Legal · United States
Privacy Policy
vincilab.de and “Your AI Employee” · United States. Effective date: September 27, 2026 · Last updated: September 27, 2026
1. Who is responsible
Fabian Mahnke (doing business as “Vinci AI”)
c/o IP-Management #10868
Ludwig-Erhard-Str. 18
20459 Hamburg, Germany
Email: [email protected]
We are established in the European Union. The EU General Data Protection Regulation (GDPR) therefore applies to everything we do with personal data, wherever you live. We apply the same standards to everyone. Where US law — for example California law — gives you additional rights or requires additional information, Section 10 provides it. We have not appointed a data protection officer, because the law does not require one for a business of our size.
2. The short version
- Our website and your customer account: we decide how the data is used. We are the “controller”.
- Your AI Employee’s server: the business data on it is yours. You decide what goes in and what it is used for; we run the server on your instructions as your “processor” under a Data Processing Addendum (DPA).
- Anthropic (Claude) and Discord: you use them under your own accounts. What your AI Employee sends to Claude goes to Anthropic in the United States under Anthropic’s privacy policy; your messages to your AI Employee pass through Discord under Discord’s privacy policy. Neither is our sub-processor.
- We do not sell personal information. We use it to run the Service, to bill you and to keep the Service secure.
3. Roles: controller, processor, and your own providers
3.1 We are the controller for: our website, your order and account, invoicing, support, and the emails we send you.
3.2 We are your processor for the data on your AI Employee’s server. You are the controller of that data — including any personal data of your customers, staff or contacts you let your AI Employee handle. Our Data Processing Addendum, which you accept at checkout, governs this: what we may do (only what is needed to set up, update, monitor, support, export and delete the server, and only on your instructions), our security measures, the sub-processors we use, and how we help you answer requests from the people whose data it is. It incorporates the European Commission’s standard contractual clauses for controllers and processors (Implementing Decision (EU) 2021/915).
3.3 Your own providers, not ours. Anthropic and Discord process your data under your own agreements with them. We describe in Sections 5.4 and 5.5 what goes where, so you can make informed choices, but we are not a party to that processing.
4. What we collect and why
4.1 If you visit our website
- Server logs. IP address, date and time, page requested, browser type — processed by our hosting provider Netlify to deliver the site and keep it secure. Legal basis: our legitimate interest in running the site reliably (GDPR Art. 6(1)(f)). Retention: as long as Netlify keeps its logs.
- No tracking on our English pages. Our English pages (vinciailab.com and vincilab.de/en/) have no forms, set no cookies, load no advertising or analytics tools and embed no third-party content. When you click “Start free”, you go to Stripe’s checkout (Section 4.2). To see which ad brought you, we may add a campaign tag to the page address (for example
?utm_source=youtube); it is recorded only in our server logs and in your Stripe checkout session. - Our German pages. If you visit our German pages (vincilab.de), their German privacy policy at vincilab.de/datenschutz applies to that visit, including its advertising measurement and forms.
4.2 If you start a trial or subscribe
- Account and order data. Name, email address, company name, country, what you ordered and when, trial and subscription status, your consent to the renewal terms (what you agreed to, when, from which address). Purpose: to run the contract, invoice you, keep the records the law requires, and prove your consent. Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). Retention: for the life of the contract plus the periods German commercial and tax law require for invoices and records (currently up to ten years); proof of consent to the renewal terms is kept at least three years, or one year after termination, whichever is longer (California law).
- Payment data. You enter your card or bank details on Stripe’s pages; we never see the full card number. From Stripe we receive your name, email address, the amount, the payment status and the card type and last digits, so we can match payments to your account and answer your questions. Legal basis: contract and legal obligation.
- Setup data. Your first name and the name of your business (so your AI Employee knows who it works for), your Discord username and Discord ID (so only you can talk to it), the hostname and IP address of your server, and the one-time setup link we email you. On your server we store only a hash of that link; it stops working 48 hours after we send it. A copy of the link stays in our access-restricted store with your setup records and is deleted when your subscription ends. Legal basis: contract.
- Support. What you write to us by email or Discord, and what we write back. Retention: 3 years after the last message.
- Service emails. Setup instructions, the trial-ending reminder, invoices, the annual subscription reminder, notices of changes, outage notices. These are part of the contract. Marketing emails only with your consent, withdrawable at any time.
4.3 Your AI Employee’s server — data you control
Your server stores your AI Employee’s memory database, tasks, project files, working rules, scheduled jobs and logs, and — as Claude Code does by default — local transcripts of its sessions for 30 days. This data is yours. It may include personal data of your customers, staff and contacts. We process it only:
- to set up, update, monitor, export and delete the server, on your instruction or as the Terms provide;
- to give you support when you ask for it;
- to fetch and publish a web page your AI Employee built, when you instruct it (Terms, Section 2);
- never for our own purposes, never to train AI models, never to sell or share.
We do not keep separate backups or snapshots of your server. We hold administrator (“root”) access to the server for the tasks above; access is limited to our own network address by the server’s firewall and secured with keys, not passwords. Your export (Terms, Section 7) contains the data listed above and never contains your Anthropic sign-in token or the Discord bot token.
4.4 Your Anthropic sign-in on the server
We never see or store your Anthropic password. During setup you sign in on Anthropic’s website; the one-time code Anthropic gives you is pasted into a setup page that runs on your own server and is handed to Claude Code there. It is not logged, not stored and not transmitted to us. Claude Code then stores an access token on your server, in the service user’s home directory, readable only by that user. A daily check on your server reads only that token’s expiry date, so we can warn you before it runs out. We do not copy, move or use the token. Because we administer the server, we technically could read it; we commit not to, except where you ask us to or the law requires it.
4.5 Tools your AI Employee can use through our accounts
For some research tasks your server can call third-party services through our account (a “tool account” with a monthly spending cap), so you do not need your own contracts:
- DataForSEO (search-volume and search-result data) receives the search terms your AI Employee submits.
- Google Gemini API on the paid tier receives the prompts your AI Employee submits; Google states that it does not use paid-tier prompts and responses to improve its products.
Our relay forwards each request and records only metadata: time, your server’s short name, the service, the endpoint, the result status, duration and cost — not the content of the request. Retention: 12 months. Reports we produce for you (for example a website or market check) may use Google PageSpeed Insights and Google Places; those calls are made by us, and you receive the finished result.
5. Who receives data
| Recipient | What and why | Where | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | hosts your dedicated server | Germany (Nuremberg or Falkenstein); Finland (Helsinki) only if agreed with you | our processor; data processing agreement |
| Hostinger International Ltd., Cyprus | our own operations server (Frankfurt am Main) and mailbox: order records, setup links, tool-account logs, your final export for 30 days, support email | Germany | our processor; data processing agreement |
| Stripe Payments Europe, Limited, Ireland (and Stripe, Inc. as its affiliate) | payments, invoices, customer portal, consent records | EU and US | our processor; Stripe DPA (part of Stripe’s service agreement); EU-US Data Privacy Framework and Standard Contractual Clauses |
| Brevo (Sendinblue GmbH), Köpenicker Str. 126, 10179 Berlin, Germany | service and marketing emails, double opt-in | EU | our processor; DPA in Brevo’s terms |
| Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA | hosts our website; also hosts a web page your AI Employee builds if you ask us to publish it | US | our processor; DPA; EU-US Data Privacy Framework |
| Discord Inc., San Francisco, USA | your channel to your AI Employee (Section 5.5) — under your own Discord account | US | your own agreement with Discord |
| Anthropic PBC, San Francisco, USA (for EU residents: Anthropic Ireland, Limited) | Claude — under your own subscription (Section 5.4) | US | your own agreement with Anthropic |
| DataForSEO; Google LLC (Gemini API paid tier; PageSpeed Insights; Places) | research tools (Section 4.5) | US / EU | their terms; Google’s data processing terms for paid Gemini use |
We also disclose data when the law requires it, and to our tax and legal advisers, who are bound by confidentiality. If we sell or transfer our business, your data may pass to the successor; we would tell you in advance.
Sub-processors for your server data (Section 3.2) are Hetzner and, for our operations around it, Hostinger, Stripe and Brevo; Netlify if you ask us to publish a web page; and DataForSEO and Google when your AI Employee uses the tool account. The full list is in the DPA. We will tell you at least 30 days before adding or replacing one, and you may object; if we cannot resolve the objection you may cancel.
5.4 Anthropic — your own provider
Every prompt your AI Employee sends and every answer it receives goes to Anthropic’s servers in the United States, under your own Claude subscription and Anthropic’s Privacy Policy (anthropic.com/legal/privacy). Whether Anthropic may use your conversations and coding sessions to train its models depends on the model-improvement setting in your Claude account (claude.ai/settings/data-privacy-controls). Anthropic states that with the setting off it keeps this data for 30 days, and with it on for up to five years; content flagged for safety review or reported by you is used regardless of the setting. We recommend turning the setting off for business use. Anthropic’s telemetry from Claude Code does not include your prompts, code or file paths. We are not a party to Anthropic’s processing.
5.5 Discord — your channel to your AI Employee
You talk to your AI Employee through a Discord bot that we register for you under our Discord developer account. Your messages and its answers pass through Discord Inc.’s servers in the United States under Discord’s Privacy Policy (discord.com/privacy) and your own Discord account. The bot’s access token is stored on your server and — so that we can reconfigure or delete the bot — in our own secured credentials store. We do not read your Discord conversations. The bot answers only in the server or channel you set up and only to your Discord ID. When your subscription ends, we delete the bot.
6. International transfers
Your server and our own systems are in the European Union. Recipients in the United States are covered by the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (Stripe, Netlify), or are services you use under your own agreements (Anthropic, Discord). If you live in the United States: your server data stays in Germany; the prompts and answers your AI Employee exchanges with Claude are processed by Anthropic in the United States.
7. How long we keep data
| Data | Retention |
|---|---|
| Website server logs | Netlify’s retention period |
| Form data, newsletter | until you withdraw consent; at most 12 months after delivery for one-off requests |
| Account, orders, invoices, consent records | contract plus statutory retention (currently up to ten years); consent records at least 3 years or 1 year after termination |
| Support correspondence | 3 years after the last message |
| Your server | deleted within 14 days after the subscription ends, with proof (Terms, Section 7) |
| Our copy of your final export | 30 days after we send it to you |
| Tool-account metadata (Section 4.5) | 12 months |
| Discord bot and its token | deleted when your subscription ends |
| Setup link | stops working 48 hours after we send it; the stored copy is deleted when your subscription ends |
8. Cookies, tracking and “Do Not Track”
- Our English pages set no cookies and use no advertising or analytics tools. No third party collects information about your online activity over time and across websites through our English pages.
- If we ever add advertising measurement to our English pages, we will ask for your consent first, update this policy beforehand, and treat a Global Privacy Control (GPC) signal from your browser as an opt-out.
- Do Not Track. Because our English pages do not track you, there is nothing for a “Do Not Track” signal to switch off; we do not otherwise respond to it, because there is no common standard for it.
9. Your rights (everyone)
You can ask us to access, correct, delete or restrict your personal data, to hand it over in a portable format, and to stop processing based on our legitimate interests; you can withdraw any consent at any time. Email [email protected]; we answer within one month. You may also complain to a data-protection authority — for us that is the Hamburg Commissioner for Data Protection and Freedom of Information, datenschutz-hamburg.de — or to the authority where you live.
For data on your AI Employee’s server that belongs to your customers, staff or contacts, you are the controller; if one of them contacts us, we will refer them to you and help you respond under the DPA.
10. Additional information for residents of the United States
California Online Privacy Protection Act (CalOPPA). Categories of personal information we collect: identifiers (name, email address, Discord ID, IP address), commercial information (orders, payments, subscription status), internet activity (website logs), professional information (business name), and any content you choose to process on your server. The third parties with whom we share information are listed in Section 5. You may review and request changes to your personal information by emailing [email protected]. We will notify you of material changes to this policy as described in Section 12. The effective date is at the top of this page. How we respond to “Do Not Track” signals and whether third parties track you across sites: Section 8.
California Consumer Privacy Act (CCPA/CPRA). We do not currently meet the thresholds that make the CCPA apply (annual gross revenue above about US$26.6 million, personal information of 100,000 or more California consumers or households per year, or half our revenue from selling or sharing personal information). We nevertheless honour requests to know, delete and correct personal information and to opt out of any sharing for advertising, and we will not treat you differently for exercising these rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising. Should that ever change, we will ask for consent first and honour Global Privacy Control signals as an opt-out (Section 8).
Other states. We give residents of every state the same rights described in Section 9.
Age. The Service is for adults and businesses. We do not knowingly collect personal information from anyone under 18.
11. Security
All connections are encrypted (TLS for web and email, SSH for server administration). Your server’s firewall allows administrative access only from our network address; the service runs under its own user; credential files are readable only by their owner; secrets are stored with restricted permissions; setup links stop working once setup is completed, at the latest 48 hours after we send them, and are stored on your server only as a hash; sign-in codes are never logged. No system is perfectly secure. If a breach affects your personal data, we will inform you without undue delay, as the law requires.
12. Changes to this policy
We will post the new version here with a new effective date. If a change materially affects customers, we will email you at least 30 days before it takes effect.
13. Contact
Fabian Mahnke · c/o IP-Management #10868 · Ludwig-Erhard-Str. 18 · 20459 Hamburg · Germany · [email protected]
← Back to Your AI Employee