Our Privacy Policy
The German version of the privacy policy shall be decisive. The English version is provided for understanding purposes only.
Our company attaches great importance to the protection of personal data and respects your desire for privacy. Below we will inform you about the collection of personal data when you use our website. If you still have any questions about the handling of your personal data, please contact our data protection officer.
1. Responsible person
The person responsible within the meaning of the General Data Protection Regulation (GDPR) is:
PicDrop GmbH, Am Kupfergraben 4/4a, 10117 Berlin
2. Contact option for the data protection officer
You can reach our data protection officer at privacy@picdrop.com or our postal address with the addition “the data protection officer”.
3. Legal basis for our data processing
The processing of personal data can be based on various legal bases. If we need your data to fulfill a contract with you or to answer your inquiries regarding a contract, the legal basis for this data processing is Art. 6 Paragraph 1 Sentence 1 Letter b GDPR. If we obtain your consent for certain data processing, the legal basis is Article 6 Paragraph 1 Sentence 1 Letter a GDPR. We carry out some data processing on the basis of our legitimate interest, always balancing your legitimate interests with our legitimate interests. The legal basis for this is Article 6 Paragraph 1 Letter f of the GDPR. To the extent that processing is necessary to fulfill a legal obligation to which we are subject, the legal basis is Article 6 Paragraph 1 Sentence 1 Letter c GDPR.
Below we explain how we process personal data via our website.
3.1 Data processing when you visit the website
When you use the website for informational purposes only, i.e. if you do not contact us using the online form or otherwise provide us with information, we collect the following technical information (log file data):
- Operating system of the device you use to visit our website
- Browser (type, version & language settings)
- the amount of data retrieved
- the current IP address of the device you use to visit our website
- Date and time of access
- the URL of the previously visited website (referrer)
- the URL of the (sub)page that you access on the website
- the Internet service provider of the accessing system
The collection of this data is technically necessary to display our website to you and to ensure stability and security. We (and our service provider) generally do not know who is behind an IP address. We do not combine the data listed above with other data.
The legal basis is Article 6 Paragraph 1 Sentence 1 Letter f GDPR. Since the collection of data to provide the website and storage in log files is absolutely necessary for the operation of the website and to protect against misuse, our legitimate interest in data processing prevails at this point.
3.2 Contacting us via email or contact form
When you contact us by email or via a contact form, the data you provide (your email address, if applicable your name and telephone number) will be stored by us in order to answer your questions and process your request. The legal basis in this respect is Article 6 Paragraph 1 Sentence 1 Letter f GDPR. If we request input via our contact form that is not required to contact you, we have always marked this as optional. This information helps us to concretize your request and to improve the processing of your request. This information is provided expressly on a voluntary basis and with your consent, Art. 6 Paragraph 1 Sentence 1 Letter a GDPR. If this involves information about communication channels (e.g. email address, telephone number), you also agree that we may also contact you via this communication channel to answer your request. You can of course revoke this consent at any time in the future.
Your data that we received when you contacted us will be deleted as soon as it is no longer needed to achieve the purpose for which it was collected, your request has been fully processed and no further communication with you is necessary or requested by you.
4. Registration & customer account at picdrop
You have the opportunity to register for our product in order to be able to use the full functionality of our website. We ask for your first and last name, your email address and desired picdrop address as well as optionally your company name. As part of the registration process, we also collect information about your user type and the intended use of our product. We use this information to provide you with configuration, functions and user guidance tailored to your use case.
For payment transactions (payment accounts) we offer the payment methods commonly used online (e.g. direct debit and credit card payment). We work with various payment service providers from whom we receive your payment data or to whom we transmit your payment data. Without these payment data and payment service providers, payment and contract processing is not possible. The legal basis for this data processing is Article 6 Paragraph 1 Sentence 1 Letter b GDPR. We base the processing of optional information on your consent in accordance with Article 6 (1) (a) GDPR.
Our payment service providers are in particular:
GoCardless SAS, 23-25 Avenue Mac-Mahon, Paris, 75017, France; German office: GoCardless GmbH, Herzogspitalstr. 24, 80331 Munich (https://gocardless.com)
Further information about GoCardless’ processing of your personal data and your ability to object to this can be found at gocardless.com/legal/privacy.
Stripe Payments Europe, Ltd., The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland (http://stripe.com)
Further information on how Stripe processes your personal data and your ability to object to this can be found at https://stripe.com/de/privacy
5. Chatbase (AI-powered chat tool)
At picdrop, we use the “Chatbase” tool provided by Chatbase, 2261 Market Street #4834, San Francisco, CA 94114, USA. Chatbase is an AI-powered chat tool that enables us to provide automated responses to user inquiries. We have entered into a data processing agreement with Chatbase in accordance with Article 28 of the GDPR.
When you interact with the chatbot, the information you enter (e.g., questions, concerns, contact information) is transmitted to Chatbase’s servers and processed there. This processing is carried out to respond to your inquiry and to continuously improve the chatbot. This information may also include personal data. (In addition, Chatbase also processes information regarding device identifiers (e.g., serial number) and the IP address.)
Chatbase uses artificial intelligence (AI) to analyze your inquiries and generate appropriate responses. Based on your inputs, the AI may draw conclusions about your interests or concerns. The AI is not trained using the data provided.
Your data is processed on the basis of Article 6(1)(f) of the GDPR (legitimate interest), as we wish to offer you a modern and efficient communication channel. If you provide information via Chatbase that is necessary for the initiation or performance of a contract, Article 6(1)(b) of the GDPR also applies.
If needed, you can provide an email address to Chatbase. We will store this email address and use it to contact you. Providing your consent is voluntary and serves to help resolve your inquiry with a team member in case Chatbase was unable to assist you.
If the chatbot cannot fully resolve your issue, we offer to forward your inquiry to our customer service team. In this case, we will ask for your email address so that our team can contact you. An automatic summary will also be generated from your chat history to date. Your email address, chat history, and summary are then transferred via a technical interface to our HelpScout ticketing system, where our customer service team will further process your inquiry. The provider of this system is HelpScout PBC, 131 Tremont Street, Boston, MA 02111, USA. We have also entered into a data processing agreement with HelpScout in accordance with Article 28 of the GDPR.
The legal basis for data processing is your consent pursuant to Article 6(1)(a) of the GDPR, which may be revoked at any time with future effect.
Our legitimate interest is to enable us to respond to your inquiries quickly and efficiently and to make effective use of our customer service resources.
We ask that you do not provide any health-related data or other sensitive information in the chat history. If your inquiry involves such information, please contact us directly at hello@picdrop.com.
Both Chatbase and Help Scout process your data on servers in the United States. Therefore, it cannot be ruled out that your data will be transferred to a third country (the United States).
Please note that the level of data protection in the U.S. is not comparable to that in the EU. The transfer is based on the EU Commission’s Standard Contractual Clauses pursuant to Article 46 of the GDPR. The data collected in connection with the use of the chatbot will be stored only for as long as necessary to process your inquiry.
You may exercise your rights as a data subject—in particular, the rights to access, rectification, erasure, restriction of processing, objection, and data portability—at any time by contacting us. For more information, please see Section 25 of this Privacy Policy. For more information on data processing by Chatbase, please visit: https://www.chatbase.co/privacy
6. Content search
Our platform offers you the opportunity to use AI-supported image search. This function is deactivated by default and can be activated voluntarily (opt-in). AI image search makes it possible to find images based on their meaning, content or descriptions – regardless of the file name or existing tags. The AI is not trained with the data sets.
As part of the AI image search, your uploaded images are analyzed by an AI model. This only happens if the content search was previously activated by the user. No copies of your images are created. Instead, a so-called “embedding” is created from each image – a purely mathematical number vector that represents the visual content of the image. These embeddings cannot be recalculated, i.e. h. It is technically impossible to reconstruct the original image from an embedding. EXIF data or user tags are not used for embedding creation. The embeddings are saved separately from the original images. Your search queries are converted into a vector in real time, but are not saved and are immediately deleted after processing.
You can deactivate the AI image search at any time (opt-out). In this case, all embeddings saved for your images will be automatically deleted after 30 days at the latest. If desired, immediate deletion can take place.
The embeddings are saved exclusively to enable a quick and high-performance search. The legal basis for processing is your consent in accordance with Article 6 (1) (a) GDPR.
The use of AI image search is voluntary and disabled by default. You can activate or deactivate the function at any time. After deactivation, your embeddings will be deleted as described above.
7. Newsletter
You can subscribe to our email newsletter on our website. We will inform you about the latest news, offers and promotions.
If you actively register, shipping will be based on your consent (Art. 6 Para. 1 lit. a GDPR in conjunction with Section 7 Para. 2 No. 3 UWG).
We use the double opt-in procedure for registrations. After entering your email, you will receive a confirmation email. Without confirmation, the registration will be automatically deleted after 3 days.
Mandatory information is your email address; Optionally, we process your name for personal contact. After confirmation, we will save your email address for the purpose of sending the newsletter until you revoke your consent. To provide evidence, we log the time of registration and confirmation as well as the IP address used at the time of registration.
Success measurement/tracking:
We can measure whether a newsletter is opened and which links are clicked in order to optimize content. This is done using tracking pixels and individual IDs embedded in the email. The legal basis is your consent (Art. 6 Para. 1 lit. a GDPR in conjunction with Section 25 Para. 1 TDDDG).
You can revoke your consent at any time with future effect. To do this, use the unsubscribe link in every email or contact the contact details above.
8. Applications
You can apply to our company via our application portal (Careers at saas.group).
As part of the application process, we usually process the following data about you:
- Master data (name, contact details, address), application documents (cover letter, CV, certificates, qualifications), communication/process data (correspondence, appointment and interview data, notes), if applicable, professionally publicly provided profiles.
- We only process special categories (e.g. health data/severe disability) or other information provided by you to the extent required by law or with your express consent
As a rule, we receive the data from you. In addition, data may come from recruiters, from publicly available profiles used for professional purposes or from recommendations.
Internally, only those involved in the process have access (personnel, respective specialist department, if applicable management/interest groups). External IT/HR service providers (e.g. hosting the application portal, video interview or appointment tools) process your data as processors bound to instructions in accordance with Art. 28 GDPR. If service providers are used outside the EU/EEA, the transfer will only take place under the conditions of Art. 44 ff. GDPR. In group-wide procedures, other group companies may be involved.
Your information will be used to process your application and decide whether to establish an employment relationship. The legal basis is Section 26 Paragraph 1 in conjunction with Paragraph 8 Sentence 2 BDSG. Furthermore, your personal data can be processed to the extent that this is necessary to defend against legal claims asserted against us from the application process. The legal basis for this is Article 6 Paragraph 1 Letter f) GDPR. The legitimate interest in the processing also lies in the stated purposes.
If there is an employment relationship between you and us, we can further process the personal data we have already received from you for the purposes of the employment relationship in accordance with Section 26 Paragraph 1 BDSG in conjunction with Art Obligations to represent the interests of employees are required.
Your application data will not be processed beyond the described use.
Your personal data will be deleted after completion of the application process at the latest after 6 months, provided that deletion does not conflict with any other legitimate interests on our part or you have not given us your consent for longer storage. Other legitimate interests in this sense include, for example, a burden of proof in proceedings under the General Equal Treatment Act (AGG).
9. Calling up the web app picdrop by invited external parties
If a photographer shares a gallery with you or invites you to use the account without you being registered with picdrop, you will receive a link from them. By clicking on the link you can access our website. In this case, we collect the same data as described in points 3.1 and 4.
10. Use of cookies
Cookies are data that are stored on your computer by a website you visit and enable your browser to be reassigned. Cookies provide information to the entity that uses the cookie. Cookies can store various information, such as your language setting, the length of your visit to our website or the entries you make there. Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offering more user-friendly and effective overall.
10.1 Transient cookies
These cookies are automatically deleted when you close the browser. These include, in particular, session cookies. These store a so-called session ID, which can be used to assign various requests from your browser to the shared session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
10.2 Persistent Cookies
These cookies are automatically deleted after a specified period of time, which may vary depending on the cookie. You can delete cookies at any time in your browser’s security settings.
11. Google Tag Manager
For reasons of transparency, we would like to point out that we use Google Tag Manager. This is a tag management system for managing JavaScript and HTML tags, used for implementing tracking and analysis tools. This is a service provided by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. The controller in the EU/EEA is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
Google Tag Manager itself does not collect any personal data. The Tag Manager makes it easier for us to integrate and manage our tags. Tags are small elements of code used to, among other things, measure traffic and visitor behavior, understand the impact of online advertising and social channels, set up remarketing and audience targeting, and test and optimize websites. If you have deactivated, Google Tag Manager will take this deactivation into account.
The recipients of the data are:
Google Ireland Limited, EU,
Google LLC, USA,
Alphabet Inc., USA.
This service may process data outside the European Union and the European Economic Area (EEA) and transfer it to a country that does not offer an adequate level of data protection.
The legal basis for this data processing is your consent. You have the option to revoke your consent once given with effect for the future by changing your settings HERE. The lawfulness of data processing until revocation remains unaffected. You can find more information about Google Tag Manager at:
https://www.google.com/intl/de/tagmanager/use-policy.html.
12. Google Analytics
If you have given your consent, Google Analytics 4, a web analysis service from Google LLC, will be used on this website. The responsible body for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).
Google Analytics uses cookies that enable your use of our websites to be analyzed. The information collected by cookies about your use of this website is usually transmitted to a Google server in the USA and stored there.
We use Google Signals. This collects additional information in Google Analytics about users who have activated personalized ads. Interests and demographic data and ads can be delivered to these users in cross-device remarketing campaigns.
In Google Analytics 4, IP address anonymization is enabled by default. Due to IP anonymization, your IP address will be shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. According to Google, the IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
During your website visit, your user behavior is recorded in the form of “events”. Events can be:
- page views,
- first visit to the website,
- start of the session,
- visited websites,
- Your “click path”, interaction with the website,
- Scrolls (whenever a user scrolls to the bottom of the page (90%)),
- Clicks on external links,
- internal search queries,
- Interaction with videos,
- file downloads,
- ads seen/clicked,
- Language setting.
It also records:
- your approximate location (region),
- Date and time of the visit,
- your IP address (in shortened form),
- technical information about your browser and the devices you use (e.g. language settings, screen resolution),
- your internet provider and
- the referrer URL (via which website/advertising medium you came to this website).
On behalf of the operator of this website, Google will use this information to evaluate your pseudonymous use of the website and to compile reports on website activities. The reports provided by Google Analytics are used to analyze the performance of our website and the success of our marketing campaigns.
Recipients of the data can be:
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as processor according to Art. 28 GDPR),
Google LLC, 1600 Amphitheater Parkway Mountain View, CA 94043, USA,
Alphabet Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, USA.
The European Commission adopted its adequacy decision for the USA on July 10, 2023. Google LLC is certified according to the EU-US Privacy Framework. Since Google servers are distributed worldwide and a transfer to third countries (e.g. to Singapore) cannot be completely ruled out, we have also concluded the EU standard contractual clauses with the provider.
The data we send and linked to cookies is automatically deleted after 14 months. The maximum lifespan of Google Analytics cookies is 2 years. The deletion of data whose retention period has been reached occurs automatically once a month.
The legal basis for this data processing is your consent in accordance with Article 6 Paragraph 1 Sentence 1 Letter a GDPR and Section 25 Paragraph 1 Sentence 1 TTDSG. You can revoke your consent at any time with future effect by accessing the cookie settings and changing your selection there. The lawfulness of the processing carried out based on consent until its revocation remains unaffected.
You can also prevent the storage of cookies from the outset by setting your browser software accordingly. However, if you configure your browser to refuse all cookies, functionality on this and other websites may be limited. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by not giving your consent to the setting of the cookie or by downloading and installing the browser add-on to deactivate Google Analytics HERE.
You can find further information about the terms of use of Google Analytics and data protection at Google at https://marketingplatform.google.com/about/analytics/terms/de/ and at https://policies.google.com/?hl=de.
13. Google Ads
We use the Google Ads service. Google Ads is an online advertising program from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
This means that we place Google Ads ads and also use Google Remarketing and conversion tracking. The ads are displayed on Google advertising network websites based on search queries. We also use Ads remarketing lists for search ads. This allows us to tailor search ad campaigns to users who have previously visited our website. The Services allow us to combine our advertisements with certain search terms or to display advertisements to previous visitors, for example, promoting services that you have viewed on our website. This means we can show you, as a user of our website, interest-based advertising on other websites within the Google advertising network (as a “Google ad” as part of Google search or on other websites).
An analysis of online user behavior is necessary for interest-based offers. Google uses cookies to carry out this analysis. When you click on an ad or visit our website, Google sets a cookie on your computer. These cookies last for 90 days. The information collected using the respective cookie is used to be able to specifically address you in a later search query. You can also find further information about the cookie technology used in Google’s information on website statistics and in the data protection regulations. With the help of this technology, Google and we as a customer receive information that you clicked on an ad and were redirected to our websites. The information obtained here is used exclusively for statistical evaluation for ad optimization. We do not receive any information that could personally identify visitors. Your IP address will be transmitted to Google, but since we use Google’s IP masking on this website as part of the use of Google Analytics, your IP address will be anonymized. The statistics provided to us by Google include the total number of users who clicked on one of our advertisements and, if applicable, whether they were redirected to a page on our website that had a conversion tag. Using these statistics, we can understand which search terms were clicked on our ad particularly often and which ads lead to you contacting us via the contact form.
You can find further information about data protection within the context of Google Ads at: https://policies.google.com/technologies/ads?hl=de.
If you do not want the processing, you can prevent the cookies required for these technologies from being stored, for example, via your browser settings. In this case, your visit will not be included in the user statistics.
You also have the option of selecting the types of Google ads or deactivating interest-based ads on Google via the ad settings (https://adssettings.google.com/authenticated?hl=de). Alternatively, you can opt out of third parties’ use of cookies by visiting the Network Advertising Initiative opt-out tool.
However, we and Google continue to receive statistical information about how many users visited this site and when. If you do not want to be included in these statistics, you can prevent this with the help of additional programs for your browser (e.g. the Privacy Badger add-on).
The legal basis for this data processing is your consent, Article 6 Paragraph 1 Letter a) GDPR and Section 25 Paragraph 1 Sentence 1 TTDSG. You can revoke your consent at any time with effect for the future by accessing the cookie settings in our consent management platform (“Change cookie settings” at the bottom of the page) and changing your selection there.
14. Facebook conversion tracking pixels
As part of usage-based online advertising, we use the Custom Audiences service from Meta Platforms, Inc., 1601 S. California Avenue, Palo Alto, CA 94304, USA (hereinafter referred to as “Facebook”). For this purpose, we define target groups of users in the Facebook Ads Manager based on certain characteristics, who will subsequently be displayed advertisements within the Facebook network. Users are selected by Facebook based on the profile information they provide and other data provided through the use of Facebook. If a user clicks on an advertisement and then comes to our website, Facebook receives the information via the Facebook pixel integrated on our website that the user clicked on the advertising banner.
Basically, a non-reversible and non-personal checksum (hash value) is generated from your usage data, which is transmitted to Facebook for analysis and marketing purposes. A Facebook cookie is set. This collects information about your activities on our website (e.g. surfing behavior, sub-pages visited, etc.). Your IP address is also stored and used to target advertising geographically.
We do not use Facebook Custom Audiences via the customer list or the “advanced matching” function.
Further information about the purpose and scope of data collection and the further processing and use of the data by Facebook as well as your setting options to protect your privacy can be found in Facebook’s data protection guidelines. You can make settings regarding which advertisements are shown to you on Facebook using this link and in the Facebook account settings.
You can prevent data collection by the Facebook pixel by clicking on the following link: [Deactivate tracking]
An opt-out cookie (persistent HTML5 storage object) is set to prevent future collection of your data when you visit this website.
You can also prevent the storage of cookies altogether by setting your browser software accordingly. However, we would like to point out that in this case you may not be able to fully use all of the functions of our website. You can find further options for deactivating third-party cookies at www.networkadvertising.org/managing/opt_out.asp or on the Digital Advertising Alliance Opt-Out Platform at http://optout.aboutads.info/?c=2&lang=en.
15. Guideflow
We use the “Guideflow” service from SAASFLOW Inc. (92, avenue Charles de Gaulle, 92522 Neuilly-sur-Seine Cedex, France – hereinafter “Guideflow”) to provide interactive product demos and step-by-step instructions on our website. Guideflow enables us to provide you with clear click-through demos of our products. Your data is therefore processed for the purpose of providing interactive product demos and instructions to clearly explain the use and functions of our products to you.
When using Guideflow, the following data is processed:
- IP address
- Identification data (e.g. session ID)
- Session data
- Browser data
- Usage data (e.g. interactions with the demo)
- Navigation data (e.g. pages visited within the demo)
The processing is carried out on the basis of Article 6 Paragraph 1 Letter f GDPR (legitimate interest). Our legitimate interest lies in the user-friendly and clear presentation of our products.
The data is transmitted to SAASFLOW Inc., the provider of Guideflow. It cannot be ruled out that data will be transferred to third countries (e.g. USA). In this case, we ensure that appropriate guarantees exist in accordance with Art. 44 ff. GDPR.
The data will only be stored for as long as is necessary to achieve the stated purposes.
Further information: https://saasflow.com/de/terms/privacy
16. Rewardful (affiliate tracking)
We use the affiliate tracking tool “Rewardful” from Rewardful Inc. to track the origin of contracts concluded through affiliate partners and to manage our partner program.
When using Rewardful, the following data is processed:
- Affiliate ID
- Time of visit
- name
- E-mail address
- IP address
- Purchase information
Cookies or similar technologies are used for recognition and assignment, which in particular store the affiliate ID and the time of the visit. Personal data such as name or email address are usually only processed if it is necessary for the processing of the partner program.
Processing is carried out on the basis of Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 Sentence 1 TTDSG. Our legitimate interest lies in the economic operation and processing of our affiliate program.
The data is transmitted to Rewardful Inc. It cannot be ruled out that data will be transferred to third countries (e.g. USA). In this case, we ensure that appropriate guarantees exist in accordance with Art. 44 ff. GDPR.
The data will be deleted as soon as it is no longer required to provide the service. The maximum storage period for cookies is 60 days.
Further information on data processing by Rewardful can be found in the provider’s data protection declaration: https://www.getrewardful.com/privacy
17. Bing Ads
To draw attention to our services, we place Bing Ads ads (a service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA). These ads appear in search engines Bing, Yahoo!, based on searches across the Yahoo!-Bing network. and MSN are displayed. This also gives us the opportunity to combine our ads with certain search terms and is therefore present on all major search engines.
Bing Ads also uses cookies to analyze user behavior. When you click on an ad or visit our website, as long as the user’s consent is documented, a cookie is placed on the user’s computer by Bing Ads. This information is used to be able to specifically address the visitor in a later search query. Further information can be found in Microsoft’s data protection declaration and in the data security guidelines and data protection declaration.
In addition, as part of Bing Ads, we use Bing Ads Conversion Tracking to display interest-based advertising. This requires an analysis of user behavior. We only receive information from Bing that a user clicked on an ad and was redirected to our websites. We use the information obtained in this way exclusively for statistical evaluation to optimize advertisements. We are not able to identify the visitor through the data collected. The statistics provided to us by Bing include the total number of users who clicked on one of our ads. We also receive information as to whether these visitors were redirected to a page on our website that has a conversion tag. Using these statistics, we can understand which search terms were clicked on our ad particularly often and which ads lead to users contacting us via the contact form. The purpose of Bing Ads Conversion Tracking is to show you interest-based advertising, to make our website more interesting for you and to achieve a more economical assessment of our advertising costs.
Information on the duration of storage can be found at: https://privacy.microsoft.com/de-de/privacystatement.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection levels on the basis of an adequacy decision by the European Commission.
The legal basis for the data processing described is your consent, Section 25 Paragraph 1 Sentence 1 TTDSG, Art. 6 Paragraph 1 Sentence 1 Letter a GDPR. Once you have given your consent, you can revoke it at any time with effect for the future by changing your selection in the cookie settings (see section 5. Cookies above). Alternatively, you can delete your cookies (all or just from this website). The banner with the choices will then appear again.
You also have the option to deactivate interest-based ads on Bing via the ad settings.
18. Meta Ads
On our website “PicDrop” we use the Meta Ads service from the provider Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Meta”) for marketing and optimization purposes. For this purpose, we use the so-called Meta Pixel (formerly “Facebook Pixel”), which is integrated by Meta on our website.
With the help of the Meta Pixel we can:
- evaluate the effectiveness of our advertising measures on Meta’s platforms (e.g. Facebook, Instagram) statistically and for market research purposes (so-called conversion measurement),
- Assign users of our website to specific target groups (“Custom Audiences”) in order to show them interest-based advertising on the meta platforms,
- optimize our advertisements and only show them to people who are likely to have shown an interest in our offers (e.g. visiting certain pages or promotions on “PicDrop”).
In doing so, we pursue our interest in effective and targeted online advertising and in improving our website.
The following data in particular can be processed via the Meta Pixel:
- Information about your use of our website (e.g. pages viewed, clicks, length of stay),
- technical information (e.g. IP address, browser type, operating system, screen resolution),
- Referrer URL (previously visited page),
- if applicable, identifiers assigned by Meta (e.g. cookie ID, advertising ID),
- Information about “events” defined by us (e.g. page views, registration, purchases, downloads).
Meta can combine this data with your Meta user account and use it for its own purposes (e.g. to improve its own products, personalized advertising, market research). We have no influence on this further data processing by Meta; it is carried out under Meta’s own data protection responsibility. Further information can be found in Meta’s privacy policy at https://www.facebook.com/privacy/policy.
18.1 Use of the Meta Conversion API
In addition to the Meta Pixel, we can use the Meta Conversion API. Certain event data (e.g. purchases, registrations or form completions) is transmitted to Meta not only via the browser pixel, but also on the server side. This increases the reliability of conversion measurement, especially if, for example, browser cookies are restricted or deleted.
Basically, the same categories of data are processed as when using the Meta Pixel; However, the transmission takes place directly from our server to Meta. The data will be processed for the same purposes as described above.
18.2 Use of Custom Audiences
Optional, if used – please remove if you do not use the function:
We can create custom audiences in order to target advertising on Meta’s platforms to specific groups. For this we can, for example:
assign website visitors to specific target groups based on their usage behavior (e.g. page views, purchases) (“Website Custom Audiences”),
In such a case, the transmitted data will be cryptographically hashed before transmission and used exclusively to form target groups and to display our advertising. According to Meta, there will be no use for other purposes or identification of individual persons based on the hash values.
The use of the Meta Pixel and, if applicable, the Meta Conversion API and Custom Audiences only takes place if you have given us your consent for this via our consent management tool (cookie banner).
The legal basis for setting/reading corresponding cookies or comparable technologies on your device is your consent in accordance with Section 25 Paragraph 1 TDDDG. The subsequent processing of personal data is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
You can revoke your consent at any time with effect for the future by accessing the cookie settings on our website and adjusting your selection accordingly or deleting cookies that have already been set.
The recipient of the data is Meta Platforms Ireland Limited as the provider of the meta services. When using Meta Ads, it cannot be ruled out that data will also be transmitted to companies in the Meta group of companies in countries outside the EU/EEA – especially in the USA – and processed there. Meta is certified according to the EU Commission’s Data Privacy Framework.
We store the specific cookies set or the information stored via the meta pixel for 90 days. Furthermore, if your data is processed via Meta Ads, we will only store it for as long as this is necessary for the stated purposes or for as long as you revoke your consent.
You can revoke your consent to the use of Meta Ads (Meta Pixel, if applicable Meta Conversion API, Custom Audiences) at any time with future effect by accessing the cookie settings on our website (“PicDrop”) again and changing your selection.
In addition, you can also object to interest-based advertising by Meta directly on the Meta platforms, e.g. under the advertising and privacy settings in your user account.
Please note that if you revoke your consent, any data processing that has already taken place will remain unaffected and you will no longer be shown certain personalized content or offers.
19. LinkedIn Ads
If you have given your consent, we use the online marketing tool LinkedIn Ads. The responsible service provider in the EU is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
For this purpose, we define target groups of users in the LinkedIn Campaign Manager based on certain characteristics, who will subsequently be shown advertisements within the LinkedIn network. Users are selected by LinkedIn based on the profile information they provide and other data provided when using LinkedIn. If a user clicks on an advertisement and then reaches our website, LinkedIn receives the information via the conversion tag integrated on our website that the user clicked on the advertising banner.
The LinkedIn tag enables the recording of websites visited, including the URL, referrer ID, IP address, device and browser characteristics and timestamp. The IP addresses are shortened or hashed (if used across devices) by LinkedIn.
Using the LinkedIn Pixel, we can show personalized ads outside of our website without identifying individual members. Data that does not identify you is also used to improve ad relevance and reach LinkedIn members across devices. LinkedIn members can control the use of their personal information for advertising purposes through their account settings. To adjust advertising preferences, LinkedIn refers to the following link: https://www.linkedin.com/psettings/advertising/actions-that-showed-interest.
We process this data to evaluate our advertising campaigns.
Further information about the purpose and scope of data collection and the further processing and use of the data by LinkedIn as well as your setting options to protect your privacy can also be found in LinkedIn’s data protection declaration.
Further information about LinkedIn Conversion Tracking can be found at: https://business.linkedin.com/de-de/marketing-solutions/conversion-tracking#get-started.
Further information on data processing and storage period can be found at https://www.linkedin.com/help/linkedin/answer/65521?lang=de.
The legal basis for this data processing is your consent, Article 6 Paragraph 1 Letter a) GDPR in conjunction with Section 25 Paragraph 1 TDDDG. You can revoke your consent at any time with future effect by opening the data protection settings below (“Website Cookies”) and making the appropriate changes there.
20. Visual Website Optimizer (VWO)
On our website we use the Visual Website Optimizer (VWO) service, a service from Wingify Software (KLJ TOWER, 1104, North, Netaji Subhash Place, Pitampura, Delhi, 110034, India). With the help of this tool, we carry out, among other things, A/B tests, multi-variant tests, user surveys as well as other usage analyzes and personalization measures in order to optimize our online offering.
VWO enables us in particular to
- to test different variants of pages, elements or functions (e.g. layout, texts, buttons) against each other,
- to analyze the behavior of users on our website (e.g. clicks, scrolling behavior, length of stay, conversion rates),
- based on the insights gained, to make our website more user-friendly and to provide content in a more targeted manner,
- to recognize technical problems, difficulties in understanding or interruptions in the usage process.
In doing so, we pursue our legitimate interest in continually improving our website and making our offering user-friendly.
When using VWO, the following information in particular can be processed:
- technical information about your device and your browser (e.g. IP address, device type, operating system, browser type/version, screen resolution),
- Usage data (e.g. pages and subpages viewed, click paths, length of stay, interactions with page elements, test variant, which test group you are in),
- If applicable, referrer URL (previously visited page), date and time of access,
- anonymized or pseudonymized identifiers (e.g. cookie ID or test ID).
The IP addresses can be shortened (anonymized) so that a direct personal reference is reduced. As a general rule, VWO does not receive any directly identifying data such as your name or email address from us.
To recognize visitors, VWO usually uses cookies or similar technologies to store:
- which variant of a page was displayed,
- which test group a user belongs to,
- whether a test has already been completed,
- whether certain actions (e.g. purchase, registration) have taken place.
The use of VWO – to the extent that cookies or similar technologies are used that are not technically necessary for the operation of the website – is only based on your consent:
The legal basis for setting/reading corresponding cookies or information on your device and the subsequent data processing is Section 25 Paragraph 1 TDDDG in conjunction with Article 6 Paragraph 1 Letter a GDPR (consent).
You give your consent via our consent management tool (cookie banner), which is displayed when you first visit our website. There you can activate the categories “Statistics”, “Analysis” or “Optimization” (or similarly named categories).
The recipient of the data is Wingify Software as a provider of VWO. VWO uses its own servers and sub-service providers to provide and process its services. It cannot be ruled out that personal data will also be processed in countries outside the European Union or the European Economic Area (third countries).
Before any transfer to a third country, we ensure – where necessary – that the requirements of Article 44 ff. GDPR are met (e.g. by concluding EU standard contractual clauses and, if necessary, additional protective measures) in order to ensure an appropriate level of data protection.
Further information on data processing by VWO as well as the subcontractors used and any third-country transfers can be found in VWO’s data protection information.
The data we process via VWO is generally only stored for as long as is necessary to carry out the tests, evaluations and optimization measures. The data collected via VWO will be stored by us for 100 days and then deleted or anonymized, provided that there are no legal retention requirements or other legitimate interests (e.g. verification purposes).
You can revoke your consent to use VWO at any time with future effect by accessing the cookie settings on our website again and adjusting your selection (e.g. deactivating analysis/optimization cookies).
Please note that a revocation does not affect the lawfulness of the processing that has taken place up to that point. If cookies are deactivated, certain testing or optimization functions may not be available or may only be available to a limited extent.
21. Satismeter (survey tool)
We use the SatisMeter survey tool from the provider SatisMeter s.r.o., Česká 1113/1, 158 00 Prague 5, Czech Republic (“SatisMeter”). SatisMeter enables us to conduct customer surveys (e.g. satisfaction surveys, Net Promoter Score (NPS), product feedback) to improve the quality of our services and further develop our offerings.
We use SatisMeter in particular for the following purposes:
- Display of survey widgets within our software,
- Collection and evaluation of feedback and ratings from our users (e.g. satisfaction with functions, support, overall product),
- Identification of potential for improvement in the use of our software,
- Measuring customer satisfaction and loyalty as well as monitoring the success of product changes.
In doing so, we pursue our interest in continuously improving our services and customer-centered further development of our software.
When using SatisMeter, the following data in particular can be processed:
- Ask whether you would recommend PicDrop
- Time of assessment
- Account + Account ID
- Device
- Sign up date
- Language
- Tariff
SatisMeter can use cookies or similar technologies to recognize users or work via scripts/SDKs integrated into our software, for example to control:
- whether and when a survey will be displayed to you,
- whether you have already taken part in a specific survey,
- in which usage situations certain surveys are delivered.
We do not transmit any sensitive data (e.g. special categories within the meaning of Art. 9 GDPR) to SatisMeter.
We base the processing on Art. 6 Para. 1 lit. a GDPR in conjunction with Section 25 Para. 1 TDDDG. Consent can be revoked at any time with future effect, e.g. via the settings in our software or via our consent management tool.
22. Noticeable
We use the Noticeable service from Noticeable.io, 1 Chemin des Rosiers, 06800 Cagnes-sur-Mer, France, to display in-app notifications within our service. Using a corresponding symbol (“rocket”), logged in users can access information about new functions, product changes and important information. We can use Noticeable to control which users see which notices and changelogs.
For this purpose, Noticeable provides a widget or scripts that are loaded when you use our service and communicate with Noticeable’s servers.
Data categories processed
When using Noticeable, the following data in particular is processed:
- Usage and interaction data:
Call up the in-app widget (click on the rocket symbol), which notifications/changelogs are displayed, if applicable opening and click rates, timestamp of usage. - Account and profile data (if necessary and transmitted by us):
internal user identification (e.g. user ID/account ID) to assign notifications to specific user groups or segments; further profile data only if this is necessary for segmentation/targeting. - Technical data:
IP address, date and time of the request, browser type and version, operating system, language settings and, if applicable, other meta/communication data required for the technical delivery of the in-app notifications. - Cookie/Similar Identifiers:
pseudonymous identifiers (e.g. cookies or similar technologies) to recognize returning users and show them appropriate notifications. - Feedback on Picdrop in the form of emoji reactions and comments
The details of the data processed by Noticeable can be found in the information provided by the service provider in its data protection information.
The processing takes place for the following purposes:
- Display in-app notifications about new features, product updates and changes directly within the user account;
- Target group-specific display of information (e.g. only for certain user groups or feature users);
- Improving our communication with users and optimizing our product by understanding which notices are used and perceived.
If the processing takes place in connection with an existing contractual relationship and a user account (e.g. for registered customers who use our service as part of a contract), the processing is based on Art. 6 Para. 1 lit. b GDPR (fulfillment of the contract or implementation of pre-contractual measures).
Otherwise – especially when it comes to the general improvement and further development of our offering as well as efficient and user-friendly communication about product changes – the processing takes place on the basis of Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in providing our users with transparent and targeted information about relevant changes and in the ongoing optimization of our service.
With regard to the above-mentioned purposes, Noticeable acts as a processor within the meaning of Article 28 GDPR. We have concluded an order processing agreement with Noticeable, in which Noticeable undertakes to comply with data protection regulations.
As part of use, data from our systems may be transmitted to Noticeable. Noticeable uses this data exclusively according to our instructions and not for its own purposes and only stores it for as long as necessary to provide the service.
23. Connect to third-party apps using Model Context Protocol (MCP)
23.1 Purposes of processing and data processed
We offer you the ability to connect external third-party applications (e.g. AI assistants like Claude from Anthropic) to your PicDrop account via the Model Context Protocol (MCP). This allows the third-party app you select to access content and features of your PicDrop account on your behalf and within the permissions you grant. This usually affects gallery names and structures, file names and metadata, download links and image files themselves, provided you grant access.
Authorization is carried out using the standardized OAuth 2.0 procedure. After selecting the respective third-party app, you will be redirected to our registration mask, where you authenticate yourself with your PicDrop access data and confirm the specific permissions requested via a consent window. Your password will never leave PicDrop. Ory does not authenticate you itself or manage PicDrop user accounts. The actual registration and user management takes place exclusively in our own system. Ory serves us exclusively as a technical OAuth 2.0/OpenID Connect infrastructure for issuing and checking access tokens.
To technically implement the authorization exchange, we use the OAuth infrastructure provider Ory (see Section 1.3. “Recipients”). In this context, the following data is processed:
- a pseudonymous, PicDrop-internal user ID (UUID),
- your IP address and your user agent (transmitted during browser redirects to the domain auth.picdrop.com operated by Ory),
- the list of apps you have connected (client IDs),
- Metadata about the granted permissions (consent metadata),
- Access and refresh tokens and session data,
- Technical flow cookies that are set during the authorization process on a domain operated by Ory and are used exclusively to protect the process against cross-site request forgery (CSRF).
No real names, email addresses, photos, galleries or other content-related data are transmitted to Ory. The pseudonymous user ID is assigned to you exclusively within our own database.
Only the data that it specifically accesses via the MCP interface after you have authorized it will be transmitted to the respective third-party app. You control the scope and content of these transfers through your use of the third-party app.
23.2 Legal basis
The legal basis for storing the technical flow cookies on your device and accessing them is Section 25 Paragraph 2 No. 2 TDDDG, as these cookies are absolutely necessary to securely carry out the authorization process you actively initiated and in particular to protect against cross-site request forgery attacks (CSRF attacks). The legal basis for the associated processing of your personal data is Article 6 (1) (f) GDPR. Our legitimate interest is to ensure the IT security of the authorization process, in particular to protect against CSRF attacks and against misuse of the interface.
The legal basis for the subsequent processing of your personal data as part of the connection of your PicDrop account with a third-party app is your consent in accordance with Art. 6 Para. 1 lit. a GDPR, which you give by actively confirming in the consent window.
23.3 Recipients of personal data
Recipients of the above data are:
- Ory Corp., 60 E 3rd Ave Ste 350, San Mateo, CA 94401, USA, as provider of the OAuth 2.0/OpenID Connect infrastructure used (Ory Network, Ory Hydra component). According to our information, Ory operates the services used on infrastructure within the EU. Ory works for us as a processor within the meaning of Art. 28 GDPR. A corresponding order processing contract has been concluded.
- The third-party app you selected (e.g. Anthropic, PBC as provider of the AI assistant “Claude”). The third-party app is independently responsible for the data accessed and further processed by it via the MCP interface within the meaning of Art. 4 No. 7 GDPR. The data protection information of the respective third-party provider applies exclusively to their data processing.
23.4 Data transfer to third countries
According to the provider, the data processed as part of Ory’s OAuth infrastructure is stored on servers within the EU. Since Ory Corp. However, if the parent company is based in the USA, access from a third country (USA) cannot be completely ruled out.
Ory Corp. is under the EU-U.S. Data Privacy Framework certified. The guarantee regarding any data transfer to the USA is the adequacy decision of the European Commission of July 10, 2023 in accordance with Art. 45 GDPR. Ory Corp. certification You can view the official list of the Data Privacy Framework at https://www.dataprivacyframework.gov/list.
We also worked with Ory Corp. the standard contractual clauses issued by the EU Commission in accordance with Article 46 (2) (c) GDPR are agreed. We will provide you with a copy of these standard contractual clauses upon request using the contact details provided in our general data protection declaration.
Transmissions to the respective third-party app (e.g. Anthropic, PBC based in the USA) are processed by them under their own responsibility. You can find information about the guarantees there in the data protection information of the respective provider.
23.5 Storage period
We store the connection between your PicDrop account and a third-party app as well as the associated tokens until you have revoked the connection (see Section 1.6. “Revocation of consent”) or the tokens become invalid due to the expiration of time.
Specifically, the following deadlines apply:
- Access tokens, refresh tokens and session data: These expire automatically after the expiry of the terms configured in our Ory project. After revocation or expiry, they become invalid immediately.
- Connection entry / consent metadata: until revoked by you
- Technical flow cookies (CSRF protection): short-lived session cookies that are deleted at the latest when the authorization process is completed or when the browser is closed.
After revocation, the access tokens and session data related to you will be deleted immediately, provided there are no legal retention obligations to the contrary.
23.6 Withdrawal of consent
You can revoke your consent to connect to a third-party app at any time with future effect. The lawfulness of the processing carried out based on consent until its revocation remains unaffected.
You can exercise your revocation as follows:
- in your PicDrop account under “Connected Apps”, where you can view all authorized third-party apps and revoke access individually,
- additionally via the contact options mentioned in the general data protection declaration.
Please note that revoking your consent to PicDrop will prevent the third-party app from further accessing your PicDrop account, but will have no effect on data already accessed and processed independently by the third-party app. To delete this data, you can contact the relevant third-party provider directly.
23.7 Further information
Further information on data processing by our processor Ory can be found in its data protection information at: https://www.ory.com/legal/privacy
You can find information about data processing by the third-party app you have selected in the data protection information of the respective provider.
24. Importing Files from Third-Party Cloud Storage Providers
24.1 Importing from Dropbox: Purposes of Processing and Data Processed
We offer you the option to import images and videos stored in your Dropbox account directly into your picdrop account. To do so, go to “Connected Apps” → “Cloud Storage” and click “Connect” to establish a connection between your Dropbox account and picdrop. We process the files and folders you select for transfer, including their associated technical metadata, as well as the connection, log and authorization data required to carry out and secure the import. This may also include personal data, such as your first and last name, email address, country, where applicable job account information, and, where applicable, the names of imported objects. Above all, it includes the imported files themselves, insofar as people, faces or voices can be identified in them.
The connection to Dropbox is established via an OAuth connection. Using the authorization process provided by Dropbox, you establish a connection between your Dropbox account and picdrop. We store the access token in encrypted form (AES-256-GCM) and only to the extent necessary to carry out the one-time import initiated by you. There is no ongoing synchronization or automatic access to your Dropbox account. You can disconnect an existing connection at any time in picdrop (“Connected Apps” → “Cloud Storage” → “Disconnect”); any remaining access tokens will then be deleted and pending imports terminated.
Following a successful import, you or the person who initiated the import will receive a status email.
24.2 Legal Basis
The Dropbox connection and Dropbox import are voluntary. Without a connection, only this import method will not be available to you. If you choose to import from Dropbox, the data is processed for the performance of a contract pursuant to Article 6(1)(b) GDPR. With regard to measures required to prevent misuse, security logs and technical error analysis, we base the processing on our legitimate interest pursuant to Article 6(1)(f) GDPR.
24.3 Recipients of Data Transfers
As part of the Dropbox import, we process data provided to us by Dropbox Inc. (data source, OAuth, file and folder access). Dropbox Inc., 50 Hawthorne Street, San Francisco, CA 94158, California, USA. We store imported files with Amazon Web Services (AWS), Europe region, Frankfurt. If you process imported files using semantic search, this is carried out through AWS Bedrock (USA). AWS Inc. has its principal office at 410 Terry Avenue North, Seattle, WA 98109-5210, United States. We have entered into data processing agreements with AWS pursuant to Article 28 GDPR. Amazon Web Services, Inc. is certified under the EU–US Privacy Framework.
24.4 Retention Period and Deletion
We store the OAuth token in encrypted form for as long as the connection to your Dropbox account is active. It is used solely to carry out imports initiated by you. If the connection is disconnected, we proceed in the following order:
1. picdrop first revokes the token with Dropbox.
2. picdrop then deletes the token and connection data from its own systems.
If revocation with Dropbox is not immediately successful, we will retry for a limited period. If these attempts are unsuccessful, the connection will nevertheless be deleted from our systems. When an account or user is deleted, we make one attempt to revoke the token with Dropbox. The token and connection data are then deleted from our systems.
No further attempts will be made.
We retain any stored job account information for as long as necessary to achieve the purposes stated above.
Your imported files are subject to our general picdrop deletion rules.
You can find further information here.
24.5 Disconnecting or Revoking the Connection
You can disconnect your Dropbox account by clicking the “Disconnect” button under “Connected Apps” → “Cloud Storage”.
25. Data transmission
Apart from the cases mentioned, your data will generally not be transferred to third parties unless we are legally obliged to do so, or the transfer of data is necessary to carry out the contractual relationship, or you have previously expressly consented to the transfer of your data.
External service providers and partner companies such as online payment providers or the shipping company responsible for delivery only receive your data to the extent that this is necessary to process your order. In these cases, however, the scope of the data transmitted is limited to the necessary minimum. To the extent that our service providers come into contact with your personal data, we ensure that they comply with the provisions of data protection laws in the same way as part of order processing in accordance with Article 28 of the GDPR. Please also note the respective data protection information of the providers. The respective service provider is responsible for the content of third-party services, although we check the services for compliance with legal requirements as far as is reasonable.
We believe it is important to process your data within the EU/EEA. However, it may happen that we use service providers who process data outside the EU/EEA. In these cases, we ensure that an adequate level of data protection comparable to standards within the EU is established at the recipient before transferring your personal data.
26. Data security
We have taken extensive technical and operational precautions to protect your data from accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security procedures are regularly reviewed and adapted to technological advances.
26.1 Your rights
You have the following rights towards us regarding personal data relating to you. To exercise your above rights, please contact privacy@picdrop.com by email or by post
The data protection officer
PicDrop GmbH,
Am Kupfergraben 4/4a,
10117 Berlin
26.2 General Rights
We would be happy to inform you whether personal data relating to you is being processed; If this is the case, you have the right to information about this personal data and to the information listed in detail in Art. 15 GDPR. In addition, under the respective legal requirements, you have the right to rectification (Article 16 GDPR), the right to restriction of processing (Article 18 GDPR), the right to deletion (Article 17 GDPR) and the right to data portability (Article 20 GDPR).
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement, if you believe that the processing of personal data concerning you violates the GDPR. The supervisory authority to which the complaint was submitted will inform you of the status and results of the complaint, including the possibility of a legal remedy in accordance with Art. 78 GDPR.
26.3 Rights in data processing based on legitimate interest
In accordance with Article 21 Para. 1 GDPR, you have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you, which is carried out on the basis of Article 6 Para. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Updated: October 5th 2026