Skip to content
CONTEXTSTUDIOSAI-NATIVE DEVELOPMENT STUDIO
EN
  • DE
  • EN
  • FR
  • IT
Book a call →

Your goal

Be visible where AI answers

(01)Technical SEO, GEO & AEOTechnically sound for Google, visible in ChatGPT & co.(02)MCP Server DevelopmentMCP servers for Claude, ChatGPT and other AI clients
GuideGEO optimization→

Automate processes

(01)CRM SetupHubSpot, Pipedrive & Co.(02)No-Code AutomationWorkflows set up in Make, Zapier & n8n(03)Project Management SetupNotion, Monday & Asana(04)SaaS Setup & ConfigurationThe right tool stack, ready to use(05)Business Process AutomationCoded workflows with monitoring & governance(06)AI Workflows & IntegrationLLMs built into existing workflows(07)Chatbot DevelopmentSecure AI chatbots with quality assurance & compliance(08)Document Processing & OCRIntelligent document processing with validation
GuideAI automation→

Build a product

(01)Custom Software DevelopmentWeb apps, portals, backends and integrations, built to fit(02)Database Design & OptimizationScalable database solutions(03)MVP SprintGoal: MVP in about 4 weeks(04)Mobile AppsiOS and Android from one codebase
GuideMVP development→

Put AI agents to work

(01)Local AI Agents on Your Own HardwareOpen models, data stays in-house(02)AI AgentsAgents that complete tasks on their own, with every step traceable
GuideAI agent development→

Connect and modernize systems

(01)Tool Integration & ConnectivityConnect existing tools – Make, n8n, webhooks(02)API Development & IntegrationA new API for your product – OpenAPI, auth, versions(03)Legacy ModernizationStep-by-step migration with observability & compliance(04)Software Architecture DesignArchitecture for production readiness(05)Security Audit & Penetration TestingSecurity check of your systems(06)Technical Support & MaintenanceOperations, updates and fixes(07)Performance OptimizationFaster, more efficient systems(08)System Monitoring & AlertsSpot outages before users notice(09)Enterprise API PlatformOne platform for many systems – gateway, SSO, portal
GuideLLM integration→

Know where we stand

(01)Tech Stack AssessmentCode, dependencies and security reviewed(02)Training & OnboardingYour team learns to use new technology with confidence(03)AI AssessmentWhere AI pays off: light check and deep dive(04)AI Strategy & Prototyping WorkshopFrom sticky note to prototype(05)AI ConsultingOngoing advice on AI decisions
GuideAI consulting→

Formats

Four formatsWorkshopsFind your route
All services →

Use Cases

(01)CRMStrengthen customer relationshipsPopular(02)E-CommerceBoost online revenue(03)Booking System24/7 appointment booking(04)Project ManagementCoordinate teams(05)InvoicingGet paid faster(06)AnalyticsData-driven decisions

Industries →

(01)Construction & CraftsManage projects digitallyTop(02)HealthcareOptimize patient care(03)HospitalityImprove guest service(04)Marketing AgenciesScale campaigns(05)VC & Private EquityPortfolio performance(06)EnterpriseModernize legacy

Roles →

(01)CEO / FounderScaling & growthFor You(02)Marketing ManagerAutomate leads(03)Sales ManagerOptimize pipeline(04)Operations ManagerStreamline processes(05)CTOModernize tech stack

Companies →

(01)StartupsLaunch fast & leanIdeal(02)SMBGrow efficiently(03)EnterpriseMaster complexity(04)SolopreneurStay in control(05)Family BusinessModernize tradition
View all →

Resources

(01)BlogLatest articles and updates(02)GuidesAI decision guides & comparisons(03)ComparisonsSide-by-side AI tool comparisons(04)GlossaryAI Masterclass & Definitions(05)FAQCommon questions answered(06)Local AIWhich models run on your hardware(07)LocationsCities and regions in Germany
  1. Services01
    All services →
    Be visible where AI answers2
    Technical SEO, GEO & AEOMCP Server DevelopmentGuide GEO optimization
    Automate processes8
    CRM SetupNo-Code AutomationProject Management SetupSaaS Setup & ConfigurationBusiness Process AutomationAI Workflows & IntegrationChatbot DevelopmentDocument Processing & OCRGuide AI automation
    Build a product4
    Custom Software DevelopmentDatabase Design & OptimizationMVP SprintMobile AppsGuide MVP development
    Put AI agents to work2
    Local AI Agents on Your Own HardwareAI AgentsGuide AI agent development
    Connect and modernize systems9
    Tool Integration & ConnectivityAPI Development & IntegrationLegacy ModernizationSoftware Architecture DesignSecurity Audit & Penetration TestingTechnical Support & MaintenancePerformance OptimizationSystem Monitoring & AlertsEnterprise API PlatformGuide LLM integration
    Know where we stand5
    Tech Stack AssessmentTraining & OnboardingAI AssessmentAI Strategy & Prototyping WorkshopAI ConsultingGuide AI consulting
    Formats3
    Four formatsWorkshopsFind your route
  2. Solutions02
    View all →
    Use Cases6
    CRME-CommerceBooking SystemProject ManagementInvoicingAnalytics
    Industries6
    Construction & CraftsHealthcareHospitalityMarketing AgenciesVC & Private EquityEnterpriseView all →
    Roles5
    CEO / FounderMarketing ManagerSales ManagerOperations ManagerCTOView all →
    Companies5
    StartupsSMBEnterpriseSolopreneurFamily BusinessView all →
  3. Resources03
    BlogGuidesComparisonsGlossaryFAQLocal AILocations
DE · EN · FR · IT
/
Book a call →
  1. Home
  2. ·
  3. Privacy Policy

Legal

Privacy Policy

In short

Privacy policy pursuant to Art. 13 and 14 GDPR for Context Studios: which data we process, on what legal basis, for how long and what rights you have.

Contents

  1. (01)Controller pursuant to Art. 4(7) GDPR
  2. (02)1. Introduction and Scope
  3. (03)2. What Data We Collect
  4. (04)3. Overview of Processing Activities
  5. (05)4. Legal Bases for Processing
  6. (06)4a. Obligation to Provide Data
  7. (07)5. Recipients and Processors
  8. (08)6. Your Rights (GDPR)
  9. (09)7. First-Party Website Analytics
  10. (10)8. AI Chatbot “Cosmo” (Google Gemini)
  11. (11)9. International Data Transfers
  12. (12)10. Retention Periods
  13. (13)11. Data Security
  14. (14)12. Children’s Privacy
  15. (15)13. Automated Decision-Making and Profiling
  16. (16)14. Changes to This Privacy Policy
  17. (17)15. Contact
  18. (18)Annex: Additional Information for California and the United Kingdom

Last updated: September 24, 2026

Controller pursuant to Art. 4(7) GDPR

Context Studios UG (haftungsbeschränkt)
Represented by the managing director: Michael Kerkhoff
Kaiser-Friedrich-Str. 6
10585 Berlin, Germany

Phone: +49 30 96610664
Email: info [at] contextstudios [dot] ai
Commercial register: Amtsgericht Charlottenburg (Charlottenburg Local Court), HRB 280670 B

We have not appointed a data protection officer, as we are currently not legally required to do so. For data protection enquiries, please contact us at info [at] contextstudios [dot] ai or use our data protection request form.

1. Introduction and Scope

This privacy policy informs you, in accordance with Art. 13 and 14 GDPR, about the processing of personal data on our website contextstudios.ai and in our web applications.

We take the protection of your personal data seriously and process it only in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

2. What Data We Collect

2.1 Personal Data (Information You Provide Voluntarily)

We collect personal data that you provide to us voluntarily when you:

  • Fill in a contact form
  • Request our information pack (we send it to the email address you provide and store the request as a contact enquiry)
  • Subscribe to our newsletter (with double opt-in confirmation)
  • Book a discovery call via Cal.com
  • Create an account with Clerk authentication
  • Sign an offer or a non-disclosure agreement (NDA) electronically (section 2.9)
  • Submit a data protection request (section 2.10)
  • Communicate with us by email
  • Use the AI chatbot (section 8)

This information may include:

  • Name and email address
  • Company name and position
  • Phone number (if provided)
  • Project requirements and preferences

Purpose and legal basis: Handling your enquiry and taking steps prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). Retention period: 2 years after the last contact, then deleted automatically, unless a business relationship exists (in which case the periods for contract data apply).

2.2 Server Log Files

When you visit our website, our hosting provider Vercel automatically records the following data in server log files:

  • IP address
  • Browser type and version
  • Operating system
  • Referrer URL
  • Time of the server request
  • Requested resource

Purpose, legal basis and retention period

The logs serve IT security, abuse prevention and error analysis. They are deleted automatically in accordance with Vercel’s specifications, to the best of our knowledge after 30 days at the latest. Security-relevant entries may be kept longer for the duration of an ongoing investigation.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and system stability).

2.3 Cookies and Similar Technologies

We use cookies and similar tracking technologies in accordance with § 25 TDDDG. Cookies that are not strictly necessary are only set after you have given your express consent. You can find further details in our Cookie Policy.

2.4 Logging of Cookie Consents

To meet our obligation to demonstrate consent under Art. 7(1) GDPR, we log your cookie consents:

  • Data collected: random consent ID, timestamp, selected categories, consent version, type of action (grant, change, withdrawal), language version and whether Global Privacy Control or Do Not Track was active
  • Purpose: demonstrating consent to supervisory authorities
  • Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 5(2) and Art. 7(1) GDPR
  • Retention period: 3 years from logging, then deleted automatically

2.5 Content Delivery Network and Security Service (Cloudflare)

Our entire website is delivered via the content delivery network (CDN) and reverse proxy of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”). Every request to our website is first received by Cloudflare servers, which cache content, forward the request to our hosting provider and protect the website against attacks (e.g. DDoS attacks) and abusive access.

In doing so, Cloudflare processes in particular the following data:

  • IP address
  • Date and time of access and the requested resource (URL)
  • Request data from the HTTP header (e.g. browser type and version, operating system, referrer URL, language setting)
  • Log and event data for delivery and for detecting and defending against attacks
  • the country or region derived from the IP address (HTTP header cf-ipcountry); we use this information only to send you to the matching language version on your first visit

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, performant and reliable delivery of our website and in defending against attacks and abuse.
Processing on our behalf: Cloudflare acts as our processor on the basis of the Cloudflare Data Processing Addendum (DPA) pursuant to Art. 28 GDPR (Cloudflare Customer DPA).
Retention period: in accordance with Cloudflare’s specifications; Cloudflare deletes or anonymises log data automatically.
Third-country transfer: The transfer to the USA is based on Cloudflare’s certification under the EU-U.S. Data Privacy Framework or on the Standard Contractual Clauses agreed in the DPA.
Cookies: Cloudflare currently does not set any cookies on our website.
More information: www.cloudflare.com/privacypolicy

2.6 Google Maps on the Contact Page

On our contact page you can display an interactive map from the Google Maps service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The map is not loaded automatically: at first you only see a placeholder. Only when you click “Load map” does your browser connect to Google servers and load the map. Your choice is not stored; when you visit the page again, the placeholder is shown again.

After the click, in particular your IP address, the date and time of the request, the referring page and browser and device information are transmitted to Google; Google may use cookies or similar technologies. Data may also be transferred to Google LLC in the USA. We have no influence on the scope and further use of this data by Google.

Legal basis: your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG, which you give by clicking “Load map”.
Withdrawal: Consent applies only to the respective page view. You can withdraw it at any time with effect for the future by not loading the map again and deleting cookies set by Google in your browser.
Third-country transfer: Google LLC is certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses apply in addition.
More information: policies.google.com/privacy

2.7 Embedded Videos (YouTube, Vimeo, Loom)

In some blog posts we embed videos from the YouTube, Vimeo or Loom platforms. Here, too, only a placeholder is shown at first. Only when you click “Play video” does your browser connect to the servers of the respective provider, and the video is loaded and played. Your choice is not stored.

  • YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use the privacy-enhanced mode (embedding via youtube-nocookie.com). Third-country transfer to Google LLC (USA): EU-U.S. Data Privacy Framework, supplemented by Standard Contractual Clauses. Privacy information: policies.google.com/privacy
  • Vimeo: Vimeo.com, Inc., New York, USA. Videos are embedded with the parameter “dnt=1” (Do Not Track). Third-country transfer: Vimeo.com, Inc. is certified under the EU-U.S. Data Privacy Framework; supplemented by Standard Contractual Clauses. Privacy information: vimeo.com/privacy
  • Loom: Loom, Inc., USA, a company of the Atlassian group (Atlassian, Inc.). Third-country transfer: the DPF certification of Atlassian, Inc. covers Loom, Inc. (EU-U.S. Data Privacy Framework); supplemented by Standard Contractual Clauses. Privacy information: atlassian.com/legal/privacy-policy

After the click, in particular your IP address, the date and time of the request, the referring page and browser and device information are transmitted to the respective provider; the provider may use cookies or similar technologies during playback. We have no influence on the scope and further use of this data by the provider.

Legal basis: your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG, which you give by clicking “Play video”.
Withdrawal: Consent applies only to the respective video and page view. You can withdraw it at any time with effect for the future by not loading the video again and deleting cookies set by the provider in your browser.

2.8 Abuse Protection for Forms (Rate Limiting)

To prevent our forms (contact, information pack, newsletter, chatbot, data protection request, signature) from being misused for mass email sending or automated attacks, we count requests per IP address and per recipient email address within short time windows. These counters are stored separately from the information you enter in the form and are deleted automatically when the time window expires, at the latest after 72 hours.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and in the secure operation of the website).

2.9 Electronic Signing of Offers and NDAs

You can accept offers and sign non-disclosure agreements (NDAs) electronically via a personal link. Before you sign, we send you a one-time code by email to confirm your identity.

  • Data processed: name, email address, where applicable your role in the company, signature image, time of signing, IP address and browser identifier (user agent) when the code is requested and when you sign; the one-time code is stored only as a hash value
  • Purpose: conclusion of the contract and proof that you signed it, and protection against misuse of the link
  • Legal basis: Art. 6(1)(b) GDPR (conclusion of the contract) and Art. 6(1)(f) GDPR (legitimate interest in reliable proof); for retention Art. 6(1)(c) GDPR
  • Recipients: Convex (storage), Resend (sending the code and the confirmation)
  • Retention period: as part of the contract documents for the statutory retention periods (up to 10 years, § 147 AO, § 257 HGB); if no contract is concluded, we delete the data as soon as it is no longer needed for evidential purposes, as a rule after the standard limitation period of 3 years has expired

2.10 Data Protection Requests

If you exercise a data subject right via our data protection request form, by email or in the chat, we process your email address, the type of request, the information you enter in free text and the times and outcome of its handling.

Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 12 et seq. GDPR (fulfilling your rights) and Art. 5(2) GDPR (accountability).
Retention period: 3 years after the request has been closed, then deleted automatically.

2.11 Accounting and Processing of Receipts

For our accounting we process invoices and receipts from customers and suppliers. Receipts are uploaded in the protected administration area; to extract invoice data (issuer, amount, date, category) we use Google’s Gemini API. The uploaded original files are deleted after processing; we keep the booked data for the statutory periods.

Legal basis: Art. 6(1)(c) GDPR (§ 147 AO, § 257 HGB).
Retention period: 10 years.

3. Overview of Processing Activities

The following table gives a complete overview of our processing activities pursuant to Art. 13 and 14 GDPR:

Overview of processing activities
ProcessingPurposeLegal basisRecipientsRetention periodTransfer
Contact enquiries and information packHandling your enquiry, sending the information packArt. 6(1)(b)/(f)Convex, Resend2 years after last contact, then deleted automaticallySCCs (Convex), DPF or SCCs (Resend)
NewsletterSending informationArt. 6(1)(a)ResendUntil unsubscription; then 30 days, then deleted automaticallyDPF or SCCs
Appointment bookingScheduling discovery callsArt. 6(1)(b)Cal.com2 yearsSCCs
User accountsAuthenticationArt. 6(1)(b)ClerkUntil account deletionDPF
Electronic signing (offers, NDAs)Conclusion of the contract, proof of signingArt. 6(1)(b)/(c)/(f)Convex, ResendUp to 10 years (contract documents)SCCs (Convex), DPF or SCCs (Resend)
Data protection requestsFulfilling your data subject rights, accountabilityArt. 6(1)(c)Convex, Resend3 years after closure, then deleted automaticallySCCs (Convex), DPF or SCCs (Resend)
First-party analyticsWebsite optimisationArt. 6(1)(a)Convex13 monthsSCCs
Google Analytics 4Audience measurement (only with consent)Art. 6(1)(a)Google Ireland/LLC14 monthsDPF + SCCs
AI chatbotCustomer serviceArt. 6(1)(a)Google LLC (Gemini API) or Anthropic PBC (Claude), Convex, Resend90 days per message; browser cache 24 hoursDPF + SCCs (Google), SCCs (Anthropic, Convex), DPF or SCCs (Resend)
AI content optimisationContent creation, SEO, transcriptionArt. 6(1)(f)OpenAI, Anthropic, ConvexDuration of processingSCCs, DPF
Accounting and receiptsStatutory bookkeepingArt. 6(1)(c)Convex, Google LLC (Gemini API)10 yearsSCCs (Convex), DPF + SCCs (Google)
Website hosting and server logsProvision of the website, IT securityArt. 6(1)(f)VercelIn accordance with Vercel’s specifications, to the best of our knowledge 30 days at mostDPF
CDN / reverse proxyDelivery, security, DDoS protectionArt. 6(1)(f)CloudflareIn accordance with Cloudflare’s specifications (logs)DPF + SCCs
Abuse protection (rate limiting)Preventing misuse of the formsArt. 6(1)(f)Convex72 hours at mostSCCs
Google Maps (contact page)Displaying a map (only after a click)Art. 6(1)(a)Google Ireland/LLCIn accordance with Google’s specificationsDPF + SCCs
Video embeds (blog)Playing videos (only after a click)Art. 6(1)(a)Google Ireland/LLC (YouTube), Vimeo, Loom (Atlassian)In accordance with the provider’s specificationsDPF + SCCs
Consent loggingObligation to demonstrate consentArt. 6(1)(c)Convex3 years, then deleted automaticallySCCs
Lead managementSales prioritisationArt. 6(1)(f)Convex2 years after last contact, then deleted automatically (not where a business relationship exists)SCCs

Key: DPF = EU-U.S. Data Privacy Framework, SCCs = Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.

Role of recipients: The role of a recipient depends on the service used and its specific configuration. Many service providers are engaged as processors pursuant to Art. 28 GDPR; for individual services, in particular Google Analytics, separate or joint controllership may exist depending on the features enabled.

4. Legal Bases for Processing

We process your personal data on the basis of:

  • Consent (Art. 6(1)(a) GDPR): newsletter, analytics, chatbot, cookie preferences, Google Maps and embedded videos (each after a click)
  • Performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR): handling enquiries, providing the services you have requested, appointment booking, electronic signing
  • Legal obligation (Art. 6(1)(c) GDPR): tax and accounting requirements, obligations to provide evidence, handling data protection requests
  • Legitimate interest (Art. 6(1)(f) GDPR): IT security, abuse prevention, delivery via a content delivery network (Cloudflare), lead scoring, proof of electronic signatures

4a. Obligation to Provide Data

Providing personal data is partly required to conclude a contract and partly voluntary. There is no statutory obligation to provide data, except for billing details after a contract has been concluded:

Obligation to provide data
AreaRequired?Consequences of not providing the data
Contact form, information packRequired for handlingWithout contact details we cannot answer your enquiry or send the information pack.
Appointment booking (Cal.com)Required for the bookingWithout an email address no appointment can be booked.
Electronic signingRequired to conclude the contractWithout your name, email address and confirmation code, electronic signing is not possible.
NewsletterVoluntary (consent)No disadvantages.
Analytics, chatbotVoluntary (consent)The website can be used in full without consent; you will then not be able to use the chatbot.
Conclusion of a contractRequired by law (§ 14 UStG)Without a billing address we cannot issue a proper invoice.

5. Recipients and Processors

We use the following service providers. Where a service provider acts as a processor, processing takes place on the basis of a data processing agreement (DPA) or a comparable data protection agreement. Transfer mechanisms and certifications are reviewed regularly.

Recipients and processors
Service providerPurposeDataTransfer mechanism
Vercel Inc. (USA)Website hostingAccess logsEU-U.S. DPF
Convex Inc. (USA)Backend databaseEnquiries, user, project and signature data, chat historiesSCCs + supplementary measures
Clerk Inc. (USA)AuthenticationName, email, login dataEU-U.S. DPF
Resend Inc. (USA)Email delivery (confirmations, information pack, newsletter, signature codes)Email address, nameEU-U.S. DPF or SCCs
Cal.com (EU/USA)Appointment bookingName, email, appointment detailsSCCs
Google Ireland Ltd. / Google LLC (USA)Google Analytics 4 (only with consent)Usage and device data (GA4 does not store IP addresses; Google signals and ad personalisation disabled)EU-U.S. DPF + SCCs
Google LLC (USA)Gemini API (AI chatbot, default; processing of receipts)Chat messages and conversation history; invoice dataEU-U.S. DPF + SCCs
OpenAI, L.L.C. (USA)AI content optimisation (SEO, transcription)Content data entered (no advertising analysis)SCCs + DPF
Anthropic PBC (USA)AI content optimisation (content creation); alternative provider of the AI chatbotContent data entered (no training on your data)SCCs
Cloudflare, Inc. (USA)CDN, reverse proxy, security/DDoS protection (processing on our behalf, DPA)IP address, request data, logsEU-U.S. DPF + SCCs
Google Ireland Ltd. / Google LLC (USA)Google Maps on the contact page (only after a click)IP address, browser/device data, referring pageEU-U.S. DPF + SCCs
Google Ireland Ltd. / Google LLC (USA)YouTube videos in the blog (privacy-enhanced mode, only after a click)IP address, browser/device data, referring pageEU-U.S. DPF + SCCs
Vimeo.com, Inc. (USA)Vimeo videos in the blog (only after a click)IP address, browser/device data, referring pageEU-U.S. DPF + SCCs
Loom, Inc. / Atlassian, Inc. (USA)Loom videos in the blog (only after a click)IP address, browser/device data, referring pageEU-U.S. DPF + SCCs

Key: DPF = EU-U.S. Data Privacy Framework, SCCs = Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.

6. Your Rights (GDPR)

Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6(1)(f) GDPR (for example lead scoring, server logs, abuse protection); this also applies to profiling based on those provisions (Art. 21(1) GDPR). We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where your data is processed for direct marketing purposes, you have the right to object at any time to such processing; this also applies to profiling to the extent that it is related to such direct marketing (Art. 21(2) GDPR). After an objection, we will no longer process your data for direct marketing purposes.

No particular form is required for the objection, e.g. by email to info [at] contextstudios [dot] ai, via our data protection request form or via the unsubscribe link in every marketing email.

Under the GDPR you also have the following rights:

  • Access (Art. 15 GDPR): request a copy of your personal data
  • Rectification (Art. 16 GDPR): have inaccurate data corrected
  • Erasure (Art. 17 GDPR): request the deletion of your data
  • Restriction (Art. 18 GDPR): restrict the processing of your data
  • Data portability (Art. 20 GDPR): receive your data in a structured format
  • Objection (Art. 21 GDPR): see above
  • Withdrawal of consent (Art. 7(3) GDPR): withdraw your consent at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected

To exercise these rights, contact us at info [at] contextstudios [dot] ai or use our data protection request form.

We will handle your request within one month; for complex or numerous requests this period may be extended by up to two further months, in which case we will inform you (Art. 12(3) GDPR).

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59-61, 10555 Berlin
Website: www.datenschutz-berlin.de

7. First-Party Website Analytics

We operate our own privacy-friendly analytics system to improve our website. This processing only takes place after you have given your express consent.

Data collected

  • Anonymous visitor ID: randomly generated UUID
  • Session data: pages visited, time on page, scroll depth
  • Geo data: country and city (derived at the edge from request metadata and converted to country/city; the underlying IP address is not stored in the analytics data)
  • Device information: browser type, device type, operating system
  • Performance metrics: Core Web Vitals (for 20% of visitors)

Privacy measures

  • No IP storage in the analytics system: IP addresses are neither collected nor stored in our analytics system
  • Consent-based: tracking only after explicit consent
  • GPC support: Global Privacy Control is respected as an opt-out preference for non-essential tracking, where technically feasible
  • Automatic deletion: 13 months (analytics), 3 months (error logs)

Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: possible at any time via the cookie banner or the cookie settings.

Google Analytics 4

In addition to our first-party analytics, we use – exclusively after your consent – Google Analytics 4 (GA4) for audience measurement. Without consent, GA4 is not loaded; if consent is withdrawn in the cookie banner, processing is immediately set to “denied” via Google Consent Mode.

  • IP addresses: Google Analytics 4 does not log or store IP addresses; the IP address is used only briefly to determine an approximate location (country/region) and is then discarded.
  • Google signals and ad personalisation: disabled (no cross-device matching, no use for advertising).
  • Data retention in GA4: 14 months
  • Lifetime of the _ga/_ga_* cookies: up to 2 years; current browsers limit them to 400 days at most. When consent is withdrawn, _ga/_ga_* and our own analytics identifiers are deleted immediately.

Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (where applicable Google LLC, USA). Third-country transfer: EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
Withdrawal: possible at any time via the cookie banner or the cookie settings.

8. AI Chatbot “Cosmo” (Google Gemini)

Our website offers an AI chatbot. You are interacting with an AI system, not with a human being; you can switch to a member of our team at any time via “Talk to a human”. The chatbot is only used after you have given your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future – via “Delete my data” in the chat or via our data protection request form (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before it. General information on our use of AI is available on our AI Transparency page.

Data collected

  • Your chat messages and the chatbot’s replies
  • Anonymous visitor and session ID, timestamps, language
  • The page you are on, device type and browser
  • Your IP address – used only for abuse prevention (rate limiting) and stored separately from the conversation history

Purposes of processing

  • Answering your questions about our services
  • At your request: handover to a member of our team, appointment booking or sending information
  • Evaluating conversations to improve the quality of the chatbot (identifying knowledge gaps and incorrect answers)
  • Abuse prevention and operational security

Recipients and third-country transfers

  • Google LLC, USA (Gemini API, Gemini Flash model): To generate an answer, we transmit your messages and the conversation history to the Gemini API. The transfer is based on the EU-U.S. Data Privacy Framework, supplemented by Standard Contractual Clauses.
  • Anthropic PBC, USA (Claude): For availability or quality reasons we may run the chatbot with a Claude model from Anthropic instead of Gemini. Your messages and the conversation history are then sent to Anthropic; the basis is Standard Contractual Clauses. Anthropic does not use API data for training.
  • Convex Inc., USA: storage of the conversation history in our database; processing on our behalf on the basis of Standard Contractual Clauses.
  • Resend Inc., USA: sending confirmation and notification emails if you submit a contact or callback request; EU-U.S. Data Privacy Framework or Standard Contractual Clauses.

Note on the Gemini API

Google processes the data in accordance with the Gemini API terms of service.

Retention period

  • Conversation history in our database: each message 90 days from when it was sent, then deleted automatically
  • Local cache in your browser: 24 hours
  • Record of consent: 90 days, together with the data it covers
  • Rate-limiting data (IP-based): up to 72 hours (24-hour window plus the deletion run)

Details from contact or callback requests that you leave in the chat are stored as an enquiry under section 2.1 and not according to this period.

Legal basis: Art. 6(1)(a) GDPR (consent); for rate limiting Art. 6(1)(f) GDPR (legitimate interest in preventing abuse). We record your consent with a timestamp and the version of the privacy policy (version 2026-09).
Deletion: at any time in the chat via “Delete my data”, via our data protection request form or by email to info [at] contextstudios [dot] ai.

9. International Data Transfers

Some of our service providers are located in third countries (in particular the USA). Where necessary, we base such transfers on appropriate safeguards such as:

  • EU-U.S. Data Privacy Framework (DPF) – adequacy decision of the European Commission of 10 July 2023, for certified companies (verifiable at dataprivacyframework.gov)
  • Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR (Implementing Decision (EU) 2021/914)
  • Supplementary technical and organisational measures
  • Transfer impact assessments (TIAs) as required and depending on the service configuration

The specific transfer mechanisms for each provider are set out in section 5.

10. Retention Periods

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations:

Retention periods
Data categoryRetention periodReason
First-party analytics13 monthsYear-on-year comparison + buffer
Google Analytics 4 (only with consent)14 monthsGA4 retention setting
AI chatbot: conversation history90 daysPer message from when it was sent, deleted automatically
AI chatbot: local browser cache24 hoursSession continuity
Rate limiting (IP, forms and chatbot)Up to 72 hoursTime window plus the deletion run
Server logs (Vercel)In accordance with Vercel’s specifications, to the best of our knowledge 30 days at mostError analysis, security
Lead/contact data, information pack requests2 years after last contactInitiating business, legal claims; deleted automatically unless a business relationship exists (in which case the periods for contract data apply)
Consent logs3 yearsObligation to demonstrate consent (Art. 7 GDPR), deleted automatically
Data protection requests3 years after closureProof of handling (Art. 5(2) GDPR), deleted automatically
Newsletter subscriptionsUntil unsubscription, then 30 daysConsent-based; the record is deleted automatically 30 days after unsubscription
User accountsUntil account deletionPerformance of the contract
Electronic signing (without conclusion of a contract)As a rule 3 yearsProof, standard limitation period
Invoice/accounting and contract data (incl. proof of signature)10 yearsStatutory retention obligation (§ 147 AO, § 257 HGB), Art. 6(1)(c) GDPR

After the retention periods have expired, data is deleted or anonymised unless statutory retention obligations prevent this.

11. Data Security

We implement appropriate technical and organisational measures:

  • TLS encryption for all data transfers
  • Encryption of data at rest
  • Secure authentication (Clerk: ISO 27001, SOC 2 certified)
  • Regular security updates and monitoring
  • Access controls and audit logging
  • Data processing agreements or comparable data protection agreements with service providers, where required

Notification of personal data breaches

In the event of a personal data breach that affects you, we will inform you without undue delay in accordance with Art. 34 GDPR. Notifications to the supervisory authority are made within 72 hours in accordance with Art. 33 GDPR.

12. Children’s Privacy

Our services are not directed at persons under the age of 16. We do not knowingly collect personal data from children. If you, as a parent, become aware that your child has provided us with personal data, please contact us at info [at] contextstudios [dot] ai.

13. Automated Decision-Making and Profiling

We do not use automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

Lead scoring (profiling)

We use an internal lead scoring system to prioritise contact enquiries. This constitutes profiling within the meaning of Art. 4(4) GDPR, but is used exclusively for the internal prioritisation of our responses and does not produce decisions with legal effects or similarly significant effects.

Data sources used

  • Information provided voluntarily in contact forms (company name, position, project details)
  • UTM parameters and referrer information (if available)
  • Interactions on the website (recorded with consent)

Scoring factors

  • Company size and type
  • Project scope and budget
  • Engagement with our content
  • Timeframe and decision status

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the efficient allocation of resources).
Your rights: You can request information about the data used for the assessment and object to the processing at any time (see Right to object under Art. 21 GDPR).

14. Changes to This Privacy Policy

We may update this privacy policy. Changes will be published on this page with an updated date. In the event of material changes, we will inform you by email or by a notice on our website.

15. Contact

If you have any questions about this privacy policy, please contact us:

Context Studios UG (haftungsbeschränkt)
Kaiser-Friedrich-Str. 6
10585 Berlin, Germany

Email: info [at] contextstudios [dot] ai

Annex: Additional Information for California and the United Kingdom

The following information supplements sections 1 to 15 for persons resident in California and other U.S. states (A.1, A.2) and in the United Kingdom (A.3). In all other respects, the privacy policy above applies.

A.1 California Consumer Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). This section supplements the information in this privacy policy.

Categories of personal information collected

In the past 12 months, we have collected the following categories of personal information as defined by the CCPA:

Categories of personal information collected
CategoryExamplesCollected?
A. IdentifiersName, email address, IP address, online identifiersYES
B. Personal information (Cal. Civ. Code § 1798.80)Name, address, email, phone numberYES
C. Protected classificationsAge, gender, race, citizenshipNO
D. Commercial informationProducts/services purchased, purchase historyYES
E. Biometric informationFingerprints, faceprints, voiceprintsNO
F. Internet activityBrowsing history, search history, website interactionYES
G. Geolocation dataPhysical location or movementsYES (country/city derived at the edge from request metadata; no IP storage)
H. Sensory informationAudio, visual, thermal, olfactoryNO
I. Professional/employment informationJob title, employer, employment historyYES (if provided)
J. Education informationEducation records, transcriptsNO
K. InferencesPreferences, characteristics, behaviourYES (from analytics)
L. Sensitive personal informationSSN, driver’s licence, financial account, precise geolocationNO

Business purposes for collection

We collect and use personal information for the following business purposes:

  • Providing services and customer support
  • Processing transactions and payments
  • Communicating with you about services, updates and offers
  • Analytics and improving our website and services
  • Security, fraud prevention and legal compliance
  • Marketing and advertising (with consent)

Categories of third parties we share with

We share personal information with:

  • Service providers: hosting (Vercel), CDN (Cloudflare), database (Convex), authentication (Clerk), email (Resend), booking (Cal.com), AI services (Google Gemini, OpenAI, Anthropic)
  • Analytics providers: Google Analytics (with consent)
  • Professional advisors: lawyers, accountants, auditors
  • Government authorities: when required by law

Sale and sharing of personal information

We do not sell your personal information for monetary consideration.

However, when you consent to analytics cookies (such as Google Analytics), this may constitute “sharing” under the CCPA because it enables cross-context behavioural advertising. Categories shared:

  • Internet activity (browsing history, page views, clicks)
  • Device information (browser type, device type, operating system)
  • Geolocation data (approximate location derived at the edge; no IP storage)

You have the right to opt out of this sharing. See our Do Not Sell or Share My Personal Information page for instructions.

Retention by category

Retention by category
CategoryRetention periodReason
Newsletter subscribersUntil unsubscription + 30 daysConsent-based processing
Contact enquiries2 years after last contactCustomer service, potential contract; deleted automatically
Client contracts and invoices10 years after the end of the contractGerman tax law (§ 147 AO)
Analytics data (Google Analytics)14 monthsAnalytics retention setting
Consent records3 yearsProof of consent (Art. 7(1) GDPR); deleted automatically
Account data (Clerk)Until account deletionService provision, security logs
Booking data (Cal.com)2 years after the meetingClient relationship management

Your California privacy rights

California residents have the following rights:

  • Right to know: request disclosure of the personal information collected, used, disclosed and sold/shared
  • Right to delete: request deletion of personal information (with exceptions)
  • Right to correct: request correction of inaccurate personal information
  • Right to opt out: opt out of the sale/sharing of personal information
  • Right to limit: limit the use and disclosure of sensitive personal information
  • Right to non-discrimination: not be discriminated against for exercising CCPA rights

How to exercise your rights

To exercise your California privacy rights:

  • Email: info [at] contextstudios [dot] ai with the subject “CCPA Privacy Rights Request”
  • Opt out of sharing: Do Not Sell or Share My Personal Information
  • Cookie settings: use our cookie settings to reject analytics cookies

We will verify your identity before processing requests. We will respond within 45 days (extendable by a further 45 days if necessary). You may use an authorised agent to submit requests on your behalf.

Global Privacy Control (GPC)

We recognise and honour the Global Privacy Control (GPC) browser signal. When GPC is detected:

  • we treat GPC as an opt-out of sale/sharing under CCPA § 1798.135(b)(2)
  • we treat GPC as an opt-out preference for non-essential tracking, where technically feasible
  • analytics and advertising cookies are not set without an explicit consent overriding it
  • this applies to the specific browser and device on which GPC is enabled

Learn how to enable GPC on our Do Not Sell or Share page.

Financial incentives

We do not offer financial incentives or price differences in exchange for the collection, sale or retention of personal information.

A.2 Privacy Rights in Other U.S. States

In addition to California, the following U.S. states have enacted comprehensive privacy laws with similar consumer rights. If you are a resident of one of these states, you have rights similar to those described in section A.1:

A.2 Privacy Rights in Other U.S. States
StateLawEffective date
CaliforniaCCPA/CPRAJanuary 1, 2020 (CCPA) / January 1, 2023 (CPRA)
ColoradoCPA (Colorado Privacy Act)July 1, 2023
ConnecticutCTDPA (Connecticut Data Privacy Act)July 1, 2023
DelawareDPDPA (Delaware Personal Data Privacy Act)January 1, 2025
FloridaFDBR (Florida Digital Bill of Rights)July 1, 2024
IndianaICDPA (Indiana Consumer Data Protection Act)January 1, 2026
IowaICDPA (Iowa Consumer Data Protection Act)January 1, 2025
KentuckyKCDPA (Kentucky Consumer Data Protection Act)January 1, 2026
MarylandMOPDA (Maryland Online Data Privacy Act)October 1, 2025
MinnesotaMCDPA (Minnesota Consumer Data Privacy Act)July 31, 2025
MontanaMCDPA (Montana Consumer Data Privacy Act)October 1, 2024
NebraskaNDPA (Nebraska Data Privacy Act)January 1, 2025
New HampshireNHDPA (New Hampshire Data Privacy Act)January 1, 2025
New JerseyNJDPA (New Jersey Data Protection Act)January 15, 2025
OregonOCPA (Oregon Consumer Privacy Act)July 1, 2024
Rhode IslandRIDPA (Rhode Island Data Privacy Act)January 1, 2026
TennesseeTIPA (Tennessee Information Protection Act)July 1, 2025
TexasTDPSA (Texas Data Privacy and Security Act)July 1, 2024
UtahUCPA (Utah Consumer Privacy Act)December 31, 2023
VirginiaVCDPA (Virginia Consumer Data Protection Act)January 1, 2023

Common rights across these states

  • Right to confirm whether we are processing your personal data
  • Right to access your personal data
  • Right to correct inaccuracies in your personal data
  • Right to delete personal data you provided
  • Right to data portability (obtain a copy in a portable format)
  • Right to opt out of targeted advertising, sales and profiling

To exercise these rights, contact us at info [at] contextstudios [dot] ai with “State Privacy Rights Request” in the subject.

Appeal process

If we deny your request to exercise your privacy rights, you have the right to appeal. To appeal, reply to our denial email within 60 days. We will respond to your appeal within 60 days. If we deny your appeal, we will provide information on how to contact your state attorney general.

A.3 UK Privacy Rights (UK GDPR)

If you are a UK resident, you have specific rights under the UK GDPR and the UK Data Protection Act 2018.

Your UK rights

You have the following rights under the UK GDPR:

  • Right of access: request a copy of your personal data (subject access request)
  • Right to rectification: have inaccurate or incomplete data corrected
  • Right to erasure: request deletion (“right to be forgotten”)
  • Right to restrict processing: limit how we use your data
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making: not to be subject to decisions based solely on automated processing

UK supervisory authority

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom

Helpline: 0303 123 1113
Website: www.ico.org.uk

International transfers from the UK

Following Brexit, transfers of personal data from the UK to countries outside the UK (including the EEA) require adequate safeguards. We safeguard transfers from the UK through:

  • UK adequacy decisions (e.g. EEA, Switzerland)
  • UK International Data Transfer Agreement (IDTA)
  • UK Addendum to the Standard Contractual Clauses
  • Recognition of the EU-U.S. Data Privacy Framework in the UK (ICO)

PECR (Privacy and Electronic Communications Regulations)

For UK residents, we comply with PECR regarding:

  • Cookies: we obtain consent before setting non-essential cookies
  • Marketing communications: we send marketing emails only with your consent (opt-in)
  • Caller ID: not applicable (we do not make marketing calls)

UK Consumer Contracts Regulations 2013

If you are a UK consumer purchasing services at a distance (online), you have:

  • Right to pre-contractual information: clear information about services, prices and terms before purchase
  • 14-day cancellation right: the right to cancel within 14 days of the contract (see our cancellation policy)
  • Exceptions: the right may not apply if you request that the service begin immediately and we perform it in full

UK Consumer Rights Act 2015

For digital content and services, you are entitled to:

  • digital content of satisfactory quality
  • fitness for a particular purpose
  • conformity with the description
  • remedies if digital content is faulty (repair, replacement, price reduction, refund)

To exercise your UK privacy rights, contact us at info [at] contextstudios [dot] ai.

CONTEXTSTUDIOSAI-NATIVE DEVELOPMENT STUDIO

AI agents, MCP integrations and software from Berlin

Context Studios UG (haftungsbeschränkt)Kaiser-Friedrich-Str. 6, 10585 Berlin+49 30 96610664info [at] contextstudios [dot] ai

Profiles

Services

  • All services
  • Technical SEO, GEO & AEO
  • MCP Server Development
  • CRM Setup
  • No-Code Automation
  • Project Management Setup

Solutions

  • View all
  • CRM
  • E-Commerce
  • Booking System
  • Project Management
  • Invoicing
  • Industries
  • Roles
  • Companies

Collaboration

  • Formats
  • Workshops
  • Find your route
  • How we quote
  • Request a proposal

Resources

  • Blog
  • Guides
  • Comparisons
  • Glossary
  • FAQ

Company

  • About Us
  • Portfolio
  • Press
  • Locations
  • MCP Server
  • Our Process
  • Contact
Focus areasAI Agency BerlinAI ConsultingAI Agent DevelopmentChatbot DevelopmentMVP DevelopmentGEO Optimization

ReviewsClutch ↗GoodFirms ↗DesignRush ↗

© 2026 Context Studios UG
ImpressumPrivacyTermsRight of WithdrawalCookiesAI TransparencyBrand facts
DE · EN · FR · IT