Privacy Policy

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data by which you can be personally identified. For detailed information on the subject of data protection, please refer to our privacy policy set out below this text.

Data Collection on Our Website

Who is responsible for the data collection on this website?

The data processing on this website is carried out by the website operator. Their contact details can be found in the legal notice of this website.

How do we collect your data?

Your data is collected, on the one hand, when you provide it to us. This may, for example, be data that you enter into a contact form.

Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of the page access). This data is collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure the error-free provision of the website. Other data may be used to analyse your user behaviour.

What rights do you have regarding your data?

You have the right at any time to receive free information about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction, blocking or deletion of this data. For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time at the address given in the legal notice. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

2. General Information and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We point out that data transmission over the internet (e.g. when communicating by e-mail) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Note on the Responsible Body

The body responsible for data processing on this website is:

Joachim Dreistein Medienentwicklung
Bolkerstraße 14
40213 Düsseldorf

Telephone: +49
info

The responsible body is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, e-mail addresses or similar).

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can withdraw consent already given at any time. An informal notification by e-mail to us is sufficient for this. The lawfulness of the data processing carried out up until the withdrawal remains unaffected by the withdrawal.

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of breaches of data protection law, you have the right to lodge a complaint with the competent supervisory authority. For our company, this is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf

Telephone: 0211/38424-0
E-mail: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de

A complete list of all data protection officers in Germany can be found here: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Information, Blocking, Deletion

Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to correction, blocking or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time at the address given in the legal notice.

Objection to Advertising E-mails

The use of contact data published within the framework of the legal notice obligation to send unsolicited advertising and information materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example through spam e-mails.

3. Data Collection on Our Website

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • operating system used
  • Referrer URL (the previously visited page)
  • Host name of the accessing computer
  • Time of the server request
  • IP address (in anonymised form)

The collection of this data is necessary to ensure the stable and secure provision of the website as well as to detect and prevent misuse. This data is not merged with other data sources. The legal basis for the processing is Art. 6 (1) (f) GDPR (legitimate interest in the technical provision and security of the website). Storage period: The data is automatically deleted after 7 days, unless statutory retention obligations prevent this.

Contact Form

If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We do not pass on this data without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR where your enquiry relates to the performance of a contract or is necessary for pre-contractual measures. In all other cases, the processing is based on our legitimate interest in handling the enquiries addressed to us effectively (Art. 6 (1) (f) GDPR). You may object to processing based on legitimate interest at any time; an informal e-mail to us is sufficient.

The data you enter into the contact form remains with us until you request its deletion, object to the processing, or the purpose for storing the data ceases to apply (e.g. after your enquiry has been fully processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.

Web analytics with Matomo

We use the open-source web analytics service Matomo in a self-hosted installation on our own server. Matomo sets no cookies; IP addresses are shortened before storage and can no longer be attributed to a person by us. The data never leaves our server. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the statistical analysis of website usage).

Contact form spam protection (Cloudflare Turnstile)

To protect against automated submissions, our contact page uses Cloudflare Turnstile (Cloudflare, Inc., USA). Your IP address is transmitted to Cloudflare and checked; as a rule, you will not have to solve a picture puzzle. Cloudflare is certified under the EU-US Data Privacy Framework. The legal basis is Art. 6 (1) (f) GDPR (protection against spam and abuse).

4. AI Chat and Voice Features

AI chat

Our pages offer an AI assistant that answers questions from the content of this website and identifies itself to you as an AI. Your question and the matching text passages from our website are transmitted to Mistral AI (France, EU servers); a data processing agreement pursuant to Art. 28 GDPR is in place with Mistral. Only in the comparison chats on our RAG comparison page are questions additionally transmitted to the US providers disclosed there (OpenAI, Anthropic, Google); these transfers are based on EU standard contractual clauses or certification under the EU-US Data Privacy Framework. The legal basis is Art. 6 (1) (f) GDPR; using the chat is voluntary.

Voice chat

If you use voice input, your recording is transmitted to Mistral AI (France) for transcription and processed within the EU; the spoken answer is also generated by Mistral AI. No audio data is transmitted unless you actively use the microphone.

File and photo upload in the chat

In the chat you can voluntarily attach a file (photo or PDF) to ask questions about its content. Attached images are transmitted to Mistral AI (France, EU servers) for description and text recognition; for PDF files, we extract the text on our own server. The resulting text is transmitted to Mistral AI for answering – just like your question. The file itself is not stored: it is kept in memory only for the duration of processing; only the file name, file type and file size remain in the chat log. Please do not upload files containing sensitive data. The legal basis is Art. 6 (1) (f) GDPR; use is voluntary.

Browser storage (chat)

So that a conversation you have started does not break off when you move to another page, the chat stores two things in your browser's memory (sessionStorage): the conversation so far and – if you switched languages within the chat – the chosen conversation language. Neither is stored until you actually use the chat; if you only read, nothing is stored. The data stays exclusively on your device, is not transmitted to anyone, and is deleted automatically when you close the browser tab. You can remove it yourself at any time using the “New conversation” button in the chat. There is no recognition across sessions and no cookies are set. This storage is strictly necessary for the function you requested (Section 25 (2) no. 2 TDDDG) and therefore does not require consent – which is why this website has no cookie banner.

Chat log

For quality assurance and to identify knowledge gaps, we log questions and answers together with technical values (language, response time, token count). Your IP address is never stored in plain text, only as a keyed check value (HMAC) that cannot be attributed to an IP address without the key we keep separately. The legal basis is our legitimate interest in an accurate and helpful assistant and in preventing abuse (Art. 6 (1) (f) GDPR); using the chat is voluntary, and you may object to the processing at any time. Logs are deleted after 90 days.

5. Free Product Demo (dAI Pro)

On request we set up a free demo of our software "dAI Pro", limited to seven days: we read up to 50 pages of your website (text only) and provide an AI assistant you can ask about that content.

What data we process

When you order: the website addresses you provide, your e-mail address, optionally your name and company, the time of your request and your IP address in pseudonymised form (as a keyed check value, HMAC). We also record your acceptance of the data processing agreement with its time and text version.

While the demo runs: the content read from your website, your test questions and the assistant's answers (conversation log with pseudonymised IP address) and the access credentials created for you. If you use voice input: your voice recording for the duration of its conversion to text.

To prevent abuse: a bot check in the order form (Cloudflare Turnstile, see below) and a rate limit per sender and domain based on this check value.

Purposes and legal bases

  • Setting up and running the demo, including the ready-mail with your credentials and the deletion confirmation: Art. 6(1)(b) GDPR (pre-contractual measures at your request).
  • Processing your website content: here we act as your processor on the basis of the data processing agreement under Art. 28 GDPR concluded when ordering.
  • Abuse and bot protection, rate limiting: Art. 6(1)(f) GDPR (legitimate interest in protecting a freely accessible, cost-intensive feature from automated abuse).
  • Proof of DPA acceptance: Art. 6(1)(c) in conjunction with Art. 5(2) and Art. 7(1) GDPR (accountability).
  • Notifying the operator about new demos (internal e-mail): Art. 6(1)(f) GDPR (operating and supporting the service).

Retention

The demo and all associated data – knowledge base, files, conversation logs, usage data, credentials and the contact details provided when ordering – are deleted automatically and completely no later than seven days after setup; earlier on request (an informal e-mail suffices). You receive a confirmation of the deletion by e-mail. The record of your acceptance of the data processing agreement is then kept without personal reference (anonymised). We do not store voice recordings ourselves; for processing by the speech recognition provider see below.

Recipients

  • IONOS SE, Montabaur (Germany): hosting of our servers in the Niederlauterbach data centre (France).
  • Hetzner Online GmbH, Gunzenhausen (Germany): storage for the encrypted backup copies of our server in the Falkenstein data centre; backups are encrypted before transfer, Hetzner holds no key.
  • Mistral AI SAS, Paris (France): AI language model, embeddings, speech output and – only if you use voice input – the conversion of spoken questions to text (processed in the EU). For demos we technically enforce this EU provider only; under its terms, API inputs are not used for training.
  • Cloudflare, Inc. (USA/EU): "Turnstile" bot check in the order form. Your IP address is transmitted to Cloudflare; the legal basis is Art. 6(1)(f) GDPR (abuse protection), transfers to the USA rely on the EU-US Data Privacy Framework.

Demo interface

For the duration of the demo you receive personal credentials for a test interface by e-mail. Test conversations held there are logged as described above. The interface is read-only; no permanent settings or accounts are created beyond the demo. The chat window's conversation history itself is kept only in your browser (sessionStorage) and reaches our servers only as the log described above.

No obligation to provide data

Providing your data is voluntary; without a website address and e-mail address, however, we cannot set up the demo (Art. 13(2)(e) GDPR).

6. Customer and Prospect Data

Enquiries, quotations, contracts and invoicing

If you request a quotation, commission us or order a dAI Pro demo, we process the information required for this: name, company, address, e-mail address, telephone number, quotation, order and invoicing data, and our correspondence with you. The purpose is to prepare quotations, to perform and invoice the contract and to support you during its term. The legal basis is Art. 6 (1) (b) GDPR (contract and pre-contractual measures); for retaining invoices, accounting records and business letters it is Art. 6 (1) (c) GDPR in conjunction with Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO).

Recipients of this data are, where required for bookkeeping and payments, our tax advisor and our bank, as well as our e-mail provider IONOS SE (Montabaur) for correspondence. No data is transferred to countries outside the EU.

We store the data for the duration of the business relationship and beyond that for as long as statutory retention periods apply (six years for business letters, eight years for accounting records, ten years for books and annual accounts). Enquiries from prospects that are not pursued further are deleted as soon as they are no longer required for contract initiation or legal defence, and at the latest after three years, unless a statutory retention obligation applies.

dAI Pro customer instances

For customers using dAI Pro as an instance operated by us, we additionally process the user accounts of the administrators named by the customer, operating and remote-maintenance logs, and usage data for invoicing (Art. 6 (1) (b) GDPR). The data the customer processes in its instance – the content of its website and documents and the chats of its website visitors – we process exclusively as a processor under Art. 28 GDPR on the basis of the contract concluded with the customer; the controller for this data is the respective customer.