Skip to content
Auf Deutsch lesen

Privacy Policy

smartragents.ai — Karl Heinz Marko (sole proprietor)

Version: July 2026

Note: This English translation is provided for convenience only. The German version of this Privacy Policy is authoritative. In case of any discrepancy, the German version prevails.

Table of Contents

  1. Controller
  2. Overview of Processing Activities
  3. Legal Bases
  4. Hosting and Infrastructure (Hetzner)
  5. Server Log Files
  6. Registration and Customer Account
  7. Contract Handling and Payment
  8. AI Functions: Processing of Inputs (Ollama and OpenRouter)
  9. No AI Training on Customer Data; Feature Requests
  10. Data Processing for Business Customers
  11. Cookies and Consent Management
  12. Contact
  13. Data Security
  14. Storage Period and Deletion
  15. Recipients and Third-Country Transfers
  16. Your Rights as a Data Subject
  17. Right to Lodge a Complaint with a Supervisory Authority
  18. Obligation to Provide Data
  19. Automated Decision-Making
  20. Changes to this Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Karl Heinz Marko smartragents.ai Am Kirchle 11 86637 Binswangen, Germany E-mail: [email protected] Phone: +49 8272 6095003

A data protection officer has not been appointed, as the statutory requirements for a mandatory appointment are currently not met.

This Privacy Policy applies to the websites smartragents.ai, smartragents.de and smartragents.com as well as to the SaaS platform provided through them.

2. Overview of Processing Activities

We process personal data in the following contexts: visits to our website (log files, technically necessary cookies), registration and management of customer accounts, handling of contracts and payments, operation of the AI agent platform including the processing of user inputs by AI models, communication with prospective and existing customers, and fulfilment of legal obligations (e.g. tax-related retention).

Data subjects are website visitors, prospective customers, customers and their employees as well as — insofar as customers process third-party data via the platform — their end customers (see Section 10).

We process personal data on the basis of:

  • Art. 6 (1) (b) GDPR — performance of a contract and pre-contractual measures (provision of the platform, customer account, payment, support);
  • Art. 6 (1) (c) GDPR — compliance with legal obligations (e.g. retention under commercial and tax law);
  • Art. 6 (1) (f) GDPR — legitimate interests (e.g. secure and stable operation of the IT infrastructure, prevention of misuse);
  • Art. 6 (1) (a) GDPR — consent (e.g. anonymised use of agent data in the context of feature requests, non-essential cookies).

Any consent given may be revoked at any time with effect for the future.

4. Hosting and Infrastructure (Hetzner)

Our website and the SaaS platform are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Processing takes place in an ISO/IEC 27001-certified data centre inside the European Union, currently Helsinki, Finland. Customer environments are operated in Docker containers isolated from one another; data is stored on RAID-protected storage systems and additionally backed up regularly.

We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR. Further information: https://www.hetzner.com/de/legal/privacy-policy

Fonts: The Inter typeface used on our pages is served exclusively from our own server. There is no connection to Google Fonts or any other external font service. When you visit our pages, no data, and in particular not your IP address, is transmitted to a font provider. The typeface is licensed under the SIL Open Font License 1.1.

Legal bases: Art. 6 (1) (b) GDPR (vis-à-vis customers) and Art. 6 (1) (f) GDPR (legitimate interest in the secure and efficient provision of our online offering).

5. Server Log Files

When you visit our websites, information transmitted by your browser is automatically stored in server log files: IP address, date and time of access, page/file accessed, amount of data transferred, browser type and version, operating system, referrer URL.

This data serves to ensure trouble-free operation, security (e.g. defence against attacks) and error analysis. The legal basis is Art. 6 (1) (f) GDPR. Log files are deleted or anonymised after 14 days, unless further retention is required for security reasons.

6. Registration and Customer Account

A customer account is required to use the platform. In this context we process: name or company name, e-mail address, password (stored encrypted/hashed), optional profile and company details, plan and contract data, as well as log data on account usage (e.g. login times).

Legal basis: Art. 6 (1) (b) GDPR. The data is stored for the duration of the contractual relationship and deleted thereafter in accordance with Section 14.

7. Contract Handling and Payment

For billing purposes we process invoicing and payment data (billing address, selected plan, invoice amounts, payment status). Payment processing is carried out via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Privacy notice: https://stripe.com/privacy. Stripe bases transfers to Stripe, Inc. in the USA on the EU Standard Contractual Clauses. Payment data such as full credit card numbers are not stored by us.

Legal bases: Art. 6 (1) (b) GDPR (contract handling) and Art. 6 (1) (c) GDPR (retention obligations under tax and commercial law, Section 147 AO, Section 257 HGB).

8. AI Functions: Processing of Inputs (Ollama and OpenRouter)

The core of our platform is the operation of AI-supported agents. In this context, the content entered by you or your users (prompts, documents, configurations) as well as the generated outputs are processed. Depending on the selected or configured model, processing takes place in one of two ways:

a) Self-hosted models (Ollama). We operate open-source language models via the Ollama software on our own infrastructure hosted by Hetzner inside the European Union. With this option, inputs and outputs do not leave our infrastructure and are not transmitted to external AI providers.

b) External models via OpenRouter. For certain functions or at the customer’s request, we integrate models from external providers via the API service OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, USA. In this case, the inputs are transmitted to OpenRouter and from there to the respective model provider. This may involve a transfer to third countries outside the EU/EEA (in particular the USA). We base such transfers on the EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR; according to the provider’s own statements, no certification under the EU-US Data Privacy Framework is in place. According to its own statements, OpenRouter does not use inputs and outputs to train its own models; we configure the connection so that, where possible, no permanent storage takes place at OpenRouter or the model providers. Further information: https://openrouter.ai/privacy

We recommend not to process special categories of personal data (Art. 9 GDPR) in inputs unless this has been expressly agreed contractually. Within the platform, it is visible or configurable whether an agent uses local or external models.

Legal bases: Art. 6 (1) (b) GDPR (provision of the commissioned function); where external models are used optionally, additionally your active selection within the scope of contract use.

9. No AI Training on Customer Data; Feature Requests

We do not use your content, inputs, outputs or agent configurations for training or fine-tuning AI models or for improving platform-wide functions.

Sole exception: If you actively submit a feature request, you may separately and voluntarily consent to the agent data relevant for the implementation being used in anonymised form to develop the desired function as a “skill” for the entire smartragents.ai system. Before use, we remove personal data and business-related identifying characteristics. The legal basis for any processing up to the point of anonymisation is your consent (Art. 6 (1) (a) GDPR); fully anonymised data is no longer subject to the GDPR. You may revoke your consent at any time with effect for the future ([email protected]).

10. Data Processing for Business Customers

If you use our platform as a business and process personal data of third parties through it (e.g. data of your end customers in agent workflows), you are the data controller; we act as a processor pursuant to Art. 28 GDPR. For this purpose, we conclude a data processing agreement (DPA) with you, which we provide on request or in the customer account. The DPA contains the list of our sub-processors (currently: Hetzner Online GmbH; where external models are used, additionally OpenRouter, Inc. and the respectively selected model providers).

We use technically necessary cookies (e.g. session cookies for login, security tokens, your language and usage-type selection) on the basis of Section 25 (2) TDDDG in conjunction with Art. 6 (1) (f) or (b) GDPR.

Meta Pixel (Facebook pixel): Only with your consent given via our consent banner do we use the Meta Pixel operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland (“Meta”) to measure the reach and effectiveness of our advertising campaigns. Your IP address, device information and your visit to our pages are transmitted to Meta; a transfer to Meta Platforms, Inc. in the USA cannot be ruled out (safeguards: EU-US Data Privacy Framework and/or Standard Contractual Clauses). The legal basis is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). Without consent the pixel is not loaded and no data whatsoever is transmitted to Meta. The consent cookie (smartragents_consent_marketing) stores your decision for 180 days. You may withdraw your consent at any time with effect for the future by deleting this website’s cookies in your browser or by contacting us at [email protected]. Further information: Meta Privacy Policy.

12. Contact

When you contact us by e-mail, contact form or telephone, we process the data you provide (name, contact details, content of the enquiry) to handle your request. Legal bases: Art. 6 (1) (b) GDPR (contract-related enquiries) or Art. 6 (1) (f) GDPR (general enquiries). The data is deleted as soon as it is no longer required for processing and no retention obligations apply.

13. Data Security

We take technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access, in particular:

  • transport encryption of all connections (TLS);
  • operation of customer environments in Docker containers isolated from one another;
  • redundant data storage on RAID storage systems and regular backups;
  • hosting in an ISO/IEC 27001-certified data centre inside the European Union;
  • access restrictions based on the need-to-know principle, hashed password storage.

The measures are continuously adapted to the state of the art.

14. Storage Period and Deletion

We store personal data only for as long as is necessary for the respective purposes or as long as statutory retention obligations exist. In particular:

  • customer account and contract data: for the duration of the contractual relationship; after the end of the contract, content data is made available for export for 30 days, then deleted;
  • invoicing and accounting records: statutory retention periods — 8 years for invoices and accounting vouchers (Section 147 (1) no. 4, (3) AO; Section 257 (1) no. 4, (4) HGB; Section 14b (1) UStG; reduced from ten to eight years by the Fourth Bureaucracy Relief Act with effect from 1 January 2025), 10 years for books, inventories, annual financial statements and management reports (Section 147 (1) nos. 1 to 3a AO; Section 257 (1) nos. 1 to 3 HGB) and 6 years for other commercial correspondence (Section 147 (1) nos. 2 and 3 AO; Section 257 (1) nos. 2 and 3 HGB);
  • server log files: in accordance with Section 5;
  • backup copies: deletion within the rolling backup cycle.

15. Recipients and Third-Country Transfers

Recipients of personal data are exclusively the service providers named in this policy (in particular Hetzner Online GmbH as hosting partner, Stripe Payments Europe, Ltd. as payment service provider, and — where configured accordingly — OpenRouter, Inc. and the selected model providers) as well as, where applicable, tax advisors and authorities within the scope of legal obligations.

As a rule, no transfer to third countries outside the EU/EEA takes place. Exception: the use of external AI models via OpenRouter pursuant to Section 8 (b); in this case we ensure appropriate safeguards under Chapter V GDPR.

16. Your Rights as a Data Subject

You have the following rights vis-à-vis us with regard to the personal data concerning you:

  • right of access (Art. 15 GDPR),
  • right to rectification (Art. 16 GDPR),
  • right to erasure (Art. 17 GDPR),
  • right to restriction of processing (Art. 18 GDPR),
  • right to data portability (Art. 20 GDPR),
  • right to revoke consent given, with effect for the future (Art. 7 (3) GDPR).

Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (f) GDPR.

To exercise your rights, an informal message to [email protected] is sufficient.

17. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de. You may also contact the supervisory authority of your habitual residence.

18. Obligation to Provide Data

The provision of the data requested during registration and conclusion of the contract is necessary for the conclusion of the contract; without this data, we cannot conclude the contract or provide the platform. Beyond that, there is no obligation to provide data.

19. Automated Decision-Making

We do not carry out automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. The platform’s AI agents generate content and suggestions; they do not make binding decisions with legal effect. If customers use the platform in their own decision-making processes, they are responsible for this themselves.

20. Changes to this Privacy Policy

We will adapt this Privacy Policy as soon as changes to our data processing or the legal situation make this necessary. The current version published on our website applies in each case.


smartragents.ai — Karl Heinz Marko · Am Kirchle 11, 86637 Binswangen · [email protected]