Skip to main content

Privacy policy

Last updated: August 27, 2026


1. Controller

The controller responsible for processing personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Nickle AI – Oreshin, Platon und Scheffler, Daniel GbR
Ludwig-Erhard-Straße 10
34131 Kassel
Germany
Email: info@nickle.ai

This Privacy Policy applies to:

  • our website nickle.ai,
  • our other business contacts,
  • our agency services in the field of web, AI, automation and related digital services.

We have not appointed a data protection officer; the statutory requirements for a mandatory appointment are not met.

The German version of this Privacy Policy is authoritative. This English version is provided for convenience.


2. General information on data processing

We process personal data exclusively within the scope of the applicable data protection regulations, in particular the GDPR, the Federal Data Protection Act (BDSG) and – where relevant – the Telecommunications Digital Services Data Protection Act (TDDDG).

Personal data is all information relating to an identified or identifiable natural person.

We process personal data in particular

  • to provide our website,
  • to process requests,
  • to initiate, conclude and perform contracts,
  • to provide our agency services,
  • to run AI-supported functions,
  • to ensure support, security, billing and communication.

Processing is carried out in particular on the following legal bases:

  • Art. 6 para. 1 lit. a GDPR – consent,
  • Art. 6 para. 1 lit. b GDPR – performance of contract and pre-contractual measures,
  • Art. 6 para. 1 lit. c GDPR – compliance with legal obligations,
  • Art. 6 para. 1 lit. f GDPR – legitimate interests,
  • Art. 9 para. 2 GDPR – insofar as special categories of personal data are processed and there is a special legal basis for this.

3. Categories of personal data

Depending on your use of our offering, we process in particular the following categories of data:

  • master and contact data, e.g. name, email address, telephone number, company,
  • communication data, e.g. email content, messages, support requests,
  • contract and billing data,
  • usage, device and log data,
  • content processed in the context of agency projects, e.g. uploads, attachments, outputs and context data,
  • payment and transaction metadata,
  • consent and preference data.

4. Visit to our website

4.1 Providing the website, server log data and defence against abuse

Our website is delivered from the global edge network of our hosting provider (see section 4.7). When you access the site, technically required data is processed automatically in order to deliver it, to ensure its stability and to defend against attacks.

In particular, the following data may be processed for this purpose:

  • IP address,
  • date and time of access,
  • browser type and browser version,
  • operating system,
  • referrer URL,
  • pages and files requested,
  • access status,
  • volume of data transferred,
  • device information.

Beyond the mere delivery of files, our hosting provider also performs the following processing at request level on our behalf:

  • edge request logs for operation, troubleshooting and security analysis,
  • bot and attack defence at network level,
  • rate limiting keyed to the IP address for our contact form and our chat function, in order to limit automated abuse. For this purpose the IP address is evaluated for a short period against a request counter; no separate profile is created.

Processing is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our website and in protecting it against misuse.

Storage period: the request-related log data is retained by our hosting provider for the period stipulated in its own retention rules and is then deleted or aggregated. We do not create any separate, permanent log archive of our own.

4.2 Cookies, storage on your device and consent management

We use cookies and comparable storage technologies on our website. A distinction must be made between two things:

  • the access to or storage of information on your device, which is governed by § 25 TDDDG, and
  • any subsequent processing of personal data, which is governed by Art. 6 GDPR.

Strictly necessary entries are used on the basis of § 25 para. 2 no. 2 TDDDG and therefore do not require consent. All other entries are set only after you have actively consented, on the basis of § 25 para. 1 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR.

Strictly necessary – no consent required

We store the following on your device without your consent being required:

  • Your consent decision – stored as a cookie for 12 months and, as a local copy, in your browser storage until you delete it, so that the consent banner is not shown again and optional services stay switched off until you allow them.
  • A local record of your consent changes – kept in your browser storage until you delete it, so that a consent decision can be traced on your own device.
  • Your display preference – whether you use the site in light or dark mode, kept in your browser storage until you delete it and, for the current tab, until the end of the browser session.
  • Your chat session – an identifier for your conversation and the messages of the current chat, stored only on your device and deleted at the end of the browser session.

The subsequent processing of the consent entries is based on Art. 6 para. 1 lit. c GDPR (documentation of consent); for the display and chat entries it is based on Art. 6 para. 1 lit. f GDPR (functional provision of the website).

Requires consent – set only after you have agreed

If you consent to analytics, Google Analytics (GA4) stores pseudonymous identifiers on your device in order to distinguish visitors, maintain the session state and limit the request rate. Depending on the tag configuration, the lifetime of these entries is between one minute and 24 months.

The device access for these entries is based on § 25 para. 1 TDDDG, and the subsequent processing of the data on Art. 6 para. 1 lit. a GDPR.

If you do not give your consent, or withdraw it, we actively delete these analytics entries from your browser insofar as this is technically possible.

Withdrawal: you can change or withdraw your decision at any time with effect for the future via our cookie settings. Pursuant to Art. 7 para. 3 GDPR, withdrawal does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.

4.3 Contact form

If you use the contact form on our website, we process the data you enter in order to handle your enquiry.

The following data is processed:

  • subject of the enquiry, first name, last name, email address and your message – these entries are required. Without them we cannot receive or answer the enquiry; the form cannot be submitted;
  • telephone number and company – these entries are voluntary. If you do not provide them, this has no consequences other than that we may be able to reach you only by email.

The form additionally contains a field that is invisible to you and is used solely to detect automated submissions. It is not evaluated for any other purpose.

Route of the data: your entry is transmitted to our own server, which forwards it to our automation systems. These run on server infrastructure operated by Hetzner Online GmbH in Helsinki, Finland. From there the enquiry is delivered to our mailbox by our transactional email provider (see section 4.7). In the course of this, your IP address is processed at our server for the rate limiting described in section 4.1; it is not forwarded to our automation systems along with the enquiry.

Legal basis: Art. 6 para. 1 lit. b GDPR (pre-contractual measures or performance of contract) and, where an enquiry is not aimed at a contractual relationship, Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient communication).

Storage period: the processing record in our automation systems is deleted automatically after 14 days. The email containing your enquiry remains in our mailbox until we delete it. There is no fixed deletion schedule for this, so the enquiry may remain there indefinitely; it is deleted when you ask us to delete it, when consent is withdrawn or when the purpose ceases to apply. Statutory retention obligations, in particular under § 257 HGB and § 147 AO, remain unaffected.

4.4 Chat function

Our website offers a chat function with which you can ask questions about our services. It is not opened automatically: data is processed only once you actively open the chat window and send a message.

The following data is processed:

  • the content of your messages and any files you attach,
  • a randomly generated conversation ID,
  • the time of the message.

Please do not enter any data in the chat that you do not want to disclose to us, in particular no special categories of personal data within the meaning of Art. 9 GDPR and no data of third parties for which you have no authorisation.

Route of the data: your message is transmitted to our own server, which passes it on to our automation systems on server infrastructure operated by Hetzner Online GmbH in Helsinki, Finland. To generate a reply, the message is transmitted to the AI service listed in section 4.7, which is operated in the Sweden Central region within the EU. To find relevant information about our services, a search is performed against a knowledge database which likewise runs on our server infrastructure in Helsinki. Your IP address is processed at our own server for the rate limiting described in section 4.1 and is not passed on to the AI service.

Legal basis: Art. 6 para. 1 lit. b GDPR where the conversation concerns the initiation of a contract, otherwise Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in answering enquiries about our services promptly. Provision of the data is neither required by law nor by contract; without your entry, the chat function simply cannot answer.

Storage period: the conversation history is deleted from our chat database automatically after 30 days. The processing record in our automation systems is deleted automatically after 14 days. The copy of the conversation held in your browser is deleted at the end of your browser session at the latest.

Note: the replies of the chat function are generated by an AI system and may be incomplete or incorrect. They do not constitute a legally binding statement on our part.

4.5 Contact by email and other channels

If you contact us by email, by telephone, via an appointment booking or by any other means, we process the data you provide in order to handle your request – in particular your name, contact details, the content of your message and the associated communication metadata.

Processing is based on Art. 6 para. 1 lit. b GDPR (pre-contractual measures or performance of contract) or on Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient communication).

Storage period: as described in section 4.3, this correspondence remains in our mailbox until we delete it. Statutory retention obligations remain unaffected.

4.6 Social media presences

We maintain company profiles on social networks. If you interact with us there, we process the data transmitted to us in order to respond to messages, comments or requests.

Processing is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the external presentation of our company, communication with interested parties and customers, and analysis of the reach of our content.

Please note that the operators of social networks regularly process personal data for their own purposes. We have only limited influence over this processing.

4.7 Processors involved in operating this website

Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
Purpose: hosting and delivery of this website, DNS, storage and delivery of the media files used on it, edge request logs, bot and attack defence, and the IP-based rate limiting described in section 4.1. The media files are stored at rest within the EU jurisdiction of the provider.
Categories of data: IP address, request and device metadata, accessed content.
Legal basis: Art. 6 para. 1 lit. f GDPR.
Retention: in accordance with the provider's own retention rules for edge log data.
Third-country transfer: standard contractual clauses (Art. 46 para. 2 lit. c GDPR); the provider is additionally certified under the EU–US Data Privacy Framework.
A data processing agreement has been concluded pursuant to Art. 28 GDPR.
Privacy policy: https://www.cloudflare.com/privacypolicy/

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Purpose: server infrastructure in Helsinki, Finland, on which our backend systems run – in particular the processing of contact form submissions, the backend of the chat function, the associated chat and knowledge database, and the content management for this website.
Categories of data: contact form entries, chat messages and attachments, conversation IDs, technical processing records.
Legal basis: Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
Retention: 14 days for processing records, 30 days for chat history.
No third-country transfer (EU provider, data centre within the EU).
A data processing agreement has been concluded pursuant to Art. 28 GDPR.
Privacy policy: https://www.hetzner.com/legal/privacy-policy/

Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France
Purpose: transactional delivery of contact form submissions to our mailbox.
Categories of data: the contact details and message content transmitted in the form.
Legal basis: Art. 6 para. 1 lit. b GDPR.
Retention: in accordance with the provider's own log retention for delivered messages.
EU-based; no third-country transfer.
A data processing agreement has been concluded pursuant to Art. 28 GDPR.
Privacy policy: https://www.brevo.com/legal/privacypolicy/

Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Purpose: AI model inference for the chat function. Your entries are processed in order to generate a reply. The service is operated in the Sweden Central region. Entries are not used to train the models.
Categories of data: message content and any attachments, conversation context.
Legal basis: Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
Retention: entries are processed only to generate the reply and are not retained by the provider for any purpose of its own beyond the periods provided for abuse monitoring.
No third-country transfer (EU region).
A data processing agreement has been concluded pursuant to Art. 28 GDPR.
Privacy policy: https://privacy.microsoft.com/privacystatement

Google Ireland Limited is used for the analytics services described in section 7. No further processors are involved in the operation of this website.


5. Business initiation, contract processing and general business communication

We process personal data of interested parties, customers, contact persons, service providers, partners and other business contacts to the extent necessary to initiate, perform and process business relationships.

In particular, the following may be processed:

  • name and professional contact details,
  • company, position and function,
  • offer, contract and project data,
  • communication content,
  • invoice and payment data,
  • documentation and evidence data.

Processing is based on Art. 6 para. 1 lit. b GDPR to the extent that it is necessary to initiate or perform the contract, and on Art. 6 para. 1 lit. f GDPR to the extent that it serves our general business communication, internal organisation or legal enforcement. Statutory retention obligations are based on Art. 6 para. 1 lit. c GDPR.


6. Agency services of Nickle AI

6.1 Type of services

As part of our agency services, we support customers in particular in the conception, development, implementation, optimization and operation of digital solutions, especially in the areas of web, AI, automation, workflow design, integrations, prototyping, prompting, assistant systems and related services.

6.2 Processed data in the project context

Depending on the order, we may process in particular the following data in the context of agency projects:

  • contact and communication data,
  • project and briefing documents,
  • access and administration data,
  • content from customer systems,
  • test, usage and error data,
  • files, texts, images, audio or other uploads,
  • AI-related inputs and outputs, insofar as these are part of the service provision.

6.3 Role distribution: controller or processor

Whether we act as a controller or processor under data protection law depends on the specific case:

  • Insofar as we process personal data to initiate, administer and process our own contractual relationship, we ourselves are the controller.
  • Insofar as we process personal data exclusively on behalf of and on documented instructions from our customers, we act as a processor within the meaning of Art. 28 GDPR.

When we act as a processor, we process personal data exclusively on documented instructions from the respective customer and conclude – where required – a data processing agreement.

6.4 Use of AI as part of agency services

If this is part of the commissioned scope of services, we may use AI systems and model providers to analyze, structure, generate or transform content, or to support project-related processes.

In particular, prompts, uploaded files, context information and generated results may be processed. We pay attention to processing that is as data-minimizing, purpose-bound and contractually secured as possible.

Where possible and contractually provided, we select configurations in which customer data is not used to train third-party models. Depending on the service used, processing may take place within the EU/EEA or in third countries. For further information, see section 9 of this privacy policy.

6.5 Confidentiality and project-related security

We take appropriate technical and organisational measures to protect project-related data from unauthorized access, loss or misuse. Access to customer environments is limited to what is necessary.

6.6 Processors for agency services

Depending on the services included in the respective project, the following processors may be used:

  • Cloudflare, Inc. (USA) – hosting, content delivery and storage of media files for websites we build and operate. Standard contractual clauses; additionally certified under the EU–US Data Privacy Framework.
  • Hetzner Online GmbH (Germany, data centres in the EU) – server infrastructure for backend, automation, database and content management systems. No third-country transfer.
  • Brevo (Sendinblue SAS) (France) – transactional email delivery. No third-country transfer.
  • Microsoft Ireland Operations Ltd. (Ireland) – AI model provision and inference. Depending on the region selected in the project, processing takes place within the EU or, where expressly agreed, in a third country on the basis of standard contractual clauses.
  • Google Ireland Limited (Ireland) – firstly, AI model provision and inference as an alternative to the above, where a customer requires it; depending on the region selected in the project, processing takes place within the EU or, where expressly agreed, in a third country on the basis of standard contractual clauses. Secondly, cloud storage of the source documents from which a project's assistant knowledge base is built; in this respect data may be processed by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, on the basis of standard contractual clauses (Art. 46 para. 2 lit. c GDPR).

A data processing agreement pursuant to Art. 28 GDPR has been concluded with each of these processors.

The processors used for a specific project depend on the services agreed in the respective contract and are listed in the DPA appendix at https://nickle.ai/dpa.


7. Analytics, reach measurement and optimization

Where we use analytics and statistics functions, this serves to better understand the use of our website, identify errors and develop our offering in a more user-friendly way.

These functions are activated only after you have actively consented pursuant to § 25 para. 1 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR. Until then, all analytics and advertising storage categories are set to "denied". Consent can be withdrawn at any time via our cookie settings with effect for the future; pursuant to Art. 7 para. 3 GDPR, the lawfulness of processing carried out up to that point remains unaffected.

Where only security or operational technical logs are involved, we rely on Art. 6 para. 1 lit. f GDPR – see section 4.1.

7.1 Google Tag Manager (GTM)

We use Google Tag Manager to provide and manage analytics tags on this website.

  • Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the processing operation, data may be transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
  • Purpose: tag management. GTM controls the loading of other tools based on your active consent status. GTM itself does not set cookies and does not independently collect personal data.
  • Legal basis: consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG.
  • Third-country transfer: data may be processed in the USA. Transfer basis: standard contractual clauses (Art. 46 para. 2 lit. c GDPR).
  • A data processing agreement has been concluded pursuant to Art. 28 GDPR.
  • Note: no optional tag delivered via GTM fires before you have actively given consent for the relevant category.
  • Privacy policy: https://policies.google.com/privacy

7.2 Google Analytics (GA4)

If you consent to analytics cookies, we use Google Analytics (GA4) on this website.

  • Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the processing operation, data may be transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
  • Purpose: statistical evaluation of website use and optimization of our online offering.
  • Legal basis: consent pursuant to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG.
  • Data categories: pseudonymous identifiers (e.g. cookie IDs), usage and event data, browser and device information, approximate location data, referrer information and timestamp.
  • Data protection configuration: Analytics is activated only after consent; IP anonymization is active; advertising personalization signals and Google Signals are disabled.
  • Storage period: in our current configuration, event data is retained for 2 months and user-related data for 14 months.
  • Third-country transfer: a transfer to the USA cannot be excluded. Transfer basis: standard contractual clauses (Art. 46 para. 2 lit. c GDPR).
  • A data processing agreement has been concluded pursuant to Art. 28 GDPR.
  • Privacy policy: https://policies.google.com/privacy

Analytics events we record on this website relate to the use of the contact form (start, submission, success, error, abandonment) and to interaction with the chat function (opening, first message, closing). No message content and no form content is transmitted to Analytics.


8. Recipients and service providers

Personal data is passed on only where this is necessary for the purposes described in this privacy policy, where you have consented, or where we are legally obliged to do so.

The processors involved in operating this website are named conclusively in section 4.7 and section 7. The processors that may be used in the context of our agency services are named in section 6.6 and, in project-specific form, in the appendix to our data processing agreement at https://nickle.ai/dpa.

In addition, personal data may be passed on to:

  • tax advisors, auditors and other professional secrecy holders, on the basis of Art. 6 para. 1 lit. c GDPR,
  • banks and payment service providers for processing payments, on the basis of Art. 6 para. 1 lit. b GDPR,
  • legal advisors, courts and authorities, where this is necessary for the establishment, exercise or defence of legal claims or where we are legally obliged to do so, on the basis of Art. 6 para. 1 lit. c and lit. f GDPR.

We ensure that service providers receive access to personal data only to the extent necessary for the respective purpose, and we conclude a data processing agreement pursuant to Art. 28 GDPR with every processor.


9. Data transfers to third countries

The processing of personal data for the operation of this website takes place within the European Union or the European Economic Area, with the exception of the analytics services described in section 7 and the hosting services described in section 4.7, in respect of which a transfer to the USA cannot be excluded.

Where a transfer to a third country takes place, we ensure that there is an appropriate data protection basis for it. This may be done in particular through:

  • an adequacy decision of the European Commission,
  • standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR,
  • additional contractual, technical or organisational safeguards,
  • statutory exceptions.

In the context of our agency services, the processing location may additionally depend on the infrastructure, model or region selected for the respective project. Details are set out in section 6.6 and in the appendix to our data processing agreement.


10. Storage periods

We store personal data only for as long as this is necessary for the respective purposes. The following periods apply:

DataStorage period
Contact form submissions and email correspondence in our mailboxUntil we delete them. There is no fixed deletion schedule; deletion takes place upon your request, upon withdrawal of consent or when the purpose ceases to apply.
Processing records in our automation systems (contact form and chat)14 days, then deleted automatically
Chat conversation history in our chat database30 days, then deleted automatically
Chat conversation copy in your browserUntil the end of your browser session at the latest
Consent entries on your deviceSee section 4.2
Analytics data2 months (event data) / 14 months (user-related data)
Edge request and server log dataIn accordance with the retention rules of our hosting provider
Contract, invoice and accounting data6 or 10 years pursuant to § 257 HGB and § 147 AO, calculated from the end of the calendar year concerned
Project data from agency servicesFor the duration of the contractual relationship and thereafter in accordance with the agreements made in the respective data processing agreement

Deleted content may temporarily remain in backups or recovery systems before it is finally deleted or anonymized.

As soon as the respective processing purpose no longer applies and there are no statutory retention obligations or legitimate reasons for further storage, we delete or anonymize the relevant data.


11. Special notes on privacy-compliant use of AI

When using AI functions, personal data should not be entered where possible if this is not necessary for the respective purpose. This applies in particular to special categories of personal data within the meaning of Art. 9 GDPR, confidential information and professional secrets.

Insofar as personal data is processed within the scope of AI functions, this is done exclusively for the provision, execution, security and improvement of the specifically provided services within the relevant legal and contractual limits.

AI-generated results may be incomplete or incorrect. They should therefore – particularly in the case of legally, economically or personally significant decisions – not be adopted without review.


12. Automated decisions

We do not carry out solely automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. The chat function described in section 4.4 generates replies automatically, but does not make any decisions about you.


13. Data security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorized access, unauthorized disclosure or unauthorized alteration.

These include in particular:

  • encrypted data transmission (TLS/HTTPS),
  • role-based access concepts and the principle of least privilege,
  • separation of the credentials of our backend systems from the code delivered to your browser,
  • rate limiting and abuse defence on the interfaces reachable from the internet,
  • media storage without a publicly reachable endpoint,
  • logging and monitoring,
  • measures to ensure availability and integrity,
  • procedures for limiting and controlling access rights.

14. Your rights

In accordance with the legal requirements, you have in particular the following rights:

  • right of access under Art. 15 GDPR,
  • right to rectification under Art. 16 GDPR,
  • right to erasure under Art. 17 GDPR,
  • right to restriction of processing under Art. 18 GDPR,
  • right to data portability under Art. 20 GDPR,
  • right to object under Art. 21 GDPR: you have the right to object at any time, on grounds relating to your particular situation, to processing carried out on the basis of Art. 6 para. 1 lit. f GDPR. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims,
  • right to withdraw consent given, with effect for the future, under Art. 7 para. 3 GDPR. Withdrawal does not affect the lawfulness of processing carried out on the basis of the consent up to the point of withdrawal,
  • right to lodge a complaint with a data protection supervisory authority under Art. 77 GDPR.

To exercise your rights, an informal message to us is sufficient, for example by email to info@nickle.ai.


15. Right to lodge a complaint with a supervisory authority

Without prejudice to other administrative or judicial remedies, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement.

The supervisory authority competent for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany
https://datenschutz.hessen.de


16. Changes to this privacy policy

We reserve the right to amend this privacy policy with effect for the future if legal, technical or business conditions change. The current version is available on our website.