Privacy Policy
Last updated: September 18, 2026
1. Controller
n3tz GmbH in Gründung
Campus Gebäude A1 2, Starterzentrum, 66123 Saarbrücken, Germany
Email: mail@n3tz.ai
Phone: +49 6898 4989977
2. Overview of Processing Activities
n3tz is the controller for its websites, its own inquiries and demos, and its own contract and billing records. When processing a customer's customer, employee or communication data on their behalf, n3tz follows that customer's instructions; the customer determines the purposes and legal bases. The Griffi-specific information below concerns enabled Griffi features, not all n3tz products. Processing is based on the GDPR, in particular:
- Art. 6(1)(b) GDPR – performance of a contract
- Art. 6(1)(f) GDPR – legitimate interest
- Art. 6(1)(a) GDPR – consent
- Art. 6(1)(c) GDPR – legal obligations
3. Hosting and Content Delivery
The public marketing and information websites n3tz.ai and griffi.ai are provided as static websites through Cloudflare Pages by Cloudflare, Inc. When it is accessed, Cloudflare processes the technical access data required for delivery, security and error analysis (in particular IP address, timestamp, requested resource and browser/device information). The n3tz AI colleague’s SaaS and backend services — internally named Empfang and Zentrale — and the central application database run on servers of Hetzner Online GmbH in Nuremberg. Cloudflare protects and proxies their public endpoints as a DNS, CDN, DDoS-protection and TLS service. All customer file content — in particular uploaded and generated document files, case photos and encrypted external backups — is stored and processed in Cloudflare R2 under its EU jurisdiction. That EU jurisdiction applies to the R2 objects; it does not mean that Cloudflare Pages or DNS/CDN/DDoS/TLS processing across the global edge network is confined to the EU. Cloudflare, Inc. remains a US legal entity, and possible support, security or sub-processor access is not categorically excluded. The legal basis for providing the website and security logging is Art. 6(1)(f) GDPR. Further details about providers and processing locations are set out in the DPA (German).
Our legitimate interest is reliable and secure delivery and preventing abuse.
4. Griffi (SaaS)
For enabled Griffi features, we process:
- Account and contract administration: name, email and company. Art. 6(1)(b) GDPR applies where the individual is a contracting party; for business representatives and employees, Art. 6(1)(f) GDPR applies to our interest in administering the business relationship.
- Login times and technically necessary usage data for account security and service administration (Art. 6(1)(f) GDPR). Customer content processed on behalf of a customer remains subject to that customer's purposes and instructions.
- Depending on enabled modules: call, webchat, email, appointment, SMS, document and accounting data, as well as case photos and related technical metadata. Our customer generally determines the purpose and legal basis as controller.
Insofar as we process personal data of the customer's end users on the customer's behalf (e.g. messages through n3tz Webchat), we act as a processor pursuant to Art. 28 GDPR. The published DPA (German) documents the data flows and safeguards. Its incorporation and the applicable German Terms are confirmed expressly before contract conclusion. Paid Griffi self-service is not yet enabled. A future checkout will process the selected configuration, billing details and documented acceptance of the applicable Terms and DPA; publishing these documents does not activate paid sales.
For AI telephony, the caller number transmitted by the telephony provider — unless withheld — may be processed in full and stored with the call record. It is used for the requested interaction, matching a returning caller, appointment bookings and callback handling requested by the caller; where such records are created, it may also appear in the associated appointment, lead or callback data. The number may also appear in email and web-push call notifications to the responsible business to enable a callback. Recipient accounts and devices, including lock-screen notifications, require appropriate protection. The current technical implementation does not automatically truncate or pseudonymize the number to its last four digits. The customer, as controller, determines the specific purpose and legal basis (typically Art. 6(1)(b) or (f) GDPR) and may use the feature only where a lawful processing purpose exists. The AI notice provides transparency; continuing the interaction is not treated as consent.
For the public n3tz/Griffi telephone demos, including the demo at +49 6898 4989978, n3tz GmbH in Gründung is the controller. These include the German, English, French, Dutch and Turkish entry points; demo numbers are separate from our business contact number. We process the transmitted phone number, call transcript and technical call data to provide the requested demo, limit abuse and cost, and diagnose errors (Art. 6(1)(f) GDPR). We do not make our own audio recording; real-time voice processing may take place through Google Gemini in the USA. The transcript and call record are deleted no later than 90 days after the call. If the conversation results in a contact or inquiry record, that record is anonymized according to the configured lead period; the default is 24 months after its last update. A one-time SMS containing a booking link is sent only after explicit consent during the call (Art. 6(1)(a) GDPR); no SMS is sent without it.
Google services: Calendar and Gmail drafts
An authorized user of our customer can connect their Google account to the n3tz Zentrale expressly and revocably at any time. Calendar and Gmail drafts are connected separately; a calendar grant does not authorize access to Gmail and vice versa. Without such a connection, n3tz does not access the Google account through these interfaces.
- Google Calendar: With the
calendar.readonlyandcalendar.eventspermissions, n3tz reads the connected calendar's free/busy times to determine available slots for scheduling; other calendars of the account are not browsed or listed. When a user schedules, reschedules or cancels appointments, n3tz creates, updates or removes the corresponding calendar events. - Gmail: With the
openidandemailpermissions, n3tz identifies the connected account and displays its address; these permissions serve account identification only. n3tz usesgmail.composeexclusively to create — upon the user's explicit action — a durable, editable Gmail draft with the recipients, subject, formatted content, plain-text alternative, selected signature and selected attachments the user has reviewed. n3tz does not read the mailbox, does not delete messages and does not send email. The user opens, reviews, edits and sends the draft themself in Gmail.
OAuth credentials are stored encrypted, bound to the tenant and user, and are never returned to the browser. Short-lived access tokens are used only for the respective API call. Beyond that, n3tz stores only the account, permission, event, draft and synchronization references required for the visible appointment or draft workflow, plus the appointment and draft data already managed in the Zentrale. The connection can be disconnected in the settings; this deletes the stored OAuth credential and prevents further API access. Appointments or drafts already created remain in the Google account until the user manages or deletes them there.
Information from Google APIs and data derived from it are used only for the calendar and draft features visible to the user. They are not sold, not used for advertising, creditworthiness decisions or data trading, and not used to train or improve general or personalized AI models. Processing by the sub-processors named in this privacy policy and in the DPA occurs only insofar as it is necessary for the requested user feature and secure operation. n3tz's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Transmission is encrypted. Connecting and disconnecting require renewed confirmation by the signed-in user; access and stored references are limited to that user's tenant and user account. When the associated n3tz user or tenant account is deleted, the connection and the associated provider references are deleted. Beyond that, deletion can be requested in accordance with section 9.
Web-push notifications are delivered by the push service associated with the browser or operating system. Where data is not obtained directly from you, it comes in particular from the commissioning business, its communication partners, authorized calendars and documents, or the telephony provider (number and connection data). These are the contact, communication and case data described here. Where n3tz is controller, we provide the information required by Art. 14 GDPR generally within one month, at the latest upon first communication or disclosure, unless a statutory exception applies. For customer processing, we support the responsible business.
5. Payment Processing
Paid Griffi self-service is not yet enabled. Stripe is planned for future payment processing. Before activation, we will identify the actual Stripe contracting entity, processing roles and payment-data processing. This notice does not claim that a live payment flow already exists.
6. AI Processing
To provide our AI features, we use language models (LLMs) from Google. For text and document processing — n3tz Webchat (the technical Empfang service), receipt OCR, document dictation, the text-based use of the internal voice assistant as well as server-side conversation summaries, lead extraction and website analysis in n3tz HQ — inference and data residency are configured on Google Vertex AI in the EU region. Contractual support, security and sub-processor access may still involve a third country and is subject to the transfer conditions below. For the AI live phone call (Gemini Live speech model), greeting voice output and the voice mode of the internal voice assistant in n3tz HQ, n3tz currently uses a Gemini API path and model through which this speech processing takes place in the USA.
The greeting voice-output text may contain personal data, particularly the caller's name and request or continuation context, and is transferred to the USA for speech output.
For document dictation, an uploaded audio clip is transmitted once to Vertex AI in the EU region for transcription and draft extraction. n3tz does not store the raw audio file persistently; the resulting source transcript may be stored with the draft for up to 90 days.
The internal voice assistant in n3tz HQ is operated by a logged-in employee of our customer and is available only where n3tz has enabled it for that customer. In voice mode we transmit to Google LLC in the USA the speech and the transcript of the running session as well as the data the assistant retrieves from the customer's records at that employee's request: customer and contact data, issued business documents as well as quote and invoice drafts including line items and amounts, call logs and conversation transcripts, contents of incoming emails, chat histories, appointment data and entries of the internal knowledge base. This also concerns people who are not participating in the voice session, in particular callers, senders of incoming emails, participants in chat histories, recipients of quotes and invoices as well as employees of our customer. The purpose is to inform the employee, to capture dictated notes and to prepare drafts; in voice mode the assistant does not send, finalise, book or delete anything. Every data lookup is limited to the tenant of the logged-in employee. We act as a processor in doing so; our customer determines the purpose and legal basis of the processing as controller (typically Art. 6(1)(b) or (f) GDPR).
Transfers to third countries require the conditions of Art. 44 et seq. GDPR. An adequacy decision such as the EU-US Data Privacy Framework (Art. 45) covers only processing by an eligible, currently certified recipient. Otherwise, appropriate safeguards under Art. 46, such as actually agreed Standard Contractual Clauses and necessary supplementary measures, are required. Merely naming an instrument does not confirm a particular account contract. Information about the applicable recipients and safeguards, and a copy of the relevant safeguards, are available from mail@n3tz.ai. The module-specific overview is in the DPA (German).
n3tz makes and stores no audio recording of its own — neither from the AI live phone call nor from the sessions of the internal voice assistant. In both cases the production configuration does not request Gemini Live session resumption and therefore does not request the optional retention of conversation state for up to 24 hours. Google may nevertheless retain submitted prompts, contextual information and paid-service output for abuse monitoring and required disclosures for up to 55 days; this also covers the data that the internal voice assistant brings into the conversation. Because the provider documentation does not expressly exclude raw audio of these voice sessions, n3tz does not promise that exclusion. Google does not use paid-service prompts or responses to improve its products.
For the internal voice assistant, n3tz likewise does not store the transcript of the voice session; it is shown to the employee only in their browser while the session is running. Only the results that the employee expressly triggers are stored permanently, in particular notes, tasks and drafts; they reside in our customer's records and are subject to its retention periods. Security logging of these sessions is content-free and contains neither conversation content nor customer or document data.
The standard configuration is not intended for clinical practice, medical advice, diagnosis or treatment, or Gemini applications directed at or likely to be used by people under 18. Other uses require prior assessment of legal bases, provider terms and safeguards, and where necessary a suitable alternative processor. n3tz approval does not replace required provider permission. Planned processing of special-category data under Art. 9 GDPR or professional secrets under § 203 StGB requires a separate agreement. Incidentally supplied sensitive data must be minimized, access-protected and deleted where necessary.
The paid-service terms govern Google's non-use of prompts and responses for product improvement. The provider's 55-day period is not an n3tz deletion promise or a guarantee of no storage or other provider access.
7. Contacting Us
When you contact us by email or telephone, we process your contact details, message and necessary connection data to handle the inquiry. Art. 6(1)(b) GDPR applies to steps towards a contract with you; for other business correspondence, including representatives and employees, Art. 6(1)(f) GDPR applies to our interest in handling the request. A reachable contact channel and information about your request are needed for an individual reply. Our contact page has no general contact form; the specific processes below are separate. Data is deleted when no longer needed, subject to applicable retention duties.
When you join the waitlist for EU-based voice hosting, we process the email address you provide, the site language and page path, and the consent version solely to send one notification when this offering becomes available. The waitlist entry alone is not a newsletter subscription. The newsletter consent described below applies only if you select the separate, optional n3tz updates choice and then confirm the link sent to your email. The legal basis is Art. 6(1)(a) GDPR. You may withdraw consent at any time by email. We delete the entry after withdrawal, if the project is discontinued, or after the one-time notification, unless a narrowly limited statutory evidence duty continues to apply.
When you send a request about Quality Lab and a possible audit, we process the email address you provide, the site language and page path, and the consent version solely to contact you once about Quality Lab and a possible audit. The request alone is not a newsletter subscription. The newsletter consent described below applies only if you select the separate, optional n3tz updates choice and then confirm the link sent to your email. The legal basis is Art. 6(1)(a) GDPR. You may withdraw consent at any time by email. We delete the entry after withdrawal, if the project is discontinued, or after the one-time contact, unless a narrowly limited statutory evidence duty continues to apply.
When you sign up for n3tz updates — through the optional choice on a waitlist or the form before the site footer — we process your email address, language, source and page path, timestamps, consent version, and salted hashes of the IP address and user agent as consent evidence. Brevo initially sends only a confirmation email. We store the subscription as confirmed, notify our team, send one welcome email and, where configured, add the address to the dedicated Brevo list only after the link is opened and the confirmation is actively submitted (double opt-in). Unconfirmed entries are deleted after 48 hours. Confirmed contact data and evidence remain stored until withdrawal or the purpose ends. The confirmation and welcome emails load the static n3tz logo from the applicable n3tz website without recipient-specific URL parameters or open tracking. The personal unsubscribe link in the welcome email removes the address from the newsletter list; once this succeeds, we remove the raw address from our newsletter evidence and retain pseudonymised withdrawal evidence for no more than four years. You may alternatively unsubscribe and withdraw consent at any time by emailing mail@n3tz.ai. The legal basis is Art. 6(1)(a) GDPR; email is sent by Sendinblue SAS (Brevo) in the EU.
If our customer sends a photo request, the requested person receives a login-free, time-limited link for uploading the photos requested for the identified case. We process the files, technical metadata, checksums and — where present in the original file — EXIF metadata solely to associate and provide them in our customer's case. Our customer determines the legal basis and purpose as controller; uploading is voluntary. Photo files, EXIF metadata, upload permissions and security events have separate purpose-based deletion criteria. Files and metadata no longer needed must be deleted according to instructions; the contract term alone does not justify retaining them.
Providing an email address in the e-invoice validator is optional; local validation works without it and the invoice file is not transmitted. If you request the result and checklist, we process your email address, language, a technical summary without invoice contents, timestamps, consent version and hashes of IP address and user agent as consent evidence. Only after confirming the link (double opt-in) do we send the requested material, notify our team and, where configured, add the address to the dedicated Brevo list; this is not a marketing subscription. Unconfirmed records are deleted after 48 hours and the evidence after 180 days. The legal basis is Art. 6(1)(a) GDPR. Email is sent by Sendinblue SAS (Brevo) in the EU.
If you contact us via WhatsApp, we process your phone number, profile name and message content, including any voice messages, photos and receipt images you send, in order to handle your request. Voice messages are transcribed automatically within the EU region. The legal basis is Art. 6(1)(b) or (f) GDPR; using this channel is voluntary, and email and telephone are available as equivalent alternatives. Delivery is handled by the WhatsApp Business Platform operated by WhatsApp Ireland Ltd., Merrion Road, Dublin 4, Ireland. Meta Platforms Ireland Ltd. may transfer data to Meta Platforms, Inc. in the USA subject to the transfer conditions in section 6. Transport is end-to-end encrypted, but the message is decrypted for further processing on our receiving side, and Meta additionally processes traffic and metadata as its own controller under its own privacy policy. On individually enabled service numbers, an automated assistant can read authorized business records, answer incoming messages directly and prepare drafts. Sending or finalizing business documents and taking other binding actions is separate and requires the applicable explicit approval and human control.
Appointment verification is a separate outbound flow: WhatsApp is the default channel for a six-digit one-time code (OTP), with SMS as an opt-out alternative or fallback. Only the phone number, code and delivery metadata are transmitted, not appointment or business contents. An inbound WhatsApp service channel need not be enabled for this verification flow. The customer determines the purpose and legal basis for its appointment process.
8. Cookies and Traffic Measurement
A first ordinary visit to n3tz.ai or griffi.ai does not set cookies or store an identifier. The browser
language is evaluated locally to select an available German, English, French, Dutch or Turkish language
URL automatically. Only if a visitor selects a language in the language menu is that functional preference
stored as n3tz_locale in local storage for no more than twelve months; it is not used for analytics
or profiling. It serves the language function you expressly selected.
For aggregate-only success measurement, n3tz.ai counts selected clicks on phone and booking calls to
action, a successfully authorised and loaded booking form, and a completed booking reported after it has
been stored successfully on the server. Completion is not reported by the browser. Counter requests are
sent only to the n3tz-operated /api/funnel endpoint on n3tz.ai, including from griffi.ai; the counter
stores only the event name and the value 1. It does not send or store the route, query
parameters, referrer, calculator inputs, device class, session identifier or user identifier. No cookie or
browser storage is used for these counters.
In addition, we keep a second, equally aggregate-only counter to measure the success of our own
advertising and pages. It counts completed actions: a click on a phone number or e-mail address, a click
on a booking call to action, a loaded booking form, a booking completed on the server, a completed quick
check, and a submitted newsletter, e-invoicing check or contact request. The counter request goes to the
n3tz-operated
/api/conversion endpoint on n3tz.ai, including from griffi.ai; from there we forward it server-side
to our own reporting system. Only the event name, the path of the current page (without query parameters and
without the fragment) and the campaign parameters utm_source,
utm_medium and utm_campaign of that same page URL are transmitted, where present.
What is stored is a plain daily counter — a single record reads "on this day, on this page, from this campaign,
this many times". IP address, browser identification, referrer, time of day, form contents, calculator inputs,
device class and any session or user identifier are neither transmitted nor stored, and a
gclid or comparable advertising click parameter is deliberately not evaluated. No cookie and no
browser storage are used, and the numbers cannot be related to a person. Each event is counted at most once
per page view.
The n3tz web chat (Griffi) is embedded on the public marketing website. A plain page view makes no request
to the chat service. The first pointerdown (mouse or pen), keydown,
touchstart or scroll event loads the embedding script from empfang.griffi.ai. The script then requests
a signed technical authorisation bound to the respective website origin and the chat session. Only after successful
issuance is it stored under
empfang_chat_capability_v3:tenant_n3tz_gmbh:https://empfang.griffi.ai in session storage. Each
value is valid for no more than five minutes; while the page remains open, renewal is attempted about 30 seconds
before expiry and a successful renewal replaces the stored value. Invalid or expired values are discarded, and
session storage ends no later than when the browser tab is closed. The value contains no chat content and is
not used for analytics or profiling. The chat frame and chat content are processed only when you expressly open
Griffi. The embedded chat then also caches the visible timeline under
empfang_timeline:tenant_n3tz_gmbh:<chat session> in empfang.griffi.ai session storage; that
cache ends no later than the tab and is separate from server-side retention. AI processing is handled via Google
Vertex AI in the EU region, as described in section 6. We use tracking or marketing cookies and external audience measurement only after your express consent (see “Consent-based audience measurement”); no profiling takes place. The exact storage inventory is available in our
German Cookie Policy.
General page interactions trigger this preparation before the chat is opened; they are not express consent to chat processing. The statements about tracking, audience measurement and profiling concern the marketing websites, not all other products.
Consent-based audience measurement
We use the following services only if you expressly agree in the consent dialog (“Accept all” or the respective category under “Settings”). Before that, none of their scripts is loaded, no cookie is set and no request is sent to the provider; Google Consent Mode itself is loaded only after your consent (basic mode without cookieless measurement). Declining or closing the dialog is not consent, and the website remains fully usable. The legal basis is your consent under Art. 6(1)(a) GDPR and, for access to your device, Section 25(1) TDDDG.
We store your choice itself as n3tz_consent in your browser’s local storage (dialog version, time, chosen categories). The entry is not transmitted to us, only serves to respect your decision and is strictly necessary for that purpose (Section 25(2) no. 2 TDDDG). We ask again after twelve months or when the dialog or the list of providers changes.
As the page address we pass on only the path and, where present, the campaign parameters utm_source, utm_medium, utm_campaign, utm_term and utm_content, no other query parameters.
Google Analytics 4
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics evaluates which pages are visited, where visitors come from (referrer, campaign) and how the website is used, so that we can improve content and advertising. It processes a random pseudonymous identifier, page path, referrer, time, browser and device details and an approximate region derived from the IP address. Google states that Google Analytics 4 does not log or store IP addresses. Google signals and use for personalised advertising are switched off.
The cookies _ga (recognising the browser) and _ga_<ID> (session state) are set for this; we limit their lifetime to no more than 12 months. Event data is deleted in Google Analytics after 2 months. Google may transfer data to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023); in addition, the EU Standard Contractual Clauses in Google’s data processing terms apply.
Ahrefs Web Analytics
The provider is Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581. Ahrefs Web Analytics counts page views without cookies or browser storage. It receives the page path (limited as above), referrer, page title, browser language, screen size and, for technical reasons, IP address and user agent. According to Ahrefs, IP addresses are not stored but hashed together with the user agent using a random value that changes daily, so only per-day visitor counts are produced and no tracking across days, devices or websites is possible.
Singapore has no European Commission adequacy decision. The transfer is based on the EU Standard Contractual Clauses in Ahrefs’ data processing agreement. Although Ahrefs works without cookies, we also load it only after your consent.
Withdrawal
You can withdraw or change your consent at any time with effect for the future via the “Cookie settings” link at the bottom of every page; this is as easy as giving consent. On withdrawal we disable Google Analytics immediately and delete the cookies _ga and _ga_* (for marketing also _gcl_*) for this website. From the next page view on, none of the services is loaded.
9. Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
Withdrawal of consent applies to future processing and does not affect the lawfulness of earlier processing. You may object to processing based on legitimate interests on grounds relating to your particular situation, and to direct marketing at any time. Other rights apply subject to their statutory conditions. To exercise your rights, please contact us at mail@n3tz.ai.
10. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. Competent authority:
Unabhängiges Datenschutzzentrum Saarland (Independent Data Protection Authority of Saarland)
Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Germany
11. Retention Periods
Personal data is deleted when its purpose ends unless applicable retention duties require otherwise. Under § 257 HGB and § 147 AO, the relevant document categories generally require ten years for books and financial statements, eight years for accounting vouchers and six years for commercial or business correspondence. The start of the period, exceptions and tax-related extensions follow the applicable statute. These duties do not impose one blanket period on all personal data.
Operational retention is generally 90 days for call transcripts, stored chat and mailbox content and source-dictation transcripts; the configurable default for separate leads is 24 months after the last update. Stored agent conversations, messages and drafts have a 12-month period. The relevant configuration, purpose and documented deletion instructions apply; statutory business-document duties remain separate. Internal voice-session transcripts are not stored permanently. Customer documents processed on a customer's behalf are distinct from n3tz's own accounting records.
Admin audit data: 24 months; support data: 24 months after closure. Appointments, inactive contacts, cases, knowledge and photos are retained according to purpose, status and customer instructions, not automatically for the whole contract. Website and security logs are retained only as needed for delivery, error analysis or a specific security incident. Evidence and suppression records are limited to what is needed to respect withdrawals and defend legal claims (Art. 6(1)(f) GDPR); pseudonymized newsletter withdrawal evidence is kept for no more than four years after withdrawal, separately from validator evidence.
At the end of processing, the customer chooses return or deletion; 30 days are available for export. The relevant primary data, including associated R2 objects, must then be deleted unless a specific statutory duty requires retention. Backups must be blocked from ordinary use until their documented expiry; pending deletions and intervening data-subject requests must be reapplied before restoration. Provider copies and customer-controlled destinations are considered separately. The Gemini period in section 6 is a provider statement, not an n3tz deletion promise.
12. Sub-processors
The DPA (German) lists providers for agreed Griffi modules. Hetzner supplies application servers and the database; Cloudflare Pages/Edge hosts the websites and inbound-mail worker, and R2 stores objects. Google Vertex AI handles EU text inference and Gemini API US voice processing. Brevo (Sendinblue SAS) delivers email, seven SMS, sipgate telephony, and WhatsApp/Meta the described WhatsApp flows. SendGrid or Gmail SMTP are alternative configured email routes, not automatic error fallbacks. OAuth Calendar/Gmail drafts and destinations chosen by customers are separate.
Atlas processes identity, permissions and authorized knowledge through Cloudflare Access/Worker/KV/D1 and GitHub knowledge sources. Git history and changes can hold lasting copies. A connected AI client receives authorized contents; further processing depends on that client and account. Revoking access does not automatically delete copies already supplied.
Academy processes identity, learning progress, submissions and assessments. Its AI coach may send questions, conversation extracts and submissions through OpenRouter to the model provider in use; no blanket EU-only or no-retention promise applies. Automated assessments can change learning progress. You can request human review or correction at mail@n3tz.ai.
Quality Lab tests separately authorized targets and may process audio recordings, transcripts and evaluations. Griffi's statement that it makes no own audio recording does not apply categorically here. Targets and recording must be authorized before tests. The Griffi DPA does not cover Atlas, Academy or Quality Lab. Roles, data scope, recipients and retention are separately defined and communicated for a specific product deployment.