Privacy Policy

Last updated: August 14, 2026

This English version is a translation provided for convenience. In case of any discrepancy, the German version prevails.

1. Controller

The controller for the data processing on makiro.de and in the makiro application is:

Tojiki — Inhaber Jakob Mayr
Kirchweg 30, 83043 Bad Aibling
Telephone: +49 171 264 95 80
Email: info@tojiki.de

There is no statutory obligation to appoint a data protection officer. For all data protection matters you can reach us at the email address given above.

2. Two roles: our own processing and processing on your behalf

As controller we process the data arising in connection with your user account — registration, use of the application, billing, support.

As processor we process the personal data that you as a user bring into makiro or have processed through the application — in particular the data of your own customers (emails, messages, appointments, documents, enquiries via your website). For this you are the controller within the meaning of the GDPR; we act exclusively on your instructions. We make a data processing agreement pursuant to Art. 28 GDPR available on request at info@tojiki.de.

3. Hosting and server log files

The application and the public websites are hosted with Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). The execution of the server functions is pinned to the Frankfurt am Main region (“fra1”).

When a page is accessed, the hosting provider processes technically necessary connection data (IP address, time, resource requested, referrer, user agent) in order to deliver the page and to secure operations. The legal basis is our legitimate interest in secure and trouble-free operation (Art. 6 (1) lit. f GDPR).

4. User account and sign-in

For signing in we use Neon Auth, a service of Neon Inc. (USA). Processed are your email address, your name (insofar as provided) as well as sign-in times and session information. If you sign in via Google, we receive your email address, your name and your Google user ID from Google; we never receive your Google password.

The legal basis is the performance of the usage contract (Art. 6 (1) lit. b GDPR). The session is maintained by means of a technically necessary cookie.

When your account is created we store, where present, the campaign identifier of the link you arrived through (utm parameters), the click ID of a Google ad (gclid) and the domain of the page that referred you to us. This tells us which channels bring customers to us. The legal basis is our legitimate interest in evaluating our advertising (Art. 6 (1) lit. f GDPR). Nothing is stored on your device for this; the data is deleted together with your account.

5. Database and storage

Application data is stored in a PostgreSQL database of Neon Inc. with the server located in Frankfurt am Main (AWS region eu-central-1). Particularly sensitive content — messages and subject lines, draft replies and notes, contact details, tasks, conversation transcripts as well as the access credentials for connected accounts — is additionally stored in encrypted form (AES-256-GCM). Which data belongs to which account is enforced by the database itself and not only by the application.

Uploaded and generated files (documents, images) are stored by us in Vercel Blob. These files are not publicly retrievable; access takes place exclusively via access-protected download routes of the application.

6. Voice-based onboarding conversations

The onboarding and parts of the application can be conducted as a voice conversation with an AI agent. For this we use ElevenLabs Inc. (USA). Processed are your voice input, the transcript produced from it and the conversation metadata.

Before the conversation begins you are informed that the conversation is being recorded and transcribed and that you are speaking with an AI agent and not with a human being; the processing takes place only after your express consent (Art. 6 (1) lit. a GDPR). You may withdraw your consent at any time with effect for the future.

Raw transcripts and audio references are automatically deleted 30 days after the conversation. Only the structured information derived from them is retained, on which your strategy and content documents are based.

7. Use of AI language models

In order to produce texts, summaries, suggested replies and strategy content, we transmit the content required for this to an AI provider. Anthropic PBC (USA) is used.

Only the content necessary for the respective task is transmitted (e.g. the text of a message, your profile and strategy information). Under the provider's terms, data transmitted via the programming interface is not used to train the models. The legal basis is the performance of the contract (Art. 6 (1) lit. b GDPR).

8. Connecting your email mailbox (Google Gmail)

If you connect your Gmail mailbox, we access your emails via the Google API with the permissions granted by you, in order to display them in your inbox, to sort them, to summarise them, to create draft replies and to archive or send messages on your instruction.

The use of data received from Google APIs takes place in accordance with the Google API Services User Data Policy including the Limited Use requirements. This data is not used for advertising, not sold to third parties and not used to train general AI models.

The legal basis is the performance of the contract (Art. 6 (1) lit. b GDPR). You can disconnect at any time in the settings and additionally revoke access in your Google account.

9. Calendar connection (Google Calendar)

If you connect your Google calendar, we read out appointments and free times, display them in the application and, on your instruction, create, change or delete appointments. The legal basis is the performance of the contract (Art. 6 (1) lit. b GDPR). The connection can be disconnected at any time.

10. Social media publishing (Meta / Instagram)

If you connect an Instagram account, we transmit the content released by you (text, images) to Meta Platforms Ireland Ltd. for publication. The processing takes place on your instruction in performance of the contract (Art. 6 (1) lit. b GDPR). Meta is independently responsible for the processing within the Meta platforms.

When you connect, we store the Instagram user id, the username, and the access token; the token is stored encrypted. If you disconnect, we delete this data. Meta can also trigger a deletion itself, for example if you revoke access in your Meta account; we then carry out such a deletion request on our end.

11. Public website and contact form (web module)

Public websites created with the web module at *.makiro.site use no cookies and no analytics tools. If visitors use the contact form there, the data provided (name, email address, optionally telephone number, message) is transferred to the inbox of the respective business and processed there. The respective business is the controller for this; we act as a processor.

12. Payment processing

For subscriptions we use Mollie B.V. (Keizersgracht 126, 1015 CW Amsterdam, Netherlands). When a paid subscription is concluded, the data required for the SEPA direct debit (name, bank details, mandate and payment data) is collected directly by Mollie and processed there. We ourselves store only the customer, mandate and subscription identifiers as well as the payment status.

The legal basis is the performance of the contract (Art. 6 (1) lit. b GDPR) as well as compliance with retention obligations under tax and commercial law (Art. 6 (1) lit. c GDPR).

13. Cookies and reach measurement

We use technically necessary cookies for signing in and for session management. These are strictly necessary for the service expressly requested by you (§ 25 Abs. 2 Nr. 2 TDDDG).

For product analytics we use PostHog (PostHog Inc., USA) on the provider's EU infrastructure (eu.posthog.com). Collection is disabled by default and starts only after you have consented in the application (§ 25 Abs. 1 TDDDG, Art. 6 (1) lit. a GDPR). The attribution takes place exclusively via a random account identifier; names or email addresses are not transmitted to PostHog. The requests run via our own domain (/ingest). You may withdraw your consent at any time; if you delete your account, the associated analytics profile is deleted as well.

14. Feedback and support

If you send feedback via the application, your message is transferred to an internal Slack channel (Slack Technologies Ltd., Ireland) so that we can deal with it. The legal basis is our legitimate interest in improving the service and in handling your request (Art. 6 (1) lit. f GDPR).

15. Transfers to third countries

Some of the service providers named have their seat in the USA (Vercel, Neon, PostHog, ElevenLabs, Anthropic, Google). Insofar as personal data is thereby transferred to the USA, we base the transfer on the European Commission's standard contractual clauses (Art. 46 (2) lit. c GDPR) or — insofar as the respective provider is certified — on an adequacy decision under the EU-US Data Privacy Framework (Art. 45 GDPR). Copies of the safeguards are available on request.

16. Retention periods

  • Account and application data: for the duration of the usage relationship.
  • Raw transcripts of voice conversations: 30 days.
  • Message threads archived by you: 365 days from the last message of the thread; after that, the thread, messages, drafts and feedback are deleted automatically. What is in the inbox or has been deferred is retained regardless of its age.
  • Billing and accounting data: until the statutory retention periods have elapsed (as a rule 8 to 10 years pursuant to § 147 AO, § 257 HGB).
  • Remaining data: deletion as soon as the purpose ceases to apply or you delete your account. Deleting the account removes your data from our database as well as the associated files, conversation recordings held by the voice provider, your analytics profile and your sign-in with the authentication service, including the email address stored there and the link to your Google account.

17. Your rights

You have the right of access (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) as well as the right to object to processing based on legitimate interests (Art. 21 GDPR). You may withdraw consent given at any time with effect for the future.

To do so, please contact info@tojiki.de. You can additionally delete your account together with the associated data yourself at any time in the settings of the application; a running subscription is terminated in the process.

Irrespective of this, you have a right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach.

18. Changes to this policy

We adapt this privacy policy when the functions of the application or the service providers used change. The version published on this page in each case applies.