Privacy Policy

Last updated: February 2026

1. General Information

droidrun GmbH, located at Rheinstraße 82, 49090 Osnabrück, prioritises personal data protection. The company complies with EU Regulation 2016/679 (GDPR), the German Federal Data Protection Act (BDSG), and this privacy policy.

This policy informs data subjects about personal data processing when using the websites droidrun.ai and mobilerun.ai, or when contacting the company.

2. Data Controller

droidrun acts as a GDPR controller for personal data processed through its websites or direct contact.

Contact Details:
droidrun GmbH
Rheinstraße 82
49090 Osnabrück
Email: dataprotection@droidrun.com

3.1 Website Visits

Automatic data collection occurs during website visits, including:

  • Browser type and version
  • Operating system
  • Device hostname
  • Access date and time
  • IP address

Legal basis: Art. 6 para. 1 sent. 1 lit. f GDPR based on legitimate interests in providing functional, secure websites.

Storage duration: Deleted after 7 days maximum, except where legal retention obligations apply.

3.2 Contact Communications

Contact data collected includes name, email address, and request-specific information.

Legal basis: Processing occurs under Art. 6 para. 1 sent. 1 lit. b GDPR for contractual performance or pre-contractual steps, or Art. 6 para. 1 sent. 1 lit. f GDPR for legitimate customer inquiry interests.

Storage duration: Deleted when purpose no longer applies, subject to legal retention requirements.

3.3 Newsletter

Newsletter processing requires email address, registration timestamp, IP address, and browser type.

Tracking: Newsletters contain tracking technologies measuring open rates, link clicks, and device information for campaign analysis.

Legal basis: Processing requires explicit consent under Art. 6 para. 1 sent. 1 lit. a GDPR via double opt-in during subscription.

Unsubscription: Recipients may revoke consent at any time using unsubscribe links in emails.

Storage duration: Email addresses retained while subscription remains active.

3.4 Organisation-Provided Accounts

Organisations providing mobilerun accounts act as sole data controllers for processing activities. droidrun functions only as a data processor.

Users should direct privacy inquiries to their organisation.

3.5 Anonymisation for Service Improvement

Anonymised data supports service development and AI model training.

Data categories:

  • Trajectories: Interaction data, commands, action sequences, task metadata, success/failure status, model selection, performance metrics
  • Usage Data: Feature patterns, frequency, performance metrics

Legal basis: Art. 6 para. 1 sent. 1 lit. f GDPR based on legitimate interests in improving systems.

GDPR applicability: GDPR does not apply to anonymised data, as it no longer constitutes personal data.

Storage duration: Indefinite storage permitted for anonymised data.

3.6 Cookies

Refer to the Cookie Policy for cookie processing details.

3.7 Social Media and Professional Networks

droidrun maintains company pages on LinkedIn, X (formerly Twitter), Instagram, TikTok, GitHub, and Discord for communication and service information.

3.7.1 Visiting Company Pages

The respective platform controls personal data processing on company pages. No data transfers occur before users activate hyperlinks.

3.7.2 Communication Via Social Platforms

Information shared includes usernames, email addresses, contact details, communication content, job titles, companies, education, photos, and voluntarily provided data.

Legal basis: Processing under Art. 6 para. 1 sent. 1 lit. b GDPR for contractual or pre-contractual purposes, or Art. 6 para. 1 sent. 1 lit. f GDPR for customer inquiry interests.

Storage duration: Deleted when purpose expires, subject to legal retention obligations.

4. Data Receivers

droidrun may transfer personal data to:

  • Legal and tax consultants (bound by confidentiality obligations)
  • Corporate transaction advisors or potential buyers
  • Data processors under Data Processing Agreements per GDPR Article 28

Current Data Processors:

ProcessorPurpose
PostHog, Inc.Product analytics and user tracking
Plus Five Five, Inc (Resend)Newsletter distribution
Cloudflare, Inc.DNS management, domain protection, hosting
Autumn LabsSubscription and billing management
Stripe, Inc.Payment processing and invoicing

5. Personal Data Transfers to Third Countries

Data is typically processed within Germany and the European Economic Area.

Transfers outside the EEA occur using EU standard contractual clauses under Art. 46 para. 2 lit. c GDPR or adequacy decisions. Documentation available upon request.

6. Data Subject Rights

6.1 Right of Revocation

Consent may be revoked at any time under Article 7(3) GDPR with future effect only.

6.2 Right of Access

Data subjects may request confirmation of processing and receive access to personal data and related information per Article 15 GDPR, subject to § 34 BDSG restrictions.

6.3 Right to Rectification

Inaccurate or incomplete personal data may be corrected per Article 16 GDPR.

6.4 Right to Erasure

Personal data deletion may be requested under Article 17 GDPR conditions, subject to § 35 BDSG restrictions.

6.5 Right to Restrict Processing

Processing restrictions may be requested per Article 18 GDPR.

6.6 Right to Data Portability

Structured, machine-readable personal data copies may be requested under Article 20 GDPR when processing is based on consent or contract with automated means.

6.7 Right to Object

Objections to personal data processing may be filed per Article 21 GDPR.

6.8 Right to Complain

Data subjects may file complaints with supervisory authorities per Article 77 GDPR. The responsible authority for droidrun is the State Commissioner for Data Protection, Lower Saxony. A complete list of German supervisory authorities is available at bfdi.bund.de.

7. Data Provision Obligations

Certain personal data provision is required for website functionality and contact purposes. Non-provision may prevent access to functions or limit the company’s ability to respond to inquiries.

8. Automated Decisions / Profiling

Personal data processing does not involve automated individual decisions within Art. 22 para. 1 GDPR scope.

9. Policy Updates

This privacy policy undergoes regular review with updates possible at any time. The last update date appears at the top. Current versions are accessible at /privacy.