Privacy Policy
Version: 29 July 2026
Language note: This English version is provided for convenience only. The German version of this privacy policy is authoritative. In the event of any discrepancy between the two versions, the German version shall prevail.
1. Introduction
This privacy policy describes how we collect, use, store, and disclose personal data when you visit our websites, use our products and services, or interact with us. Your privacy matters to us; we process personal data in accordance with applicable data protection law, in particular the EU General Data Protection Regulation (GDPR).
2. Controller
The controller responsible for data processing is:
TinyCloud GmbH
Connollystr. 8
80809 Munich, Germany
Email: [email protected]
3. What data we process
We may process various types of personal data about you. This includes in particular:
- Account data, such as your name, email address, and account settings;
- Content data, i.e., content you enter, upload, or have generated while using our services;
- Voice data, when you use our voice features: your voice input is processed by the AI service providers we engage solely to carry out your instructions and, under the agreements we have concluded with them, is not used to train AI models;
- Usage and connection data, such as IP address, time of access, and technical information about the device used;
- Contract and billing data, such as booked services and invoicing details;
- Communication data, when you get in touch with us.
If you sign in with a third-party provider, we receive from that provider the data required for sign-in. The provider’s own privacy policy applies to its processing.
4. How we use your data
We use your personal data in particular to
- provide our websites, products, and services and perform the contracts concluded with you — including AI-supported features, in which content you provide may be processed by us or by service providers we engage;
- ensure the stability and security of our systems and prevent misuse;
- bill our services;
- communicate with you, for example in the course of contract performance or in response to inquiries;
- inform existing customers about our own, similar services — you may object to this at any time;
- improve and further develop our products and services;
- comply with legal obligations.
5. Direct outreach to businesses (prospects)
To initiate business relationships, we process contact and company data of business operators — such as name, address, phone number, and publicly available information about the company’s web presence — taken from publicly accessible sources such as business and map directories. The purpose of this processing is to approach businesses with offers relevant to them, which may include preparing a non-binding demonstration of our services. The legal basis is our legitimate interest in direct marketing to businesses (Art. 6(1)(f) GDPR; cf. Recital 47).
You may object to this processing at any time. An informal message to [email protected] suffices; we then permanently add your business to our suppression list and will not contact you again. Data of prospects with whom no contract is concluded is deleted no later than twelve months after our last outreach.
6. Legal bases
The legal basis for processing is, as a rule, the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), or our legitimate interest in the secure, reliable, and economical operation of our services and in direct marketing to businesses (Art. 6(1)(f) GDPR). Where we obtain your consent in individual cases, that consent is the legal basis (Art. 6(1)(a) GDPR); you may withdraw consent at any time with effect for the future.
7. Sharing your data
Where necessary, we share your personal data with the following categories of recipients: service providers we engage to deliver our services (including in the areas of hosting, content delivery and security, AI services, payment processing, email delivery, and domain registration), which generally process personal data only on our instructions, as well as authorities and other bodies where we are legally obliged to do so. An overview of the processors we use is available at Data Processors.
8. International data transfers
We may transfer your personal data to countries outside the European Union or the European Economic Area. In such cases, we ensure that appropriate safeguards within the meaning of Art. 44 et seq. GDPR are in place, such as EU Standard Contractual Clauses or an adequacy decision of the European Commission.
9. Data security
We take appropriate technical and organizational measures to protect your personal data against loss, misuse, and unauthorized access, in particular by encrypting data in transit.
10. Retention
We generally store your personal data only for as long as necessary for the purposes described in this privacy policy, or as long as we are obliged or entitled to do so under statutory retention periods. We retain invoicing and accounting records for up to ten years under German commercial and tax law (Section 147 of the German Fiscal Code, Section 257 of the German Commercial Code). If you delete your account, your data is generally deleted after a short recovery window; backups are overwritten on a rolling basis.
11. Cookies and similar technologies
We use only technically necessary cookies and similar technologies, for example for sign-in, your language preference, and the security of our services; no consent is required for these. To improve our offering, we may use privacy-friendly, cookieless reach measurement on our own infrastructure, which does not build user profiles.
12. Our customers’ websites
For websites our customers create and operate with TOBY, the respective customer is the controller under data protection law. Where personal data — for example from contact forms — is processed through our systems in that context, we act as the customer’s processor.
13. Automated decision-making
We do not carry out automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
14. Your rights
Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, and data portability, as well as the right to object to processing based on legitimate interests (Art. 15–21 GDPR). To exercise your rights, an informal message to [email protected] suffices. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
15. Changes to this privacy policy
We may update this privacy policy from time to time, for example when our services or the legal situation changes. The version published on this page applies.