⚠️ Interim draft. The counsel-reviewed version will be published by 2026-06-15.
Privacy Policy
1. Controller
Kerim Agdaci, Elsenheimerstraße 25C, 85283 Wolnzach (see Imprint).
2. Data we process
- Email (sign-up, Telegram bot link)
- Tenant content (brand description, uploaded files, voice samples)
- IP address (pseudonymised via daily-rotating salt)
- Cookie IDs for session cookies
3. Purposes + legal bases
- Contract performance (GDPR Art. 6(1)(b)): platform provisioning
- Legitimate interest (Art. 6(1)(f)): security, anti-abuse
- Consent (Art. 6(1)(a)): C1-C7 as captured in the onboarding wizard
4. Processors / Sub-Processors
List of sub-processors per Art. 28 GDPR:
- Anthropic PBC (USA) — AI inference
- Cloudflare, Inc. (USA + EU) — hosting, KV, R2, Workers AI
- Supabase Inc. (USA with EU region) — database, auth
- AWS, Inc. (EU Frankfurt) — Remotion Render Lambda
- Resend, Inc. (USA; EU region migration scheduled 2026-06-08 — see migration runbook) — transactional email delivery (magic links, invitations)
- Telegram Messenger Inc. (BVI) — notification bot
- Exa Labs Inc. (USA) — web search
- Blotato Inc. (USA) — cross-platform posting
- Workers Logs / Observability (Cloudflare) — diagnostics
- MailerLite (Lithuania, EU) — email marketing (only on C7)
DPAs are signed or will be signed by 2026-06-15.
5. Retention
See retention matrix at /legal/help (category → location → period → legal basis).
6. Your rights
Art. 15 (access), 16 (correction), 17 (erasure), 18 (restriction), 20 (portability), 21 (objection), 22 (automated decision).
Complaint to supervisory authority (BayLDA for Bavaria): <https://www.lda.bayern.de>.
7. Contact
Privacy requests: contact@bykainsights.com
Last updated: 2026-06-03