Privacy statement
Thank you for visiting our website and for your interest in our app and our company. In the following privacy policy, we inform you about our processing of your personal data and your rights as a Data subject.
Our offers, including this website, are not intended for children.
For the purposes of easier readability, we use the masculine form for personal designations in this privacy policy where appropriate. However, it goes without saying that all genders (m/f/d) are equally included and meant.
I. Responsible person and data protection officer
Flyweight GmbH, represented by the managing directors: Matthias Frisch, Marc-Andre Hoffmann and Christian Jürgen Cook, Jungbuschstraße 28, 68159 Mannheim.
II. Processing of your data
1. Website visitors
Below we explain how we process your personal data when you visit our website.
a. Visit the website without input
When you visit our website without making any further entries, the browser used on your device sends information for technical reasons.
Data categories: Technical data (IP address, device type and model, operating system, browser type and version, time zone and language setting, access date and time and the referrer URL - the website from which you came).
Purpose: We process the aforementioned data categories in order to provide the content of the websites accessed and for the security of our IT systems. This data is not used for any other purpose.
Origin of the data: This data is collected directly from you.
Legal basis: The processing is based on our legitimate interest in accordance with Article 6 para. 1 lit f. GDPR. Our legitimate interest in the processing lies in the provision of the website and ensuring the security of our IT systems used for this purpose.
Storage period: The data is only stored temporarily for the duration of the session. They are deleted after the end of the respective session.
Recipient category: Security provider
Location of the recipients: USA
Guarantees for transfers to third countries: Privacy Framework
b. Contact us
You can contact us at any time using the contact forms provided on our website.
Data categories: Customer data (first name, surname); contact data (telephone number and e-mail address); communication data (content of your message).
Purpose: To receive and respond to your contact.
Source of the data: We receive this data directly from you via the contact medium you have selected.
Legal basis: If pre-contractual measures are initiated by the message, e.g. a request for products or services or this was sent in connection with an existing contract, the data in question is processed in accordance with Art. 6 para. 1 lit. b GDPR.
Storage period: If no further cooperation results from the contact, we will only store your data until your inquiry has been answered or the correspondence with you has been completed. If further cooperation results from the initial contact, the corresponding storage periods of the listed processing apply. As a rule, your data will be deleted after expiry of the limitation period, starting at the end of the year in which the contractual relationship was terminated.
Recipient category: Software provider, cloud storage provider
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
c. Use of web analysis tools
We use web analytics tools to gain insights into the use of our website so that we can measure and improve the performance, content or functionality of our website. We use the following analysis service providers:
- Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043, United States Tools used: Google Analytics and Google Tag Manager
- Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA Tool used: Microsoft Clarity
These tools use cookies and embedded scripts to collect and analyze data about user behavior on our website. These cookies are only used if you have previously given your consent to their use. Further information on the use of cookies can be found in the relevant section below.
Data categories: Technical data (IP address, device type and model, operating system, browser type and version, screen resolution, time zone and language setting, access date and time, user interactions such as clicks and scroll behavior, and the referrer URL – the website from which you came).
Purpose: To measure interaction with our website, understand user behavior, assess the success of our online offering, and improve our website’s content, functionality, and usability.
Source of the data: This data is collected directly from you through the use of cookies and embedded tracking scripts.
Legal basis: The processing takes place on the basis of the consent obtained from you via our cookie consent tool in accordance with Art. 6 para. 1 lit. a GDPR.
Storage period: The data is only stored temporarily. It is anonymized and/or deleted after the session or after a defined retention period, as specified by the respective service providers.
Recipient category: Software provider
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU standard contractual clauses (SCC)
d. Consent management
We use a cookie consent tool on our website.
Data categories: Date and time of the visit, browser information, information on consent, information on the end device, IP address of the requesting end device.
Purpose: The purpose of data processing is to offer visitors to our website the opportunity to consent to the use of cookies. The documentation of such consent is required in accordance with the accountability obligation under Art. 5 para. 2 GDPR and is necessary to ensure the revocation of consent and to control the setting of cookies.
Source of the data: This data is collected directly from you.
Legal basis: The processing of the above data is based on Art. 6 para. 1 sentence 1 lit. c GDPR in conjunction with. § 25 para. 1 TDDDG.
Storage period: We delete your personal data when it is no longer required to achieve the purpose for which it was processed. This is usually the case after three years, starting at the end of the year in which the data was collected.
Recipient category: Software provider
Seat of the recipients: EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
e. Training and use of the app as provider of the chatbot
Processed data categories: The data categories result from the content of the website. In most cases, this will be contact data.
Purpose of processing: Creating the database with the necessary information for the chatbot and processing the data from the database to create the answers to the end customers' inquiries using the chatbot.
Source of the data: We collect this data directly from you.
Legal basis: We process the data to fulfill the contract in accordance with Article 6 (1) (b) GDPR.
Storage period: We store this data for the term of the contract and beyond until the expiry of statutory retention periods, which may be 6 to 10 years.
Recipient category: Software providers, cloud storage providers, payment service providers
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC), Privacy Framework
f. Use of the app as a visitor to our customers' website
When using the chatbot, your queries are combined using the database created from the website information read from our own website and a large language model to provide you with answers to your query. The chatbot is instructed not to ask for personal data. Good to know: If separate forms appear as a result of your inquiries, in which you may then have to provide personal data based on your inquiry, the information you provide there will be processed separately and accordingly not sent to AI.
Processed data categories: The data categories result from your requests when you provide personal data within the question. For example, if you ask “Where is my order?”, a form will appear for you to enter your order number and zip code. For another example, if you would like to find out more details about a product and be advised accordingly, a form will appear to record how you would like to be contacted, you can enter the relevant information (such as: name, telephone, email, etc.).
Purpose of processing: Processing of your data to create answers to the requests from you as an end customer using the chatbot. For example, if you ask “Where is my order?” and enter your order number and zip code, this information will be used to make a direct request to the store system (Shopify) so that the delivery information can be sent and you can be informed of the status of the order. If you would like advice on a product, your request (with the data you have provided and the entire chat history) will be forwarded to the store operator so that they can contact you.
Source of the data: We collect this data directly from you.
Legal basis: We process the data to fulfill the contract in accordance with Article 6 (1) (b) GDPR.
Storage period: We store this data for the term of the contract and beyond until the expiry of statutory retention periods, which may be 6 to 10 years.
Recipient category: Software providers, cloud storage providers, payment service providers, online shop operator
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC), appropriateness decision under Article 45 GDPR (Privacy Framework)
g. Use of the Flyweight Copilot browser extension
Flyweight Copilot is an optional browser extension that a merchant's support team can install in the inbox they already use (for example Gmail, Brevo, GREYHOUND or Zendesk). When a support agent opens a customer conversation, the extension reads that conversation and uses the merchant's connected store data to draft a suggested reply. The agent reviews and edits every draft before it is sent; the extension does not send messages on the agent's behalf. It is installed without access to any website and requests access to a single inbox only when the agent connects that inbox.
Processed data categories: The content of the customer support conversation currently open in the inbox (message subject and message bodies); the customer's email address, and their name where the inbox displays it; and any order references contained in the conversation. To connect a store, an access token for the merchant's Shopify store is stored locally in the browser and sent with each request.
Purpose of processing: To draft a suggested support reply for the agent, grounded in the merchant's store data (such as the referenced order and the customer's order history). For example, when the agent opens a “Where is my order?” message, the referenced order and the customer's history are looked up in the connected store so that the draft can state the current status. The draft is generated with the help of a large language model and is always reviewed by the agent before it is sent.
Source of the data: We collect this data from the inbox page the support agent has open.
Legal basis: We process the data to fulfil the contract in accordance with Article 6 (1) (b) GDPR. With regard to the customer data contained in the conversation, we act as a processor on behalf of the merchant operating the store.
Storage period: Drafts and the store connection are stored locally in the agent's browser profile and can be removed there at any time. Conversation content that we process on our servers on behalf of the merchant is deleted in accordance with our data processing agreement, within 30 days of the end of the underlying contract. Accounting and commercial records are retained until the expiry of the applicable statutory retention periods, which may be 6 to 10 years.
Recipient category: Software providers, cloud storage providers, and an AI / large language model service provider used to generate the draft.
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
h. Use of the Flyweight web app (operator accounts)
The Flyweight web app (inbox.flyweight.io) is where a merchant's support team answers customer conversations and manages the Flyweight Copilot extension. Accounts are created by invitation only: a merchant invites a team member by email, and the invited person creates their account by accepting the invitation.
Processed data categories: First and last name, email address and password (stored only as a cryptographic hash); the shops an account may act for; optional display preferences (language, region, time zone); and technical sign-in data (IP address and browser information) recorded with each session. An invitation stores the invited email address until it is accepted, declined or expired.
Purpose of processing: Providing the web app: creating and securing the account, signing the operator in, showing which shops they may answer for, and attributing actions inside the app to the person who took them.
Source of the data: We collect this data directly from you. Your email address initially comes from the shop that invited you.
Legal basis: We process the data to fulfil the contract in accordance with Article 6 (1) (b) GDPR. Technical sign-in data is processed on the basis of our legitimate interest in the security of the web app in accordance with Article 6 (1) (f) GDPR.
Storage period: We store account data for as long as the account exists, and beyond that until the expiry of statutory retention periods where these apply. Sessions expire automatically. Invitations that are not accepted expire after 7 days.
Recipient category: Software providers, cloud storage providers, and our CRM and email service provider (see the following section).
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
i. Service and product emails
We send emails that belong to operating our apps: an invitation when a shop adds you to its team, a welcome message when your account is created, password reset emails, security notices, and important information about the service and how to use it. We send comparable service information to the notification contacts a merchant names in the app.
Processed data categories: Name, email address, the shop the account or contact belongs to, and the app language.
Purpose of processing: Delivering the emails that operating the service requires, and informing you about important changes to the service and how to use it.
Source of the data: We collect this data directly from you, or from the shop that invited you or named you as a contact.
Legal basis: We process the data to fulfil the contract in accordance with Article 6 (1) (b) GDPR, and on the basis of our legitimate interest in informing users about the service they use in accordance with Article 6 (1) (f) GDPR. You can object to the informational emails at any time using the link contained in each email or by writing to data-privacy@flyweight.io. Emails beyond this, such as marketing, are sent only with your consent in accordance with Article 6 (1) (a) GDPR, which you can withdraw at any time.
Recipient category: For sending these emails and managing contacts we use Brevo, a service provided by Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France, as a processor bound by a data processing agreement.
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
j. Assertion and/or defense against legal claims
If necessary, we also process personal data to assert and/or defend against legal claims.
Processed data categories: All relevant personal data stored by us about you that is necessary for the assertion and/or defense against legal claims and may be processed for this purpose within the framework of legal requirements, i.e. is not subject to any prohibitions on processing.
Purpose of processing: Assertion and/or defense against legal claims.
Source of the data: We collect this data directly from you.
Legal basis: We process this data on the basis of the so-called legitimate interest pursuant to Article 6 para. 1 lit f. GDPR. Our legitimate interest is the assertion and/or defense against legal claims.
Storage period: We store this data for as long as it is necessary for the assertion and/or defense against legal claims. As a rule, this is the case until the end of the three-year limitation period, starting at the end of the year in which you asked us to delete your personal data.
Recipient category: Software providers, cloud storage providers, law firms, authorities, courts
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
k. Demo booking
We use Calendly, a service provided by Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA, to allow visitors to easily book demo calls for our AI chat solution directly through our website.
Processed data categories: When you book a demo call via Calendly, the following data may be processed:
- Name
- Email address
- Preferred date and time for the demo
- Any information you provide in free text fields (e.g., notes or specific requests)
- IP address and technical data (only as necessary to provide the service)
Purpose of processing: To allow visitors to easily book demo calls for our AI chat solution directly through our website.
Source of the data: We process your data to schedule and manage demo calls as requested by you.
Legal basis: We process this data on the basis of Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures), where you book a demo call, and Art. 6(1)(a) GDPR (consent), where you consent to the use of Calendly via our cookie banner, in particular regarding any associated cookies or the loading of external content.
Storage period: We store this data for the term of the contract and beyond until the expiry of statutory retention periods, which may be 6 to 10 years.
Location of recipients: EU and non-EU
Guarantees for transfers to third countries: EU Standard Contractual Clauses (SCC) and Privacy Framework
Cookies: Calendly may use cookies or load external content. These will only be activated after you have provided your consent via our cookie banner. Without your consent, Calendly will not be loaded, and no data will be transmitted to Calendly.
III. Cookies
We use so-called cookies on our website to ensure the functions of our website, to gain knowledge about the use of our website, to be able to show you personalized advertising and to enable the success of our advertising measures. Further information on the cookies used and their categorization can be found in this section under "List of cookies used". We only use cookies that are not technically necessary if you have given us your consent in accordance with Article 6(1)(a) GDPR via our cookie consent tool.
1. General information on cookies
A cookie is a small data package (text file) that your browser stores on your device at the instruction of a website you visit in order to "remember" information about you, such as your language settings or login information. These cookies are set by us and are known as first-party cookies. We also use third-party cookies, which come from a different domain to the website you are visiting. We use these cookies to support our advertising and marketing efforts.
2. Management of the cookies used
You can manage your selection of cookies and thus the consent you have given at any time via the cookie settings. You can access these settings at any time from any subpage of our website by clicking on the green cookie symbol at the bottom left of the website.
3. List of cookies used
You can find a list of the cookies we use in our cookie consent tool.
IV. Receiver
As part of the operation of the website and the services offered on the website, we use service providers who act as data processors. These service providers include software providers, cloud providers and technical support companies that are necessary for the fulfillment of our business purposes and help us to improve the quality of our services and offer innovative solutions.
When working with these service providers, we bind them to compliance with data protection by means of a data processing agreement and do not authorise them to process data for their own purposes.
In addition, personal data may be passed on to independent controllers such as tax consultants, law firms, courts or authorities, insofar as this is permitted or we are legally obliged to do so in order to meet legal requirements, ensure compliance and to assert or defend against legal claims.
V. Data security
We have implemented appropriate technical and organizational security measures to prevent your personal data from being accidentally lost, used or accessed without authorization, altered or disclosed.
In addition, we restrict access to your personal data to those employees, agents, contractors and other third parties who need it for business reasons and are legally authorized to use it.
We have put in place procedures to deal with any suspected personal data breach and will notify you and the relevant supervisory authority of a breach where we are legally required to do so.
VI. Your rights
1. Right to information
You have the right to request information at any time about how and what personal data we process about you. If you make such a request, you will also receive a copy of the personal data we have stored about you. If these copies contain confidential information or personal data of other data subjects, we will black them out accordingly or alternatively inform you which personal data are contained on these copies and for what purposes.
2. Right to rectification
If the personal data we have stored about you is incorrect or incomplete, you have the right to demand immediate correction and/or completion at any time.
3. Right to erasure or restriction of processing
You have the right to request that we delete your personal data at any time. We will comply with this request immediately, unless we are subject to legal obligations that prohibit deletion at this time. This may be the case, for example, if we are obliged to store your data for a longer period of time for tax law reasons. If this applies to you, we will inform you of this upon your request for deletion, restrict processing for purposes other than storage and delete the data immediately after expiry of the statutory retention periods, without the need for any further request from you.
In addition to the right to erasure, you also have the right to request that we restrict the processing of your personal data if:
- You dispute that the personal data we have stored about you is correct until we have had the opportunity to check the accuracy of the data;
- Our processing of your personal data is unlawful, but you oppose the erasure and alternatively request the restriction of processing;
- We no longer need your personal data, but you need it to assert, exercise or defend legal claims, or
- you object to the processing in accordance with your right under Article 21 GDPR and as long as it has not yet been determined whether our interests outweigh yours.
4. Right to object to the processing
You have the right to object under the conditions of Article 21 GDPR. You have the possibility to object to the processing based on Article 6 para. 1 lit. f. GDPR at any time for reasons arising from your particular situation. This also applies accordingly to profiling based on these provisions. The information as to whether processing is based on Article 6 para. 1 lit. f. GDPR can be found in the above descriptions of the processing operations.
5. Right to withdraw consent
If processing is based on your consent, you can withdraw this consent at any time with effect for the future. This will not affect the lawfulness of the processing for the period prior to your withdrawal. Please note that if you withdraw your consent, we will no longer be able to offer you the services that depend on it, such as emails that require your consent.
6. Right to data transfer
You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, insofar as this is technically feasible. In addition, you have the right to request that we transmit this data to another controller without hindrance from us.
7. Automated decision-making in individual cases, including profiling
According to Art. 22 GDPR, you have the right not to be subject to a decision based solely on automated processing - including profiling - which produces legal effects concerning you or similarly significantly affects you. However, we do not currently use such methods
8. Right to lodge a complaint with the supervisory authority
Independently of and in addition to the rights listed, you have the right to lodge a complaint with the supervisory authority if you believe that the processing of personal data concerning you is in breach of the GDPR.
The following supervisory authority is responsible for us:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart
Phone: 0711/61 55 41 – 0
Fax: 0711/61 55 41 – 15
E-Mail: poststelle@lfdi.bwl.de
Website: https://www.baden-wuerttemberg.datenschutz.de
However, we ask you to give us the opportunity to discuss your concerns with you before making a complaint in order to find an uncomplicated and satisfactory solution for you. You can contact our data protection team at any time by emailing data-privacy@flyweight.io or by contacting our external data protection officer using the contact details provided at the beginning of this policy.
VII. Status of and changes to this privacy policy
This privacy policy was last updated on: 26.08.2026
Due to changing business requirements, legal or regulatory requirements, as well as technical developments, it may be necessary to adapt this privacy policy. We will inform you of any significant changes to the privacy policy. You can access the latest version of the privacy policy at any time on this website.