Privacy Policy
Last updated: 2026-04-23 · Jurisdiction: Germany (DSGVO / BDSG)
1. Controller
Mignuti Chatbot [company-legal-name] — see Imprint. Contact: privacy@mignuti.com.
2. Data we process
- Account data: email, name, organization. Basis: Art. 6(1)(b) GDPR.
- Knowledge-base content (PDFs): uploaded by customers. Processed on the customer's instructions under AVV (Art. 28 GDPR).
- Chat messages (end-user ↔ bot): stored on behalf of the customer. Anonymized after 90 days (message content scrubbed; aggregated metrics retained).
- Billing: processed via Stripe (Ireland). Payment card data never touches Mignuti Chatbot servers.
3. Sub-processors
Full list: /en/legal/subprocessors. Changes are notified 30 days in advance (opt-in).
4. International transfers
Platform data (database, files, auth) is processed exclusively in the EU (Frankfurt, Supabase / AWS). For AI responses, chat messages are transferred to Anthropic PBC (USA), and for semantic search to OpenAI (USA) — safeguarded by the EU-US Data Privacy Framework (Art. 45 GDPR) and, in addition, EU SCCs 2021/914. As an additional safeguard, personal data (email, phone, IBAN, credit card, etc.) is automatically redacted before any transfer to the AI providers (PII redaction).
5. Your rights (Art. 15–22 GDPR)
Access, rectification, erasure, restriction, objection, portability. Email privacy@mignuti.com. End-users who chat with a mignuti-chatbot-powered widget can request deletion via the in-widget "delete my conversation" link (no account required).
6. Retention
- Messages (content): 90 days, then anonymized.
- Billing records: 10 years (§ 147 AO German tax law).
- Audit log: 2 years active, 7 years cold.
7. Cookies & Analytics
Marketing site uses Plausible (EU, cookie-free). After consent, the chat widget stores a session ID in the browser's localStorage (no cookie, no cross-site transmission) for conversation continuity. No third-party tracking.
8. Complaints
Supervisory authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Nordrhein-Westfalen (if Mignuti Chatbot is seated in NRW) — address: Kavalleriestr. 2-4, 40213 Düsseldorf.
This template will be reviewed by German IT counsel before public launch. Placeholder values in [brackets] are replaced once the entity is formally incorporated.