Privacy Policy
Last updated: 27 July 2026 · tb.eflowai.de
Note. This is a convenience translation. The German version of this policy is the binding one; in case of discrepancy, the German text prevails.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
eflowAIModering 5, Raum D350.1
22457 Hamburg, Germany
Email: tech@apimcp.ai
Contact: Johnvir Khattar
The full provider identification — legal form, register entry and VAT number — is in the imprint.
No data protection officer has been appointed, as the conditions of Art. 37 GDPR in conjunction with § 38 BDSG are not met. For any data protection matter, reach us at the address above.
2. Principles
We process personal data only where necessary to provide this website and our services, and only on one of the legal bases set out in Art. 6 GDPR. We do not sell data, do not build profiles and use no automated decision-making within the meaning of Art. 22 GDPR.
Please note that data transmission over the internet — email in particular — may have security gaps. Complete protection against third-party access is not possible.
3. Cookies, tracking and third-party content
This website sets no cookies. No analytics or audience-measurement tools, ad networks, social media plugins, embedded videos, map services or captcha services are used. The contact form embeds no outside provider either (see section 5). Because no information within the meaning of § 25(1) TDDDG is stored on or read from your device, no consent is required — and there is therefore no cookie banner.
Typefaces
The “Archivo” typeface is served exclusively from our own server. There is no connection to Google Fonts or any other font CDN, and your IP address is not transmitted to any third party for this purpose.
Language preference
If you switch languages, your browser stores that choice in your device’s localStorage. This information stays on your device, is never transmitted to us and permits no inference about your identity. You can delete it at any time via your browser settings.
4. Hosting and server log files
This website runs on Firebase Hosting, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement under Art. 28 GDPR is in place with the provider.
When the page is requested, access data is automatically recorded in server log files:
- IP address of the requesting device
- Date and time of access
- Name and URL of the file retrieved, and volume of data transferred
- Notification of successful retrieval (HTTP status code)
- Browser type and version, operating system, referrer URL
Purpose: delivering the content, ensuring system security and stability, and diagnosing errors.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, fault-free operation of this website.
Retention: log data is held by the host and deleted on a rolling basis. We do not evaluate it on a personal level and do not merge it with other sources.
Delivery runs over a global content delivery network, so processing in third countries, the United States in particular, cannot be excluded — see section 7.
5. Getting in touch
You can reach us through the contact form at /kontakt or by email. Through the form we process:
- Required: name, company and email address — without these we cannot answer the enquiry.
- Optional: position, brand, website and your message.
The details are transmitted to us by email and handled in our mailbox. No database is created — we do not additionally store the enquiry in a CRM and we do not analyse it. A copy of your enquiry is sent to the address you gave, as confirmation. The form sets no cookies and uses no third-party captcha; submission runs through our own domain, so your browser opens no connection to an outside provider. Processing takes place on a server in the EU (Frankfurt am Main).
You can withdraw the consent you give before sending at any time, informally, at tech@apimcp.ai. The lawfulness of processing carried out before the withdrawal is unaffected.
Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to the initiation or performance of a contract; otherwise Art. 6(1)(f) GDPR, based on our legitimate interest in responding to enquiries.
Retention: we delete correspondence once your matter has been dealt with conclusively and no commercial or tax retention obligation applies (§ 257 HGB, § 147 AO — six and ten years respectively).
6. Processing within the eflowAI service
When you run the pre-flight audit or build flows with eflowAI, we process the data you provide for it — typically catalogue and article data from your source system (shop system, ERP, PIM, middleware or file export), the mappings derived from it, and the responses coming back from the target channels. This data is largely non-personal. Insofar as it does contain personal data (for example the names of contacts in master data or order processes), we act solely on your instructions as your processor.
For the demo at this address: it runs on the sample assets provided. If you load your own data into the demo, the provisions of this section apply accordingly.
Before any processing begins we conclude a data processing agreement with you under Art. 28 GDPR. It sets out the subject matter and duration, the nature and purpose of processing, the categories of data subjects, the technical and organisational measures under Art. 32 GDPR, and every sub-processor used — including the hosting provider and the AI model providers used for text analysis and generation.
Your data is not used to train general-purpose AI models. Every change the system makes to article data is logged and remains traceable.
7. Transfers to third countries
Where data is transferred to service providers outside the European Economic Area, this takes place only on the basis of an adequacy decision of the EU Commission (Art. 45 GDPR) or appropriate safeguards under Art. 46 GDPR, in particular the EU Commission’s standard contractual clauses.
Google LLC, the parent company of our hosting provider, is certified under the EU-US Data Privacy Framework, for which the EU Commission issued an adequacy decision on 10 July 2023.
8. Encryption
This website uses TLS encryption throughout. You can recognise this by the “https://” in your browser’s address bar and by the padlock symbol. While encryption is active, the data you send us cannot be read by third parties.
9. Your rights
You have the following rights in relation to us:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate or incomplete data (Art. 16 GDPR)
- Erasure, unless a retention obligation applies (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Right to object under Art. 21 GDPR
Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
An informal message to tech@apimcp.ai is enough to exercise these rights.
10. Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement. The authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und InformationsfreiheitLudwig-Erhard-Straße 22, 20459 Hamburg, Germany
datenschutz-hamburg.de
11. Changes to this policy
We update this policy whenever changes in the law or in our processing make it necessary. The version available here is the one that applies; the date above states when it was last revised.