Privacy Policy
A. General Notes
We are very pleased about your interest in our website meingpt.com. Data protection is of particularly high importance to us. Use of the internet pages of meingpt.com is generally possible without any indication of personal data. However, if a data subject wishes to use special services of our company via our internet site, it may become necessary to process personal data. If the processing of personal data is required and there is no legal basis for such processing, we generally obtain the consent of the data subject.
The processing of personal data, for example the name, address, email address, or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation and in compliance with the applicable national data protection regulations for SelectCode GmbH. Through this privacy policy, our company aims to inform the public about the nature, scope, and purpose of the personal data we collect, use, and process. Furthermore, data subjects are informed of their rights through this privacy policy.
SelectCode GmbH, as the data controller, has implemented numerous technical and organizational measures to ensure a comprehensive protection of personal data processed through this website. Nevertheless, internet-based data transmissions may generally have security gaps, so an absolute protection cannot be guaranteed. For this reason, it is up to each data subject to transmit personal data to us through alternative means, such as by phone.
1. Name and address of the controller responsible for processing
Responsible within the meaning of the General Data Protection Regulation (GDPR), other applicable data protection laws in the Member States of the European Union, and other provisions with data protection character is:
SelectCode GmbH
Oskar-von-Miller-Straße 11
82008 Unterhaching
Germany
VAT ID: DE313955277
Represented by:
Florian Baader, Reiner Conrad
Telephone: + 49 89 541 986 46
Email: webmaster@selectcode.de
Website: meingpt.com
2. Name and address of the data protection officer
We have appointed an external data protection officer for our company.
heyData GmbH
Schützenstr. 5
10117 Berlin
Germany
E-Mail: support@heydata.eu
Website: www.heydata.eu
Our internal contact person for data protection is:
Stephan Le
Oskar-von-Miller-Straße 11
82008 Unterhaching
E-Mail: webmaster@selectcode.de
Any affected person can contact our data protection officer directly at any time with any questions or suggestions regarding data protection.
3. Definitions
The privacy policy of SelectCode GmbH is based on the terminology used by the European legislator when enacting the General Data Protection Regulation (GDPR). Our privacy policy is designed to be easily readable and understandable for both the public and our customers and business partners. To ensure this, we would like to explain the terminology used in advance. In this privacy policy, we use the following terms, among others:
a) Personal data
Personal data is any information that relates to an identified or identifiable natural person (hereinafter referred to as the "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
b) Affected person
A data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.
c) Processing
Processing is any operation or set of operations performed on personal data, whether automated or not, including collecting, capturing, organizing, structuring, storing, adapting or altering, retrieving, querying, using, disclosing by transmission, dissemination or otherwise making available, aligning or combining, restricting, deleting, or destroying.
d) Restriction of processing
Restriction of processing is the marking of stored personal data with the aim of restricting its future processing.
e) Profiling
Profiling is any form of automated processing of personal data that involves using this personal data to evaluate certain personal aspects related to an individual, particularly to analyze or predict aspects regarding work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or changes in location of that individual.
f) Pseudonymization
Pseudonymization is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately and is subject to technical and organizational measures that ensure that the personal data is not assigned to an identified or identifiable natural person.
g) Processor
The processor is a natural or legal person, authority, institution, or other entity that processes personal data on behalf of the controller.
h) Recipient
The recipient is a natural or legal person, authority, institution, or other entity to whom personal data is disclosed, regardless of whether they are a third party or not. However, authorities that may receive personal data in the context of a specific investigation under Union law or the law of the Member States are not considered recipients.
i) Third
A third party is a natural or legal person, authority, institution, or other entity other than the data subject, the controller, the processor, and the persons who are authorized to process personal data under the direct responsibility of the controller or the processor.
j) Consent
Consent is any declaration of will made by the data subject voluntarily for a specific case in an informed and unambiguous manner in the form of a statement or another clear confirmatory action, through which the data subject indicates that they agree to the processing of their personal data.
4. Legal basis for processing
Article 6(1)(a) of the GDPR serves as the legal basis for processing activities where we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, as is the case, for example, with processing operations necessary for the delivery of goods or the provision of other services or counter-performances, then the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations that are necessary for the implementation of pre-contractual measures, such as in cases of inquiries about our products or services. If our company is subject to a legal obligation that requires the processing of personal data, such as to fulfill tax obligations, the processing is based on Article 6(1)(c) of the GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case if a visitor were to be injured at our facility and, as a result, their name, age, health insurance data, or other vital information had to be disclosed to a doctor, a hospital, or other third parties. In this case, the processing would be based on Article 6(1)(d) of the GDPR. Ultimately, processing operations could be based on Article 6(1)(f) of the GDPR. This legal basis applies to processing operations that are not covered by any of the aforementioned legal bases if the processing is necessary for the purposes of legitimate interests pursued by our company or a third party, provided that the interests, fundamental rights, and freedoms of the data subject do not override those interests.
5. Rights of the data subject
a) Right to confirmation
Every affected person has the right granted by the European directives and regulations to request confirmation from the data controller as to whether personal data concerning them is being processed. If an affected person wishes to exercise this right to confirmation, they can contact a member of staff of the data controller at any time.
b) Right to access
Every person affected by the processing of personal data has the right granted by the European legislator to obtain from the controller of the processing, free of charge, at any time, information about the personal data concerning him or her and a copy of such information.
c) Right to rectification
Every person affected by the processing of personal data has the right granted by the European legislator to request the immediate correction of inaccurate personal data concerning them. Furthermore, the affected person has the right, taking into account the purposes of the processing, to request the completion of incomplete personal data — including by means of an additional declaration.
d) Right to deletion
Every person affected by the processing of personal data has the right granted by the European directives and regulations to request from the controller that the personal data concerning them be erased without delay, provided that one of the reasons stated in the GDPR applies and insofar as the processing is not necessary.
e) Right to restriction of processing
Every person affected by the processing of personal data has the right granted by the European legislator to request the restriction of processing from the controller, if one of the conditions mentioned in the GDPR is met.
f) Right to data portability
Every person affected by the processing of personal data has the right granted by the European legislator to receive the personal data concerning them, which they provided to a controller, in a structured, commonly used and machine-readable format.
g) Right of objection
Every individual affected by the processing of personal data has the right granted by the European Directive and Regulation to object at any time to the processing of personal data concerning them, on grounds relating to their particular situation, that is based on Article 6(1)(e) or (f) of the GDPR.
h) Automated decisions in individual cases including profiling
Every person affected by the processing of personal data has the right granted by the European legislator to not be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning them or similarly significantly affects them.
i) Right to withdraw consent to data protection
Every person affected by the processing of personal data has the right granted by the European directive and regulation to withdraw consent to the processing of personal data at any time.
B. Data processing on our website
1. Cookies
The websites of SelectCode GmbH use cookies. Cookies are text files that are stored and saved on a computer system via an internet browser. Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a string through which websites and servers can be assigned to the specific internet browser in which the cookie was stored. This enables the visited websites and servers to distinguish the individual browser of the affected person from other internet browsers that contain different cookies. A specific internet browser can be recognized and identified by the unique cookie ID. Currently, this website sets exclusively technically necessary cookies and our own first-party cookies, which we base on our legitimate interest in the technically error-free, secure and optimized provision of the site as well as in privacy-friendly reach and funnel analysis (Art. 6 para. 1 lit. f GDPR). These are in particular mg_vid (a pseudonymous analytics ID for recognizing returning visitors) and mg_known (which contains only the value "1" to recognize logged-in users, no personal data/PII). We do not currently set consent-requiring cookies (e.g., for marketing or from third parties). Should we use such technologies in the future, we will obtain your consent (Art. 6 para. 1 lit. a GDPR) in advance via a consent banner.
2. Cookie Consent
Because this website currently sets exclusively technically necessary and our own first-party cookies (see section 1) and does not store any consent-requiring cookies, a cookie/consent banner is currently not required. Should we use consent-requiring technologies in the future, we will obtain your consent in advance via a consent banner, document it in compliance with data protection law (legal basis Art. 6 (1) lit. a resp. sentence 1 lit. c GDPR) and allow you to revoke it at any time with effect for the future.
3. Collection of general data and information (Hosting & Server log files)
Our website is hosted and provided through a Content Delivery Network (CDN) by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. The website of SelectCode GmbH collects a range of general data and information with each access of the website by an affected person or an automated system. This general data and information is stored in the server's log files. The following can be collected: (1) the types and versions of browsers used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrer), (4) the subpages that are accessed via an accessing system on our website, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) other similar data and information that serve to avert dangers in the event of attacks on our information technology systems.
When using this general data and information, SelectCode GmbH does not draw conclusions about the affected person. Instead, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as the advertising for it, (3) ensure the permanent functionality of our information technology systems and the technology of our website, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack.
These anonymously collected data and information are therefore evaluated by SelectCode GmbH on the one hand statistically and further with the aim of increasing data protection and data security in our company. The processing takes place on the basis of our legitimate interest in a secure, high-performance, and reliable provision of our online offering in accordance with Art. 6 para. 1 lit. f GDPR. The transfer of data to the USA is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (DPF) of 10 July 2023; the European Commission's Standard Contractual Clauses additionally apply as a safeguard. We have also entered into a contract for order processing (AV contract) with Cloudflare.
4. Contact option via the website
Due to legal regulations, the website of SelectCode GmbH contains information that allows for quick electronic contact with our company, including a general address for so-called electronic mail (email address). If a data subject contacts the controller responsible for processing via email or through a contact form, the personal data transmitted by the data subject will be automatically stored. Such personal data provided voluntarily by a data subject to the controller responsible for processing will be stored for the purpose of processing or contacting the data subject. There will be no transfer of this personal data to third parties.
C. Detailed description of the services used and processes
Detailed description of the services and processes used
We use various services on our website to ensure functionality, analyze usage, improve our offerings, and carry out marketing measures. Below we provide detailed information about each individual service.
The services currently in use are based on our legitimate interest (Art. 6 para. 1 lit. f GDPR) or – for forms and communication – on the performance of a contract or pre-contractual measures (Art. 6 para. 1 lit. b GDPR). We do not currently use consent-requiring, technically non-necessary services. Should we do so in the future, their use will be based solely on your consent (Art. 6 para. 1 lit. a GDPR), which you can give via a consent banner and revoke at any time with effect for the future.
1. Consent Management
Consent Management (Cookie Banner)
Provider: SelectCode GmbH – consent is obtained via our own cookie/consent banner and documented in compliance with data protection regulations.
Purpose: Where we use consent-requiring cookies or technologies, we obtain and manage your consent for them in a data-protection-compliant manner. No such consent-requiring technologies are currently in use (see section B).
Processed Data: Date and time of the visit, device information, browser information, as well as your selected choice (consent data).
Legal Basis: The processing is necessary for the fulfillment of a legal obligation (Art. 6 para. 1 lit. c GDPR).
Third Country Transfer: The processing takes place exclusively within the European Union.
2. Hosting, CDN & Security
Cloudflare
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Purpose: Provision of a Content Delivery Network (CDN) for faster delivery of our website content and protection against cyber attacks (e.g., DDoS attacks).
Processed data: IP address, server log data (request details, timestamps), cryptographic signatures.
Legal basis: Our legitimate interest in providing a secure, performant, and reliable delivery of our website (Art. 6 para. 1 lit. f GDPR).
Third country transfer: The data is processed globally on Cloudflare's servers, including in the USA. The transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (DPF) of 10 July 2023; the European Commission's Standard Contractual Clauses additionally apply as a safeguard. We have concluded a data processing agreement with Cloudflare.
Cloudflare Turnstile
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Purpose: Protection of our contact form against spam and bots. Turnstile is data-minimizing and does not set classic tracking cookies.
Processed data: IP address, technical browser and device information, and a token generated by Cloudflare for verification.
Legal basis: Our legitimate interest in protecting the contact form against spam/bots and preventing abuse (Art. 6 para. 1 lit. f GDPR).
Third country transfer: The transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (DPF) of 10 July 2023; the European Commission's Standard Contractual Clauses additionally apply as a safeguard.
3. Analysis & Statistics
Plausible Analytics (self-hosted)
Provider: Self-hosted Plausible instance, operated by SelectCode GmbH on its own infrastructure at trends.selectcode.de. No external processor is used; SelectCode itself is the processing entity.
Purpose: Measurement and analysis of website usage in a privacy-friendly manner. Plausible is cookieless, does not use persistent identifiers, and does not collect personal identifiers. All data is aggregated and anonymized.
Processed data: URL of the visited page, HTTP referrer, browser type, operating system, device model, country of the visitor. No IP address is stored.
Legal basis: Our legitimate interest in statistical analysis to optimize our website, while not infringing on user privacy (Art. 6 para. 1 lit. f GDPR).
Transfer to third countries: No transfer to third countries takes place. Processing occurs exclusively on our own infrastructure in the European Union; there is no transfer to third parties.
First-Party Analytics (SelectCode)
Provider: SelectCode GmbH – our own server-side first-party tracking on our own infrastructure (internal "Apollo" backend). No external service provider is used.
Purpose: Reach and funnel analysis to improve our offering.
Processed data: Pseudonymized usage and event data (e.g., pages viewed, interactions). A first-party cookie mg_vid (pseudonymous visitor ID) is set, as well as, where applicable, mg_known (which contains only the value "1" to recognize logged-in users, no PII).
Legal basis: Our legitimate interest in the internal analysis and optimization of our services (Art. 6 para. 1 lit. f GDPR) or your consent (Art. 6 para. 1 lit. a GDPR) for non-essential analysis.
Transfer to third countries: No transfer to third parties and no transfer to third countries takes place.
4. Marketing & Lead Generation
Leadfeeder (cookieless)
Provider: Liidio Oy (Leadfeeder / Dealfront), Keskuskatu 6 E, 00100 Helsinki, Finland.
Purpose: Identification of companies (not individuals) that visit our website to support our B2B sales and marketing activities. The match is IP-based, against a database of company data.
Processed data: IP address, company name, visited pages, duration of stay, origin of the visitor. We run the service cookieless: the tracker cookie (_lfa) is technically suppressed, so no cookie is stored on your device.
Legal basis: Our legitimate interest in B2B lead generation and reach analysis (Art. 6 para. 1 lit. f GDPR). As no cookie is set, no consent under Section 25 TDDDG is required in this respect.
Third country transfer: The provider is Liidio Oy, based in Finland (EU); processing takes place primarily in the EU. Where the provider uses sub-processors to deliver the service, transfers to third countries may occur; these are safeguarded by the EU Commission's standard contractual clauses or – where applicable – the adequacy decision on the EU-US Data Privacy Framework.
Newsletter dispatch (Resend)
Provider: Resend – operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA; data processing in the EU region (Ireland, eu-west-1).
Purpose: Dispatch of our newsletter and of webinar invitations/confirmations to prospects who have registered for them.
Processed data: email address, name, company, time of registration, opening and click behaviour.
Legal basis: consent (Art. 6(1)(a) GDPR), obtained via double opt-in. You may withdraw at any time via the unsubscribe link in every email or by emailing datenschutz@meingpt.com.
Data residency: your data is processed exclusively in the EU (Ireland, eu-west-1); there is no transfer to the USA in this respect. As the provider has a US parent company, Resend is additionally certified under the EU-US Data Privacy Framework (DPF) and the EU Standard Contractual Clauses apply. A data processing agreement (Art. 28 GDPR) is in place with the provider.
Webinars
Purpose: Hosting online webinars and events for prospects.
Processed data: registration data (name, email, company), participation data, chat contributions during the webinar; if recorded, image and sound (only with separate consent). Platform: webinars are held via Google Meet (Google Ireland Limited) or Microsoft Teams (Microsoft Ireland Operations, Ltd.). Both providers have a US parent company; processing takes place primarily in EU data centres. Where data is transferred to the USA, it is safeguarded via the EU Standard Contractual Clauses or — where applicable — the adequacy decision for the EU-US Data Privacy Framework.
Legal basis: participation (Art. 6(1)(b) GDPR); recording only with separate consent (Art. 6(1)(a) GDPR). Participant data is deleted after 6 months, recordings after 3 months.
5. Embedded Content & Fonts
Fonts (self-hosted)
All fonts used on our website are self-hosted (via next/font, delivered locally on our own domain). There is NO data transfer to Google or gstatic.com and NO transfer to third countries.
6. Forms & Communication
Tally Forms
Provider: Tally BV, Belgium.
Purpose: Creation and embedding of online forms to capture user inquiries, registrations, or feedback.
Processed data: All data you enter into the form fields, as well as your IP address and browser data for spam prevention.
Legal basis: The processing is carried out to take steps at your request prior to entering into a contract or for the performance of a contract (Art. 6 para. 1 lit. b GDPR).
Transfer to third countries: Processing primarily takes place within the European Union.
Fillout
Provider: Fillout, Inc., USA.
Purpose: Creation and integration of interactive forms and surveys on our website.
Processed data: The data you enter into the form, IP address, device and browser information.
Legal basis: Your consent to participate in the survey or to submit the data (Art. 6 para. 1 lit. a GDPR) or to process your request (Art. 6 para. 1 lit. b GDPR).
Transfer to third countries: The data is processed in the USA. The transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (DPF) of 10 July 2023; the European Commission's Standard Contractual Clauses additionally apply as a safeguard.
7. Technical Functionality & Others
Stripe
Provider: Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, California, 94080, USA (hereinafter referred to as "Stripe"). For users in the European Economic Area (EEA), Switzerland, and the United Kingdom, however, the Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, is the primary responsible data controller.
Purpose: When you purchase a paid service on meingpt.com, we use Stripe's global payment gateway to securely and efficiently process the payment transaction. We chose Stripe because the service meets the highest security standards (PCI-DSS certification) and allows us to offer you a variety of payment methods worldwide without having to store sensitive credit card information ourselves.
Processed Data: To carry out the payment, the payment data you provide (e.g., cardholder name, email address, billing address, credit card number, expiration date, CVC code), information about your purchase (e.g., amount, date, currency), as well as data for transaction verification, will be transmitted directly to the responsible Stripe entity. Additionally, Stripe may collect further data for fraud prevention and identity verification, such as your IP address or device and browser information. Important note: We do not store your complete credit card data on our systems at any time.
Legal Basis: The transmission and processing of this data is carried out to fulfill the contract concluded with you and to implement the payment (Art. 6 para. 1 lit. b GDPR).
Third Country Transfer: As a global service provider, Stripe processes data in multiple countries, including the USA. The transfer of data from the EEA to the USA is secured through robust legal mechanisms. Stripe relies on its certification under the EU-U.S. Data Privacy Framework (DPF). Additionally, Standard Contractual Clauses (SCCs) of the EU Commission may also be used for security purposes. This ensures that your data is provided with a level of protection that is comparable to that of the GDPR, even when processed outside of Europe.
Further Information: You can view Stripe's privacy policy here: https://stripe.com/de/privacy.
8. Technical Functionality & Others
Sentry
Provider: Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Purpose: Real-time error and performance monitoring of our application. Sentry helps us quickly identify and fix technical errors (bugs).
Processed data: IP address, device and browser data, error reports (may potentially contain user-generated content that triggered the error).
Legal basis: Our legitimate interest in the technical stability, security, and optimization of our website (Art. 6 para. 1 lit. f GDPR).
Transfer to third countries: The data is processed in the USA. The transfer is based on the standard contractual clauses of the EU Commission. We have entered into a data processing agreement with Sentry.
D. Data processing on social media platforms
We are present on social media networks to introduce our organization and our services. The operators of these networks regularly process data of their users for advertising purposes. Among other things, they create user profiles based on their online behavior, which, for example, are used to display advertisements on the network's pages and elsewhere on the internet that align with the users' interests. To do this, the operators of the networks store information about the usage behavior in cookies on the users' computers. It is also not excluded that the operators merge this information with other data. Further information and guidance on how users can object to the processing by the site operators can be found in the privacy policies of the respective operators listed below. It may also be the case that the operators or their servers are located in non-EU countries, which means they process data there. This can pose risks for users, e.g., because the enforcement of their rights may be more difficult or government bodies may gain access to the data.
If users of the networks contact us through our profiles, we process the data provided to us to respond to the inquiries. This is our legitimate interest, so the legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR.
1. Meta (Instagram/Facebook)
We maintain a profile on Instagram. The operator is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy can be accessed here: https://privacycenter.instagram.com/policy/
SelectCode Instagram Account: https://www.instagram.com/selectcodesoftware
2. YouTube
We maintain a profile on YouTube. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The privacy policy can be accessed here: https://policies.google.com/privacy?hl=de.
myGPT YouTube account: https://www.youtube.com/channel/UCJ3nRHViG_puF_D49tx_kWQ
3. LinkedIn
We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy can be found here: https://www.linkedin.com/legal/privacy-policy?_l=de_DE. An option to object to data processing can be found through the ad settings: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
myGPT LinkedIn Account: https://www.linkedin.com/company/meingpt
a) Personal data
E. Final provisions
We are very pleased with your interest in our website meingpt.com. Data protection is of particularly high importance to us. The use of the websites of meingpt.com is generally possible without any indication of personal data. However, if a data subject wants to use special services of our company via our website, it may be necessary to process personal data. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain the consent of the data subject.
The processing of personal data, such as the name, address, email address, or telephone number of a data subject, is always in accordance with the General Data Protection Regulation and in compliance with the applicable national data protection regulations for SelectCode GmbH. Through this privacy policy, our company aims to inform the public about the nature, scope, and purpose of the personal data we collect, use, and process. Furthermore, data subjects are informed about their rights through this privacy policy.
SelectCode GmbH has implemented numerous technical and organizational measures as the controller responsible for processing to ensure the most complete protection possible of personal data processed through this website. Nevertheless, internet-based data transmissions may have security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us through alternative means, such as by phone.
1. Routine deletion and blocking of personal data
The data controller processes and stores personal data of the data subject only for the period necessary to achieve the storage purpose, or as provided by European directives and regulations or other legislation to which the data controller is subject. If the storage purpose ceases to exist or a storage period prescribed by European directives or other competent legislation expires, the personal data will be routinely blocked or deleted in accordance with the legal regulations.
2. Duration of storage of personal data
The criterion for the duration of the storage of personal data is the respective statutory retention period. After the expiration of the period, the corresponding data will be routinely deleted, provided they are no longer necessary for contract fulfillment or contract initiation.
In addition, the following applies: Prompts you entered via the AI functionality and the responses generated from them will be stored on our systems for a duration of [Example: 90 days] to allow you access to your conversation history. After this period expires, the contents will be automatically anonymized or deleted, unless there are legal retention obligations to the contrary.
The criterion for the duration of storage of personal data is the respective legal retention period. After the expiry of the period, the corresponding data will be routinely deleted, provided they are no longer necessary for the fulfillment of the contract or for initiating the contract.
Additionally, it applies: Prompts entered by you via the AI functionality and the responses generated from them will be stored on our systems for a duration of [Example: 90 days] to allow you access to your conversation history. After this period, the contents will be automatically anonymized or deleted, unless there are legal retention obligations to the contrary.
3. Legal or contractual regulations for providing personal data; Necessity for contract conclusion; Obligation of the data subject to provide personal data; possible consequences of non-provision
We inform you that the provision of personal data is partly legally required (e.g., tax regulations) or may also arise from contractual agreements (e.g., information about the contracting party). Sometimes, it may be necessary for a data subject to provide us with personal data in order to conclude a contract, which must then be processed by us. A failure to provide the personal data would result in the inability to conclude the contract with the data subject.
4. Existence of an automated decision-making process
As a responsible company, we refrain from automated decision-making or profiling.
5. Changes to this Privacy Policy
We reserve the right to change this privacy policy with effect for the future, especially in the event of a change in the legal situation, case law, or our business processes. An up-to-date version is available on our website at all times. We recommend that you visit this page regularly.
6. Questions and comments
If you have any questions or comments regarding this privacy policy, please feel free to contact us using the contact information provided in Section A.1.
Status of this privacy policy: July 2026