1 · Controller
The controller under the General Data Protection Regulation (GDPR) is:
Mark Toni MilosavljevicSole proprietor
Goethestraße 23 · 71364 Winnenden · Germany
Phone: +49 152 3375 8925
Email: hello@peaksly.ai
You may send data protection requests to the email address above.
3 · Website access and hosting
When you access this website, your browser sends technically necessary information which the server records in a log file:
- IP address of the requesting device
- date and time of access
- name and size of the requested file
- status of the request
- browser type and operating system
- previously visited page, if supplied by your browser
The data is required to operate and secure the server and is not combined with other data. Legal basis: Article 6(1)(f) GDPR — the legitimate interest in stable and secure operation. Retention: according to the hosting provider's privacy information, logs are deleted within seven days. They may be retained longer in a specific security incident where necessary.
Hosting processor
ALL-INKL.COM – Neue Medien MünnichProprietor: René Münnich
Hauptstraße 68 · 02742 Friedersdorf · Germany
The provider processes this data on instructions under a data processing agreement pursuant to Article 28 GDPR. The server is located in Germany and this hosting does not involve a third-country transfer.
4 · Encryption and form security
This website and its forms use an encrypted TLS connection. Contact and order details are therefore protected in transit. To prevent automated or repeated submissions, the server creates a short-lived, single-use form token and temporarily processes the IP address in pseudonymised form. This uses no cookies or browser storage. The legal basis is Article 6(1)(f) GDPR — the legitimate interest in protecting the forms and server against misuse.
5 · Contact form, email and phone
Depending on your selection, the contact form transmits topic, name or role, email address, message and, for a call request, country, time zone, preferred date and availability window. A call is only booked after separate confirmation.
The enquiry is stored outside the publicly accessible web area at ALL-INKL.COM and is also sent through the business email service at Hostinger to peaksly and as an acknowledgement to the email address supplied. Hostinger processes message content and metadata as processor and uses subprocessors. Where data is processed outside the EEA, the agreement provides in particular for the EU Standard Contractual Clauses. Details are available in the Hostinger Data Processing Agreement.
- Purpose: handling and answering your enquiry and, where relevant, preparing or performing a contract.
- Legal basis: Article 6(1)(b) GDPR for pre-contractual steps at your request; otherwise Article 6(1)(f) GDPR — the legitimate interest in properly handling business enquiries.
- Provision: contacting peaksly is voluntary. Fields marked as required are necessary to assign and answer the enquiry.
- Retention: non-contractual enquiries are generally deleted within twelve months after completion unless a statutory or evidentiary reason requires longer retention. Contract and business records are subject to Section 6.
If you contact peaksly by email or phone instead, the information you provide is processed for the same purposes and legal bases.
A customer portal with login is not currently approved for production customer use and will receive separate privacy information before activation.
6 · Online order, contract and invoicing
The order page transmits business, billing address, country, business proof, contact person, email address, market and language, preferred start, selected plan and add-ons, and the required acknowledgements. Data is stored outside the publicly accessible web area at ALL-INKL.COM and sent through Hostinger to peaksly and as an acknowledgement to the email supplied. The automatic acknowledgement is not acceptance; a contract only comes into existence upon written acceptance by peaksly.
Automatic EU VAT ID pre-check: if you use an EU VAT ID as business proof, the form server sends only the country code and VAT ID to the European Commission's VAT Information Exchange System (VIES). Business name, address and other order details are not sent to VIES. The purpose is to pre-check the supplied number for contract preparation and tax classification; the legal bases are Articles 6(1)(b) and (c) GDPR. The result, check time and any request identifier returned by VIES are stored with the order. A negative result or an unavailable interface does not cause an automated rejection but triggers manual review. VIES replaces neither the business-status review nor the final tax assessment.
- Purpose: business-status review, processing the binding customer offer, contract formation and performance, communication, invoicing and compliance with legal duties.
- Legal basis: Article 6(1)(b) GDPR where the data subject is the contracting party; Article 6(1)(f) GDPR for business contacts and preserving evidence; Article 6(1)(c) GDPR for tax and commercial duties.
- Recipients: hosting and email providers; for the EU VAT ID pre-check, the European Commission and the responsible national tax administration; account-holding banks, tax advisers and tax authorities; and bodies legally entitled to receive the data.
- Provision: required information is necessary for business-status review, processing the offer and a possible contract. The order cannot be accepted without it.
- Retention: declined orders are deleted after required evidentiary and limitation periods. Contract, business and invoice records are generally retained for six, eight or ten years depending on their statutory classification. The period normally starts at the end of the year in which the record was created.
7 · Service delivery
To analyse visibility in AI search engines, generally worded prompts are sent to the AI services identified in the accepted proposal and their answers are evaluated. Personal customer, employee or applicant data, credentials and confidential content must not be supplied for this purpose and are not part of the prompts. If such data is nevertheless submitted, I remove it as soon as I become aware of it. Results are supplied only to the customer and agreed recipients; they are not published or used as a reference without separate permission.
Purpose and legal basis: data is processed to perform the agreed measurement plan, review results and provide reports. The basis is Article 6(1)(b) GDPR where the data subject is the contracting party; for a business customer's contacts it is Article 6(1)(f) GDPR — the legitimate interest in performing the business relationship as agreed.
Recipients and international transfers: the AI and infrastructure providers identified in the accepted proposal receive the prompts and technical metadata needed for the agreed measurement path. Provider, measurement route and any international transfer are identified before service starts in the proposal or accompanying privacy information. Where required, appropriate safeguards under Chapter V GDPR are put in place. A copy of the safeguards agreed in each case is available on request at hello@peaksly.ai. No measurement starts without an approved and documented data path.
Provision: project, brand, domain, market and configuration details are required to the extent necessary for the agreed service. Without them, the relevant service cannot be supplied or can be supplied only in a limited form.
- Raw provider answers: deletion 30 days after measurement; not displayed in the customer portal and only redacted excerpts in reports.
- Normalised measurements and derived metrics: deletion or irreversible anonymisation 13 months after measurement.
- Project, configuration and portal data: deletion or irreversible anonymisation no later than 90 days after the contract ends.
- Invoices and accounting records: separate statutory retention, currently generally eight years from the end of the year in which they were created.
8 · Fonts, language and presentation
The “Outfit” and “Geist” fonts are served locally. No connection is made to Google Fonts or another external font provider. German and English use separate URLs; the language switch is a normal link and is not saved in the browser.
9 · No automated decision-making
No automated decision-making or profiling within Article 22 GDPR takes place.
10 · Your rights
Depending on the statutory conditions, you have rights to access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection to processing based on legitimate interests (Article 21). You may withdraw consent with future effect where processing is based on consent (Article 7(3)). Email hello@peaksly.ai to exercise a right.
Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority under Article 77 GDPR. The authority responsible for the controller is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, baden-wuerttemberg.datenschutz.de. You may also contact the authority for your habitual residence, workplace or the place of an alleged infringement.
11 · Changes
This policy will be updated if the processing changes, for example because of a new function or a change in law. The version published here at the time of your visit applies.
Effective: 21 August 2026 · A German version of this Privacy Policy is available at peaksly.ai/datenschutz.html. Provider details are available in the Imprint.