Privacy Policy for Vimmera Studio
1. Scope and Allocation of Roles
This privacy policy informs you about the processing of personal data when using the registered software platform “Vimmera Studio”.
If a customer provides user accounts or processes personal data with Vimmera Studio for its own purposes, the customer is generally the controller within the meaning of the GDPR. Vimmera AI Solutions GmbH processes this data as a processor in accordance with the customer’s instructions. In addition, the data processing agreement and the customer’s privacy information apply. The customer is responsible for informing data subjects about its specific use of Vimmera Studio.
Vimmera itself is the controller insofar as data is processed for its own purposes. This applies in particular to contract and billing administration, business contacts, inquiries addressed directly to Vimmera, as well as data that Vimmera processes to secure the platform, investigate specific security incidents, or enforce and defend its own legal claims.
For visits to www.vimmera.de and the publicly accessible chat “Mera” there, the separate privacy information of the website applies.
2. Controller
For processing for which Vimmera itself is the controller:
Vimmera AI Solutions GmbH
Löwestrasse 66
14612 Falkensee
Germany
Email: info@vimmera.de
In the case of processing on behalf of a customer, the respective customer is the controller. Its contact details can be found in particular in the invitation, the company area in Vimmera Studio, or the customer’s privacy information. Data subject requests addressed to Vimmera will, if necessary, be forwarded to the responsible customer.
3. Data processing by Vimmera as controller
Depending on use, Vimmera processes in particular:
- account, authentication, role, and authorization data,
- usage, login, error, security, and log data,
- support and communication data, and
- contract, billing, and business data.
The data comes from the user, the respective customer, or is generated when using the platform.
Processing takes place:
- to provide and manage access and to perform and bill contracts on the basis of Art. 6(1)(b) GDPR, insofar as the data subject is itself a contractual party;
- to manage user accounts and business contacts, for communication, support, and the secure and functional operation of the platform on the basis of Art. 6(1)(f) GDPR;
- to fulfill commercial, tax, and other legal obligations on the basis of Art. 6(1)(c) GDPR; and
- to enforce or defend legal claims on the basis of Art. 6(1)(f) GDPR.
The legitimate interests consist in carrying out and documenting business relationships, processing inquiries, securely providing Vimmera Studio, and protecting users, customers, and systems.
Recipients may include authorized users and administrators of the customer, authorized employees of Vimmera, hosting, cloud, AI infrastructure, transcription, communication, security, and IT service providers, payment, tax, and accounting service providers, legal advisors, as well as legally authorized authorities and courts. Where service providers process data on behalf of Vimmera, they are engaged on the basis of a contract pursuant to Art. 28 GDPR.
4. Technically necessary local storage
Vimmera Studio uses the browser’s local storage insofar as this is necessary for login, multi-factor authentication, session control, security, and technically necessary settings. In particular, session and authentication identifiers, temporary security tokens, and settings may be stored there.
Storage or access is necessary for the platform accessed by the user and takes place pursuant to Section 25(2) No. 2 TDDDG. Subsequent processing of personal data is governed by Art. 6 GDPR and the role allocation described in Section 1.
Session and authentication information is removed or rendered unusable upon logout or loses its effect after expiry. Technical settings may remain stored until they are replaced, deleted via the browser, or no longer needed. Vimmera Studio does not use analytics, tracking, or marketing services.
5. Processing of customer content
Data processed on behalf of a customer may in particular include user account data, inputs, chat histories, documents, images, audio recordings, transcripts, translations, project and knowledge content, as well as technical usage data. The customer determines the specific purposes, data subjects, types of data, and legal bases.
Vimmera does not routinely review customer content. Access by authorized employees takes place only on the basis of a customer instruction, for requested support, due to a legal obligation, or to investigate a specific security incident.
Special categories of personal data pursuant to Art. 9 GDPR may only be processed in a customer project specifically intended and separately agreed for this purpose. For this, the customer must determine a legal basis under Art. 6 GDPR and an exception under Art. 9(2) GDPR, inform data subjects, and implement the necessary protective measures. Where processing is based on consent, this must be obtained expressly and verifiably before processing.
6. Processing outside the European Economic Area
The standard configuration of Vimmera Studio is designed for processing within the European Union or the European Economic Area.
Where service providers or their sub-processors process data outside the European Economic Area in individual cases, this takes place only under the conditions of Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision or suitable safeguards such as the European Commission’s standard contractual clauses. Information about the safeguards used in the specific case can be requested at info@vimmera.de.
7. Storage period and deletion
Customer content processed on behalf of a customer is stored until it is deleted by an authorized user or administrator, an agreed deletion period expires, or the contract ends. After the end of the contract, the personal data processed by Vimmera on behalf of the customer, including residual copies controllable by Vimmera in backups, is generally deleted within three months, unless a legal obligation or permissible further storage prevents this.
Login, usage, security, error, and log data maintained by Vimmera in its own responsibility are generally stored for six months and then deleted or anonymized. In the event of a specific security incident, misuse, or legal dispute, the necessary data may be stored until the investigation or proceedings have been completed and until the expiry of relevant limitation periods.
Support and communication data are deleted once the inquiry has been completed and there are no legal retention obligations or legitimate reasons for further storage.
Contract and business data are stored in accordance with statutory retention periods. Commercial and business letters are generally retained for six years, accounting records generally for eight years, and books, records, and financial statements that must be retained longer by law are generally retained for ten years.
8. Rights of data subjects
Subject to the legal requirements, data subjects have in particular the right of access pursuant to Art. 15 GDPR, rectification pursuant to Art. 16 GDPR, erasure pursuant to Art. 17 GDPR, restriction of processing pursuant to Art. 18 GDPR, data portability pursuant to Art. 20 GDPR, objection pursuant to Art. 21 GDPR, withdrawal of consent pursuant to Art. 7(3) GDPR, and the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.
For processing for which a customer is the controller, these rights should be asserted against the respective customer. Vimmera supports the customer in accordance with the data processing agreement. For processing for which Vimmera itself is the controller, requests may be sent to info@vimmera.de or to the address stated in Section 2.
Where Vimmera processes personal data on the basis of Art. 6(1)(f) GDPR, data subjects may object to the processing at any time for reasons arising from their particular situation. Vimmera will then no longer process the data unless there are compelling legitimate grounds for the processing or the processing serves the establishment, exercise, or defense of legal claims.
9. Required data
Certain account, authentication, and authorization data are required to set up a user account and provide Vimmera Studio securely. Without this data, the platform cannot be used, or can only be used to a limited extent. The responsible customer determines which business content is required for a customer project.
As of: 3 August 2026