Michy
How it works Why trust it Who it’s for Blog
Start with your model

Legal

Privacy

How we process personal data on this website.

1. Controller

Nerando GmbH
Managing director Henning Lategahn
Grenzweg 12, 76327 Pfinztal, Germany
Email: henning@meetmichy.ai

Michy is a product of Nerando GmbH, not a separate company. Nerando GmbH is the controller for the processing described on this page.

2. Data protection officer

We have not appointed a data protection officer. Nerando GmbH does not currently have twenty people continuously engaged in automated processing of personal data (section 38 (1) BDSG). The conditions of Article 37 (1) GDPR are, on our assessment, also not met.

3. What this website does not do

This website does not set cookies. It does not write to your browser’s storage, and it does not read from it. There is no analytics, statistics or tracking service, and no advertising conversion tag.

Because nothing is stored on or read from your device for that purpose, the operation of this website does not require consent under section 25 (1) TDDDG. There is no consent banner — not from neglect, but because there is nothing to consent to on that basis.

The exception is webfonts, described in section 5. They are loaded from Google’s servers, so a visit does reach a third party.

4. Visiting the website and server logs

The website is delivered by Bunny.net, BunnyWay d.o.o., Slovenia, as a processor.

Each request is logged: time, requested address, HTTP status code, bytes transferred, referring address, browser identification (user-agent), country, delivering location, and the IP address in truncated form. Truncation removes the trailing part of the address. We still treat these data as personal, because a truncated prefix can still be linked to a person depending on the connection.

The purposes are operating and delivering the website, detecting technical faults, defending against abuse and overload, and a summarised view of traffic. That view does not recognise individual visitors: it counts page views, countries of origin and referring addresses, not people.

The legal basis is Article 6 (1) (f) GDPR. The legitimate interest is a technically sound, secure website and an understanding of whether it is used. The processing is necessary because without a log a failure cannot be tied to a cause and an attack cannot be told from ordinary traffic; the truncated IP address is the smallest form in which repeat requests from the same source remain visible at all. Our interest prevails in the balancing test because no profile is built, the address is truncated, and the entry is deleted after 30 days — a by-product of delivery from which nobody can be named.

Only European delivery locations are enabled. Requests from other regions are also answered from the EU, so the log data arise and remain in the EU. They are also archived in a separate storage area of the same provider and deleted there after 30 days.

5. Webfonts

The pages load typefaces from Google Fonts. The stylesheet is requested from fonts.googleapis.com; the font files from fonts.gstatic.com. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, operates the service. A transfer to the United States is not excluded; Google relies on the EU-US Data Privacy Framework and, in addition, on standard contractual clauses.

Google receives your IP address, the requested file, the referrer and your browser identification. We do not send Google a name or an email address. The purpose is to display the typefaces specified for this site. The legal basis we currently rely on is Article 6 (1) (f) GDPR, with the legitimate interest of a consistent visual presentation. System fonts would work; the Google request is therefore not strictly necessary for the site to function. If you do not want this request to be made, you can block third-party fonts in your browser.

6. The email field

The “Start with your model” field collects the work email address you type. An invisible extra field is present only as spam defence: automated programs often fill every field, while a person does not see it. If it is filled, the request is discarded and not processed further. The legal basis for that check is Article 6 (1) (f) GDPR, with the legitimate interest of keeping automated entries out.

If the invisible field is empty, we store your address so we can reply within one working day, as the page offers. The legal basis is Article 6 (1) (b) GDPR: the processing is necessary to take steps at your request. There is no newsletter, no automated sequence, and no passing of your address to third parties for their own marketing.

The request is not stored on the web server. It is handed to the automation service n8n Cloud, written to the CRM Attio, and a notice is sent to us through Google Workspace. Those recipients are named in section 7. The CRM record remains until you object, and for no longer than 24 months after the last contact.

7. Recipients

The providers below process data only on our instructions and on the basis of an agreement under Article 28 GDPR, unless stated otherwise.

Bunny.net (delivery)

BunnyWay d.o.o., Slovenia. Delivery of the website and server logs under section 4. Because only European locations are enabled, there is no transfer to a third country for that processing.

Google Fonts (typefaces)

Google Ireland Limited, Ireland, as described in section 5. Google acts as its own controller for the font service.

n8n Cloud (form request)

n8n GmbH, Berlin. Receives the form request and passes it on. The service runs on Microsoft Azure in the Germany (Frankfurt) region; Microsoft is therefore a sub-processor.

Attio (CRM)

Attio Limited, 42 St John’s Square, 2nd Floor, London EC1M 4EA, United Kingdom. Stores the request with the email address and, where present, campaign parameters. The transfer to the United Kingdom relies on the European Commission’s adequacy decision of 19 December 2025, which applies until 27 December 2031. Attio uses its own sub-processors, including recipients in the United States, and relies on standard contractual clauses for those. The enrichment that could send contact data to services in the United States is switched off in our workspace; your email address is not sent there.

Google Workspace (mail)

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Sends the internal notice that a request arrived. A transfer to the United States is not excluded; Google relies on the EU-US Data Privacy Framework and, in addition, on standard contractual clauses.

8. Security

The website is delivered only over an encrypted connection (TLS). Access to the systems named here is currently limited to the managing director. Each account through which personal data can be reached is protected by a unique password from a password manager and by a second factor — for the mail system’s administration access, by a hardware security key. The devices used are fully encrypted and lock themselves.

Availability includes backups, and those have a consequence we do not hide: if an entry is deleted, it does not disappear everywhere at the same moment. Backups of the services involved may still hold it for a limited time. They are not reused and expire under each provider’s own retention.

9. Your rights

You have the right of access to personal data stored about you (Article 15 GDPR), to rectification of inaccurate data (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20), and to object to processing (Article 21). The right to object applies in particular to processing based on a legitimate interest: the server logs in section 4, the webfonts in section 5, and the spam field in section 6.

Independently of that, you may lodge a complaint with a supervisory authority (Article 77 GDPR). The authority at the controller’s seat is:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
P.O. Box 10 29 32, 70025 Stuttgart, Germany
Office: Heilbronner Straße 35, 70191 Stuttgart
Telephone +49 711 615541-0, poststelle@lfdi.bwl.de

10. No automated decision-making

There is no automated decision-making, including profiling, under Article 22 GDPR.

11. Whether you have to provide data

You are not obliged to provide data. Visiting the site generates the server logs in section 4 in any event. Without an email address we cannot reply. No further disadvantage arises.

12. Status of this notice

As of 14 September 2026. We will amend this notice as soon as the processing described here changes.

Michy
How it works Why trust it Blog Who it’s for

Michy

© 2026 Nerando GmbH · Impressum · Privacy

How it works Why trust it Who it’s for Blog
Start with your model