Skip to main content

Informal translation

This translation is provided for information only. The legally binding version is the German one. Go to the German version.

Privacy Policy

As of June 2026

Informational translation. This is an unofficial English translation of our German privacy policy. Only the German version is legally binding.

1. Privacy at a glance

This privacy policy informs you about how we process personal data when you visit our website michailidou-services.de. Personal data is all data with which you can be personally identified (e.g. name, email address, IP address).

We process your data exclusively on the basis of statutory provisions (GDPR, TDDDG).

2. Controller

Responsible for the data processing on this website is:

Michailidou Digital Services I.E. Alexia Michailidou Zakaria Paliashvili Street 41 0179 Tbilisi, Georgia Email: info@michailidou-services.de

3. Representative in the European Union (Art. 27 GDPR)

Since the controller is based outside the European Union but processes personal data of persons in the EU, we have designated a representative in the Union in writing pursuant to Art. 27 GDPR:

Admir Xhoxha Psaron 17 12132 Peristeri, Greece Email: info@michailidou-services.de

You can contact our EU representative directly on all matters relating to data protection and the exercise of your rights.

4. General principles of processing

4.1 Legal bases

We process your personal data on the following legal bases:

  • Art. 6 (1)(a) GDPR – Consent (e.g. cookies, analysis tools)
  • Art. 6 (1)(b) GDPR – Performance of a contract (e.g. demo request, order processing)
  • Art. 6 (1)(c) GDPR – Legal obligation (e.g. retention obligations)
  • Art. 6 (1)(f) GDPR – Legitimate interest (e.g. IT security, server logs)

4.2 Storage duration

Personal data is stored as long as it is necessary for the respective purpose or as long as statutory retention obligations prescribe. Specific storage periods can be found in the following sections.

4.3 Data transfer to third countries

Some of the service providers we use are based in the USA or process data in third countries outside the EU/EEA (see section 9). We ensure that these transfers take place either on the basis of the EU-US Data Privacy Framework (DPF), on Standard Contractual Clauses (SCC), or with your express consent. You should be aware that the data protection level in the USA does not, in the view of the CJEU (Schrems II, judgment of 16.07.2020), correspond to the European level, and in particular access by US authorities cannot be excluded.

4.4 Provision of data

Providing your personal data is neither legally nor contractually required. However, for certain functions — such as contacting us, requesting a demo, or the customer login — providing the data marked as such is necessary; without it, we cannot deliver the respective service.

4.5 Automated decision-making

Automated decision-making producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR does not take place.

5. Data collection when visiting the website

5.1 Server log files

When our website is called up, technical data is automatically recorded in so-called server log files:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • Anonymized or shortened IP address

The processing serves the technical provision of the website, the maintenance of IT security, and error analysis. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest). This data is deleted after a maximum of 14 days or anonymized so that no personal reference is possible.

5.2 Website hosting

The website michailidou-services.de is provided via Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). Content delivery takes place by default via the EU region Frankfurt (Vercel region fra1); static assets may be delivered via Vercel's global edge network insofar as this is necessary for performance (no personal reference to the asset files themselves).

When the website is accessed, Vercel automatically processes connection data (in particular the IP address) for technical provision and IT security. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest).

Vercel is certified under the EU-US Data Privacy Framework (DPF). A data processing agreement (Data Processing Addendum) exists with Vercel including EU Standard Contractual Clauses (SCC) as supplementary safeguards for any data transfers to the USA. Further information at vercel.com/legal/privacy-policy and vercel.com/legal/dpa.

6. Contact and demo requests

6.1 Email and contact form

When you contact us by email or request a demo (Calendly appointment or direct inquiry), we process the following data:

  • Name
  • Email address
  • Company / brand
  • Request / message
  • Phone number, if applicable

The legal basis is Art. 6 (1)(b) GDPR (initiation of a contractual relationship) or Art. 6 (1)(f) GDPR (legitimate interest in efficient response). The data is deleted as soon as the inquiry has been conclusively processed and no statutory retention obligations preclude this (commercial/tax retention of contract documents up to 10 years).

6.2 Appointment booking via Google Calendar / Calendly

For appointment booking, we use Google Calendar (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) or Calendly. The transmitted data (name, email, requested appointment) is used exclusively for appointment coordination.

7. Cookies, local storage and tracking

We use cookies and comparable technologies (local storage) on our website. Technically necessary storage takes place on the basis of Art. 6 (1)(f) GDPR or § 25 (2) TDDDG.

7.1 Technically necessary storage

  • mds_cookie_consent – stores your cookie settings (local storage, permanent)
  • mds_utm_attribution – first-touch UTM parameters for conversion attribution (local storage)

7.2 Analytics: Google Tag Manager and Google Analytics 4

We use Google Tag Manager and Google Analytics 4 from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) to statistically evaluate the use of our website. Data transfer to the USA to Google LLC is possible. Google is certified under the EU-US Data Privacy Framework.

In doing so, the following data is processed, among other things: pages accessed, time spent, referrer, browser and device information, shortened IP address, pseudonymized user ID. Storage period: max. 14 months.

Legal basis: Art. 6 (1)(a) GDPR and § 25 (1) TDDDG.

8. Customer login (magic link)

On our website you can log into your customer area via a passwordless magic-link login (entering your email address, confirmation via login link sent to you). For providing the login and storing your account, we use Supabase Inc. (970 Toa Payoh North #07-04, Singapore 318992) as a processor.

Data processed: email address, session token, time of logins, IP address at login (technical security).

Legal basis: Art. 6 (1)(b) GDPR (contract initiation / performance), for IP processing for abuse prevention also Art. 6 (1)(f) GDPR (legitimate interest).

Data residency: We operate our Supabase project in the EU region Frankfurt (eu-central-1). Database content (accounts, sessions) is processed and stored there. Supabase Inc. itself is a US/Singapore company; administrative access from third countries is possible. We have concluded a data processing agreement with Supabase including EU Standard Contractual Clauses.

Sending the login link: The login link is sent via the transactional email service used by Supabase (sub-processor; see Supabase sub-processor list).

Storage duration: Account data is stored as long as the customer relationship exists. Sessions are automatically terminated after inactivity. We delete your account at your request; statutory retention obligations remain unaffected.

Further information at supabase.com/privacy and supabase.com/legal/dpa.

9. Recipients and processors

We use the following processors and service providers. We have concluded a data processing agreement pursuant to Art. 28 GDPR with all of them where necessary:

  • Vercel Inc. (USA) – Website hosting; DPF-certified
  • Supabase Inc. (Singapore / USA) – Authentication & account database (EU region Frankfurt); SCC safeguards
  • Google Ireland Limited (Ireland) or Google LLC (USA) – Tag Manager, Analytics, Google Calendar; DPF-certified
  • Calendly LLC (USA) – Appointment booking; DPF-certified

10. Your rights as a data subject

You have the following rights against us at all times regarding the personal data concerning you:

  • Information (Art. 15 GDPR) – whether and what data we process about you
  • Rectification (Art. 16 GDPR) – of inaccurate data
  • Erasure (Art. 17 GDPR) – "right to be forgotten"
  • Restriction (Art. 18 GDPR) – of processing
  • Data portability (Art. 20 GDPR) – machine-readable export of your data
  • Objection (Art. 21 GDPR) – against processing based on legitimate interests
  • Withdrawal of consent (Art. 7 (3) GDPR) – with effect for the future

To exercise these rights, please contact info@michailidou-services.de or our EU representative (see section 3). Account holders can additionally have their account deleted directly in the logged-in area. We will process your request without delay, at the latest within one month.

11. Right to lodge a complaint with the supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. A list of German data protection authorities can be found at: bfdi.bund.de.

12. Data security

We use SSL/TLS encryption to transmit your data. We take technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access.

13. Currency and changes to this privacy policy

This privacy policy is dated June 2026. Due to the further development of our website or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed at any time at michailidou-services.de/datenschutz.


14. Account and data deletion (deletion concept)

(1) Deletion on request. Via the "Delete account & data" function in the customer dashboard, the customer can request the deletion of their account and all associated personal data (Art. 17 GDPR).

(2) 30-day period. Once triggered, the deletion is scheduled and carried out finally and irreversibly after 30 days. Within this period the customer can revoke the deletion by reactivating their account.

(3) Scope of deletion. This deletes in particular profile and account data, settings, agent runs and their results, uploaded files, and the access and integration data linked to the account.

(4) Statutory retention. Invoices and payment records are retained even after deletion for the duration of the commercial and tax retention periods (in particular § 257 HGB, § 147 AO — up to ten years) and deleted once the respective period expires. To that extent the processing is based on Art. 6 (1) (c) GDPR (legal obligation). Payment records are provided via our payment service provider (Stripe).

(5) Confirmation. The customer receives confirmation of the completed deletion by email to the address last on file.

15. Transactional emails

(1) As part of performing the contract, we send transactional emails only (e.g. purchase and cancellation confirmations, notices about completed or failed agent runs, and payment and deletion notifications).

(2) These emails are necessary to perform the contract; the processing is based on Art. 6 (1) (b) GDPR (or (c), where a legal obligation applies). No consent is required for this.

(3) We do not run any email marketing (no newsletter, advertising or re-engagement mailings).