privacy
Last updated: 4 October 2026
1. Who we are
Kasimir ("Kasimir", "Kas", "we", "us") is a marketing AI agent for businesses, available at kasimir.work and app.kasimir.work. The controller responsible for processing personal data under the EU General Data Protection Regulation (GDPR) is:
Deal Engine GmbH
Studio Babelsberg, Media Tech Hub Space, Haus 4, August-Bebel-Str. 26-53
14482 Potsdam, Germany
Email: hello@deal-engine.de · Phone: +49 331 23 18 68 43
Managing directors: Ramtin Ramin (CEO), Anna-Lena Reindl (COO). For any privacy question or request, write to hello@deal-engine.de.
2. Summary
- We process account data, the content you create with Kas and data from the marketing and social accounts you choose to connect, only to provide the service to you.
- We do not sell personal data, do not use it for advertising and do not share it with data brokers.
- Connected accounts can be disconnected at any time on the Connections page; tokens are then deleted.
- Our servers are in Germany and the EU. Our AI provider processes prompts in the USA under contractual safeguards and does not train its models on our customers' content.
- You can request access, correction or deletion at any time. See Data deletion.
3. Data we process
Account and workspace data
Name, email address, password hash (managed by our authentication provider), workspace name, company website, team memberships and settings such as autopilot preferences.
Brand and content data
Brand kit (logo, colours, fonts, tone of voice), strategies, content calendars, prompts you send to Kas, the conversation history and the assets Kas generates (presentations, videos, images, captions). When you enter a website, we load that public website to extract brand information.
Data from connected accounts
Only if you connect an account, and only within the permissions you grant on the provider's consent screen. Details per platform are in section 5.
Technical data
IP address, date and time, requested page, browser information and error logs, needed to deliver the website securely. Job logs record which actions the agent took (for example "rendered presentation") so you can follow and audit them.
4. Purposes and legal bases
- Providing the service (account, workspaces, generating strategies and assets, publishing on your instruction): contract performance, Art. 6(1)(b) GDPR.
- Connecting third-party accounts: your consent on the provider's screen and contract performance, Art. 6(1)(a) and (b) GDPR. You can withdraw consent at any time by disconnecting.
- Security, abuse prevention, error analysis: legitimate interests, Art. 6(1)(f) GDPR.
- Statutory retention (e.g. invoices): legal obligation, Art. 6(1)(c) GDPR.
5. Connected platforms
Connections are always initiated by you on the Connections page and authorised on the respective platform's own consent screen. We access only what is needed for the features you use, never post without your instruction (approval or an autopilot you switched on yourself) and never use platform data for advertising or to build profiles of people.
Google (Search Console, Google Analytics 4, Google Ads, Tag Manager)
With read-only access we retrieve search performance (queries, pages, clicks, impressions, positions), website analytics (traffic, conversions, audiences in aggregated form), ad campaign performance and tag configuration. We use this data solely to show it to you and to let Kas analyse it for your strategy, recommendations and reports inside Kasimir.
Kasimir's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, do not sell it, do not transfer it to third parties except the processors needed to provide Kasimir's features (section 7), and do not allow humans to read it unless you ask us to (for support), it is necessary for security or legal reasons, or the data is aggregated and anonymised for internal operations.
Meta (Facebook Pages, Instagram, Meta Ads)
For publishing we receive the identifiers and names of the Facebook Pages and Instagram professional accounts you select and permission to publish posts, images and videos on them; for analysis we read basic insights of your posts and, if connected, Meta Ads performance. We use this data only to publish the content you approve and to report on its results.
We receive your basic profile (name, profile identifier, picture) and, if you choose a company page, the page identifier and name, plus permission to create posts with text, images and videos on your behalf. If you connect LinkedIn Ads, we read campaign performance. LinkedIn data is used only to publish your approved content and to report on it.
TikTok
We receive your TikTok account identifier, display name and avatar and permission to upload and publish videos you approve. If you connect TikTok Ads, we read campaign performance. We do not access your private messages, followers' personal data or content you did not publish through Kasimir.
We receive your account identifier, username and boards and permission to create pins with the images Kas generates. Data is used only to publish and report on your pins.
X (Twitter)
We receive your account identifier, handle and display name and permission to publish posts with media on your behalf. Data is used only to publish your approved posts.
How tokens are stored
Access tokens for social publishing are stored on our own servers in Germany (a self-hosted instance of the open-source scheduler Postiz). Access tokens for data channels are held by our integration provider (section 7). Credentials stored in our database are encrypted at rest with AES-256-GCM. Disconnecting a channel deletes its tokens.
6. AI processing
Kas uses large language models from Anthropic (Claude) to plan, write and design. Prompts and the context needed for a task (for example your brand kit, strategy and relevant channel data) are sent to Anthropic for processing. Under Anthropic's commercial terms, Anthropic does not train its models on our customers' content. AI output can be inaccurate; you review it before it is published unless you switch on fully automatic publishing.
7. Processors and recipients
We use the following service providers, each bound by a data processing agreement under Art. 28 GDPR:
- Hetzner Online GmbH, Germany: servers for the website, app, worker and the self-hosted publishing scheduler.
- Supabase, Inc.: database, authentication and file storage, hosted in the EU (Ireland).
- Anthropic PBC, USA: AI language models (section 6).
- Cogny AB, Sweden: integration layer for connecting Google, Meta, LinkedIn and TikTok data and ad accounts.
- Dataforseo OÜ, Estonia: public search market data (keyword volumes, search results, competitor domains). No personal data from your accounts is sent there.
- The platforms you connect receive the content you publish through them.
We do not sell or rent personal data and do not share it for advertising.
8. International transfers
Data is stored in Germany and the EU. Processing by Anthropic takes place in the USA. Such transfers are based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the recipient is certified, the EU-U.S. Data Privacy Framework (Art. 45 GDPR). You can request a copy of the safeguards by email.
9. Retention and deletion
- Access tokens of connected accounts: until you disconnect the account or delete your workspace or account.
- Generated assets, strategies, calendars and conversations: until you delete them or your workspace.
- Server logs: up to 14 days. Agent job logs: up to 90 days.
- Account data: until you delete your account; afterwards only what we must keep by law (e.g. invoices for 10 years).
- Deletion requests are completed within 30 days. See Data deletion instructions.
11. Security
All connections use TLS. Workspace data is separated by row-level security in the database. Third-party credentials are encrypted at rest (AES-256-GCM). Access to production systems is limited to authorised team members.
12. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future, for example by disconnecting an account. To exercise your rights, email hello@deal-engine.de.
You can also lodge a complaint with a supervisory authority, for example the data protection authority of the State of Brandenburg (Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg).
You can additionally revoke Kasimir's access in your account settings on each platform (for example Google Account › Security › Third-party access, Facebook Settings › Business Integrations, LinkedIn Settings › Data privacy, TikTok Settings › Security › Manage app permissions).
13. Children
Kasimir is a business service. It is not directed to and may not be used by persons under 18.
14. Changes
We update this policy when our processing changes. The current version is always available at kasimir.work/privacy with its date.