Data Processing Overview

This is a translation of the German data processing overview (Datenverarbeitungsübersicht). The German version is legally authoritative.

Last updated: April 2026


Scope

This overview describes all external service providers used in connection with our website michmatz.me and our product MichMatz ReadMe. It supplements our Privacy Policy with detailed information on data processing activities, data processors, and the handling of AI services.

Controller

MichMatz GmbH, Nikolausplatz 3, 50937 Cologne, Germany. Represented by Michael Schulz and Mathias Würthle. Email: hello@michmatz.me

Website (michmatz.me)

For the website michmatz.me, we use the following external services. Detailed information can be found in our Privacy Policy.

Product (MichMatz ReadMe)

Core Data Architecture Principle

Personal data (name, email, billing address, school affiliation, student profiles, learning progress) is stored exclusively at Hetzner in Germany.

AI providers receive only anonymous creative instructions (theme, genre, age group, language, CEFR level), never personal data.

Data Processors (Personal Data)

The following service providers process personal data on our behalf. Data Processing Agreements (DPAs) pursuant to Art. 28 GDPR have been concluded with all of them.

ProviderPurposeData ProcessedLegal BasisDPALocation
HetznerDatabase hosting, servers, backupsAll user data (email, name, credentials, profiles, learning progress)Art. 6(1)(b) GDPRYes (DPA via Hetzner portal)Germany (EU)
StripePayment processing, subscriptionsEmail, billing address, payment method, subscriptionArt. 6(1)(b) GDPRYes (automatic via SSA + DTA for SCCs)USA (EU data residency available)
BrevoTransactional emails (auth links)Email addresses, email contentArt. 6(1)(b) GDPRYes (via Brevo dashboard)France (EU)

AI Providers: No Personal Data

These providers generate fictional content (stories, images, audio). They receive only anonymous creative instructions, no personal data. No user can be identified from the data these providers receive.

Example: What AI providers receive

None of these examples contain personal data. The story is AI-generated fiction.

ProviderTypeData ReceivedPersonal Data?
Anthropic (Claude)Text (LLM)Anonymous creative instructionsNo
OpenAIText (LLM)Anonymous creative instructionsNo
Google GeminiText (LLM)Anonymous creative instructionsNo
MistralText (LLM)Anonymous creative instructionsNo
BFL / Black Forest Labs (FLUX)ImageAI-generated image promptsNo
OpenAI (DALL-E)ImageAI-generated image promptsNo
Google ImagenImageAI-generated image promptsNo
Hyperbolic (SDXL)ImageAI-generated image promptsNo
ElevenLabsAudio (TTS)AI-generated fiction textNo
OpenAI TTSAudio (TTS)AI-generated fiction textNo
Google Cloud TTSAudio (TTS)AI-generated fiction textNo
Gemini TTSAudio (TTS)AI-generated fiction textNo
Inworld AIAudio (TTS)AI-generated fiction textNo
Fish AudioAudio (TTS)AI-generated fiction textNo

Self-Hosted Services

The following services run entirely on our own Hetzner infrastructure in Germany. No external data transfer takes place.

Supabase (Postgres, Auth, Storage), NATS (message broker), Infisical (secrets management), Traefik (reverse proxy), Uptime Kuma (monitoring), Dozzle (log aggregation), CrowdSec (intrusion detection), Fail2ban (brute-force protection), Internal CA (mTLS certificates)

Data Processing Agreements (DPAs)

We have concluded Data Processing Agreements pursuant to Art. 28 GDPR with all providers that process personal data.

ProviderDPA StatusSCCs (Art. 46)
HetznerDPA via Hetzner account portalNot required (EU)
StripeAutomatic via Services AgreementYes, via Data Transfers Addendum
BrevoAccepted via Brevo dashboardNot required (EU), DPF certified

Data Transfers to Third Countries

Some service providers are based in the USA. Data transfers are carried out on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR or an adequacy decision (EU-U.S. Data Privacy Framework). AI providers in the USA receive no personal data, no third-country transfer of personal data to these providers takes place.

Further Information

The full privacy policy with information on your rights as a data subject can be found in our Privacy Policy.