Privacy Policy
Information on the processing of your personal data. Last updated: July 2026.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Danny Scherer
agenticonsult
Oberheidt 1A
42349 Wuppertal
Tel. 0151 23454663
danny.scherer@agenticonsult.de
VAT ID: DE 367382528
Owner:
Danny Scherer
1. General
1.1 This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data in connection with our website agenticonsult.de, the customer account, the purchase of digital products and subscriptions, and the Command Center desktop application.
1.2 For the terms used (e.g. "personal data" or "processing"), please refer to Article 4 GDPR.
2. Basis of data processing
2.1 Legal bases
We process personal data on the basis of consent (Art. 6(1)(a) GDPR), for the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR), and on the basis of legitimate interests (Art. 6(1)(f) GDPR).
2.2 Recipients
We disclose personal data only insofar as necessary to fulfil the stated purposes, where you have consented, or where we are legally entitled or obliged to do so. Recipients are in particular the processors and payment service providers named in this policy, and, where applicable, tax advisers and public authorities (e.g. tax authorities).
2.3 Transfers to third countries
Insofar as data is transferred to service providers based or processing outside the EU/EEA (in particular in the USA), this is done on the basis of appropriate safeguards, in particular the EU Standard Contractual Clauses under Art. 46(2) GDPR or an adequacy decision.
2.4 Storage period
We store personal data only for as long as necessary to fulfil the purposes or as required by statutory retention obligations. Tax and commercial retention obligations (Section 147 AO, Section 257 HGB) may require storage of up to ten years.
2.5 No automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR takes place.
3. Provision of the website, server log files and hosting
When you access our website, data that is technically necessary for delivery and security is automatically collected, in particular your IP address, date and time of access, browser type and version, operating system and the page accessed. The legal basis is our legitimate interest in secure and functional operation (Art. 6(1)(f) GDPR).
Hosting (Vercel)
Our website is hosted by Vercel Inc. (USA) and delivered via its content delivery network. The aforementioned server and log data are processed in the course of this. A data processing agreement is in place with Vercel; the transfer of data to the USA takes place on the basis of the EU Standard Contractual Clauses.
4. Cookies and consent management
We use cookies and comparable technologies. The storage of information on your device or access to it takes place only with your consent (Section 25(1) TDDDG), unless it is strictly necessary to provide a service you have expressly requested (Section 25(2) TDDDG). You can make and revoke your choice at any time via our cookie banner. Details are set out in our Cookie Policy.
5. Customer account, registration and sign-in
A customer account is required to purchase products and use the Command Center. During registration and sign-in we process in particular your email address and the data required for sign-in (for email/password sign-in a secured password hash; for Google sign-in the account data transmitted by Google). The legal basis is Art. 6(1)(b) GDPR (contract/pre-contractual measures).
Sign-in with Google (OAuth)
If you sign in with your Google account, we receive from Google the data required for authentication (e.g. name, email address, Google identifier). The provider is Google Ireland Limited, Ireland. Google's privacy information applies in addition.
Storage of account and contract data (Supabase)
Account, authentication and entitlement data is processed in a database we operate with Supabase Inc. with server location in the EU (Frankfurt). A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase.
6. Payment processing (Stripe)
For payment processing we use Stripe (Stripe, Inc., USA, and Stripe Payments Europe). The data required for payment (e.g. payment method, amount, time, currency and fraud-prevention data) is processed. The legal basis is Art. 6(1)(b) GDPR (performance of contract) and, for fraud prevention, Art. 6(1)(f) GDPR. Payment data is processed directly by Stripe; the transfer of data to the USA takes place on the basis of the EU Standard Contractual Clauses. Transaction data is stored for up to ten years due to tax obligations.
For fraud prevention and to preserve evidence in the event of a payment dispute, we additionally store ourselves: your IP address and browser identifier (user agent) at the time of the order, and a log of downloads of purchased digital products (time, product, IP address, browser identifier). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the prevention of payment fraud (Recital 47 GDPR) and the defence against unjustified payment disputes. Order-related evidence is deleted after 400 days and download logs after 560 days — the longer period follows the card networks' dispute filing windows.
Automated decisions: Stripe automatically assesses every card payment for fraud risk and may decline a payment on that basis. This assessment takes place at Stripe, which is independently responsible for it. A declined payment means only that the purchase does not go ahead — no existing contract is terminated and no account is suspended. If your payment was declined and you believe this is incorrect, please contact support@agenticonsult.de: we will review the matter personally and find another way forward with you.
7. Provision and download of digital products
After the purchase of digital products, we make the content available to you for download via your logged-in account area. For this we process your account and order data for the performance of the contract (Art. 6(1)(b) GDPR).
The product files are held in private storage at Vercel Inc. (Vercel Blob, USA) and delivered on download via time-limited access links. A data processing agreement is in place with Vercel; the transfer of data to the USA takes place on the basis of the EU Standard Contractual Clauses.
8. Command Center desktop application
The Command Center is a desktop application executed locally on your device. Your files, memory and knowledge graph remain on your device and are not transmitted to us.
Licence and entitlement check
To verify your subscription, the application performs an entitlement check against our server at regular intervals. Only the account or device identifiers required for this are transmitted; no usage content or files are transferred. The legal basis is Art. 6(1)(b) GDPR (performance of contract).
Update check
The application checks at regular intervals whether a new version is available. Only the technically required details (installed version number, operating system) are transmitted to our update server; no usage content or files are transferred. The legal basis is Art. 6(1)(b) GDPR (provision of the contractually owed updates, Section 327f BGB).
The user's own AI access
For AI functions, the application uses the access to third-party providers that you provide yourself (e.g. Anthropic, xAI/Grok, OpenAI). Calls to these services are made via your own account and are subject to the respective provider's privacy terms; we are not involved as controller in these calls.
9. Newsletter and intelligence feed
Your email address is required to receive our free newsletter. Sign-up uses the double opt-in procedure: after signing up you receive a confirmation email; only after confirmation do we add you to the distribution list. The legal basis is your consent (Art. 6(1)(a) GDPR); we base the proof of consent on Art. 6(1)(c) and (f) GDPR. You can unsubscribe at any time via the unsubscribe link or by email.
For sending the newsletter and transactional emails we use Resend (Resend, Inc., USA) as a processor pursuant to Art. 28 GDPR; the transfer of data to the USA takes place on the basis of the EU Standard Contractual Clauses.
Published AI-generated content in the intelligence feed is labelled as AI-generated.
10. Contact form and email contact
If you contact us via the contact form or by email, we process the data you provide (e.g. name, email address, content of the message) to handle your request. The legal basis is Art. 6(1)(b) GDPR (where there is a contractual context) or Art. 6(1)(f) GDPR (legitimate interest in responding).
For the technical transmission of form messages we use EmailJS (EmailJS Pte. Ltd.); processing takes place on servers in the USA on the basis of a data processing agreement and the EU Standard Contractual Clauses.
Email messages we receive or send are stored and processed in our mailboxes at STRATO AG (Berlin, servers located in Germany).
11. Social media presences
We maintain publicly accessible profiles on social networks and a community server in order to provide information about our products and to be reachable for those interested in them. This website contains links to those profiles and nothing more. No provider content is loaded, and merely visiting our pages transmits no data to them. Section 11a additionally applies to our Discord community server, where we process message content under our own responsibility.
- Instagram (Meta Platforms Ireland Limited, Ireland)
- X (Twitter International Unlimited Company, Ireland)
- Discord (Discord Netherlands BV, Netherlands)
If you visit one of these profiles, the respective provider processes your data on its own responsibility and under its own terms; this may also take place outside the European Union. We have no influence over the scope, purposes or retention periods of that processing.
Where a provider makes statistics and reach functions available to us for our profile, we are joint controllers with that provider for this processing within the meaning of Art. 26 GDPR. We receive aggregated evaluations only and have no access to the underlying personal data. The essential content of the respective arrangement is made available by the providers in their own privacy notices.
The legal basis for operating the profiles is Art. 6(1)(f) GDPR (legitimate interest in public presence and communication). If you wish to avoid processing by these providers, please use the offerings on this website or contact us by email.
11a. Community server (Discord) — supported by an AI system
We operate a publicly accessible community server on Discord where users can ask questions about our products and give feedback. Discord is responsible for the platform itself (see section 11). This section describes only the processing we carry out ourselves on that server, for which we are the sole controller.
When you post a message in one of the supported channels, we process:
- your Discord display name and your Discord user ID,
- the content of your message together with its time and channel,
- any reactions you add to posts in those channels.
These messages are read and answered by an AI system. Replies from our account in the supported channels may be written entirely by an AI system; they carry a corresponding notice. Further details are on our AI transparency page.
The purpose of this processing is to answer your enquiries and to receive feedback on our products. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to an existing or prospective contractual relationship, and otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and improving our products).
We do not store the content of your messages in our own systems. They are read at the time of processing and do not enter a knowledge base, a search index, or the training of AI models. The only thing retained is a technical log recording which channel was read from or written to and when; that log contains no message content. The message itself remains on the server at Discord and is subject to Discord's own terms.
We use language models from Anthropic to produce the replies. No automated decision within the meaning of Art. 22 GDPR takes place; the replies are information and assistance, not decisions concerning you with legal effect.
If you would prefer to contact us without an AI system processing your message, please use the e-mail address given in our legal notice or the contact form on this website.
12. Overview of processors and third-party providers
We use exclusively the service providers listed below. We do not use tracking, analytics, marketing or social-media services other than those disclosed here.
- Vercel Inc. (USA): hosting and delivery of the website (CDN, server logs) and private storage for purchased digital products (Vercel Blob)
- Supabase Inc. (server location EU/Frankfurt): database for account, auth and entitlement data
- Stripe, Inc. / Stripe Payments Europe: payment processing
- Resend, Inc. (USA): sending of newsletter and transactional emails
- STRATO AG (Germany): hosting of our email mailboxes (storage of incoming and outgoing correspondence)
- EmailJS Pte. Ltd. (servers USA): technical transmission of contact-form messages
- Google Ireland Limited (Ireland): sign-in with Google (OAuth), if used by you
13. Your rights and supervisory authority
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR). You can withdraw any consent given at any time with effect for the future.
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, Germany.
14. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy to reflect changes in the legal situation or changes to our services and data processing. The version published on this page applies.