Privacy policy

What data we process, why, for how long — and what rights you have.

Demo page — this text is not binding

This page is part of a demonstration of KiViP Concierge. The text is complete but has not been reviewed by a lawyer; personal names are placeholders. No rights or obligations arise from it. This notice will be removed before going live — and not before.

In short

— You send us tasks in a chat. What you send is processed in order to complete them. — Answers are produced with the help of an AI model. A person reviews the result before you receive it. — We do not analyse your content for advertising, do not sell it and do not train models with it. — There is no tracking on these pages. Only a technically necessary session cookie — hence no cookie banner. — You can have your data deleted, except for what we are legally required to keep.

Controller

The controller under the GDPR is: ALSEMIMA Distribution Systems GmbH, Carl-Zeiss-Straße 5, 71229 Leonberg Email: info@alsemima.com No data protection officer has been appointed; the conditions of Art. 37 GDPR do not currently apply.

Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection, and may withdraw consent at any time. Write to info@alsemima.com; we reply within one month. You may also lodge a complaint with the supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

What we process and why

We only process what is necessary to run the service. The legal basis is stated in each case.

Account

Name, email address, password (hashed only), language, time zone, form of address, and — if enabled — two-factor or passkey credentials. Basis: performance of the contract, Art. 6(1)(b) GDPR.

Chat content and files

Everything you send us — messages, documents, images, audio and video — and what is produced from it. What your concierge remembers is visible and editable in your account. Basis: Art. 6(1)(b) GDPR.

Billing

Top-ups, balance, usage per task, invoices and the details required for tax. Basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR.

Access and security logs

We log who accessed which customer data and when — including within our own team — plus standard server logs. Basis: legitimate interest, Art. 6(1)(f) GDPR.

Cookies

A session cookie so you stay signed in, and a local note about light or dark mode. Nothing else — no analytics, advertising or third-party cookies, and therefore no cookie banner.

Artificial intelligence

Most of the work is produced with the help of a language model. What that means for your data is set out here.

What is transmitted

To answer a request we transmit the necessary excerpt of your content to the model provider — no more than that. Providers are OpenAI Ireland Ltd. and Anthropic PBC, under Art. 28 GDPR agreements and, where data leaves the EU, the EU standard contractual clauses.

No training on your content

Your content is not used to train models — neither by us nor by the model provider. This is contractually assured.

A human decides

There is no automated decision-making within the meaning of Art. 22 GDPR. A concierge reviews the result before you receive it, and AI replies are always identifiable as such.

No emotion recognition from voice or face

If we analyse a recording, we analyse the text in it. We do not infer emotional state from voice, pace, pauses or facial expression — Art. 5 of the EU AI Act, applied everywhere rather than only where it is mandatory.

Special categories of data

Documents you send may contain data specially protected under Art. 9 GDPR. Such processing relies on your separate, explicit consent (Art. 9(2)(a)), the content is stored encrypted, and no full text of it enters a search index.

Who else sees the data

We only pass data to processors necessary for operation, under Art. 28 GDPR agreements. We do not sell data and do not share it for advertising.

Recipients

Hosting
Hetzner Online GmbH, Germany — operating the application, servers in Germany.
Payments
Stripe Payments Europe Ltd., Dublin — processing top-ups. We never see card or bank details.
Email
Mailgun Technologies Inc. — delivery of confirmations, invitations and notifications.
AI models
OpenAI Ireland Ltd. and Anthropic PBC — answering your requests.

If this list changes, this policy changes with it.

Transfers outside the EU

Hosting and payment processing take place in the EU. Transfers to the USA cannot be ruled out for email delivery and the model providers; they rely on the EU standard contractual clauses and supplementary measures.

How long we keep data

Retention periods:

Retention periods

Account
Until you delete it; then without undue delay.
Chats and files
Until you delete them or close the account.
Invoices and ledger
Ten years, as required by German tax and commercial law.
Access logs
Twelve months.
Server logs
Thirty days.

After expiry, data is deleted or anonymised.

Security

Transport is encrypted; specially protected content is additionally encrypted at rest; internal access is individually granted, revocable and logged; two-factor authentication and passkeys are available.

Changes to this policy

We update this policy when processing changes. The version published here applies.

Authoritative version

In case of discrepancies between language versions, the German version prevails.

Last updated

August 2026