Privacy policy
What data we process, why, for how long — and what rights you have.
Demo page — this text is not binding
This page is part of a demonstration of KiViP Concierge. The text is complete but has not been reviewed by a lawyer; personal names are placeholders. No rights or obligations arise from it. This notice will be removed before going live — and not before.
In short
— You send us tasks in a chat. What you send is processed in order to complete them. — Answers are produced with the help of an AI model. A person reviews the result before you receive it. — We do not analyse your content for advertising, do not sell it and do not train models with it. — There is no tracking on these pages. Only a technically necessary session cookie — hence no cookie banner. — You can have your data deleted, except for what we are legally required to keep.
Controller
The controller under the GDPR is: ALSEMIMA Distribution Systems GmbH, Carl-Zeiss-Straße 5, 71229 Leonberg Email: info@alsemima.com No data protection officer has been appointed; the conditions of Art. 37 GDPR do not currently apply.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and may withdraw consent at any time. Write to info@alsemima.com; we reply within one month. You may also lodge a complaint with the supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
What we process and why
We only process what is necessary to run the service. The legal basis is stated in each case.
Account
Name, email address, password (hashed only), language, time zone, form of address, and — if enabled — two-factor or passkey credentials. Basis: performance of the contract, Art. 6(1)(b) GDPR.
Chat content and files
Everything you send us — messages, documents, images, audio and video — and what is produced from it. What your concierge remembers is visible and editable in your account. Basis: Art. 6(1)(b) GDPR.
Billing
Top-ups, balance, usage per task, invoices and the details required for tax. Basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR.
Access and security logs
We log who accessed which customer data and when — including within our own team — plus standard server logs. Basis: legitimate interest, Art. 6(1)(f) GDPR.
Cookies
A session cookie so you stay signed in, and a local note about light or dark mode. Nothing else — no analytics, advertising or third-party cookies, and therefore no cookie banner.
Artificial intelligence
Most of the work is produced with the help of a language model. What that means for your data is set out here.
What is transmitted
To answer a request we transmit the necessary excerpt of your content to the model provider — no more than that. Providers are OpenAI Ireland Ltd. and Anthropic PBC, under Art. 28 GDPR agreements and, where data leaves the EU, the EU standard contractual clauses.
No training on your content
Your content is not used to train models — neither by us nor by the model provider. This is contractually assured.
A human decides
There is no automated decision-making within the meaning of Art. 22 GDPR. A concierge reviews the result before you receive it, and AI replies are always identifiable as such.
No emotion recognition from voice or face
If we analyse a recording, we analyse the text in it. We do not infer emotional state from voice, pace, pauses or facial expression — Art. 5 of the EU AI Act, applied everywhere rather than only where it is mandatory.
Special categories of data
Documents you send may contain data specially protected under Art. 9 GDPR. Such processing relies on your separate, explicit consent (Art. 9(2)(a)), the content is stored encrypted, and no full text of it enters a search index.
Who else sees the data
We only pass data to processors necessary for operation, under Art. 28 GDPR agreements. We do not sell data and do not share it for advertising.
Recipients
- Hosting
- Hetzner Online GmbH, Germany — operating the application, servers in Germany.
- Payments
- Stripe Payments Europe Ltd., Dublin — processing top-ups. We never see card or bank details.
- Mailgun Technologies Inc. — delivery of confirmations, invitations and notifications.
- AI models
- OpenAI Ireland Ltd. and Anthropic PBC — answering your requests.
If this list changes, this policy changes with it.
Transfers outside the EU
Hosting and payment processing take place in the EU. Transfers to the USA cannot be ruled out for email delivery and the model providers; they rely on the EU standard contractual clauses and supplementary measures.
How long we keep data
Retention periods:
Retention periods
- Account
- Until you delete it; then without undue delay.
- Chats and files
- Until you delete them or close the account.
- Invoices and ledger
- Ten years, as required by German tax and commercial law.
- Access logs
- Twelve months.
- Server logs
- Thirty days.
After expiry, data is deleted or anonymised.
Security
Transport is encrypted; specially protected content is additionally encrypted at rest; internal access is individually granted, revocable and logged; two-factor authentication and passkeys are available.
Changes to this policy
We update this policy when processing changes. The version published here applies.
Authoritative version
In case of discrepancies between language versions, the German version prevails.
Last updated
August 2026