Privacy Policy

This policy informs you about how we process personal data when you use our website and our SaaS offerings. It applies to minonexus.com and minonexus.de and their subpages.

This is a convenience translation. Only the German version at minonexus.com/datenschutz is legally binding.

1. Controller

Minonexus GmbH
Isartalstr. 32
80469 Munich
Germany

Contact: Markus Hauser [email protected]

2. Hosting & processors

Our website and SaaS services are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. These servers are located exclusively in data centres in Germany or elsewhere in the EU.

We have concluded a data processing agreement with Hetzner under Art. 28 GDPR. Hosting does not involve any transfer of personal data to third countries.

Sign-in, user accounts and the database of the protected areas are operated for us by Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513, in a data centre in the EU (Stockholm, Sweden). The data processing agreement under Art. 28 GDPR forms part of Supabase's terms of service. Access from countries outside the EU cannot be ruled out; the European Commission's Standard Contractual Clauses apply to it (Art. 46(2)(c) GDPR).

The websites minonexus.com and minonexus.de are delivered through the network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, which protects them against attacks and makes them load faster. In doing so, Cloudflare processes the technical access data described in section 3, in particular your IP address. The data processing agreement under Art. 28 GDPR forms part of Cloudflare's terms of service. For transfers to the USA, Cloudflare is certified under the EU-US Data Privacy Framework; the Standard Contractual Clauses apply in addition (Art. 45, 46(2)(c) GDPR).

3. Access data (server logs)

When you visit our pages, we process technical access data (e.g. IP address, date and time, user agent, requested URL, referrer) to ensure stability and security (e.g. to fend off attacks).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Retention: typically 14 days.

4. Cookies & consent

We use necessary cookies for technical operation. Optionally – with your consent – we use analytics cookies to improve our offerings. Your choice is stored locally and can be changed at any time.

  • Necessary: sign-in, session state, security (cannot be deselected).
  • Analytics (optional): anonymous usage statistics.

Legal bases: Art. 6(1)(c) GDPR (security obligations), Art. 6(1)(f) GDPR (technically necessary processing), Art. 6(1)(a) GDPR (consent for analytics).

4a. Web analytics with Google Analytics (GA4)

Status: active (after consent)

We use Google Analytics (GA4), an analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"), to better understand and improve the use of our website.

Consent Mode v2: The Google Analytics script is technically loaded when a page is opened, but with consent denied by default (Google Consent Mode v2). In this state no personal data is collected and no cookies are set. Only after your explicit consent (Art. 6(1)(a) GDPR) is the consent status updated to "granted" and data collection activated.

Cookies: Once you have given consent, Google Analytics sets the following cookies:

  • _ga – distinguishing unique users (lifetime: 2 years)
  • _ga_<ID> – storing the session state (lifetime: 2 years)

Data categories (when active): page views, interactions, pseudonymous IDs, approximate location (country/region), device/browser, referrer, session duration and custom events (e.g. registration, use of our products MinoSketch/MinoCheck/MinoDrain, contact form submission, appointment booking). GA4 does not store IP addresses; IP addresses are used solely for geolocation (country/region) and then discarded.

Recipient: Google as processor. We have concluded the data processing terms for Google Analytics with Google under Art. 28 GDPR. Transfers to third countries (in particular the USA) may occur; Google uses Standard Contractual Clauses (SCC) for this.

Withdrawing consent: You can withdraw your consent at any time via the cookie settings (see section 4). After withdrawal, data collection stops immediately, the consent status is reset to "denied" and the analytics cookies (_ga, _ga_<ID>) are deleted automatically.

Retention (when active): 14 months.

5. Contacting us

When you contact us by e-mail, we process your details (e.g. name, e-mail address, content of the message) to handle your request.

Messages sent through our contact form are delivered via the e-mail service Brevo (Sendinblue SAS, 9–17 rue Salneuve, 75017 Paris, France). The data processing agreement under Art. 28 GDPR forms part of Brevo's terms of service. Processing takes place in the EU.

Legal bases: Art. 6(1)(b) GDPR (pre-contractual/contractual enquiries), Art. 6(1)(f) GDPR (general enquiries). Retention: 6 months after your request has been closed (section 8).

6. User account & SaaS use

In the protected area (after sign-in) we process, to perform the contract, among other things: identification data (e.g. name, e-mail address), access data (password hash), logs/metadata (e.g. sign-in/sign-out, change histories), usage data (e.g. design processes carried out).

We use your e-mail address and phone number to contact you about your account, booked appointments and your projects. We do not send advertising.

Legal basis: Art. 6(1)(b) GDPR (contract/provision of services) and Art. 6(1)(f) GDPR (prevention of misuse and fraud, IT security).

Quality assurance and further development. We evaluate the designs created in the protected area internally in order to review and further develop the quality of our design methods. This uses the design data itself — room programme, plot layout, geometry and the key figures of the result. Your name and contact details are not part of this evaluation. The technical review is carried out exclusively by persons bound to confidentiality; individual designs are neither published nor passed on to third parties. If you delete designs or projects, fully computed designs are detached from your account and continue to be used for this purpose without any link to you — unless you have objected; in that case we delete them completely.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in quality assurance and further development of our services). You can object to this processing at any time — in your account under “Meine Daten” (My data) or informally at [email protected] (section 9). An objection has no effect on your use of our services.

6a. Use through AI assistants (connector)

Through our connector – a server based on the open Model Context Protocol (MCP) at mcp.minonexus.com – you can connect an AI assistant from another provider to your Minonexus account. The assistant then calls our tools on your behalf. We provide instructions for the following assistants:

Other assistants that support MCP can connect in the same way; this section applies to them accordingly.

Connection and sign-in

You grant the connection by signing in with your Minonexus account and allowing access on our consent page (OAuth). In doing so, we store with our sign-in service (Supabase, section 2) the details with which the assistant registers (the name and redirect address it provides itself), your consent and the access keys issued. You can disconnect at any time in the assistant; if you also want to revoke the connection with us, a message to [email protected] is sufficient.

What we process

  • Tool inputs that the assistant passes on from the conversation – such as addresses, coordinates, land parcels, building plots or room wishes – and the results we compute from them.
  • Account data as in the portal: product access, usage credit and bookings, as well as projects and designs you create through the assistant. Section 6 applies to them.
  • Files such as IFC exports are provided via a download link that is valid for no more than 30 minutes.
  • Technical logs per call: time, name of the tool, identifier of your account and of the assistant, duration and result. We do not log inputs, results or access keys. Retention as for the server logs (section 3).

Some tools provide a view (e.g. the 3D terrain) that the assistant displays in its interface. It loads data from our servers and a graphics library from cdn.jsdelivr.net; the respective server receives your IP address in the process.

The assistant as a separate controller

What you write in the conversation and what our tools return to the assistant is processed by its provider under its own responsibility and in accordance with its privacy policy – including outside the EU, where the provider does so. We transmit results only to the assistant you have connected, and only when it calls our tools. We have no influence on the processing by the provider.

Legal basis: Art. 6(1)(b) GDPR (execution of the calls you initiate); for the logs, Art. 6(1)(f) GDPR (secure operation, prevention of misuse).

6b. Consultation appointments with a Minonexus architect

In the portal and through the connector (section 6a) you can request a free 30-minute consultation with an architect from Minonexus. The consultants are part of Minonexus GmbH. We do not pass on your data for this purpose to other architecture firms or any other third parties.

What we process

  • your first and last name, your e-mail address and, if stored in your account, your phone number,
  • the chosen appointment and, if you provide one, your note on the topic of the conversation,
  • the link to the design you want to discuss, if you request the appointment from a design,
  • your two consents, together with the time at which you gave them.

Who receives the data

Your request, with these details, is received by the architect who holds the chosen appointment, by e-mail and in our system. We send the e-mails via Brevo (section 5). The conversation takes place by phone or video conference; we agree on the channel with you. If we use a video service for this, we name the provider in the invitation.

Should we work with external architecture firms in the future, we will name them before you make a request and ask for your consent to this separately.

Your consents

A request is only possible if you yourself give two consents: that the architect may contact you about this appointment, and that your contact details may be passed on to them for this purpose. If you use an AI assistant, you give both in the appointment view that the assistant displays; the assistant cannot give them on your behalf. You can withdraw your consents at any time with effect for the future by cancelling the appointment under “Meine Termine” (My appointments) or informally at [email protected].

Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (holding the consultation you requested). Retention: section 8.

7. Embedded content & third parties

We currently do not embed any external content that transmits data to third parties without consent. Should we embed, for example, YouTube videos, maps or external widgets in the future, this will only happen after your consent and with separate information.

8. Retention

We store personal data only for as long as is necessary for the respective purpose:

DataRetention
Server and connector logs14 days (sections 3 and 6a)
Download links for files, e.g. IFC exportsno more than 30 minutes; the file is deleted after the first complete download
Connection of an AI assistant (your consent, the assistant's registration, access keys) until you revoke the connection or close your account
Account, projects and designs for the term of the user agreement; after your account is closed, we delete them within 30 days. Excepted are designs that continue to be used under section 6 without any link to you, unless you have objected
Appointment requests and the related consentsuntil your account is closed, then as account data
Contact requests6 months after your request has been closed
Analytics (only with consent)14 months (section 4a)

Statutory retention obligations remain unaffected.

9. Your rights

  • Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21) to processing based on Art. 6(1)(e) or (f)
  • Withdrawal of consent given (Art. 7(3)) with effect for the future
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise your rights, please contact [email protected].

10. Data security

We take appropriate technical and organisational measures (e.g. TLS encryption, access controls, backups) to protect personal data against loss, misuse and unauthorised access.

11. Changes to this policy

We update this privacy policy when the legal situation, our services or the processing of data change. The current version is always available on this page.