Privacy Notice
Privacy notice pursuant to Art. 13, 14 GDPR regarding the use of the service maKI (LLM proxy of Universität Mannheim).
The following describes which personal data we process for which purposes, on what legal basis, for how long we retain it, to whom it may be disclosed, and which rights you can exercise.
Controller and Data Protection Officer
Section titled “Controller and Data Protection Officer”Controller:
Universität Mannheim
Schloss
68161 Mannheim
Germany
Email: rektor@uni-mannheim.de
Operating unit:
Universitätsrechenzentrum (URZ)
Universität Mannheim
L 15, 16
68131 Mannheim, Germany
Data Protection Officer:
Jan Morgenstern
Attorney and Specialist Lawyer for IT Law
Johannesstraße 30, 67346 Speyer, Germany
Email: datenschutzbeauftragter@uni-mannheim.de
Service description and purpose of processing
Section titled “Service description and purpose of processing”maKI is an internal LLM proxy service based on LiteLLM. It provides staff of Universität Mannheim with API access to locally hosted language models.
Universität Mannheim collects and processes your personal data in order to:
- provide LLM inference for work-related purposes
- meter usage and plan capacity
- control access via API keys
- communicate with users for operational purposes (maintenance announcements, outage notifications)
Consequences of non-provision
Section titled “Consequences of non-provision”An API key is required to use the service. Without an API key, access is not possible. There is no statutory obligation to provide personal data; no disadvantages arise from non-provision other than the inability to use the service.
Categories of data
Section titled “Categories of data”| Data category | Examples |
|---|---|
| API key assignment | Key name, assigned person or team, email address |
| Usage data | Timestamp, model used, token count, cost per request |
| Monthly aggregates | Token totals and costs per key, model, and month |
| Access logs | IP address, timestamp, requested path, HTTP status code |
Types of API keys
Section titled “Types of API keys”The service distinguishes three key types:
- Personal keys — assigned to an individual person. Usage data can be indirectly attributed to that person via the key.
- Service keys — assigned to an application or team, with no reference to an individual. Usage data cannot be used to infer the behavior of individual employees.
- Batch keys — for low-priority background workloads, also assigned to an application or team with no reference to an individual.
What is not stored
Section titled “What is not stored”- No storage of prompts or model responses. The contents of your requests and generated responses are not logged.
- No automated decision-making within the meaning of Art. 22 GDPR.
Purpose limitation of usage data
Section titled “Purpose limitation of usage data”Usage data is collected exclusively for capacity planning, cost allocation, and technical operations. It is not used for monitoring the behavior or performance of employees.
Legal basis
Section titled “Legal basis”The processing of personal data by Universität Mannheim is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Art. 6(1)(e) GDPR in conjunction with Art. 6(3) GDPR and § 4 of the Baden-Württemberg State Data Protection Act [LDSG BW]).
Specifically, the provision of maKI is based on the university’s statutory task of providing IT infrastructure for research, teaching, and administration.
Source of the data
Section titled “Source of the data”Data is collected exclusively directly from the data subjects — when applying for an API key (name, work email address) and when using the service (usage and access logs).
Recipients
Section titled “Recipients”Your personal data is not transferred to third parties. All processing takes place on university-owned infrastructure at the Mannheim site.
No data is transferred to external service providers or to third countries. All models made available to end users run locally on GPU infrastructure at Universität Mannheim. No data processing agreement with external providers is in place.
In addition, in accordance with archival law, records must be offered to the university archive before deletion; the archive decides on whether to take over records.
Retention period
Section titled “Retention period”| Data type | Retention period |
|---|---|
| Detailed usage data | 12 months, then automatically aggregated into monthly totals |
| Monthly aggregates | Indefinite (no personal reference after aggregation) |
| API key assignment | Until deactivation + 12 months |
| Access logs | 7 days (automatic rotation) |
Your rights as a data subject
Section titled “Your rights as a data subject”You have the right:
- pursuant to Art. 15 GDPR to request access to the personal data we process about you
- pursuant to Art. 16 GDPR to request the rectification of inaccurate or completion of incomplete personal data stored about you
- pursuant to Art. 17 GDPR to request the erasure of personal data stored about you, where no legal retention obligation exists
- pursuant to Art. 18 GDPR to request the restriction of processing of your personal data
- pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority
To exercise your rights as a data subject, please contact:
Email: anfrage.datenschutz@uni-mannheim.de
Supervisory authority:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
Right to object
Section titled “Right to object”Where your personal data is processed on the basis of Art. 6(1)(e) GDPR (processing in the public interest), you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data on grounds relating to your particular situation.
To exercise your right to object, a simple email is sufficient:
anfrage.datenschutz@uni-mannheim.de
Cookies and third-party services
Section titled “Cookies and third-party services”maKI is a pure API service with no end-user web interface. The API does not set any cookies. The documentation site at maki.uni-mannheim.de/docs also does not set cookies and does not embed any external services, CDNs, tracking or analytics tools. All resources (fonts, stylesheets, scripts) are served from university-owned infrastructure.
Technical and organizational measures
Section titled “Technical and organizational measures”- Encryption of all connections (TLS)
- Network segmentation (no direct internet access for backend systems)
- Access exclusively via API keys
- Regular backups with restore validation
- Monitoring and alerting
Optional content screening (guardrail)
Section titled “Optional content screening (guardrail)”In operation, an optional guardrail can be enabled that screens incoming requests with a locally hosted classification model before the main model call, in order to detect requests for personal data of third parties. This screening runs exclusively on university-owned infrastructure; request contents are not stored. The guardrail is not enabled by default and can be activated per key or per model.
Contact
Section titled “Contact”For questions about data protection for this service, contact:
Philipp Hematty
Email: philipp.hematty@uni-mannheim.de
Or the Data Protection Service of Universität Mannheim:
Email: anfrage.datenschutz@uni-mannheim.de