AS OF 6 JULY 2026
Privacy Policy
The short version first: this website works without cookies, without external services in your browser and without advertising trackers. We process personal data only when you actively contact us.
Note: This is a convenience translation. The German version is the legally binding one.
1. Controller
ByteNubes GmbHSeeholzenstraße 2, 82166 Gräfelfing, Germany
Represented by: Stephan Walkowiak (Managing Director)
Phone: +49 152 343 402 94 · Email: [email protected]
"KI für München" is a brand of ByteNubes GmbH.
2. Overview of processing
Personal data is processed on this website only in the following cases:
- Technically necessary server log data when pages are accessed (section 6)
- Cookieless, anonymised reach measurement (section 7)
- Data you actively submit: contact, newsletter, appointment booking (sections 8–10)
The readiness check on this website transfers no data: your answers are evaluated exclusively in your browser and are not stored.
3. Legal bases
We process personal data on the basis of the GDPR, in particular: consent (Art. 6(1)(a)), performance of a contract and pre-contractual enquiries (Art. 6(1)(b)), legal obligations (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)), such as the secure and efficient operation of this website.
4. Security measures
We take technical and organisational measures pursuant to Art. 32 GDPR and work to the principles of ISO/IEC 27001. This website is delivered exclusively TLS-encrypted and loads no resources from third-party servers: fonts and all scripts are served from our own server; there are no connections to third-party font or script CDNs.
5. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). Consent given can be withdrawn at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Competent supervisory authority: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
6. Hosting, delivery and server logs
The origin web server of this website is operated on ByteNubes GmbH's own infrastructure in Germany. When you access the website, the web server processes technically necessary data (IP address, time, page accessed, user agent) in log files to ensure operation and security (Art. 6(1)(f) GDPR). These log files remain on our own infrastructure in Germany and are not shared with third parties. We retain them only for as long as necessary for secure and stable operation and for investigating security incidents, and delete them thereafter. The domain is registered with IONOS SE, Montabaur, Germany; authoritative DNS resolution is provided by Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, USA; EU representative Cloudflare Germany GmbH, Rosental 7, 80331 Munich), which processes the DNS queries in doing so (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-U.S. Data Privacy Framework; a data processing agreement and standard contractual clauses (Art. 46 GDPR) apply in addition.
Contact form and newsletter (Cloudflare Workers): The technical transmission of form and newsletter submissions is handled via a Cloudflare service (Cloudflare Workers) before your message is passed to our email provider (see section 8). Connection data (incl. IP address) may be processed by Cloudflare in this context (Art. 6(1)(b) and (f) GDPR). Processing outside the EU cannot be ruled out; the safeguards named above apply (Data Privacy Framework, data processing agreement, standard contractual clauses). Website traffic itself is not routed through Cloudflare but delivered directly from our server in Germany; no Cloudflare content-delivery proxy or web application firewall is used.
7. Reach measurement with Plausible Analytics (self-hosted)
For anonymous reach measurement we use Plausible Analytics — operated on our own infrastructure, not as a cloud service. Plausible uses no cookies and stores no personal data; IP addresses are not stored and visitors are not made re-identifiable. The legal basis is our legitimate interest in statistical analysis of website use (Art. 6(1)(f) GDPR). As no access to your device takes place, no consent is required (§ 25 TDDDG does not apply).
8. Contact
When you contact us by email or form, we process your details (name, email address, message, optionally company and phone number) to handle the enquiry (Art. 6(1)(b) GDPR). Form submissions are transmitted via Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany) as our processor under a data processing agreement. Enquiry data is deleted once processing is complete and no statutory retention obligations apply.
9. Newsletter
We use Brevo (see section 8) for newsletter dispatch. Registration uses the double-opt-in procedure; we process your email address and registration data. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the unsubscribe link in every email.
10. Appointment booking (self-hosted)
For online appointment booking we embed a self-operated instance of the open-source software Cal.com on the booking page, hosted on our own infrastructure in the EU. No data is transferred to Cal.com, Inc. (USA) or any other third party. When you use the booking function, we process the data you enter (name, email address, chosen slot, optional details) to arrange and hold the appointment. The booking software loads only on the booking page; visiting the rest of the website triggers no embed. The legal basis is the implementation of pre-contractual measures (Art. 6(1)(b) GDPR). Alternatively, you can always book by email or phone.
11. Cookies and local storage
This website uses no consent-requiring cookies, no tracking technologies and no local storage (localStorage/sessionStorage) within the meaning of § 25(1) of the German TDDDG; the reach measurement (Plausible) is cookieless. Strictly necessary cookies may be set when you actively use the appointment booking — these are strictly necessary for the service you requested and are therefore exempt from consent under § 25(2) TDDDG. A cookie consent banner is thus not required.
12. Artificial intelligence
No AI system on this website processes visitor data. Details of AI use in our company — including governance, responsibilities and EU AI Act classification — are disclosed in our AI transparency statement. Personal data submitted with enquiries is never used to train AI models.
13. Changes and questions
We update this policy whenever the legal situation or our processing changes; the version published here applies. Questions about data protection: [email protected].