Last updated: February 10, 2026
Privacy Policy
At ZODD (zodd.ai), operated by Sumosmash UG (haftungsbeschränkt), we take your privacy seriously. This Privacy Policy explains how we collect, use, share, and protect your personal data.
1. Data Controller
The data controller responsible for your personal data is:
Sumosmash UG (haftungsbeschränkt)
Operating as: ZODD (zodd.ai)
Seydelstr. 12
10117 Berlin, Germany
Email: hello@zodd.ai
For statutory company details, please see our Imprint.
2. Information We Collect
2.1 Information You Provide
- Contact information (name, email, phone, company)
- Project details and requirements
- Payment and billing information
- Communications with our team
2.2 Information Collected Automatically
- IP address and device data
- Browser type, operating system, and version
- Pages visited and time spent on our website
- Referring website addresses
2.3 Cookies and Tracking
We use cookies and similar technologies for:
- Essential – Required for site functionality and security
- Analytics – Google Analytics, PostHog (only with your consent)
- Marketing – LinkedIn Insight Tag (only with your consent)
Our consent banner displays “Accept all” and “Reject all” buttons on the first layer with equal prominence. You can change your preferences anytime via the “Cookie settings” link in the footer.
3. Legal Bases for Processing
We process personal data under GDPR Article 6 on the following bases:
- Contract performance – To deliver our services and fulfill agreements
- Legitimate interests – For business operations, security, and service improvement
- Consent – For analytics, marketing, and optional activities
- Legal obligations – For tax, accounting, and compliance with regulations
4. How We Use Your Information
We use your information to:
- Provide and manage AI development services
- Communicate about projects and provide support
- Process payments and billing
- Send service updates and transactional notifications
- Improve services and develop new features
- Comply with legal requirements and protect our rights
- Send marketing communications (only with your consent)
We also assess any government or law-enforcement request for data for legality and proportionality.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
5. Data Sharing and Disclosure
We do not sell your personal data. We share data only with trusted processors and as legally required:
- Google Ireland Ltd. – Website analytics (Google Analytics)
- PostHog Inc. – Product analytics
- LinkedIn Ireland Unlimited Company – Marketing analytics (Insight Tag)
- Stripe Payments Europe Ltd. – Payment processing
- Vercel Inc. – Hosting and infrastructure
All processors are bound by GDPR-compliant contracts and safeguard your data appropriately.
6. International Data Transfers
Some providers process data outside the EU/EEA. In these cases, we ensure an adequate level of protection through:
- EU Standard Contractual Clauses (SCCs)
- EU adequacy decisions (e.g., UK, Japan)
- EU–US Data Privacy Framework (DPF) for certified US companies
You may request a copy or summary of the safeguards used for such transfers by contacting us.
7. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption of data in transit and at rest
- Pseudonymisation where possible
- Access controls and authentication mechanisms
- Regular security reviews and employee training
8. Data Retention
We retain data only as long as necessary for the stated purposes:
- Project data: Project duration + 3 years
- Financial records: 10 years (required by German law)
- Marketing data: Until you withdraw consent
- Website analytics: Up to 26 months
We review retention periods regularly and delete or anonymize data when no longer needed.
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access – Request a copy of your data
- Rectification – Correct inaccurate or incomplete data
- Erasure – Request deletion (“right to be forgotten”)
- Restriction – Limit how your data is processed
- Portability – Receive your data in a portable format
- Objection – Object to processing, including direct marketing
- Withdraw consent – Withdraw any consent you previously gave
To exercise these rights, contact hello@zodd.ai
You also have the right to lodge a complaint with your local supervisory authority.
In Berlin:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin
10. Children's Privacy
Our services are not directed at individuals under 16 years old. We do not knowingly collect data from children under 16.
11. Updates to This Policy
We may update this Privacy Policy from time to time. Significant changes will be notified via our website or email.
12. Contact
For privacy questions or to exercise your rights:
Last updated: February 10, 2026
See also: Terms of Service / Imprint