Platform

Products

Private AI infrastructure — from compute to agents.

Target groups

Use Cases

For enterprise, SMBs, and individual developers.

Knowledge & Support

Resources

Everything you need to succeed with Mycelis.

Legal

Privacy Policy

Last updated: March 2025

§ 1 Controller

The controller within the meaning of the General Data Protection Regulation (GDPR), other national data protection laws, and other data protection provisions is:

Mycelis GmbH (i.G.)
Sample Street 1
10115 Berlin
Germany

Email: privacy@mycelis.io
Web: mycelis.io

§ 2 Data Collected

We process the following personal data:

  • Account data: Name, email address, password (hashed), and workspace name during registration.
  • Usage data: API requests (anonymized volume, timestamp, deployment ID), token consumption for billing.
  • Technical data: IP address, browser type, operating system, referrer URL (anonymized after 24h).
  • Payment data: Processed exclusively via our payment provider (Stripe). We do not store full card details.
  • Uploaded documents: Knowledge base files are stored encrypted and processed only to create embeddings.

§ 3 Purpose of Processing

We process personal data for the following purposes:

  • Provision and operation of the platform (deployments, API gateway, dashboard)
  • Billing and invoicing (usage-based according to token consumption)
  • Authentication and access control
  • Security and abuse prevention
  • Product improvement based on anonymized usage statistics
  • Transactional emails (registration confirmation, invoices, critical system notifications)

§ 4 Legal Basis

Processing is carried out based on the following legal bases pursuant to Art. 6 GDPR:

  • Art. 6(1)(b) GDPR Contract performance: operation of the platform and billing.
  • Art. 6(1)(c) GDPR Legal obligation: retention of invoice data (§ 257 HGB, § 147 AO).
  • Art. 6(1)(f) GDPR Legitimate interests: security, abuse prevention, anonymized usage analysis.
  • Art. 6(1)(a) GDPR Consent: marketing emails (where explicitly consented).

§ 5 Cookies and Tracking

We use only technically necessary cookies:

  • Session cookie: Used for authentication in the dashboard. Deleted on logout.
  • Theme cookie: Stores the color scheme preference (light/dark). 365-day lifetime.

We do not use tracking pixels, social media plugins, or advertising cookies. No sharing with third-party analytics services.

§ 6 Your Rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You can request a copy of all data stored about you.
  • Right to rectification (Art. 16 GDPR): Incorrect data can be corrected at any time.
  • Right to erasure (Art. 17 GDPR): Deletion of account and all personal data on request — within 30 days.
  • Right to restriction (Art. 18 GDPR): Restrict processing instead of complete deletion.
  • Right to object (Art. 21 GDPR): Objection to processing based on legitimate interests.
  • Data portability (Art. 20 GDPR): Export your data in a machine-readable format (JSON).

To exercise your rights, contact: privacy@mycelis.io

§ 7 Third Parties & Data Transfers

We use the following service providers that process personal data on our behalf:

RunPod
GPU infrastructure for model deployments · USA / EU
Data processing agreement (Art. 28 GDPR), SCCs
Stripe
Payment processing · USA / EU
Data processing agreement (Art. 28 GDPR), SCCs
Hetzner
Server infrastructure for core services · Germany (EU)
Data processing agreement (Art. 28 GDPR)

No data is shared with third parties for advertising purposes.

§ 8 Data Security

All connections are TLS encrypted (TLS 1.3). Passwords are hashed and salted with bcrypt. API keys are stored only in hashed form. Knowledge base documents are encrypted at rest (AES-256). We conduct regular security audits.

§ 9 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent supervisory authority for Berlin is the Berlin Commissioner for Data Protection and Freedom of Information.

For questions or concerns regarding data protection: privacy@mycelis.io