Draft informational page. Content remains subject to final legal review and is not final counsel-approved text.
Closed Beta legal version: bundle 2026-07-28-cb1 · document 2026-07-28
This page is a transparency draft for V1 launch preparation. It is not a final effective legal text and has not been signed off by counsel.
Privacy Policy
Datenschutzerklärung
1. Controller identity
Controller / Operator: Zwima Technologie GmbH
Dormagener Str. 2e
41468 Neuss
Germany
Website: https://zwima-group.info
Email: hello@zwima-group.info
2. Scope of this policy
This draft describes how personal data may be processed in connection with the ZWIMA AI website, accounts, dashboards, and API services. Product features and processors may evolve; where details are not yet counsel-approved they are marked POLICY_PENDING or LEGAL_REVIEW_REQUIRED.
3. Roles (confirmed model)
3.1 API customer content
For prompts, files, business data, and model outputs that you submit to or receive through the ZWIMA API:
- You (the customer) are the Data Controller
- Zwima Technologie GmbH is the Data Processor
- ZWIMA processes such data only on your documented instructions (see also our DPA draft)
3.2 Platform operations data
For account, billing, security, audit, anti-abuse/fraud, and statutory compliance data, Zwima Technologie GmbH is an independent Data Controller. Account and billing data are not described as controlled by the customer.
4. Account and authentication data
When you register or sign in, we process account identifiers and authentication-related data (for example name, email, organisation membership, and session/security tokens via our authentication provider). Legal basis candidates: Art. 6(1)(b) and/or (f) GDPR — LEGAL_REVIEW_REQUIRED.
5. API prompts, files, business data and model outputs
Content you send to the API (prompts, files, business data) and resulting model outputs are processed so we can provide the service as your processor under your instructions. You determine what personal data (if any) is included in those inputs. Retention for this category: POLICY_PENDING (counsel to define; not invented here).
6. Usage, billing and security logs
We process usage metrics, billing/subscription/payment/invoice records, and security, abuse-prevention, fraud/risk, and audit logs as independent controller for operating, securing, and billing the platform and meeting legal duties. Specific retention periods: POLICY_PENDING.
7. Processing purposes
- Provide and improve the website, accounts, and API services
- Authenticate users and protect accounts
- Process API requests and return model outputs on customer instructions
- Billing, invoicing, and subscription administration
- Security, abuse prevention, fraud/risk controls, and auditing
- Legal compliance and tax retention where required
- Respond to privacy and GDPR requests at hello@zwima-group.info
8. Legal bases under GDPR
Depending on the processing activity, we may rely on Art. 6(1)(b) (contract), Art. 6(1)(c) (legal obligation), and/or Art. 6(1)(f) (legitimate interests, e.g. security). Mapping of each purpose to a final legal basis: LEGAL_REVIEW_REQUIRED. Where we act as processor, the customer's legal bases apply to the underlying processing of customer content.
9. AI providers and sub-processor disclosure
To operate the platform we use categories of service providers that may process personal data as our sub-processors (or as processors supporting ZWIMA as controller for platform data), including:
- AI model providers
- Cloud / database providers
- Authentication provider
- Email provider
- Payment provider
The concrete vendor list is maintained on our Sub-processors page (and DPA annex). Named transfer/retention details may still be POLICY_PENDING / LEGAL_REVIEW_REQUIRED. We do not claim that all processing occurs only in the EU, and we do not claim that third-country providers are never used.
10. International data transfers
Where personal data is transferred outside the EEA (or other applicable regions), we will use appropriate safeguards as required by law (for example Standard Contractual Clauses), as documented in the final LEGAL annex. Transfer inventory and mechanism details: LEGAL_REVIEW_REQUIRED.
11. Data retention
We retain personal data only as long as needed for the purposes above or as required by law. Exact deletion and retention schedules are POLICY_PENDING and will not be invented on this draft page.
12. Security measures
We apply technical and organisational measures appropriate to the risk (access controls, encryption in transit where applicable, logging, and least-privilege practices). A formal TOM annex is LEGAL_REVIEW_REQUIRED.
13. Data subject rights
Where GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to certain automated decisions. How to exercise rights for platform-controller data: contact hello@zwima-group.info. For API content where you are controller, contact your organisation; we assist as processor under the DPA.
14. Right to lodge a complaint
You may lodge a complaint with a competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or of an alleged infringement. The authority competent for our seat in North Rhine-Westphalia is expected to be the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) — confirmation LEGAL_REVIEW_REQUIRED.
15. Contact for privacy and GDPR requests
All privacy, GDPR, and data-subject requests for V1: hello@zwima-group.info. A dedicated privacy@ address is an optional future improvement and is not used on this page.
16. Cookies
On V1 we use strictly necessary cookies only. We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, Hotjar, Microsoft Clarity, ad retargeting, or other non-essential marketing cookies. V1 does not show an Accept/Reject consent banner. If we introduce non-essential cookies later, we will enable a CMP and obtain consent first. Details: Cookies.
17. Changes to this policy
We may update this draft as the product and legal review progress. Material changes will be reflected on this page; effective-date / versioning mechanics: POLICY_PENDING.
Related: Impressum · Cookies · DPA · Sub-processors