Skip to content

Legal · Privacy

What we process — and what we deliberately don’t.

This policy describes the processing of personal data when you visit cusea.ai. The second half summarises how the CUSEA platform processes our customers’ data — there we act as a processor, not as the controller.

  • Last updated 31 August 2026
  • GDPR · BDSG
  • Processing inside the EU
Contents of this document
  1. 1.Controller
  2. 2.Principles
  3. 3.Visiting this website
  4. 4.Fonts and embedded content
  5. 5.Cookies
  6. 6.Voice demo
  7. 7.Provider pricing, booking, email
  8. 8.Processing inside the CUSEA platform
  9. 9.Security
  10. 10.Your rights
  11. 11.Changes to this policy

At a glance

Controller
SOMI Software GmbH
Data protection contact
datenschutz@somi.de
Tracking, analytics, advertising
none on this website
Cookies
two strictly necessary ones — provider area only
Consent banner
not required, because nothing consent-bound is set
Place of processing
European Union

1.

ControllerDirect link to this clause

The controller for data processing on this website within the meaning of Art. 4 (7) GDPR is SOMI Software GmbH, Kennedyallee 93, 60596 Frankfurt am Main, Germany, represented by Maani Nayeri.

Data protection
datenschutz@somi.de
Phone
+49 6131 489 46-0
Postal address
Kennedyallee 93 60596 Frankfurt am Main

Please address requests concerning your rights under Chapter III GDPR to the data protection address. Further provider details are in the imprint.

2.

PrinciplesDirect link to this clause

This website is built to learn as little about you as possible. Concretely:

  • No analytics or advertising tools. No web analytics, tracking pixels, ad networks, social media plugins or profiling are in use.
  • No resources from third-party servers. Fonts, scripts, graphics and images are served from our own server. Your browser opens no connection to third parties when the page loads.
  • No consent-bound cookies. A consent banner would be a question without a subject — the two cookies that exist are strictly necessary (clause 5).
  • Processing inside the EU. Operations, the voice demo and the platform use locations or EU data residency options within the European Union only.

Personal data therefore arises only in a few clearly identifiable places — the ones that follow.

3.

Visiting this websiteDirect link to this clause

When you open a page, your browser transmits technically necessary data which our server records in log files:

  • IP address of the requesting device
  • date and time of access
  • the address requested, the volume of data transferred and the status code
  • browser type, browser version and operating system
  • where applicable, the previously visited page (referrer)

The purpose is to deliver the page, keep operations secure and stable and investigate misuse. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in a functioning and attack-resistant website. This data is neither merged with other sources nor evaluated for marketing purposes.

Retention: log data is deleted after 30 days at the latest, unless it is exceptionally needed longer to investigate a specific security incident.

The technical operation of this website is handled by a processor inside the European Union under an agreement pursuant to Art. 28 GDPR.

4.

Fonts and embedded contentDirect link to this clause

The typefaces used on this website (Geist, Geist Mono and Poppins) are downloaded at build time and served together with the page. Loading a page opens no connection to Google Fonts, and no IP address is transmitted to Google.

Every other element — graphics, diagrams, animations and scripts — is hosted on our own server as well. Videos, maps, social network buttons and embedded booking frames are deliberately not included.

5.

CookiesDirect link to this clause

The public part of this website sets no cookies. Two cookies exist only in the protected provider area, and only once you enter something:

cusea_msp_access
Remembers a redeemed access code so provider pricing stays visible after unlocking. Contains a signed identifier of the grant, no plain text. Lifetime: 12 months.
cusea_msp_admin
Session cookie of the internal administration interface. Lifetime: 12 hours.

Both cookies are set httpOnly and sameSite=lax, so JavaScript cannot read them, and neither carries an identifier that would recognise you across other websites. They are strictly necessary to provide the service you expressly requested within the meaning of § 25 (2) no. 2 TDDDG, so no consent is required. The legal basis for the subsequent processing is Art. 6 (1) (b) GDPR.

6.

Voice demoDirect link to this clause

On the Voice Agents page you can hold a conversation with an AI voice agent. The demo starts only if you enter a name and actively begin the call. Without that click no microphone is addressed and no connection is opened.

During the call we process: the name you entered, the page language, your speech input and its transcript. Speech processing runs through ElevenLabs on the EU residency endpoint api.eu.residency.elevenlabs.io.

After you hang up, the transcript your browser already holds is sent to our server once and summarised there by a language model into a sample case. By default that summary runs on the IONOS AI Model Hub with inference in Germany; inputs are not used to train models. The case is shown to you and is not stored by us — reloading the page removes it.

A call is capped at 180 seconds. Please do not mention real personal data about third parties or confidential content in the demo — none of it is needed for the walkthrough.

The legal basis is your consent under Art. 6 (1) (a) GDPR, which you give by starting the call and can withdraw at any time with effect for the future by ending it.

7.

Provider pricing, booking, emailDirect link to this clause

Provider access. We release pricing for managed service providers after a call, using a personal code. Our register holds the form of address, first and last name, company, email address, an internal note and the creation, redemption and expiry of the code. The purpose is issuing and administering that access; the legal basis is Art. 6 (1) (b) or (f) GDPR. Access details are sent by email through our mail server. Once access expires or is revoked we delete the entry, unless a statutory retention obligation applies.

Booking a demo. The “Book a demo” buttons lead to a SOMI Group booking system at booking.somi.one. You enter your data only there; no booking frame is embedded in this page, so nothing is transmitted without your click. The privacy notice of that service applies to the booking.

Contact by email. If you write to us, we process your details to handle the enquiry and any follow-up. The legal basis is Art. 6 (1) (b) GDPR for contract-related enquiries and otherwise Art. 6 (1) (f) GDPR. We delete the correspondence once it is settled and no commercial or tax retention period of six or ten years applies any more.

8.

Processing inside the CUSEA platformDirect link to this clause

The purpose is to provide and operate an AI-supported IT service desk: capturing, classifying, handling, resolving and documenting service requests via telephony/voice, email, chat/Teams and the web portal, plus device management where the add-on is booked. This involves master and contact data, communication content, recordings and transcripts where the voice channel is active, device and diagnostic data where the Workplace add-on is booked, and authentication and log data. Special categories of personal data under Art. 9 GDPR are not the subject of the processing.

Place of processing. We use locations or EU data residency options inside the EU or EEA exclusively. Where processing exceptionally takes place in a third country, we ensure appropriate safeguards under Art. 44 et seq. GDPR — in particular EU standard contractual clauses and, where applicable, an adequacy decision.

Subprocessors. § 7 of the DPA lists the services in use conclusively. We inform customers of intended changes in good time in advance; they may object for good cause. The current list is available in the platform under “Tarif & Vertrag → AVV” and on request via datenschutz@somi.de.

Telephony origination (PSTN/SIP trunk) runs through telecommunications providers which are independent controllers subject to telecommunications secrecy and are not subprocessors.

Breach notification. We report personal data breaches to the customer without undue delay, and at the latest within 48 hours of becoming aware of them.

After the contract ends we return the data in a common format or delete it in a compliant manner, at the customer’s choice, unless a statutory retention obligation applies. Deletion is confirmed on request. Clause 9.4 of the terms and § 9 of the DPA set out the details.

9.

SecurityDirect link to this clause

Traffic to this website is TLS-encrypted throughout. Remote access to endpoints as part of the managed services runs exclusively over secured, encrypted connections and is logged.

The technical and organisational measures under Art. 32 GDPR form Annex 2 to the DPA and cover, among others, physical access, system access, data access and separation control, pseudonymisation, transfer and input control, availability and resilience control, and procedures for regular review. Compliance is evidenced by certification to ISO/IEC 27001:2022 (reg. no. 01 153 2500849, TÜV Rheinland Cert, valid until 19 May 2029). We provide the certificate and the catalogue of measures on request via datenschutz@somi.de.

10.

Your rightsDirect link to this clause

You have the following rights against us:

  • Access to the data processed about you (Art. 15 GDPR)
  • Rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • Erasure, unless a statutory retention obligation applies (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a common, machine-readable format (Art. 20 GDPR)
  • Objection to processing based on a legitimate interest (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)

An informal message to datenschutz@somi.de is enough. We reply within the time limits of Art. 12 GDPR.

Independently of this you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, place of work or the alleged infringement. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information in Wiesbaden (datenschutz.hessen.de).

11.

Changes to this policyDirect link to this clause

We update this policy when the processing changes — because a feature is added or a service provider changes, for instance. The version published here is the one that applies. Material changes affecting existing customers are additionally communicated under the rules of the service agreement.

This privacy policy was last updated on 31 August 2026.

Other documents