Privacy Policy
DANIC Tech GmbH — for our website and for the use of BeeHive, BeeKeeper and the customer portal
1 Controller and contact
| Field | Details |
|---|---|
| Controller | DANIC Tech GmbH, represented by the managing directors Nicolas Schulwitz and Daniel Deckert |
| Address | Augustastraße 32, 12203 Berlin, Germany |
| Register | Amtsgericht Charlottenburg, HRB 288412 B |
| Data protection contact | datenschutz@danic.ai |
| General contact | kontakt@danic.ai |
No data protection officer has been appointed; there is currently no statutory duty to appoint one. The contact point above is not an appointment within the meaning of Articles 37 et seq. GDPR.
2 Guide
This policy covers two separate areas. Which one applies to you depends on how you come into contact with us.
| If you … | this applies to you |
|---|---|
| visit our website, use the contact form, subscribe to our newsletter or apply for a position | Section 3 |
| create an account in the customer portal, are invited, install BeeKeeper or use BeeHive | Section 4 |
| were invited as an employee of a company that has a contract with us | Section 4.2 — for most of this data your employer is the controller, not us |
3 Our website
3.1 Server log files
When you call up our website, data that your browser transmits is collected automatically: IP address, date and time, page accessed, referrer, browser type and operating system. The purpose is technically fault-free delivery and the defence against attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure operation. Storage period: 48 hours at most.
3.2 Cookies and consent management
We distinguish three categories:
| Category | Content | Legal basis |
|---|---|---|
| Necessary | Technically required, always active | § 25(2) TDDDG; Art. 6(1)(f) GDPR |
| Analytics | PostHog, see 3.3 — only with your consent | § 25(1) TDDDG; Art. 6(1)(a) GDPR |
| Marketing | Optional, only with your consent | § 25(1) TDDDG; Art. 6(1)(a) GDPR |
We operate the consent management ourselves; no external service is used. We store your selection in the cookie danic_consent for about six months. Logging on our server takes place without storing the raw IP address. You may withdraw your consent at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.
3.3 Web analytics with PostHog
With your consent we use PostHog to measure reach. The provider is PostHog, Inc., San Francisco, USA. Usage behaviour, device and browser information and a truncated IP address are collected. Cross-site tracking does not take place. Recording of sessions is optional. The legal basis is Art. 6(1)(a) GDPR. We base the transfer to the USA on the provider’s certification under the EU-U.S. Data Privacy Framework.
PostHog is integrated exclusively on our website. No product analytics by PostHog takes place in BeeHive, BeeKeeper or the customer portal.
3.4 Contact
If you write to us via the contact form or by email, we process the information you provide in order to handle your request. The legal basis is Art. 6(1)(b) GDPR insofar as it concerns the initiation or performance of a contract, and otherwise Art. 6(1)(f) GDPR. We delete the information once the purpose has ceased — as a rule after the conversation has ended, unless statutory retention periods stand in the way. We delete technical metadata such as IP address and timestamp after seven days at most.
3.5 Applications
We process application documents in order to carry out the application procedure on the basis of § 26(1) BDSG and Art. 6(1)(b) GDPR. We delete them six months after the procedure has ended at the latest, unless you have agreed to longer storage.
3.6 Newsletter and transactional emails
We use Brevo for sending. The provider is Sendinblue SAS, Paris, France; the servers are located exclusively in the EU (France, Germany, Belgium). Brevo is our processor. For the newsletter the legal basis is your consent under Art. 6(1)(a) GDPR; you may withdraw it at any time via the unsubscribe link. For operational transactional emails — such as invitations and sign-in links — the legal basis is Art. 6(1)(b) GDPR.
4 Use of our products: BeeHive, BeeKeeper and the customer portal
4.1 Scope
This section applies to registration for and use of our customer portal and of the development environment BeeKeeper installed locally on your device, with BeeHive content. Sections under 3 apply to our website.
4.2 Who is responsible for what
Where a company, as our customer, creates employees in a workspace or invites them, we process that data on behalf of the customer on the basis of a data processing agreement under Art. 28 GDPR. The customer is the controller in that respect. Please address your rights as a data subject to your employer; we will support the employer in doing so.
We are independently responsible for operation, registration and authentication, enforcement of the licence, defence against misuse and fraud, for records of the contract, billing and operational metrics. The following sections apply to that.
4.3 Registration and sequence
Access comes into being in a fixed sequence:
- The person authorised to represent the customer signs the contract including the data processing agreement and sends both back to us. The contract and the data processing agreement are thereby concluded. (Alternatively, the data processing agreement may be accepted electronically later.)
- We record the signed data processing agreement with a timestamp and send that person a link to download BeeKeeper together with an invitation.
- That person installs BeeKeeper, signs in there and then to BeeHive, and creates the organisation. The trial period starts when the organisation is created.
- That person invites the people who are to collaborate.
- The invited people accept the invitation, sign in to BeeKeeper and can use BeeHive.
Without acceptance of the data processing agreement, no further people can be invited and no permissions can be assigned. We therefore do not process any personal data on behalf of the customer before that contract has been concluded (Art. 28(3) GDPR).
The sign-in data of the person authorised to represent the customer from step 3 (sign-in) arises before processing on behalf of the customer. We are independently responsible for it: we process it in order to perform the contract already signed, on the basis of Art. 6(1)(b) GDPR. The details are set out in Section 4.4.
If you were invited: your employer entered your business email address. We process it on behalf of your employer, on the basis of the data processing agreement that already exists at that time. Your employer is the controller; see Section 4.2.
For sign-in you may choose Google or GitHub as an identity provider or use a sign-in link by email. If you choose an identity provider, we receive an identity confirmation from that provider; the provider acts as its own controller for your account there. We also record which of these routes you used to sign in and whether it is an organisation or a personal workspace.
Before the contract is concluded we process only the contact details required for sending and returning the contract, together with the technical data that arises in any event when our pages are called up: the server log files under Section 3.1 and the bot protection. The legal basis is Art. 6(1)(b) GDPR for pre-contractual measures and Art. 6(1)(f) GDPR for protecting sign-in against automated access.
4.4 Data, purposes and legal bases
| Category | Purpose | Legal basis |
|---|---|---|
| Registration and account data: display name, business email address, user ID, workspace, role, type of workspace and sign-in route | Creating the account, providing the product | Art. 6(1)(b) GDPR |
| Sign-in data: session token, sign-in events, sign-in links; where sign-in is via Google or GitHub, the provider’s identity confirmation | Sign-in, session management, account security | Art. 6(1)(b) and (f) GDPR |
| Licence and permission data per workspace: plan, term, status, unlocked command catalogue, number of permissions assigned. This includes a signed licence statement that BeeKeeper fetches and caches locally on your device; without a connection it remains effective for 24 hours at most. | Provision and enforcement of the licence | Art. 6(1)(b) and (f) GDPR |
| Device and access data of key release: device identifier, timestamp. We do not collect IP addresses in this context. Issued decryption keys are limited to seven days at most. | Detection and defence against misuse, protection of our trade secrets | Art. 6(1)(f) GDPR |
| Organisation data from sign-in: name, address and contact person of the organisation and — where provided — the VAT identification number | Formation and performance of the contractual relationship | Art. 6(1)(b) GDPR |
| Usage data without content, pseudonymised: invocation of commands and functions with frequency, error and abort events, product version, operating system, workspace and pseudonymous user identifier. No prompts, no model responses, no source code, no repository contents, no work results, no file names or paths. Collection begins only once we display it in the product and you have consented; until then we collect no usage data. | Improving the product and the customer experience, more targeted support in the event of faults; principle of data minimisation | § 25(1) TDDDG; Art. 6(1)(a) GDPR (consent) |
| Log and audit data and operational metrics: event type, workspace, acting person, result — without prompts, without repository contents, without secrets | Traceability, security, operation | Art. 6(1)(f) GDPR |
| Contractual records: accepted versions of the contract with version number, SHA-256 checksum, time and acting person | Evidence of conclusion of the contract | Art. 6(1)(b), (c) and (f) GDPR |
| Billing data: plan, term, payment status, invoice data | Billing, commercial and tax obligations | Art. 6(1)(b) and (c) GDPR |
| Support communication and support materials deliberately sent to us | Handling the request; for customer content, on behalf of the customer | Art. 6(1)(b) GDPR; on behalf of the customer, Art. 28 GDPR |
| Feedback that you deliberately send us (error reports, suggestions for improvement) | Handling your notice, improving the product | Art. 6(1)(f) GDPR |
4.5 What we do not process
Where the products are used as intended, inputs to the language model (prompts), model responses, source code, repository contents and work results do not reach us. The agents run in a protected area on your device and, from there, speak via Claude Code directly with your own account at the language model provider. We have no access to that connection.
- Sign-in with the model provider takes place in the protected area; the credentials remain on your device and do not reach us.
- Access to your repositories takes place exclusively locally on your device and under your own credentials. Our systems are not involved.
- From use of the product we store no IP addresses and no full payment-card data.
- Settings and project data that you enter locally in BeeKeeper remain in a local database on your device and do not reach us. The display name you assigned when signing in is, by contrast, account data (Section 4.4) and appears in member lists and invitations.
- The usage data under Section 4.4 contains no content. We see that a command was invoked — not with what. It is pseudonymised and is not used to assess the behaviour of individual persons.
- We do not use customer content for training or fine-tuning AI models.
The only exception is material that someone deliberately sends us for error analysis. We do not review such transmissions for their content in advance; we process them only for the support case in question.
4.6 Automatic updates
BeeKeeper updates itself automatically. In doing so, version information is retrieved and signed program files are loaded. Content from your device is not transferred. The legal basis is Art. 6(1)(b) GDPR, supplemented by point (f) on account of our interest in a secure and up-to-date state of the software.
4.7 Recipients and places of processing
| Recipient | Service and location | Role |
|---|---|---|
| Cloudflare, Inc. | Hosting, application execution, database and object storage with EU jurisdiction, bot protection at registration, DDoS protection and HTTP observability. Execution may take place via the provider’s global network. | Processor |
| Supabase, Inc. | Identity and sign-in service, region eu-central-1 (Frankfurt). | Processor |
| Sendinblue SAS (Brevo) | Sending of operational transactional emails such as invitations and sign-in links; servers in the EU. | Processor |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing, exclusively for contracts that are subject to a charge. Not used during the free trial. | Independent controller |
| Google LLC · GitHub, Inc. | Optional sign-in via these identity providers, if you choose them. | Independent controllers |
The provider of the language model and your own development platform are not on this list. You use them on the basis of your own contracts; we are not involved and receive no data from there.
4.8 Transfers to third countries
Where a transfer to a third country takes place, we base it on an adequacy decision — including the EU-U.S. Data Privacy Framework for certified recipients — or on the standard contractual clauses of the European Commission pursuant to Implementing Decision (EU) 2021/914, supplemented by encryption in transit and at rest and by data minimisation. We provide the contracts in force with our service providers on request, to a reasonable extent.
4.9 Storage period
| Category | Period |
|---|---|
| Device and access data of key release | 48 hours |
| Account, workspace and membership data | without undue delay on the customer’s instruction; under the trial agreement otherwise 90 days after the end of the trial (unless release was requested earlier), under a paid contract 30 days after the end of the contract |
| Accounts never confirmed and orphaned directory entries | 30 days |
| Expired or withdrawn invitations | 90 days |
| Log and audit data, operational metrics | 12 months |
| Feedback submitted by the user | 12 months after receipt |
| Support materials | 12 months after the support case is closed |
| Database backups | rolling 30 days |
| Contractual records and billing data | for the duration of the statutory retention and evidence obligations |
4.10 Data processing agreement
For processing that we carry out on behalf of a customer, the data processing agreement applies which the person authorised to represent the customer as a rule signs together with the main contract (or, alternatively, accepts electronically after signing in). It describes the subject matter, nature and purpose of the processing, the categories of data and data subjects, the technical and organisational measures, the sub-processors and the deletion concept. Customers receive it with the contract or in the customer portal.
5 Your rights
Under the General Data Protection Regulation you have the following rights:
| Right | Content |
|---|---|
| Access (Art. 15) | Confirmation of whether we process data concerning you, and information about that data |
| Rectification (Art. 16) | Rectification of inaccurate data and completion of incomplete data |
| Erasure (Art. 17) | Erasure, unless a retention obligation stands in the way |
| Restriction (Art. 18) | Restriction of processing |
| Data portability (Art. 20) | Provision in a commonly used, machine-readable format |
| Objection (Art. 21) | Objection to processing that we base on a legitimate interest |
| Withdrawal (Art. 7(3)) | Withdrawal of consent given, with effect for the future |
| Complaint (Art. 77) | Complaint to a supervisory authority |
Please contact datenschutz@danic.ai for this purpose.
If you are an employee of a company that uses our products, please direct your request to your employer. The employer is the controller for that processing; we support the employer in responding.
6 Competent supervisory authority
7 Changes to this policy
We adapt this policy when our processing activities or the legal situation change. Each version carries a version number and a date. We keep earlier versions available for retrieval, because our contracts refer to the version in force when the contract was concluded.
| Version | Effective from | Material change |
|---|---|---|
| v2.2 | 29.09.2026 | Data processing agreement acceptance: the agreement is as a rule signed together with the contract (electronic acceptance remains an alternative); the trial period starts when the organisation is created (4.3, 4.10). |
| v2.1 | 29.09.2026, 16:04 | Alignment with development (code review of 28.09.): usage data only after consent (§ 25(1) TDDDG), display name as account data instead of local, model-provider credentials remain local, trial-customer data 90 days after the end of the trial, VAT ID and feedback added |
| v2.0 | — (draft, not published) | New Section 4 on use of the products; clarification of roles; recipients, third-country transfer and storage periods added; data protection contact changed to datenschutz@danic.ai |
| v1.0 | 13.05.2026 | First version, website only |