top of page

Privacy Policy

 

Effective date: 08.07.2026

This Privacy Policy explains how CARNIQ Technologies GmbH, Orionstrasse 4, 85716 Unterschleissheim, Germany, registered with the commercial register of the Local Court of Munich under HRB 285225 (“CARNIQ”, “we”, “us”, or “our”), collects, uses, stores, shares, and protects personal data when you visit our website, contact us, request a demo, subscribe to our newsletter, use carAISuite, purchase or evaluate our services, or otherwise interact with us.

This Privacy Policy applies to our website, carAISuite software platform, web applications, desktop applications, support, demos, pilot projects, paid design partnerships, professional services, and related business activities.

carAISuite is intended for business and professional use only. It is designed for companies, professional users, engineering organizations, automotive suppliers, OEMs, engineering service providers, freelancers, consultants, sole traders, founders, independent professionals, and other persons or entities acting for purposes related to their trade, business, craft, or profession. carAISuite is not intended for private consumer use.

This Privacy Policy does not replace any data processing agreement, enterprise agreement, order form, or other written agreement between CARNIQ and a customer. Where CARNIQ processes personal data on behalf of a customer as processor, the applicable data processing agreement shall govern such processing.

 

1. Controller

The controller responsible for the processing of personal data described in this Privacy Policy is:

CARNIQ Technologies GmbH
Orionstrasse 4
85716 Unterschleissheim
Germany

Email: info@carniq.ai
Phone: +49 (0) 15146859832

The controller is the natural or legal person who determines the purposes and means of processing personal data.

For privacy-related questions, concerns, or requests, please contact us at info@carniq.ai.

 

2. Overview of Processing

We may process personal data in the following situations:

a. when you visit our website;
b. when you contact us by email, phone, contact form, LinkedIn, event, or other communication channel;
c. when you request a demo, quotation, pilot, design partnership, or commercial proposal;
d. when you create or use a carAISuite account;
e. when your company or organization uses carAISuite;
f. when you upload, process, review, or generate engineering documents through carAISuite;
g. when you use AI-assisted features, credits, workflows, exports, or integrations;
h. when you receive support, onboarding, training, or professional services;
i. when you subscribe to newsletters, webinars, events, or marketing communication;
j. when we manage customers, prospects, contracts, invoices, and business relationships;
k. when we comply with legal, tax, accounting, security, and compliance obligations.

 

3. Categories of Personal Data We Process

Depending on your interaction with us, we may process the following categories of personal data:

3.1 Contact and Business Data

This may include:

a. name;
b. business email address;
c. phone number;
d. company name;
e. job title;
f. department;
g. business address;
h. country;
i. LinkedIn or other professional profile information you provide to us;
j. communication history;
k. meeting notes, demo requests, and commercial interests.

3.2 Account and User Data

When you or your organization use carAISuite, we may process:

a. user name;
b. business email address;
c. login credentials or authentication identifiers;
d. role, workspace, tenant, project, or permission information;
e. account status;
f. subscription plan;
g. assigned modules;
h. user activity logs;
i. access timestamps;
j. support and troubleshooting information.

3.3 Technical and Device Data

When you visit our website or use our software, we may process:

a. IP address;
b. browser type and version;
c. operating system;
d. device type;
e. language settings;
f. referring URL;
g. pages visited;
h. date and time of access;
i. session information;
j. error logs;
k. security logs;
l. approximate location derived from IP address;
m. cookie and consent preferences.

3.4 Usage and Product Data

When you use carAISuite, we may process:

a. features used;
b. workflows started or completed;
c. document-processing events;
d. AI feature usage;
e. credit consumption;
f. usage limits;
g. exports;
h. integrations used;
i. performance logs;
j. error messages;
k. system events;
l. support diagnostics;
m. metadata necessary for billing, security, troubleshooting, and service improvement.

3.5 Customer Content and Engineering Data

When customers use carAISuite, they may upload or process engineering documents and project information. Such data may include:

a. requirements;
b. system specifications;
c. software specifications;
d. architecture documents;
e. test documents;
f. traceability information;
g. review comments;
h. quality records;
i. compliance documents;
j. customer standards;
k. OEM requirements;
l. project files;
m. prompts and instructions;
n. AI-assisted outputs.

These documents may contain personal data if the customer includes names, email addresses, employee identifiers, reviewer comments, author names, project-member details, or other personal information.

The customer is responsible for ensuring that uploaded documents and project data are lawful, suitable, and necessary for processing through carAISuite.

3.6 Billing and Contract Data

We may process:

a. company billing details;
b. VAT ID or tax information;
c. invoice address;
d. purchase order information;
e. payment status;
f. subscription plan;
g. order forms;
h. contracts;
i. credit purchases;
j. payment communication.

We generally do not store full credit-card details ourselves. Payment information may be processed by payment providers if such providers are used.

3.7 Marketing and Event Data

If you subscribe to newsletters, webinars, events, or marketing communications, we may process:

a. name;
b. email address;
c. company;
d. job title;
e. communication preferences;
f. event participation;
g. webinar registration;
h. consent records;
i. unsubscribe information;
j. engagement information, such as email opens or clicks, where legally permitted.

 

4. Purposes and Legal Bases of Processing

We process personal data only where a legal basis under the GDPR applies.

4.1 Website Operation and Security

We process technical data to provide our website, ensure stability, prevent misuse, detect security incidents, and troubleshoot technical problems.

Legal basis: Article 6(1)(f) GDPR — legitimate interest in secure and reliable website operation.

Where cookies or similar technologies require consent, processing is based on Article 6(1)(a) GDPR and Section 25(1) TDDDG.

4.2 Contact Requests and Communication

If you contact us, we process your contact details and communication content to respond to your inquiry, arrange meetings, provide information, and manage follow-up communication.

Legal basis: Article 6(1)(b) GDPR if the inquiry relates to a contract or pre-contractual measures; otherwise Article 6(1)(f) GDPR — legitimate interest in handling business inquiries. If consent is requested, Article 6(1)(a) GDPR applies.

4.3 Demo Requests, Sales, Pilots, and Design Partnerships

We process business contact data, company information, use-case information, meeting notes, and commercial communication to evaluate customer needs, provide demos, prepare offers, manage pilots, and conclude agreements.

Legal basis: Article 6(1)(b) GDPR for pre-contractual and contractual steps; Article 6(1)(f) GDPR for B2B relationship management and commercial communication.

4.4 Account Creation and User Administration

We process account and user data to create and manage accounts, assign access rights, authenticate users, manage subscriptions, and provide the Services.

Legal basis: Article 6(1)(b) GDPR where the user is an individual contracting party or where processing is necessary to perform the contract with the customer; Article 6(1)(f) GDPR where we process business-user data to provide services to the customer organization.

4.5 Provision of carAISuite

We process account data, usage data, technical logs, Customer Content, and AI-related processing data to provide carAISuite, including document analysis, requirements engineering workflows, AI-assisted outputs, traceability support, quality checks, exports, and integrations.

Legal basis: Article 6(1)(b) GDPR where processing is necessary for contract performance; Article 6(1)(f) GDPR for business-user processing, platform operation, support, security, and service improvement.

Where CARNIQ processes personal data contained in Customer Content on behalf of a customer, CARNIQ generally acts as processor under Article 28 GDPR. In such cases, the customer is the controller and CARNIQ processes the data according to the customer’s instructions and the applicable data processing agreement.

4.6 AI-Assisted Processing

carAISuite may process prompts, uploaded documents, metadata, and generated outputs through AI-assisted features. This may include analysis, extraction, classification, review, transformation, summarization, generation, and comparison of engineering content.

We process such data to provide AI-assisted functionality requested by the customer.

Legal basis: Article 6(1)(b) GDPR for contract performance and Article 6(1)(f) GDPR for providing secure, reliable, and useful AI-assisted professional software.

CARNIQ will not use Customer Content to train, fine-tune, or improve public or general-purpose AI models unless the customer has expressly agreed to such use in writing.

4.7 Credits, Usage Limits, and Billing

We process usage data, credit consumption, account data, subscription data, and billing data to measure use, apply usage limits, allocate credits, invoice customers, prevent misuse, and manage commercial terms.

Legal basis: Article 6(1)(b) GDPR for contract performance; Article 6(1)(c) GDPR for legal accounting and tax obligations; Article 6(1)(f) GDPR for fraud prevention, platform stability, and billing administration.

4.8 Support, Maintenance, and Troubleshooting

We process contact data, account data, technical logs, error reports, screenshots, support tickets, and relevant Customer Content if required to resolve support issues.

Legal basis: Article 6(1)(b) GDPR for contract performance; Article 6(1)(f) GDPR for maintaining a secure and reliable service.

4.9 Product Improvement and Analytics

We may process usage data, technical data, error logs, feature statistics, and aggregated or anonymized data to improve our products, identify bugs, enhance performance, plan capacity, and develop new features.

Legal basis: Article 6(1)(f) GDPR — legitimate interest in improving our software and services.

Where possible, we use aggregated or anonymized data that does not identify individual users, customers, projects, or confidential engineering content.

4.10 Marketing, Newsletters, and Webinars

We may process your contact details to send newsletters, product updates, event invitations, webinar information, or similar communications.

Legal basis: Article 6(1)(a) GDPR if we rely on consent; Article 6(1)(f) GDPR for B2B direct marketing where legally permitted.

You may unsubscribe or object to marketing communications at any time.

4.11 Legal Compliance and Claims

We may process personal data to comply with legal obligations, accounting obligations, tax retention rules, export-control obligations, sanctions checks, regulatory requirements, and to establish, exercise, or defend legal claims.

Legal basis: Article 6(1)(c) GDPR for legal obligations; Article 6(1)(f) GDPR for legal defense and risk management.

 

5. Customer Content, AI Processing, and No Model Training

5.1 Customers may upload or process engineering documents, project files, requirements, specifications, architecture documents, test artifacts, compliance documents, prompts, and other project-related content through carAISuite.

5.2 Customer Content remains under the control of the customer. CARNIQ does not claim ownership of Customer Content.

5.3 CARNIQ processes Customer Content only to provide, secure, maintain, support, and improve the Services for the customer, unless otherwise agreed in writing.

5.4 CARNIQ will not sell Customer Content.

5.5 CARNIQ will not use Customer Content to train, fine-tune, or improve public or general-purpose AI models unless the customer has expressly agreed to such use in writing.

5.6 CARNIQ may use aggregated, anonymized, or statistical usage data that does not identify the customer, authorized users, projects, products, end customers, or confidential technical content for product improvement, security, analytics, capacity planning, and business reporting.

5.7 Customer Content may be processed by third-party infrastructure providers, cloud providers, AI service providers, or technical processors where necessary to provide carAISuite. Such providers are used under appropriate contractual safeguards, including data processing agreements where required.

5.8 Customers should not upload unnecessary personal data, special categories of personal data, private employee data, classified data, export-controlled data, or defense-restricted data unless legally permitted, contractually agreed, and technically supported.

 

6. Cookies, Consent, and Similar Technologies

Our website may use cookies and similar technologies. Cookies are small text files stored on your device.

We may use:

a. strictly necessary cookies required for website operation, security, consent management, login, or session handling;
b. preference cookies to remember user settings;
c. analytics cookies to understand website usage;
d. marketing cookies to measure campaigns or improve B2B communication, where legally permitted.

Where required by law, we ask for your consent before using non-essential cookies or similar technologies. You can revoke or change your consent at any time through the cookie settings available on our website.

Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG for consent-based cookies; Article 6(1)(f) GDPR and Section 25(2) TDDDG for strictly necessary cookies.

Current cookie/consent provider: Cookiebot

 

7. Hosting and Infrastructure

Our website and Services may be hosted by external hosting, cloud, infrastructure, or platform providers. These providers may process technical data, log data, account data, Customer Content, and other information necessary to operate the website and Services.

Legal basis: Article 6(1)(f) GDPR — legitimate interest in secure and reliable hosting; Article 6(1)(b) GDPR where hosting is necessary to provide contractual services.

We enter into data processing agreements with processors where required by Article 28 GDPR.

Website hosting provider: Wix

carAISuite application hosting provider: Frontend hosted on Cloudflare; backend hosted on Nebius

Database region: MongoDB hosted on AWS, Frankfurt, Germany, EU region eu-central-1

Vector database region: AWS, EU region eu-central-1

 

8. Contact Forms, Email, Phone, and Business Communication

If you contact us through a form, email, phone, LinkedIn, event, or other communication channel, we process the personal data you provide, including your name, contact details, company, message content, and related metadata.

We use this data to respond to your request, manage follow-up communication, prepare offers, schedule demos, provide support, and maintain business relationships.

Legal basis: Article 6(1)(b) GDPR where the communication relates to a contract or pre-contractual measures; Article 6(1)(f) GDPR for general business communication; Article 6(1)(a) GDPR where consent is requested.

We retain such data until the purpose of the communication has been fulfilled, unless legal retention obligations, ongoing business relationships, or legitimate interests require longer storage.

 

9. CRM, Sales, and Customer Relationship Management

We may use customer relationship management tools to manage prospects, customers, demo requests, communication, sales pipelines, support interactions, and marketing communication.

Processed data may include name, business email, phone number, company, role, communication history, meeting notes, product interests, lead source, and contract status.

Legal basis: Article 6(1)(f) GDPR — legitimate interest in efficient B2B customer management and communication; Article 6(1)(b) GDPR for contract-related processing; Article 6(1)(a) GDPR where consent is required.

CRM providers: HubSpot and Zoho

If data is transferred outside the EU/EEA, we use appropriate safeguards such as adequacy decisions, EU Standard Contractual Clauses, or other legally recognized transfer mechanisms.

 

10. Analytics and B2B Website Intelligence

We may use analytics tools to understand how visitors use our website and to improve website performance, content, and marketing effectiveness.

Analytics data may include visited pages, time on site, referring website, approximate location, device information, browser information, and interaction data.

Where analytics tools use non-essential cookies or similar technologies, we use them only with your consent.

Legal basis: Article 6(1)(a) GDPR and Section 25(1) TDDDG where consent is required; Article 6(1)(f) GDPR where analytics are strictly necessary or based on legitimate B2B interests and legally permitted.

Analytics providers: Google Analytics and Wix Analytics

We may also use B2B visitor identification tools to identify companies that visit our website, where legally permitted. Such tools should be configured to avoid identifying individual private users wherever possible.

 

11. Newsletter and Marketing Communication

If you subscribe to our newsletter or request product updates, we process your email address and any additional information you provide, such as name, company, and role.

We use this data to send product updates, event invitations, webinar information, educational content, and marketing communication related to CARNIQ and carAISuite.

Legal basis: Article 6(1)(a) GDPR if based on consent; Article 6(1)(f) GDPR for legally permitted B2B communication.

You may unsubscribe at any time by using the unsubscribe link in the email or by contacting us at info@carniq.ai.

After unsubscribing, we may retain your email address in a suppression list to ensure that you no longer receive marketing emails. Legal basis: Article 6(1)(f) GDPR — legitimate interest in complying with opt-out requests.

 

12. Webinars and Events

If you register for or participate in a webinar, demo session, workshop, trade fair meeting, or event, we may process your name, company, job title, email address, registration data, attendance data, communication preferences, and questions or feedback.

We use this data to organize the event, send reminders, provide materials, follow up on business inquiries, and improve our services.

Legal basis: Article 6(1)(b) GDPR where registration relates to a contractual or pre-contractual activity; Article 6(1)(f) GDPR for B2B event organization and follow-up; Article 6(1)(a) GDPR where consent is required.

Webinar/event providers: Microsoft Teams and LinkedIn Events

 

13. Payment and Billing Providers

If we use external payment providers, payment data may be processed by those providers to complete transactions, manage payment methods, prevent fraud, process refunds, and comply with financial regulations.

Processed data may include name, billing address, email address, payment method, transaction ID, amount, currency, payment status, and invoice details.

Legal basis: Article 6(1)(b) GDPR for contract performance; Article 6(1)(c) GDPR for legal accounting and tax obligations; Article 6(1)(f) GDPR for fraud prevention and payment security.

Payment providers: Stripe and bank transfer

 

14. Authentication and Third-Party Login

carAISuite may allow login through third-party identity providers, such as Google, Microsoft, or other single sign-on providers.

If you use third-party login, we may process identity data provided by the identity provider, such as name, email address, user ID, organization, and authentication status.

Legal basis: Article 6(1)(b) GDPR for account access and service provision; Article 6(1)(f) GDPR for secure authentication and account administration.

The third-party identity provider may process your data under its own privacy policy.

 

15. Integrations and Third-Party Systems

carAISuite may allow import, export, file exchange, API access, or integration with third-party systems such as requirements-management tools, document systems, cloud services, engineering repositories, authentication providers, or AI infrastructure providers.

If the customer activates or uses integrations, personal data may be exchanged between carAISuite and the connected third-party system.

The customer is responsible for ensuring that the integration is lawful, properly configured, and permitted under its own contracts and internal policies.

Legal basis: Article 6(1)(b) GDPR for contract performance; Article 6(1)(f) GDPR for providing integrated professional software functionality.

 

16. AI Service Providers and Subprocessors

To provide AI-assisted functionality, CARNIQ may use AI model providers, cloud infrastructure providers, vector database providers, document-processing providers, OCR providers, or other technical subprocessors.

Depending on the configuration, these providers may process prompts, uploaded documents, metadata, embeddings, outputs, logs, or technical data necessary to perform the requested AI workflow.

CARNIQ uses such providers under contractual safeguards and, where applicable, data processing agreements.

CARNIQ will not permit subprocessors to use Customer Content to train public or general-purpose AI models unless the customer has expressly agreed to such use in writing.

AI/model provider: OpenAI, Google, Anthropic
Vector database provider: Qdrant

 

17. Data Sharing and Recipients

We may share personal data with the following categories of recipients where necessary and legally permitted:

a. hosting and cloud infrastructure providers;
b. IT service providers;
c. AI service providers and technical subprocessors;
d. CRM and communication providers;
e. email and newsletter providers;
f. analytics and cookie-consent providers;
g. payment and billing providers;
h. accounting, tax, legal, and compliance advisors;
i. customer-authorized integration providers;
j. business partners where required for agreed services;
k. public authorities, courts, regulators, or law enforcement where legally required;
l. potential acquirers, investors, or professional advisors in connection with corporate transactions, subject to appropriate confidentiality protections.

We do not sell personal data.

Where we use processors, we enter into data processing agreements as required under Article 28 GDPR.

 

18. International Data Transfers

Where possible, we prefer processing personal data within the European Union or European Economic Area.

If personal data is transferred to countries outside the EU/EEA, we ensure that appropriate safeguards are in place. These may include:

a. an adequacy decision by the European Commission;
b. EU Standard Contractual Clauses;
c. additional technical and organizational measures;
d. certification under an approved transfer framework, where applicable;
e. explicit consent in specific cases;
f. another lawful transfer mechanism under Chapter V GDPR.

 

19. Storage Duration

We store personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Typical retention periods include:

a. website logs: generally retained for a limited period required for security and troubleshooting;
b. contact inquiries: retained until the inquiry is completed, unless further retention is justified by a business relationship or legal obligation;
c. customer account data: retained for the duration of the customer relationship and a reasonable period thereafter;
d. billing and accounting data: retained according to applicable commercial and tax retention obligations;
e. support tickets: retained for the duration necessary to provide support, improve service quality, and document issue resolution;
f. Customer Content: retained according to the customer agreement, data processing agreement, product functionality, and deletion/export settings;
g. marketing data: retained until you unsubscribe, object, revoke consent, or the purpose no longer applies;
h. security logs: retained for a period necessary to detect, investigate, and prevent misuse or security incidents.

If you request deletion or revoke consent, we will delete the relevant data unless we have another legal basis or legal obligation to retain it.

 

20. Security Measures

We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include:

a. encryption in transit;
b. access controls;
c. authentication mechanisms;
d. role-based permissions;
e. logging and monitoring;
f. backup and recovery procedures;
g. separation of customer environments where applicable;
h. confidentiality obligations for personnel;
i. processor and subprocessor controls;
j. security reviews and technical safeguards.

No system can be guaranteed to be fully secure. Customers and users are responsible for protecting their login credentials, using secure devices, and promptly notifying us of suspected unauthorized access.

 

21. Children

Our website and Services are not directed at children or private consumers. carAISuite is intended for professional and business use only.

We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate legal basis, we will delete such data.

 

22. Your Rights Under the GDPR

Subject to the conditions set out in the GDPR, you have the following rights:

a. right of access to your personal data;
b. right to rectification of inaccurate personal data;
c. right to erasure;
d. right to restriction of processing;
e. right to data portability;
f. right to object to processing based on legitimate interests;
g. right to object to direct marketing at any time;
h. right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
i. right to lodge a complaint with a supervisory authority.

To exercise your rights, contact us at info@carniq.ai.

If your personal data is processed by CARNIQ on behalf of a customer, we may forward your request to the relevant customer or ask you to contact the customer directly, because the customer may be the controller responsible for your data.

 

23. Right to Object

If we process your personal data based on Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.

If you object, we will no longer process the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defense of legal claims.

If your personal data is processed for direct marketing, you have the right to object at any time. If you object to direct marketing, we will no longer process your personal data for that purpose.

 

24. Withdrawal of Consent

Where processing is based on your consent, you may withdraw your consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

You may withdraw consent by using the relevant unsubscribe link, changing cookie settings, or contacting us at info@carniq.ai.

 

25. Automated Decision-Making

We do not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

carAISuite may use AI-assisted features to generate, review, classify, or transform engineering content. Such outputs are intended for professional review and are not used by CARNIQ to make automated legal or employment decisions about individuals.

 

26. Third-Party Links

Our website and Services may contain links to third-party websites, platforms, or services. We are not responsible for the privacy practices, content, or security of third-party websites or services.

Please review the privacy policies of third-party providers before using their services or providing personal data.

 

27. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, technology, legal obligations, business operations, or data-processing practices.

The latest version will be published on our website with the effective date shown above.

Where legally required, we will notify affected users or customers of material changes.

 

28. Contact

For questions, concerns, or requests regarding this Privacy Policy or the processing of personal data, please contact:

CARNIQ Technologies GmbH
Orionstrasse 4
85716 Unterschleissheim
Germany

Email: info@carniq.ai
Phone: +49 (0) 15146859832

bottom of page