Privacy Notice

Last updated: September 5, 2026

1. Controller

Emilian Scheel, trading as ALL IN AGI, Moosdorfstraße 10, 12435 Berlin, Germany. Contact: go@all-in-agi.com.

2. Website and technical delivery

When you visit this website, technically necessary connection and security data is processed, including IP address, time, requested resource, status code, and browser information. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in operating the website securely and reliably. The site is hosted by Vercel Inc.; contractual and booking data is stored in a Neon PostgreSQL database in Frankfurt. Applicable data-processing terms, standard contractual clauses, and transfer assessments are used.

3. Hackathon requests and contracts

We process company and contact data, event address, dates, configuration, communications, authority confirmations, and contract evidence to handle requests and perform contracts under Article 6(1)(b) GDPR and for traceable B2B communication and legal defense under Article 6(1)(f). Unsuccessful inquiries are normally deleted six months after the last contact; contract records remain for applicable limitation and retention periods.

4. Scheduling with Cal.com

We use Cal.com to show availability and reserve preparation calls and hackathon dates. Necessary contact, schedule, and event data is transferred. Cal.com may process data in the United States under the applicable contractual safeguards.

5. Maps, location access, and address search

Maps use MapLibre GL and tiles from OpenFreeMap. Address search and coordinates selected through browser location access or the map are sent through our server to the public Photon service operated by komoot and based on OpenStreetMap data. The providers receive technically necessary connection data. Location access is optional, requires browser permission, and can be denied; addresses can always be entered manually.

6. Email delivery

Transactional email is sent through Cloudflare Email Service. Recipient, name, booking or contract details, attachments, time, delivery status, and technical message identifiers are processed under Article 6(1)(b) and (f) GDPR.

7. Invoices and payment records

We process billing address, contacts, email, optional VAT ID and purchase order, services, and payment data for invoicing and accounting under Article 6(1)(b) and (c) GDPR. Tax-relevant invoices and structured originals are generally retained for eight years.

8. Participants, devices, and security data

Participant lists are collected only where required for access, safety, or an agreed service. Dietary requirements should be provided as anonymous totals. Personal data, production data, trade secrets, and confidential source code may not be used on supplied devices or accounts without a separate agreement.

9. Photos and video

Capture, protected delivery, and publication are separate purposes. Marketing publication requires voluntary, documented consent under Article 6(1)(a) and Article 7 GDPR and Section 22 KUG. Consent can be withdrawn prospectively and participation remains possible without marketing consent.

10. Google Analytics

With your consent, we use Google Analytics 4 to measure reach and improve the website and booking flow. Usage, device, browser, approximate location, referrer, and interaction data may be processed under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Google Ireland Limited is the provider; transfers to the United States may occur under its safeguards. Event data is retained for 14 months. Google Signals, advertising links, remarketing, personalized ads, and user-provided data collection are disabled. Analytics cookies are set only after consent.

11. Recipients and international transfers

Access is limited to staff and service providers who require data for delivery, hosting, scheduling, email, or accounting, and authorities where legally required. Processors are contracted under Article 28 GDPR. Third-country transfers require an adequacy decision or safeguards such as standard contractual clauses and a documented risk assessment.

12. Your rights

Subject to GDPR requirements, you may request access, correction, deletion, restriction, portability, or object to processing. Consent can be withdrawn prospectively. You may complain to a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information.

13. Required information and automated decisions

Required request and billing information is necessary to handle the request or contract; without it, services may not be available. We do not make solely automated decisions with legal or similarly significant effects.

You can withdraw analytics consent at any time: .