Privacy
How this website handles personal data.
A plain account of what this website collects, why, and what you can ask us to do about it.
Last updated 2026-08-30
01Who is responsible
The controller for this website is Mainhattan Labs UG (haftungsbeschränkt), Große Gallusstraße 14, 60315 Frankfurt am Main, Germany. Ailpa is an operating brand of Mainhattan Labs UG (haftungsbeschränkt) and is not a separate legal entity.
Data protection enquiries: [email protected].
02What this notice covers
The public website at ailpa.ai, the contact form, and email correspondence that begins from the website.
If a mandate proceeds, the parties agree separate confidentiality, security and data processing terms appropriate to the transaction.
03What we process
- Access data: IP address, request time, page requested, browser and device information, referrer and security events.
- Contact data: the subject you select, your name, email address, company and message, with basic technical metadata.
- Email: the content of your message, its headers, and anything you choose to attach.
Please do not send confidential documents through the public form.
05Why we process it, and on what basis
To deliver and secure the website, which is our legitimate interest. To receive, assess and answer enquiries, which are steps taken before entering a possible advisory relationship at your request. To keep appropriate business records, which is our legitimate interest and in some cases a legal obligation.
06The contact form
Submissions are posted to a Cloudflare Pages Function, validated, and stored in Cloudflare KV so we can respond. A notification is sent to us by email through Resend. Submissions are never sold, never used for advertising profiles, and never used to train public AI models.
07Who else is involved
Cloudflare for hosting, security and storage. Resend for the notification email. Our own business email provider. We do not sell personal data.
08Transfers outside the EEA
Some providers operate global infrastructure. Where personal data leaves the EEA we rely on safeguards such as adequacy decisions or standard contractual clauses.
09How long we keep it
Security logs are kept for as long as the provider requires. Contact submissions are kept for up to 24 months unless a longer period is necessary. Email correspondence may be kept longer where it forms part of business records.
10Your rights
Subject to applicable law you may request access, rectification, erasure, restriction or portability, and you may object to processing based on legitimate interests.
You may also complain to the Hessian Commissioner for Data Protection and Freedom of Information at datenschutz.hessen.de.
11Changes to this notice
We update this notice when the website or the law changes. The date above shows the current version.