Skip to content

Privacy Notice

Privacy notice pursuant to Art. 13, 14 GDPR regarding the use of the service maKI (LLM proxy of Universität Mannheim).

The following describes which personal data we process for which purposes, on what legal basis, for how long we retain it, to whom it may be disclosed, and which rights you can exercise.

Controller:
Universität Mannheim
Schloss
68161 Mannheim
Germany
Email: rektor@uni-mannheim.de

Operating unit:
Universitätsrechenzentrum (URZ)
Universität Mannheim
L 15, 16
68131 Mannheim, Germany

Data Protection Officer:
Jan Morgenstern
Attorney and Specialist Lawyer for IT Law
Johannesstraße 30, 67346 Speyer, Germany
Email: datenschutzbeauftragter@uni-mannheim.de

Service description and purpose of processing

Section titled “Service description and purpose of processing”

maKI is an internal LLM proxy service based on LiteLLM. It provides staff of Universität Mannheim with API access to locally hosted language models.

Universität Mannheim collects and processes your personal data in order to:

  • provide LLM inference for work-related purposes
  • meter usage and plan capacity
  • control access via API keys
  • communicate with users for operational purposes (maintenance announcements, outage notifications)

An API key is required to use the service. Without an API key, access is not possible. There is no statutory obligation to provide personal data; no disadvantages arise from non-provision other than the inability to use the service.

Data categoryExamples
API key assignmentKey name, assigned person or team, email address
Usage dataTimestamp, model used, token count, cost per request
Monthly aggregatesToken totals and costs per key, model, and month
Access logsIP address, timestamp, requested path, HTTP status code

The service distinguishes three key types:

  • Personal keys — assigned to an individual person. Usage data can be indirectly attributed to that person via the key.
  • Service keys — assigned to an application or team, with no reference to an individual. Usage data cannot be used to infer the behavior of individual employees.
  • Batch keys — for low-priority background workloads, also assigned to an application or team with no reference to an individual.
  • No storage of prompts or model responses. The contents of your requests and generated responses are not logged.
  • No automated decision-making within the meaning of Art. 22 GDPR.

Usage data is collected exclusively for capacity planning, cost allocation, and technical operations. It is not used for monitoring the behavior or performance of employees.

The processing of personal data by Universität Mannheim is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Art. 6(1)(e) GDPR in conjunction with Art. 6(3) GDPR and § 4 of the Baden-Württemberg State Data Protection Act [LDSG BW]).

Specifically, the provision of maKI is based on the university’s statutory task of providing IT infrastructure for research, teaching, and administration.

Data is collected exclusively directly from the data subjects — when applying for an API key (name, work email address) and when using the service (usage and access logs).

Your personal data is not transferred to third parties. All processing takes place on university-owned infrastructure at the Mannheim site.

No data is transferred to external service providers or to third countries. All models made available to end users run locally on GPU infrastructure at Universität Mannheim. No data processing agreement with external providers is in place.

In addition, in accordance with archival law, records must be offered to the university archive before deletion; the archive decides on whether to take over records.

Data typeRetention period
Detailed usage data12 months, then automatically aggregated into monthly totals
Monthly aggregatesIndefinite (no personal reference after aggregation)
API key assignmentUntil deactivation + 12 months
Access logs7 days (automatic rotation)

You have the right:

  • pursuant to Art. 15 GDPR to request access to the personal data we process about you
  • pursuant to Art. 16 GDPR to request the rectification of inaccurate or completion of incomplete personal data stored about you
  • pursuant to Art. 17 GDPR to request the erasure of personal data stored about you, where no legal retention obligation exists
  • pursuant to Art. 18 GDPR to request the restriction of processing of your personal data
  • pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority

To exercise your rights as a data subject, please contact:
Email: anfrage.datenschutz@uni-mannheim.de

Supervisory authority:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

Where your personal data is processed on the basis of Art. 6(1)(e) GDPR (processing in the public interest), you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data on grounds relating to your particular situation.

To exercise your right to object, a simple email is sufficient:
anfrage.datenschutz@uni-mannheim.de

maKI is a pure API service with no end-user web interface. The API does not set any cookies. The documentation site at maki.uni-mannheim.de/docs also does not set cookies and does not embed any external services, CDNs, tracking or analytics tools. All resources (fonts, stylesheets, scripts) are served from university-owned infrastructure.

  • Encryption of all connections (TLS)
  • Network segmentation (no direct internet access for backend systems)
  • Access exclusively via API keys
  • Regular backups with restore validation
  • Monitoring and alerting

In operation, an optional guardrail can be enabled that screens incoming requests with a locally hosted classification model before the main model call, in order to detect requests for personal data of third parties. This screening runs exclusively on university-owned infrastructure; request contents are not stored. The guardrail is not enabled by default and can be activated per key or per model.

For questions about data protection for this service, contact:
Philipp Hematty
Email: philipp.hematty@uni-mannheim.de

Or the Data Protection Service of Universität Mannheim:
Email: anfrage.datenschutz@uni-mannheim.de