Legal

Privacy policy

Last updated: 5 May 2026

1. Who we are

fonkle. is a Dutch company that creates personalised children's books using AI. We are the data controller within the meaning of the General Data Protection Regulation (GDPR). For questions about this privacy policy or your personal data, contact us at [email protected].

2. What personal data we collect

We only collect data necessary to process your order:

  • Name, email address and phone number
  • Delivery address (street, postcode, city, country)
  • Photos you upload for personalising your book
  • Payment details are processed by Stripe; we do not store card data

3. Legal basis and purposes

We process your data on the following legal bases (Article 6 GDPR):

  • Performance of contract — generating, printing and delivering your book
  • Performance of contract — processing your payment
  • Performance of contract — sending order status updates
  • Legitimate interest — customer service for questions or issues

4. Processors and transfers

To create and deliver your book, we engage the following processors (Article 28 GDPR):

  • Anthropic (US) — AI analysis of photos and story generation
  • Google (US) — illustration generation
  • Stripe (US/EU) — payment processing
  • Lulu (US) — book printing and shipping
  • Resend (US) — sending transactional emails
  • Cloudflare (US/EU) — hosting and storage

Some of these processors are based in the United States. Transfers are carried out under the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses (SCCs).

5. Retention periods

Order data (name, address, email, payment status) is retained for seven years for tax compliance purposes. Uploaded photos and generated book files are deleted within 90 days after delivery, unless you request earlier deletion.

6. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or theft. All data transfers are encrypted (TLS). Photos and book files are stored in encrypted cloud storage with restricted access.

7. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability and objection to processing. Send your request to [email protected]. We will respond within 30 days. You may also file a complaint with the Dutch Data Protection Authority.

8. Cookies

We only use strictly necessary cookies for the website to function, such as maintaining your login session and remembering your book in progress. We do not place tracking, analytics or advertising cookies.

9. Changes

We may update this privacy policy. In case of material changes we will inform you by email or a notice on the website. The date at the top indicates when this policy was last updated.