Privacy policy.
How Creative Human AI GmbH collects, processes, and protects personal data on this website and in Glasshouse, the product it runs under the same domain. Written against the GDPR (Regulation (EU) 2016/679) and the German Bundesdatenschutzgesetz (BDSG).
This is an English rendering. The binding version is the German one at /datenschutz/.
The website parts of this policy are final. The Glasshouse parts are a draft for Creative Human AI GmbH and its counsel. 7 particulars are still marked pending below. Each names what has to be supplied; none carries an invented value.
1. Data controller
The data controller responsible for this website and for Glasshouse under Article 4(7) GDPR is:
Creative Human AI GmbH
Hedda Zinner Weg 7a
18106 Rostock
Deutschland
Represented by: Heiko Altrichter, Geschäftsführer.
Contact: contact@creativehuman.ai. For a Glasshouse account: support@creativehuman.ai.
2. What data we collect and why
We collect as little personal data as the site and the product can reasonably function with. Two categories come from the website, three from Glasshouse.
2.1 Server access logs
When you load a page on creativehuman.ai, our hosting provider (Cloudflare) automatically records:
- your IP address (truncated or hashed where configurable),
- the timestamp of the request,
- the URL you requested and the HTTP status of the response,
- your browser user-agent string and referring URL (if any),
- the country the request originated from (derived from IP).
These logs are used for security (detecting abuse, DDoS mitigation), operational stability, and diagnosing errors. They are not joined with any personal profile and are not used for advertising or user tracking.
2.2 Form submissions
When you submit a form on this site, whichever topic you pick, we collect the fields you provide, typically:
- your name,
- your email address,
- your organisation (if you provide one),
- the topic dropdown value (e.g.
glasshouse-cloud,training), to route your enquiry, - the free-text message you write.
We use this data only to respond to your enquiry and to have a business conversation with you. We do not sell it, do not share it with third parties outside the processors named in section 4, and do not use it for advertising.
2.3 Glasshouse: account and sign-in
Signing in to Glasshouse runs through Google Identity (Google SSO). From it we receive your name, your email address and your Google account identifier. We set a signed session cookie that lasts seven days. No password is stored on this route.
2.4 Glasshouse: materials, questions and runs
What you upload and type into Glasshouse, meaning documents, images and the decision question, is stored so a run stays reproducible and its report stays evidenced. From those materials the engine builds the graph, the cast, the personas' posts and the report. Materials are stored in the EU.
We train no models on your materials. Whether the providers we use may keep or use inputs for their own purposes is a matter of the contract with them.
Provider contracts: confirm the no-training-on-inputs assurance from each provider named in section 4.2 and name it here.
If your materials contain personal data about other people, you stay the controller for it and we process it on your instructions.
Processing agreement with customers: settle the Art. 28 GDPR template and how it gets signed.
2.5 Glasshouse: operation, security and billing
We log technical events with trace identifiers, and what a run consumed in tokens and credits.
3. Legal bases for processing
Under Article 6(1) GDPR, each category of processing rests on a specific legal basis:
- Server access logs: Art. 6(1)(f) GDPR, a legitimate interest in operating and securing the website against abuse and DDoS, and in diagnosing operational errors.
- Contact form data (initial enquiry): Art. 6(1)(b) GDPR, processing necessary for pre-contractual steps at your request. When you ask us for a demo, advisory, or training conversation, we need your contact data to respond.
- Continuing conversation and follow-up: Art. 6(1)(f) GDPR, a legitimate interest in maintaining a business conversation you initiated and in keeping a minimal record of correspondence.
- Glasshouse account, materials and runs: Art. 6(1)(b) GDPR. Without an account there is no access to the product, and processing your materials is the service you asked for.
- Glasshouse operation, security and billing logs: Art. 6(1)(f) GDPR, a legitimate interest in a service that runs, stays secure and bills correctly. For the billing records themselves it is Art. 6(1)(b) and Art. 6(1)(c) GDPR.
4. Processors and recipients
4.1 This website
The website relies on three data processors under Art. 28 GDPR. Each has a signed Data Processing Agreement (DPA) on file and each is obliged to process personal data only on our instructions.
Cloudflare, Inc. (hosting, CDN, edge functions, DDoS protection)
101 Townsend Street, San Francisco, CA 94107, USA.
Cloudflare serves this site and runs the Pages Function that receives your form submissions. Personal data that reaches Cloudflare includes IP address, user-agent, request metadata, and form submission payload. Cloudflare's EU data protection framework is documented at cloudflare.com/trust-hub/gdpr/.
Resend, Inc. (transactional email delivery)
United States.
The Pages Function hands each form submission to Resend, which delivers it as one email to our team inbox. Resend receives the submission payload and your email address as the reply-to. Resend's data protection documentation is at resend.com/legal/dpa.
Resend, Inc.: registered address, to be confirmed by counsel.
Google Ireland Limited (Google Workspace, business email)
Gordon House, Barrow Street, Dublin 4, Ireland (EU counterparty for GDPR purposes). Onward transfers are possible to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
The inbox that receives form submissions runs on Google Workspace. Google's data protection documentation is at workspace.google.com/terms/dpa_terms.html.
4.2 Glasshouse
Glasshouse sends content to two providers. What each one sees is stated in full, because for both the answer is text, not only numbers.
Google Cloud (hosting, sign-in, embeddings)
The service runs on Google Cloud, with the database on Cloud SQL and the stored files in Cloud Storage. Google Identity carries the sign-in. Vertex AI computes embeddings, the numeric vectors the report measures similarity with, and computing them means the text itself goes there: passages from your documents, the personas' posts, and the text of your question and of the report. What comes back is numbers; what is sent is content.
Alibaba Cloud Model Studio (inference)
Every model call the product makes goes there, carrying the text of your materials, your question, the personas' posts and the report.
Processing agreements: check the Art. 28 GDPR contracts with both Glasshouse providers and record what is in force here.
5. International data transfers
The website processors named in section 4.1 may transfer personal data to the United States. These transfers are governed by:
- the EU–U.S. Data Privacy Framework (DPF), to which Cloudflare Inc. and Google LLC are certified participants (Resend, Inc. is covered by the clauses below), and
- the EU Standard Contractual Clauses (2021/914) as a secondary safeguard, embedded in each processor's DPA with us.
For Glasshouse, inference reaches an endpoint in the eu-central-1 region. What decides where execution happens is not the region but the service deployment scope of the workspace in use, and under the current interim posture that scope is global. Processing outside the EEA is therefore not excluded, and this page deliberately makes no claim of EU-only inference.
Residency, re-audit open: the paragraph above states an interim posture and is re-checked before the first external customer account is opened.
Transfer basis for Glasshouse: record the standard contractual clauses in force with each provider and check the transfer impact assessment.
6. Cookies and tracking
This site sets no marketing cookies, no third-party analytics, and no cross-site trackers. The marketing pages serve their web fonts from this domain. Two pages, /glasshouse/ and /brew-chai/, load their fonts from Google Fonts, and Google may receive your IP address as a technical consequence of loading the font file. Google has documented this and supplies an SCC-backed processing notice at developers.google.com/fonts/faq/privacy. Apart from that, the only network requests made from your browser on this site are for the HTML, CSS, JavaScript, and images served by Cloudflare.
Glasshouse sets the cookies it needs to work: the signed session cookie of the sign-in, a short-lived state cookie that protects the sign-in itself, and one cookie each for the language, the colour scheme and your answer to the cookie notice. The legal basis is § 25 Abs. 2 Nr. 2 TDDDG. No third-party trackers are loaded.
Analytics. Neither the site nor Glasshouse sets an analytics cookie or loads a measurement tool, and the Glasshouse cookie notice therefore asks for no analytics permission: there is nothing to permit. If analytics is ever introduced, this policy is updated first with the tool, the data collected and the legal basis, and where § 25 TDDDG requires consent, it is asked for and runs only on an answer given then.
7. Retention
- Server access logs are retained by Cloudflare on our behalf for the period documented in Cloudflare's log retention policy (typically a short operational window, measured in days).
- Form submission emails in our Google Workspace inbox are retained for up to 24 months from the date of the enquiry. After 24 months we delete the submission, unless (a) you have become a client and the correspondence is part of an active engagement, or (b) we are legally obliged to keep it longer under tax or commercial law (§ 257 HGB / § 147 AO, up to 10 years for certain business records).
- Glasshouse materials and runs stay until you delete them or ask us to. That is the v1 policy and it exists so a report can still be evidenced months later. Account data stays while the account does.
- If you ask us to delete your data earlier, we will delete it unless point (b) above applies, in which case we will tell you which records we must keep and why.
Glasshouse logs and billing records: set the retention periods, taking the commercial and tax-law periods into account.
8. Who can access your data inside the company
Only the Geschäftsführung of Creative Human AI GmbH has routine access to the inbox that receives form submissions. Members of the engineering or advisory team only see your enquiry if and when it is relevant to responding to you.
9. Your rights under the GDPR
As a data subject you have, at no cost and without having to justify yourself, the following rights with respect to personal data we hold about you:
- Right of access (Art. 15 GDPR): you can ask what data we hold and receive a copy.
- Right to rectification (Art. 16): you can ask us to correct inaccurate data.
- Right to erasure (Art. 17, "right to be forgotten"): you can ask us to delete data we hold.
- Right to restriction (Art. 18): you can ask us to stop processing your data while you dispute its accuracy or our legal basis.
- Right to data portability (Art. 20): you can ask for your data in a machine-readable format and have it transmitted to another controller.
- Right to object (Art. 21): where we rely on legitimate interest (Art. 6(1)(f)), you can object and we must stop unless we show compelling grounds that override your interests.
- Right to withdraw consent (Art. 7(3)): if we ever ask for and rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email contact@creativehuman.ai, or for a Glasshouse account support@creativehuman.ai. We aim to respond within one month (Art. 12(3) GDPR) and will confirm receipt earlier.
10. Right to lodge a complaint
You have the right to complain to a supervisory authority (Art. 77 GDPR) if you believe our processing of your personal data violates the GDPR. Because Creative Human AI GmbH is registered in Rostock, the lead supervisory authority in Germany is:
Der Landesbeauftragte für Datenschutz und Informationsfreiheit Mecklenburg-Vorpommern
Werderstraße 74a, 19055 Schwerin, Deutschland
Telefon: +49 385 59494-0
E-Mail: info@datenschutz-mv.de
Web: datenschutz-mv.de
You may also lodge your complaint with the data protection authority in your EU member state of residence or place of the alleged infringement.
11. Data Protection Officer
Creative Human AI GmbH is not currently required to appoint a Data Protection Officer under § 38 BDSG (we have fewer than 20 persons continuously engaged in the automated processing of personal data, and we do not process special categories of data as a core activity). If the company's scale or the nature of its processing crosses the threshold, we will appoint a DPO and update this policy immediately.
12. Automated decision-making
No decision about you is taken automatically, on this website or in Glasshouse. Glasshouse plays a decision forward against synthetic personas and writes a report about it; what is then done with that report is decided by people. There is no automated decision-making producing legal or similarly significant effects for you within the meaning of Art. 22 GDPR, and no profiling of you on which such a decision could rest.
13. Personas are synthetic
The personas in a Glasshouse run are invented. They are built from roles and traits, never from profiles of real individuals, and Glasshouse keeps no register of real people for a run to be matched against. Real organisations can appear in your materials and in a report; a real, identifiable individual as a persona is ruled out.
14. Children's data
This site is a business-to-business site, and Glasshouse is offered to businesses only. Neither is directed at children, and we do not knowingly collect personal data from minors. If you believe a minor has submitted personal data through this site, email us and we will delete it.
15. Changes to this policy
We may update this policy as the site, the product and the company evolve, for example when we introduce product analytics, add a new processor, or change a retention period. Changes are announced by updating the "Last updated" date below. Where a change materially affects your rights, we will flag it more prominently. The paragraphs marked pending lose that mark as counsel signs them off.