Privacy Policy

Privacy policy for the processing of personal data at LeonLab.ai.

Legal

Privacy Policy

This Privacy Policy explains the nature, scope and purpose of the processing of personal data in connection with the use of the LeonLab website and SaaS platform.

Controller

LeonLab UG (haftungsbeschränkt)
Cappelerstr. 130B
35039 Marburg
Germany

Email: [email protected]

Represented by

Navid Behnami

Hosting

Our website and SaaS platform are hosted by OVHcloud. When users access our website or use the platform, technical access data is processed, in particular IP address, date and time of access, pages accessed, browser type, operating system and server log files.

This processing is necessary to provide the website and platform securely, reliably and stably. The legal basis is Art. 6(1)(f) GDPR.

Data We Process

We process personal data that is generated when users access our website or SaaS platform, or that users actively provide to us. This includes in particular:

  • Contact data, such as name, email address and content submitted through contact forms.
  • Account and login data, especially when registering or signing in via Google Login.
  • Technical access data, such as IP address, browser type, operating system, date and time of access and server log files.
  • Usage data within the platform, such as used features, projects, actions and system messages.
  • Newsletter data, if users subscribe to the newsletter.
  • Payment and billing data, if paid services are purchased through Stripe.
  • WordPress project data, such as website URL, technical site information, plugin/theme information, analysis results, logs and credentials or tokens provided by the user.
  • Content, prompts and technical context data entered by users within the platform, insofar as this is necessary to provide the requested AI functions.
  • Cookie and consent data, where cookies or similar technologies are used.

Google Login

Users can sign in via Google Login. Depending on the permissions granted by the user, we may process the user's name, email address, profile picture and technical identification data of the Google account. This processing is carried out to provide a simple and secure login based on Art. 6(1)(b) GDPR.

Contact Form

If users contact us via a contact form, we process the information entered in order to handle the request and possible follow-up questions. The legal basis is Art. 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR.

Newsletter

If users subscribe to our newsletter, we process the data required for this purpose, in particular the email address. The newsletter is sent through an internal LeonLab service; no external newsletter provider is used for this purpose.

Subscription takes place only with the user's consent. The legal basis is Art. 6(1)(a) GDPR. Users may unsubscribe from the newsletter at any time.

Google Analytics

We use Google Analytics, a web analytics service provided by Google, to analyze the use of our website and improve our offering. In particular, technical usage data, device information, browser information, approximate location, usage behavior and cookie information may be processed.

Google Analytics is used only if users have given their consent through our cookie banner. The legal basis is Art. 6(1)(a) GDPR. Consent can be withdrawn at any time through the cookie settings.

Cookies and Cookie Banner

We use necessary cookies and, where users consent, analytics cookies. Necessary cookies are required for the technical operation of the website and SaaS platform. Analytics cookies, in particular for Google Analytics, are set only after prior consent.

Users can change their cookie settings or withdraw consent at any time through our own cookie banner.

Payment Processing via Stripe

For paid services, we use Stripe as a payment service provider. Payment, billing and transaction data are processed to the extent necessary to process payments, issue invoices and comply with legal obligations.

The legal bases are Art. 6(1)(b) GDPR for contract performance and Art. 6(1)(c) GDPR for legal retention obligations.

WordPress Project Data

LeonLab processes WordPress project data only to the extent necessary to provide the functions requested by the user. This may include website URLs, technical website information, plugin and theme data, analysis results, logs, and credentials, tokens or application passwords provided by the user.

Users can delete connected WordPress projects and related data at any time or disconnect the connection. After deletion, the corresponding data will be deleted unless statutory retention obligations or security interests prevent deletion.

AI Functions with Azure OpenAI

To provide AI functions, we use Azure OpenAI by Microsoft. Content entered by users, prompts, project information, technical context data and system responses may be processed to the extent necessary to perform the requested functions.

LeonLab uses Azure OpenAI in particular for data protection and GDPR reasons. AI processing is provided through a European Azure region or EU Data Zone, so that AI data is processed within the European Union or the European Economic Area.

The processing is carried out to provide the SaaS and AI functions on the basis of Art. 6(1)(b) GDPR. Where Azure OpenAI is used as a service provider, the processing is based on corresponding contractual agreements with Microsoft.

We do not use content transmitted to Azure OpenAI for our own training purposes. Processing takes place only to the extent necessary to provide the functions requested by the user.

Legal Bases

The processing of personal data is carried out on the basis of the GDPR. Depending on the processing activity, we rely in particular on the following legal bases:

  • Art. 6(1)(a) GDPR, where users have given consent, e.g. for newsletters, Google Analytics or analytics cookies.
  • Art. 6(1)(b) GDPR, where processing is necessary for the performance of a contract or pre-contractual measures, e.g. for accounts, SaaS usage, WordPress functions, AI functions and payments.
  • Art. 6(1)(c) GDPR, where we are legally required to process data, e.g. for tax and commercial retention obligations.
  • Art. 6(1)(f) GDPR, where processing is necessary to protect legitimate interests, e.g. IT security, abuse prevention, error analysis and platform stability.

Recipients and Service Providers

To provide our website and SaaS platform, we use service providers, in particular OVHcloud for hosting, Google for login and analytics, Stripe for payment processing and Microsoft Azure OpenAI for AI functions. Azure OpenAI is used in a European Azure region or EU Data Zone to ensure processing within the EU or EEA.

Retention Period

We store personal data only for as long as necessary for the respective purposes or as required by statutory retention obligations.

  • Contact requests are deleted once the request has been fully processed, unless legal obligations prevent deletion.
  • Account and project data are generally stored for the duration of the user account.
  • WordPress project data can be deleted by the user at any time or removed by disconnecting the connection.
  • Newsletter data is stored until consent is withdrawn.
  • Payment and invoice data are stored in accordance with statutory retention obligations.
  • Server log files are stored only for as long as necessary for security, error analysis and operation.

Rights of Data Subjects

Data subjects have the right, in accordance with the GDPR, to access, rectification, erasure, restriction of processing, data portability and objection to certain processing activities. Consent given may be withdrawn at any time with effect for the future.

To exercise these rights, users can contact us at [email protected] .

Right to Lodge a Complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates data protection law.

Note

This template is a technical and content basis for the website. For a legally secure final version, it should be reviewed by a legal professional if necessary.