EN: Privacy Policy
Version dated 10 September 2026.
1. Who Is Responsible For Processing
A-Z Geschäftsbesorgungs UG (haftungsbeschränkt), Amtsgericht Berlin (Charlottenburg), HRB 239083, Wilhelm-von-Siemens-Straße 16-18, 12277 Berlin, Germany, represented by Managing Director Oliver Sauereßig, is the Provider of Octodus and the controller of personal data for the processing purposes it determines in supplying its Service. Email: labs@octodus.com.
This Policy applies to the octodus.com website and to the web dashboard, bot, spaces and integration features supplied under the Octodus Terms. Reading a translation of this Policy does not change the Provider or the allocation of duties described here.
Where an organisation submits data about its staff, clients or other people to have the Service carry out its instructions, that organisation determines the lawful purposes for such submission and processing. The Provider's duties when processing on that organisation's behalf are set by applicable law and any required data-processing agreement. This Policy does not replace such an agreement and does not relieve the Provider of its own duties.
2. What Data This Policy Covers
The categories processed depend on the features you use and the content of your task. They may include:
- Account and connection data: name, contact details and identifiers obtained from you or your chosen sign-in service; identifiers for users, chats and spaces, and records of membership and permissions in a team.
- Content of your work: messages, tasks, links, uploaded documents and other files, images, audio and video, results and intermediate materials, and logs of the operations performed. If you submit voice or media, processing may include converting it to text or another format to carry out the task.
- Project context and memory: information, conclusions, instructions and materials retained to continue the work. Memory may contain information drawn from earlier messages and files, not only their original copies.
- Integration data: information available through a connection you authorised, connection parameters, and any tokens, keys or other access credentials you supply. This content may include information about third parties where it appears in materials you submit or in a connected system.
- Order and billing data: details of the customer and payer, invoicing details, payments received and confirmations, energy consumption and top-ups, and billing-related correspondence. This does not mean the Service receives every field entered directly into a third-party payment provider's own form.
- Technical data: IP address, browser and device information, timestamps, actions on the website, cookies and local settings where used, task status, consumption volume, error and security-event records.
- Support requests and any materials you supply to help resolve them.
Do not submit personal data, passwords or secrets beyond what a task requires. Special categories of data, including health data, biometric data used to identify a person, and information protected as a legally recognised secret, must not be submitted unless the necessary legal and technical conditions are in place. The mere presence of a file-upload or integration feature in the interface does not itself confirm suitability for such data.
3. Sources, Purposes And Legal Bases
Data comes from you, authorised members of your space, your chosen sign-in service and connected systems; technical data is generated through your use of the Service. Whether processing is necessary is assessed against the specific purpose:
- Creating and maintaining an account, granting access to a space, carrying out tasks, retaining the context needed for them, and delivering results: performance of the contract with the data subject; processing data about other people requires its own appropriate basis and, where required, a processing instruction.
- Handling orders, and recording payments, consumption and required documents: performance of the contract and compliance with statutory obligations.
- Handling support requests, correcting errors and keeping the Service operational: performance of the contract, compliance with law, and, where permitted, the legitimate interests of the Provider, balanced against your rights.
- Preventing unauthorised access and misuse, and resolving disputes: statutory obligations and permissible legitimate-interest bases for protecting rights.
- Analysing use of the website: evaluating which pages and interface elements are used, subject to the applicable analytics and consent requirements described in Section 10.
Where a purpose requires consent, that consent must be specific and obtained separately from acceptance of other documents. Reading this Policy, accepting the Terms, or staying silent does not substitute for required consent. The absence of data that is objectively necessary for a feature, or required by law, may make that feature unavailable; it does not justify requesting excessive data.
Data is not sold to third parties. Using content for advertising, a public portfolio, or model training is not authorised merely by accepting the Terms or reading this Policy.
4. AI, Tools And Training
To respond to you and carry out a task, the Service uses AI computation and tools, including external services. They may receive the request, the necessary parts of history and memory, files or excerpts of files, results of earlier steps, and technical parameters. A multi-step task may require several calls, including repeat calls and calls to different providers. The license for a given model and the party actually processing a request are not always the same entity.
Carrying out a request, storage, technical security review, quality evaluation and model training are distinct kinds of use. This Policy does not grant a general permission to train models on your materials. Processing for a separate, additional purpose requires its own lawful basis and the required notice or consent.
This Policy does not promise a single retention period or a universal no-training guarantee across every external provider: terms depend on the actual service, feature and mode used. If a task needs a particular confidentiality mode, a no-training guarantee, or processing confined to a particular territory, that must be arranged before submitting the relevant materials. You may ask about recipients and applicable terms using the contact details in Section 1. This paragraph does not authorise the Provider to transfer data without a required basis or to breach an agreed restriction.
5. Who Receives Access
Access and disclosure are limited to the relevant purpose and legal basis. Recipients may include:
- Authorised members and administrators of your space, within the permissions granted. Shared history, files and memory may be visible to the team; one member leaving does not equate to deletion of all shared materials.
- People who operate and support the Service, where access is necessary for their duties and they are bound by corresponding confidentiality obligations.
- Providers of compute and AI, hosting and storage, technical maintenance, and communications; providers of authorisation, analytics and billing, within the feature actually used.
- Services you connect and the addressees of actions agreed in your task. Sending a message, publishing content, or delivering a result may disclose its content to the stated recipients or to an unrestricted audience.
- Competent authorities and other parties where disclosure is required by law or otherwise has an appropriate legal basis.
The Service currently offers its bot through Telegram: Telegram's Privacy Policy applies to your use of Telegram. This is not an exhaustive list of every vendor and does not confirm that every task is sent to each of them. A third-party service may determine its own processing within the scope of your relationship with it; a link to its policy does not remove the Provider's own duties. Where the Service engages a specific hosting or analytics vendor, this section will be updated to name it.
6. Place Of Processing And Transfers
Octodus's infrastructure and data processing take place on servers located in Germany. This is the confirmed technical fact about where Service data is hosted and processed.
Calls to external AI tools and to services you connect may be carried out in other countries under those services' own rules; such calls do not change the fact that Octodus's own infrastructure is located in Germany, and do not change the Provider's duties.
Processing and any transfer are subject to the applicable requirements for a lawful basis, localisation, notices, restrictions and data protection, including the GDPR's rules on transfers outside the EU/EEA where relevant. Using a foreign service, or a user's consent alone, does not by itself remove these requirements. Where a special transfer mechanism or a processing agreement is required, it must be in place before the relevant processing occurs. You may ask the Provider about recipients, countries and applicable safeguards that affect you. Naming a country or vendor is not a certification claim or a statement that the whole system meets the requirements of a particular jurisdiction.
7. Connections And Protection Of Data
A connection may use OAuth or another method specific to a given integration for granting access. Grant only the permissions actually needed. A connection is not an unlimited mandate: the scope of actions and how they are agreed are governed by the Terms and by the specific task.
The Provider must take the necessary organisational and technical protective measures, limit access to its purpose, and keep entrusted information confidential. This Policy does not promise the absence of every incident, universal end-to-end encryption, or that authorised support staff can never access materials.
If access is compromised, revoke or replace it immediately on the relevant system and notify support. Revocation stops new calls made under the revoked access but does not undo operations already performed and does not automatically delete data already received. Consequences for stored materials are assessed separately.
8. Storage And Deletion
Data must not be kept longer than necessary for a lawful purpose. The period depends on the category and the circumstances:
- Account, membership and settings data are kept to maintain access, and afterwards only where another lawful need exists.
- Tasks, results, files and memory are kept to perform and continue your work, to provide history, and to operate your space, for as long as the relevant purpose and basis continue. A deletion request is considered independently of whether you keep using other features.
- Access credentials are kept only as long as the active connection needs them; ending a connection requires a separate assessment of whether to delete stored credentials and previously received materials.
- Billing documents and evidence of the contractual relationship are kept for mandatory statutory periods and the permissible period for defending claims. Deleting an account does not override statutory retention duties.
- Logs and support records are kept only as necessary to investigate an error or incident, to defend rights, and to meet legal obligations.
Deleting a message, a file, a project's memory, an account and an entire space are different operations. A request should identify the underlying data, derived memory and any managed copies it covers; it is not limited to hiding a message in the interface. Processing a request takes into account other members' rights, a customer's obligations, and any lawful basis for retaining particular records.
Backup and mirror copies, and copies held by external recipients, may follow a separate retention and deletion cycle. Immediate destruction of every copy, or a single fixed number of days, is not promised. This is not a licence for indefinite retention: statutory requirements to stop processing and delete still apply. On request, the Provider will state the applicable periods or criteria, any exceptions, and how a request is carried out. Data that has already been lawfully published or sent to an independent recipient may not always be removable with a single command inside Octodus; the Provider's own duties continue to apply.
9. Your Rights And Requests
Where the law provides for it, you have the right to be informed about processing and to access your data, to request rectification, restriction, blocking or erasure, to withdraw consent, to object to processing, and to request a portable copy. The scope of these rights and how they are exercised are set by applicable law, including the GDPR/DSGVO. You may lodge a complaint with your competent data protection supervisory authority — in Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit, or the authority competent for your own place of residence — and you may apply to a competent court.
Write to labs@octodus.com or to the postal address in Section 1. State which data or space is affected and what action you are requesting. A complete technical log is not required; do not send a password or an active secret. To prevent disclosure of someone else's data, proportionate proof of identity or authority may be requested.
A response and any required action are provided within the statutory deadlines. If a request cannot be fulfilled in full, the Provider will state the basis, any permissible limits, and the further process available. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal and does not stop processing that rests on another lawful basis. Where data is processed on an organisation's instructions, a request is handled taking that organisation's role into account; not having access to an account does not remove your right to contact the Provider directly.
10. Cookies And Analytics
As of the date of this version, octodus.com does not load any analytics, advertising or tracking cookies, and does not run a cookie-consent banner, because no such tool is deployed on the site. The page itself requests fonts from Google Fonts (fonts.googleapis.com / fonts.gstatic.com) to render its typography; this involves your browser connecting to Google's servers, which may process your IP address under Google's own terms, independently of any cookie set by this site.
If the Service later adds analytics, advertising or other non-essential cookies or similar technologies, this section will be updated to describe them, and, where the law requires prior consent, that consent will be requested before the relevant technology is activated.
Your browser settings let you restrict cookies, local storage and connections to third-party domains, including Google Fonts, regardless of what this section describes.
11. Changes To This Policy
The current version, with its date, is published at this page. A change to the text is not retroactive consent, authorisation for a new purpose, or a withdrawal of previously accepted commitments. Any notice, consent or other requirement triggered by a change in processing is carried out in the cases and within the periods required by law or by an individual agreement.