Privacy Policy

Last updated: February 2026

1. Data Controller

The data controller is: Expert Sieve UG (haftungsbeschränkt) Wilhelm-Raabe-Str. 6 04416 Markkleeberg Germany Email: info@heykurt.de Phone: +49 341-39 29 48 04

2. Overview of Processing

We only process personal data to the extent necessary to provide our services. Processing is based on Art. 6 (1) GDPR.

3. Hosting and Servers

This website is hosted by netcup GmbH (Karlsruhe, Germany). When you visit our website, server log files are automatically created containing your IP address, browser type, operating system, referrer URL, hostname, and time of access. This data is required to ensure smooth operation and is deleted after 7 days. Provider: netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany

4. Web Analytics

We use Pirsch Analytics for statistical analysis of website usage. Pirsch is a privacy-friendly analytics tool that does not use cookies and does not store personal data. IP addresses are anonymized and not stored. Provider: Pirsch Analytics (Emvi Software GmbH), Germany/EU Privacy information: https://pirsch.io/privacy

5. Cloud Infrastructure

For operating our application, we use cloud services from Scaleway. Data processing takes place in data centers within the European Union (France). Provider: Scaleway SAS, 8 rue de la Ville l'Evêque, 75008 Paris, France

6. AI Services

HeyKurt uses AI services to process requests: Mistral AI For answering user queries and semantic search in your knowledge base, we use AI models from Mistral AI. Mistral AI is a French company and data processing takes place within the European Union. Provider: Mistral AI, 15 rue de Castiglione, 75001 Paris, France

7. Email Communication

For email communication, we use Proton Mail. When you contact us by email, your data is processed on Proton servers in Switzerland. Switzerland is recognized as a third country with an adequate level of data protection according to Art. 45 GDPR. Provider: Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland

8. Browser Extension (Chrome Extension)

HeyKurt offers an optional browser extension for Google Chrome that provides an AI assistant directly in the browser. Permissions and Data Access The extension requires the following permissions: • Access to the active browser tab (URL and page content) • Local storage for settings (chrome.storage.local) • Network access for communication with the HeyKurt backend Processed Data The extension processes the following data: • Login credentials (email/password) for authentication – the password is only transmitted for login and is not stored locally • JWT token for authentication (stored locally in the browser) • Page context: On supported helpdesk platforms (e.g., Freshdesk, Zoho Desk), ticket information such as subject, customer name, and customer message is extracted. On other pages, the page title and any selected text is captured. • Chat messages and history within the current session • URL of the current page Data Storage All settings (authentication token, username, preferred language, display settings) are stored exclusively locally in the browser (chrome.storage.local) and are not synced with the Google account. Data Transmission Chat messages including the extracted page context are transmitted exclusively to the configured HeyKurt instance (default: app.heykurt.de) via encrypted HTTPS connections. No data is transmitted to third parties. Legal Basis Processing is based on Art. 6 (1) (b) GDPR (performance of contract) for authenticated users.

9. Your Rights

You have the following rights regarding your personal data: • Right to access (Art. 15 GDPR) • Right to rectification (Art. 16 GDPR) • Right to erasure (Art. 17 GDPR) • Right to restriction of processing (Art. 18 GDPR) • Right to data portability (Art. 20 GDPR) • Right to object (Art. 21 GDPR) To exercise your rights, contact us at info@heykurt.de.

10. Third Country Transfers

All services we use are operated within the EU or Switzerland. Switzerland has an adequacy decision from the EU Commission according to Art. 45 GDPR, ensuring an adequate level of data protection. No data is transferred to the USA or other third countries without an adequacy decision.

11. Changes

We reserve the right to adapt this privacy policy to comply with changed legal requirements or changes to our services. The current version can always be found on this page.