Privacy Policy
How Agent Mai handles personal data, service providers, retention, and your GDPR rights.
- Document
- Privacy information under Articles 13 and 14 GDPR
- Version
- 2.0
- Updated
- 12 July 2026
- GDPR information
- Controller identified
- No ad tracking

On this page
1. Controller and contact
The controller for the Agent Mai website, account administration, commercial communications, and platform operations is ALB Digital Dienstleistungen, Mainzer Str. 235, 53179 Bonn, Germany.
Privacy questions and requests can be sent to admin@vonbraide.com. No separate data-protection officer is publicly designated at the effective date of this notice. If that changes, the appointed contact details will be published here.
2. Our role depends on the data
Controller
We decide why and how we process visitor, account, billing, support, security, and service-administration data.
Processor for customer content
For personal data in a customer workspace or audit material, the customer is normally the controller and Agent Mai processes it on documented instructions under the applicable Data Processing Agreement.
3. Data categories and sources
- Account and workspace data: name, work email, password hash, organisation, role, account state, and workspace membership provided during registration or by a workspace administrator.
- Customer content: audit descriptions, evidence, technical documentation, and generated outputs that a user submits to the Service. This content can contain personal data if the customer includes it.
- Transaction data: plan, billing state, Stripe customer and subscription identifiers, and payment event references. Card details are processed by Stripe, not stored by Agent Mai.
- Technical and security data: IP address, browser and device information, request timestamps, authentication events, and service logs generated when the website or application is used.
- Correspondence: messages and attachments sent to our contact mailbox, plus information supplied by an administrator when inviting a colleague.
4. Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Create and administer accounts, workspaces, access controls, support, and the Service. | Art. 6(1)(b) GDPR: contract performance or pre-contractual steps. |
| Secure the Service, prevent abuse, troubleshoot, and maintain service integrity. | Art. 6(1)(f) GDPR: legitimate interests in secure and reliable operations. |
| Meet tax, accounting, fraud-prevention, and lawful-disclosure duties. | Art. 6(1)(c) GDPR: legal obligation. |
| Process workspace content for the customer. | Art. 28 GDPR: processing on the customer controller's documented instructions. |
| Send non-essential electronic marketing, where used. | Consent or another basis permitted by applicable law. Consent can be withdrawn at any time. |
We do not sell personal data or use it for unrelated advertising profiles.
5. Recipients and service providers
We disclose data only where necessary to operate the Service, fulfil a contract, comply with law, or follow a customer's documented instruction. Depending on the features used, recipients may include managed hosting and database providers, Stripe for payments, and the AI provider configured for an audit.
AI-assisted cloud audits
OptionalIf the cloud audit provider is enabled, the technical description submitted for that audit is sent to Mistral AI's API to generate a draft assessment. Do not include personal data or confidential information that is not necessary for the requested analysis. If no provider is configured, the Service uses its built-in heuristic path.
Private Vault audits
Customer-configuredFor Private Vault mode, content is sent only to the OpenAI-compatible endpoint configured for that workspace or deployment. The customer must ensure that its chosen endpoint, instructions, and data-transfer settings are lawful and contractually appropriate.
Website font delivery
Public websiteThe public website loads the Material Symbols font from Google Fonts. This can transmit technical request data, such as IP address and browser information, to Google when the font is requested. It is not used for analytics or advertising.
6. International transfers
Some suppliers or customer-selected endpoints may process data outside the European Economic Area. Where a transfer is subject to Chapter V GDPR, we use the applicable adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses, and apply supplementary measures where required. The relevant transfer information for customer content is provided in the applicable Data Processing Agreement or on request.
7. Retention
- Session data: the authenticated session cookie expires no later than seven days after issue unless you sign out earlier.
- Account and workspace data: retained while the account or workspace is active and thereafter only as needed for offboarding, dispute handling, legal claims, or statutory records. Customer-content retention follows the applicable customer agreement and documented instructions.
- Billing records: retained for the statutory retention period that applies to the relevant record.
- Security and technical logs: retained only for the period necessary to operate, secure, and investigate the Service, then deleted or anonymised unless a longer period is necessary for an incident, claim, or legal obligation.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Send requests to admin@vonbraide.com. We may request proportionate information to verify identity. We respond without undue delay and normally within one month, subject to the GDPR's permitted extension rules.
You may also lodge a complaint with the supervisory authority responsible for our establishment: the Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), or with the authority in your habitual residence, workplace, or place of the alleged infringement.
9. Automated decisions
Agent Mai does not make decisions about individuals that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR. Audit classifications and draft outputs are decision-support tools for the customer's qualified reviewers, not determinations about a person.
11. Updates to this notice
We update this notice before introducing material new processing, providers, or legal changes. The date at the top identifies the current version. Material updates will be communicated in the Service or by email where required.
Questions about this document? Email admin@vonbraide.com.
Contact options