Privacy Policy
Telekinesis GmbH
Neckarstraße 4, 4.1.08
64283 Darmstadt
Germany
Last updated: 23rd December 2025
1. Data Controller
Telekinesis GmbH
Neckarstraße 4, 4.1.08
64283 Darmstadt
Germany
Email: suman.pal@telekinesis.ai
Phone: +49 157 5817 8477
2. What Data We Collect
2.1 Account Data
We collect:
- First & last name
- Role
- Job description
- Company
2.2 Technical Metadata
(Does NOT include user content)
We log:
- Timestamp
- API endpoint/model used
- Request size
- Error logs
IP addresses are truncated/anonymized.
2.3 Billing Data
Handled by Stripe. Telekinesis does not store card data.
2.4 Feedback and Usage Metadata
We may collect and use metadata (non-personal) from customer interaction with the Services, including performance feedback, usage patterns, or technical suggestions, to improve the quality and security of the platform. This data does not include personal content or inference inputs.
2.5 Inference Input/Output Data (Free Tier Only)
For Free Tier users only, we collect and retain input and output data used in the Services, including:
- images
- video frames
- point clouds
- generated model outputs
This data is used to:
- improve and train our models
- test and evaluate service performance
- detect abuse or fraud
- conduct internal research and analytics
By using the Free Tier, you provide explicit consent to this processing in accordance with GDPR Art. 6(1)(a). Free Tier access requires this consent.
3. Input Data Storage Policy by Tier
- Free Tier: Input/output data is stored and used as described in Section 2.5.
- Paid & Enterprise Tiers: Telekinesis does not store input images, videos, point clouds, or outputs. Inference is processed only in memory and deleted immediately.
Telekinesis does not use customer data for training.
4. Legal Basis (Art. 6 GDPR)
- Free Tier: Consent (Art. 6(1)(a)) for input/output data
- Paid/Enterprise:
- Contract performance (Art. 6(1)(b))
- Legitimate interest (security, fraud prevention, platform improvement)
- Legal obligation (e.g., tax, compliance)
No consent is required for analytics or cookies, as Telekinesis does not use tracking cookies or marketing pixels.
5. Data Storage Locations
Telekinesis uses cloud infrastructure provided by Amazon Web Services (AWS), including regions located within the European Union and the United States (e.g., US East), depending on service configuration and availability.
CRM: HubSpot EU region (if configured)
6. Data Sharing
Telekinesis uses the following GDPR-compliant subprocessors:
- Amazon Web Services (AWS) – cloud hosting and infrastructure
- Stripe Payments Europe – billing
- HubSpot – CRM (EU region where available)
Where Personal Data is transferred outside the European Economic Area, including to the United States, such transfers are protected by appropriate safeguards in accordance with GDPR Chapter V, including the European Commission’s Standard Contractual Clauses (SCCs).
Telekinesis does not sell personal data.
7. Data Retention
- Account data → retained until user deletes or account is deactivated
- Logs → retained for 6–12 months
- Billing data → retained for 10 years (German tax law)
- Free Tier input/output data → retained up to [define period, e.g., 12 months]
8. User Rights
Under GDPR, you may:
- Access your personal data
- Request rectification
- Request deletion
- Request data portability
- Object to certain processing
- Withdraw consent (Free Tier only)
9. Security Measures
- TLS encryption (in transit)
- AES encryption (at rest)
- Role-based IAM access
- Real-time logging and monitoring
- Secure cloud infrastructure hosted by AWS with industry-standard security controls and international data transfer safeguards
10. Cookies
- No tracking cookies
- No analytics or third-party marketing
- Only essential session cookies (e.g., for login security)
11. Updates
We will notify users of material changes to this Privacy Policy.
12. Export Control
To comply with applicable export control and sanctions regulations, Telekinesis may restrict access to its Services based on IP address, user profile, or country of registration. These checks do not involve the processing of personal content or inference data.

