FaceStream.AI
Version: 9 October 2026
1. Controller
The controller responsible for the processing of personal data described in this Privacy Policy is:
kumkju Beteiligungs- und Verwaltungsgesellschaft mbH
Romain-Rolland-Straße 172
13089 Berlin
Germany
Managing Director: Norman Albusberger
Commercial Register: Amtsgericht Charlottenburg (Berlin), HRB 178056 B
EUID: DEF1103R.HRB178056B
VAT ID: DE413447111
Email: info@facestream-ai.com
Privacy requests: privacy@facestream-ai.com
FaceStream.AI is a brand of kumkju Beteiligungs- und Verwaltungsgesellschaft mbH.
This Privacy Policy applies to the FaceStream.AI website, customer portal, purchasing and licensing processes, activation service, update service, downloads, and communications with us.
2. Scope and distinction between FaceStream.AI and customer-operated installations
FaceStream.AI is face-recognition software designed to run entirely on hardware controlled by the customer, such as a Raspberry Pi, NAS, or server in the customer's own network.
The software may locally process names, portrait photographs, facial feature vectors, camera images, visit events and other information configured by the operator. These data are stored on the operator's hardware or on storage locations selected by the operator.
kumkju Beteiligungs- und Verwaltungsgesellschaft mbH does not receive and has no technical access to the faces, photographs, biometric feature vectors, camera addresses, recognition events or local configuration stored in a customer's FaceStream.AI installation. There is no cloud-based face recognition and no remote-maintenance access for the manufacturer.
The operator of an individual FaceStream.AI installation determines which cameras are used, which persons are enrolled, the purposes for which recognition is performed, how long locally generated data are retained, and whether information is transmitted to third-party destinations configured by the operator.
Accordingly, the operator is responsible for assessing the applicable data-protection requirements for its own use of FaceStream.AI and for providing any privacy information required for persons captured by its cameras or biometric-recognition system.
This Privacy Policy primarily describes processing for which kumkju Beteiligungs- und Verwaltungsgesellschaft mbH is responsible.
3. General legal bases for processing
We process personal data only where there is a legal basis for doing so. Depending on the processing activity, the relevant legal basis may in particular be:
- Article 6(1)(b) GDPR where processing is necessary to enter into or perform a contract, including purchasing, account administration, licensing, activation and delivery of the software;
- Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation, including statutory accounting, tax and record-retention obligations;
- Article 6(1)(f) GDPR where processing is necessary for our legitimate interests or those of a third party and those interests are not overridden by the interests or fundamental rights and freedoms of the data subject, including secure and reliable operation of our services, prevention of misuse, troubleshooting and protection of our IT infrastructure; and
- Article 6(1)(a) GDPR where we expressly request consent for a specific processing activity.
Where processing is necessary for entering into or performing a contract, failure to provide the required data may mean that we cannot enter into, perform or administer the relevant contract or licence.
4. Website and customer portal
4.1 Technical access data
When our website, customer portal, activation service, update service or download infrastructure is accessed, the server necessarily receives technical connection information. Depending on the service, this may include:
- IP address;
- date and time of access;
- requested resource or file;
- HTTP status;
- amount of data transferred;
- referrer; and
- user agent.
We process these data to deliver the requested service, maintain the security and stability of our infrastructure, diagnose technical errors and detect misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable and technically reliable provision of FaceStream.AI services and the protection of our systems.
Our relevant server infrastructure is hosted by Hetzner in a data centre in Finland, European Union.
Specific retention periods for activation, update and download logs are described below.
4.2 Customer account and portal
The FaceStream.AI portal processes information required to administer customers, purchases and licences. This may include:
- email address and account information;
- billing address;
- billing and contractual information;
- licences;
- registered devices or installation identifiers;
- information required to associate purchases with the customer account; and
- activation history associated with licences and installations.
A purchase may take place before a portal account is created. The purchase is subsequently associated with the portal account using the billing email address.
The purpose of this processing is to establish and administer the customer relationship, provide purchased licences and downloads, manage licences and devices, and enable customers to use the contractual services.
The legal basis is Article 6(1)(b) GDPR. Where records must be retained for tax, commercial or accounting purposes, Article 6(1)(c) GDPR also applies.
Customer, contractual and licence data are retained for as long as they are required for the customer relationship, for the administration of valid or otherwise relevant licences, or for compliance with statutory obligations. A customer may request deletion of personal data. We will comply with such a request to the extent that the data are no longer required for contractual or licence administration and no statutory retention obligation or other applicable legal ground requires continued processing.
5. Purchases, billing and payments
Payments are processed using Stripe, including Stripe Tax, in connection with the FaceStream.AI purchasing process.
Depending on the transaction, the data involved may include:
- billing email address;
- name and billing address;
- payment information;
- invoice and transaction information; and
- VAT identification number, where applicable.
Payment data required by Stripe for payment processing are transmitted to or collected by Stripe. We process the information made available to us in connection with the transaction for payment processing, contract administration, accounting and tax purposes.
The legal basis for processing necessary to execute the purchase is Article 6(1)(b) GDPR. Processing required to comply with tax, accounting or other statutory obligations is based on Article 6(1)(c) GDPR.
Stripe acts as an external recipient or service provider in connection with payment and tax processing. Stripe's own processing of personal data is also subject to its applicable privacy information.
6. Licence activation
6.1 When activation takes place
Where a licence contains an activation endpoint, an installed FaceStream.AI system contacts:
https://activation.facestream-ai.com/v1/activation
at startup and subsequently every six hours. If the activation status is unknown or unavailable, the software may retry every five minutes.
Licences intended for installations without internet access can be issued without an activation endpoint. Such installations do not contact the activation service.
6.2 Data transmitted by the software
An activation request contains:
- licence ID;
- machine/installation ID;
- product identifier;
- software version; and
- edition/variant.
The machine/installation ID is a shortened SHA-256-derived identifier generated from the most persistent locally available machine source, salted with the product name. Its purpose is to identify an installation without transmitting the underlying hardware serial number or source identifier.
The activation service additionally receives the public IP address and the time of the request as part of the network connection.
6.3 Activation logging
For each activation request, we log:
- timestamp;
- licence ID;
- machine/installation ID;
- reported edition;
- software version, including the Free/Pro variant;
- returned activation status;
- whether a signed lease was requested; and
- IP address.
The activation service does not log faces, photographs, biometric data, camera addresses, recognition events or the customer's local FaceStream.AI configuration.
We process activation data to validate and administer licences, provide signed activation status information, enforce licence status and revocation where applicable, diagnose activation problems, and detect misuse of licences.
To the extent activation is necessary for the relevant licence, the legal basis is Article 6(1)(b) GDPR. Security, misuse-prevention and technical diagnostic processing may additionally be based on Article 6(1)(f) GDPR. Our legitimate interests are the protection of our licensing system, prevention of licence misuse, and reliable operation and troubleshooting of the activation service.
6.4 Retention
IP addresses in activation logs are retained for 90 days and are then removed from the activation logs.
The remaining activation log data are retained for 12 months.
After that period, only aggregated counts without IP addresses or personal references are retained.
7. Update checks
FaceStream.AI may request the static update information available from:
https://updates.facestream-ai.com/stable.json
The standard software configuration checks for updates every six hours and may perform an additional background check when the user interface is opened and the previous result is more than one hour old. The operator can disable update checks.
The update request does not contain a licence ID, machine ID, installed software version or edition identifier. The public IP address is necessarily transmitted when the server is contacted.
For the update feed, our Nginx access logs record:
- IP address;
- timestamp;
- requested file;
- HTTP status;
- amount of data transferred;
- referrer; and
- user agent.
These logs are retained for 30 days.
The data are processed to provide the update service, maintain its security and availability, diagnose errors and detect misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are secure and reliable service operation and IT security.
The update check only retrieves information about available software versions. It does not automatically install an update.
8. Software downloads
Public and protected software downloads generate standard Nginx access-log entries containing:
- IP address;
- timestamp;
- requested file;
- HTTP status;
- amount of data transferred;
- referrer; and
- user agent.
We do not maintain an additional personalised download history beyond information required for portal, contractual or licence administration.
Nginx access logs for downloads are retained for 30 days.
The processing is necessary to deliver requested software and downloads and to maintain the security, integrity and technical availability of the download infrastructure. Depending on the download, the legal basis is Article 6(1)(b) GDPR and/or Article 6(1)(f) GDPR.
The download infrastructure is hosted by Hetzner in Finland, European Union.
9. Email communications
We use Mailjet to send customer emails.
In this context, the recipient's email address and the content of the relevant customer email are processed.
Transactional emails may include communications relating to purchases, accounts, billing, licences, activation or other customer-service matters.
Where an email is necessary to perform or administer a contract, the legal basis is Article 6(1)(b) GDPR. Where an email is required to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR. Other necessary service communications may be based on Article 6(1)(f) GDPR, where applicable.
We currently do not send newsletters. If we introduce marketing newsletters in the future, the relevant privacy information and, where required, consent mechanism will be implemented before that processing begins.
10. Customer support and direct communications
Customers may contact us using the published contact addresses, including:
info@facestream-ai.comfor general enquiries;support@facestream-ai.comfor product questions;billing@facestream-ai.comfor billing and tax matters;privacy@facestream-ai.comfor privacy requests; andsecurity@facestream-ai.comfor vulnerability reports.
We process the sender's contact information and the content of the communication in order to respond to and manage the request.
There is currently no dedicated ticketing system.
FaceStream.AI does not contain an integrated mechanism that automatically sends product logs, screenshots, configuration files, camera information, faces or event data to us. If information from a customer's installation is provided to us voluntarily in an individual support case, the processing of that material must be assessed according to the content and circumstances of that support request. Customers should avoid sending personal data or confidential configuration information unless it is necessary for resolving the support matter.
The legal basis is Article 6(1)(b) GDPR where the communication relates to a contract or pre-contractual request. Otherwise, processing may be based on Article 6(1)(f) GDPR, with our legitimate interest being the handling of enquiries, support requests and security reports.
11. Cookies and similar technologies
Only technically necessary cookies are used where required to provide the requested functionality, for example authentication or session functionality.
11.1 Umami Cloud website analytics
On the publicly accessible FaceStream.AI website, we use the web analytics service Umami Cloud, provided by Umami Software, Inc., Delaware, United States. Umami helps us understand in aggregate how the website is found and used so that we can assess its reach, improve content and navigation, and identify technical problems.
The Umami tracker is not loaded until you have given your consent. If
you consent, your browser retrieves the tracker from
https://cloud.umami.is/script.js and transmits analytics data to
Umami. Depending on the page view, these data include the requested URL
and page title, referrer URL, time of access, hostname, browser language,
screen resolution, browser, operating system, device type and country
derived from the connection. The IP address and user agent are
necessarily transmitted when communicating with Umami's servers. Umami
states that the analytics data are anonymised, no personally
identifiable information is stored and visitors are represented by an
anonymous session identifier.
Umami does not set analytics cookies and does not track visitors across different websites. We do not assign a distinct ID, transmit account data or use session replay or heatmap functions. Umami is not loaded in the customer account, authentication area or administration area.
Processing and access to information on your device take place only with your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You may refuse consent without any disadvantage. You may also withdraw it at any time with effect for the future by selecting “Privacy settings” in the website footer and then “Decline”. Withdrawal does not affect processing carried out before withdrawal.
Your decision is stored in your browser's local storage under
facestream.analytics-consent.v1. This entry contains only granted or
denied. It is used solely to remember and implement your privacy
choice and remains until you delete the browser storage or make a new
choice.
Umami processes analytics data for us as a processor. Depending on our Umami Cloud plan, analytics events are retained for the period provided by the plan and are then deleted; Umami currently specifies six months for the Hobby plan, two years for Pro and five years for Business. We will delete data earlier where they are no longer required and this is available under the service. Further information is available in Umami's privacy policy, DPA and subprocessor list.
No advertising cookies or cross-site marketing technologies are used.
The locally operated FaceStream.AI software uses the
facestream_session cookie for authenticated sessions in the product's
local web interface. The session has a duration of 12 hours. This local
interface is operated on the customer's own installation and is not a
cloud service through which kumkju Beteiligungs- und
Verwaltungsgesellschaft mbH receives the customer's local recognition
data.
12. Hosting
The relevant FaceStream.AI server infrastructure, including the portal, licensing/activation services, update infrastructure and downloads, is hosted by Hetzner.
The servers concerned are located in Finland, European Union.
In connection with hosting, the hosting provider may process technical server and connection data as necessary to provide and secure the infrastructure. Where the provider processes personal data on our behalf, such processing is carried out as a service provider to us.
13. Recipients and service providers
Personal data may be disclosed to service providers where this is necessary to provide FaceStream.AI services or fulfil contractual or legal obligations.
The service providers identified for the current service include in particular:
- Hetzner --- hosting and server infrastructure in Finland, EU;
- Stripe --- payment processing and Stripe Tax; and
- Mailjet --- sending customer emails; and
- Umami Software, Inc. --- consent-based analytics for the public website.
We may also disclose data to public authorities, courts, tax authorities or other legally entitled recipients where we are required to do so by law or a binding legal request.
We do not disclose the locally stored facial images, biometric feature vectors, recognition events or local camera configuration of customer-operated FaceStream.AI installations because, according to the product architecture, we do not receive or have technical access to those data.
14. Processing inside customer-operated FaceStream.AI installations
This section is provided to distinguish the manufacturer's processing from processing performed by customers using the software.
Depending on how an operator configures FaceStream.AI, a local installation may process:
- names assigned to enrolled persons;
- portrait photographs;
- 128-dimensional facial feature vectors used for recognition;
- face crops;
- full camera still images associated with recognition events;
- timestamps and visit information;
- camera identifiers;
- liveness/anti-spoofing results;
- delivery logs containing person names, message content and responses from configured destination systems;
- camera addresses and credentials; and
- credentials and tokens for notification systems configured by the operator.
FaceStream.AI does not record continuous video or audio. It does not estimate age, gender, ethnicity, emotion or behaviour. According to the product architecture, it does not send telemetry, usage statistics or crash reports to the manufacturer.
Enrolled persons are not automatically deleted by the software. The operator can delete persons and individual photographs.
For recognition events, the default local retention configuration is:
Local data Default
Visit events 90 days Maximum number of visits 500 Full-frame event images 14 days
The operator can change these settings and can disable individual limits by setting them to zero. The operator can also manually delete individual visits or all visits.
Delivery logs are limited to 500 entries, after which the oldest entries are removed.
These retention settings concern data stored under the operator's control and are not retention periods applied by kumkju Beteiligungs- und Verwaltungsgesellschaft mbH.
The operator is responsible for determining whether and on what legal basis it may use cameras, facial recognition and biometric identifiers, which persons may be enrolled, what retention periods are appropriate, what notices must be provided, and whether additional obligations apply to the particular deployment.
15. Destinations configured by the operator
A FaceStream.AI operator can configure the locally operated software to send recognition information to destinations selected by that operator, including email/SMTP, Telegram, Pushover, ntfy, MQTT, webhooks, KNX, Loxone, Syslog and UDP.
Depending on the operator's configuration, messages may contain a person's name, camera information, recognition status, liveness result, date and time, event information, and in some channels a face crop or full-frame image.
A new installation has no connection or notification rule configured by default.
These transmissions are initiated and configured by the operator. kumkju Beteiligungs- und Verwaltungsgesellschaft mbH does not select the recipients and does not receive the transmitted content merely because FaceStream.AI is used.
Operators must independently assess the privacy and security implications of the destinations they configure.
16. No manufacturer access to biometric and camera content
For clarity, the following information from a customer's local FaceStream.AI installation is not transmitted to us as part of the product's normal operation:
- names of recognised or enrolled persons;
- portrait photographs;
- facial feature vectors;
- face crops or full-frame event images;
- camera addresses or credentials;
- local recognition events;
- number of enrolled persons;
- local notification rules or credentials; or
- the local FaceStream.AI configuration.
The only routine product-originated communication to the manufacturer is the licence activation process described in Section 6 and the separate update request described in Section 7. Offline licences without an activation endpoint do not perform activation requests, and update checks can be disabled.
17. Data security
We use technical and organisational measures appropriate to the nature of the processing to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The FaceStream.AI product architecture is designed so that biometric and camera content remains on hardware controlled by the operator unless the operator itself configures an external destination.
For communications with the activation service, HTTPS is mandatory.
No internet-based service can be guaranteed to be absolutely secure. Customers are responsible for appropriately securing their own FaceStream.AI installations, networks, cameras, credentials and configured third-party destinations.
18. International data transfers
Our FaceStream.AI hosting infrastructure described above is located in Finland within the European Union.
Some external service providers used for payment processing, email delivery or website analytics may operate internationally or use infrastructure or subprocessors in different countries. Umami Software, Inc. is a company in the United States; Umami states that its Cloud servers are located in the United States and the European Union and publishes a data-processing agreement incorporating safeguards for international transfers. Even where the selected data region is in the EU, access or processing from a third country cannot be entirely ruled out.
Where personal data are transferred to a country outside the European Union or European Economic Area and an adequate level of protection is not otherwise established, the transfer must be based on an applicable safeguard under Chapter V GDPR, such as an adequacy decision or appropriate contractual safeguards, in particular the European Commission's standard contractual clauses.
Further information regarding safeguards applicable to a particular
transfer may be requested using privacy@facestream-ai.com.
19. Statutory retention obligations
Even where personal data are no longer required for active customer or licence administration, we may be legally required to retain certain contractual, invoice, accounting or tax records for statutory retention periods.
During such mandatory retention periods, processing is restricted to the purposes permitted by law unless another legal basis permits further processing.
Once the applicable purpose and mandatory retention requirements cease to apply, the relevant personal data are deleted or anonymised unless another legal basis permits continued processing.
The specific technical retention periods stated in this Privacy Policy, including 30-day download and update logs, 90-day activation IP retention and 12-month activation-log retention, remain unaffected.
20. Rights of data subjects
Subject to the requirements and limitations of applicable law, data subjects have the following rights under the GDPR:
- Right of access under Article 15 GDPR;
- Right to rectification under Article 16 GDPR;
- Right to erasure under Article 17 GDPR;
- Right to restriction of processing under Article 18 GDPR;
- Right to data portability under Article 20 GDPR;
- Right to object under Article 21 GDPR; and
- Right to withdraw consent at any time under Article 7(3) GDPR where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to object to processing based on legitimate interests
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you.
We will then cease processing the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
Requests concerning data-subject rights may be sent to:
privacy@facestream-ai.com
21. Right to lodge a complaint
You have the right to lodge a complaint with a competent data-protection supervisory authority if you consider that the processing of personal data relating to you infringes the GDPR.
You may in particular contact the supervisory authority responsible for our establishment in Berlin or the supervisory authority at your habitual residence, place of work or place of the alleged infringement.
22. Automated decision-making
We do not use the personal data processed by the manufacturer-side services described in this Privacy Policy for decision-making based solely on automated processing that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
The facial-recognition functionality performed locally by a customer's installation is controlled by the respective operator and is outside the manufacturer's access. Operators must independently assess any decisions or actions they connect to recognition results.
23. Changes to this Privacy Policy
We may amend this Privacy Policy where this becomes necessary due to changes in our services, technical infrastructure, processing activities or applicable legal requirements.
The current version will be made available through the FaceStream.AI website or portal.
Last updated: 9 October 2026