Beta phase: 50% discount for the first 6 months
Secure now
LEGAL

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how we process personal data in connection with Timmy, an AI-powered marketing automation tool.

1. Controller

The controller under the GDPR is Nuwis GmbH, Fritz-Tarnow-Str. 2A, 22869 Schenefeld, Germany, Managing Director: Mücahit Özcakir, email: info@nuwis.de.

2. Legal bases

We process personal data based on consent, contract performance, legal obligations and legitimate interests under Art. 6 GDPR.

3. Your rights

You have rights to access, rectification, erasure, restriction, data portability, objection and withdrawal of consent. You may also lodge a complaint with the competent supervisory authority.

4. Hosting

Timmy runs on Convex infrastructure in the EU region. Account, content, usage and technical access data are processed to deliver and secure the service.

5. Cookies and local storage

We use technically necessary session cookies and local storage. We currently do not use consent-based marketing or tracking cookies on public pages.

6. User account

Through Better Auth we process email address, name, password hash, session and verification information to provide the account.

7. AI content creation

To create text, images and scripts, inputs may be transmitted to providers such as Google Gemini, Firecrawl and, in preparation, fal.ai. Please do not submit special categories of personal data.

8. Connected platforms

At your request, Timmy publishes to connected channels such as LinkedIn, Instagram, YouTube, Google Business Profile, Google Search Console, WordPress, Payload CMS or custom blogs.

Google user data

Google user data is used only for enabled functions, not sold, not shared for advertising and not used to train general AI models. OAuth tokens are encrypted server-side and deleted or revoked when no longer needed, unless retention duties apply.

Publishing infrastructure bundle.social

To connect social media accounts, publish posts and retrieve statistics, comments and reviews (LinkedIn, Facebook, Instagram, YouTube, TikTok, X, Threads, Pinterest, Reddit) we use bundle.social (BUNDLE SP. Z O.O., ul. Hoża 86/410, 00-682 Warsaw, Poland) — as a processor under a data processing agreement, with processing on servers in the EU. The content and media to be published as well as platform metrics, comments and reviews are transmitted. Access tokens of connected social media accounts are stored by bundle.social, not in our database. bundle.social retains platform data for a limited period (statistics approx. 30 days); permanent archiving takes place in Timmy.

9. Email delivery

We use Brevo for transactional emails. Marketing emails are sent only with separate consent.

10. Analytics

We use PostHog via the EU cloud to improve product quality and stability without client-side tracking on public pages.

11. International transfers

Some providers may process data in the United States. Transfers rely on the EU-US Data Privacy Framework, standard contractual clauses or supplementary safeguards where applicable.

12. Storage and deletion

We store data only as long as necessary or legally required. Technical logs are usually deleted or anonymized within 30 days. Account and content data are generally deleted within 90 days after contract end unless retention duties apply.

13. Security

We use technical and organizational measures, TLS encryption and encrypted storage of credentials and tokens.

14. Processing on behalf

Where customers process personal data through Timmy, we act as processor on their behalf under a data processing agreement.

15. Updates

This Privacy Policy is currently valid and may be updated when the service or legal requirements change.