Privacy policy.
What happens to personal data when you visit getmow.ai. Written against the GDPR and the German TDDDG. Plain language, because a policy nobody can read protects nobody.
Last updated: 13 August 2026
1. Who is responsible
The controller within the meaning of Art. 4(7) GDPR is:
Cloud Studios UG (haftungsbeschränkt)Wiclefstraße 59
10551 Berlin, Germany
Managing Director: Eli Läufer
Amtsgericht Charlottenburg, HRB 280883 B
hello@getmow.ai
Get MOW is a brand and product of Cloud Studios UG (haftungsbeschränkt) and is not a separate legal entity. Full provider details are in the Impressum.
For any question about your personal data, write to hello@getmow.ai. You do not need to give a reason and there is no charge.
2. Data protection officer
We have not appointed one, and we are not required to. Art. 37(1) GDPR makes a data protection officer mandatory only for public authorities, for large scale regular and systematic monitoring, or for large scale processing of special category or criminal conviction data. Section 38(1) BDSG adds a threshold of twenty people constantly engaged in automated processing, processing requiring a data protection impact assessment, or commercial processing for transfer or market research. None of these applies to us.
3. What we do not do
- No advertising pixels, no conversion tracking, no retargeting and no heatmaps.
- No advertising cookies, and no profiles built about you as a person. Measurement is described in section 3a and happens only if you accept it.
- Fonts are self-hosted. Your IP address is never sent to a font provider.
- No contact form, no newsletter, no chat widget, no account and no login.
- We do not sell personal data and we do not pass it to advertising networks, data brokers or list vendors.
Before you choose, nothing happens. Until you answer the banner, this site sets no cookies, writes nothing to your browser storage, and makes no request to any third party. That is not a promise about our intentions, it is how the code is built: the measurement software is not even downloaded until you accept. If you decline, it is never downloaded at all.
Two things we write to your device either way. The first is your answer to the banner itself, stored as mow-consent in your browser's local storage. It records the version of the notice, whether you accepted, and when. It contains no identifier of any kind. Without it we would have to ask you again on every single page, which would be worse for you, so we treat it as strictly necessary under Section 25(2) no. 2 TDDDG. The second is a flag named mow-ident, written the first time you open the homepage in a browser session so the short brand intro does not replay on every page load. It holds one value, contains no identifier, is never sent to anyone, and your browser discards it when the session ends. Same basis.
We use no consent management platform. The banner is our own and it talks to nobody. There is one choice, on one layer, and refusing takes exactly one click, the same as accepting.
3a. Measurement, only if you accept
If you accept on the banner, we measure how this website gets used so we can improve it. If you decline, everything in this section simply does not happen, and no part of the site works any differently for you.
What we use: PostHog, a product analytics tool. Our instance runs on PostHog Cloud EU, hosted in Frankfurt, Germany.
What is collected: the pages you open and in what order, the page that referred you, your approximate country, browser and device type, and whether you pressed the button that loads the booking calendar. It also includes a session replay: a reconstruction of your visit that lets us watch how the pages were used, as a silent playback built from what was on screen and where the pointer moved.
What is deliberately excluded: we do not record your IP address, which is discarded rather than stored. Every form field is masked before anything leaves your browser, so typed content is never captured. Nothing inside the Cal.com booking frame is recorded. Network request contents are not recorded. No profile is created for you as a person, and nothing here is combined with your name or email if you later book a call.
Legal basis: your consent, under Section 25(1) TDDDG for the storage on your device and Art. 6(1)(a) GDPR for the processing that follows. You can change your mind at any time using the “Privacy choices” link at the bottom of every page. Withdrawing stops the recording immediately, deletes what PostHog had stored in your browser, and is exactly as easy as accepting was. Withdrawal does not affect what was processed beforehand.
Processor and transfer: PostHog, Inc. is established in the United States, although the data described here is stored on servers in Frankfurt. Any access from the United States rests on the European Commission's Standard Contractual Clauses. PostHog, Inc. is not certified under the EU-US Data Privacy Framework. To confirm: the executed PostHog data processing agreement and its date. PostHog issues a DPA to Cloud customers on request; request it before this section goes live and record when it was signed
Retention: session replays are kept for one month and event data for twelve months, after which PostHog deletes them.
4. Server log data
When you open a page, your browser sends a request to our hosting provider, which records it in a log file. That happens on every website, whether or not you interact with anything.
What is recorded: your IP address, the date and time, the page requested, the volume transferred, the HTTP status code, the referring URL if your browser sends one, and your browser and operating system identifiers.
Why: to deliver the site, keep it available, defend against attacks and abuse, and diagnose faults.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operating a secure and functioning website. The data is not combined with other data and is not used to profile you.
Processor: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, United States, acting on our behalf under an Art. 28(3) GDPR data processing agreement.
Transfer to the United States: Vercel Inc. states that it complies with the EU-US Data Privacy Framework, having certified its adherence with the US Department of Commerce, and that it uses standard contractual clauses where appropriate. The transfer of log data rests on those mechanisms.
Retention: we operate no log storage of our own, we do not export logs, and we do not combine or analyse them. Vercel keeps runtime logs for a short period fixed by our plan, currently one hour on its Hobby plan and one day on its Pro plan, after which they are gone.
5. Booking a call
Our booking page can display a scheduling calendar provided by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, United States. The calendar is not part of our website. It is a Cal.com page shown inside a frame on ours.
It does not load until you ask for it. The booking page first shows a static placeholder. No connection to Cal.com is made and nothing leaves your browser at that point. The calendar loads only when you press the button that asks for it. Pressing it is your consent under Section 25(1) TDDDG to Cal.com storing and reading information on your device, and your consent under Art. 6(1)(a) GDPR to your IP address and browser data being transmitted to Cal.com for that purpose. Consent applies to that page view; reload the page and the placeholder returns. You can withdraw consent at any time by not loading the calendar, and you can always email us instead.
What Cal.com receives when the calendar loads: your IP address, user agent, screen and language settings, the referring page and the time of the request. Cal.com then sets cookies on your device under the cal.com domain, including a Cloudflare bot protection cookie that expires after about thirty minutes. Cal.com describes the cookies it uses, including analytics and advertising cookies on its own platform, in its privacy policy.
What you give Cal.com if you complete a booking: your name, email address, time zone, the slot you choose and your answers to the booking questions. Cal.com may add technical data such as your IP address and the booking time. The booking then appears in our calendar and a confirmation email is sent to you.
Our calendar is Google. We run Google Workspace, so completing a booking also writes the event into our Google calendar, including your name, your email address, the time and anything you wrote in the booking questions. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland is our processor for that under Google's Cloud Data Processing Addendum, so the leg between us and Google stays inside the European Economic Area. Where Google moves data onward to the United States, that transfer rests on Google LLC's certification under the EU-US Data Privacy Framework, with Standard Contractual Clauses as the contractual fallback.
Legal basis for the booking data: Art. 6(1)(b) GDPR where you are booking on your own behalf, because arranging the call is a step taken at your request before a contract. Where you book for a company, Art. 6(1)(f) GDPR: our legitimate interest, and your employer's, in arranging a business conversation with the right person. You can object to that processing at any time under Art. 21 GDPR. You are not obliged to provide any of it. Without it we cannot schedule a call, but you can email us and arrange one that way.
Who is responsible for what. For the booking data you enter, we decide the purpose and Cal.com, Inc. processes it on our instructions under a data processing agreement concluded between us on 13 August 2026. For the loading of the frame we are the controller: we chose to embed Cal.com and you consented by pressing the button. Once the calendar has loaded, Cal.com is an independent controller for what it does with data for its own purposes, which is governed by its policy and not by ours. Cal.com names a data protection officer at legal@cal.com and an Art. 27 GDPR representative at legal+eu@cal.com.
Transfer to the United States. Cal.com, Inc. is established in the United States and booking data is processed there. The transfer rests on the European Commission's Standard Contractual Clauses, incorporated into our data processing agreement with Cal.com: Module Two, controller to processor, for the data we send them, and Module Three, processor to processor, where they pass data to their own sub-processors. Cal.com, Inc. is not certified under the EU-US Data Privacy Framework, so the clauses are the mechanism, not a fallback. United States law permits public authority access to data held by US providers on terms that differ from EU law. If we judge that those safeguards no longer hold, we will move to an EU-hosted alternative and update this policy.
Retention. Bookings that did not lead to a conversation, and their form answers, are deleted after six months. Where a call leads to a contract, the related records are kept for the statutory periods under Section 257 HGB and Section 147 AO on the basis of Art. 6(1)(c) GDPR.
6. Cookies and access to your device
Section 25(1) TDDDG permits storing information on your device, or reading information already there, only with your prior informed consent. That covers cookies and equivalents such as local storage, session storage and fingerprinting. Section 25(2) creates narrow exceptions for transmission and for what is strictly necessary to provide a service you expressly requested.
Before you answer the banner, the only things written to your device are the two flags described in section 3, mow-consent and mow-ident. Both hold a single value, neither contains an identifier, neither is readable by any third party, and neither is ever transmitted.
Two things go beyond that, and each has its own separate consent:
- Measurement, if you accept on the banner. PostHog then stores an anonymous identifier on your device so a single visit can be stitched together. Declining means it is never downloaded, so nothing is stored. Section 3a has the detail.
- The Cal.com calendar, if you press the button that loads it. It sits behind that click for exactly this reason: nothing is requested from Cal.com until you press it, so the press is the consent. Section 5 has the detail.
These are independent. Declining measurement does not stop you booking a call, and loading the calendar does not turn measurement on.
7. Contacting us by email
If you email us we receive your address, your name if you give it, and whatever you write.
Legal basis: Art. 6(1)(b) GDPR where you write on your own behalf about a possible or existing contract. Where you write for a company, Art. 6(1)(f) GDPR, our legitimate interest in answering enquiries addressed to us. You can object to the latter at any time under Art. 21 GDPR.
Processor: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, our email provider through Google Workspace, acting under Google's Cloud Data Processing Addendum, which is our Art. 28 GDPR agreement. Our contracting party is the Irish entity, so the leg between us and Google stays inside the European Economic Area. Where Google moves data onward to the United States, that transfer rests on Google LLC's certification under the EU-US Data Privacy Framework, with Standard Contractual Clauses as the contractual fallback.
Retention: correspondence is kept while the conversation is live and for twenty-four months afterwards, so we can pick up a thread again. Where an email forms part of a commercial or tax record, Section 257 HGB and Section 147 AO apply instead, on the basis of Art. 6(1)(c) GDPR.
8. Your free audit
If you request an audit, we prepare an assessment of how AI engines currently answer questions in your category and publish it as a page on the getmow.ai domain, which we then discuss with you on a call.
What we process: your name, business email address, company and website, your answers to our questions, and information about your company and market that is publicly available or comes from our own queries to AI engines and search engines. The audit is about a company and its products, not about you as an individual, but your name and contact details are attached to it.
Legal basis: Art. 6(1)(b) GDPR where you request the audit on your own behalf, otherwise Art. 6(1)(f) GDPR, our legitimate interest, and your employer's, in preparing a substantive assessment before a commercial conversation.
What we send to AI engines and AI providers. Two different things happen, and only the second involves you personally.
The queries we run against public AI engines to see how your category is answered contain categories, companies and products. They contain no personal data, because they are the questions a buyer would ask.
Producing the audit document itself does involve an AI system, and your name and your company are part of what is sent to it. The provider is Anthropic PBC, established in the United States. That transfer rests on the European Commission's Standard Contractual Clauses, Modules Two and Three, incorporated into Anthropic's commercial terms; Anthropic PBC is not certified under the EU-US Data Privacy Framework. Under those commercial terms your data is not used to train any model. You can obtain a copy of the safeguards by writing to us. If you would rather your name were not sent to an AI provider at all, tell us and we will prepare your audit using the company and domain only.
For companies we have researched but not yet spoken to, we do not put a named individual into an AI system at all: that research runs on the company and its public material.
Access: your audit page has a long, unguessable address, is excluded from search engines, and is not linked from anywhere on getmow.ai. Anyone you forward the address to can open it. If you want it access controlled or taken down, tell us and we will do it. Retention: audit pages and their underlying data are deleted twelve months after the call, unless an engagement follows.
8a. Data we collect about you from other sources
When we research a company for an audit, or before making contact, we may collect a professional contact's name, role, business email address, company and public statements from the company's own website, public professional networks, and the answers search engines and AI assistants give about that company.
Why: to reach the right person and to prepare a substantive assessment. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in business development. Categories and source: as above, always business contact data from public sources, never special category data.
Notice: we tell you we hold this data at the latest in our first message to you, and always within one month of collecting it, as Art. 14 GDPR requires. Retention: deleted twelve months after the last contact, or immediately if you ask.
9. Recipients
- Vercel Inc., United States, our hosting provider, which processes server log data. Processor under Art. 28 GDPR.
- Cal.com, Inc., United States, for the booking calendar, which is where a booking is held. Processor for the booking data you enter, independent controller for its own purposes.
- Google Ireland Limited, Ireland, for Google Workspace: our email, and the calendar a completed booking is written into. Processor under Art. 28 GDPR.
- PostHog, Inc., United States, hosting our analytics instance in Frankfurt. Only if you accept measurement. Processor under Art. 28 GDPR.
- Anthropic PBC, United States, the AI provider used to produce a personalised audit. Only where you have asked for an audit. Processor under Art. 28 GDPR.
- Professional advisers and authorities, where we are legally required to disclose data or need advice to establish or defend a legal claim. Art. 6(1)(c) or Art. 6(1)(f) GDPR.
Nobody else. We do not pass personal data to advertising networks, data brokers or list vendors.
10. No automated decision-making
We use no automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22(1) GDPR. Nothing on this site scores you, ranks you or decides anything about you automatically.
11. Your rights
Your right to object. Where we process your data on the basis of our legitimate interest, which covers our server logs, our research for audits and business contact data, you can object at any time on grounds relating to your particular situation. Where we process it for direct marketing, you can object at any time with no reason and we stop. Write to hello@getmow.ai.
Write to the same address to exercise any of the rights below. We respond within one month, and will tell you if we need longer, which Art. 12(3) GDPR permits in limited cases.
- Access, Art. 15. Whether we process data about you, and a copy of it.
- Rectification, Art. 16. Correction of inaccurate data, completion of incomplete data.
- Erasure, Art. 17. Deletion where one of the grounds in Art. 17(1) applies.
- Restriction, Art. 18. A pause on use while an accuracy dispute or objection is resolved.
- Portability, Art. 20. Data processed on consent or contract, by automated means, in a machine readable format.
- Objection, Art. 21. Against processing based on Art. 6(1)(f), on grounds relating to your particular situation. Against direct marketing at any time, with no reason needed.
- Withdrawal of consent, Art. 7(3). Including consent to load the booking calendar. Withdrawal does not affect processing carried out before it.
12. Complaints
Under Art. 77 GDPR you may complain to a supervisory authority in the member state where you live, where you work, or where the alleged infringement took place. The authority competent for us is:
Berliner Beauftragte für Datenschutz und InformationsfreiheitAlt-Moabit 59-61, 10555 Berlin, Germany
Telephone: +49 30 13889-0
mailbox@datenschutz-berlin.de
You are welcome to raise the issue with us first, but you are under no obligation to, and your right to complain is unaffected either way.
13. Security, children, changes
The site is served over HTTPS with TLS. The mailbox and calendar where enquiries and bookings arrive are reachable only by the two people who run Get MOW, each through their own named account. We keep the number of systems that touch your data deliberately small, and every provider named in section 9 processes it on our instructions under a data processing agreement. We review these arrangements at least once a year, and whenever the site, the tools or the law change. No transmission over the internet is completely secure and we do not claim otherwise.
This website addresses businesses and people acting in a professional capacity. It is not directed at children and we do not knowingly collect data from them.
We update this policy when the site changes or the law does. The date at the top shows the current version. Material changes are reflected here before they take effect.