Privacy Policy
Information about the processing of personal data on nezam.ai pursuant to Article 13 GDPR.
Deutsche Originalfassung lesen
Translation notice: This English translation is provided for convenience only. The German version is the sole legally authoritative and binding version.
Last updated: 25 September 2026
1. Controller
Nezam AI GmbH
Am Neuen Markt 9 E-F, 14467 Potsdam, Germany
Telephone: +49 331 76993748
Email: [email protected]
2. Provision of the website
When you access the website, technically necessary connection data is processed, in particular the IP address, time, requested resource, referrer, browser and device information. This enables secure and reliable provision of the website.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our website.
DNS: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (authoritative DNS only; no proxy for website content). Cloudflare answers DNS requests for domain resolution; website traffic is not routed through the Cloudflare proxy network.
Hosting: Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany.
Retention: Application-level access logging is disabled. Security-related infrastructure data, where generated, is stored for no more than 7 days unless a specific security incident requires longer preservation.
3. Contact form
When you use the contact form, we process your name, company, business email address and message. We also record the submission time, IP address, user agent, derived browser/device type, browser language, referrer, origin and form URL. This technical data is used to prevent misuse, provide traceability and process the request securely.
Purposes and legal bases: Processing your enquiry and taking pre-contractual steps under Article 6(1)(b) GDPR; secure communication and misuse prevention under Article 6(1)(f) GDPR. Our legitimate interest is the reliable handling of business enquiries and protection of the form.
Name, company, email address and message are required. We use Cloudflare Turnstile to protect against automated misuse. Technically necessary connection, browser, device and interaction data is sent to Cloudflare and a security assessment is generated. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protecting the form, our mail infrastructure and uninvolved recipients from spam.
An acknowledgement is sent to the specified email address only after a successful Turnstile check. There is no automated decision-making concerning contracts or services and no profiling for advertising purposes.
Retention: Contact enquiries and associated technical request data are deleted no later than 6 months after the enquiry is finally concluded, unless contractual or statutory retention obligations require longer storage.
4. Recipients and service providers
Contact enquiries are received by the responsible persons at Nezam AI GmbH. The following service providers are used for provision, transmission and storage:
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (authoritative DNS only; no proxy for website content) for authoritative domain-name resolution;
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (Turnstile protection against automated contact-form misuse) for contact-form misuse checks;
- MXroute LLC, Texas, USA for SMTP transmission and the company mailbox;
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Gmail infrastructure for an authorised recipient) for an authorised internal blind copy;
- Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany for technical operation of the contact server.
Recipients may use the data only to process and document the enquiry.
5. Transfers to the USA
MXroute LLC is based in the USA. MXroute states that it does not claim formal alignment with specific GDPR programmes. A lower level of data protection and a risk of government access therefore cannot be excluded for this transfer.
Before submission, we therefore obtain your explicit consent under Article 49(1)(a) GDPR. Consent is voluntary and may be withdrawn with future effect. Processing already carried out remains lawful. If you do not want this transfer, you may contact us by telephone at +49 331 76993748 instead.
Cloudflare and Google may also process data in the USA. Both companies state that they participate in the EU-US Data Privacy Framework; where necessary, Standard Contractual Clauses are used. Further information: Cloudflare Privacy Policy and Google data transfer frameworks.
6. Local settings and cookies
We do not use analytics, marketing or profiling cookies. After your selection, the browser stores only nezam-theme (appearance), nezam-lang (language) and nezam-cookie-notice-v1 (cookie-notice acknowledgement) in local storage. These values remain until website data is deleted in the browser and are not transmitted to our server.
Storage is necessary for the setting you requested (Section 25(2)(2) TDDDG). Consent is therefore not required. The notice shown on the first visit is solely for transparent information. See the Cookie and Local Storage Policy for details.
7. Your rights
Subject to the statutory requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). You may withdraw consent at any time with future effect.
Send your request to [email protected].
8. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority responsible for our registered office is:
The Brandenburg Commissioner for Data Protection and Access to Information
Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany
www.lda.brandenburg.de
9. Security and updates
The website uses TLS encryption. We take appropriate technical and organisational measures pursuant to Article 32 GDPR. This policy will be updated if services, recipients or legal bases change.