Privacy Policy
Last updated: June 2026
Golemry is the controller responsible for personal data processed through the service. How that data is handled is documented in full on our Data & Security page. You can reach us at contact@golemry.com; our legal identity and postal address are in the Impressum.
What We Collect
We collect only what's needed to provide and improve the service:
- Account information: your email address and authentication details when you sign up
- Automation data: the jobs, configurations, and outputs your automations create through the service
- Usage data: how you interact with the service (pages visited, features used) to help us improve
How We Use Your Data
Your data is used to:
- Provide and maintain the Golemry service
- Authenticate your account and secure your data
- Improve the product based on usage patterns
- Communicate with you about your account or service updates
Legal Basis for Processing
We process personal data on the following legal bases under Article 6 GDPR:
- To provide the service and run the automations you configure: performance of a contract (Art. 6(1)(b)).
- To secure the service, prevent abuse, and improve the product: our legitimate interests (Art. 6(1)(f)).
- To meet bookkeeping and tax obligations for billing data: compliance with a legal obligation (Art. 6(1)(c)).
- Where we ask for it, your consent (Art. 6(1)(a)), which you may withdraw at any time.
Data Retention
Account information is retained for the life of your account. Job configurations and schedules are retained for as long as the job exists. Run data (agent conversation transcripts, run artifacts, logs, and observability traces) is retained for 30 days. Billing records are retained for the periods required by statutory tax and commercial law.
You can ask us to delete your data and account at any time (see “Your Rights”). Deletion is processed on request; account and job configuration persist until then so your automations keep running. Specific retention windows per subprocessor are listed on the Data & Security page.
Third-Party Services
We use trusted third-party services for hosting, authentication, and analytics. These providers only have access to the data necessary to perform their function. Our Data & Security page lists every subprocessor with its purpose, processing region, and retention window, and documents the full data path.
We do not sell, rent, or share your personal data with third parties for marketing.
International Data Transfers
Some of our subprocessors process personal data in the United States. Where that happens, the transfer relies on appropriate safeguards under Chapter V GDPR: Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Our observability and product-analytics providers are EU-hosted. The processing region for each subprocessor is listed on the Data & Security page.
Product Analytics
We use an EU-hosted analytics service to understand how the product is used and where we can make it better. Events record milestones such as signing up, connecting an agent, or creating a job. When you are signed in, these are linked to your account so we can find and fix the places people get stuck.
We also use session recordings that replay how the interface was used. Anything you type into a field is masked in your browser before it is sent, so values like passwords and API keys never appear in a recording. All analytics data is processed and stored in the EU.
Processing Your End-Users' Data (Controller / Processor)
For your own account and usage data, we are the controller. When your automations process personal data belonging to your customers or end-users, you are the controller for that data and Golemry acts as your processor under Article 28 GDPR, processing it only to run the automations you configure. A data processing agreement (DPA) is available on request: email contact@golemry.com.
Your Data Stays Yours
Your automation data is used solely to improve your automations. We do not use your data to train general-purpose AI models or share it across accounts. Your data is never sold or used for purposes beyond operating the service for you.
Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Request correction of inaccurate data (Art. 16)
- Request deletion of your data and account (Art. 17)
- Restrict or object to processing (Art. 18, 21)
- Receive your data in a portable format (Art. 20)
- Withdraw consent at any time, without affecting prior processing (Art. 7(3))
To exercise any of these rights, contact us at contact@golemry.com. Deletion and access requests are handled manually within the statutory time frame.
You also have the right to lodge a complaint with a supervisory authority (Art. 77). Our competent authority is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Heilbronner Straße 35, 70191 Stuttgart.
Contact
Questions about your privacy? Reach us at contact@golemry.com.