Privacy Policy
1. Controller
Kerim Agdaci, Elsenheimerstraße 25C, 85283 Wolnzach (see Imprint).
2. Data we process
- Email (sign-up, Telegram bot link)
- Tenant content (brand description, uploaded files, voice samples)
- IP address (pseudonymised via daily-rotating salt)
- Cookie IDs for session cookies
3. Purposes + legal bases
- Contract performance (GDPR Art. 6(1)(b)): platform provisioning
- Legitimate interest (Art. 6(1)(f)): security, anti-abuse
- Contract performance / legal obligation (Art. 6(1)(b)/(c)): C1, C2a, C3, C4 — required conditions of the service, not freely-given consent
- Consent (Art. 6(1)(a)): C2b, C5a/C5b, C6a/C6b, C7, C8, C9 — freely given, withdrawable at any time in Settings → Consents
4. Processors / Sub-Processors
List of sub-processors per Art. 28 GDPR:
- Anthropic PBC (USA) — AI inference
- Cloudflare, Inc. (USA + EU) — hosting, KV, R2, Workers AI
- Cloudflare Public DNS Resolver (1.1.1.1) — destination-hostname resolution for the outbound-request safety check we run before contacting any web address you supply (notification webhooks, your own endpoints, website analysis). Only the destination hostname is sent — no cycle content and no identifier of you or your workspace. This is Cloudflare's public resolver service and runs under its own service terms, not under the customer agreement covering the hosting entry above.
- Supabase Inc. (USA with EU region) — database, auth
- AWS, Inc. (EU Frankfurt) — media rendering + GPU media generation (voice synthesis, music generation)
- Resend, Inc. (EU region, Ireland / eu-west-1) — transactional email delivery: magic links, workspace invitations, and cycle notifications to an email address you designate yourself in Settings → Notifications
- Telegram Messenger Inc. (BVI) — notification bot
- Exa Labs Inc. (USA) — web search
- Upload-Post / TONVI TECH SL (EU) — cross-platform posting (posting provider; only if you connect this provider)
- Workers Logs / Observability (Cloudflare) — diagnostics
- MailerLite (Lithuania, EU) — email marketing (only on C7)
Data processing agreements with all sub-processors are concluded before processing begins.
4a. Recipients you designate
Independently of the sub-processors above, you can direct the platform to send cycle notifications to destinations you choose yourself: a Telegram chat, a Slack workspace, an email address, or any HTTPS endpoint you name. When you configure such a destination, we transmit — on your instruction — only the cycle topic, the cycle ID, a link to the cycle and, for failures, a short reason. These recipients are not our sub-processors: we neither select them, contract with them, nor can we instruct or audit them. You remain responsible for that recipient, including its location and, where it lies outside the EU/EEA, for the transfer safeguard applicable to it. Once a message has been delivered we can neither recall nor control it. You can change or remove any destination at any time in Settings → Notifications.
5. Retention
See retention matrix at /legal/help (category → location → period → legal basis).
6. Your rights
Art. 15 (access), 16 (correction), 17 (erasure), 18 (restriction), 20 (portability), 21 (objection), 22 (automated decision).
Complaint to supervisory authority (BayLDA for Bavaria): <https://www.lda.bayern.de>.
No Data Protection Officer has been appointed, as the legal requirements under Art. 37 GDPR are not met.
7. Materials, knowledge-base processing, and AI assistant features (Phase 17)
In addition to items 2-4, we process the following as part of these features:
- Uploaded materials (corpus): documents/images you upload under Settings → Materials, plus derived text excerpts and vector embeddings. Purpose: building a searchable knowledge base for AI-assisted generation and the assistant feature. Legal basis: contract performance (Art. 6(1)(b) GDPR); where materials might touch Art. 9 GDPR special-category data, the separate rights-warranty you confirm at upload time additionally applies. Storage: private Cloudflare R2 area (organization-scoped) and Supabase database (EU region, row-level security). Embeddings are generated via Cloudflare Workers AI (model
@cf/baai/bge-m3); to the extent processing outside the EU occurs as part of model provisioning, it is safeguarded by EU Standard Contractual Clauses (Art. 46 GDPR). Retention: until you delete the individual material or your account; account deletion automatically erases all of your organization's materials records (files, database rows, derived embeddings). - Decision ledger: logs, for every content cycle, the engine's topic/format selection, your human review decision, and the publishing outcome — to improve the selection logic ("flywheel learning"). No solely automated decision with legal effect under Art. 22 GDPR occurs (human-in-the-loop is preserved). Legal basis: legitimate interest (Art. 6(1)(f) GDPR), alternatively contract performance. Retention + erasure: as above, same erasure pass as your materials.
- AI assistant feature (RAG): when you use the assistant feature (questions about your own materials, or research queries), your query and the matching text excerpts from your knowledge base are transmitted to Anthropic (Claude, USA) — the same processing already disclosed for regular content generation (item 4, AI inference). Transmission under EU Standard Contractual Clauses; Anthropic does not use your queries for model training. Processing is transient; we do not durably log the query in plaintext. The feature is subject to technical spend caps to prevent abusive use.
- Social publishing — multi-organization model: each organization gets its own, organization-specific Upload-Post profile (TONVI TECH SL, Spain) with its own connected social accounts. The DPA with TONVI TECH SL (version 1.4, countersigned 2026-06-14) covers this model at current usage volume. Deleting your account best-effort deprovisions your Upload-Post profile too.
8. Contact
Privacy requests: contact@bykainsights.com
Last updated: 2026-08-02