Privacy Policy
for the website decky-ai.com and the PowerPoint add-in “Decky AI”
Last updated: July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Maven Labs UG (haftungsbeschränkt) Represented by the managing director: Maximilian Nitsche Baaderstraße 17 80469 Munich Germany
Register court: Amtsgericht München Commercial register number: HRB 308823 VAT identification number: DE462005553
Phone: +49 174 43 53 754 Email: hello@decky-ai.com
No data protection officer has been appointed, as there is no statutory obligation to do so (§ 38 of the German Federal Data Protection Act, BDSG).
2. Scope of Application and Definitions
2.1 Scope of Application
This Privacy Policy applies to:
- the PowerPoint add-in “Decky AI” (hereinafter the “Service”),
- the associated backend and API services required to provide its functions,
- the associated website at decky-ai.com (hereinafter the “Website”).
The add-in is aimed at both consumers (B2C) and businesses and corporate customers (B2B).
Role as processor: To the extent business customers have personal data of third parties (e.g., customers, employees, or business partners) processed through the Service via content they provide, Maven Labs acts as a processor within the meaning of Art. 28 GDPR in this respect. We conclude a separate data processing agreement (DPA) with the respective customer for this processing. This Privacy Policy primarily describes the processing activities for which Maven Labs itself is the controller.
2.2 Definitions
| Term | Definition |
|---|---|
| Inputs | All content provided by the user, including chat commands, presentation content, uploaded documents, and other data submitted for AI-powered processing. |
| Outputs | All results generated by the Service, including edited slides, generated text, images, or layout changes. |
| User Content | Collective term for Inputs and Outputs together. |
| Technical Data | Automatically collected operational data such as IP address, timestamps, and device/browser information. |
3. Collection of Personal Data
3.1 Data You Provide Directly
a) Account Data
Use of the Service requires a user account. Authentication is performed via Microsoft EntraID (formerly Azure AD CIAM). The following data is processed in this context:
- email address
- first and last name
- company (if provided)
- phone number (if provided)
- internal user ID (OpenID claims:
oid,sub) - timestamps of registration and login
- IP address and the approximate location derived from it (country/region) at registration and login
We process the IP address and the approximate region (country/region) derived from it to secure the account, to prevent fraud and abuse, and to provide region-specific offerings. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
b) Inputs and Outputs
In the course of using the Service, users may in particular input or upload the following content:
- text and chat commands
- PowerPoint presentations and slide content
- images (e.g., PNG, JPEG) and documents (e.g., PDF)
- other content for AI-powered processing
This content may contain personal data as well as corporate or confidential business data. The decision as to which content is submitted rests solely with the user.
c) Payment Information
If you take out a paid subscription, payment information is processed by our payment service provider, Stripe. Maven Labs does not store credit card numbers or bank details. We only receive from Stripe a customer ID, the subscription status, and the payment history (amounts and timestamps).
d) Feedback
If you use the feedback feature, the feedback is stored together with the associated conversation history in order to improve the quality of the Service. No feedback is collected under the Enterprise plan.
e) Communication
If you contact us by email, via the contact form on the Website, or via the support form, we process your name, email address, and the content of your message in order to process your inquiry (Art. 6(1)(b) or (f) GDPR).
3.2 Automatically Collected Data
When using the Service, the following Technical Data is automatically collected:
- Connection data: IP address, timestamps, HTTP status codes
- Usage data: number of requests, quota used, subscription status
- Error and crash reports: error messages, exceptions, affected functional areas
- Telemetry: operation names, response times, system status (without direct personal reference)
This data is used exclusively to ensure technical operation, security, and troubleshooting.
3.3 Necessity of Data Provision
Providing the account data listed in Section 3.1(a) is a contractual prerequisite for using the Service. Without this data, no user account can be created and the Service cannot be provided. Providing Inputs (Section 3.1(b)) is voluntary; however, the AI-powered features cannot be executed without it.
3.4 Data from Third Parties
As a general rule, we do not receive personal data about you from third parties, except where you authenticate via Microsoft EntraID, in which case we receive the data described in Section 3.1(a).
4. Purposes and Legal Bases of Processing
| Purpose | Legal Basis |
|---|---|
| Provision and operation of the Service, including AI-powered content creation, media search, authentication, and payment processing | Art. 6(1)(b) GDPR (performance of contract) |
| Operational security, quality assurance, and abuse prevention, monitoring, error analysis, LLM tracing (objection possible) | Art. 6(1)(f) GDPR (legitimate interest) |
| Communication and support | Art. 6(1)(b) GDPR (performance of contract) or Art. 6(1)(f) GDPR (legitimate interest) |
| Reach measurement and marketing on the Website (only with consent, e.g., Google Analytics, Google Ads, LinkedIn, Apollo) | Art. 6(1)(a) GDPR (consent), § 25(1) of the German Telecommunications-Telemedia Data Protection Act (TDDDG) |
Which categories of data are processed for the respective purposes is set out in §§ 3 and 5.
5. AI Processing and External Service Providers (Processors)
5.1 Principles of AI Processing
To provide the Service, Inputs are transmitted to external AI model providers. Depending on the plan and availability, we use different AI model providers (see Section 5.2 and the current list at decky-ai.com/subprocessors); the specific choice of model may change in the course of product operations. In this context:
- Processing primarily serves to execute the respective user request; in addition, as described in § 4, it may also serve security and quality assurance purposes.
- The AI model providers used generally process Inputs only temporarily to execute the request. Where no zero-data-retention agreement is in place with a given provider, brief interim storage for security and abuse review may occur (typically up to 30 days); the applicable exception for the Azure OpenAI Service is described separately below.
- Anthropic (Standard/B2C plan): We maintain an organization-wide zero-data-retention agreement with this provider. Inputs and outputs are not stored beyond execution of the request; only purely technical, brief interim storage (typically a few minutes up to one hour) occurs to accelerate requests. User content is not used to train or improve AI models.
- For the Enterprise plan, we likewise generally agree with the AI providers used for chat/LLM inference (in particular AWS Bedrock) that user content is not permanently stored beyond execution of the request (zero data retention). Purely technical, brief interim storage (typically up to 5 minutes) to accelerate requests may occur; no storage beyond this takes place. In addition, user content is not used to train or improve AI models.
- Exception – Microsoft Azure OpenAI Service (both plans): We use this provider exclusively for embeddings (semantic search) and AI image generation – not for chat/LLM inference over presentation content or conversation history. For this provider, the applicable standard abuse monitoring applies to these processing activities: the search and image generation requests submitted may be temporarily stored (typically up to 30 days). This data is not used to train or improve AI models.
Processing regions by user group: Under the Standard/B2C plan, AI inference may also take place outside the EU, depending on the provider used. For Enterprise customers, content processing takes place within the EU (EU-hosted infrastructure). Because some of the processors we use are operated by companies headquartered in the US despite EU hosting, access under foreign law (e.g., the US CLOUD Act) cannot be entirely ruled out; we address this risk through the safeguards described in § 7.2.
5.2 Register of Processors and Third-Party Providers
To operate the Service, we use processors and third-party providers from the following categories: AI model providers, internet research, image and media providers, as well as authentication, payment, and infrastructure. The complete, continuously maintained list – including location/region, data processed, purpose, and GDPR safeguard for each provider – can be found at decky-ai.com/subprocessors. We continuously maintain this list there; if a provider changes (switch, addition, or removal), we update this page first.
Note on analytics/tracing in the add-in: For quality assurance, error analysis, and product improvement, we process usage and LLM interaction data under the Standard/B2C plan. This processing takes place without permanent storage of an identifier on your device and on the basis of our legitimate interest (Art. 6(1)(f) GDPR, see § 4). You may object to this processing at any time in the add-in’s account settings (opt-out, Art. 21 GDPR). For business customers on the Enterprise plan, product analytics and tracing are technically disabled and unavailable; no transmission takes place.
6. Disclosure of Personal Data
Personal data is disclosed exclusively:
- To the processors and third-party providers listed in Section 5.2, to the extent necessary to provide the Service.
- To payment service providers (Stripe) for processing payment transactions.
- Pursuant to legal order to competent authorities, to the extent we are legally obligated to do so (e.g., requests from law enforcement authorities).
- To enforce our rights, to the extent necessary to assert, exercise, or defend legal claims.
- In connection with a corporate transaction (e.g., merger, sale, or transfer of business units), with the acquirer remaining bound by this Privacy Policy.
We do not sell personal data.
Within the Service (add-in), Maven Labs does not create user profiles for marketing purposes and does not share user content with advertisers. On our Website, we use reach measurement and remarketing technologies – only with your prior consent (see § 9.2); any advertising profiles created in this context relate to your browsing behavior on the Website, not to user content from the add-in.
7. International Data Transfers (Third-Country Transfers)
7.1 Processing Locations
Processing takes place predominantly within the European Union. Due to the AI infrastructure used, processing under the Standard/B2C plan may also take place in the United States. For Enterprise customers, we offer processing of AI models within the EU (see Section 5.1).
7.2 Safeguards for Third-Country Transfers
For transfers to third countries, we rely on the following safeguards pursuant to Art. 44 et seq. GDPR:
- Adequacy decisions of the European Commission, where applicable – in particular the EU-US Data Privacy Framework pursuant to Implementing Decision (EU) 2023/1795, to the extent and as long as the relevant US provider holds an active certification on the official list at dataprivacyframework.gov.
- Standard Contractual Clauses (SCCs) pursuant to Implementing Decision (EU) 2021/914, supplemented by a Transfer Impact Assessment (TIA), for transfers to providers for whom an adequacy decision cannot be relied upon (solely) or is no longer available.
- Data Processing Agreements (DPAs) pursuant to Art. 28 GDPR with the respective processors used.
Where US providers hold a certification under the Data Privacy Framework, we additionally base the transfer on Standard Contractual Clauses in order to ensure a consistent level of protection even in the event of future changes in the legal situation or loss of certification. An overview of our processors and third-party providers can be found in § 5.2; the continuously updated, authoritative version of this list is available at decky-ai.com/subprocessors and may change as the Service is further developed (e.g., when providers are switched or added). We will communicate material changes in accordance with § 16.
8. Storage and Deletion
| Data Category | Retention Period | Deletion |
|---|---|---|
| Account data | For as long as the user account exists, plus statutory retention periods (8 or 10 years depending on the document, pursuant to § 147 of the German Fiscal Code, AO) | After account deletion and expiry of statutory periods |
| Inputs and Outputs | Temporarily during the session; if LLM tracing is enabled, for up to 14 days in abbreviated form | Automatic deletion after expiry |
| Conversation state | For the duration of the usage session, potentially up to 30 days for resumption | Automatic cleanup |
| Slide library (saved slides) | Slides that you expressly save in your slide library are stored on our EU-hosted infrastructure until you delete the item or your account | Deletable by the user at any time; removed upon account deletion |
| Usage data and telemetry | Up to 90 days | Automatic rotation and deletion |
| Payment data (with Stripe) | Per Stripe’s privacy policy; tax-relevant data for 8 or 10 years depending on the document, pursuant to § 147 AO | Per Stripe’s privacy policy |
| Error and crash reports | Up to 90 days | Automatic deletion |
| Feedback | Until revoked or until the account is deleted | Upon request or upon account deletion |
The periods above concern storage by us or our tracing tool. Processing at the AI model providers is governed by § 5.1.
Data is deleted or anonymized as soon as the respective processing purpose no longer applies, unless a statutory retention obligation prevents this. The sole exception is content that you deliberately save in your slide library: these slides remain stored on our EU-hosted infrastructure, private to you or your organization, until you delete them.
9. Cookies and Similar Technologies
9.1 Add-in
Within the add-in, we do not use cookies and do not store any persistent identifiers on your device. For authentication, only technically necessary session data is held in memory. The product analytics described in § 5.2 takes place without device-side storage of an identifier; the assignment occurs server-side or only for the duration of the session. This analytics is active by default but can be disabled at any time by users in the add-in’s account settings (opt-out; Art. 6(1)(f) in conjunction with Art. 21 GDPR). For Enterprise customers, it is technically disabled and unavailable. Only your opt-out decision itself is stored – as a technically necessary piece of information (§ 25(2) TDDDG).
9.2 Website
On the Website (decky-ai.com), we use a consent management tool (Cookie-Script, cookie-script.com). On your first visit to the Website, you will be shown a cookie banner through which you can grant, restrict, or reject your consent by category (necessary/statistics/marketing). You may change or revoke your decision at any time, with effect for the future, via the “Cookie Settings” link in the Website footer.
Technically necessary cookies (e.g., to store your cookie consent) are set without consent pursuant to § 25(2) TDDDG. Statistics and marketing technologies are only set or loaded after your express, category-specific consent pursuant to § 25(1) TDDDG and Art. 6(1)(a) GDPR. The embedded Cal.com booking widget and the Fontshare font CDN are, by way of exception, loaded technically immediately when the respective page is accessed; this processing is based on our legitimate interest in a functioning appointment booking system and the display of the Website, respectively (Art. 6(1)(f) GDPR). Data may be transmitted to the respective providers in connection with these services.
Overview of Cookies and Services Used on the Website
The up-to-date cookie declaration, automatically recorded by the consent management tool (including exact cookie names and durations, which may change on the provider’s side), can be retrieved at any time via the “Cookie Settings” link in the footer.
| Category | Provider/Service | Purpose | Duration (typical) | Consent Required? |
|---|---|---|---|---|
| Necessary | Cookie-Script (consent management, EU) | Stores your cookie consent decision (CookieScriptConsent) | 12 months | No (§ 25(2) TDDDG) |
| Necessary | Microsoft Azure Static Web Apps (hosting/CDN) | Delivery of Website content (technical operation) | – | No (technical operation) |
| Necessary | Self-hosted fonts (Inter, served from decky-ai.com) | Display of the Website’s font | – | No (no third-party transmission) |
| Statistics | Google Analytics 4 (via Google Tag Manager, GTM-W8N84KRK) | Reach measurement, usage statistics for the Website | up to 24 months (_ga) | Yes |
| Marketing | Google Ads (AW-17878644536, googleadservices.com, doubleclick.net) | Conversion tracking and remarketing for Google Ads campaigns | up to 90 days | Yes |
| Marketing | LinkedIn Insight Tag (snap.licdn.com) | Conversion tracking and reach measurement for LinkedIn campaigns | up to 6 months | Yes |
| Marketing | Apollo.io website tracker (assets.apollo.io, aplo-evnt.com) | Recognition of recurring corporate visitors for B2B sales and marketing (lead identification) | up to 12 months | Yes |
| Functional | Cal.com (embedded booking widget, app.cal.com) | Enables booking a demo appointment directly on the Website | per Cal.com cookie policy | No – integration is loaded technically immediately upon accessing the page (Art. 6(1)(f) GDPR) |
| Functional | Fontshare (font CDN, api.fontshare.com) | Loads certain display fonts; in doing so, your IP address is transmitted to the provider | – | No – integration is loaded technically immediately upon accessing the page (Art. 6(1)(f) GDPR) |
10. Security Measures (Technical and Organizational Measures)
We implement appropriate technical and organizational measures pursuant to Art. 32 GDPR to ensure a level of protection appropriate to the risk. These include, in particular:
- Encryption: Data transmissions to our central services are generally encrypted (TLS). Data stored by us is encrypted using state-of-the-art methods.
- Access control: Token-based authentication and role-based access control for the system components we operate.
- Abuse protection: Rate limiting and automated detection of abusive usage.
- Regular updates: Timely deployment of security updates for the system components we operate.
11. Rights of Data Subjects
As a data subject, you have the following rights. To exercise your rights, please contact us at hello@decky-ai.com.
| Right | Basis | Explanation |
|---|---|---|
| Access | Art. 15 GDPR | You have the right to obtain information about the personal data we process about you. |
| Rectification | Art. 16 GDPR | You may request the rectification of inaccurate data or the completion of incomplete data. |
| Erasure | Art. 17 GDPR | You may request the deletion of your data, provided no statutory retention obligations preclude this. |
| Restriction of processing | Art. 18 GDPR | Under certain conditions, you may request the restriction of processing. |
| Data portability | Art. 20 GDPR | You have the right to receive the data concerning you in a structured, commonly used, and machine-readable format. |
| Objection | Art. 21 GDPR | You may object at any time to the processing of your data based on Art. 6(1)(f) GDPR. We will then cease processing unless we can demonstrate compelling legitimate grounds. |
| Withdrawal of consent | Art. 7(3) GDPR | If you have given consent, you may withdraw it at any time with effect for the future. |
Automated Decision-Making
No automated decision-making within the meaning of Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you. The Service uses AI models exclusively to generate content in response to your request; no automated decisions are made about your person, creditworthiness, suitability, or similar matters.
Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with the competent data protection supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach Germany Website: www.lda.bayern.de
12. Children and Minors
The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. Should we become aware that a child under 16 has provided us with personal data, we will delete it without undue delay. Please contact us at hello@decky-ai.com if you become aware of this.
13. User Responsibility for Submitted Content (Data Protection Perspective)
13.1 Personal Data of Third Parties
If a user submits personal data of third parties via the Service (e.g., in uploaded documents or presentations), the user is responsible for ensuring they have a sufficient legal basis for such processing (e.g., consent or legitimate interest). Where the user acts as controller and Maven Labs as processor, the separate data processing agreement applies (Section 2.1).
Individual/Standard plan (B2C): Since no separate data processing agreement is concluded between Maven Labs and the user for these plans, users on the Individual/Standard plan should not upload or input personal data of third parties via the Service unless they themselves have a sufficient independent legal basis for doing so. For the lawful processing of third-party data on our behalf, the Enterprise plan with a separate DPA is available.
13.2 Special Categories of Personal Data (Art. 9 GDPR)
The Standard/B2C plan is not intended for the processing of special categories of personal data (e.g., health data, data on racial or ethnic origin, political opinions, religious beliefs, biometric or genetic data); such data may not be submitted via the Service on this plan. Enterprise customers may only process such data within the scope of the separate DPA and where they have their own legal basis under Art. 9 GDPR; they must limit such processing to what is necessary.
14. AI Outputs – Transparency (Art. 50 EU AI Act)
The Service uses artificial intelligence (AI) to generate, edit, and structure content. All Outputs generated by the Service – including text, layouts, images, and structural suggestions – are generated wholly or partly by AI models. Users are hereby expressly informed that they are interacting with an AI system when using the Service and that the Outputs generated are machine-generated.
Pursuant to Art. 50(2) of the EU AI Act, we label AI-generated Outputs of the Service in a machine-readable format as artificially generated or manipulated. This labeling is mandatory, not merely optional, to the extent the relevant Output falls within the substantive scope of Art. 50(2) of the EU AI Act.
15. Microsoft Office Store
If distributed via the Microsoft Office Store (Microsoft AppSource), Microsoft’s privacy terms additionally apply (Microsoft Privacy Statement). This Privacy Policy is linked accordingly in the store.
Installation via the Microsoft Office Store is subject to Microsoft’s terms of use. Maven Labs has no influence over Microsoft’s data processing in connection with the store.
16. Changes to This Privacy Policy
Maven Labs may update this Privacy Policy in response to legal, technical, or organizational changes. In the event of material changes, we will inform you in an appropriate manner (e.g., by email or via a notice within the Service).
The current version is available at decky-ai.com/add-in-privacy-policy. The date of the last update can be found at the beginning of this document.
17. Contact
If you have any questions about this Privacy Policy or wish to exercise your rights as a data subject, please contact:
Maven Labs UG (haftungsbeschränkt) Baaderstraße 17 80469 Munich Germany
Phone: +49 174 43 53 754 Email: hello@decky-ai.com