Skip to content
biwak

Start

Privacy policy

This English version is provided for your convenience. Only the German version is legally binding.

Version of 4 October 2026 · Controller: Hermann Hampel

This policy has two parts because they concern two different things. Part A describes what happens when you visit this website. Part B describes local data and the processing for model access, account and billing.

We collect your data exclusively from you. Art. 13 GDPR is therefore the relevant provision. Personal data is any information that can be related to you — on this website, that is essentially your IP address, what you write to us in an email and what you enter in the request form at the bottom of the page.

Service providers and their contracts

This website at a glance

The following overview is not a declaration of intent but the verified state of the source code. The details are set out in the numbered sections below.

Website & data processing
Cookies None Not even “technically necessary” ones.
Analytics, statistics, advertising Vercel Web Analytics Cookie-free page view statistics without an advertising profile, plus a count of clicks on “Download”; details in section 3.
Connections to third-party servers Vercel as host Delivery and Web Analytics; no maps or social networks.
Fonts Served locally No Google Fonts, no transfer of your IP address to third parties.
Form One, for requests Email address and your choice, sent to our own endpoint — no form service, see section 6.
Newsletters, promotional emails None A request is followed by a reply, nothing else.
Consent banner Not required There is nothing for which we would need to ask for your consent.
Storage in your browser Two places biwak.site.theme — only your choice of night or day view; and on /kontoauszug-umwandeln, a PDF you drop there before signing in, until you are signed in. See section 7.
Server log files At the host, according to its retention periods Generated for technical reasons when a page is accessed, see section 3.
Deletion periods in our database Automatic, every night Since 22 September 2026, see section 10.
Recipient Eleven, named individually With registered office and place of processing, see section 9.
Transfers to third countries Five recipients outside the EU Standard contractual clauses under Art. 46 GDPR; for GitHub and Switzerland, an adequacy decision under Art. 45. For all performance levels, Microsoft Azure in the EU Data Zone processes first; only if Azure declines does the task text go via PREM SA in Switzerland to computing partners in the EU, see section 14.
Profiling, automated decision-making Does not take place
Part A · This website

1 · Controller

The controller responsible for the processing of personal data on this website within the meaning of Art. 4(7) GDPR is:

Controller
Provider Hermann Hampel
Address Johanneskirchner Straße 101, 81927 München
Email kontakt@biwak.ai

The full provider information under § 5 DDG (German Digital Services Act) can be found in the legal notice.

2 · Data protection officer

We have not appointed a data protection officer, nor are we obliged to do so. The obligation to appoint one under § 38 BDSG (German Federal Data Protection Act) only applies if, as a rule, at least twenty persons are constantly engaged in the automated processing of personal data. We are not that large.

We therefore answer questions about data protection ourselves. Write to kontakt@biwak.ai. A person from the workshop will reply, not a form system.

3 · Server log files

When you access this website, your browser transmits technically necessary information. Our host records it in log files:

  • the address accessed and the amount of data transferred
  • the date and time of access
  • the referring address (referrer), if your browser sends it
  • browser type, browser version and operating system
  • Your IP address

Purpose: to deliver the page, keep operations stable and detect attacks. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and trouble-free operation of this website; without this data, a page cannot technically be delivered or protected against misuse. Storage period: These logs are generated at the host and deleted there according to its retention periods. We do not keep a copy of our own.

Language version. This website is available in German and in English. If you open a page from outside — via a search engine, a link or by typing in the address — our hosting provider derives the country the request comes from from your IP address. From Germany, Austria, Switzerland and Liechtenstein you see the German version, from all other countries the English one. The country is used only for this one redirect and is not stored; no cookie is set for it. You can switch to the other language at any time at the top right. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is to show you the page in a language you are likely to be able to read.

What we count from this. We want to know whether and how this site is used. For this purpose, we use Vercel Web Analytics. When a page is accessed, your browser loads a script from the same website address and transmits the page view to Vercel. The service does not use cookies and does not store any identifier in your browser. It records the path accessed, the time, the referring page, browser and device information and approximate location data. Visitors are distinguished only for the duration of one session, using a hash value derived from the incoming request; this session information is discarded after 24 hours. The information is used exclusively for aggregated visitor statistics; we do not create advertising or user profiles. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is to recognise whether this offering is being found and which pages are used. As no cookies are set and no information is stored in or read from your terminal equipment, no consent is required under § 25 TDDDG (German Telecommunications Digital Services Data Protection Act).

In addition, we may analyse the log files that exist anyway. Exactly four items of information per request are included in this analysis:

  • the path accessed, without anything after the question mark
  • the day of access
  • the response status
  • the host name of a referring page — never the full referrer

Your IP address, your browser type and the full referrer are not included in this analysis. They are not read in the process. The result is totals — “this many views of this page on this day” — from which no individual visit and no individual person can be reconstructed. No profile, no recognition and no visitor identifier is created. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is the technical and aggregated analysis of usage.

We do not combine this data with other sources, nor do we analyse it for advertising purposes. Any analysis beyond the totals mentioned takes place only for a specific reason, when there is a concrete suspicion of an attack or a malfunction.

Clicks on “Download”. If you download a version of Biwak, our server counts the click in our database in Frankfurt am Main (section 9): time, platform, file and target address, plus your IP address and your browser’s identifier. If you are signed in, your account ID and your email address are added. Purpose: to see how often each version is downloaded and to detect misuse, such as large numbers of automated requests. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is reliable and secure delivery. Storage period: The database automatically removes the IP address, browser identifier and email address after 30 days, and the entire entry after 180 days (section 10).

A note on honesty: the preview server we use for development does not log anything. As soon as the site is publicly accessible, the data mentioned above is generated at the host.

4 · Hosting and processing on our behalf

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. The host processes the data mentioned in section 3 exclusively on our behalf and in accordance with our instructions. The basis for this is a data processing agreement under Art. 28 GDPR.

Vercel delivers the site via a worldwide network of delivery nodes; requests from Germany are usually served from a European node. Because the company has its registered office in the United States, processing in a third country nevertheless cannot be ruled out. The basis for this is the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR, which form part of Vercel’s data processing agreement.

We operate the database behind the Biwak account and the relay through which model tasks run at Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Both are located in a project in Frankfurt am Main; processing takes place there. The browser workspace and the application from the version following 0.2.31 pin the relay to Frankfurt am Main; older versions of the application do not, in which case Supabase runs it in the region closest to the caller, which for calls from Germany is Frankfurt. Because the company has its registered office in Singapore, access from a third country nevertheless cannot be ruled out. The basis for this is the standard contractual clauses under Art. 46(2)(c) GDPR as part of Supabase’s data processing agreement.

5 · Encrypted transmission

This website is delivered exclusively via HTTPS. All traffic between your browser and the server is encrypted with TLS. You can tell that the connection is secure by the padlock in your browser’s address bar.

6 · Requests and contact

At the bottom of the home page there is a form you can use to book a demo or have a link sent to your computer. It is sent to an endpoint at the same address as this page. No form service is involved — nothing is reported to a third party along the way, and the form does not set any cookies.

What you enter is transmitted, and apart from that only two things:

  • your email address — without it we cannot reply
  • your choice: demo or link to your computer
  • which button on the page led you to the form
  • the time of submission

We store this information in our database in Frankfurt (section 4) and send a notification of it to our mailbox. To send this notification and the sign-in codes, we use Resend — the provider is Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. Emails are sent via a node in Ireland; the email service’s account data is stored in the United States. Further details in section 9. Your IP address is not stored in the process. It is used for a counter in working memory that prevents a script from flooding the form, and disappears when the time window ends.

The option of writing an ordinary email remains available alongside this: every contact link on this website is a simple mailto: link that opens your own email program.

Purpose: to process and answer your enquiry or request. Legal basis: Art. 6(1)(b) GDPR, insofar as your enquiry serves the initiation or performance of a contract — for example a demo or a quote. Otherwise Art. 6(1)(f) GDPR, with our legitimate interest in answering enquiries addressed to us.

Your message is processed by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin; we have a data processing agreement with this provider under Art. 28 GDPR.

Deletion: We delete your enquiry as soon as it has been dealt with, provided no statutory retention obligation prevents this. We retain business correspondence for six or ten years respectively under § 257 HGB (German Commercial Code) and § 147 AO (German Fiscal Code); during this time, the processing of these messages is restricted and they are kept only for evidentiary purposes.

Cancel and withdraw without signing in

Via Cancel contracts here and Withdraw from contract, we accept your declaration without you having to sign in. The following are transmitted: the type of declaration, your name, your email address, the contract details, the desired date and, in the case of an extraordinary cancellation, the reason. If the address belongs to a Biwak account with an active subscription, we set the subscription at our payment service provider Stripe to “ends at the end of the paid month”. The confirmation with date and time is sent via Resend to the address provided, with a copy to our mailbox. We do not create a separate record in our database for this. We use your IP address only in truncated form for a counter that protects the form against misuse; the counter expires after one hour.

Legal basis: Art. 6(1)(c) GDPR in conjunction with §§ 312k and 356a BGB (German Civil Code), and Art. 6(1)(b) GDPR. Retention: as for business correspondence, six years under § 257 HGB.

Note: An ordinary, unencrypted email can, in principle, be read by others on its way. Please do not send us confidential documents by email unsolicited. For confidential matters, we will agree another channel with you.

7 · Storage on your terminal equipment

This website does not set any cookies. For the statistics described in section 3, it integrates Vercel Web Analytics; there is no advertising and no profile-building tracking.

Two things are stored locally in your browser. First: if you switch between night and day view, your browser remembers your choice under the key biwak.site.theme in local storage (localStorage). The value is nacht (night) or tag (day) — nothing else. It is not transmitted to us and contains no identifier by which you could be recognised. It remains stored until you delete the website data in your browser.

This storage only takes place when you operate the switch, and it is strictly necessary to provide the function you have expressly requested. It is therefore exempt from consent under § 25(2) no. 2 TDDDG. For this reason, a consent banner is not required — and we deliberately do not use one. A banner without any processing that requires consent would feign a choice that does not exist here.

Second, only on the Convert bank statements page: if you drop a file there or choose the sample statement before you are signed in, your browser keeps the file (or just the note “sample statement”) in its database (IndexedDB, name biwak-kontoauszug) so that it can be attached to your task after you sign in. Until then, nothing is transmitted to us. The entry is deleted as soon as it has been handed over to your task, and when you leave the page without going on to sign in. The page no longer uses an entry that is older than one hour and deletes it the next time it is opened. You can remove the entry on the page at any time or delete it together with your browser’s website data. This storage, too, only happens in response to your action and is strictly necessary for the function you have requested (§ 25(2) no. 2 TDDDG).

8 · Fonts and third-party content

The fonts used — Archivo Expanded, IBM Plex Sans and IBM Plex Mono — are stored on the same server as this website and are delivered from there. There is no connection to Google Fonts or any other third-party font service. Your IP address is not transmitted to any third party in the process.

The same applies to everything else: no content delivery network, no embedded videos, no maps, no social media buttons, no external scripts. The site loads files exclusively from its own address. Images and graphics are, for the most part, embedded directly in the page source code.

Two links lead to third-party services. “Book a meeting” opens the appointment booking of Calendly LLC, 271 17th St NW, Ste 1000, Atlanta, GA 30363, USA. Calendly only receives your details if you book an appointment there, and then directly from you and under its own responsibility; Calendly’s privacy policy applies. The installation files behind “Download” are hosted on GitHub (section 9). As long as you do not click either of these links, neither service learns of your visit.

9 · Recipients and transfers to third countries

Art. 13 GDPR would allow us to name only the categories of recipients here instead of the recipients themselves — “hosting service provider”, “payment service provider”. We name them, together with their registered office and place of processing, and place their contracts alongside: you can open or download every file with one click, in the version we rely on. Anyone who needs to check where something goes can do nothing with a category.

See your tasks

Account, payments, email

Only if you choose it

  • GitHub Installation files worldwide

    GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA

    Hosts the installation files and updates. Your computer downloads directly from there.

    Sees
    Your IP address when downloading
    Location
    worldwide
    Basis
    EU-U.S. Data Privacy Framework
    Contract
    GitHub’s own responsibility; no DPA with Biwak needed.
    At the provider
  • Google Sign-in with Google Ireland

    Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

    Only if you sign in with Google. Passkey or email code work without Google.

    Sees
    That you are signing in to Biwak
    Location
    at Google
    Basis
    Google’s own responsibility
    Contract
    No DPA: Google acts as an independent controller here.
    At the provider

Prepared, not in use

  • Amazon Web Services Language models (Bedrock) EU

    Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg

    Amazon Bedrock in the EU, as a possible additional model route.

    Sees
    Nothing. No tasks run through it.
    Location
    EU regions
    Basis
    Standard contractual clauses 2021
    Contract
    Applies via the AWS Customer Agreement, without a separate signature.
    At the provider
  • Google Cloud Language models (Vertex) EU

    Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland

    Vertex in the EU multi-region, as a possible additional model route.

    Sees
    Nothing. No tasks run through it.
    Location
    EU multi-region
    Basis
    Standard contractual clauses 2021
    Contract
    Applies via the Google Cloud agreements, without a separate signature.
    At the provider
Checksums (SHA-256) of all files

Each file is the version we rely on. The checksum shows that it is unchanged; each company’s original is linked under “At the provider”.

Microsoft Azure, Data Protection Addendum (DPA), German versionfc4f13ed128ba3b992d85b0436ef420c4ed6c7ad6fca026af38212a53cb194c4
Prem AI, API privacy policy, with sub-processors816191bf7ad6a88dad251b3ca3c2d6a7bb22dea3a260cd25c82ef32b25417865
Prem AI, API terms of use25800cf7232a2de3ad5276da6467739481caa94ee058ed10c4324d7f634312e9
Scaleway, data processing agreement (DPA)f9155cf31e57385ca2f98d69e10757fca5926aa200f606423dd60b8e01e61de9
Scaleway, technical and organisational measures340fde140a1f27a0de0ea84e721c1590b5b2abea842235b5ecfd84535c9d19b5
Scaleway, specific terms for AI servicesbe20e4112ff6f95688f5b27202714a64fa0c79ea852781f49e7f51812b7e2084
Scaleway, ISO/IEC 27001:2022 certificate (BSI)54c9a8a6df9af9c5454b9a9a339dfc098354461970dd0e5221529d5ad6b80b81
Scaleway, terms of usee64726b64f95bd9d5231cd6dde244f326fc48932155826247931a0310a08e28b
Supabase, data processing agreement (DPA)3a77206d6cb53ce05ee076d3d488fbca85a0ef5b9c6222e05d9a1d82576a4c1b
Supabase, list of sub-processorse85324d3d26fd754755a8cbcf8ddf3f1e8b04f164eb4959a63e53f6aa3f5fa6d
Supabase, Transfer Impact Assessment1b71ea56e25b67cbfe0ac78eb5bc974faa875aae7ac5b95c25fc30b9227b90a3
Supabase, terms of use79c37cd2d2c0227d0bb6f519791da09133075ccd7ca78a8cca25c686d8b83b0f
Vercel, data processing agreement (DPA)6309c941abdaefa19a758d5acc0bd4b529410e25f70920d719a2bb5b8e61a23f
Vercel, list of sub-processors99347c620c138d60526e700ef3bdae053fd90005fb8fafb65e07249db1948f51
Vercel, terms of usee535bd3093daf1ae4ef13416c2c41e29b64e47333bf78a93d4861f2dd3cd440e
Stripe, data processing agreement (DPA)640e1ab01d2e73718dd6966bfd9a1fdec07bae2d2305927ed0ece09173347e60
Stripe, Data Transfer Addendum (DTA)a50615f8697b13a130db51e24cd267f19b0f30fb595f4a73a306064c11654368
Stripe, list of sub-processorse0135f1c621b5ac1e90a501b4f165a4d8755514a316f5d735d57230e075b3ae5
Resend, data processing agreement (DPA)37ff5dadd45168273d5a7cdf2e85d23120bdb0dc896b93b5a145ed81afbc5a1a
Resend, list of sub-processors063cea8b113124d3c1e58a60e31b30082489965573258d7d8aa0207ca8dd3c4c
Resend, terms of use58dece26ad394624af045ee2be4ec135486d20291d6baac03ec99fadf3d68f05
Linkup, terms of use (Art. 10: data processing on our behalf)b9747365d9f03682ab198b539c5ba8578f0e7f12095c89ef93db7c13da90bfed
Linkup, data processing: regions and storagea3e270f9ba3ce86282de07e636ad98d4eee9ebd222510ba1d49e550af0881e9d
Linkup, privacy policy1b247a0ce50ee34d9ac49522db1bfecccf089051b49149e3dd710dda95f5432a
STRATO, data processing agreement with sub-processorsbfd7785a8b09628b23452872ba7a3a39e7d6eef244c395b82f28f9a62bb8bfbd
GitHub, privacy policy923f3561bb9314b224b77b9d9f30900297d5a668f54d86aaaef19b4c3e8d70c3
Amazon Web Services, data processing agreement (DPA)15f95fd3f83f4880e538ec08867b58f4648bf48fb7a0f8af7d0f79c94f456c19
Google Cloud, Cloud Data Processing Addendum (DPA)df2ef60e627bcef18ad9bb2344e2a7b5a75a698a365742fad79c57ab47f15e98

Beyond this, we do not pass on your data. We do not sell data, we do not rent out addresses and we do not transmit anything for advertising purposes. Data is passed on to authorities only insofar as we are legally obliged to do so.

Five recipients have their registered office outside the European Union: Vercel, Resend and GitHub in the United States, Supabase in Singapore and PREM SA in Switzerland. With Vercel, Resend and Supabase, processing in a third country is therefore possible; the safeguard for this is the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR as part of the respective data processing agreement. GitHub only sees who downloads an installation file or an update, and bases the transfer on the EU-U.S. Data Privacy Framework. Linkup has its registered office in France, but according to its own documentation it also processes search terms in the USA, Canada or the Asia-Pacific region, depending on load; we have no safeguard under Art. 46 GDPR for this. For Switzerland and the United Kingdom, the European Commission has found an adequate level of data protection (Art. 45 GDPR). For all performance levels, Microsoft Azure in the EU Data Zone processes first; the task text then goes via Frankfurt to Microsoft Ireland. If Azure declines a task or the application retries it, it goes to PREM SA in Switzerland and from there to computing partners in the EU and the United Kingdom (section 14). With the older Scaleway models and the fallback for images, it does not leave the European Union; it then goes via Frankfurt to Paris. We do not transmit anything to an international organisation. Should anything change regarding the recipients, it will be stated here.

10 · Storage periods at a glance

Since 22 September 2026, our database has enforced these periods itself every night — nobody has to remember to do so:

  • Clicks on “Download” (section 3): IP address, browser identifier and email address after 30 days, the entire entry after 180 days
  • Information on model requests (section 14): IP address and browser identifier after 30 days — at present, we do not record either of them at all

For everything else, the following applies:

  • Server log files: at the host, according to its deletion periods
  • Email enquiries and requests: until dealt with; then deletion, unless a statutory retention period under § 257 HGB or § 147 AO applies (six or ten years respectively)
  • The key biwak.site.theme is stored exclusively in your browser and is subject solely to your control
  • A file dropped on /kontoauszug-umwandeln before signing in: in your browser, until it is handed over to your task or until you leave the page without signing in, for at most one hour (section 7)
  • An error report you send from the application: thirty days from receipt, after which the service no longer releases it and deletes it at the next clean-up; earlier at your request (section 15)
  • A report you send about an AI response: likewise thirty days from receipt, earlier at your request (section 15)
  • For businesses covered by our data processing agreement: we delete conversations and files in the browser workspace, team data, error reports, notifications and requests for help, including their copies in the mailbox, no later than 30 days after the end of the contract (Part C, no. 9 of the agreement)

Where a fixed period cannot meaningfully be specified, the following applies: we delete data as soon as the purpose no longer applies and no statutory obligation prevents deletion.

11 · Obligation to provide your data

You are under no statutory or contractual obligation to provide us with personal data. The information in the log files arises for technical reasons when the page is accessed; without it, delivery is not possible. Everything you tell us in an email, you tell us voluntarily — without this information, however, we cannot answer your enquiry. You will suffer no other disadvantages.

12 · Automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. We do not create user profiles and do not evaluate you automatically.

Part B · The application on your computer

13 · Application and Biwak account

The information above describes the website. The following sections distinguish between local data in the application and the processing for Biwak model access.

Biwak runs tools on your computer and stores conversations and checkpoints there. For model tasks, you sign in with your Biwak account. Biwak processes sign-in and usage data for access, allowances, credit balances and billing. Deleting local files does not delete this account data.

Local file processing and server-side model access are separate processing operations. The necessary agreements and information on the service providers involved must be checked on the basis of your specific use.

If you use Biwak as a business, we process the content of your tasks on your behalf. Our data processing agreement (in German) under Art. 28 GDPR applies to this, automatically with the Biwak subscription and without a signature.

Teams

If several people work as a team from a shared allowance, all members of the team can see each other’s names and email addresses. The owner of the team (and an administrator, where there is one) can also see how many credits each person has used in the current billing month — never their tasks, files or conversations. Team invitations are sent via the same email service as the sign-in codes (Resend, section 9) to the address entered by the person issuing the invitation; they name that person, the team and a link that is valid for 14 days.

Browser workspace

If you use Biwak at biwak.ai/chat, your tasks, the model’s responses and the work progress are stored in our database in Frankfurt am Main (section 4) — so that a task continues to run even if you close the window. The agent itself works on our server at Scaleway in Paris, where the files of your workspace are also stored (section 9).

Who can see this content. Only the controller, Hermann Hampel, via a separate administration view that requires its own password and a passkey. Nobody else has this access. The view is read-only; it changes nothing and never acts on your behalf. Content is viewed only for a stated reason:

  • you have asked us for help (Art. 6(1)(b) GDPR),
  • we are looking for an error that affects your task (Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR),
  • there are indications of misuse or a security incident (Art. 6(1)(f) GDPR; our legitimate interest is secure operation),
  • as long as the workspace is a preview feature: checking whether responses and tools work correctly (Art. 6(1)(f) GDPR; our legitimate interest is a product that does what it promises). You can object to this check at any time (section 16). It does not take place for accounts that belong to an organisation — there, we only view content for one of the three other reasons. Nor does it take place for businesses covered by our data processing agreement.

Each viewing is logged with the time, the reason and the conversation concerned before any content is displayed; the log contains no content and is deleted after twelve months. We do not use content to train models or for advertising, and we do not pass it on. If you delete a conversation in the workspace, its content is also gone from the administration view.

Conversations you hold in the application on your computer do not reach us — except in an error report or a report that you send yourself (section 15). From the application, we only see usage data: when, with which model and to what extent a task ran, and whether it came from the browser or from the application for macOS, Windows or Linux.

14 · Requests to a language model

A personal concern. As the provider of Biwak, data security matters to me personally. That is why we explain openly which content is processed for your task, which providers are involved and which commitments and exceptions apply. For us, this transparency is the foundation of your trust. — Hermann Hampel

Model tasks are sent via the signed-in Biwak access to the model provider in use. Biwak provides this access for your account and manages the access credentials on the server side.

In the process, your input, the required conversation context and the file contents used are transmitted. Biwak assigns the actual usage to your account and counts it against the allowance of your plan; new accounts receive a one-off allocation of trial credits.

The route in detail. Your task goes from your computer to our relay at Supabase in Frankfurt am Main and from there to the language model. Three providers are connected. Since 4 October 2026, all five performance levels of the slider have been processed first at Microsoft Azure; if Azure declines a task, the same task is processed via Prem AI, and if the application retries a task, every second attempt starts there. As long as our quota at Azure is small, Prem therefore processes the larger share of tasks. Scaleway processes tasks from older versions of the application (up to 0.2.24), a previously saved model choice that the slider shows as “Custom”, and, as a fallback, images that neither Azure nor Prem could read. We name the stations here because “via our access” does not answer the question your IT department asks.

  • Microsoft Azure (contractual partner: Microsoft Ireland Operations Limited) processes first, using the “Data Zone Standard” deployment type for the EU: Microsoft processes inputs and responses only within the EU Data Zone, which Microsoft defines according to its EU Data Boundary; according to Microsoft, this may include EFTA states such as Norway and Switzerland in addition to the member states. Stored data remains in Germany, where our Azure resource is located. There, texts are processed by the DeepSeek V4 Flash model, and images are read by GPT-5.4 mini.
  • If Azure declines a task before a response begins — for example because the quota is exhausted — the same task goes to PREM SA in Lugano, Switzerland. Prem does not process tasks itself but forwards them to partners; according to Prem’s privacy policy for the API, these are Nebius (EU and United Kingdom) and TensorX (Ireland). There, images are read by the DeepSeek V4.1 Flash model. Prem’s access runs via the Cloudflare network. Switzerland and the United Kingdom are not part of the European Union, but the European Commission has certified that both have an adequate level of data protection (Art. 45 GDPR).
  • The older models without a prefix are processed at Scaleway SAS in Paris, as is the fallback for images: if the image models at Azure and Prem fail before a response begins, the next attempt reads the image with the Qwen3.8 27B model at Scaleway. Both stations are located in the European Union; the task text does not leave it.

Web search and web pages. If a task needs information from the internet, the browser workspace sends the search terms to Linkup (registered office in France; according to Linkup, also processed in the USA, Canada or the Asia-Pacific region depending on load, section 9); your files are not included. In the application on your computer, the agent only searches if a search service has been set up there. If the agent opens a web page, it requests it directly — in the browser from our server in Paris, in the application from your computer; the page accessed then sees this address, as with any ordinary page request. You can switch off both in the settings.

What happens to the task text. At Microsoft Azure, Microsoft’s data processing agreement (Products and Services Data Protection Addendum) applies. According to Microsoft’s documentation, inputs and responses are not accessible to other customers or to the model manufacturers, including OpenAI and DeepSeek, and are not used for training; the models themselves do not store anything. Microsoft itself names one exception: to detect abuse, requests are checked automatically, and conspicuous requests may be stored and reviewed by humans; this storage is located in the geography of our resource, i.e. in Germany. Microsoft grants an exemption from this only upon a separate application, which we have not yet submitted.

What Microsoft’s data processing agreement commits to. We have read the version of 22 May 2026 and filed it with a checksum. Under it, Microsoft processes your data only to provide the service in accordance with our instructions, and not for profiling, advertising or market research. Data is disclosed only where required by law: Microsoft refers authorities to us, notifies us unless this is prohibited, challenges orders that violate the law of the EU or of a member state, and discloses no more than the minimum necessary; nobody receives blanket access or the platform’s keys. Microsoft notifies us of security incidents without undue delay. Its staff are bound by confidentiality. Microsoft announces new subprocessors in advance, and those for AI features 30 days in advance. Under the agreement, the security measures comply with ISO/IEC 27001, 27002 and 27018 and are audited annually by independent auditors. The agreement permits transfers to the USA (standard contractual clauses, Data Privacy Framework); for EU Data Boundary services, Microsoft commits to storage and processing in the EU and the EFTA states, and according to Microsoft our deployment type follows this boundary. What the agreement does not contain is an obligation under Section 203 of the German Criminal Code (StGB); we do not have a separate addendum for professionals bound by confidentiality with Microsoft (section 13).

When Prem processes a task, Prem’s “Zero Data Retention” mode applies: according to Prem’s documentation, the partners are contractually obliged not to store or log inputs and responses or use them for training. Prem itself states that this commitment is based on contracts and operating procedures, not on technical safeguards such as an encrypted execution environment, and recommends its encrypted mode for personal data and legal documents, which Biwak does not currently use. We have negotiated a data processing agreement with Prem but not yet signed it. The interface no longer offers a choice between providers. Before confidential tasks, please therefore check the actual data flows and the necessary contractual documents; for professionals bound by confidentiality, section 13 also applies.

For the older models at Scaleway and the fallback for images, the following applies: in the data privacy policy for its Generative APIs (as of 3 October 2025), Scaleway commits that inputs and responses are by default not stored (“Zero Data Retention”), not read, not analysed and not used to train models; the model manufacturers have no access to them. Scaleway itself names one exception: if a request triggers a server error, its full content may be stored for up to two weeks and read for troubleshooting. These commitments are set out in the provider’s documentation, not in its data processing agreement; we do not yet have written confirmation of them as part of the contract. We keep the retrieved version with a checksum.

What Scaleway can demonstrate. Scaleway operates an information security management system certified to ISO/IEC 27001:2022. The certificate comes from the British Standards Institution — not from the German Federal Office for Information Security. It was issued on 6 December 2023 and is valid until 5 December 2026. Its scope reads “Providing the technical infrastructure platform to support the Scaleway’s Public Cloud products” and lists the facilities individually, including the Paris data centres. What is certified is therefore the operator’s management system, explicitly not an individual service and not Biwak. We keep the retrieved certificate with a checksum; we do not state its registration number here because the certificate itself prohibits the number and certification mark from being used in documents about products or services. For an audit, we will give you the number on request. We have no comparable information for Prem AI and its partners. For Microsoft Azure, the audit obligation is set out in the data processing agreement (see above); we have not yet filed the certificates themselves.

15 · Error report from the application

The application does not report anything to us of its own accord: no telemetry, no usage statistics, no crash report in the background. There is, however, one route that you trigger. If something gets stuck, you choose “Send report” or “Cancel” right at the start. Only with “Send report” does Biwak create the full technical error report and transmit it. With “Cancel”, no report is created and nothing is transferred from the device.

What it contains. Your own description; the Biwak version; information about this computer (operating system, architecture, computer name, user folder, time zone, language); your local configuration and the permissions granted; the most recently logged errors; the log files from ~/.biwak/logs; and the complete transcript of the open conversation — your messages, the model’s responses, every tool call with its result. Access credentials appear in it masked, not in plain text. The report is sent as a single text document with a checksum; the checksum covers exactly the content that reaches the account service.

What happens to it. The report goes to our account service and is assigned there to your account and the sending device; it is stored in the storage of our Supabase project in Frankfurt am Main. After acceptance, the account service sends the complete report via Resend to kontakt@biwak.ai. You receive a report number and the deletion date in return. We use the report exclusively to deal with the reported problem — not for statistics, not for product improvement, not for training models.

How long. The thirty days from receipt refer to storage in the account service; after that, the service no longer releases the report and deletes it at the next clean-up, which currently runs when a new report comes in. Before then, you can request deletion at any time and without giving reasons — the report number in a message to kontakt@biwak.ai is sufficient. The information on business correspondence in section 6 applies to the retention of the forwarded email in the mailbox. For businesses covered by our data processing agreement, we process reports and notifications as a processor under that agreement instead of under this section: we then delete the copy in the mailbox manually once the matter has been dealt with, no later than 30 days afterwards; only what must be retained as a commercial or business letter is kept (Annex II and Part C, no. 9 of the agreement).

Legal basis. Art. 6(1)(b) GDPR, insofar as dealing with your problem is part of performing the contract for the use of Biwak; otherwise Art. 6(1)(f) GDPR — our legitimate interest in finding and fixing a reported error. You are not obliged to send a report; with “Cancel”, no report is created.

▲ Still open: the record of processing activities. A record under Art. 30 GDPR does not yet exist for this processing. Until it does, the practical rule for you is: only send a report if the transcript of the conversation contains no content that your organisation is not allowed to disclose — so for professionals bound by confidentiality, if in doubt, do not send it. In that case, cancel and write to us with what you consider shareable.

Who opens the report. Only the controller, Hermann Hampel — as an email in the mailbox and in the administration view from section 13, there only to deal with the problem, at your request or in the event of danger, and never for quality checks. Every viewing there is logged.

Reporting an AI response

Below every response, next to “Copy”, there is an exclamation mark. Use it to report a response that you consider offensive, dangerous or incorrect. Here too, nothing happens in the background: only with “Report” is anything sent, and with “Cancel” nothing is.

What it contains. The reported response verbatim, the reason chosen and your comment if you write one; plus the Biwak version, the operating system, the model and the time of the response. In addition, the complete transcript of the conversation from which the response originates is always included — as with the error report, with all messages, responses and tool calls — because only the transcript shows how the response came about. The dialog announces this in its first line. Log files, settings, computer name and user folder are not included.

What happens to it. The report takes the same route as an error report: to our account service, into storage in Frankfurt am Main, and via Resend to kontakt@biwak.ai. You receive a number and the deletion date in return; the same thirty days, the same right to request deletion and the same circle of people with access apply as above. We use the report to check the response and to remedy the issue — for example in the instructions for the model or in the choice of model — not for statistics, not for advertising and not for training models. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in detecting and stopping inappropriate output. The Microsoft Store explicitly requires this reporting route for applications with generative AI.

Without a direct route. In the browser workspace and when you are not signed in, the report is not sent directly. Biwak then copies its text to the clipboard and opens your email program; you decide what you send, and section 6 applies to the message.

If you send us something yourself instead. If you send an excerpt, a screenshot or a log file by email, you alone decide what it contains; section 6 of this policy applies to this message. Please check beforehand whether it contains personal data of third parties, and redact anything that is not necessary.

Your rights

16 · Your rights in detail

You have the following rights against us:

  • Access (Art. 15 GDPR): you can find out whether and which data we process about you and request a copy of it.
  • Rectification (Art. 16 GDPR): we must correct inaccurate data and complete incomplete data.
  • Erasure (Art. 17 GDPR): you can request erasure, provided no statutory retention obligation prevents it.
  • Restriction of processing (Art. 18 GDPR): instead of deleting data, we can also merely store it.
  • Data portability (Art. 20 GDPR): you receive data you have provided to us in a common, machine-readable format.
  • Objection (Art. 21 GDPR): see the separately highlighted notice immediately below.

A right to withdraw consent under Art. 7(3) GDPR has no application here: we do not base any processing on consent, so there is nothing to withdraw.

An informal message to kontakt@biwak.ai is sufficient to exercise these rights. Exercising them is free of charge for you. We respond within one month; if, in exceptional cases, we cannot manage this in time, we will tell you and give our reasons.

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out on the basis of Art. 6(1)(f) GDPR. On this website, this concerns the server log files (section 3) and the answering of enquiries insofar as they do not serve the initiation of a contract (section 6); in the browser workspace, it concerns the check as to whether responses work correctly (section 13).

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

You can send your objection informally to kontakt@biwak.ai. A justification relating to your situation helps us in our assessment, but it is not a prerequisite for us to deal with your objection.

We occasionally write by letter to companies for which Biwak might be a good fit (direct marketing, legitimate interest under Art. 6(1)(f) GDPR). For this purpose, we use the company name and address from public sources, usually the company’s website, and the name of a person only from a source that the person has published themselves, such as a team page; the letter states this source. This information is stored in our database in Frankfurt am Main (section 4). We delete names and addresses after six months without contact.

You can object to such a letter at any time without giving reasons (Art. 21(2) GDPR), informally to kontakt@biwak.ai. You will then receive no more post from us; to ensure that this remains the case, we keep the company name on a do-not-contact list.

17 · Complaint to a supervisory authority

Without prejudice to any other remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority — in particular in the member state of your place of residence, your place of work or the place of the alleged infringement.

The authority responsible for us is:

Bavarian State Office for Data Protection Supervision („Bayerisches Landesamt für Datenschutzaufsicht“, BayLDA)
Promenade 18, 91522 Ansbach

We would rather receive a direct message than a complaint — but the route to the authority is always open to you, and you do not have to contact us first.

18 · Changes to this policy

We adapt this policy when the legal situation changes or when we change something on the website that affects processing — for example when changing host. The version published here applies in each case. We record significant changes in the change log so that you can see what has changed and when.

This version as of: 4 October 2026