Privacy Notice for Services
Version 1.2 · Effective 2 October 2026
This notice describes how we process personal data when you use one of our online
services. For visits to our websites, our
general privacy notice applies.
Our services are offered exclusively to businesses — companies, organisations and
website operators acting in the course of their trade, business or profession.
1. Controller
xplicator GmbH
Eichholz 52, 20459 Hamburg, Germany
Managing directors: Gerrit Kolb, Michaela Maiwald
Commercial register: Amtsgericht Hamburg, HRB 148442
VAT ID: DE314224922
Phone: +49 40 36843454
Data protection enquiries: contact@xplicator.com
We have not appointed a data protection officer, as there is no legal obligation
to do so. Please send data protection enquiries to the address above.
2. Two roles that have to be kept apart
Our services process two kinds of data, and they are legally different:
| Data flow | Our role | Legal basis |
|---|---|---|
| Content your end users enter | processor on your behalf | Art. 28 GDPR, on your instruction |
| Data about you as a customer | controller | Art. 6(1)(b) GDPR |
| Access and quota records | controller | Art. 6(1)(f) GDPR |
If you deploy a service on a website on which third parties can enter text — a
chat assistant, for instance — then you are the controller for that input and
we are your processor. We process it solely on your instruction and never for our
own purposes.
3. As processor: content entered by your end users
3.1 What reaches us
This depends on the service and is set out in its annex. What all services have
in common: what actually reaches us is determined by what your end users type,
not by the software. A visitor can write anything into a chat field, including
names, addresses or health information that nobody asked for.
Two things follow for you. The notice about this processing belongs in your
privacy notice, and you should not invite sensitive input.
3.2 Purpose, and bound by your instruction
The sole purpose is delivering the service you ordered. We do not process this
content for our own purposes and disclose it to no one other than the
sub-processors named in the service’s annex.
We do not use it to train or improve models. This applies to all our services
and without exception.
3.3 Retention
Set per service in its annex. Where a service retains content beyond delivering
the result — to keep your own history searchable, for instance — the annex states
for how long, whether you can set the period yourself, and how you delete the
data. When your access ends we delete such content in any case.
3.4 Processing location and sub-processors
Unless you select otherwise in the service, content your end users enter, and
everything we store for you, we process on hardware we operate ourselves: on our
own premises and on dedicated servers we rent, entirely within the EU/EEA.
Some services use external language models — to prepare knowledge sources you
provide (ingestion) or, where you select it, to answer requests. Depending on
the plan and the processing mode you choose, these providers may be located
outside the EU/EEA, in particular in the USA. Knowledge sources processed in such
a mode must not contain personal data. Which plans and modes exist, which
providers are involved, where they process, and in which mode personal data is
permitted is set out in the service’s annex with their name, seat, purpose and
processing location.
The processors named in our
general privacy notice are
not involved in processing the content described in this section. That notice
covers visits to our websites — analytics, advertising, embedded content, payment
— and none of those providers receive content you or your end users transmit to a
service of ours.
We inform you before changing sub-processors and give you a right to object; the
detail is in the data processing agreement.
3.5 Third-party providers you configure
Some services allow you to set up your own access to a third-party provider
within the interface — your own model API key with an external provider, for
example. If you use this:
- the forwarding to that provider happens on your instruction and on the
basis of your contract with them; - that provider is not our sub-processor but a recipient you chose. Assessing
that transmission under data protection law — including any transfer to a third
country — is yours to do; - we have no influence over the processing location, retention periods or use of
the data at that provider and can make no statement about them. Read their
privacy notice; - whether and how you use this possibility is your decision. Without your own
credential, the processing of end-user content stays on our own infrastructure
within the EU/EEA unless you select external processing in the service (3.4);
for the ingestion of knowledge sources, 3.4 applies.
3.6 Transfers to third countries
By default, no transfer of personal data to a third country takes place through
us: content your end users enter and data we store for you remain within the
EU/EEA.
Knowledge sources processed by external providers we select may be processed
outside the EU/EEA. Because such sources must not contain personal data (3.4),
this does not involve a transfer of personal data. Where a service lets you
select answering by external providers via our routing and you do so, your end
users’ messages are processed by the providers named in the annex; any transfer
to a third country is then covered by the safeguards set out in the data
processing agreement. For providers you configure yourself, see 3.5.
3.7 Data processing agreement
For the processing described in this section we enter into an agreement under
Art. 28 GDPR with you. Request it at contact@xplicator.com.
You need this agreement if you are established in the EU and deploy a service in
such a way that third parties can enter text. Without it you lack a basis for the
processing even though the technology works.
3.8 Technical and organisational measures
- Transport over TLS only; unencrypted requests are refused.
- Access only with valid credentials; each API key is bound to exactly one agent.
- API keys are stored as hashes, never in clear text.
- Access credentials for connected sources are stored encrypted and deleted when
the connection is removed. - Processing of end-user content and stored data on hardware we operate
ourselves, within the EU/EEA, unless you select otherwise in the service; physical access control on our own premises is
ours, and at a hosting provider it is covered by the agreement with that
provider. - External AI providers that we select ourselves are restricted to providers
that do not use inputs to train or improve models; for paid plans, to the list
in the service’s annex. - Rate limiting per API key to protect the service against overload and abuse.
- Regular backups of stored data (accounts, agents, knowledge sources and
retained conversations). Data you delete is removed from the backups when they
are overwritten in the regular backup cycle.
4. As controller: data about you as a customer
4.1 Registration and access
When an access is set up we process the data you provide — regularly your e-mail
address and, for paid use, company and billing details. Which details a
particular service collects is stated in its annex.
Legal basis: Art. 6(1)(b) GDPR. The details are necessary for the performance of
the contract.
Retention: for as long as the access exists, then until statutory retention
periods expire.
4.2 Usage counters and records
To enforce allowances and to defend against abuse we process technical usage data
per access: the time of last use and the number of requests in the current
period. In addition, our servers log the IP address of the system making the
request, the time of the request and the endpoint called. When a service is used
through a plugin on your website, this is the IP address of your web server, not
that of your visitors. These logs are deleted after 30 days, unless they are
needed to investigate a specific security incident or to establish, exercise or
defend legal claims in a specific case; in that case we keep only the entries
concerned, and only until the matter is closed.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is protecting the service
from overload and abuse and honouring the allowances we state.
4.3 Billing
For paid use we process billing data. Legal bases: Art. 6(1)(b) GDPR for the
performance of the contract and Art. 6(1)(c) GDPR for retention under commercial
and tax law. We keep invoices and other accounting records for eight years under
§ 147 AO and § 257 HGB.
Payments are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street
Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. We pass Stripe the data
necessary for the payment (e.g. name, e-mail address, amount, invoice number);
you enter your payment details directly with Stripe, and we receive only
confirmation of the payment. Stripe may transfer data to Stripe, Inc. in the USA
and is certified under the EU-US Data Privacy Framework. Privacy information:
https://stripe.com/privacy
4.4 Service e-mails
For an active access we send operational messages: credentials, notice that an
allowance has been used up, changes to the service, incident reports. This is not
marketing; no consent is required for it, and objecting to it ends the use of the
access.
Legal basis: Art. 6(1)(b) GDPR.
5. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure
(Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to
object to processing based on Art. 6(1)(f) (Art. 21). Contact
contact@xplicator.com.
Where we act as your processor (section 3), your end users address their requests
to you. If such a request reaches us nonetheless, we forward it to you and do
not answer it ourselves.
You also have the right to complain to a supervisory authority. The authority
responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany
6. Changes to this notice
We update this notice when a service or the law changes. The version in force is
always at this address, and the date above states when it took effect. For
changes affecting the processing in section 3 we also write to active accounts.
7. Annexes per service
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 1 October 2026 | first version |
| 1.1 | 2 October 2026 | 4.2: logs may be kept for a specific legal claim |
| 1.2 | 2 October 2026 | 3.4–3.6, 3.8: processing modes per plan as set out in the service’s annex; external answering only on your selection |