Note on language: This is a translation of our German privacy policy, provided for your convenience. The legally binding version is the German original. In the event of any discrepancy between the two, the German version prevails. References to German statutes (BDSG, TDDDG, AO, HGB, BGB) are cited by their original designation.
01
General information and scope
This privacy policy applies to the website kurokolabs.ai and to all associated digital offerings and services of Kuroko Labs GmbH, including the customer portal, the contact forms and all AI-supported services used in the course of our business activities.
This privacy policy takes into account the requirements of the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), Regulation (EU) 2024/1689 on artificial intelligence (EU AI Act) and the Japanese Act on the Protection of Personal Information (APPI).
We take the protection of your personal data seriously and treat your data confidentially and in accordance with statutory data protection provisions.
02
Controller
Controller within the meaning of the GDPR (Art. 4 no. 7):
Kuroko Labs GmbH
Represented by: Wessal Furmoly (Managing Director)
Poccistraße 5
85375 Neufahrn bei Freising
Germany
Email: wessal@kurokolabs.ai
Phone: +49 176 30472811
Commercial register: Munich Local Court, HRB 312188. VAT ID (Sec. 27a UStG): DE462493210. Tax number: 115/130/90090.
We provide services in the fields of AI agent development, web design, process optimisation and digital strategy for business customers (B2B) in Germany and abroad.
03
Data protection officer
Under Sec. 38 (1) BDSG, the appointment of a data protection officer is required where at least 20 persons are permanently engaged in the automated processing of personal data. Irrespective of this, an obligation to appoint may arise where processing operations are carried out that are subject to a data protection impact assessment under Art. 35 GDPR (Sec. 38 (1) sentence 2 BDSG).
We continuously review whether an obligation to appoint exists and will appoint a data protection officer as soon as the statutory conditions require it.
For data protection enquiries, please contact:
wessal@kurokolabs.ai
04
Overview of processing operations and legal bases
Personal data is processed exclusively on the basis of the following legal bases:
| Legal basis | Scope of application |
|---|---|
| Art. 6 (1) (a) GDPR (consent) | Analytics cookies (Google Analytics), optional additional functions |
| Art. 6 (1) (b) GDPR (performance of a contract) | Customer portal, project management, invoicing, chat, AI services within commissioned projects |
| Art. 6 (1) (c) GDPR (legal obligation) | Tax retention obligations (Sec. 147 AO, Sec. 257 HGB), GoBD compliance |
| Art. 6 (1) (f) GDPR (legitimate interest) | Server logs, bot protection, IT security, fraud prevention, audit logging. Our legitimate interest lies in ensuring a secure, functioning web presence and safeguarding our business processes. |
| Sec. 26 BDSG | Processing of applicant data in the context of recruitment procedures |
| Sec. 25 (2) TDDDG | Strictly necessary cookies and access to terminal equipment (permitted without consent) |
05
Categories of data collected
5.1 Website visit (server logs)
Each time our website is accessed, the following data is collected automatically: IP address (truncated/anonymised after processing), date and time of access, URL accessed, referrer URL, browser and operating system used, volume of data transferred.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in ensuring trouble-free operation, detecting and averting attacks and analysing faults.
Retention period: 7 days, then irreversibly deleted.
5.2 Contact form and enquiries
When you use our contact form or contact us by email or telephone, we collect: name, email address, telephone number (if provided), services requested, project details, budget range, time frame and the timestamp of the contact.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR (legitimate interest in handling business enquiries).
Retention period: Enquiries that do not lead to contract initiation are deleted after 6 months. Where a contract is initiated, the retention periods set out in section 18 apply.
5.3 Customer portal (registration, login, two-factor authentication)
When you register for our customer portal, we collect: name, email address, password (stored exclusively as a cryptographic hash), form of address, company name (optional) and the timestamp of registration and acceptance of the GTC (version, point in time).
To secure your account we use device-based two-factor authentication (2FA). The following additional data is collected: device hash (SHA-256 derived from browser and connection data), IP address, device designation (e.g. “Chrome on Windows”), time of last use. For unknown devices, a time-limited one-time code (OTP) is sent by email.
The following may additionally be stored in the customer profile: first and last name, telephone number, address (street, postcode, city), country, industry, VAT identification number and a separate correspondence email address.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). For 2FA: Art. 6 (1) (f) GDPR (legitimate interest in the security of customer accounts).
Retention period: Account data is stored for the duration of the business relationship. Unverified accounts are deleted automatically after 24 hours, matching the validity period of the verification link.
5.4 Project management and chat
In the course of project delivery we process: project data (designation, type, status, progress, scheduling), chat messages between the customer and the project team (max. 2,000 characters per message), read markers, proposed consultation and review appointments, development updates and uploaded concept documents (PDF, max. 15 MB).
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
Retention period: For the duration of the business relationship plus statutory retention periods.
5.5 Invoices and quotations
For invoicing and the preparation of quotations we process: recipient data (name, company, address, email), invoice/quotation numbers, line items, amounts, tax data, payment status and, upon acceptance of a quotation, the IP address and user agent at the time of acceptance (evidentiary requirement under Sec. 126b BGB).
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract), Art. 6 (1) (c) GDPR (tax retention obligations).
Retention period: 8 years pursuant to Sec. 147 (3) AO (version in force from 1 January 2025) or 6 years pursuant to Sec. 257 HGB for commercial letters.
5.6 AI agents and AI-supported services
When our AI-based services and agents are used within commissioned projects, the following data is processed: conversation histories (inputs and outputs), session metadata and, where applicable, uploaded documents.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
Retention period: 30 days after the last session, then irreversibly deleted.
Important note: When using AI systems, please do not enter particularly sensitive personal data (e.g. health data, banking credentials, passwords, data within the meaning of Art. 9 GDPR). We accept no responsibility for the voluntary entry of such data by users. Details on our use of AI can be found in sections 06–09.
5.7 Job applications
In the context of application procedures we process: name, email address, cover letter/message, CV (PDF upload), qualifications and any other information you provide in your application, as well as the application status.
Legal basis: Sec. 26 (1) BDSG (data processing for the purposes of the employment relationship).
Retention period: 6 months after conclusion of the application procedure (rejection), unless consent has been given to longer storage in our talent pool. In the event of recruitment: transfer to the personnel file.
06
Use of artificial intelligence (AI)
We develop AI agents and AI-supported solutions for our business customers and, in the course of our services, deploy various AI systems within the meaning of Regulation (EU) 2024/1689 (EU AI Act).
6.1 AI models and providers used
To deliver our AI services we use the API interfaces of the following providers:
- OpenAI LLC (San Francisco, USA), GPT-4, GPT-4 Turbo, GPT-4o and successor models
- Anthropic PBC (San Francisco, USA), Claude models
- Google LLC (Mountain View, USA), Gemini models via Google Cloud Platform / Vertex AI
The specific provider and model used are defined in the respective project contract and communicated to the customer.
6.2 Nature of the data processing by AI
AI systems process personal data exclusively for the performance of the respective project assignment (Art. 6 (1) (b) GDPR). Processing comprises the analysis of input data (prompts) and the generation of outputs (responses). No use beyond this takes place.
6.3 No model training with customer data
Personal data transmitted via the API interfaces of the providers named above is not used to train, fine-tune or improve generative AI models. This is contractually secured by the respective Data Processing Agreements (DPAs) and API terms of use and technically ensured by corresponding configurations (training opt-out).
6.4 Human oversight (human-in-the-loop)
AI-generated results are reviewed by qualified staff before they take effect vis-à-vis customers or third parties. AI systems do not take independent legally binding decisions. All actions triggered by AI agents (e.g. sending messages, database changes) remain the responsibility of the respective operator. Where deviating arrangements on automation are agreed within individual projects, this is governed and documented separately in the relevant project contract and data processing agreement.
6.5 AI literacy (Art. 4 EU AI Act)
In accordance with Art. 4 of the EU AI Act, we ensure that all staff who deploy or supervise AI systems have a sufficient level of AI literacy. This includes knowledge of the functioning, limitations and risks of the systems used.
07
Automated decision-making and profiling (Art. 22 GDPR)
We do not take decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you (Art. 22 (1) GDPR).
Where AI systems are deployed in the course of our services, they serve exclusively as a support tool for human decision-makers. The final decision always rests with a human being.
Should this change in future, we will inform you in advance in accordance with Art. 13 (2) (f) GDPR about the logic involved, the significance and the envisaged consequences of such automated processing, and we will guarantee the safeguards required under Art. 22 (3) GDPR (human intervention, expression of your point of view, contestation of the decision).
08
AI transparency under the EU AI Act (Art. 50)
In accordance with Art. 50 of Regulation (EU) 2024/1689, we inform you about the use of AI systems as follows:
8.1 Disclosure of AI interactions
Where you interact with an AI system in the context of our services (e.g. AI-supported chatbots, automated reply suggestions), this is clearly indicated. You are informed that you are communicating with an AI system and not with a human being (Art. 50 (1) EU AI Act).
8.2 Marking of AI-generated content
Content generated or substantially modified by AI systems (text, images, code) is marked as such to the extent required under Art. 50 (2) EU AI Act. Marking is applied in machine-readable format where technically feasible.
8.3 Our role under the EU AI Act
Depending on the context, Kuroko Labs acts as a provider, where we develop and place standalone AI systems on the market for customers, or as a deployer, where we use existing AI models (GPT-4, Claude, Gemini) in our own services. The respective role and the resulting obligations are set out in the project contract with the customer.
8.4 Prohibited AI practices
We do not deploy AI systems that fall within the prohibited practices under Art. 5 of the EU AI Act. In particular, this means: no social scoring, no emotion recognition in the workplace, no subliminal manipulation, no biometric categorisation to infer sensitive characteristics.
Note: The transparency obligations under Art. 50 EU AI Act become fully enforceable on 2 August 2026. We are implementing these requirements ahead of that date.
Detailed information on our AI governance, risk classification and your obligations as a deployer can be found on our AI transparency page.
09
Data protection impact assessment (Art. 35 GDPR)
Where our processing operations, in particular the use of AI systems to process personal data, are likely to result in a high risk to the rights and freedoms of natural persons, we carry out, or have already carried out, a data protection impact assessment (DPIA) pursuant to Art. 35 GDPR.
The DPIA covers in particular: a systematic description of the processing operations, an assessment of necessity and proportionality, an assessment of the risks to the rights and freedoms of data subjects, and the remedial measures and safeguards envisaged to mitigate those risks.
In addition, where high-risk AI systems within the meaning of the EU AI Act are deployed, a fundamental rights impact assessment (Art. 27 EU AI Act) is carried out to the extent required by law. Both assessments may be combined in a single document in accordance with recital 96 of the EU AI Act.
Information on data protection impact assessments carried out can be requested at wessal@kurokolabs.ai.
10
AI sub-processors
To deliver our AI-supported services we engage the following sub-processors, which may receive personal data in the course of AI processing:
| Provider | Location | Purpose | Transfer basis | Model training |
|---|---|---|---|---|
| OpenAI LLC | USA | GPT models / language model inference | EU-US DPF + SCCs | No (API opt-out) |
| Anthropic PBC | USA | Claude models / language model inference | SCCs + DPA | No (API policy) |
| Google LLC | USA / EU | Gemini models, Vertex AI, GCP | EU-US DPF + SCCs | No (Vertex AI Terms) |
Data processing agreements (DPAs) pursuant to Art. 28 GDPR are in place with all AI providers. The providers actually deployed are defined in the respective project contract. On request, we will inform you which providers are used in your project.
We reserve the right to engage further AI providers, provided that they ensure a comparable level of data protection and that the transfer is based on an appropriate legal basis (SCCs, adequacy decision or DPF). Customers are informed of material changes.
11
Disclosure to third parties
As a matter of principle, your personal data is disclosed to third parties only where:
- you have given your explicit consent (Art. 6 (1) (a) GDPR),
- disclosure is necessary for the performance of a contract (Art. 6 (1) (b) GDPR),
- there is a legal obligation (Art. 6 (1) (c) GDPR), or
- legitimate interests require it and your interests warranting protection do not override them (Art. 6 (1) (f) GDPR).
Categories of recipients:
- Tax advisors and auditors, fulfilment of tax and commercial law obligations (Art. 6 (1) (c) GDPR).
- Qonto (Olinda SAS, France), business bank account and invoicing: synchronisation of transaction and receipt data and transmission of outgoing invoices (name, address, VAT ID, invoice data) for automatic payment matching. Processing within the EU. A data processing agreement pursuant to Art. 28 GDPR is in place. Legal bases: Art. 6 (1) (b) and (f) GDPR. See section 14.9 for details.
- Google Ireland Ltd. (Google Workspace), email communication, storage of business documents and scheduling. This involves correspondence, contract and invoice documents and appointment data. A data processing agreement pursuant to Art. 28 GDPR is in place; transfers to third countries are based on the EU-US Data Privacy Framework with standard contractual clauses as a fallback safeguard. See section 14.10 for details.
- AI providers, in accordance with section 10 of this privacy policy.
- Hosting and IT service providers, under data processing agreements pursuant to Art. 28 GDPR (see section 14).
- Public authorities and bodies, where there is a legal obligation (e.g. tax authorities, law enforcement authorities).
Payments are made exclusively by SEPA bank transfer. No external payment service providers (e.g. Stripe, PayPal) are used. Bank details are stored solely on invoices and in our accounting system.
Data processing agreements pursuant to Art. 28 GDPR are in place with all service providers that process personal data on our behalf.
12
International data transfers
Some of the service providers we use are established outside the EU/EEA. For transfers to third countries we ensure an adequate level of data protection by means of:
- adequacy decisions of the European Commission pursuant to Art. 45 GDPR,
- standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR in their current version (Implementing Decision (EU) 2021/914),
- the EU-US Data Privacy Framework (DPF) for certified US companies (adequacy decision of 10 July 2023). SCCs are additionally maintained as a fallback safeguard.
For every third-country transfer we carry out an assessment of the level of data protection in the recipient country (transfer impact assessment, TIA) to the extent this is required beyond an adequacy decision.
USA: Transfers to OpenAI, Anthropic, Google and Supabase are based on the EU-US DPF (where certified) and/or SCCs. We are aware of the risk that may arise from Section 702 FISA and maintain SCCs as an additional safeguard.
These transfers also include our use of Google Workspace for email, document storage and scheduling (section 14.10). The plan we use does not provide for a guaranteed European storage location; the transfer is based on the adequacy decision concerning the EU-US Data Privacy Framework. Should that decision be repealed, suspended or declared invalid in future, we will base the affected transfers on the standard contractual clauses that remain agreed, carry out an assessment of the level of data protection in the recipient country and examine supplementary safeguards.
Japan: A European Commission adequacy decision for Japan has been in place since 23 January 2019 (Art. 45 GDPR). In addition, we observe the requirements of the Japanese APPI. Data transfers to Japan therefore do not require additional safeguards.
Information on the safeguards applied in individual cases can be requested at wessal@kurokolabs.ai.
13
Cookies and consent management
Our website uses cookies and similar technologies. The legal basis is determined by Sec. 25 TDDDG (German Telecommunications Digital Services Data Protection Act, formerly TTDSG).
Strictly necessary cookies (Sec. 25 (2) TDDDG, no consent required):
| Cookie | Purpose | Lifetime |
|---|---|---|
| access_token / access_token_admin | Authentication (JWT, httpOnly, Secure, SameSite=Strict) | 15 minutes |
| refresh_token / refresh_token_admin | Token renewal (httpOnly, Secure, SameSite=Strict) | 7 days |
| kl_device | Recognition of a trusted device for two-factor authentication (httpOnly, Secure, SameSite=Lax). Contains a random secret with no personal reference; matching is done via an HMAC. | 90 days |
| __csrf | CSRF protection (httpOnly, Secure, SameSite=Strict) | Session |
These cookies are strictly necessary for the secure operation of the customer portal and cannot be deactivated. They contain no personal data in readable form (the JWT payload is Base64-encoded, the refresh token is stored as a SHA-256 hash in the database).
Analytics cookies (Sec. 25 (1) TDDDG, only with consent):
We use Google Analytics 4 (measurement ID: G-NZ501W0KK2) on the public pages of our website. The analytics scripts are loaded only after your explicit consent via our cookie banner. No tracking takes place without your consent. Details on Google Analytics can be found in section 14.3.
On the protected portal pages (login, registration, dashboard, admin) no analytics or marketing cookies are used.
You may withdraw your consent at any time with effect for the future by adjusting your cookie settings via the cookie banner or by deleting the cookies in your browser. We store your selection for 12 months; after that, we will ask for your consent again.
14
Services used
14.1 Hosting, Hostinger International Ltd.
Our website and backend are hosted by: Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. The server infrastructure is located on EU servers in Europe. No systematic transfer to third countries takes place in the context of hosting. A data processing agreement pursuant to Art. 28 GDPR is in place. Further information: hostinger.com/legal/privacy-policy.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in reliable hosting).
14.2 Protection of our forms against misuse
To protect our contact and enquiry forms against automated misuse (spam, bots) we use exclusively our own server-side protective measures: a limitation of request frequency (rate limiting) per IP and email address, CSRF protection and server-side input validation. No data is transmitted to third parties in this process and no additional cookies are set; the only data processed is the IP address that is technically necessary for delivery in any event (see 14.1).
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in protection against bot attacks and spam).
14.3 Web analytics, Google Analytics 4
On the public pages of our website (not on portal pages) we use Google Analytics 4 provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). Google Analytics uses cookies and similar technologies to analyse usage behaviour in pseudonymised form.
Data processed: IP address (anonymised), page views, time on page, source of origin, device and browser information.
Data transfer: Data may be transferred to the USA. Google Ireland is the contracting party; the EU-US DPF and SCCs apply to onward transfers to Google LLC.
Legal basis: Art. 6 (1) (a) GDPR (consent). Tracking is activated only after your explicit consent via the cookie banner (Sec. 25 (1) TDDDG).
Objection/opt-out: You may withdraw your consent at any time. You may also use the browser add-on to deactivate Google Analytics: tools.google.com/dlpage/gaoptout.
Further information: policies.google.com/privacy.
14.3.1 Own reach measurement, cookieless
In addition, we use a self-developed, cookieless analytics system that runs exclusively on our own servers. It records page views, approximate click positions (as percentages relative to page size) and scroll depth. It sets no cookies, uses no device storage, builds no user profiles and stores no IP addresses or other identifying characteristics; attribution to individual persons is impossible. Your browser's Do-Not-Track and Global Privacy Control signals are respected. The anonymous data is deleted after 180 days.
Data processed: page visited, click position, scroll depth, device category, referrer domain, page language, clicks on calls to action (button label only), progress through the contact and application forms (opened, step reached, submitted, abandoned), dwell time per step, and the campaign parameters of the entry URL (utm_source, utm_medium, utm_campaign), each without any personal reference. The utm values are filtered against a fixed list of permitted characters. The content of the form fields is not recorded; name, email address, telephone number and free text are excluded. Advertising click identifiers such as gclid, wbraid or gbraid are not collected or stored by this system.
Data transfer: none (own servers).
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in improving our website). As no information is stored on or read from your device, no consent under Sec. 25 TDDDG is required.
14.4 Typefaces, self-hosted
The typefaces used on our website (“Helvetica Now Display” and “Noto Sans JP” for Japanese text) are served exclusively from our own servers. Loading them establishes no connection to Google's servers or to any other third party, and no data is transmitted to third parties.
Data transfer: none.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a uniform, typographically consistent presentation without involving third parties).
14.5 Scheduling in the customer portal
For consultation and review appointments we propose time slots in the customer portal, which you confirm or decline there. To confirm, we send a calendar file (.ics) by email and additionally offer a link that adds the appointment to your own calendar with one click. No automated access to your calendar takes place: we request no calendar permissions and read no calendar data.
Data processed: appointment title, date, time, participant addresses, solely for the appointments agreed in the portal.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
Our own calendar is managed via Google Workspace, see section 14.10.
14.6 Content delivery, Webflow CDN
For the delivery of static content (images, stylesheets) we use the content delivery network of Webflow Inc., San Francisco, CA, USA. Delivery takes place via Fastly Inc. and Amazon CloudFront (AWS). When this content is retrieved, your IP address is transmitted to the CDN servers.
Data transfer: USA. SCCs as the transfer basis.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in fast and reliable content delivery).
14.7 Storage of AI conversation data
Where AI conversations are stored persistently within a commissioned project, this takes place on servers within the EU. The service actually used is named in the respective project contract and data processing agreement; one option is Supabase Inc., Oakland, CA, USA, with data held on EU servers in Frankfurt (AWS eu-central-1). The EU-US DPF and SCCs apply to administrative access from the USA.
No AI conversation data is currently stored in our own customer portal.
Retention period: where storage takes place, 30 days after the last session.
14.8 AI infrastructure
The AI infrastructure used varies from project to project and may include services from the following providers: Amazon Web Services (AWS), Hostinger, Google Cloud Platform (GCP), Microsoft Azure, Hetzner and DigitalOcean. Where data can be processed on EU servers, this is preferred. The specific services used are defined in the respective project contract or data processing agreement.
14.9 Banking & invoicing, Qonto
For our business account we use Qonto (Olinda SAS), 18 rue de Navarin, 75009 Paris, France. Qonto is a payment institution established in France (EU) and regulated by the ACPR (Autorité de Contrôle Prudentiel et de Résolution). Processing and data storage take place exclusively on servers within the European Union (France, Ireland), no transfer to third countries takes place.
Purposes of processing:
- Transaction synchronisation (read access): Account movements are imported into our accounting system via the Qonto API in order to match incoming payments automatically against open invoices and to record expenses.
- Receipt archiving (read access): Receipts linked to transactions (invoice PDFs, till receipts) can be transferred to our GoBD-compliant receipt archive via the Qonto Attachments API (retention period: 8 years pursuant to Sec. 147 (3) AO).
- Invoicing customers (write access): Outgoing invoices from our customer portal are transmitted to Qonto as “client invoices”. Qonto automatically reconciles incoming SEPA payments against these invoices and can report the invoice status back to our system. Customer data processed: name, address, email address, VAT ID and tax number (where available, both are transmitted as soon as the customer record is created), invoice number, date, amount, line items, payment terms, recipient's bank details.
Legal bases: Art. 6 (1) (b) GDPR (performance of a contract, invoicing is a statutory component of our contractual relationship), Sec. 14 UStG (obligation to issue invoices), Art. 6 (1) (f) GDPR (legitimate interest in efficient, low-error accounting and automated payment matching).
Data processing agreement: A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Qonto. The DPA is available via the Qonto customer portal.
Retention period: Transaction and receipt data is retained for 8 years pursuant to Sec. 147 (3) AO (version in force from 1 January 2025). Subsequent deletion is automated on the basis of the retention end date stored in Qonto or in our system.
Further information: legal.qonto.com/en.
14.10 Business communication and document storage, Google Workspace (Gmail, Drive, Calendar)
For our business communication and the storage of business documents we use Google Workspace (Business Starter plan) provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland is our contracting party; Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and further companies published by Google are engaged as sub-processors.
We use the following core services:
- Gmail (email): Our business correspondence and the dispatch of all system emails (verification, one-time codes, notifications, invoices, quotations, appointment confirmations) run through the mailbox wessal@kurokolabs.ai. Automated dispatch from our customer portal takes place via the Google Workspace SMTP relay service; authorisation is granted on the basis of our server's IP address. Data processed: sender and recipient addresses, subject, message content including attachments (e.g. invoice and quotation PDFs), timestamps and technical connection and log data.
- Google Drive (document storage): Business documents such as contracts, quotations, invoices, project documentation and correspondence are stored there. Data processed: name, address and contact details of contact persons, contract and invoice data and all further personal data contained in those documents. Files are not shared publicly; access is restricted to the management.
- Google Calendar and Google Meet: Planning and holding consultation, review and coordination appointments. Data processed: appointment title, date and time, participant addresses, description, connection data. This service concerns our company calendar and is to be distinguished from the optional connection of your own Google calendar described in section 14.5.
Data processing agreement: A data processing agreement pursuant to Art. 28 GDPR is in place with Google Ireland in the form of the Cloud Data Processing Addendum, which forms part of the Google Workspace agreement. In it, Google undertakes to process customer data of the core services solely on documented instructions and not to use it for advertising purposes or profiling. Google publishes the current list of sub-processors at workspace.google.com/terms/subprocessors.html.
Storage location and third-country transfers: Processing takes place in Google's data centres worldwide; processing in the USA cannot be ruled out. The Business Starter plan we use contains no contractual assurance of an exclusively European storage location (the “Data Regions” feature is available only from higher plans). The transfer is based on the European Commission's adequacy decision of 10 July 2023 concerning the EU-US Data Privacy Framework, under which Google LLC is certified; in addition, the standard contractual clauses agreed in the Cloud Data Processing Addendum apply as a fallback safeguard. Details on third-country transfers can be found in section 12.
Security: Data is encrypted in transit and at rest. Our Workspace accounts are protected by two-factor authentication; access follows the need-to-know principle.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract and pre-contractual measures, correspondence, quotations, invoices), Art. 6 (1) (c) GDPR (retention of commercial letters and accounting records pursuant to Sec. 147 AO, Sec. 257 HGB) and Art. 6 (1) (f) GDPR (legitimate interest in secure, reliable and traceable business communication).
Retention period: In accordance with section 18. Emails and documents of commercial or tax relevance are subject to the statutory retention periods and are deleted only after those periods have expired.
Further information: Cloud Data Processing Addendum and policies.google.com/privacy.
14.11 SSL/TLS encryption
All connections to our website and our services are secured by SSL/TLS encryption (HSTS with preload). Transmissions between your browser and our servers are exclusively encrypted.
15
Processing on behalf of a controller (data processing agreements)
Where we process personal data on your behalf in the course of our services, we conclude a data processing agreement with you pursuant to Art. 28 GDPR. The agreement governs in particular:
- the subject matter and duration of the processing,
- the nature and purpose of the processing,
- the type of personal data and the categories of data subjects,
- the obligations and rights of the controller,
- technical and organisational measures (TOMs),
- provisions on sub-processing (sub-processors).
A template of our data processing agreement is available on request at wessal@kurokolabs.ai.
16
Your rights as a data subject
You have the following rights under the GDPR:
- Right of access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data is being processed and to access that data, including a copy.
- Right to rectification (Art. 16 GDPR): Rectification of inaccurate data or completion of incomplete data without undue delay.
- Right to erasure (Art. 17 GDPR): Erasure of your data, provided no statutory retention obligation stands in the way. Please note that tax retention obligations (Sec. 147 AO, Sec. 257 HGB) may preclude the immediate erasure of invoice and contract data.
- Right to restriction of processing (Art. 18 GDPR): Restriction of processing under the statutory conditions.
- Right to data portability (Art. 20 GDPR): Receipt of your data in a structured, commonly used and machine-readable format (a JSON export is available via the customer portal) and transmission to another controller.
- Right to withdraw consent (Art. 7 (3) GDPR): Withdrawal at any time with effect for the future. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.
Separate information on the right to object pursuant to Art. 21 GDPR:
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR. This also applies to profiling based on those provisions.
In the event of your objection, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Please address objections to: wessal@kurokolabs.ai.
Right to lodge a complaint with a supervisory authority:
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach, Germany
www.lda.bayern.de
Please address requests to exercise your rights to: wessal@kurokolabs.ai. We process your requests without undue delay and at the latest within one month (Art. 12 (3) GDPR). In complex cases the period may be extended by a further two months; you will be informed of this within the first month.
17
Data security, technical and organisational measures
In accordance with Art. 32 GDPR we implement technical and organisational measures (TOMs) to ensure a level of protection appropriate to the risk:
General measures:
- Transport encryption: TLS/SSL for all connections, HSTS with preload (max-age 1 year).
- Authentication: Password hashing with bcrypt (salt rounds: 12), two-factor authentication (OTP by email), device-based trust system, automatic account lockout after 5 failed attempts within 15 minutes.
- Session security: JWT tokens with a lifetime of 15 minutes (access) and 7 days (refresh), httpOnly and Secure flags, SameSite=Strict, CSRF protection (double-submit pattern).
- Access control: Role-based authorisation (admin/customer), need-to-know principle, strict separation of resources between customer accounts.
- Rate limiting: Differentiated rate limits for login, registration, OTP verification, contact forms and general API access.
- Security headers: Content Security Policy (CSP), X-Frame-Options: deny, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin.
- Audit logging: Security-relevant events (login attempts, registrations, password changes, email verifications) are logged with a timestamp, anonymised IP address and device information.
- Input validation: Server-side validation of all user input, parameterised SQL queries to protect against SQL injection, path traversal protection for file uploads.
- Regular security reviews: Our systems are regularly checked for vulnerabilities and updated.
AI-specific measures:
- Data minimisation: Only the personal data necessary for the respective AI assignment is transmitted to AI providers.
- No model training: API configurations ensure that transmitted data is not used for training.
- Automatic deletion: AI conversation data is deleted automatically after 30 days.
- Input/output logging: AI interactions are logged for quality assurance and traceability and deleted once the retention period has expired.
Please note that data transmission over the internet (e.g. in email communication) may in principle have security gaps. Complete protection against access by third parties is not technically possible.
18
Retention periods and deletion concept
We store personal data only for as long as is necessary for the respective processing purpose or as long as statutory retention obligations exist:
| Data category | Retention period | Legal basis |
|---|---|---|
| Server logs | 7 days | Art. 6 (1) (f) GDPR |
| Contact enquiries (without contract) | 6 months | Art. 6 (1) (f) GDPR |
| Customer account data | Duration of the business relationship + retention periods | Art. 6 (1) (b) GDPR |
| Unverified accounts | 24 hours (automatic deletion) | |
| Invoices, accounting records | 8 years (Sec. 147 (3) AO, version in force from 1 January 2025) | Art. 6 (1) (c) GDPR |
| Commercial letters, contracts | 6 years (Sec. 257 (4) HGB) | Art. 6 (1) (c) GDPR |
| Email correspondence (Google Workspace) | Commercial letters 6 years, accounting records 8 years; other correspondence up to 12 months after the end of the business relationship | Art. 6 (1) (c) GDPR or Art. 6 (1) (f) GDPR |
| Business documents (Google Drive) | Contracts 6 years, invoices and receipts 8 years; project documents not subject to retention obligations up to 12 months after project completion | Art. 6 (1) (c) GDPR or Art. 6 (1) (b) GDPR |
| AI conversations | 30 days after the last session | Art. 6 (1) (b) GDPR |
| Applicant data | 6 months after rejection | Sec. 26 BDSG |
| Backups (encrypted, EU servers) | Daily backups 30 days, weekly 12 weeks, monthly 12 months, annual 7 years | Art. 6 (1) (f) GDPR (Art. 32 (1) (c)) |
| Audit logs | 3 years | Art. 6 (1) (f) GDPR |
| Project chat messages | Duration of the business relationship + retention periods | Art. 6 (1) (b) GDPR |
Once the retention period has expired, personal data is deleted or irreversibly anonymised, unless a statutory retention obligation stands in the way. Deletions are carried out automatically (for technically controlled periods) or as part of regular manual reviews.
19
Personal data breaches (Art. 33/34 GDPR)
In the event of a personal data breach we act in accordance with Art. 33 and 34 GDPR:
- Notification of the supervisory authority (Art. 33 GDPR): Notification of the BayLDA within 72 hours of becoming aware of the breach, where the breach is likely to result in a risk to the rights and freedoms of natural persons.
- Communication to data subjects (Art. 34 GDPR): Information of the data subjects without undue delay where there is a high risk to their rights and freedoms.
We document all personal data breaches internally in accordance with Art. 33 (5) GDPR and immediately take appropriate technical and organisational measures for containment and prevention.
20
Japan-specific information (APPI)
For customers and data subjects resident in Japan, the provisions of the Japanese Act on the Protection of Personal Information (APPI) as amended apply in addition:
- Adequacy decision: A mutual adequacy decision has been in place between the EU and Japan since 23 January 2019. The transfer of personal data between the EU and Japan therefore does not require additional safeguards (Art. 45 GDPR, Art. 28 APPI).
- Right of access (Art. 33 APPI): You have the right to request information about the personal data we hold about you. A JSON export of your data is available via the customer portal.
- Correction and deletion (Art. 34/35 APPI): You may request the correction of inaccurate data and the cessation of the use of your data.
- Language: Email communication and invoices are sent in Japanese depending on the country stored in your profile (Japan).
- Purposes of use (Art. 21 APPI): The purposes for which we use personal data are published in section 4 of this policy.
- Security measures and countries of processing (Art. 32(1)(iv) APPI, Enforcement Rules Art. 10): The technical and organisational measures we have taken are described in section 17. Personal data of Japanese data subjects is processed in the following countries: Germany (registered office and business operations), member states of the European Union (servers per section 14.1, Hostinger International Ltd. registered in Cyprus; payment processing in France and Ireland per section 14.9) and the United States (sections 12 and 14). Information on the data protection regime of each country and on the measures taken by the recipient there is available on request (Art. 28 APPI).
- No joint use, no anonymously processed information: We do not engage in joint use within the meaning of Art. 27(5)(iii) APPI. We do not create anonymously processed information under Art. 43 APPI.
- Where to lodge a complaint: Please address complaints to wessal@kurokolabs.ai in the first instance; we respond within 30 days. Independently of this, you may contact the Japanese supervisory authority: Personal Information Protection Commission (個人情報保護委員会), www.ppc.go.jp.
Transfer to the USA: The adequacy decision between the EU and Japan covers only data flows between those two jurisdictions. Data of Japanese data subjects is additionally held in Google Workspace (section 14.10), where processing in the USA cannot be ruled out. For that transfer we rely on the EU-US Data Privacy Framework with standard contractual clauses as a fallback safeguard; in accordance with Art. 28 APPI we provide this information separately and will supply further details on the recipient country on request.
Requests from Japanese data subjects are processed within 30 days. Contact: wessal@kurokolabs.ai.
21
Changes to this privacy policy
We reserve the right to update this privacy policy as necessary in order to adapt it to changes in the legal situation, new service providers or changes in our data processing practices.
In the event of material changes affecting your rights as a data subject, we will inform you in an appropriate manner (e.g. by email or by a notice on our website).
We recommend that you review this privacy policy regularly.
22
Change history
| Version | Date | Change |
|---|---|---|
| 2.5 | 20.08.2026 | Japan chapter (20) extended by the APPI publication duties that the GDPR does not have in this form: purposes of use (Art. 21), security measures including the names of the countries in which processing takes place (Art. 32(1)(iv), Enforcement Rules Art. 10), clarification on joint use (Art. 27(5)(iii)) and anonymously processed information (Art. 43), and the Japanese complaint authority (Personal Information Protection Commission) |
| 1.0 | 26 Feb 2025 | First version |
| 2.0 | 10 Apr 2026 | Complete revision: EU AI Act (Art. 50 transparency, Art. 5 prohibited practices, Art. 22 GDPR), TDDDG alignment, retention periods updated (8 years pursuant to Sec. 147 AO as amended), all services disclosed (Google Analytics, Google Fonts, Google Calendar API, Webflow CDN, Qonto), deletion concept added, DPIA section, Japan/APPI section expanded, customer portal data processing detailed |
| 2.1 | 2 May 2026 | Qonto section expanded: transmission of outgoing invoices (“client invoices”) and retrieval of receipts via the Attachments API |
| 2.3 | 11 Aug 2026 | Alignment with actual system behaviour following a full legal and security audit: section 14.4 (typefaces are self-hosted, no connection to Google), 14.5 (scheduling without calendar access), 14.7 (AI conversation data project-dependent, currently not stored in the portal), 14.9 (tax number and 8-year period), cookie table extended by kl_device, deletion concept extended by backups, retention period for unverified accounts corrected to 24 hours, APPI section extended by the US transfer. Implemented technically: analytics cookies are now genuinely loaded only after consent, and audit logs store truncated IP addresses only |
| 2.2 | 11 Aug 2026 | Google Workspace (Gmail, Drive, Calendar) added as a processor (section 14.10): business communication and document storage including storage location, third-country transfers and fallback safeguard. Former section “Email/SMTP, Hostinger” replaced, SSL/TLS section moved to 14.11. Categories of recipients (section 11), international transfers (section 12) and the deletion concept (section 18) updated accordingly. English and Japanese versions published for the first time |