Account data
The data you enter when creating an account with our sign-in service at https://auth.2kw.ai: name, e-mail address, organisation name, and the memberships and roles inside an organisation. Legal basis: performance of the contract (Article 6(1)(b) GDPR).
Billing data
Company name and address, billing contact, VAT identification number, subscription and invoice history. Payment method details are collected and held by Stripe in its hosted billing portal and are not stored on our systems. Legal bases: performance of the contract (Article 6(1)(b) GDPR) and statutory retention duties for accounting records (Article 6(1)(c) GDPR).
Usage records and traces
Every request through the platform produces a record of the model used, token counts, cost and latency, attributed to the organisation and, where a person acted, to the account. These records are the basis for plan limits, invoicing and the cost dashboard. Prompt and completion text is dropped before a trace is stored unless an administrator of the organisation has switched on prompt or completion capture; both switches are off by default. Legal basis: performance of the contract (Article 6(1)(b) GDPR).
Technical data
Server logs with IP address, user agent, requested path, timestamp and status, at Cloudflare and on our own servers, and container logs from the production cluster. Legal basis: our legitimate interest in operating the service securely and diagnosing faults (Article 6(1)(f) GDPR).
Website analytics
https://2kw.ai uses our own Umami analytics instance at umami.manfred-kunze.dev, hosted on the same infrastructure. No analytics provider receives visitor data. Legal basis: our legitimate interest in understanding how the website is used (Article 6(1)(f) GDPR).