Privacy Policy
Last updated: August 13, 2026
1. Controller
n3tz GmbH in Gründung
Innovation Center of Saarland University, Campus A2.1, 66123 Saarbrücken, Germany
Email: mail@n3tz.ai
Phone: +49 6898 4989977
2. Overview of Processing Activities
We process personal data only to the extent necessary to provide our website and services. Processing is based on the GDPR, in particular:
- Art. 6(1)(b) GDPR – performance of a contract
- Art. 6(1)(f) GDPR – legitimate interest
- Art. 6(1)(a) GDPR – consent
3. Hosting and Content Delivery
The public marketing and information website n3tz.ai is provided as a static website through Cloudflare Pages by Cloudflare, Inc. When it is accessed, Cloudflare processes the technical access data required for delivery, security and error analysis (in particular IP address, timestamp, requested resource and browser/device information). The n3tz AI colleague’s SaaS and backend services — internally named Empfang and Zentrale — and the central application database run on servers of Hetzner Online GmbH in Nuremberg. Cloudflare protects and proxies their public endpoints as a DNS, CDN, DDoS-protection and TLS service. All customer file content — in particular uploaded and generated document files, case photos and encrypted external backups — is stored and processed in Cloudflare R2 under its EU jurisdiction. That EU jurisdiction applies to the R2 objects; it does not mean that Cloudflare Pages or DNS/CDN/DDoS/TLS processing across the global edge network is confined to the EU. Cloudflare, Inc. remains a US legal entity, and possible support, security or sub-processor access is not categorically excluded. The legal basis for providing the website and security logging is Art. 6(1)(f) GDPR. Further details about providers and processing locations are set out in the DPA (German).
4. n3tz AI Colleague (SaaS)
When using our SaaS products, we process:
- Customer data: name, email, company, payment data (performance of a contract, Art. 6(1)(b))
- Usage data: login times, feature usage (legitimate interest, Art. 6(1)(f))
- Depending on enabled modules: call, webchat, email, appointment, SMS, document and accounting data, as well as case photos and related technical metadata. Our customer generally determines the purpose and legal basis as controller.
Insofar as we process personal data of the customer's end users on the customer's behalf (e.g. messages through n3tz Webchat), we act as a processor pursuant to Art. 28 GDPR. The published DPA (German) documents the data flows and safeguards. Its incorporation and the applicable German Terms are confirmed expressly before contract conclusion. In the business checkout, the selected configuration, billing details and documented acceptance of the Terms and DPA are processed to perform the contract.
For AI telephony, the caller number transmitted by the telephony provider — unless withheld — may be processed in full and stored with the call record. It is used for the requested interaction, matching a returning caller, appointment bookings and callback handling requested by the caller; where such records are created, it may also appear in the associated appointment, lead or callback data. The current technical implementation does not automatically truncate or pseudonymize the number to its last four digits. The customer, as controller, determines the specific purpose and legal basis (typically Art. 6(1)(b) or (f) GDPR) and may use the feature only where a lawful processing purpose exists. The AI notice provides transparency; continuing the interaction is not treated as consent.
For calls to the public n3tz telephone demo at +49 6898 4989978, n3tz itself is the controller. We process the transmitted phone number, call transcript and technical call data to provide the requested demo, limit abuse and cost, and diagnose errors (Art. 6(1)(f) GDPR). We do not make our own audio recording; real-time voice processing may take place through Google Gemini in the USA. The transcript and call record are deleted no later than 90 days after the call. If the conversation results in a contact or inquiry record, that record is subject to its own, longer retention period and is anonymized afterwards. A one-time SMS containing a booking link is sent only after explicit consent during the call (Art. 6(1)(a) GDPR); no SMS is sent without it.
Google services: Calendar and Gmail drafts
An authorized user of our customer can connect their Google account to the n3tz Zentrale expressly and revocably at any time. Calendar and Gmail drafts are connected separately; a calendar grant does not authorize access to Gmail and vice versa. Without such a connection, n3tz does not access the Google account through these interfaces.
- Google Calendar: With the
calendar.readonlyandcalendar.eventspermissions, n3tz reads the connected calendar's free/busy times to determine available slots for scheduling; other calendars of the account are not browsed or listed. When a user schedules, reschedules or cancels appointments, n3tz creates, updates or removes the corresponding calendar events. - Gmail: With the
openidandemailpermissions, n3tz identifies the connected account and displays its address; these permissions serve account identification only. n3tz usesgmail.composeexclusively to create — upon the user's explicit action — a durable, editable Gmail draft with the recipients, subject, formatted content, plain-text alternative, selected signature and selected attachments the user has reviewed. n3tz does not read the mailbox, does not delete messages and does not send email. The user opens, reviews, edits and sends the draft themself in Gmail.
OAuth credentials are stored encrypted, bound to the tenant and user, and are never returned to the browser. Short-lived access tokens are used only for the respective API call. Beyond that, n3tz stores only the account, permission, event, draft and synchronization references required for the visible appointment or draft workflow, plus the appointment and draft data already managed in the Zentrale. The connection can be disconnected in the settings; this deletes the stored OAuth credential and prevents further API access. Appointments or drafts already created remain in the Google account until the user manages or deletes them there.
Information from Google APIs and data derived from it are used only for the calendar and draft features visible to the user. They are not sold, not used for advertising, creditworthiness decisions or data trading, and not used to train or improve general or personalized AI models. Processing by the sub-processors named in this privacy policy and in the DPA occurs only insofar as it is necessary for the requested user feature and secure operation. n3tz's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Transmission is encrypted. Connecting and disconnecting require renewed confirmation by the signed-in user; access and stored references are limited to that user's tenant and user account. When the associated n3tz user or tenant account is deleted, the connection and the associated provider references are deleted. Beyond that, deletion can be requested in accordance with section 9.
5. Payment Processing
Payments are processed via Stripe (Stripe Payments Europe, Ltd., Ireland). Stripe processes payment data as an independent controller in its own right. Further information: Stripe Privacy Policy.
6. AI Processing
To provide our AI features, we use language models (LLMs) from Google. For text and document processing — n3tz Webchat (the technical Empfang service), receipt OCR, document dictation, the text-based use of the internal voice assistant as well as server-side conversation summaries, lead extraction and website analysis in n3tz HQ — inference and data residency are configured on Google Vertex AI in the EU region. Contractual support, security and sub-processor access may still involve a third country and is governed by Google's DPA and the agreed transfer mechanisms. For the AI live phone call (Gemini Live speech model), greeting voice output and the voice mode of the internal voice assistant in n3tz HQ, n3tz currently uses a Gemini API path and model through which this speech processing takes place in the USA.
The greeting voice-output text may contain personal data, particularly the caller's name and request or continuation context, and is transferred to the USA for speech output.
For document dictation, an uploaded audio clip is transmitted once to Vertex AI in the EU region for transcription and draft extraction. n3tz does not store the raw audio file persistently; the resulting source transcript may be stored with the draft for up to 90 days.
The internal voice assistant in n3tz HQ is operated by a logged-in employee of our customer and is available only where n3tz has enabled it for that customer. In voice mode we transmit to Google LLC in the USA the speech and the transcript of the running session as well as the data the assistant retrieves from the customer's records at that employee's request: customer and contact data, issued business documents as well as quote and invoice drafts including line items and amounts, call logs and conversation transcripts, contents of incoming emails, chat histories, appointment data and entries of the internal knowledge base. This also concerns people who are not participating in the voice session, in particular callers, senders of incoming emails, participants in chat histories, recipients of quotes and invoices as well as employees of our customer. The purpose is to inform the employee, to capture dictated notes and to prepare drafts; in voice mode the assistant does not send, finalise, book or delete anything. Every data lookup is limited to the tenant of the logged-in employee. We act as a processor in doing so; our customer determines the purpose and legal basis of the processing as controller (typically Art. 6(1)(b) or (f) GDPR).
The resulting transfer to the USA (limited to the AI live phone call, the greeting voice output and the voice mode of the internal voice assistant) is based on the EU-US Data Privacy Framework (Art. 45 GDPR; Google LLC is DPF-certified) as well as supplementary Standard Contractual Clauses. The provisions and full list of sub-processors are documented in the DPA (German).
n3tz makes and stores no audio recording of its own — neither from the AI live phone call nor from the sessions of the internal voice assistant. In both cases the production configuration does not request Gemini Live session resumption and therefore does not request the optional retention of conversation state for up to 24 hours. Google may nevertheless retain submitted prompts, contextual information and paid-service output for abuse monitoring and required disclosures for up to 55 days; this also covers the data that the internal voice assistant brings into the conversation. Because the provider documentation does not expressly exclude raw audio of these voice sessions, n3tz does not promise that exclusion. Google does not use paid-service prompts or responses to improve its products.
For the internal voice assistant, n3tz likewise does not store the transcript of the voice session; it is shown to the employee only in their browser while the session is running. Only the results that the employee expressly triggers are stored permanently, in particular notes, tasks and drafts; they reside in our customer's records and are subject to its retention periods. Security logging of these sessions is content-free and contains neither conversation content nor customer or document data.
Gemini-based features are provided only for adult-facing administrative communication, reception and appointment processes. Tenants directed at or likely to be accessed by people under 18, as well as clinical practice, medical advice, diagnosis or treatment, require prior written confirmation from n3tz of a valid provider clearance or a suitable alternative processor.
7. Contacting Us
When you contact us by email or contact form, the submitted data (name, email, message) is stored in order to process your inquiry. Legal basis: Art. 6(1)(b) or (f) GDPR. Data is deleted once the inquiry has been resolved, unless statutory retention obligations apply.
When you join the waitlist for EU-based voice hosting, we process the email address you provide, the site language and page path, and the consent version solely to send one notification when this offering becomes available. The waitlist entry alone is not a newsletter subscription. The newsletter consent described below applies only if you select the separate, optional n3tz updates choice and then confirm the link sent to your email. The legal basis is Art. 6(1)(a) GDPR. You may withdraw consent at any time by email. We delete the entry after withdrawal, if the project is discontinued, or after the one-time notification, unless a narrowly limited statutory evidence duty continues to apply.
When you send a request about Quality Lab and a possible audit, we process the email address you provide, the site language and page path, and the consent version solely to contact you once about Quality Lab and a possible audit. The request alone is not a newsletter subscription. The newsletter consent described below applies only if you select the separate, optional n3tz updates choice and then confirm the link sent to your email. The legal basis is Art. 6(1)(a) GDPR. You may withdraw consent at any time by email. We delete the entry after withdrawal, if the project is discontinued, or after the one-time contact, unless a narrowly limited statutory evidence duty continues to apply.
When you sign up for n3tz updates — through the optional choice on a waitlist or the form before the site footer — we process your email address, language, source and page path, timestamps, consent version, and salted hashes of the IP address and user agent as consent evidence. Brevo initially sends only a confirmation email. We store the subscription as confirmed, notify our team, send one welcome email and, where configured, add the address to the dedicated Brevo list only after the link is opened and the confirmation is actively submitted (double opt-in). Unconfirmed entries are deleted after 48 hours. Confirmed contact data and evidence remain stored until withdrawal or the purpose ends. The confirmation and welcome emails load the static n3tz logo from the applicable n3tz website without recipient-specific URL parameters or open tracking. The personal unsubscribe link in the welcome email removes the address from the newsletter list; once this succeeds, we remove the raw address from our newsletter evidence and retain pseudonymised withdrawal evidence for no more than four years. You may alternatively unsubscribe and withdraw consent at any time by emailing mail@n3tz.ai. The legal basis is Art. 6(1)(a) GDPR; email is sent by Sendinblue SAS (Brevo) in the EU.
If our customer sends a photo request, the requested person receives a login-free, time-limited link for uploading the photos requested for the identified case. We process the files, technical metadata, checksums and — where present in the original file — EXIF metadata solely to associate and provide them in our customer's case. Our customer determines the legal basis and purpose as controller; uploading is voluntary. The upload permission and related security events are time-limited, while photos remain stored until our customer deletes them or the contract ends.
Providing an email address in the e-invoice validator is optional; local validation works without it and the invoice file is not transmitted. If you request the result and checklist, we process your email address, language, a technical summary without invoice contents, timestamps, consent version and hashes of IP address and user agent as consent evidence. Only after confirming the link (double opt-in) do we send the requested material, notify our team and, where configured, add the address to the dedicated Brevo list; this is not a marketing subscription. Unconfirmed records are deleted after 48 hours and the evidence after 180 days. The legal basis is Art. 6(1)(a) GDPR. Email is sent by Sendinblue SAS (Brevo) in the EU.
If you contact us via WhatsApp, we process your phone number, profile name and message content, including any voice messages, photos and receipt images you send, in order to handle your request. Voice messages are transcribed automatically within the EU region. The legal basis is Art. 6(1)(b) or (f) GDPR; using this channel is voluntary, and email and telephone are available as equivalent alternatives. Delivery is handled by the WhatsApp Business Platform operated by WhatsApp Ireland Ltd., Merrion Road, Dublin 4, Ireland. Meta Platforms Ireland Ltd. may transfer data to Meta Platforms, Inc. in the USA on the basis of the EU-US Data Privacy Framework adequacy decision, supplemented by standard contractual clauses. Transport is end-to-end encrypted, but the message is decrypted for further processing on our receiving side, and Meta additionally processes traffic and metadata as its own controller under its own privacy policy. An automated assistant may reply and prepare drafts; any legal decision or outbound message is only sent after a human review.
8. Cookies and Traffic Measurement
A first ordinary visit to n3tz.ai does not set cookies or store an identifier. The browser language is
evaluated locally to select an available German, English or French language URL automatically. Only if a
visitor selects a language in the language menu is that functional preference stored as n3tz_locale in local storage for no more than twelve months; it is not used for analytics or profiling. This expressly
requested functional preference is necessary under section 25(2)(2) TDDDG.
For aggregate-only success measurement, n3tz.ai counts selected clicks on phone and booking calls to
action, a successfully authorised and loaded booking form, and a completed booking reported after it has
been stored successfully on the server. Completion is not reported by the browser. Counter requests are
sent only to the first-party /api/funnel endpoint; the counter stores only the event name and the
value 1. It does not send or store the route, query parameters, referrer, calculator inputs,
device class, session identifier or user identifier. No cookie or browser storage is used for these
counters.
The n3tz web chat (Griffi) is embedded on the public marketing website. A plain page view makes no request
to the chat service. The first pointerdown (mouse or pen), keydown,
touchstart or scroll event loads the embedding script from empfang.n3tz.ai. The script then requests
a signed technical authorisation bound to n3tz.ai and the chat session. Only after successful issuance is it
stored under
empfang_chat_capability_v3:tenant_tarik:https://empfang.n3tz.ai in session storage. Each value
is valid for no more than five minutes; while the page remains open, renewal is attempted about 30 seconds before
expiry and a successful renewal replaces the stored value. Invalid or expired values are discarded, and session
storage ends no later than when the browser tab is closed. The value contains no chat content and is not used
for analytics or profiling. The chat frame and chat content are processed only when you expressly open Griffi.
The embedded chat then also caches the visible timeline under
empfang_timeline:tenant_tarik:<chat session> in empfang.n3tz.ai session storage; that cache
ends no later than the tab and is separate from server-side retention. AI processing is handled via Google Vertex
AI in the EU region, as described in section 6. We do not use tracking or marketing cookies, external traffic
measurement or profiling on n3tz.ai. The exact storage inventory is available in our
German Cookie Policy.
9. Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
To exercise your rights, please contact us at mail@n3tz.ai.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. Competent authority:
Unabhängiges Datenschutzzentrum Saarland (Independent Data Protection Authority of Saarland)
Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Germany
11. Retention Periods
Personal data is deleted as soon as the purpose of processing no longer applies and no statutory retention obligations (e.g. 6 years under the German Commercial Code (HGB), 10 years under the German Fiscal Code (AO)) prevent deletion.
12. Sub-processors
A current list of the sub-processors we engage can be found in the DPA (German).