Back to resources

Legal register

Product Privacy Notice

Englishproduct-privacy-notice

AUVY · Legal registerEnglishproduct-privacy-notice

AUVY — In-Product

AUVY GmbH · Am Haag 8 · 82166 Gräfelfing · HRB 311039 (AG Munich) · VAT ID DE461400892

Data protection: privacy@auvy.ai · Security: security@auvy.ai · General: contact@auvy.ai

Version: 1.2 · Last updated: 2026-08-10

Application to consumer customers (B2C): In contracts with consumers within the meaning of § 13 German Civil Code (BGB), no processor relationship exists. AUVY is controller within the meaning of Art. 4 No. 7 GDPR for all personal data processed in that context — including content the consumer brings into their personal workspace. The purposes, legal bases, retention periods, recipients and data subject rights described below apply accordingly; this Notice replaces the DPA as the sole basis of processing. Professional secret-holder data (§ 203 German Criminal Code) remains prohibited for consumer contracts (see § 6).

§ 1 Purpose of this Notice

This Privacy Notice informs you under Art. 13 and 14 GDPR about the processing of personal data by AUVY GmbH ("AUVY") when you use AUVY as an end user of your workspace.

This notice applies in addition to the General Terms and Conditions – AUVY and the DPA; in case of conflict, the individual contractual provisions prevail.

§ 2 Controller and Contact Details

The controller for the processing activities described in this notice is:

AUVY GmbH · Am Haag 8 · 82166 Gräfelfing · Germany

Represented by managing directors Achim Ströbel and Patrick Schröppel.

We have not currently appointed an external Data Protection Officer.

§ 3 Role Allocation in Detail

Data category AUVY role Legal basis
Workspace content, prompts, uploaded files, AI outputs ("Customer Data") Processor for B2B workspaces; controller for B2C consumer workspaces DPA (B2B) or this notice (B2C)
Account master data (name, email, workspace role) Controller this notice
Authentication, session tokens Controller this notice
Billing and contract data Controller this notice
Security, audit and diagnostic logs for platform operation Controller this notice
Telemetry on platform stability (pseudonymized) Controller this notice

The following sections describe exclusively processing activities in which AUVY is the controller. For processing of Customer Data, the DPA applies.

§ 4.1 Account Creation and Authentication

  • Data: name, email address, password hash, workspace membership and role, Better Auth session and sign-in metadata, and MFA / WebAuthn factors where enabled.

  • Purpose: service provision, access control, identity verification.

  • Legal basis: Art. 6 (1)(b) GDPR (contract performance) and (f) GDPR (legitimate interest in secure authentication).

§ 4.2 Workspace Administration

  • Data: workspace name, memberships, roles, settings, license assignments.

  • Purpose: configuration and administration of the customer workspace.

  • Legal basis: Art. 6 (1)(b) GDPR.

§ 4.3 AI Inference and Customer Data Processing

Substantive AI inference on Customer Data takes place under processor terms; insofar, the Customer is controller and AUVY is processor (see DPA).

For operational telemetry of the inference pipeline (latencies, model routing, errors), AUVY collects pseudonymized metadata as controller to ensure service operation (Art. 6 (1)(f) GDPR). Content itself is not part of this telemetry.

§ 4.4 Security and Audit Logs

  • Data: login events, authentication successes/failures, geo-IP, user agent, security-relevant actions (workspace settings, role changes, token creation).

  • Purpose: protection against unauthorized access, traceability, fulfillment of security obligations toward customers.

  • Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in security) in conjunction with Art. 32 GDPR.

§ 4.5 Billing and Contract Administration

  • Data: contractual party master data, invoice data, payment records, acceptance logs of GTC/AUP versions.

  • Purpose: invoicing, tax obligations, evidence of GTC inclusion.

  • Legal basis: Art. 6 (1)(b) GDPR (contract performance), (c) GDPR (statutory obligations, in particular § 14 UStG, §§ 147 AO, 257 HGB).

  • Payment processing: Stripe Payments Europe Ltd., Ireland.

§ 4.6 Support and Communication

  • Data: content of your inquiries, contact details, possibly workspace IDs for reproduction.

  • Purpose: processing of support requests.

  • Legal basis: Art. 6 (1)(b) and (f) GDPR.

§ 4.7 Product Improvement

  • Data: exclusively anonymized and aggregated usage statistics (e.g., number of active sessions, feature usage).

  • Purpose: stability and further development of the platform.

  • Legal basis: Art. 6 (1)(f) GDPR.

  • Important: Customer Data is not used for product improvement or training purposes (see § 5).

§ 4.8 Customer-Enabled Integrations

When you enable third-party integrations in the workspace, AUVY processes connection metadata, OAuth tokens, and tool request/response payloads needed to run the integration. The connected third-party service may process data under its own terms as an independent recipient.

  • Purpose: provide integrations you explicitly enable in the workspace.

  • Legal basis: Art. 6 (1)(b) GDPR (contract performance) and, where applicable, Art. 6 (1)(a) GDPR (consent during OAuth).

  • Recipients: the connected service and infrastructure required to operate the integration (see subprocessors register). Destination systems you enable act as independent recipients under your control.

§ 5 AI-Specific Processing

(1) No training on customer data. AUVY does not use Customer Data or AI outputs to train or fine-tune own or third-party AI models.

(2) Contractual assurances by model providers. AUVY uses AI models via AWS Bedrock, Microsoft Azure where configured, and other model providers identified in the Trust Center subprocessor register. Providers process under their applicable contracts and DPAs; submitted content is not designated for model training where covered. This is not a blanket assurance about customer-selected destinations.

(3) Web tools. Product web_search / web_read use Linkup (EU / Azure EU). Only data needed for the active tool call is sent. See register v3.1.

(4) AI inference retention. Inference content is retained at the model providers in accordance with their contractual commitments only briefly (typically a few hours) for abuse detection, or discarded directly.

(5) Transparency under Art. 50 EU AI Act. Article 50 has applied since 2 August 2026. AUVY handles provider duties for covered AUVY direct-interaction systems, including informing users that they are interacting with AI unless obvious. A business customer acting as deployer remains responsible for deployment-specific notices, including covered emotion-recognition or biometric-categorisation notices and disclosure of deepfakes or certain AI-generated public-interest text. For consumer workspaces, AUVY remains controller for the consumer context described above.

(6) Machine-readable provenance. Where Article 50 (2) applies to AUVY in a provider role, AUVY must implement technically feasible marking and detection measures for covered synthetic content. Marks can be removed or degraded by copying, editing, conversion, screenshots, or downstream tools and do not prove factual accuracy or authorship. AUVY does not claim that every output has persistent machine-readable provenance.

(7) Prohibited and high-risk AI. AUVY may not be used for prohibited practices under Article 5 and is not approved by default for high-risk uses under Annex III; see AUP § 6.

(8) AI literacy. AUVY takes role-appropriate AI-literacy measures for personnel who operate and support AI features. Business customers retain corresponding obligations for persons acting on their behalf. This is not a blanket compliance claim for a customer's deployment.

§ 6 Professional Secret-Holders and Special Data Categories

(1) Input of special categories of personal data within the meaning of Art. 9 GDPR by the Customer is permitted only if the Customer has a valid legal basis and AUVY has been informed in advance (see AUP § 7).

(2) Processing of professional secret-holder data within the meaning of § 203 of the German Criminal Code (in particular data of clients, patients or comparable entrustors of physicians, attorneys, tax advisors, notaries, psychotherapists) is permitted in AUVY only if the confidentiality clause in § 12 of the AVV (DPA / Annex A) has been bilaterally activated in text form — i.e., text-form confirmation by the Customer and text-form counter-confirmation by AUVY that the obligations of employees and sub-processors required under § 12(3) of the AVV are in place.

Until this bilateral activation has occurred, the input of professional secret-holder data is prohibited. There is no technical product feature for this; admissibility derives exclusively from the contractual activation. Because the prerequisites of the counter-confirmation are organizationally demanding, activation is in practice reserved for Enterprise Customers.

§ 7 Recipients and Sub-Processors

(1) For the operation of AUVY, AUVY engages the following sub-processors — both for Customer Data (in processor capacity) and for controller data (data processing in the strict sense under Art. 28 GDPR):

Provider Purpose Location
Hetzner Online GmbH App services, workers, and self-hosted stores (PostgreSQL, MongoDB, Redis, Qdrant, object storage) EU (Helsinki — hel1)
Amazon Web Services EMEA SARL EU cloud infrastructure and AI inference (Bedrock) EU (Frankfurt)
Microsoft Ireland Operations Ltd. AI inference (Azure, where configured); speech-to-text EU (Frankfurt, Sweden)
Linkup SAS Product web_search / web_read (web search and page contents) EU (Azure EU)
Vercel Inc. Frontend / edge hosting EU (Frankfurt); edge may route request metadata globally
Stripe Payments Europe, Ltd. Payment processing, tax logic EU (Ireland)
Resend Inc. Transactional email (login, confirmations) EU send (Ireland); account metadata in US (GDPR DPA, SCCs, DPF)
PostHog Inc. Optional product analytics and feature flags when enabled EU (Frankfurt)

(2) OpenPulse is a service operated by AUVY on internal EU infrastructure in Helsinki; the repository does not establish a separate contracting legal entity, so it is not represented as a third-party subprocessor. Customer-selected destinations are independent recipients under the customer's control.

(3) The current list with update date is available at trust.auvy.ai/subprocessors (register v3.1, 2026-08-10). “Optional” means data is sent only when the relevant configured feature/path is invoked. Changes are announced at least 30 days in advance; rights to object follow the DPA. Public version history: trust.auvy.ai/changelog.

(4) Disclosure to authorities occurs only in case of mandatory legal obligation.

§ 8 Third-Country Transfers

Where personal data is transferred to third countries, AUVY relies on:

  • the EU-US Data Privacy Framework, where the respective provider is certified;

  • the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) under Module 2/3;

  • supplementary technical and organizational guarantees (encryption, access restrictions, EU region pinning where offered).

Copies of relevant safeguards are available via privacy@auvy.ai.

§ 9 Retention Periods

Data category Retention
Identity and account master data while the user account exists; erased or anonymized after a valid identity-erasure request where no legal grounds require retention. Identity erasure does not automatically delete a shared workspace.
Authentication tokens only as long as the session is active; max. according to expired token lifetime
Customer Data (workspace content) as per DPA for B2B; export and owner-authorized workspace deletion in product; final deletion generally 30 days after workspace contract termination. Removing one member or identity does not automatically delete content controlled by the remaining workspace.
Security / audit logs typically 12 months; security-relevant case-by-case extension
Telemetry / diagnostics pseudonymized; up to 90 days person-relatable, then aggregated/anonymized
Accounting vouchers and invoices generally 8 years under German commercial and tax law
Annual accounts, inventories, commercial books, comparable accounting records may be 10 years
Commercial and business correspondence generally 6 years
Contract and acceptance evidence category- and purpose-based; extensions apply where tax, audit, litigation, limitation, or other law requires

§ 10 Security Measures

AUVY takes appropriate technical and organizational measures, in particular:

  • TLS 1.2+ in transit · AES-256 (or equivalent) at rest for production volumes;

  • RBAC, logical tenant separation, Better Auth session controls, and customer MFA / WebAuthn where enabled;

  • daily encrypted backups of the Mongo document / trace plane (Postgres / identity backup operated separately);

  • workspace audit logs for security-relevant product actions;

  • contractual incident notification paths under Art. 33 GDPR and the AVV.

Full TOMs see AVV, Annex 2.

§ 11 Your Rights as a Data Subject

(1) Where AUVY is controller (see § 3), you have the following rights:

  • access (Art. 15 GDPR),

  • rectification (Art. 16 GDPR),

  • erasure (Art. 17 GDPR), insofar as no retention obligations preclude this,

  • restriction of processing (Art. 18 GDPR),

  • data portability (Art. 20 GDPR),

  • objection to processing based on legitimate interests (Art. 21 GDPR),

  • withdrawal of granted consent with effect for the future (Art. 7 (3) GDPR).

(2) Where AUVY is processor (Customer Data), please contact your workspace administrator or the contractual party of your company that, as controller, processes the request. AUVY supports the controller under Art. 28(3) GDPR.

(3) Requests directly to AUVY: privacy@auvy.ai. To protect against abuse, we may request additional identity verification.

(4) An identity/account erasure request and a workspace-deletion request have different effects. AUVY can erase or anonymize the requesting person's controller data where legally possible. A shared B2B workspace remains under the organisational controller and is deleted only on an authorised workspace instruction or at the end of the workspace contract.

§ 12 Right to Lodge a Complaint

Notwithstanding other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular the authority competent at AUVY's seat:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 18 · 91522 Ansbach · lda.bayern.de

§ 13 Automated Decisions

AUVY does not make solely automated decisions with legal or similarly significant effect within the meaning of Art. 22 GDPR toward end users in the AUVY product. AI-generated outputs are non-binding suggestions; their use is the Customer's responsibility; see GTC § 14.

§ 14 Changes to this Notice

AUVY adapts this notice when legal frameworks or processing activities change. Material changes are announced at least 30 days in advance via email or in-product.

§ 15 Contact