The original legal text is written in German to meet legal rules in Germany and the EU. This English version was created by AI (GPT) for convenience and is not legally binding. If there are differences between the two, the German version below is the official one.
Privacy Policy of Gilu AI
This Privacy Policy of Gojambel GmbH ("Gilu AI"), Undinestr. 3, 81927 Munich, provides information on the collection, processing, and use of personal data in accordance with the General Data Protection Regulation (GDPR).
The protection of personal data is a matter of great importance to us. In this Privacy Policy, we explain whether and for what purposes personal data is collected and processed. We comply with all applicable data protection and data security regulations. Our employees are regularly trained and bound to confidentiality and compliance with all data protection requirements.
The controller within the meaning of Art. 4 No. 7 GDPR is:
Gojambel GmbH - Gilu AI
Undinestr. 3, 81927 Munich
Email: hello@gilu.ai
Phone: +49 176 63829541
a) Contact Form
Collected data: First name, last name, email address, phone number, message.
Purpose: To initiate contact and respond to inquiries.
Legal basis: Art. 6(1)(a), (b), (f) GDPR
b) Contact via Email
Processing of transmitted contact data (name, email address, message content).
Legal basis: Art. 6(1)(b), (f) GDPR
c) Product Data and AI Monitoring Content
When customers use the product, we process the information they enter and generate in the platform, including brand profiles, website URLs, competitor names, prompts, AI model responses, citations, run history, analytics, and CSV exports. This data is used to provide monitoring, reporting, troubleshooting, and account administration features.
Legal basis: Art. 6(1)(b), (f) GDPR
d) Cookies
Use of technically necessary cookies and locally stored consent preferences. Optional categories are only used after consent. The consent banner is operated locally/offline and does not transmit consent records to c15t or a hosted consent provider.
Legal basis: Art. 6(1)(f) GDPR, Art. 6(1)(a) GDPR where consent is required, and § 25 TTDSG
e) Server logs and operational analytics
We process technically necessary server logs and basic operational usage data to provide, secure, troubleshoot, and improve the website and product. Product analytics, where used, are operated through a self-hosted OpenPanel setup. Optional analytics or marketing cookies are only used where consent is required and has been given through our consent banner.
Legal basis: Art. 6(1)(f) GDPR for security and operations; Art. 6(1)(a) GDPR and § 25 TTDSG where consent is required.
f) Marketing Email Opt-In
If users voluntarily subscribe to product updates, newsletters, or an AI visibility brief, we process the submitted email address and related opt-in metadata to send those messages. Marketing emails are only sent after opt-in and can be unsubscribed from at any time via the unsubscribe link in the email or by contacting us.
Legal basis: Art. 6(1)(a) GDPR and § 7 UWG where applicable.
Processing is carried out exclusively for the following purposes:
Data is only disclosed where necessary to fulfill a contract or where legally required. Disclosure to public authorities occurs only within the framework of mandatory statutory provisions.
Data is stored only as long as necessary for the respective purpose. It will be deleted once that purpose no longer applies, unless retention is required by statutory obligations.
The following table provides an overview of our currently commissioned service providers and processors:
| Name | Service | Data Processing Location | Agreement (DPA/SCCs) |
|---|---|---|---|
| Hetzner | Infrastructure service provider | Germany | Yes |
| Lettermint B.V. | Email delivery | Netherlands / EU | EU-based provider; DPA where applicable |
| Armitage Labs OÜ / Creem.io | Payment processing | Estonia / EU | EU-based provider; payment-related controller obligations may apply |
| OpenRouter | AI model routing to included providers, currently OpenAI, Google, Meta, and Perplexity. OpenRouter is not used by us as storage for customer prompts. | USA / international | OpenRouter DPA/SCCs where applicable |
| Optional OAuth sign-in | EU / USA | Google data processing terms/SCCs |
Physical Access Control
System Access Control
Data Access Control
Separation Control
Pseudonymisation and Encryption
Input Control
Data Transfer Control
These TOMs are reviewed regularly and adjusted as necessary to reflect new technical or legal requirements.
We reserve the right to amend this Privacy Policy as necessary. Please check this page regularly for the latest version.
As of: November 2025
Datenschutzerklärung von Gilu AI
Die vorliegende Datenschutzerklärung der Gojambel GmbH ("Gilu AI"), Undinestr. 3, 81927 München, informiert über die Erhebung, Verarbeitung und Nutzung personenbezogener Daten gemäß der Datenschutz-Grundverordnung (DSGVO).
Der Schutz personenbezogener Daten ist uns ein wichtiges Anliegen. In dieser Datenschutzerklärung erläutern wir, ob und zu welchem Zweck personenbezogene Daten erhoben und verarbeitet werden. Wir halten uns an alle geltenden Datenschutz- und Datensicherheitsvorschriften. Unsere Mitarbeitenden werden regelmäßig geschult und zur Vertraulichkeit sowie zur Einhaltung sämtlicher datenschutzrechtlicher Bestimmungen verpflichtet.
Verantwortlicher im Sinne von Art. 4 Nr. 7 DSGVO ist:
Gojambel GmbH - Gilu AI
Undinestr. 3
81927 München
E-Mail: hello@gilu.ai
Telefon: +49 176 63829541
a) Kontaktformular
Erhebung von: Name, Nachname, E-Mail-Adresse, Telefonnummer, Nachricht.
Zweck: Kontaktaufnahme und Beantwortung der Anfrage.
Rechtsgrundlage: Art. 6 Abs. 1 lit. a), b), f) DSGVO
b) Kontaktaufnahme via E-Mail
Verarbeitung der übermittelten Kontaktdaten (Name, E-Mail-Adresse, Inhalt).
Rechtsgrundlage: Art. 6 Abs. 1 lit. b), f) DSGVO
c) Produktdaten und KI-Monitoring-Inhalte
Wenn Kunden das Produkt nutzen, verarbeiten wir die in der Plattform eingegebenen und erzeugten Informationen, einschließlich Brand Profiles, Website-URLs, Wettbewerbern, Prompts, KI-Modellantworten, Zitierungen, Run-Historie, Analysen und CSV-Exporten. Diese Daten werden zur Bereitstellung von Monitoring, Reporting, Fehlerbehebung und Kontoverwaltungsfunktionen verarbeitet.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b), f) DSGVO
d) Cookies
Verwendung technisch notwendiger Cookies sowie lokal gespeicherter Consent-Präferenzen. Optionale Kategorien werden nur nach Einwilligung genutzt. Das Consent-Banner wird lokal/offline betrieben und übermittelt keine Consent-Datensätze an c15t oder einen gehosteten Consent-Anbieter.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO, Art. 6 Abs. 1 lit. a DSGVO soweit eine Einwilligung erforderlich ist, sowie § 25 TTDSG
e) Server-Logs und betriebliche Nutzungsdaten
Wir verarbeiten technisch notwendige Server-Logs und grundlegende betriebliche Nutzungsdaten, um Website und Produkt bereitzustellen, abzusichern, Fehler zu beheben und zu verbessern. Produktanalyse wird, soweit eingesetzt, über eine selbst gehostete OpenPanel-Installation betrieben. Optionale Analyse- oder Marketing-Cookies werden nur eingesetzt, soweit eine Einwilligung erforderlich ist und über das Consent-Banner erteilt wurde.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO für Sicherheit und Betrieb; Art. 6 Abs. 1 lit. a DSGVO und § 25 TTDSG, soweit eine Einwilligung erforderlich ist.
f) Marketing-E-Mail-Opt-in
Wenn Nutzer freiwillig Produktupdates, Newsletter oder einen AI Visibility Brief abonnieren, verarbeiten wir die angegebene E-Mail-Adresse und zugehörige Opt-in-Metadaten zum Versand dieser Nachrichten. Marketing-E-Mails werden nur nach Opt-in versendet und können jederzeit über den Abmeldelink in der E-Mail oder durch Kontaktaufnahme mit uns abbestellt werden.
Rechtsgrundlage: Art. 6 Abs. 1 lit. a DSGVO und § 7 UWG, soweit anwendbar.
Verarbeitung erfolgt ausschließlich zur:
Daten werden nur weitergegeben, wenn dies zur Vertragserfüllung erforderlich ist oder gesetzlich vorgeschrieben. Eine Datenübermittlung an Behörden erfolgt nur im Rahmen zwingender gesetzlicher Vorschriften.
Daten werden nur so lange gespeichert, wie dies für den jeweiligen Zweck notwendig ist. Danach erfolgt eine Löschung, sofern keine gesetzlichen Aufbewahrungspflichten entgegenstehen.
Die nachfolgende Tabelle gibt eine Übersicht über der von uns eingesetzten Auftragsverarbeiter und die wesentlichen Dienstleister:
| Name | Leistung | Datenverarbeitung in | Vertrag (AVV/SCCs) |
|---|---|---|---|
| Hetzner | Infrastructure service provider | Deutschland | Ja |
| Lettermint B.V. | E-Mail-Versand | Niederlande / EU | EU-Anbieter; AVV soweit anwendbar |
| Armitage Labs OÜ / Creem.io | Zahlungsabwicklung | Estland / EU | EU-Anbieter; zahlungsbezogene Verantwortlichkeit kann gelten |
| OpenRouter | KI-Modell-Routing zu den eingebundenen Anbietern, derzeit OpenAI, Anthropic, Google, Meta und Perplexity. OpenRouter wird von uns nicht als Speicher für Kunden-Prompts genutzt. | USA / international | OpenRouter-AVV/SCCs soweit anwendbar |
| Optionaler OAuth-Login | EU / USA | Google-Datenverarbeitungsbedingungen/SCCs |
Zutrittskontrolle
Zugangskontrolle
Zugriffskontrolle
Trennung
Pseudonymisierung und Verschlüsselung
Eingabekontrolle
Weitergabekontrolle
Diese TOMs werden regelmäßig überprüft und bei Bedarf an neue technische oder gesetzliche Anforderungen angepasst.
Wir behalten uns vor, diese Erklärung bei Bedarf anzupassen. Bitte prüfen Sie regelmäßig den aktuellen Stand.
Stand: November 2025