Privacy Policy
Version: 3 September 2026
Language note: This English version is provided for convenience only. The German version of this privacy policy is authoritative. In the event of any discrepancy between the two versions, the German version shall prevail.
1. Introduction
This privacy policy describes how we collect, use, store, and disclose personal data when you visit our websites, use our products and services, or interact with us. Your privacy matters to us; we process personal data in accordance with applicable data protection law, in particular the EU General Data Protection Regulation (GDPR).
2. Controller
The controller responsible for data processing is:
TinyCloud GmbH
Connollystr. 8
80809 Munich, Germany
Email: [email protected]
3. What data we process
We may process various types of personal data about you. This includes in particular:
- Account data, such as your name, email address, and account settings, as well as the date and version of the Terms of Service you accepted and your consent choices;
- Content data, i.e., content you enter, upload, or have generated while using our services;
- Conversations with the assistant, i.e., your chat messages and, in voice mode, your voice input (see section 5);
- Usage and connection data, such as IP address, time of access, and technical information about the device used;
- Contract and billing data, such as booked services and invoicing details;
- Communication data, when you get in touch with us.
If you sign in with a third-party provider, we receive from that provider the data required for sign-in. The provider’s own privacy policy applies to its processing.
4. How we use your data
We use your personal data in particular to
- provide our websites, products, and services and perform the contracts concluded with you — including AI-supported features, in which content you provide may be processed by us or by service providers we engage;
- ensure the stability and security of our systems and prevent misuse;
- bill our services;
- communicate with you, for example in the course of contract performance or in response to inquiries;
- inform existing customers about our own, similar services — you may object to this at any time;
- improve and further develop our products and services;
- comply with legal obligations.
5. Conversations with the assistant
You operate TOBY by writing to the assistant or, depending on your plan, by talking to it. We process your conversations as follows:
- Carrying out your instructions. Your messages, uploaded files, and voice input are transmitted to and processed by the AI service providers we engage in order to create and edit your website. Under the agreements we have concluded with these providers, your input is not used there to train AI models. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
- Conversation history. We keep the history of your conversations in your account for as long as the account exists — in voice mode as a written transcript; we do not store audio recordings. This lets the assistant build on earlier instructions, lets you read back the history, and lets us help you when something goes wrong. Without the consent described below, our staff look at your conversations only where necessary to support you at your request, to fix errors, or to keep our systems secure (Art. 6(1)(b) and (f) GDPR). The history is deleted together with your account (section 11).
- Improving TOBY — only with your consent. When you first sign in, we ask whether TOBY may use your conversations with the assistant to improve TOBY. If you give this consent, our staff may review your conversations and derive anonymized test cases from them, which we use to check and improve how the assistant behaves; names, addresses, phone numbers, and other details that could identify you or your business are replaced with fictional ones. The legal basis is your consent (Art. 6(1)(a) GDPR). Consent is voluntary; using TOBY does not depend on it. You can withdraw it at any time with effect for the future in your settings under “Privacy”. Withdrawal does not affect the lawfulness of processing carried out before it; test cases that have already been anonymized no longer contain personal data.
6. Direct outreach to businesses (prospects)
To initiate business relationships, we process contact and company data of business operators — such as name, address, phone number, and publicly available information about the company’s web presence — taken from publicly accessible sources such as business and map directories. The purpose of this processing is to approach businesses with offers relevant to them, which may include preparing a non-binding demonstration of our services. The legal basis is our legitimate interest in direct marketing to businesses (Art. 6(1)(f) GDPR; cf. Recital 47).
You may object to this processing at any time. An informal message to [email protected] suffices; we then permanently add your business to our suppression list and will not contact you again. Data of prospects with whom no contract is concluded is deleted no later than twelve months after our last outreach.
7. Legal bases
The legal basis for processing is, as a rule, the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), or our legitimate interest in the secure, reliable, and economical operation of our services and in direct marketing to businesses (Art. 6(1)(f) GDPR). Where we obtain your consent in individual cases, that consent is the legal basis (Art. 6(1)(a) GDPR); you may withdraw consent at any time with effect for the future. We record the date and version of the Terms of Service you accepted, as well as consents given and withdrawn, so that we can demonstrate them (Art. 6(1)(c) in conjunction with Art. 5(2) and Art. 7(1) GDPR).
8. Sharing your data
Where necessary, we share your personal data with the following categories of recipients: service providers we engage to deliver our services (including in the areas of hosting, content delivery and security, AI services, payment processing, email delivery, and domain registration), which generally process personal data only on our instructions, as well as authorities and other bodies where we are legally obliged to do so. An overview of the processors we use is available at Data Processors.
9. International data transfers
We may transfer your personal data to countries outside the European Union or the European Economic Area. In such cases, we ensure that appropriate safeguards within the meaning of Art. 44 et seq. GDPR are in place, such as EU Standard Contractual Clauses or an adequacy decision of the European Commission.
10. Data security
We take appropriate technical and organizational measures to protect your personal data against loss, misuse, and unauthorized access, in particular by encrypting data in transit.
11. Retention
We generally store your personal data only for as long as necessary for the purposes described in this privacy policy, or as long as we are obliged or entitled to do so under statutory retention periods. We retain invoicing and accounting records for up to ten years under German commercial and tax law (Section 147 of the German Fiscal Code, Section 257 of the German Commercial Code). You can delete your account yourself at any time in your settings. It is then locked immediately and permanently deleted after a 30-day recovery window — together with your conversations with the assistant and your settings; backups are overwritten on a rolling basis. At your request, we also delete your data without a recovery window.
12. Cookies and similar technologies
We use only technically necessary cookies and similar technologies, for example for sign-in, your language preference, and the security of our services; no consent is required for these. To improve our offering, we use privacy-friendly, cookieless reach measurement on our own websites, which we operate ourselves on our own infrastructure; it stores no IP addresses, builds no user profiles, and transmits no data to third parties.
13. Our customers’ websites
For websites our customers create and operate with TOBY, the respective customer is the controller under data protection law. Where personal data — for example from contact forms — is processed through our systems in that context, we act as the customer’s processor. The same applies to the visitor statistics we keep for customer websites: they work without cookies or identifiers, store no IP addresses, and build no user profiles; per page view, only the page requested, the time, the country of origin, the referring website, the browser type, and the response status are recorded.
14. Automated decision-making
We do not carry out automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
15. Your rights
Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, and data portability, as well as the right to object to processing based on legitimate interests (Art. 15–21 GDPR). To exercise your rights, an informal message to [email protected] suffices. You can also delete your account yourself at any time in your settings, and you can withdraw consent to the review of your conversations there under “Privacy” (section 5). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
16. Changes to this privacy policy
We may update this privacy policy from time to time, for example when our services or the legal situation changes. The version published on this page applies.