Privacy Notice

Privacy Notice — Lebi AI GmbH | Version 3.0 | Status Active | Locale EN | Framework GDPR | Owner Lebi AI GmbH | Classification Public

1. Scope of this Notice

This Privacy Notice explains how Lebi AI GmbH (hereafter “the Company”, “we” or “us”) processes personal data where we act as the controller: when you visit our website, book or attend a product demonstration, enter into or maintain a business relationship with us, or apply for a position with us.

This Notice does not cover the processing of patient data through our platform. When a healthcare practice deploys our platform, the practice is the controller for that processing and the Company acts solely as a processor on the practice’s documented instructions pursuant to Art. 28 GDPR. Information for patients is provided by the practice concerned, on the basis of a separate information document which we make available to our practice clients for that purpose.

For clarity: none of the tools described in this Notice has access to patient data.

2. Data Controller (Art. 13(1)(a) GDPR)

The controller responsible for the processing described in this Notice is:

Lebi AI GmbH Sophienstr. 9 10178 Berlin, Germany Registered with the commercial register of the Amtsgericht Charlottenburg under HRB 290354 B Managing Directors: Dr. Christian Limberg, Ragnar Jongen Email: privacy@lebi.ai Telephone: +49 30 82681888

3. Data Protection Officer (Art. 37 GDPR)

We have appointed an external Data Protection Officer to ensure independent oversight:

Zhihu Chen Marsstein GmbH Bücklestraße 3 78467 Konstanz, Germany Registered with the commercial register of the Amtsgericht Freiburg im Breisgau under HRB 734736 Email: dpo@marsstein.ai

You may contact either our Data Protection Officer or our internal privacy team at privacy@lebi.ai in relation to any matter covered by this Notice, including the exercise of your rights.

Part 1 — Website

4. Website Operation and Hosting

When you access our websites (such as https://www.lebi.care/ or https://www.lebi.ai/), your browser transmits technical data to our web server, including your IP address, the date and time of the request, the page requested, the referring page, and information about your browser and operating system. This data is required to deliver the website to you and to maintain its stability and security. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and reliable provision of our website.

Our website is hosted by Leaseweb Deutschland GmbH, Hanauer Landstraße 121, 60314 Frankfurt am Main, Germany, which hosts our website on servers located in Germany and which acts as our processor under a data processing agreement pursuant to Art. 28 GDPR. Server log data is retained for up to six months and then deleted.

We use one strictly necessary session cookie, lebi_session, which is required for the website to function. This cookie does not require your consent under § 25(2) TDDDG.

5. Bot Protection

We use Cloudflare Turnstile, a service of Cloudflare, Inc., to protect our forms against automated abuse. Turnstile evaluates technical characteristics of your browser and your IP address in order to distinguish human visitors from automated traffic. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protecting our systems and forms against misuse. As this is a strictly necessary security measure, no consent is required under § 25(2) TDDDG. Processing may involve a transfer to the United States; see Section 23.

6. Consent Management

Before any non-essential cookie or tracking technology is loaded, we ask for your consent through a consent banner which we operate ourselves. The banner is based on the open-source software react-cookie-manager and runs entirely on our own infrastructure; no third-party provider is involved and no data is transmitted to any consent management service. Your consent decision is stored in a cookie in your browser and, together with a timestamp and the version of the cookie declaration in force, in a record held on our servers in Germany so that we can demonstrate compliance and so that you are not asked again on every visit. The legal basis for storing the consent record is Art. 6(1)(c) in conjunction with Art. 7(1) GDPR.

Details of every cookie and tracking technology used on our website — including provider, purpose, storage duration and the category to which it belongs — are set out in the cookie declaration accessible at any time through the consent banner. You can withdraw or change your consent there at any time with effect for the future.

No analytics or advertising technology described in Sections 7 and 8 is loaded before you have given your consent.

7. Web Analytics

Subject to your consent, we use the following analytics services to understand how our website is used and to improve it:

Google Analytics 4 and Google Tag Manager, services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager itself does not collect personal data; it manages the loading of other tags in accordance with your consent decision. Google Analytics collects usage data, including pages viewed, session duration, approximate location derived from a shortened IP address, and device and browser information.

PostHog, provided by PostHog, Inc., used to analyse how visitors interact with our website and product pages. Our account is provisioned in PostHog’s European cloud region, meaning that data is stored on infrastructure within the European Union. Access from the United States by PostHog, Inc. is not excluded; that transfer is safeguarded as described in Section 23.

The legal basis for both is your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may withdraw your consent at any time with effect for the future through the consent banner.

8. Advertising

Subject to your consent, we use the following services to advertise our product to healthcare practices and to measure the effectiveness of that advertising:

Google Ads, a service of Google Ireland Limited, used to display advertisements and to measure conversions arising from them.

Meta Pixel, a service of Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, used to measure the effectiveness of advertising delivered on Facebook and Instagram and to build advertising audiences.

LinkedIn Insight Tag, a service of LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland, used to measure the effectiveness of advertising delivered on LinkedIn and to address our advertising to relevant professional audiences.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and § 25(1) TDDDG. These services involve the processing of personal data by the respective providers in a manner for which we and the provider are jointly responsible; see Section 21. They may also involve transfers to the United States; see Section 23.

9. Our Social Media Profiles

We maintain company profiles on LinkedIn, Facebook and Instagram. When you visit or interact with these profiles, the platform operator processes your personal data on its own infrastructure and under its own terms, and provides us with aggregated statistics about the use of our profile. For the processing of that statistical data we are jointly responsible with the platform operator; see Section 21. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is presenting our company and communicating with interested professionals.

We have no influence over, and no access to, the data that the platform operators process for their own purposes. For information about that processing, please consult the privacy policy of the platform concerned.

10. Contact Forms and Email

If you contact us through a form on our website or by email, we process the data you provide — typically your name, email address, telephone number, organisation and the content of your message — in order to respond. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to the conclusion of a contract, and otherwise Art. 6(1)(f) GDPR, our legitimate interest being to respond to enquiries addressed to us.

Enquiries submitted through our website are received in our customer relationship management system; see Section 15.

Part 2 — Demonstrations, Sales and Business Relationship

11. Voice Demonstration on our Website

Our website, together with the associated demonstration telephone numbers, offers a voice demonstration through which you can experience our assistant for yourself. When you use this function, the content of the conversation is processed in order to generate the assistant’s spoken response, and we process metadata relating to the call, in particular the time and duration. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is enabling interested parties to evaluate our service and operating the demonstration securely.

The demonstration operates against a test environment. It is not connected to any practice management system and contains no real patient data. No audio recording of the call is made or stored at any time. A written transcript of the conversation is made and retained, so that we can record the contact details you give us, follow up on your enquiry, and check that the demonstration functioned correctly. Transcription is an inherent part of this demonstration and cannot be switched off; if you would prefer no transcript to be made, please use our contact form or our demonstration booking page instead. The transcript is deleted after twelve months. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest being to record the details of an enquiry made to us and to verify the correct operation of the demonstration, and additionally Art. 6(1)(b) GDPR where the call takes place at your request in advance of a possible contract. You may object at any time in accordance with Art. 21 GDPR. Please do not disclose health data or other personal data relating to third parties during the demonstration; a corresponding notice is given at the start of the call, and where such data is nevertheless disclosed we delete it from the transcript as soon as we become aware of it.

At the beginning of the call, before any other content is spoken, you are informed that you are interacting with an artificial intelligence system and that the conversation is transcribed so that we can record your contact details and follow up on your enquiry. The first of these statements is made in accordance with Art. 50 of Regulation (EU) 2024/1689.The call is processed by sub-processors providing telephony, speech recognition and language model services as cloud services, each bound by a data processing agreement pursuant to Art. 28 GDPR. These services process the data within the European Economic Area; where a provider belongs to a group of companies headquartered outside the European Economic Area, any resulting access is safeguarded as described in Section 23. Neither we nor these providers use the content of demonstration calls, or the transcripts of them, to train, build or improve AI models.

Where you provide your contact details in connection with the demonstration, those details are recorded in our customer relationship management system; see Section 15.

12. Booking a Demonstration

We use HubSpot Meetings, provided by HubSpot Ireland Limited, to allow you to book a product demonstration. When you book, we process your name, email address, organisation, the appointment time you select, and any information you add to the booking form. The data is used to schedule and prepare the demonstration.

The legal basis is Art. 6(1)(b) GDPR where you are yourself the prospective contracting party, and otherwise Art. 6(1)(f) GDPR, our legitimate interest being to respond to a demonstration request made on behalf of your organisation.

Our HubSpot account is provisioned in HubSpot’s European data region, meaning that customer data is stored on infrastructure located in Germany. HubSpot’s own data processing agreement nevertheless provides that personal data may be accessed and processed on a global basis and in particular by HubSpot, Inc. in the United States. Such access is therefore not excluded, and the resulting transfer is safeguarded by the EU–US Data Privacy Framework, under which HubSpot is certified, with Standard Contractual Clauses applying as a fallback. See Section 23.

13. Video Conferencing

Product demonstrations are conducted using Zoom (Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San José, CA 95113, USA), Google Meet (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) or Microsoft Teams (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland), depending on which service you prefer. When you join a meeting, the provider processes your name, your email address, connection data and, where you enable them, your audio and video. The legal basis is Art. 6(1)(b) GDPR. Where a provider is established in the United States or belongs to a group of companies headquartered there, the resulting transfer is safeguarded as described in Section 23.

14. Recording and Transcription of Demonstration Calls

Where we record or transcribe a demonstration call, we do so only with the express consent of every participant, obtained at the beginning of the call and before recording starts. You are free to refuse; the demonstration will proceed without a recording. The legal basis is Art. 6(1)(a) GDPR, and consent may be withdrawn at any time with effect for the future.

Recordings and transcripts are used solely to produce an internal summary of the discussion so that we can follow up accurately. Transcription is carried out either by the transcription function of the video conferencing service used for the call - as described in Section 13 - or by a transcription service which we operate ourselves on our own infrastructure in Germany. Where a video conferencing provider performs the transcription, it acts as our processor under a data processing agreement pursuant to Art. 28 GDPR. Neither we nor these providers use the content of these calls to train, build or improve AI models. Transcripts are deleted after twelve months.

15. Customer Relationship Management

We use HubSpot as our customer relationship management system to record and manage our contacts with prospective and existing clients. We process contact and organisation details, our correspondence with you, notes of meetings and calls, and the status of the business relationship.

The account is provisioned in HubSpot’s European data region, with data stored in Germany. As set out in Section 12, access by HubSpot, Inc. in the United States is not excluded under HubSpot’s data processing agreement; that transfer is safeguarded as described in Section 23.

The legal basis is Art. 6(1)(b) GDPR where the processing relates to an existing or prospective contract, and otherwise Art. 6(1)(f) GDPR, our legitimate interest being the management and development of our business relationships. You may object to processing based on Art. 6(1)(f) GDPR at any time in accordance with Art. 21 GDPR.

Please note that the storage of tracking cookies set by HubSpot on our website requires your consent and is addressed in Section 6; the legal bases set out in this Section concern the customer relationship management database itself.

16. Contract Management, Accounting and Payment

To perform our contracts and meet our commercial and tax obligations we process contract data, invoicing data and payment data. The legal basis is Art. 6(1)(b) GDPR for the performance of the contract and Art. 6(1)(c) GDPR for compliance with our retention and bookkeeping obligations under the German Commercial Code (HGB) and the Fiscal Code (AO). Where our contractual relationship concerns a client established in the Netherlands, the corresponding Dutch retention obligations also apply, in particular the seven-year retention period under Article 52 of the Algemene wet inzake rijksbelastingen (AWR) and the administration obligations under Articles 2:10 and 3:15i of the Burgerlijk Wetboek.

In this context personal data is disclosed to our tax adviser, to our bank, and to our accounting software provider, each of which is bound by professional secrecy, statutory duties of confidentiality, or a data processing agreement pursuant to Art. 28 GDPR as applicable.

17. Internal Collaboration and Business Tools

For internal communication, document management, and the automation of routine business processes we use standard business software. The providers concerned act as our processors under data processing agreements pursuant to Art. 28 GDPR, and process business contact data only. Where a provider belongs to a group of companies headquartered in the United States, the transfer is safeguarded as described in Section 23.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the efficient and secure operation of our business.

18. Internal Use of AI Assistance Tools

We use general-purpose AI assistance tools to support internal work such as drafting, research and summarisation. These tools process business data only. Patient data processed through our platform is never made available to them, and the providers of these tools are not sub-processors of our platform.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the efficient operation of our business. We have contractually excluded the use of our data for the training or improvement of the providers’ models.

19. Secure Disposal of Records

Where physical records containing personal data are disposed of, we use a certified document destruction service, which acts as our processor pursuant to Art. 28 GDPR.

20. Job Applications

If you apply for a position with us, we process the data contained in your application — your contact details, curriculum vitae, references and any further information you provide — for the purpose of assessing your application. The legal basis is Art. 88 GDPR in conjunction with § 26(1) BDSG and Art. 6(1)(b) GDPR.

If your application is unsuccessful, your data is deleted six months after the conclusion of the procedure, unless you have consented to us retaining it for consideration in future procedures. The six-month period reflects the limitation period under § 15(4) of the General Equal Treatment Act (AGG).

Common Provisions

21. Joint Controllership (Art. 26 GDPR)

For certain processing operations connected with advertising and with our social media profiles, we and the provider concerned jointly determine the purposes and means of processing and are therefore joint controllers within the meaning of Art. 26 GDPR. This applies to:

Google Ads, in respect of the conversion measurement and audience functions we use, jointly with Google Ireland Limited.

Meta Pixel and the insights relating to our Facebook and Instagram profiles, jointly with Meta Platforms Ireland Limited.

The LinkedIn Insight Tag and the insights relating to our LinkedIn profile, jointly with LinkedIn Ireland Unlimited Company.

In each case the joint controllership is governed by an arrangement concluded with the provider. Under those arrangements, the provider is responsible for informing data subjects about the processing, for securing the processing, and for responding to requests to exercise data subject rights, in each case in respect of the processing carried out on its infrastructure. You may exercise your rights against either us or the provider; where a request concerns processing on the provider’s infrastructure, we will forward it to the provider. The essential content of each arrangement is published by the provider concerned.

22. Recipients of Personal Data (Art. 13(1)(e) GDPR)

Personal data is disclosed only where this is necessary for the purposes described in this Notice. The categories of recipients are: hosting and infrastructure providers; security and bot protection providers; web and product analytics providers; advertising platforms; customer relationship management and scheduling providers; video conferencing and meeting transcription providers; internal collaboration, communication and process automation providers; providers of AI assistance tools; accounting software providers; our tax adviser; our bank; document destruction services; and, where legally required, public authorities and courts.

Providers acting on our behalf do so as processors bound by a data processing agreement pursuant to Art. 28 GDPR. The providers named in Section 21 act as joint controllers in respect of the processing described there.

23. Transfers to Third Countries (Art. 44–49 GDPR)

Our infrastructure is located within the European Union. Some of the providers described in this Notice belong to groups of companies headquartered in the United States, and their use may involve the transfer of personal data to the United States or access to that data from there.

Such transfers are safeguarded by an adequacy decision under Art. 45 GDPR where the recipient is certified under the EU–US Data Privacy Framework, and otherwise by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with supplementary technical and organisational measures, including encryption in transit and at rest. One provider relies on Binding Corporate Rules approved pursuant to Art. 47 GDPR.

Personal data processed on behalf of our practice clients in connection with our platform is not covered by this Section. That data is processed within the European Economic Area; where a provider involved in that processing is established in, or is controlled by an undertaking established in, a third country, the transfer safeguards set out in our data processing agreement with the practice apply.

24. Retention (Art. 13(2)(a) GDPR)

Server log data: up to six months (Art. 6(1)(f) GDPR).

Consent records: three years after withdrawal or expiry (Art. 6(1)(c), Art. 7(1) GDPR).

Analytics data: up to 14 months, or until consent is withdrawn (Art. 6(1)(a) GDPR).

Enquiries not leading to a contract: three years after the last contact (Art. 6(1)(f) GDPR).

Prospect and customer relationship management records: three years after the last contact (Art. 6(1)(f) GDPR).

Demonstration recordings and transcripts: twelve months (Art. 6(1)(a) GDPR).

Website voice demonstration: call metadata 30 days; transcript twelve months; no audio recording is stored (Art. 6(1)(f) GDPR).

Contract data: six years after the end of the year in which the contract ended (§ 257 HGB, § 147 AO).

Accounting and invoicing data: ten years after the end of the year concerned (§ 257 HGB, § 147 AO).

Unsuccessful applications: six months after the conclusion of the procedure (§ 15(4) AGG).

Where data is subject to a statutory retention obligation, it is restricted from further processing until that period expires and is then deleted.

25. Your Rights (Art. 15–22 GDPR)

You have the right to obtain access to the personal data we hold about you (Art. 15 GDPR); to have inaccurate data rectified (Art. 16 GDPR); to have your data erased where one of the grounds in Art. 17 GDPR applies; to obtain restriction of processing (Art. 18 GDPR); to receive the data you have provided in a structured, commonly used and machine-readable format and to have it transmitted to another controller (Art. 20 GDPR); and to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR). Where processing is based on your consent, you may withdraw that consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.

Where your data is processed for direct marketing purposes, you may object at any time without giving reasons, and we will cease that processing.

To exercise any of these rights, contact privacy@lebi.ai or write to us at our registered address.

26. Right to Lodge a Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, www.datenschutz-berlin.de. If you are located in the Netherlands, you may also lodge a complaint with the Autoriteit Persoonsgegevens, Bezuidenhoutseweg 30, 2594 AV Den Haag (postal address: Postbus 93374, 2509 AJ Den Haag), www.autoriteitpersoonsgegevens.nl.

27. Automated Decision-Making and Artificial Intelligence

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.

Our platform is an AI system used for administrative patient communication on behalf of healthcare practices — appointment booking and rescheduling, the relay of repeat prescription requests, callbacks and practice information. It performs no clinical assessment, triage or diagnosis, and it makes no decisions about the care a patient receives; all outcomes are determined by the practice. In accordance with Art. 50 of Regulation (EU) 2024/1689, callers are informed at the beginning of every call, before any other content is spoken, that they are interacting with an artificial intelligence system. The disclosure cannot be skipped, and each instance is logged.

Neither we nor our sub-processors use patient communication data, or data from practice management systems, to train, build or improve AI models. The providers of the models used within our service receive no data that they are permitted to store or use for their own purposes.

28. Changes to this Notice

We may amend this Notice to reflect changes in our processing activities or in legal requirements. The current version is always available at https://www.lebi.ai/ and https://www.lebi.care/. This version is effective as of 24 August 2026 and describes the processing carried out by the Company, and previously by Lebi AI GmbH i.G., since the notarisation of its articles of association on 10 July 2026. The Company was entered in the commercial register on 11 August 2026.