for llmtaskforce.ai (public information pages) and app.llmtaskforce.ai (the beta application), pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR)
Private, non-commercial service — closed feedback beta. This service is operated by a private individual, not by a company. It is free of charge, without advertising and without an offer for sale. It is intended to be made available only to a limited group of personally invited persons in order to obtain feedback on the platform; it is not a public service for a general audience or consumers. This private and non-commercial orientation does not alter the data-protection obligations: wherever personal data are processed, the GDPR applies in full regardless of the duration, scale or commercial nature of the offering.
The controller within the meaning of Article 4(7) GDPR is:
Dr. Daniel Opoku, private individual (no company, not operating commercially)
Gebrüder-Coblenz-Str. 10, 50679 Cologne, Germany
Email: your.agents@llmtaskforce.ai
Telephone: +49-221-44900105
Represented by: Dr. Daniel Opoku (private individual, no separate representation)
Data protection officer: None has been appointed. The assessment documented in the legal bundle is that there is currently no obligation to appoint one under Article 37 GDPR and section 38 BDSG because, among other things, as a rule at least 20 persons are not permanently engaged in the automated processing of personal data. REQUIRES LEGAL CONFIRMATION This assessment, in particular whether a data protection impact assessment (DPIA, Article 35 GDPR) becomes mandatory for the combination of multi-provider AI onward routing and security monitoring — which would trigger an appointment obligation under section 38(1), second sentence, BDSG regardless of the number of persons — must be completed by an attorney and, where in doubt, a consulted data protection officer before publication.
Competent data protection supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, https://www.ldi.nrw.de. Check the contact details against the authority’s current details before publication.
llm_task_force is a human-in-the-loop orchestration tool that forwards structured tasks to specified AI-agent roles and external AI model providers. The service is not itself a model provider. This privacy policy applies to:
llmtaskforce.ai (home page, legal notice, this privacy policy); andapp.llmtaskforce.ai, which is available exclusively to personally invited testers with individual access.Access is granted exclusively by personal invitation and serves use of, and feedback on, the platform. It is a closed service, not a public service for a general audience or consumers. Testers should not enter or upload data for whose processing they do not have rights or authorisation. Entering special categories of personal data under Article 9 GDPR, children’s data, health or payment data, third-party credentials or unlawful content is discouraged unless this has been expressly agreed and legally reviewed (see section 6).
Personal data originate from the following sources:
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account, invitation and authorisation data | Email address, invitation status, actor_id, tenant_id, role, login events, one-time password (OTP) by email | Setting up and operating beta access, authentication, tenant and role verification | Article 6(1)(b) GDPR for the invitation and provision of access; Article 6(1)(f) GDPR for security and orderly beta operation |
| Tenant content: tasks, prompts, messages, uploaded files, transcripts, AI responses | Free-text tasks, project files, chat/task histories, AI outputs | Processing the task you requested through the agent roles and model providers you selected; display and continuation in the dashboard | Article 6(1)(b) GDPR; additionally Article 6(1)(f) GDPR for error analysis and security within the beta |
| Security and audit logs | Login/token events, role/tenant access, security-relevant actions | Access control, abuse detection, traceability | Article 6(1)(f) GDPR |
| Server, application and error logs | Timestamps, IP address, user agent, technical error IDs | Operational security, troubleshooting, attack detection | Article 6(1)(f) GDPR |
| Geo/network security logging (log mode) | Source IP address, country and network range (autonomous system) derived from it | Detecting and logging access from unexpected countries/networks for early abuse detection; the beta does not block access, it records only a “would-block” log entry | Article 6(1)(f) GDPR, supported by recital 49 GDPR (network and information security) |
| Cost and usage metadata (token harvest) | Provider/model/tool values, token/cost values, timestamps, path/object hashes — no raw content of prompts, responses or files | Cost control, capacity planning, abuse detection, beta evaluation | Article 6(1)(f) GDPR; Article 6(1)(b) GDPR where required for the beta service |
| Optional local voice data | Local voice input/output, if enabled | Input assistance for requested tasks; cloud voice processing is switched off in the beta, processing is local only | Article 6(1)(b) GDPR for the expressly used feature |
| Browser storage and cookies | Session cookie ltf_auth_session, CSRF-protection cookie ltf_csrf, theme preference with prefix ltf_ | Maintaining the session, access protection, protection against cross-site request forgery, remembering the selected display | Session and CSRF cookie: strictly necessary under section 25(2) TDDDG. Theme: functional preference; REQUIRES LEGAL CONFIRMATION whether strictly necessary or consent-required |
No consent-based analytics, advertising or tracking services are used. Personal data are not disclosed or sold for advertising purposes.
Data protection is designed as a product feature, not added afterwards. The platform is built so that the operator does not by default access the readable content of your tenant — your tasks, files and results. Specifically, according to the current system state, this means:
Open issue stated candidly rather than concealed: An internal, independent security review of 8 July 2026 found that, at the time of review, two specific administrative endpoints (escalation log and dispatch log) could return unfiltered content of another tenant to a platform-wide administrator, contrary to the rule described above. The other reviewed paths (in particular transcript and individual-audit routes and the customer-facing privacy endpoints) were assessed as correctly restricted. Now closed: both findings were fixed on 8 July 2026; since then both endpoints return only content-free metadata, including to platform-wide administrators, and never the tenant content itself. REQUIRES LEGAL CONFIRMATION: whether the “operator cannot read” principle may go further and be presented as a seamless, absolute guarantee (compare the corresponding clause in the beta Terms). This privacy policy describes the principle as the design principle and overwhelmingly prevailing actual state of the platform, not as a seamless, absolute assurance already fully verified.
Because the operator does not routinely read your tenant content under this design principle, it generally cannot search, curate or restore it for you on a content basis. You are primarily responsible for backing up and restoring your own data through the built-in self-service functions; the beta Terms regulate the details.
The service is not intended to process special categories of personal data under Article 9 GDPR. Free text and uploads may nevertheless contain such data if testers enter them. REQUIRES LEGAL CONFIRMATION: a defensible Article 9 GDPR exception for intentionally entered special categories, or alternatively an express prohibition with organisational enforcement, must be finalised before productive use with real test data.
Decided (operator decision of 20 July 2026) The processing of tenant content takes place exclusively on a server operated at Hetzner Online GmbH (Germany/EU), internally called ltf_server; for this, Hetzner is the hosting sub-processor (data processing agreement with Hetzner concluded on 3 July 2026). The tenant test and beta phase begins only once this deployment is, in accordance with the project’s own decision log, evidenced to be in operation; as of this draft that evidence has not yet been furnished, and no processing of tenant content yet takes place. The operator’s internal development and operations infrastructure is not a processing location for tenant content.
Under the existing drafts, the public information pages (llmtaskforce.ai) are hosted by IONOS SE (Elgendorfer Str. 57, 56410 Montabaur), which also provides the email service for the domain; domain registration and authoritative DNS name servers are provided through Spaceship, Inc (Phoenix, AZ, USA). These two roles concern the marketing/contact layer, not the processing of tenant content, and continue independently of the tenant hosting at Hetzner. Confirm before publication.
llm_task_force forwards tasks to configured external AI model providers: Anthropic, OpenAI and Google. No local model processing takes place for the hosted beta.
For a single task, content required for that task may be transmitted simultaneously to several of those providers (parallel transmission, “fan-out”). In addition, one provider’s output may be forwarded as input for a further processing step to a different provider (“onward transfer” or “cross-feed”). A task can therefore involve multiple recipients at the same time and multiple consecutive transmission steps. Only the data required for the particular processing step are transmitted to each provider (prompts, selected files or excerpts, context, intermediate and final results from other providers in the context of onward transfer, technical metadata, AI responses).
Legal basis: Article 6(1)(b) GDPR for the task processing you requested; Article 6(1)(f) GDPR for a controlled and secure beta operation.
These providers are sub-processors within the meaning of Article 28 GDPR to the extent that the operator itself acts as a processor for a tenant (see section 16 and the separate data processing agreement template). REQUIRES LEGAL CONFIRMATION for each provider: exact contracting entity, data processing agreement/Data Processing Addendum, transfer mechanism, retention and “no-training” status.
On the system state used as the basis here, Anthropic and OpenAI process in the United States (a third country); for Google, processing in the EU or United States may be possible depending on the specific contractual configuration. For transfers to the United States, processing relies on the EU Standard Contractual Clauses (SCC) under Article 46 GDPR or — where the specific recipient is actively certified at the time of transfer and the processing is within the scope of certification — the EU-US Data Privacy Framework (DPF) adequacy decision under Article 45 GDPR. Through fan-out and onward transfer (section 8), more recipients and additional transfer steps may be involved per task than when using one provider. Despite contractual and technical safeguards, residual risks remain for US transfers, in particular possible access by public authorities. REQUIRES LEGAL CONFIRMATION: SCC module, DPF certification status for each provider and at the relevant time, and a complete transfer impact assessment covering the multi-provider combination and onward transfer.
For Spaceship (USA, registrar/DNS), the EU Standard Contractual Clauses apply through Spaceship’s Data Processing Addendum; only registration- and DNS-related data are affected, not tenant content.
Deletion is preceded by a manual review so that security incidents, open support cases, legal defence or contractual evidence obligations can be considered. Where two values are stated, the first is the regular review period and the second is the maximum retention following manual review.
| Data area | Regular review period | Maximum retention |
|---|---|---|
| Account, invitation and role data | for the duration of beta access | insert specific period for unaccepted invitations |
| Inbox / incoming tasks | 90 days | 365 days |
| Responses / results / transcripts / uploads | 30 days | 180 days |
| Audit logs | 90 days | 365 days |
| Server, application and error logs | 30 days | 180 days |
| Cost and usage metadata | 90 days | 365 days |
| Geo/IP security log (log mode) | 90 days (proposal) | specific period to be confirmed |
Encrypted backups may contain deleted data until the respective backup cycle ends. Specific backup retention, restore/deletion reconciliation and the persons responsible for manual review must be documented before publication.
Subject to the conditions of the GDPR, you have the following rights: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20, where the conditions are met), objection to processing based on Article 6(1)(f) GDPR (Article 21), and withdrawal of consent with effect for the future (Article 7(3)) if a processing operation is in future based on consent. Under the current operational concept, the beta does not make a decision based solely on automated processing within the meaning of Article 22 GDPR that produces legal or similarly significant effects concerning testers.
Some of these rights can be exercised through the self-service functions built into the platform (for example, export of one’s own tenant data). A message to the contact address stated in section 1 is also sufficient. Identity verification may be required to prevent unauthorised disclosures. Requests are generally answered within one month under Article 12(3) GDPR.
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority responsible for the controller is the LDI NRW stated in section 1.
According to the current system state, the measures used include HTTPS-only with TLS 1.3 on every network segment, HSTS, administrative access only through a secured administrative network, role- and tenant-based access restrictions, two-factor authentication using an email one-time password, audit logs, encrypted backups, a strict Content Security Policy, rate limiting, and no analytics or tracking services. These statements describe the intended beta state; the complete, versioned documentation of technical and organisational measures (TOM) under Article 32 GDPR is in and also identifies open points there, in particular encryption of operational data at rest and key management — this privacy policy does not claim that those open points have already been closed.
The application uses technically necessary cookies: the session cookie ltf_auth_session (HttpOnly, Secure, SameSite=Strict) and the CSRF-protection cookie ltf_csrf; both are strictly necessary under section 25(2) TDDDG. A functional display preference (light/dark) is additionally stored in the browser. The public information pages set no cookies; a display preference only is stored in the browser’s local storage. Fonts are supplied exclusively locally from the operator’s own server; no external font services are embedded.
AI outputs are generated automatically and may be incomplete, incorrect or unsuitable. Testers must review AI outputs professionally before using them outside the beta. No advertising profiling takes place. The transparency obligations of Regulation (EU) 2024/1689 on artificial intelligence require separate LEGAL REVIEW for notices from 2 August 2026.
To the extent that you, as an invited tenant, process personal data of third parties through the platform (for example, data of colleagues, customers or other persons in your tasks, files or projects), you are yourself the controller of that processing within the meaning of Article 4(7) GDPR, and the operator acts as a processor under Article 28 GDPR. A separate data processing agreement (DPA) is provided for this case. REQUIRES LEGAL CONFIRMATION: execute the DPA with every affected tenant before productive use with real third-party data.
This privacy policy may be adjusted during the beta, in particular if model providers, retention periods, storage locations, roles or legal bases change. Material changes will be communicated to testers in an appropriate form.
ltf_server) actually goes live, and corresponding updating of this policy and the sub-processor list (see section 7).