Privacy Policy

As of: July 2026

Protecting your personal data is important to us. AI Service Partners GmbH ("ASP", "we", "us") processes personal data exclusively in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications-Digital-Services Data Protection Act (TDDDG). Below we inform you about which personal data we collect, process and use in connection with the use of our website, the initiation and performance of consulting and IT projects, and the application process.

1. Controller and Contact

Controller within the meaning of Art. 4 (7) GDPR: AI Service Partners GmbH Französische Straße 47 10117 Berlin, Germany Email: info@asp-group.ai Commercial Register: Local Court Charlottenburg, HRB 289656 B Authorised Managing Directors: Luca Ernst Ludwig Harrichhausen, Filippo Valerio Scopel

2. Data Protection Officer

Please direct any data protection enquiries, requests to exercise your rights or questions on our data protection management to: privacy@asp-group.ai. An external Data Protection Officer has been appointed; the contact details will be provided on a case-by-case basis if needed. A Data Protection Officer within the meaning of § 38 BDSG will be officially appointed and published here at the latest when the applicable statutory thresholds are reached.

3. Data Subjects and Categories of Personal Data

Depending on the type of use and contractual relationship, we process personal data in the following categories: • Website visitors: technical connection data, IP address, device and browser information, date and time of access, referrer. • Prospects and enquirers: name, company, role, email, phone number, message content. • Customers and contact persons: contract, communication, billing and project data. • Applicants: application documents, CV, qualifications, correspondence. • Service providers and partners: contact and contract data. • Newsletter and event participants: email address, optionally name and company.

4. Access Data and Server log Files

Each time you visit our website, our hosting provider automatically collects information that your browser transmits and stores it in so-called server log files: IP address (in shortened form), date and time of the request, time zone difference to Greenwich Mean Time, content of the request, HTTP status code, volume of data transmitted, referrer URL, browser type and version, operating system. Legal basis: Art. 6 (1) lit. f GDPR. Legitimate interest: provision, stability and security of our website and abuse detection. Retention period: 30 days; longer only in the event of a specific security incident.

5. Hosting and Content Delivery

Our website is operated on infrastructure provided by Cloudflare, Inc. and Lovable/Supabase (with EU representatives appointed in accordance with Art. 27 GDPR). These providers process connection data and content necessary to deliver the website on our behalf. Data processing agreements pursuant to Art. 28 GDPR are in place and – where transfers to third countries occur – Standard Contractual Clauses of the European Commission (Art. 46 (2) lit. c GDPR), including supplementary technical and organisational measures (Transfer Impact Assessment), have been implemented.

6. Cookies and Similar Technologies

On our website, we use only technically necessary cookies required to operate the site and to remember your language selection (legal basis: § 25 (2) no. 2 TDDDG). For the use of non-essential cookies (e.g. analytics, marketing) we obtain your explicit consent via a consent banner (§ 25 (1) TDDDG in conjunction with Art. 6 (1) lit. a GDPR). You may withdraw your consent at any time with effect for the future.

7. Contacting us (Contact Form, Email, Phone)

When you contact us via our contact form, by email or by telephone, we process the information you provide (name, company, contact details, request) in order to handle and respond to your enquiry. Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual measures) or Art. 6 (1) lit. f GDPR (legitimate interest in responding to enquiries). Retention period: until completion of the communication and beyond only within the scope of statutory retention obligations (§ 257 HGB, § 147 AO – up to 10 years).

8. Data Processing Within Consulting and Implementation Projects

As part of our consulting, development and implementation services, we process personal data of our customers and – within the scope of data processing on behalf of the controller (Art. 28 GDPR) – personal data made available to us by our customers (e.g. for AI prototypes, data analyses, model training or the operation of automation solutions). Before starting any project that involves the processing of personal data or special categories of data, we conclude a data processing agreement with our customers and document the roles, purposes of processing, technical and organisational measures (TOMs) and, where applicable, a data protection impact assessment (Art. 35 GDPR). We use only carefully selected sub-processors and ensure that they provide an equivalent level of data protection.

9. Use of Third-Party AI Systems and Models

In customer projects, we use – following documented approval by the customer – AI models and platforms from established providers (including Anthropic, OpenAI, Google Cloud, Microsoft Azure, Databricks). Where personal data is processed, this is done on the basis of an appropriate legal ground, under data processing agreements, and – for transfers outside the EEA – on the basis of Standard Contractual Clauses including supplementary safeguards. Our customers' training data is not used to further develop the providers' models without explicit consent. In selecting, configuring and monitoring these systems we align with the requirements of the EU AI Act and recognised standards (e.g. ISO/IEC 42001, NIST AI RMF).

10. Applications

Application data that you send us by email or via our applicant portal is processed exclusively for the purpose of the application procedure (Art. 88 GDPR in conjunction with § 26 BDSG). At the end of the process, applicant data will be deleted at the latest after six months, unless you consent to longer storage (e.g. talent pool) or an employment relationship is established.

11. Newsletter and Event Invitations

If you subscribe to our newsletter or register for an event, we process your email address and optionally your name and company on the basis of your consent (Art. 6 (1) lit. a GDPR). Distribution is carried out via a service provider with which a data processing agreement is in place. You may withdraw your consent at any time, e.g. via the unsubscribe link in each email or by message to privacy@asp-group.ai.

12. Recipients and Categories of Recipients

Your personal data is only shared with recipients who need it for the purposes described, in particular: IT and hosting providers, AI and cloud platform providers (processors), advisors, tax advisors and auditors, payment service providers, and competent authorities within the scope of statutory obligations.

13. Data Transfers to Third Countries

Where we transfer personal data to countries outside the European Economic Area (EEA), we only do so if an adequacy decision of the European Commission exists (Art. 45 GDPR), Standard Contractual Clauses have been concluded (Art. 46 (2) lit. c GDPR), binding corporate rules apply or explicit consent has been given. We document additional technical and organisational safeguards in the form of a Transfer Impact Assessment.

14. Storage Duration

We only store personal data for as long as necessary for the respective purposes or where we are legally required to do so. The data will then be deleted or anonymised. Statutory retention obligations under commercial and tax law (generally 6 or 10 years) remain unaffected.

15. Your Rights as a Data Subject

You have the following rights vis-à-vis us at any time: • Right of access (Art. 15 GDPR) • Right to rectification (Art. 16 GDPR) • Right to erasure (Art. 17 GDPR) • Right to restriction of processing (Art. 18 GDPR) • Right to data portability (Art. 20 GDPR) • Right to object to processing based on legitimate interests (Art. 21 GDPR) • Right to withdraw consent with effect for the future (Art. 7 (3) GDPR) • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular with the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin. An informal message to privacy@asp-group.ai is sufficient to exercise your rights.

16. Automated Decision-Making

No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place on our website. If in individual projects we operate AI-based decision-support systems on behalf of customers, we will provide separate information about this.

17. Technical and Organisational Measures

In accordance with Art. 32 GDPR, we take appropriate technical and organisational measures to protect your personal data against loss, destruction, manipulation, unauthorised access and unauthorised disclosure. These include, among others, encrypted transmission (TLS), encrypted storage, role-based access controls, multi-factor authentication, regular security reviews and staff training on data protection and information security.

18. Changes to This Privacy Policy

We update this privacy policy whenever changes to the processing operations we carry out make this necessary. The current version is always available on this page.