NewThe ManyPI MCP Server is now live

Your data rights

What rights you have, and exactly how to use them — whether or not you are a ManyPI user.

Version 2.0 · Effective 5 September 2026

This page is a practical guide. It does not replace our Privacy Policy, which is the formal notice under Articles 13 and 14 GDPR, but it explains what to do rather than what the law says.

If you were emailed by a ManyPI customer and want it to stop, skip to section 3. It is written for you and there are things we can do immediately.

Contents

Two very different groups of people arrive at this page, and the answer differs for each. Please read the one that applies to you.

A. You use ManyPI, or you are thinking about it.

We are the controller of your account, billing and usage data. Exercise your rights against us directly — see section 2.

B. You received an email from someone who uses ManyPI, or you found your details in a ManyPI customer's system.

For that data we are only the processor. The ManyPI customer who contacted you decided to collect your details and to write to you; they are the controller, and the law gives you your rights against them. We are not permitted to reach into their data and make decisions about it on our own initiative.

That said, we do not intend to leave you going in circles, and there are things we can do directly. See section 3 — it is written for you.

C. Both. Read both sections.

Where we act as controller — your account, your billing, your use of the Service, our own marketing — you have the following rights under the GDPR.

Right of access (Art. 15). To know whether we process your personal data, and to receive a copy along with information about purposes, categories, recipients, retention and your rights.

Right to rectification (Art. 16). To have inaccurate data corrected and incomplete data completed.

Right to erasure (Art. 17). To have your data deleted where one of the grounds in Article 17(1) applies. This is not absolute: we may keep what we are legally required to keep, in particular invoices and accounting records, which German commercial and tax law requires us to retain for up to ten years.

Right to restriction (Art. 18). To have processing restricted while a dispute about accuracy or lawfulness is resolved.

Right to data portability (Art. 20). To receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

Right to object (Art. 21). To object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. Where we process your data for direct marketing, you may object at any time and we will stop — no reasons needed and no balancing applies.

Right to withdraw consent (Art. 7(3)). Where processing is based on your consent — analytics cookies, our newsletter — you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand.

Rights concerning automated decisions (Art. 22). We do not subject you to decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

How to exercise them.

  • In the app: Settings contains data export and account deletion, and Notifications contains your marketing preferences. This is the fastest route.
  • Cookies: use the "Cookie settings" link in the footer to change or withdraw your analytics consent.
  • By email: privacy@manypi.com.

What happens next. We respond within one month. If a request is complex or we have received several from you, we may extend by up to two further months and will tell you within the first month, with reasons. We do not charge, unless a request is manifestly unfounded or excessive. We may ask for information to confirm your identity — only what is necessary, and only where we have genuine doubt.

You did not sign up for anything, and you are entitled to a straight answer. Here it is.

Who holds your data. A business that uses our software collected your business contact details — usually your name, job title, employer and work email address, sometimes a phone number or a professional profile link — and stored them in their own private workspace. That business decided to do that and decided to contact you. Under the GDPR they are the controller and we are their processor. We do not have a customer relationship with you, we did not choose to contact you, and we do not use your details for our own purposes.

Why this matters for your request. The law directs your rights at the controller, and it also stops us from reaching into a customer's workspace and acting on our own judgement. If we deleted records from a customer's database on an unverified request, we would be the ones acting unlawfully.

Step 1 — go to the sender. The fastest route is to reply to the email you received and ask them to delete your data and stop contacting you. They are legally obliged to comply. Every message sent through our platform is required to carry a working unsubscribe link and a genuine, monitored reply address.

Step 2 — if that does not work, come to us. Write to privacy@manypi.com with the email you received, including its full headers if you can. We will:

  • identify which of our customers holds your data;
  • forward your request to them and formally instruct them to act on it;
  • tell you that we have done so, and who they are, so that you can pursue it directly if you choose;
  • follow up if they do not respond.

What we can do for you immediately, without needing anyone's permission.

  • Add your address to a permanent suppression list. On request we will suppress your address so it cannot be contacted through our platform. Tell us whether you want this applied to the specific sender or across our entire platform — we can do either.
  • Delete your entry from our own caches. As explained in section 4, we hold two small operational caches for which we are the controller. You can have your entry removed from those directly, and we will do it without asking anyone.
  • Tell you what we hold about you in those caches, on request.

Where your details came from. Business contact information collected through our platform is drawn from publicly accessible sources — most often a company's own website, and public professional directories and profiles. Our customer is required by Article 14 GDPR to tell you the specific source on request. If they will not, tell us and we will help you establish it.

We would rather you complained to us than stayed on a list. If a ManyPI customer is ignoring you, that is a breach of our Acceptable Use Policy and we want to know. Reports go to abuse@manypi.com.

We are being explicit about this because it is the one place where we hold information about people who never signed up, on our own account rather than a customer's.

To avoid fetching the same public page and querying the same mail server over and over — which would burden other people's infrastructure — we keep two shared caches:

  • Published company contact details, organised by website domain: email addresses, phone numbers, named roles and social profile links as published by the company on its own site.
  • Email deliverability results, organised by address: whether a mailbox was found to exist, and the responding server's code.

Our legal basis is Article 6(1)(f) GDPR — the legitimate interest of ourselves, and of the operators of the systems we would otherwise query repeatedly, in not performing the same lookup many times. We have carried out and documented a balancing assessment.

Safeguards. Entries expire on a defined cycle. The deliverability cache cannot be read by any customer account at all — it is reachable only by internal service processes — specifically so it cannot be used to test whether arbitrary addresses exist. Neither cache records who looked anything up. Neither is used to build a profile of you, and neither is sold, licensed or shared.

Your rights here run against us directly. Write to privacy@manypi.com and we will tell you what we hold and remove it. You do not need to involve any customer, and we will not ask one.

When you are interacting with AI. The ManyPI assistant is an artificial intelligence system, and we tell you so at the point of use. Content it produces is generated, not written by a person.

What we send to an AI provider. OpenAI is our only AI provider. Depending on the feature used, we transmit: instructions given by our customer; contact records supplied as context for drafting a message; excerpts of the text of replies received, for sentiment and intent classification; the contents of files uploaded for analysis; and excerpts of web pages retrieved during research.

Training. We do not use personal data processed through the Service to train, fine-tune or improve any AI model, and we have contracted with our AI provider on terms that prohibit them from training their models on data submitted through the interface we use.

Automated decisions. Our software scores and ranks contacts so that a user can decide who to approach first. That is a prioritisation aid for a human being, not a decision about you. It produces no legal effect concerning you and does not similarly significantly affect you within the meaning of Article 22 GDPR. Our terms prohibit customers from using the Service to make decisions of that kind — for instance about employment, credit or insurance.

Accuracy. AI output can be wrong. If a message you received contained inaccurate information about you or your company, tell us at privacy@manypi.com; if it came from one of our caches we will correct it at source.

Account data, CRM records, contact records and synchronised mail are stored on servers in the European Union. Background processing runs on servers in Germany and Finland. Ordinary storage and processing therefore involves no transfer outside the EEA.

Some functions require providers established outside the EEA — AI inference and payment processing in the United States, web data collection in Israel. For every such transfer we rely on the EU Standard Contractual Clauses as a standing safeguard, in addition to any adequacy decision or framework certification that may separately apply. We deliberately do not rely on the EU-US Data Privacy Framework alone, because its validity is currently before the Court of Justice of the European Union.

The full list, with each provider's role, location and safeguard, is on our Sub-processors page.

If you are not satisfied with how we have handled your request, please tell us first at privacy@manypi.com. Most problems are misunderstandings and we would like the chance to fix ours.

You also have the right to lodge a complaint with a supervisory authority, in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. Our lead authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit

Alt-Moabit 59-61, 10555 Berlin, Germany

Telephone: +49 30 13889-0

https://www.datenschutz-berlin.de

You may also seek a judicial remedy, and you may have a right to compensation under Article 82 GDPR.

If your complaint is about a ManyPI customer rather than about us, the competent authority is the one for that customer's own establishment. Tell us and we will identify them for you so that you can direct your complaint correctly.

Controller

ManyPI

Ole Nepomuk Mai

Goethestrasse 70

10625 Berlin

Federal Republic of Germany

Data protection enquiries and rights requests: privacy@manypi.com

Legal and contractual enquiries: legal@manypi.com

Abuse reports: abuse@manypi.com

Security reports: security@manypi.com

Telephone: +49 30 3977 0918

Data protection officer. ManyPI is a sole proprietorship and does not meet the criteria in Article 37(1) GDPR for the mandatory designation of a data protection officer, so none has been appointed. Data protection enquiries are handled by the owner personally at the address above. Should the criteria come to apply, we will designate an officer, publish the contact details here and notify the supervisory authority.

ManyPI, Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Federal Republic of Germany