Privacy Policy

Last updated: November 1, 2024 | Effective: November 1, 2024

1. Introduction

Gimerny AI GmbH ("Gimerny AI," "we," "us," or "our"), registered at Friedrichstrasse 68, 10117 Berlin, Germany, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (gimerny.com), use our platform and products, or otherwise interact with us.

We process personal data in compliance with the European General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws. Our Data Protection Officer can be reached at dpo@gimerny.com.

2. Data We Collect

We collect information in the following categories:

2.1 Information You Provide: Name, email address, company name, job title, and phone number when you request a demo, create an account, or contact us. Payment information processed through our third-party payment processor (Stripe). Content you upload to our platform, including molecular structures, biological data, and research documents.

2.2 Automatically Collected Information: IP address, browser type, operating system, device identifiers, and referring URLs. Usage data including pages visited, features used, timestamps, and session duration. Cookies and similar tracking technologies (see Section 8).

2.3 Data from Third Parties: Business contact information from data enrichment services. Information from identity verification providers for compliance purposes.

3. How We Use Your Data

We use your data for the following purposes and legal bases under GDPR Article 6:

Contract Performance (Art. 6(1)(b)): To provide, maintain, and improve our platform and services. To process transactions and manage your account. To provide customer support.

Legitimate Interest (Art. 6(1)(f)): To analyze usage patterns and improve our products. To send relevant product updates and research publications. To prevent fraud and ensure platform security. To conduct business analytics and reporting.

Consent (Art. 6(1)(a)): To send marketing communications (you may opt out at any time). To use non-essential cookies and tracking technologies.

4. Data Sharing and Disclosure

We do not sell your personal data. We may share data with the following categories of recipients:

Service Providers: Cloud infrastructure (AWS, Google Cloud), payment processing (Stripe), analytics (Mixpanel), customer support (Zendesk), and email communications (SendGrid). All providers are contractually bound to process data only on our instructions.

Legal Requirements: We may disclose data when required by law, regulation, legal process, or governmental request.

Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

5. International Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or your explicit consent. Our US operations process data under SCCs with supplementary technical measures including encryption in transit (TLS 1.3) and at rest (AES-256).

6. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy. Account data is retained for the duration of your account plus 30 days. Transaction records are retained for 10 years as required by German commercial law (HGB). Usage analytics data is retained for 26 months, then aggregated and anonymized. Marketing consent records are retained until consent is withdrawn, plus 3 years for compliance documentation.

7. Your Rights

Under GDPR, you have the following rights: access to your personal data (Art. 15), rectification of inaccurate data (Art. 16), erasure ("right to be forgotten") (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing (Art. 21), and withdrawal of consent at any time (Art. 7(3)).

To exercise these rights, contact us at privacy@gimerny.com. We will respond within 30 days. You also have the right to lodge a complaint with the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte fur Datenschutz und Informationsfreiheit).

8. Cookies and Tracking

We use the following categories of cookies:

Essential Cookies: Required for platform functionality, authentication, and security. Cannot be disabled.

Analytics Cookies: Help us understand how visitors use our website. We use Mixpanel with IP anonymization enabled. These require your consent.

Marketing Cookies: Used for advertising attribution and retargeting. These require your consent and can be managed through our cookie preference center.

9. Security Measures

We implement industry-standard security measures including encryption in transit (TLS 1.3) and at rest (AES-256), SOC 2 Type II certified infrastructure, regular penetration testing by independent security firms, role-based access control with multi-factor authentication, and continuous security monitoring and incident response. For details, see our Security page.

10. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or by posting a prominent notice on our website at least 30 days before the changes take effect.

12. Contact

For privacy-related inquiries: privacy@gimerny.com. Data Protection Officer: dpo@gimerny.com. Gimerny AI GmbH, Friedrichstrasse 68, 10117 Berlin, Germany.