Last updated: August 2025
1. Introduction
At keinsaas, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Important:
This website is operated by two legally separate companies, each responsible for different services.
2. Data Controllers
Depending on the service you use, different companies are responsible for processing your personal data:
For Consulting and Agency Services
keinsaas GbR
Hagen Rothmann & Paul Raben
Geibelstraße 57
22303 Hamburg, Germany
📧 Email: info@keinsaas.com
Responsible for:
• Website operations and marketing
• Consulting and agency services
• Automation projects and implementations
• Custom software development
• Customer inquiries and support for agency services
For Software Products (keinsaas Navigator)
keinsaas OÜ
Järvevana tee 9
11314 Tallinn, Estonia
Registry code: 17354044
📧 Email: navigator@keinsaas.com
Responsible for:
• keinsaas Navigator (LLM chat interface)
• User accounts and subscriptions
• Chat data storage
• Technical support for software products
3. Data We Collect
Personal Information:
• Name, email address, contact details when you register or contact us
• Company information and professional details
• Payment information (processed through Stripe)
Usage Data:
• Pages visited, features used, time spent
• IP address, browser type, device information
• Cookies and similar tracking technologies
Navigator-Specific Data (keinsaas OÜ):
• Account Data: Email, name, subscription details
• Chat Data: All messages you send and receive, including uploaded files and generated responses
• LLM Selection: Which AI models you choose to use (e.g., GPT-4, Claude, Gemini)
• Usage Metrics: Credit consumption, number of chats, model usage statistics
Communication Data:
• Messages sent through contact forms
• Email communications and support requests
4. Legal Basis for Processing
We process your personal data based on the following legal bases under GDPR:
• Contract performance (Article 6(1)(b)): To provide our services
• Consent (Article 6(1)(a)): For marketing communications and non-essential cookies
• Legitimate interests (Article 6(1)(f)): For website analytics and service improvement
• Legal obligations (Article 6(1)(c)): For compliance with applicable laws
5. How We Use Your Data
For All Services (keinsaas GbR and keinsaas OÜ):
• Service Provision: To provide and improve our services
• Communication: To respond to inquiries and provide customer support
• Marketing: To send relevant updates about our services (with your consent)
• Analytics: To analyze website performance and user behavior
• Legal Compliance: To fulfill legal and regulatory requirements
Specifically for keinsaas Navigator (keinsaas OÜ):
• Chat Processing: Your messages are sent to the AI model you select (hosted by OpenAI, Anthropic, Google, or other providers depending on your choice)
• Chat Storage: All chats are stored in Supabase (AWS servers in Europe) to provide chat history and continuity
• Credit Management: To track and manage your credit consumption based on model usage
• Service Improvement: To improve our platform and user experience
Important: Your chat data is processed by the AI providers you select. EU-hosted models are visually marked in the interface. Non-EU models (e.g., standard OpenAI, Anthropic) may process data outside the EU.
6. Data Sharing and Third-Party Services
keinsaas GbR uses Vercel (AWS EU servers) for hosting, email services for marketing, and analytics tools. keinsaas OÜ (Navigator) uses AI providers (OpenAI, Anthropic, Google), Supabase (AWS EU), Vercel, and Stripe for payments. When you use Navigator, your messages are sent to your chosen AI provider. EU-hosted options are clearly marked. We have Data Processing Agreements with all processors per Article 28 GDPR. We may disclose data if required by law. We do not share chat data with third parties for marketing, train AI models on your data (subject to AI provider terms), or sell your personal information.
7. International Data Transfers
keinsaas GbR processes data primarily within the EU/EEA. keinsaas OÜ (Navigator): Chat storage in EU (Supabase on AWS), AI processing depends on your model selection (EU-hosted models keep data in EU, non-EU models may transfer to USA or other locations), hosting in EU (Vercel on AWS). For transfers outside the EU, we rely on Standard Contractual Clauses (SCCs), adequacy decisions from the European Commission, and AI providers' data protection frameworks. You control which AI models process your data - choose EU-hosted options to keep data within the EU.
8. Data Retention
keinsaas GbR: Account data until deletion or 3 years after last activity, marketing data until unsubscribe, support communications up to 3 years, project documentation as required by German law (typically 10 years). keinsaas OÜ (Navigator): Account data until deletion or 3 years after last activity, chat history stored until you delete it or close your account, uploaded files same as chat history, billing records as required by Estonian law (typically 7 years). Both: Analytics data up to 26 months anonymized, legally required retention per German/Estonian laws. You can delete chats or your account anytime through Navigator or by contacting navigator@keinsaas.com.
9. Your Rights
Under GDPR you have: Right to Access (Article 15), Right to Rectification (Article 16), Right to Erasure (Article 17), Right to Restrict Processing (Article 18), Right to Data Portability (Article 20), Right to Object (Article 21), Right to Withdraw Consent (Article 7). To exercise rights: For agency services contact info@keinsaas.com, for Navigator contact navigator@keinsaas.com or use account settings. Response time: Within 30 days.
10. Cookies and Tracking
We use cookies to keep you logged in, remember preferences, analyze website usage, and improve user experience. Manage cookies through browser settings. Essential cookies are required for service functionality.
11. Marketing Communications
When you sign up or use our services, you may receive marketing emails. You can unsubscribe using the link in emails, contact info@keinsaas.com to opt out, or update preferences in your account settings.
12. Data Security
We implement security measures including encryption (SSL/TLS for transmission, encryption at rest), access control (restricted to authorized personnel), regular security audits, and secure infrastructure (AWS and Vercel with industry-standard security).
13. Data Breach Notification
In case of a data breach, we will notify the supervisory authority within 72 hours, inform affected individuals if there is high risk, and take immediate steps to contain and remedy the breach.
14. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect data from children under 16.
15. Supervisory Authorities
For keinsaas GbR (Germany):
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, https://datenschutz-hamburg.de
For keinsaas OÜ (Estonia):
Estonian Data Protection Inspectorate, Tatari 39, 10134 Tallinn, Estonia, https://www.aki.ee
16. Changes to This Policy
We may update this policy periodically. We will notify you of material changes via email or website notice.
17. Contact Us
General Inquiries and Agency Services:
keinsaas GbR
📧 info@keinsaas.com
📍 Geibelstraße 57, 22303 Hamburg, Germany
Navigator and Data Deletion:
keinsaas OÜ
📧 navigator@keinsaas.com
📍 Järvevana tee 9, 11314 Tallinn, Estonia