1. Data Protection at a Glance
General Notes
The following notes provide a simple overview of what happens to your personal data when you use this website and the Corgent platform. Personal data are all data with which you can be personally identified. Legal bases arise in particular from Regulation (EU) 2016/679 (GDPR), the German Telecommunications Digital Services Data Protection Act (TDDDG), and, supplementarily, the Digital Services Act (DDG).
Data Collection on this Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the legal notice (Impressum) of this website.
How do we collect your data?
Your data is collected on one hand by you communicating it to us. This can be, for example, data that you enter in a contact form or provide during registration. Other data is collected automatically when you use the website and, depending on the feature, via browser storage, analytics, security, and anti-abuse systems. These are mainly technical data (e.g., internet browser, operating system, time of the page view, device information, and pseudonymous identifiers).
What do we use your data for?
Part of the data is collected to ensure the secure and error-free provision of the website. We also process data for account management, authentication, system-critical/transactional emails, payment handling, providing AI agents, abuse and security prevention, error monitoring, usage analytics, and — only with separate consent — for newsletter/product updates and optional product analytics.
2. Hosting and Content Delivery Networks (CDN)
External Hosting
Our core infrastructure runs in the EU: the primary database and file storage are hosted by Supabase in the EU (eu-central-1, Frankfurt, Germany), and the API and background workers run on Railway in Europe. Transactional emails are delivered via Resend using an EU domain region (eu-west-1). Analytics uses PostHog EU Cloud after your consent. AI model inference is provided via OpenRouter with Zero Data Retention (ZDR) and data_collection=deny; requests are not used to improve providers' models. Model providers behind OpenRouter may process requests outside the EU during inference; this transfer is covered by OpenRouter's Data Processing Agreement and standard contractual clauses (GDPR Chapter V). Error monitoring via Sentry may process limited technical diagnostic data outside the EU; personal data is stripped from these payloads before they are sent. The frontend is delivered via Netlify, which uses a global content delivery network (CDN) for static content. The full overview is available at /subprocessors.
Subprocessors
We use specialized providers for hosting, payments, email, analytics, and AI inference. A current list with regions, transfer profiles, and erasure paths is published at /subprocessors. Where a transfer to third countries is necessary, it takes place only on the basis of GDPR Chapter V (in particular adequacy decisions, standard contractual clauses, and additional safeguards).
3. General Information and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and according to the legal data protection regulations as well as this privacy policy. This privacy policy is mandatory information under Art. 13/14 GDPR; “acceptance” of the privacy policy is not a legal basis for processing. Where we obtain consents (e.g. analytics, newsletter), this is done separately, voluntarily, and revocably (Art. 6 Para. 1 lit. a, Art. 7 GDPR).
Note on the Responsible Body
The responsible body for data processing on this website is:
Malango Tech UG (haftungsbeschränkt) i.G.
Schumannstraße 24
71640 Ludwigsburg
Germany
Email: mk@corgent.ai
4. Data Collection on this Website
Cookies
Our internet pages use cookies and similar browser storage mechanisms such as local storage. These technologies do not cause any damage to your end device. Some are technically necessary for authentication (login status), CSRF protection, security, and core application behavior (legal basis: § 25 Abs. 2 TDDDG and Art. 6 Para. 1 lit. b/f GDPR). Optional analytics, diagnostics, campaign-attribution, and widget-analytics storage are used only after your prior consent via our cookie settings or auth checkboxes (legal basis: § 25 Abs. 1 TDDDG and Art. 6 Para. 1 lit. a GDPR). You can change or withdraw consent at any time via Cookie Settings in the footer.
Website widget (embed)
If you embed our website widget or use it in test mode, the widget may — after you consent to the analytics cookie category — set first-party cookies, in particular corgent_visitor_id (pseudonymous visitor ID, up to 365 days), corgent_attribution (campaign/click IDs, up to 90 days), and helper cookies corgent_returning, corgent_first_seen, and corgent_user_id. Without analytics consent these cookies are not set; an in-memory identifier may be used for the active chat session only. When you withdraw analytics consent, we delete the widget cookies listed above. Event transmission to our servers also requires consent. Legal basis: Art. 6 Para. 1 lit. a GDPR and § 25 Abs. 1 TDDDG.
Registration on this Website
You can register on this website to use additional functions on the page. We use the data entered for this purpose (in particular name, email address, authentication data, and where applicable organization details) for account setup and administration, authentication, transaction handling, providing the respective services, and account-related system-critical messages. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. For authentication we use Supabase; for transactional email delivery we may use Supabase Auth and Resend. Legal basis: Art. 6 Para. 1 lit. b GDPR (contract/pre-contractual steps) and Art. 6 Para. 1 lit. f GDPR for security and abuse prevention.
Email address and communication
We store your email address as part of your account. System-critical and transactional emails (e.g. sign-in/verification confirmations, password reset, security information, billing receipts, breaking changes/breaking updates regarding service availability) are required for contract performance and do not require separate marketing consent (Art. 6 Para. 1 lit. b GDPR; see also the distinction under § 7 UWG). Regular newsletters and promotional product updates are excluded from this and are sent only after separate, revocable consent.
5. Payment Providers and Resellers
Stripe
We use Stripe to top up your platform-bound credit balance. The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When payments are processed, payment and identification data may be transmitted to Stripe. This processing takes place on the basis of Art. 6 Para. 1 lit. b GDPR (performance of a contract) and our legitimate interest in a secure and efficient payment and fraud prevention process under Art. 6 Para. 1 lit. f GDPR. Details can be found in Stripe's privacy policy at: https://stripe.com/en/privacy.
6. Use of AI Services and Handling of AI Inputs
OpenRouter and Zero Data Retention
To provide our AI functionalities, we use interfaces (APIs) to various AI model providers, in particular via OpenRouter under a Data Processing Agreement. When you use our AI agents, your inputs (prompts), attachments, conversations, and usage-related metadata are forwarded to these services to generate responses, route requests, calculate costs, and prevent abuse. For AI inference we enforce Zero Data Retention (ZDR) and data_collection=deny: providers may not store or use your request contents to improve their own models. Content is processed briefly during inference to generate the response; depending on the selected model, this inference may take place on provider infrastructure outside the EU. Such transfers are covered by OpenRouter's Data Processing Agreement and standard contractual clauses (GDPR Chapter V). Legal basis: Art. 6 Para. 1 lit. b GDPR (performance of a contract) and Art. 6 Para. 1 lit. f GDPR (security/abuse prevention). Where another subprocessor requires a third-country transfer (for example limited technical diagnostics), GDPR Chapter V and our subprocessor list apply.
Data you feed into the AI
You decide which content you enter into chats, agents, files, or tools. Do not enter special categories of personal data (Art. 9 GDPR), trade secrets, or third-party data unless you are authorized to do so and it is strictly necessary. You are responsible for ensuring that your inputs are lawful. Corgent stores conversations and work results in your tenant context to the extent required for platform functionality (performance of a contract). Rights of erasure and access remain unaffected.
AI risks and user responsibility
AI outputs are generated by language models based on probabilities and may be incomplete, inaccurate, outdated, biased, fabricated (hallucinations), or unsuitable for your purpose. You are obliged to review results on your own responsibility before using them, especially before taking actions with legal, financial, HR, health, or safety implications. Automated suggestions do not replace professional review. Further rules are set out in the Terms of Service.
7. Integrations You Connect (Third Parties)
If you connect optional integrations to third-party services on the platform (e.g. email, CRM, communication, developer, or other third-party providers), you authorize Corgent to access, on your behalf and via the relevant interface (API), the data you have authorized within that service and to process it as part of the agents or automations you configure. For the processing of personal data within the third-party service itself (e.g. within your account there), the respective third-party provider is an independent controller under the GDPR; its privacy policy and terms of service apply in addition and take precedence. Corgent has no influence over the availability, content, currency, data quality, or changes to the interfaces and data of these third-party services. The legal basis for processing by Corgent as part of the integration is Art. 6 Para. 1 lit. b GDPR (performance of a contract) and, to the extent access tokens or credentials are stored, Art. 6 Para. 1 lit. f GDPR (secure and functional provision of the integration).
8. Analytics and Error Monitoring
Product analytics (PostHog)
We use PostHog only after you actively consent (cookie settings or auth checkbox). With consent, page views, feature usage, pseudonymous device and session identifiers, and technical context may be measured in order to understand product usage and improve Corgent. For signed-in users, analytics events may also be associated with account traits such as email address, role, and aggregate usage metrics. The legal basis is Art. 6 Para. 1 lit. a GDPR (consent) and § 25 Abs. 1 TDDDG for related device access. Consent is voluntary and not a condition of core use. Without consent, PostHog is not loaded. Withdrawal is possible at any time via Cookie Settings.
Error monitoring (Sentry)
We use Sentry on the client only after you consent to the performance/diagnostics category. With consent, client-side and server-side errors as well as limited technical diagnostic context may be processed so that we can detect, analyze, and fix technical faults. Sentry may process this telemetry on infrastructure outside the EU/EEA; personal data is stripped from error payloads before they are sent (beforeSend filtering). The legal basis is Art. 6 Para. 1 lit. a GDPR (consent) and § 25 Abs. 1 TDDDG. Without consent, client-side Sentry is not activated.
10. Ranking, Recommendations, and Similar Product Logic
Ranking and recommendation features
We may use interaction, usage, spending, ratings, and similar service data to operate search, ranking, anti-abuse, and recommendation features inside the platform. Where a specific feature requires separate consent under applicable law, we will request that consent before activation and provide the relevant control in the product. Otherwise, such processing is based on Art. 6 Para. 1 lit. b GDPR (performance of a contract) or Art. 6 Para. 1 lit. f GDPR (legitimate interest in service quality, discoverability, and platform security).
11. Retention Periods
How long we store data
We store personal data only for as long as necessary for the relevant purposes or as required by law. Account profile data is generally stored for the lifetime of the account and removed after account deletion subject to legal exceptions. Billing and invoice-relevant records are retained for up to 10 years to comply with tax and commercial law obligations. Security and abuse-prevention logs are generally retained for up to 90 days unless longer retention is required for incident investigation or legal defense. Analytics events are retained according to environment and consent settings, with periodic minimization and deletion workflows. We store proof of consent (Art. 7 Para. 1 GDPR) for as long as required for demonstrability and legal defense.
12. Your Rights
Data subject rights under the GDPR
Subject to the statutory requirements, you have in particular the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to certain processing activities (Art. 21). Where processing is based on your consent, you may withdraw that consent at any time with effect for the future (Art. 7 Para. 3 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
13. Children's Privacy
Corgent is a business-to-business (B2B) service intended for adult users acting on their own behalf or as authorized representatives of a legal entity. We do not knowingly collect or process personal data from children. If we become aware that we have inadvertently collected personal data from a minor acting outside an authorized business capacity, we will delete that data. If you believe a child has provided us with personal data, please contact us using the details in our legal notice.
14. Privacy Contact
You can send privacy-related requests to the controller named in the legal notice. Please describe your request as precisely as possible so that we can review and answer it efficiently.