Privacy Policy
LILY LABS GMBH With this document (“Privacy Policy”), we, LILY Labs GmbH (“LILY”, “We”) inform you about the nature, scope and purpose of the processing of personal data in connection with the processing activities identified in section 1 below.
Content Overview
- 1 SCOPE OF THIS PRIVACY POLICY
- 2 CONTROLLER CONTACT DETAILS
- 3 PERSONAL DATA CATEGORIES AND SOURCES
- 3.1 Categories of Personal Data
- 3.2 Sources of Personal Data
- 4 PROCESSING PURPOSES
- 4.1 Website
- 4.2 LILY Services
- 4.3 LILY Business
- 5 CATEGORIES OF PERSONAL DATA; LEGAL BASES; OBLIGATION TO PROVIDE PERSONAL DATA
- 6 PROCESSORS, THIRD-PARTY RECIPIENTS AND THIRD-COUNTRY TRANSFERS
- 6.1 Processors
- 6.2 Third-Party Recipients
- 6.3 International Data Transfers
- 7 STORAGE AND DELETION OF PERSONAL DATA
- 8 YOUR RIGHTS
- 9 CHANGES TO THIS PRIVACY POLICY
1 SCOPE OF THIS PRIVACY POLICY
(1) This Privacy Policy applies to the following processing activities where LILY qualifies as independent controller:
- the LILY website (“Website”);
- the use of the services provided by LILY under the LILY Beta Programme and the applicable Terms of Use (“Beta Terms”), including in particular, the B2B gate, use of the LILY command-line interface (“CLI”), the web-based LILY platform (“Platform”) and the LILY-operated multi-tenant server infrastructure (together “LILY Services”);
- LILY’s general business processes, such as billing and payment, marketing, advertising and business email communication with LILY (together “LILY Business”).
The LILY Services are directed exclusively at B2B customers, i.e., legal persons or partnerships with legal capacity. Accordingly, personal data processed under this Privacy Policy generally relate to the respective B2B customer’s representatives, contact persons, authorised users and beneficial owners, each acting in a business capacity. As a general rule, We therefore do not process any sensitive data (Art. 9 GDPR) or personal data related to private life/circumstances of the aforementioned data subjects.
For the Beta Terms, please refer to lilylabs.io/legal/terms.
(2) Cookie & Consent Policy.The use of cookies, analytics tools and comparable technologies used for the storage of, and access to, information on your terminal equipment (“Cookies”) and the consent management platform (“CMP”) used in that context are described in detail in our separate Cookie & Consent Policy. This Privacy Policy describes the subsequent processing of personal data gathered through Cookies.
2 CONTROLLER CONTACT DETAILS
(1) LILY is the controller for the processing of personal data covered by this Privacy Policy within the meaning of the General Data Protection Regulation (GDPR). LILY’s contact details are provided below:
LILY Labs GmbH
Maudacherstraße 45
67065 Ludwigshafen am Rhein
Germany
Email: privacy@lilylabs.io
(2) Under applicable law, LILY is not required to appoint a data protection officer. Please direct any data protection enquiries to the email address above.
3 PERSONAL DATA CATEGORIES AND SOURCES
3.1 Categories of Personal Data
We process the following categories of personal data in relation to the different processing activities covered by this Privacy Policy:
| Categories of personal data | Details |
|---|---|
| Website Usage Data / Cookie Data | In particular, IP address (anonymized), date and time of access, referred/requested URL, browser settings and similar data, device category, geo-location data, website interaction (clicks on sign-up buttons etc.) |
| Account Data | In particular, name, email address, business contact details and company information, user account ID, technical delivery information and timestamps, VAT-ID |
| CLI Usage Data | In particular, user account ID, deployment metadata (e.g. deployment identifier, target environment, timestamps, CLI and runtime version), resource usage (CPU, RAM, storage, egress) |
| Platform Analysis Data | In particular, user account ID, product interaction (page views, time spent within the dashboard, button clicks, UI interactions etc.), feature-flag assignments (A/B test groups), browser settings and similar data, device category |
| Product Telemetry Data | In particular technical logs and operational telemetry, CLI version and build identifier, operating-system family and architecture, command invoked (e.g. build, deploy), deployment identifier and associated account ID |
| Direct Marketing Data | In particular email address, name, company, interests in LILY's services, email delivery status, engagement metadata, marketing opt-ins |
| AML Screening Data | In particular, Account Data, information regarding beneficial-owner names/roles, screening results, match/false-positive assessments, related decision records |
3.2 Sources of Personal Data
We generally collect all personal data that We process directly from you when you provide the data to us. To some extent, some of the personal data is also collected automatically when you visit the Website or use the LILY Services.
4 PROCESSING PURPOSES
We process your personal data for the following purposes under each of the different processing activities covered by this Privacy Policy:
4.1 Website
Managing and Providing Access to the Website
When you visit our Website, or access the LILY Services through the Website, your browser transmits certain data to our web server. We process such data to ensure the functionality and security of the Website, including detecting and repelling attacks and ensuring the functionality of the Website.
4.2 LILY Services
Beta Programme Registration
To access and use the Beta Programme you must register a business account, using the B2B gate. Data provided in the B2B gate is used for authentication and verification purposes to set up your account, validate the VAT-ID provided against the EU VIES system, or, for non-EU users, an equivalent business identifier and verify your status as entrepreneur.
Resource Metering
As a key part of the LILY Services, We provide the CLI with integrated compiler and local runtime environment for compiling, locally executing and deploying user applications. CLI enables users to compile their source code by means of the different functionalities offered under the LILY Services. To the extent personal data is processed in this context, processing is carried out for metering of resource consumption for credit-based billing (as further detailed in the Beta Terms).
Platform Analytics
When you use the Platform, We process certain data to operate, secure, debug and improve the Platform’s core functionality, i.e. to understand which features are used and where errors or friction occur. If you have consented via the CMP to the use of the respective Cookies, We may also use your personal data for marketing, advertising or conversion purposes.
Product Telemetry
We may collect technical logs and operational telemetry of programs, applications or workload compiled by users of the LILY Services that are executed on LILY’s multi-tenant server infrastructure (Void). Such processing activities are carried out for error and crash analysis, to ensure and maintain operational stability and capacity management, security monitoring and abuse prevention.
4.3 LILY Business
Business Communication and Transactions
We process certain personal data to transact business and maintain a professional relationship with you and/or the company you represent, in particular to send contractually required and operationally necessary emails concerning the services requested, including registration and admission confirmation, billing notices, service notifications, and support emails.
Compliance with Legal Obligations, Exercising and Defending against Claims
As part of our general business processes, We may process certain personal data to comply with applicable legal obligations, such as tax law requirements, identity verification (KYC) and screening of paying customers, their beneficial owners and relevant counterparties against applicable financial-sanctions and asset-freeze lists. This may include AML checks where applicable (as further detailed in the Beta Terms). We may also process personal data to establish, exercise or defend our legal rights, to comply with lawful government requests for disclosure of personal information or otherwise to comply with legal obligations.
Advertising and Marketing
We may process certain personal data to send you emails informing you about product news or beta announcements. If you have signed up for newsletters, We may, in addition, process your data to inform you about the services, offerings, events and newsletters in which you have expressed an interest.
5 CATEGORIES OF PERSONAL DATA; LEGAL BASES; OBLIGATION TO PROVIDE PERSONAL DATA
(1) In the table below, you will find an overview of categories of personal data that We process for the purposes listed above in section 4 and the legal bases We rely on in each case.
| Processing Purposes | Categories of personal data | Legal bases | |
|---|---|---|---|
| Website | Managing and Providing Access to the Website/Platform | Website Usage Data / Cookie Data | Art. 6(1)(f) GDPR — Legitimate interest (secure and stable operation of the Website) |
| LILY Services | Beta Programme Registration | Account Data; AML Screening Data | Art. 6(1)(f) GDPR — Legitimate interest (providing and operating the means for customer registration required to access the LILY Services); Art. 6(1)(c) GDPR — Compliance with legal obligations |
| Resource Metering | CLI Usage Data; Product Telemetry Data | Art. 6(1)(f) GDPR — Legitimate interest (metering of resources to enable cosumption-based billing) | |
| Platform Analytics | Platform Analysis Data; Website Usage Data / Cookie Data | Art. 6(1)(f) GDPR — Legitimate interest (secure and stable operation of the Platform, product/service improvement); Art. 6(1)(a) GDPR — Consent | |
| Product Telemetry | Product Telemetry Data | Art. 6(1)(f) GDPR — Legitimate interest (secure and stable operation of LILY Services, product/service improvement) | |
| LILY Business | Business Communication and Transactions | Account Data | Art. 6(1)(f) GDPR — Legitimate interest (enabling business communication) |
| Compliance with Legal Obligations, Exercising and Defending against Claims | Account Data; AML Screening Data; Website Usage Data / Cookie Data | Art. 6(1)(c) GDPR — Compliance with legal obligations; Art. 6(1)(f) GDPR — Legitimate interest (establish, exercise or defend our legal rights) | |
| Advertising and Marketing | Website Usage Data / Cookie Data; Direct Marketing Data | Art. 6(1)(a) GDPR — Consent; Art. 6(1)(f) GDPR — Legitimate interest (direct marketing) |
(2) There is generally no statutory or contractual obligation that requires you to provide certain personal data to us. Providing your personal data is therefore voluntary and you may choose not to provide your personal data. In such case, however, you may not be able to use certain functionalities of the Website and/or to interact with us. Also, providing your personal data will be necessary to use the LILY Services and/or conclude a contract with us.
6 PROCESSORS, THIRD-PARTY RECIPIENTS AND THIRD-COUNTRY TRANSFERS
Where We can do so lawfully under applicable law, We may share certain personal data processed by us with the following categories of recipients, some of whom may be located in a country that does not provide an adequate level of data privacy and protection rights as the European Union (“EU”), as necessary for the purposes identified above in section 4 (see section 6.2 for more information). These recipients may have both direct access to your personal data (e.g., if We transfer your personal data) or remote access (e.g., if these recipients access personal data that is stored in our systems).
6.1 Processors
We rely on the following services providers when processing personal data for the purposes identified in this Privacy Policy. Recipients handle personal data in EU data centres unless otherwise stated; where a recipient processes data in the US or another country that is not considered as providing for an adequate level of data protection under EU law , the transfer basis is stated in the table.
| Processor | Seat | Processing location | Role / purpose | Transfer mechanism |
|---|---|---|---|---|
| IONOS SE | Montabaur, Germany | Karlsruhe, Frankfurt (Germany) | Processor (server infrastructure, hosting) | n/a (EU only) |
| Google Ireland Limited | Dublin, Ireland | europe-west1 (Belgium) | Processor (server infrastructure) | n/a (EU only) |
| PostHog Inc. | San Francisco, USA | Germany | Processor (Platform product analytics) | n/a (EU only) |
| Resend (Solamatic, Inc.) | San Francisco, USA | USA | Processor (email delivery) | EU-U.S. DPF |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Dublin, Ireland | EU, US | Processor (payment processing) | n/a for EU, EU-U.S. DPF for US |
| Cloudflare, Inc. | San Francisco, USA | Global (anycast) | Processor (DNS, reverse proxy, WAF, TLS termination for lilylabs.io, auth. and admin.; terminates every client IP) | EU-U.S. DPF, SCCs as fallback |
| MailerLite (Lithuania) | Vilnius, Lithuania | EU | Processor (newsletter and waitlist opt-in) | n/a (EU only) |
| Google Ireland Limited | Dublin, Ireland | EU | Processor (authentication — sign-in with Google) | n/a (EU only) |
| GitHub, Inc. | San Francisco, USA | USA | Processor (authentication — sign-in with GitHub; repository integration) | EU-U.S. DPF, SCCs as fallback |
6.2 Third-Party Recipients
In addition to the processors identified above, We may also disclose your personal data to third parties who process personal data as independent controllers, i.e., who will process your personal data for their own purposes. These are, in particular, the following:
Advisors and authorities: This includes auditors, accounting service providers, lawyers, banks, tax advisors and similar bodies to the extent that sharing your personal data with them is necessary for the provision of their services and/or compliance with legal obligations that We are subject to. We may also be legally obligated to provide information to certain public authorities upon request, such as law enforcement agencies, authorities that prosecute administrative offenses subject to fines and tax authorities.
Payment service providers: We may also share your personal data with payment service providers such as Stripe that may act as independent controllers for payment execution and compliance with their own AML, fraud and/or sanction list screening obligations.
6.3 International Data Transfers
Where a recipient processes data in the US or another country that is not considered as providing for an adequate level of data protection under EU law, residual risks exist due to potential access by local authorities. For the US, We rely on the EU-US Data Privacy Framework to ensure an adequate level of data protection where a recipient is certified. In other cases, We have implemented appropriate safeguards, such as the EU Standard Contractual Clauses, and/or are relying on binding corporate rules of the recipient or an appropriate derogation. Where applicable, We implement supplementary technical and contractual safeguards. In addition to the rights set out in section 8 below, you can request further information on such appropriate safeguards, using the contact details indicated in that section 8.
7 STORAGE AND DELETION OF PERSONAL DATA
We process personal data only for as long as necessary for the respective purposes or as required by statutory retention obligations. Data subject to statutory commercial or tax retention requirements (in particular Section 257 of the German Commercial Code (Handelsgesetzbuch), Section 147 of the German Fiscal Code (Abgabenordnung)) are retained for the prescribed period (generally 6 to 10 years). Data subject to anti-money-laundering retention (Section 8 of the German Act on Money-Laundering (Geldwäschegesetz)) are generally retained for 5 years, unless longer retention is statutorily required. Data needed to assert, exercise or defend legal claims are generally retained until expiry of the applicable limitation period (generally 3 years). Operational and technical data (such as server logs, telemetry and analytics data) are generally deleted or anonymised within 90 days after collection, unless longer retention is required for security incident investigation or legal proceedings. After the purpose ceases and any retention periods expire, data are deleted or anonymised.
8 YOUR RIGHTS
You have the following rights regarding your personal data:
- Right of access: You have the right to obtain confirmation from us at any time as to whether or not personal data concerning you are being processed, and, where that is the case, to obtain access to the personal data relating to you that is being processed by us to the extent and under the conditions of Art. 15 GDPR.
- Right to rectification: In accordance with Art. 16 GDPR, you have the right to obtain from us the rectification of inaccurate personal data concerning you. If applicable, you have the right to request the completion of incomplete personal data.
- Right to erasure: You can request the erasure of your personal data under the conditions of Art. 17 GDPR.
- Right to restriction of processing: Under the conditions of Art. 18 GDPR, you have the right to request that the processing of your personal data be restricted. In this case, the corresponding data will be marked and may only be processed by us for certain purposes.
- Right to data portability: In accordance with Art. 20 GDPR, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you have the right to transmit those personal data to another organisation without hindrance from us.
In certain cases, you have the right to object to the processing of your personal data at any time on grounds relating to your particular situation. If you exercise this right to object, We will no longer process your personal data for these purposes unless We have compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
If We process your personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
Where We process your personal data on the basis of consent, you have the right to withdraw your consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of the processing of your personal data up to the time of withdrawal. For newsletters that you have subscribed for, you can withdraw your consent via the unsubscribe link provided in the newsletter; Cookie consent can be withdrawn via the CMP.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for LILY is: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.
You can exercise your rights at any time by contacting us at: privacy@lilylabs.io.
9 CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time as necessary when processing activities, service providers or legal requirements change. The current version is available at lilylabs.io/legal/privacy. For material changes, registered users will be notified by email.
Last change: August 2026
Step into the world after the cloud.
Start for free, integrate in minutes, and scale when you need to.
What is coming after the cloud
LILY Labs GmbH, Maudacherstraße 45, 67065 Ludwigshafen am Rhein
Amtsgericht Ludwigshafen am Rhein, HRB 70791
© 2026 LILY Labs GmbH. All rights reserved.