One AI assistant — as a widget, in your apps, and via APIStart your free trial
Kyros
Chat widget
Embeddable AI chat for any website
Video avatar bot
Real-time talking avatar
Knowledge base
Grounded answers with sources
Interactive cards
In-chat forms & actions
Compare models
Compare models side by side
Moderation
PII & content guardrails
Customer support
Deflect repetitive tickets
Sales & lead gen
Qualify visitors & capture leads
Internal knowledge
One place for team answers
E-commerce
Insurance
Law firms
Healthcare
Blog
Guides & best practices
Glossary
AI terms explained
Templates
Ready-made cards & assistants
Case studies
Results from real teams
Documentation
Embed, API & more
Integrations
Connect your tools
Pricing
Sign inStart free
  1. Home
  2. Privacy

Legal

Privacy Policy

How we process personal data on kyros.omniratio.de and when operating the AI assistants.

As of July 2026 (version 2). This is a translation of the German original; in case of conflict between the German and English versions, the German version prevails.

1. Controller

omniratio in Gründung UG (haftungsbeschränkt)
Erlenweg 12
26209 Hatten, Germany
Commercial register: Amtsgericht Oldenburg, HRB 221015
Represented by: Jorge Marx Gómez (Managing Director)
Email: info@omniratio.de

No data protection officer has been appointed, as there is no statutory obligation to do so. The designated contact point for data protection is: Dr. Keyvan Narimani (info@omniratio.de).

2. Roles (controller / processor)

Depending on the processing activity, omniratio acts in two different roles:

  • Controller: For data arising from visits to the website kyros.omniratio.de as well as from registration, workspace and account administration and billing (e.g. master data, account data, audit log data, platform usage data), omniratio is the controller within the meaning of Art. 4 (7) GDPR.
  • Processor: Where customers operate AI assistants via Kyros – as a website widget, in their own applications, via API or as a video avatar – we process the resulting content exclusively on behalf of and on the instructions of the customer (Art. 28 GDPR). This concerns in particular the contents of the knowledge base (including any personal data contained therein, e.g. customer employee data with name and business phone number/area of responsibility), the inputs and outputs of the assistants (chat content), form entries submitted by end users via interactive cards, and the usage and traffic data arising from operation of the widget. In this respect the customer is the controller. The basis is the data processing agreement (DPA) concluded with the customer pursuant to Art. 28 GDPR, which is made available on request.

Note for end users: If you use a Kyros assistant on a customer’s website (e.g. a municipality’s citizen chatbot), the respective customer is the controller under data protection law. Their privacy notices are authoritative in this respect. In addition, every chat widget contains a privacy panel informing you about the data processed, the legal basis, retention and the processing on behalf of the customer.

3. Provision of the service

Kyros is an AI assistant platform. The service comprises:

  • building and operating a knowledge base per assistant – by crawling the customer’s websites and documents (including PDF, Word and Excel files), through question-and-answer pairs provided by the customer (“golden answers”), as well as generating embeddings and storing them in a vector database;
  • retrieval-augmented generation (RAG) of answers using large language models via a multi-provider model router with automatic fallback; answers cite their sources;
  • provision of the assistants as an embeddable chat widget, for integration into the customer’s own applications, via an API, and optionally as a video avatar with speech output;
  • interactive cards (e.g. forms and actions in the chat) through which end users can submit input;
  • storage of inputs and outputs (chat logs) for the purpose of quality control by the customer;
  • workspace features for customers: registration and authentication, member and role management, audit log, billing via a credit system.

The website kyros.omniratio.de serves to present the offering, provide documentation, and enable registration, account and workspace administration and billing. Where necessary, the following information distinguishes between processing in the context of the website/platform and processing in the context of operating the assistants on behalf of the customer.

4. Purpose and legal bases of processing

We process personal data only to the extent necessary to provide and use our service and to fulfil contractual and statutory obligations.

We collect and process the following categories of personal data:

  • Master data: name, email address
  • Account and contract data: user ID, workspace membership, roles and permissions, authentication data, billing and usage data (credit consumption)
  • Audit log data: logging of relevant workspace actions (actor, timestamp, type of change) for traceability and security
  • Knowledge base content (customer input): content provided by the customer that may contain personal data – e.g. customer employee data (first and last name, business phone number/function for responsibility enquiries)
  • Chat content: inputs and outputs of the assistants (prompts/outputs), stored for quality control
  • Form entries via interactive cards: data actively entered by end users (e.g. contact details in lead forms), where the customer uses such cards
  • Usage and traffic data of the widget: technical data arising during operation (e.g. IP address, session/device information, timestamps)

Knowledge base content, chat content, card entries and widget traffic data are processed by us exclusively as a processor on behalf of the customer (see section 2).

Data minimisation in chat: Entering personal data into the chat field is – outside of the interactive cards provided for that purpose – not intended; end users are informed accordingly. An upstream content check (see section 6) withholds messages containing identifying personal data before they reach the language model or are stored. Processing of special categories of personal data under Art. 9 GDPR is not intended and is prevented by these filters.

Purposes of processing:

  • Provision and operation of the AI assistants including knowledge base and answer generation
  • Registration, user and workspace administration, authentication and billing
  • Quality control of the service (chat logs, configurable by the customer)
  • Ensuring security and preventing misuse (including content moderation, protection against prompt injection and data poisoning, audit log, domain allowlisting, signed embed codes)
  • Creation of aggregated, fully anonymised usage and performance statistics solely to provide, secure and improve the operational performance of the service

Legal bases:

  • For account, contract, workspace and billing data: Art. 6 (1) (b) GDPR (performance of a contract).
  • For security measures, the audit log and anonymised operational statistics: Art. 6 (1) (f) GDPR (legitimate interest in secure, traceable and stable operation).
  • Where we process content on behalf of the customer, this is done on the basis of the data processing agreement (Art. 28 GDPR); the legal basis for the processing vis-à-vis the data subjects is determined by the customer as controller.

No training of AI models: We do not use the data processed on behalf of our customers – including the contents of the knowledge base as well as the inputs and outputs of the assistants – to train, fine-tune or otherwise improve our own or third-party AI or language models. Such use is also contractually prohibited for our sub-processors.

5. Recipients / sub-processors

To provide our service we engage the following processors. Data processing agreements pursuant to Art. 28 GDPR have been concluded with all providers. Content data is processed exclusively within the EU/EEA.

5.1 Strato AG (application and vector database hosting)

Provider: Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
Service: hosting of the application and the vector database (knowledge base)
Place of processing: Germany (Frankfurt am Main)
Third-country transfer: not applicable (EU/EEA)

5.2 Hetzner Online GmbH (backups)

Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Service: storage of backups
Place of processing: Germany (Frankfurt am Main)
Third-country transfer: not applicable (EU/EEA)

5.3 Microsoft Ireland Operations Ltd. (LLM inference and embeddings)

Provider: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Service: LLM inference via Microsoft Azure and generation of embeddings (Cohere)
Place of processing: EU/EEA (EU Data Zone / EU Data Boundary)
Safeguards: Microsoft Products & Services DPA; supplemented by EU Standard Contractual Clauses (SCCs), EU-U.S. Data Privacy Framework (DPF) and a Transfer Impact Assessment (TIA) for any intra-group access

The transmitted content is not used to train the models.

5.4 Mistral AI (LLM inference and content moderation)

Provider: Mistral AI, 15 Rue des Halles, 75001 Paris, France
Service: LLM inference and calibrated classification as part of content moderation (see section 6)
Place of processing: EU/EEA (EU Data Zone)
Third-country transfer: not applicable (EU/EEA)

5.5 Vercel Inc. (frontend hosting)

Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA
Service: hosting and delivery of the frontend (website and chat widget)
Place of processing: EU function region (Frankfurt am Main)
Safeguards: data processing agreement (vercel.com/legal/dpa) with EU Standard Contractual Clauses and UK addendum; EU-U.S. Data Privacy Framework (DPF); Transfer Impact Assessment (TIA)

5.6 Google Ireland Ltd. / Firebase (infrastructure and authentication)

Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Service: infrastructure services and authentication of platform user accounts (registration, login, session management)
Data processed: name, email address, authentication data, login timestamps
Safeguards: Google Cloud Data Processing Addendum (Art. 28 GDPR); for any third-country transfers, EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework (DPF)

Model selection: Kyros provides language models from several providers via a model router. Which model providers are used for an assistant is determined by the customer through its configuration; processing always takes place in EU processing regions of the providers named in this policy or in the DPA.

No other disclosure of personal data to third parties takes place unless required by law. The addition or replacement of sub-processors is handled vis-à-vis our customers in accordance with the information and objection procedure agreed in the DPA (notice in text form with a 14-day objection period).

6. Content moderation and technical filters

To protect end users and to implement data minimisation, every incoming chat message – provided moderation is enabled for the respective assistant (default) – undergoes an automated content check before processing. The check takes place before the message reaches the language model or is stored.

Six categories are active by default: personal data (PII), sexual content, hate and discrimination, violence and threats, dangerous and criminal content, and self-harm. The categories health, financial and legal advice as well as jailbreak attempts can additionally be enabled. Classification is performed via a calibrated judgement (provider: Mistral, processing in the EU) with a configurable sensitivity threshold.

  • Unobjectionable input is processed further unchanged.
  • Flagged input is withheld: the original text does not enter further processing and is not stored. Only a notice naming the triggered categories is stored; the message is marked as “moderated” and answered with a polite refusal. In this case no storage location contains the original text.

Structured input (e.g. button actions via interactive cards) and empty texts are not moderated. If the checking service is temporarily unavailable, the input is processed in its original form (availability before checking); the downstream deletion and protection mechanisms remain unaffected.

In addition, system prompt guardrails prevent the output of complete lists of personal data from the knowledge base (e.g. employee data) outside of a specific enquiry; employee names are only output together with the business phone number in the context of responsibility.

7. Retention periods

We delete personal data automatically upon expiry of the following periods. Enforcement takes place via regular deletion runs.

  • Chat histories (inputs and outputs): inactivity-based retention, configurable per assistant by the customer as controller: platform default of 30 days from the last activity, an individual inactivity period, or no storage at all. An automated deletion run takes place every 24 hours; after the period expires, the complete conversation history and the conversation record are permanently and physically deleted (maximum deletion latency: 24 hours). Active conversations are not deleted.
  • Usage/traffic data and logs (operations, API, errors): 90 days.
  • Audit log data: for the duration of the workspace’s existence.
  • Account and contract data (in particular billing data): contract term plus statutory and commercial retention periods (up to 10 years).
  • Knowledge base and backups: after termination of the main contract, all customer data is, at the customer’s choice, either returned or completely deleted; backups are deleted as part of the regular deletion cycles and are protected in accordance with the contract until then. Customers can export and delete data per workspace.
  • Documentation evidencing compliant processing on instruction: 3 years after the end of the contract.

8. Rights of data subjects

Within the scope of the applicable statutory provisions, you have the right:

  • to obtain information about the personal data we store about you (Art. 15 GDPR)
  • to request rectification of inaccurate data (Art. 16 GDPR)
  • to request erasure or restriction of processing (Art. 17, 18 GDPR)
  • to object to processing where it is based on legitimate interest (Art. 21 GDPR)
  • to request data portability (Art. 20 GDPR)
  • to withdraw a given consent at any time with effect for the future (Art. 7 (3) GDPR)
  • to lodge a complaint with a supervisory authority (Art. 77 GDPR); the authority responsible for omniratio is: Die Landesbeauftragte für den Datenschutz Niedersachsen

You can exercise your rights simply and easily by email: info@omniratio.de. To technically support access and erasure requests, data export and deletion functions are available per workspace.

Important for end users of the assistants: Where we process personal data as a processor on behalf of a customer (in particular chat content, card entries, widget traffic data and knowledge base content), please direct data subject requests to the respective customer (e.g. the operator of the website on which you use the assistant) as the controller. We support the customer in fulfilling such requests pursuant to Art. 28 (3) GDPR and forward requests addressed directly to us to them without undue delay, without acting on them ourselves.

9. Automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place. The assistants provide information on the basis of the knowledge base supplied by the customer; they do not make decisions producing legal effects or similarly significantly affecting data subjects. The automated content moderation (section 6) serves solely security and data minimisation and produces no legal effect vis-à-vis users.

10. Obligation to provide data

Use of the assistants is voluntary and possible without providing personal data; entering personal data in the chat outside of the forms provided for that purpose is expressly not intended. To use the platform as a customer, the provision of certain data (in particular account, contract and billing data) is required; without this data, use of the service is unfortunately not possible.

11. Cookies, local storage and audience measurement

We do not use advertising or tracking cookies and do not create cross-site user profiles. We use only strictly necessary cookies and entries in your browser’s local storage, as well as – solely with your consent – cookieless audience measurement.

Strictly necessary cookies and local storage:

  • NEXT_LOCALE (cookie): stores the selected language version (German/English) so that the website is delivered in your preferred language.
  • Authentication (local storage, Firebase): session and sign-in information of logged-in users so that the session persists across page views (see section 5.6).
  • cookie_consent (local storage): stores your choice in the cookie notice (“accepted”/“declined”) so that it is not shown again on every page view and so that audience measurement is loaded only where consent has been given.
  • Chat widget (local storage, key “omniratio-harness-conversation:…”): stores the identifier of the ongoing conversation so that a chat can be continued after navigating or reloading. Choosing “New chat” deletes the entry. This processing takes place on behalf of the respective customer (see section 2).

The legal basis is Art. 6 (1) (b) GDPR where storage is necessary for sign-in and performance of the contract, and otherwise Art. 6 (1) (f) GDPR (legitimate interest in technically faultless operation). In each case, the storage is strictly necessary to provide the service you have expressly requested (§ 25 (2) no. 2 TDDDG).

Audience measurement (only with your consent): If you accept in the cookie notice, we use Vercel Web Analytics (Vercel Inc., see section 5.5) to evaluate the use of our website. The service is cookieless: it sets no cookies, stores no identifiers on your device and does not enable cross-site recognition. Only aggregated metrics are collected (e.g. pages viewed, referrer, approximate region, device type). Without your consent the script is not loaded; if you decline, no audience measurement takes place. The legal basis is Art. 6 (1) (a) GDPR (consent) in conjunction with § 25 (1) TDDDG. You may withdraw your consent at any time with effect for the future: “Cookie settings” in the page footer resets your choice, disables audience measurement immediately and shows the cookie notice again so that you can decide anew.

You can delete stored cookies and local storage entries at any time via your browser settings and restrict their storage. Please note that sign-in, language detection and the continuation of a chat will then no longer work reliably.

Kyros

Build AI assistants grounded in your content and deploy them anywhere — widget, apps, API. From the DACH region.

Product
  • Chat widget
  • Video avatar bot
  • Knowledge base
  • Interactive cards
  • Compare models
  • Moderation
  • Pricing
Solutions
  • Customer support
  • Sales & lead gen
  • Internal knowledge
Industries
  • E-commerce
  • Insurance
  • Law firms
  • Healthcare
Resources
  • Blog
  • Glossary
  • Templates
  • Case studies
  • Documentation
  • Integrations
Company
  • About
  • Careers
  • Partner program
  • Contact
  • Book a demo
Trust & legal
  • Security
  • GDPR
  • Imprint
  • Privacy
  • Terms
© 2026 omniratio UG
Hosted in the EU · German & English