Privacy Policy
Last updated July 31, 2026
This privacy notice explains how Index Commerce GmbH, doing business as superglue ("Superglue," "we," "us," or "our"), processes personal data. It applies when you:
- visit superglue.ai, trust.superglue.ai, or another website that links to this notice;
- use the hosted Superglue platform at app.superglue.cloud;
- create an account or use our products and services; or
- contact us for sales, support, events, or other business matters.
This notice describes our current managed-cloud setup and business operations. A customer may provide a separate privacy notice for personal data that it controls and processes through Superglue.
Contents
- Who Is Responsible for Your Data?
- When Are We a Controller or Processor?
- What Personal Data Do We Process?
- Where Does the Data Come From?
- Why Do We Process Data?
- How Do Our AI Features Process Data?
- Who Receives Personal Data?
- Do We Transfer Data Outside the EEA?
- How Do We Use Cookies and Analytics?
- How Long Do We Keep Data?
- How Do We Protect Data?
- What Are Your Rights?
- Do We Make Automated Decisions?
- Do We Process Children's Data?
- Do You Have to Provide Data?
- How Do We Update This Notice?
- How Can You Contact Us?
1. Who Is Responsible for Your Data?
For processing where we determine the purposes and means, the controller is:
Index Commerce GmbH
Leopoldstraße 2-8
32051 Herford
Germany
Email: security@superglue.ai
2. When Are We a Controller or Processor?
We act as a controller for our websites, accounts, billing, support, security, product analytics, marketing, and business communications.
We act as a processor when a customer uses Superglue to process personal data in customer systems, workflows, files, or execution results ("Customer Content"). The customer determines why that data is processed. Our Data Processing Addendum applies to that processing.
If you have a question about Customer Content, contact the customer that provided or controls it. We assist customers with valid data subject requests as required by our Data Processing Addendum.
3. What Personal Data Do We Process?
Account and identity data
- name, work email address, username, organization, and role;
- login provider identifiers and account profile information; and
- authentication and session data, including password hashes and tokens.
Billing and transaction data
- billing contact details and billing address;
- subscription, invoice, payment status, and transaction records; and
- Stripe customer and subscription identifiers.
Stripe receives and stores payment card details. Superglue does not store full payment card numbers or card security codes.
Service and Customer Content
- system and workflow configurations;
- workflow execution inputs, outputs, results, and history;
- files that users upload;
- integration metadata; and
- encrypted API credentials and OAuth tokens.
We process Customer Content only under the customer's instructions, our agreement, and applicable law.
Technical, usage, and security data
- IP address, browser type, device type, operating system, and language;
- referring URL, pages viewed, features used, and timestamps;
- application, access, audit, diagnostic, and error logs; and
- security events and fraud-prevention signals.
Communications and business data
- support requests and messages;
- sales and event communications;
- contact preferences; and
- contracts, order details, and related business records.
Special-category data
We do not intentionally collect special-category personal data for our own controller purposes. Customer Content may contain such data when a customer directs us to process it. In that case, the customer is responsible for establishing a valid legal basis and giving us appropriate instructions.
4. Where Does the Data Come From?
We receive personal data:
- directly from you when you register, use the service, pay, or contact us;
- from your organization or an organization administrator;
- from Google or GitHub when you choose provider-based sign-in;
- from Stripe about subscriptions, invoices, and payment status;
- automatically from your device and use of our websites or service; and
- from systems connected by a customer, under that customer's instructions.
5. Why Do We Process Data?
The table maps each purpose to its GDPR legal basis. Where a contract is with your organization rather than with you personally, we generally rely on our legitimate interests in providing that service to the organization.
| Purpose | Data | Legal basis |
|---|---|---|
| Create accounts, authenticate users, provide the platform, and execute requested workflows | Account data, service data, Customer Content, technical data | Contract or pre-contract steps, Article 6(1)(b); legitimate interests, Article 6(1)(f) |
| Manage subscriptions, billing, invoices, and payments | Account, billing, and transaction data | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c) |
| Provide support and send service or administrative messages | Account, service, and communications data | Contract, Article 6(1)(b); legitimate interests in supporting users, Article 6(1)(f) |
| Protect the service, prevent fraud, enforce access controls, and investigate incidents | Account, technical, security, and service data | Legitimate interests in securing our service, Article 6(1)(f); legal obligation, Article 6(1)(c) |
| Measure usage, diagnose problems, and improve our websites and products | Technical, usage, analytics, and communications data | Legitimate interests in improving our service, Article 6(1)(f); consent where required, Article 6(1)(a) |
| Send marketing communications and measure campaign performance | Contact, preference, and engagement data | Consent, Article 6(1)(a); legitimate interests where permitted, Article 6(1)(f) |
| Meet legal, tax, accounting, and regulatory duties or establish legal claims | Account, billing, transaction, communications, and security data | Legal obligation, Article 6(1)(c); legitimate interests in legal claims, Article 6(1)(f) |
You may object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds or need the data for legal claims.
6. How Do Our AI Features Process Data?
Superglue accesses AI models through AWS Bedrock. AWS is our AI service provider. We do not send Customer Content directly to model developers as separate Superglue subprocessors.
We use AI features to interpret instructions, build tools, generate code, and support workflow execution. Depending on the feature, inputs and outputs may contain Customer Content. We limit personal data sent to AI services, mask credentials, and keep credentials outside AI prompts.
We do not use Customer Content to train AI models. Our AWS agreement provides that data submitted through AWS Bedrock is used for inference and is not used to train the underlying models.
We use Langfuse for AI observability, tracing, evaluation, and troubleshooting. Relevant prompts, responses, metadata, and performance data may appear in traces.
7. Who Receives Personal Data?
We use the following vendors from our current Trust Center. A vendor receives personal data only when required for its function.
| Vendor | Purpose |
|---|---|
| AWS | Cloud hosting, databases, storage, security services, authentication infrastructure, and AI model access through AWS Bedrock |
| GitHub | Source control, software development, and deployment workflows |
| Stripe | Subscriptions, invoices, payments, and fraud prevention |
| Google Workspace | Business email, documents, calendars, customer communications, and collaboration |
| Slack | Internal communications, collaboration, support coordination, and operational alerts |
| Langfuse | AI observability, tracing, evaluation, and performance monitoring |
| PostHog | Website and product analytics, usage measurement, and feature management |
We require vendors that process personal data for us to use appropriate safeguards and process data under written terms. We may also disclose data when required by law, to protect legal rights, or as part of a merger, financing, acquisition, or sale of assets.
8. Do We Transfer Data Outside the EEA?
Some service providers may process personal data in countries outside the European Economic Area ("EEA"). When personal data is transferred outside the EEA, we use a legally recognized transfer mechanism and appropriate safeguards.
Depending on the recipient and destination, these safeguards may include an applicable European Commission adequacy decision, the EU-US Data Privacy Framework for certified recipients, or the European Commission's Standard Contractual Clauses. We may also use supplementary technical and organizational measures.
You may request information about the safeguards used for a transfer, or a copy where available, by emailing security@superglue.ai. We may redact information that is confidential or protected by law.
9. How Do We Use Cookies and Analytics?
We use cookies and similar technologies for authentication, security, preferences, and analytics. Strictly necessary technologies support login, sessions, security, and requested features.
We use PostHog to understand website and product usage. PostHog may process online identifiers, device and browser information, page views, feature usage, and interaction events.
You can block or delete cookies through your browser settings. Blocking necessary cookies can prevent account login or other features.
10. How Long Do We Keep Data?
We retain personal data only for the relevant business purpose, contract, legal requirement, or legal claim. Our current retention schedule is:
| Data | Retention |
|---|---|
| Active account and customer data | For the service term; deletion from live systems within 30 days after a valid account deletion request or termination |
| Workflow configurations and integration credentials | For the service term; until account termination or integration removal |
| Workflow execution history and results | 90 days |
| File uploads | 90 days after last use |
| Application, security, access, database, and audit logs | For the duration of the business relationship |
| Performance metrics | 90 days |
| Production database backups | 30 days; deleted data can remain in encrypted backups until the backup expires |
| Invoices, billing, and financial records | 10 years, where required by German tax and commercial law |
| Contracts and agreements | Up to 10 years after termination, where required |
| Marketing contacts | Until consent is withdrawn, you object, or the data is no longer needed |
We may keep data longer during a legal hold, dispute, investigation, or when law requires it. We delete or anonymize data when the retention period ends. If we restore a backup, we reapply documented deletion requests.
11. How Do We Protect Data?
We use technical and organizational measures designed to protect personal data. These include:
- AES-256 encryption for AWS storage and databases;
- TLS 1.2 or later for data in transit;
- application-level encryption for integration credentials and OAuth tokens;
- role-based access, least-privilege permissions, and multi-factor authentication;
- tenant isolation, audit logging, security monitoring, and incident response procedures; and
- vendor review and written data protection terms.
No method of transmission or storage is completely secure. If a personal data breach creates a legal notification duty, we will notify the competent authority and affected people as required by law.
12. What Are Your Rights?
Subject to the conditions in applicable law, you may have the right to:
- access your personal data and receive a copy;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- receive portable data in a machine-readable format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time; and
- lodge a complaint with a data protection authority.
To exercise a right, email security@superglue.ai. We may request information needed to verify your identity. We respond without undue delay and generally within one month. Complex requests may take up to two additional months, and we will explain the extension.
Withdrawing consent does not affect processing that was lawful before the withdrawal. You can unsubscribe from marketing emails through the link in each message.
You may complain to the supervisory authority where you live or work, or where an alleged infringement occurred. Our lead authority is the Bavarian State Office for Data Protection Supervision (BayLDA).
13. Do We Make Automated Decisions?
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects. Superglue includes AI-assisted features, but sensitive tool executions and security-related decisions require human oversight under our current procedures.
14. Do We Process Children's Data?
Our services are for businesses and are not directed to children under 18. We do not knowingly collect personal data from children for our own purposes. Contact security@superglue.ai if you believe a child provided personal data to us.
15. Do You Have to Provide Data?
Account, authentication, billing, and service data marked as required is necessary to create an account, enter into a contract, or provide the service. Without it, we may be unable to provide the requested account or service. Marketing information and optional profile fields are voluntary.
16. How Do We Update This Notice?
We update this notice when our processing, vendors, products, or legal obligations change. The date at the top shows the latest revision. For material changes, we may also provide a notice on our website, in the service, or by email.
17. How Can You Contact Us?
For privacy questions or data subject requests:
Index Commerce GmbH
Leopoldstraße 2-8
32051 Herford
Germany
Email: security@superglue.ai