Legal
Privacy policy
Information under Art. 13 GDPR. As of . This English version is provided for convenience; the German version is legally binding.
We take the protection of your personal data seriously. This policy explains which data we collect on azena.ai, the purposes for which we process it and the rights you hold.
The azena.ai website was relaunched in September 2026. For the time being, a few older subpages, such as the AI glossary or our terms and conditions, are still served from the previous version. You can recognize them by their earlier design. Where processing only takes place on these older subpages, the relevant section says so.
1. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is:
Baybora Gülec
K-Labs GmbH
Birkheckenstraße 78a
70599 Stuttgart, Germany
Phone: +49 155 106 556 64
Email: [email protected]
2. Data collected when you visit our website
When you simply browse our website, our hosting provider (Cloudflare, see sections 3 and 10) automatically records the following data in server logs:
- IP address (truncated / anonymized)
- browser and operating system used
- date and time of access (timestamp)
- referrer URL and the page requested
Retention period: 30 days at most. This data is not combined with any other data. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the security and stable operation of the website).
3. Hosting with Cloudflare
Our website is delivered via Cloudflare Pages, a service of Cloudflare, Inc. (USA). Cloudflare serves the pages through its network of data centers and protects them against attacks and overload. In doing so, Cloudflare processes the access data listed in section 2, in particular your IP address. The server functions of our website, for example for the inquiry form (section 7), also run on Cloudflare.
Cloudflare fetches the older subpages in the background from the previous version of our website, which is also hosted on Cloudflare. No additional provider is involved.
Cloudflare processes the data on our behalf (Art. 28 GDPR). Any transfer to the USA is based on standard contractual clauses under Art. 46 GDPR. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in delivering our website securely, quickly and reliably).
4. Fonts and scripts
The fonts used on our website (Fraunces and Geist) and the GSAP library we use for animations are stored on our own web space. Your browser loads them, like all images and videos, directly from azena.ai. These pages do not connect to Google Fonts or to any other font or script service (CDN).
To stop programs that crawl the web for addresses from harvesting our email address, Cloudflare obfuscates it on our pages. The small script that makes it readable for you again is also served from azena.ai.
Exception: the older subpages currently still embed fonts from Google Fonts (Google Ireland Limited, Ireland) and from Fontshare (Indian Type Foundry, India). When you open one of these pages, your browser connects to their servers and transmits your IP address. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in a consistent presentation of the pages).
5. Cookies and tracking
We use only technically necessary storage mechanisms (e.g. localStorage for your light/dark theme setting). We use no Google Analytics, no tracking and no third-party cookies. No consent is therefore required.
The theme setting only exists on the older subpages. All other pages store nothing in your browser when you visit and set no cookies.
Our pages also contain an internal tool that we use to record notes on our own pages. It can only be activated with a secret key held exclusively by us. For visitors it stays off: it is not loaded and stores nothing.
6. Ask-Azena chat
When you use our “Ask Azena” chat, your requests are routed via a Cloudflare Pages Function to a self-hosted Nexus AI router. Processing takes place exclusively in data centers in the EU/Germany.
Your inputs are not stored permanently; processing is stateless. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest in providing an efficient consulting service).
The chat is currently only available on the older subpages.
7. Inquiry form (/anfrage) and guide requests
When you use our inquiry form, we collect the following data:
- first name, last name
- business email address
- company and your role
- phone number (optional)
- topics you are inquiring about (optional)
- message (free text, optional)
When you request a guide, we collect your name, your company, your business email address and your answer to how far your company has come with the topic. With both forms, your browser also transmits which of our pages you sent it from and in which language.
Your browser sends the details in encrypted form to a server function of our website on Cloudflare (section 3). It forwards them as an email via the delivery service Resend to our inbox and sets your email address as the reply-to address. Resend sends email for our domain via servers in the EU (Ireland). The website itself does not store your details, not even in a database; they reach us only as an email.
Purpose: processing your inquiry and initiating a contract. Data is stored in our CRM systems for the duration of the business relationship and for the statutory retention periods of 6 years under § 257 HGB / 10 years under § 147 AO. The legal basis is Art. 6 (1) (b) GDPR (initiation and performance of a contract).
We send you the guide by email if you agree to this in the form. The legal basis is your consent (Art. 6 (1) (a) GDPR). You may withdraw it at any time, for example by email to [email protected]; the lawfulness of processing carried out before withdrawal is not affected.
To protect against spam, each form contains a field that is invisible to people. If it is filled in, we discard the message. We use neither cookies nor third-party services for this. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in preventing spam).
8. Booking appointments via Calendly
For meetings, we link to our booking calendar at Calendly (Calendly LLC, USA). Calendly is not embedded on our website: as long as you stay on our pages, no data is transferred to Calendly. Only when you click “Choose a time” does Calendly’s page open in a new tab.
From then on, Calendly processes your data, such as your IP address and the details you enter when booking, usually your name, email address and preferred time. We receive this booking data from Calendly in order to prepare and hold the meeting. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures taken at your request). The transfer to the USA is based on standard contractual clauses under Art. 46 GDPR. Processing on Calendly’s pages is additionally governed by Calendly’s privacy notice.
9. Newsletter subscription
For our newsletter we collect only your email address.
- sent once every two weeks with an AI funding briefing
- subscription uses a double opt-in process via a confirmation email
- you can unsubscribe at any time via the “unsubscribe” link at the foot of every email
The legal basis is Art. 6 (1) (a) GDPR (consent). You may withdraw your consent at any time; the lawfulness of processing carried out before withdrawal is not affected.
The sign-up field is currently only available on the older subpages.
10. Recipients of your data
In the course of providing our services, data is passed to the following processors:
- Cloudflare, Inc. — hosting & Pages Functions (USA, standard contractual clauses under Art. 46 GDPR)
- Resend, Inc. — transactional email for /anfrage, guide requests and the newsletter (USA, standard contractual clauses under Art. 46 GDPR; sent via servers in the EU, Ireland)
- Slack Technologies, LLC — internal lead notification to our team (USA, standard contractual clauses under Art. 46 GDPR)
- Calendly LLC — appointment booking, once you use our booking link (USA, standard contractual clauses under Art. 46 GDPR)
Data processing agreements under Art. 28 GDPR are in place with all of the providers named above.
11. Your rights
You hold the following data subject rights:
- access to the data we hold about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing (Art. 21 GDPR)
You also have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR — the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW).
12. Contact for data protection inquiries
For access requests, erasure or any other data protection inquiries, please contact: [email protected].
As of .