Skip to main content

Privacy Policy

This is a courtesy translation. Only the German version is legally binding; in case of any discrepancy, the German text prevails. Zur deutschen Datenschutzerklärung →

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website and use our services. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to our Privacy Policy set out below.

Controller

The controller responsible for data processing on this website is:

CodaAI – a brand of AMP Beratung
Owner: Anja Miebach
Langer Weg 7b
33332 Gütersloh
Germany
E-mail: hi@codaai.ai

2. Hosting

This website is hosted by an external service provider (host). Personal data collected on this website is stored on the host's servers. This may include IP addresses, contact requests, meta and communications data, contract data, contact details, names, website access data and other data generated via a website.

The host is used for the purpose of fulfilling contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of a secure, fast and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR).

We have concluded a data processing agreement (DPA) with the above-mentioned provider(s). This is a contract required by data protection law which guarantees that they process the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures

Data Protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this Privacy Policy.

Your Rights as a Data Subject

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and the right to object. To exercise these rights, please contact us at the address given above.

SSL / TLS Encryption

For security reasons and to protect the transmission of confidential content – such as orders or enquiries you send to us as the site operator – this site uses SSL or TLS encryption.

4. Data Collection on This Website

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and browser version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, and IP address. This data is not merged with other data sources. The basis for data processing is Art. 6(1)(f) GDPR.

Contact by E-mail or Contact Form

If you contact us by e-mail or via a contact form, your request, including all resulting personal data (name, request), will be stored and processed by us for the purpose of handling your enquiry. We do not pass this data on without your consent. Processing is carried out on the basis of Art. 6(1)(b) GDPR where your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures.

Engagement and Use of CodaAI Services

If you request an audit or engage us for the Digital Visibility programme, we process the data required for this solely to carry out the respective engagement. We need the mandatory information requested in order to carry out the engagement.

Data processed includes:

  • Contact data (e.g. name, e-mail address, phone number)
  • Contract data (e.g. services booked, invoicing data)
  • Content data (e.g. briefings, documents and subject-matter information you provide to us for creating content)
  • Usage data (e.g. pages visited, access times)

Processing is carried out on the basis of our legitimate interest in the efficient and secure provision of our services (Art. 6(1)(f) GDPR) and for the performance of a contract (Art. 6(1)(b) GDPR).

Visibility Snapshot

With the Visibility Snapshot you check whether AI systems name your company for a specific question. For this we process the website address and the question you enter. We retrieve publicly accessible pages of the website (e.g. homepage, robots.txt, sitemap), have a service provider create a screenshot of the homepage for the preview, and put the question to providers of AI services and data service providers, including outside the EU. Please do not include personal data in the question. To protect against misuse we process your IP address and store it only as an encrypted checksum that can no longer be linked to new accesses from the following day; in addition we use a service to detect automated access (captcha). The legal basis is our legitimate interest in providing the free service and protecting it against misuse (Art. 6(1)(f) GDPR). We delete checks for which no comparison is requested after 90 days.

Requesting the competitor comparison: If you request the AI competitor comparison, we additionally process your business email address and the name you enter. We first send you an email with a confirmation link and log the time of the request and the confirmation. Only after confirmation do we prepare the comparison and send it to you. The legal basis is the handling of your request (Art. 6(1)(b) GDPR). We delete unconfirmed requests after 7 days; we store the data of a confirmed request for no longer than 24 months after the last contact, unless statutory retention obligations apply.

5. Use of Third-Party AI Services

Our service uses artificial intelligence models from third-party providers to generate content. When you use our services, the content data you enter may be transferred to the servers of these providers. We have concluded data processing agreements with these providers to ensure GDPR-compliant processing of your data.

These providers include:

  • OpenAI, L.L.C., San Francisco, USA
  • Anthropic, PBC, San Francisco, USA (provider of Claude)
  • Mistral AI, Paris, France

We only transmit the data necessary for the provision of the service. The legal basis for this processing is the performance of our contract with you (Art. 6(1)(b) GDPR).

6. Analytics and Advertising

Google Analytics

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We have concluded a data processing agreement with Google and use the "anonymizeIP" function.

7. Cookies

Our website uses cookies. These are small text files stored by your browser on your device. We use technically necessary cookies (Art. 6(1)(f) GDPR) and, with your consent (Art. 6(1)(a) GDPR), cookies for analytics and marketing purposes. You can manage your consent via our cookie consent banner.

You can withdraw your consent at any time with future effect:

8. Sub-Processors

We use the following service providers as data processors under Art. 28 GDPR. A Data Processing Agreement (DPA) has been concluded with each of them.

Provider Purpose Location
GitHub Inc. Serving the website (GitHub Pages) USA
Supabase Inc. Receiving and forwarding form submissions USA
Google Ireland Limited Google Analytics for audience measurement (consent-based) and Google Workspace for mailbox, calendar and appointment booking Ireland, transfer to the USA possible
seven communications GmbH & Co. KG SMS delivery for booking confirmations, reminders and verification codes Kiel, Germany
Hetzner Online GmbH Hosting of the personal audit dashboards and the Visibility Snapshot (audit.codaai.ai) Gunzenhausen, Germany
Resend, Inc. Sending confirmation and result emails of the Visibility Snapshot USA
Cloudflare, Inc. Protection against automated access (Turnstile) for the Visibility Snapshot USA

Where a provider processes personal data outside the EU, we rely on the European Commission’s Standard Contractual Clauses or on the EU-US Data Privacy Framework. This list reflects the status as of 3 August 2026; changes will be published here.