you have a Kadrenta account and want it gone, write to support@kadrenta.com and it will be done by hand.
- Backups are not arranged, and no restore has ever been rehearsed. A backup nobody has restored is an assumption. Do not treat this product as the only copy of anything you cannot lose.
- Nobody outside has reviewed the security of this. Everything described in the next section was built and checked by the same people who wrote it.
- There is no data processing agreement and no formal breach procedure yet. If something goes wrong you will be told, and that is a commitment rather than a process.
How it is protected
Concretely, and only things that are actually in place:
- Every studio's data is fenced at the database itself, not only in the application. The connection the application uses cannot bypass that fence — it is a database role without the permission to.
- Passwords are stored as hashes and never in readable form. A password reset ends every existing session.
- Review links carry a token long enough not to be guessed, can have a passphrase, can expire, and can be revoked with immediate effect. The passphrase is stored hashed with 210,000 rounds of PBKDF2.
- Files never travel through the application. A browser uploads to and downloads from storage directly, using an address that is signed and expires in minutes — one minute for anything reached through a share link.
- Sign-in, password reset, share-link passphrases and the front-page form all have limits on how often they can be tried, counted per address and per account.
- Everything is served over TLS, with a strict content security policy and without any third-party script.
Getting in touch
Write to support@kadrenta.com. That address reaches a person.
If you are in the EU and you are not satisfied with the answer, you can complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.