Legal
Privacy Policy
Last updated: March 2026
1. Who we are
Bienity is a technology company registered under the legal name of Muhammad Kamran Ali in Berlin, Germany. We develop and operate multiple Software-as-a-Service (SaaS) products. The Bienity website serves as the public discovery and marketing platform for our product ecosystem.
Data controller: Bienity, Ebertystr. 35 Berlin, Germany
Contact: [email protected]
2. What data we collect
We collect only what is necessary to operate this website and respond to your enquiries:
- Contact form data (name, email, message) — only when you submit the form
- Newsletter email — only when you voluntarily subscribe
- Website analytics data via Umami (see section 4)
We do not collect sensitive personal data, financial information, or create user profiles.
3. Legal basis for processing
We process your data under the following legal bases (GDPR Art. 6):
- Consent (Art. 6(1)(a)) — newsletter subscription
- Legitimate interest (Art. 6(1)(f)) — responding to contact form enquiries, website security
- Contract performance (Art. 6(1)(b)) — when you enquire about our services
4. Analytics — Umami
We use Umami, a privacy-first, open-source analytics platform. Umami does not use cookies, does not track users across websites, and does not collect personally identifiable information.
All analytics data is stored exclusively on servers located in Germany and is not shared with third parties. Umami is fully GDPR-compliant by design — no consent banner is required for its use.
Data collected includes: page views, referrer domain, browser type, device type, and approximate country — all anonymised and aggregated.
5. Merchant customer data
We do not read, collect, store, or process the personal data of our merchants' customers. Our apps access only publicly available store data — product titles, descriptions, pricing, blog content, and store metadata — which is the same information already visible on the merchant's public storefront.
We do not access, store, or transmit:
- Customer names, email addresses, or phone numbers
- Order history or purchase behaviour
- Payment or billing information
- Customer browsing or behavioural data
- Shipping addresses or delivery details
The only personal information we collect and store is the store owner's information (name, email address, company name, and business address) — provided during app installation via Shopify's official OAuth flow. This information is used solely for account management, service communication, and GDPR compliance. We do not share this information with any third party.
6. Data storage and infrastructure
All personal data (store owner information) and operational data is stored exclusively on infrastructure located in Germany, provided by IONOS SE, a GDPR-compliant hosting provider headquartered in Montabaur, Germany. We do not transfer personal data outside the European Economic Area (EEA).
Infrastructure details:
- Application servers: IONOS Cloud, Germany
- Database: IONOS Cloud, Germany & Supabase (AWS eu-central-1, Frankfurt, Germany)
- Analytics (Umami): self-hosted on IONOS infrastructure in Germany
All infrastructure providers operate within the European Union and are subject to GDPR.
7. Data retention
Website data:
- Contact form submissions: retained for up to 12 months, then deleted
- Newsletter subscriptions: retained until you unsubscribe
- Analytics data: aggregated and anonymised; individual session data is not stored
App and merchant data:
- Merchant account data: retained while the app is installed; permanently deleted 30 days after uninstall or account deletion request
- Generated content, job history, and billing records: deleted with the account
- Blog analytics: retained for up to 2 years while the app is installed; deleted with the account
8. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI).
9. Third-party services
We use the following third-party services on this website:
- Umami Analytics — privacy-first, Germany-hosted, GDPR-compliant
10. Third-party AI data processing
Our SaaS products use third-party AI providers to process data on behalf of merchants. The following providers are used:
- Anthropic / Claude (US-hosted) — used by GhostQuill for all content pipeline steps: discovery, research, generation, auditing, and fact-checking. Processing occurs in the United States under a data processing addendum that prohibits training on merchant data.
- Mistral AI (EU-hosted) — used by Parley for conversational AI and store-aware customer support. Processing occurs within the European Union.
What data is sent to AI providers: Only publicly available store and product data — including product titles, descriptions, categories, pricing, and store metadata. This is the same information already visible on the merchant's public storefront.
What data is never sent: Customer personal data — including buyer names, email addresses, order history, payment information, and behavioural data — is never transmitted to any AI provider at any step of the content pipeline.
All AI processing is initiated server-side by Bienity infrastructure. Merchants can review and edit all generated content before it is published to their store.
11. Changes to this policy
We may update this policy periodically. Significant changes will be communicated via our website. The "last updated" date at the top of this page reflects the most recent revision.
12. Contact
For any privacy-related questions: [email protected]
Bienity, Ebertystr. 35 Berlin, Germany