Last updated: February 10, 2026

Privacy Policy

At ZODD (zodd.ai), operated by Sumosmash UG (haftungsbeschränkt), we take your privacy seriously. This Privacy Policy explains how we collect, use, share, and protect your personal data.

1. Data Controller

The data controller responsible for your personal data is:

Sumosmash UG (haftungsbeschränkt)

Operating as: ZODD (zodd.ai)

Seydelstr. 12

10117 Berlin, Germany

Email: hello@zodd.ai

For statutory company details, please see our Imprint.

2. Information We Collect

2.1 Information You Provide

  • Contact information (name, email, phone, company)
  • Project details and requirements
  • Payment and billing information
  • Communications with our team

2.2 Information Collected Automatically

  • IP address and device data
  • Browser type, operating system, and version
  • Pages visited and time spent on our website
  • Referring website addresses

2.3 Cookies and Tracking

We use cookies and similar technologies for:

  • Essential – Required for site functionality and security
  • Analytics – Google Analytics, PostHog (only with your consent)
  • Marketing – LinkedIn Insight Tag (only with your consent)

Our consent banner displays “Accept all” and “Reject all” buttons on the first layer with equal prominence. You can change your preferences anytime via the “Cookie settings” link in the footer.

3. Legal Bases for Processing

We process personal data under GDPR Article 6 on the following bases:

  • Contract performance – To deliver our services and fulfill agreements
  • Legitimate interests – For business operations, security, and service improvement
  • Consent – For analytics, marketing, and optional activities
  • Legal obligations – For tax, accounting, and compliance with regulations

4. How We Use Your Information

We use your information to:

  • Provide and manage AI development services
  • Communicate about projects and provide support
  • Process payments and billing
  • Send service updates and transactional notifications
  • Improve services and develop new features
  • Comply with legal requirements and protect our rights
  • Send marketing communications (only with your consent)

We also assess any government or law-enforcement request for data for legality and proportionality.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

5. Data Sharing and Disclosure

We do not sell your personal data. We share data only with trusted processors and as legally required:

  • Google Ireland Ltd. – Website analytics (Google Analytics)
  • PostHog Inc. – Product analytics
  • LinkedIn Ireland Unlimited Company – Marketing analytics (Insight Tag)
  • Stripe Payments Europe Ltd. – Payment processing
  • Vercel Inc. – Hosting and infrastructure

All processors are bound by GDPR-compliant contracts and safeguard your data appropriately.

6. International Data Transfers

Some providers process data outside the EU/EEA. In these cases, we ensure an adequate level of protection through:

  • EU Standard Contractual Clauses (SCCs)
  • EU adequacy decisions (e.g., UK, Japan)
  • EU–US Data Privacy Framework (DPF) for certified US companies

You may request a copy or summary of the safeguards used for such transfers by contacting us.

7. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit and at rest
  • Pseudonymisation where possible
  • Access controls and authentication mechanisms
  • Regular security reviews and employee training

8. Data Retention

We retain data only as long as necessary for the stated purposes:

  • Project data: Project duration + 3 years
  • Financial records: 10 years (required by German law)
  • Marketing data: Until you withdraw consent
  • Website analytics: Up to 26 months

We review retention periods regularly and delete or anonymize data when no longer needed.

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Access – Request a copy of your data
  • Rectification – Correct inaccurate or incomplete data
  • Erasure – Request deletion (“right to be forgotten”)
  • Restriction – Limit how your data is processed
  • Portability – Receive your data in a portable format
  • Objection – Object to processing, including direct marketing
  • Withdraw consent – Withdraw any consent you previously gave

To exercise these rights, contact hello@zodd.ai

You also have the right to lodge a complaint with your local supervisory authority.

In Berlin:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Alt-Moabit 59–61, 10555 Berlin

Email: mailbox@datenschutz-berlin.de

10. Children's Privacy

Our services are not directed at individuals under 16 years old. We do not knowingly collect data from children under 16.

11. Updates to This Policy

We may update this Privacy Policy from time to time. Significant changes will be notified via our website or email.

12. Contact

For privacy questions or to exercise your rights:

Privacy Contact

Sumosmash UG (haftungsbeschränkt)

Email: hello@zodd.ai

Last updated: February 10, 2026

See also: Terms of Service / Imprint