2kw.ai
Sign inBook a 15-min demo
Legal · Privacy

Privacy notice for the 2kw.ai platform

How Manfred Kunze Development GmbH processes personal data on https://2kw.ai, https://app.2kw.ai and the API. The company website manfred-kunze.dev has its own privacy policy.

Last updated 2026-09-02 · Version 2026-09-02

1. Controller

The controller for the data described in sections 3 to 6 is Manfred Kunze Development GmbH, Franz-Wachter-Straße 28, 70188 Stuttgart, Germany, represented by the managing directors Robin Kunze and Falk Wittmann. Contact us through the contact form or by e-mail to [email protected]. Company register and VAT details are in the imprint.

2. Two roles: controller and processor

For the data you enter to run an account, for billing and for the technical operation of the platform, we are the controller. For the content you submit to the platform for processing, such as uploaded documents, prompts, extraction schemas and the results, you are the controller and we process on your instructions as a processor under Article 28 GDPR. That processing is governed by the data processing agreement and section 7 of the general terms, not by this notice. Section 7 of this notice describes it for transparency.

3. Data we process as controller

Account data

The data you enter when creating an account with our sign-in service at https://auth.2kw.ai: name, e-mail address, organisation name, and the memberships and roles inside an organisation. Legal basis: performance of the contract (Article 6(1)(b) GDPR).

Billing data

Company name and address, billing contact, VAT identification number, subscription and invoice history. Payment method details are collected and held by Stripe in its hosted billing portal and are not stored on our systems. Legal bases: performance of the contract (Article 6(1)(b) GDPR) and statutory retention duties for accounting records (Article 6(1)(c) GDPR).

Usage records and traces

Every request through the platform produces a record of the model used, token counts, cost and latency, attributed to the organisation and, where a person acted, to the account. These records are the basis for plan limits, invoicing and the cost dashboard. Prompt and completion text is dropped before a trace is stored unless an administrator of the organisation has switched on prompt or completion capture; both switches are off by default. Legal basis: performance of the contract (Article 6(1)(b) GDPR).

Technical data

Server logs with IP address, user agent, requested path, timestamp and status, at Cloudflare and on our own servers, and container logs from the production cluster. Legal basis: our legitimate interest in operating the service securely and diagnosing faults (Article 6(1)(f) GDPR).

Website analytics

https://2kw.ai uses our own Umami analytics instance at umami.manfred-kunze.dev, hosted on the same infrastructure. No analytics provider receives visitor data. Legal basis: our legitimate interest in understanding how the website is used (Article 6(1)(f) GDPR).

4. Where data is processed

  • Application, sign-in service, document conversion and object storage: Hetzner Online GmbH, data centres in Falkenstein and Nuremberg, Germany. Documents uploaded for extraction, conversion or transcription are held in memory while they are processed and are not stored. Documents uploaded through the Files API or into a knowledge base are stored in Hetzner Object Storage in Germany until they expire or are deleted.
  • Platform database: managed PostgreSQL on Tiger Cloud (Timescale, Inc.) in the Amazon Web Services region eu-central-1 (Frankfurt, Germany); backups are kept in the same region for 14 days.
  • Built-in models: one Azure OpenAI deployment of type Data Zone Standard, resource in the Sweden Central region. For Data Zone deployments in an EU resource, Microsoft processes prompts and completions in EU member states only and keeps data at rest in the resource's geography.
  • Bring-your-own-key routing (Scale and Enterprise plans): requests go to the provider you selected, under your own contract with that provider. That processing is outside this notice.
  • Content delivery and TLS termination: Cloudflare's global network, handling requests in transit.
  • Billing: Stripe Payments Europe, Limited, in the European Union, with Stripe entities in the United States involved in payment processing.
  • Infrastructure monitoring: Grafana Cloud in Grafana Labs' Germany region, receiving cluster metrics, Kubernetes events and container logs. Monitoring data therefore stays in the EU, as section 7 of the general terms states for customer data.

5. Recipients and sub-processors

We share personal data only with the processors needed to run the platform. The current list, with purpose, location and the transfer safeguard for each, is maintained at /subprocessors and forms Annex IV of the data processing agreement. As of the date of this notice these are:

  • Microsoft Ireland Operations Limited
  • Hetzner Online GmbH
  • Timescale, Inc., d/b/a Tiger Data
  • Cloudflare, Inc.
  • Stripe Payments Europe, Limited
  • Raintank Inc. dba Grafana Labs

Where a provider's contracting entity sits outside the European Economic Area, the European Commission's standard contractual clauses in that provider's data processing terms apply. We do not sell personal data and do not share it for advertising.

6. Retention

Account data
For the term of the contract. After termination it is deleted unless a statutory retention duty applies.
Billing records
For the statutory retention periods under German commercial and tax law.
Usage records and traces
For the term of the contract, as the basis of invoicing and of the cost dashboard.
Uploaded documents
Documents uploaded for extraction, conversion or transcription are held in memory for the duration of processing and not stored. Files uploaded through the Files API for use in agent conversations expire 24 hours after they were last used; expired or deleted files are removed from storage after a grace period of 7 days. Documents uploaded into a knowledge base are kept for as long as they belong to it; deleting a document withdraws its passages from retrieval and marks its file for removal under the same grace period. The extraction and conversion results are kept as part of your organisation's data for the term of the contract.
Server and container logs
For the period needed to operate the service and investigate incidents.

7. Content you submit for processing

Documents, audio, prompts, schemas and results you submit are processed on your instructions to deliver the service. Under section 7 of the general terms, inputs and results are not used to train, retrain or improve AI foundation models, are not disclosed to third parties except as needed to provide the service or as required by law, and are not accessible to other customers or to the providers of the underlying models. Data stored beyond the immediate processing is stored to deliver and improve the service for your organisation; its deletion follows the contractual agreements and statutory retention duties. If the content contains personal data of third parties, you are responsible for having a legal basis to process it.

8. Your rights

You have the right of access (Article 15 GDPR), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20) and to object to processing based on legitimate interests (Article 21). Send requests through the contact form or by e-mail to [email protected]. For content your organisation submitted as controller, direct the request to that organisation; we assist it under the data processing agreement.

You may lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for us is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI), Lautenschlagerstraße 20, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de.

9. Changes to this notice

The date at the top of this page is the date of the current version. Material changes are announced to the contact address on the customer account before they take effect.

Related
Security overviewHosting, encryption, tenant isolation, access control and vulnerability reporting.Sub-processorsEvery third party that processes customer data on our behalf, with location and safeguards.Data processing agreementArticle 28 GDPR agreement based on the Commission's standard contractual clauses, with annexes.ProcurementCompany facts and every document a purchasing or compliance review asks for, on one page.