Controller
anycast.io UG (haftungsbeschränkt)
Hintere Straße 125a, 90768 Fürth, Deutschland
Privacy
Stand: September 2026
anycast.io UG (haftungsbeschränkt)
Hintere Straße 125a, 90768 Fürth, Deutschland
We process personal data where necessary to operate the platform, provide sign-in and billing, support team functions and deliver the service securely.
This includes email addresses, account data, technical access data, usage data and content stored in threads, projects, research runs or storage functions.
We operate the 2342.ai core platform on our own infrastructure at the Deutschherrnkarree in Nuremberg. Core-Backbone GmbH provides colocation and network connectivity. We do not use a third-party public cloud as the primary infrastructure for storing and delivering the core platform.
Server logs may contain IP addresses, timestamps, requested URLs, browser information and technical error data. This processing supports secure platform operations.
For sign-in, we process email address, session data and technical device data. Magic-link sign-in creates and verifies a time-limited token.
Session and access data are processed to enable sign-in, limit misuse and manage existing sessions.
When you use the platform, we process content from chats, projects, research runs, file uploads, vector stores and API calls. We also store the selected model, timestamps, token usage and cost information.
When you use an external model through our platform, data required for that processing is forwarded to the relevant provider.
Depending on the selected external model, Amazon Web Services EMEA SARL, Google Cloud EMEA Limited and Microsoft Ireland Operations Limited may be involved as providers or subprocessors.
For external models, processing location, retention and other conditions depend on the selected data path and applicable agreements. We do not make a blanket promise that every external AI request is processed exclusively in EU data centers. GLM 5.2 uses a regional European endpoint. We do not promise Germany-only processing or zero data retention for this data path.
Our Data Processing Agreement and current subprocessor list are publicly available at 2342.ai/en/dpa and 2342.ai/en/subprocessors. Organization owners and admins can accept the current DPA electronically in the organization area and retrieve a record containing its version, timestamp and document fingerprint. We provide a countersigned copy to business customers on request.
Not every model is automatically suitable for every use of personal or confidential data. Controllers must choose a suitable model and data path based on purpose, contractual basis and data type. The model catalog identifies GLM 5.2.
2342.ai does not use customer data to train its own foundation models. For GLM 5.2 as a Public Preview model, Mistral reserves the right to use inputs and outputs for training; the general training opt-out and ZDR do not apply under the preview terms.
Chats, files, vector stores, API logs and usage data may be retained for different periods depending on the feature and as necessary for operations, billing, security, team functions or legal obligations.
Customers can delete content and accounts. Statutory retention obligations, billing records and security logs may prevent the immediate deletion of every technical record.
When you use team functions, we process team membership, roles, invitations and shared content such as prompt libraries or budget information.
Certain team data, including name, email address, role and team-related usage values, may be visible to authorized team members.
For billing and payment processing, we process plan and usage data. Payment data itself is processed only through the payment service providers used for the relevant transaction.
Subject to the GDPR, you have in particular the rights of access, rectification, erasure, restriction of processing, data portability and objection.
For privacy-related requests, use the contact details published in our imprint at 2342.ai/en/imprint.