Who runs Engadin AI
The company
Section titled “The company”Engadin AI is built and operated by Wolf+Bär GmbH, a Swiss limited liability company based in Zürich and trading as SweetCode.
| Legal entity | Wolf+Bär GmbH |
| Registered office | Stampfenbachstrasse 32, 8001 Zürich, Switzerland |
| Commercial register | Canton of Zürich |
| Enterprise identification number (UID) | CHE-447.190.660 |
| Trading name | SweetCode |
| Contact | sweetcode.com/support |
| Imprint | sweetcode.com/imprint |
The registration is public and independent of anything written here: the number above resolves in Zefix, the Swiss federal commercial registry. Under the same entity, SweetCode has built and supported commercial software since 2013, and is a member of Swiss Made Software.
What “the operator” means in these pages
Section titled “What “the operator” means in these pages”The rest of this documentation says the operator of this installation rather than naming a company. That is deliberate: the software is multi-tenant and can be run by someone else for their own customers, and those pages have to stay true when it is.
On engadin.ai, the operator is Wolf+Bär GmbH. Wherever a page says to ask the operator — for a retention window, for a single lead to be deleted, for a zero-retention arrangement with the model vendor — that means sweetcode.com/support.
Who is responsible for what
Section titled “Who is responsible for what”- You are the controller for the visitors who talk to your agent. You put the assistant on your site, and you decide what happens with the conversations and leads it produces.
- Wolf+Bär GmbH is the processor, acting on your instructions.
- Cloudflare, the model vendor and Mailgun are sub-processors. They are named, with what each one does and where, in security and privacy.
That split is why the privacy notice on your own site is yours to write. What we owe you is the ability to answer a visitor who asks what you hold, which the export and delete functions provide.
Where your data is kept
Section titled “Where your data is kept”The short version, in full under where your data is processed:
- Conversations, messages, leads and visitor attachments are stored in the
European Union, under Cloudflare’s
eujurisdiction. That is a contractual restriction fixed when the store is created, not a routing preference, and it cannot be loosened afterwards. - The search index holds embeddings and an agent id. No readable text, so there is nothing in it to place.
- Answers are generated in the United States by Anthropic or OpenAI, under standard contractual clauses and the EU-US Data Privacy Framework. An agent that cannot use a United States processor can be pointed at Cloudflare’s own models instead.
- No vendor in the chain trains a model on your conversations, and each says so in writing.
Documents you can ask for
Section titled “Documents you can ask for”- A data processing agreement between your company and Wolf+Bär GmbH.
- A zero-retention arrangement with the model vendor, where nothing is written down on their side at all. Ask whether your workspace runs under one.
- A fixed retention window applied to your workspace, if your policy sets one.
- Cloudflare’s DPA and current sub-processor list, which are public on its GDPR trust hub, alongside its verification under the EU Cloud Code of Conduct.
Reporting a security issue
Section titled “Reporting a security issue”Report it to sweetcode.com/support rather than filing it publicly, and give us a way to reach you back. Please do not test against another workspace’s agent: everything is scoped per workspace, and a report is more useful than a demonstration.