Last updated: 4 October 2026
Privacy policy
This is a translation for information only. The German version is legally binding and prevails in case of any discrepancy: Datenschutzerklärung (in German).
This website does not set any cookies. Whether we may count visits is your decision in the consent window shown on your first visit; without your consent, nothing is counted. As long as you are only reading and have not agreed to visitor counting, nothing is loaded from third-party servers. Only when you start using the contact form is Cloudflare’s security check added; this is described in detail below. The chatbot you can try out here runs on our own server. The chat window is loaded on every page; a conversation only begins when you type something into it. The consent window only asks about this one thing; there is nothing else to consent to.
Personal data is therefore only processed on this website in eight places: in our host’s logs when you visit the site; in the chat, when you type something into it; in the demo shop, which creates a demo business of your own when you open it; when you fill in and submit the contact form; when you request the free trial; when you book a plan via Stripe; in visitor counting, if you have agreed to it in the banner; and in your email, when you write to us. All of this is described in detail below.
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR, in German: Datenschutz-Grundverordnung, DSGVO) is:
Owner: Maximilian Bertsch
c/o Online-Impressum #10217
Europaring 90
53757 Sankt Augustin
Germany
Email: kontakt@veradicta.com
For all questions about data protection and the exercise of your rights, you can reach us at this address.
We have not appointed a data protection officer; we are not legally obliged to do so.
2. When you visit this site
Our website is hosted on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you visit the site, your browser requests the page content from Cloudflare. In doing so, Cloudflare processes technical data that your browser transmits automatically:
- the IP address of your device
- the date and time of the visit
- the address requested
- information about your browser and operating system
- the previously visited page, if your browser sends it
- the language setting
This processing is technically necessary, because nobody can send you a website without your device’s IP address. The legal basis is our legitimate interest in providing the site in a technically error-free and secure manner pursuant to Article 6(1)(f) GDPR.
We do not operate a server of our own for this website and do not keep any logs of our own. We do not see this data and do not analyse it. Cloudflare does not specify a fixed retention period but bases it on operational and security purposes; details can be found in Cloudflare’s privacy policy.
Cloudflare acts for us as a processor pursuant to Article 28 GDPR. The data may be transferred to the USA in the process. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework; there is therefore an adequacy decision of the European Commission pursuant to Article 45 GDPR for the transfer. In addition, Cloudflare has agreed the standard contractual clauses of the European Commission with us.
3. No cookies, counting only with your consent
This website does not set any cookies and does not store any identifier on your device while you are reading. Your browser’s local storage contains only your answer in the consent window on visitor counting (yes or no, with the date), for 365 days; after that we ask again. Anyone who has switched off counting permanently for their device (see the ‘Visitor counting’ section) also has this opt-out note there, without an expiry date and without an identifier. None of this leaves your device.
The chat window also remembers in your browser’s session storage whether you have dismissed its small speech bubble, so that it does not pop up again on every page. The same applies if you make the window wider or leave it open and move to another page: this is also stored there so that it stays as you set it when you change pages. These are individual characters without an identifier, and they disappear as soon as you close the tab.
If you send a message in the chat window, it additionally stores a random conversation identifier there, together with the time of your last message, so that your conversation does not start again when you move to another page. It is valid until 30 minutes after your last message, also disappears with the tab and is not used to recognise you on a later visit.
So that the window can show you the conversation again after you change pages, the conversation text so far is also stored there, at most the last 40 messages and 60,000 characters. It belongs to the same identifier: once that is no longer valid, the text is discarded, and when you close the tab it disappears like everything else in session storage. The same text is in any case held on our server until it is deleted after 30 days at the latest.
Everything the chat window stores in this way implements a function that you requested by opening the window or by sending your message, and is strictly necessary for that purpose (§ 25(2) no. 2 TDDDG). We do not need consent for this; when you close the tab, all of it is gone.
We count how often the site is visited, but only if you have agreed to this in the consent window; without consent, the counting script does not load. Even then, this happens without cookies and without recognising you. How this works, what data is involved and how you can withdraw your consent is explained in the ‘Visitor counting’ section below.
No content from third-party providers is embedded: no maps, no videos, no social media buttons, no advertising networks. The fonts used (Geist and Archivo) are also delivered with the site and are not retrieved from a third party. Viewing this site therefore does not create a connection to Google, Meta or any other provider. The only thing loaded is the chatbot from our own server. What happens in that case is described in the next section.
One exception begins only with your own action: as soon as you start using the contact form, your browser loads Cloudflare’s security check. Anyone who only reads the site is not affected. What is transmitted in the process is described below in the section on the contact form.
There is therefore a consent banner only for visitor counting. Everything else on this site works without consent.
4. Visitor counting
We would like to know whether this site is visited, which pages are read and whether it loads quickly. For this we use Cloudflare Web Analytics, a service of Cloudflare, Inc., which also delivers the site (see above). This only happens if you have clicked ‘Accept all’ in the consent window or have switched on statistics under ‘Settings’. Only then does your browser load a small script from Cloudflare, which reports the following:
- the address requested and the page you came from, if your browser sends it
- browser, operating system and device type (computer, tablet or mobile phone)
- the country, derived from the IP address
- measurements of the page’s loading time, as determined by your browser itself
Your device’s IP address inevitably reaches Cloudflare in the process, because no connection is possible without it. Cloudflare derives only the country from it and then discards the address in the nearest data centre without storing it. The script does not set any cookies, does not store anything in your browser’s storage and does not create a fingerprint of your browser or device. We can therefore recognise neither you nor your visit, not even on a second visit.
We see only totals: how many views a page had, from which countries, with which browsers, and how long it took to load on average. Cloudflare keeps the individual reports for seven days; after that only aggregated figures remain. This is different from the host’s logs described in the section above, which we do not see.
The legal basis is your consent (Article 6(1)(a) GDPR and § 25(1) TDDDG). It is voluntary: anyone who declines or leaves the box unanswered is not counted and can use the site in exactly the same way. Cloudflare acts as our processor pursuant to Article 28 GDPR; for the possible transfer to the USA, what is said above about visiting the site applies.
Your browser remembers your answer in its local storage for 365 days so that the box does not appear again on every visit. Only ‘yes’ or ‘no’ and the date are stored, no identifier, and the answer is not transmitted to anyone. Anyone who wishes to switch off counting permanently for their device can visit veradicta.com/?zaehlung=aus once; local storage then additionally holds an opt-out note without an expiry date, also without an identifier, and the counting script no longer loads on that device. This can be undone with veradicta.com/?zaehlung=an.
You can withdraw your consent at any time: the ‘Privacy settings’ link in the footer of every page reopens the window; switching off statistics and clicking ‘Save choice’ ends counting from that moment. This does not affect the lawfulness of the counting carried out up to that point (Article 7(3) GDPR). What was counted up to then can no longer be attributed to you, because no identifier was ever created.
5. The chat demo on this site
On this site you can try out our chatbot. It is the same product that we offer, and it runs on our own server at bot.veradicta.com.
The chat window is loaded on every page as soon as the page itself has finished loading. No click or scrolling is needed for this. In the process, your browser connects to our server and asks which colour and which icon the window should have. This generates only the technical connection data described further down in this section. No other information about you is collected, and a conversation only begins when you type something into the window.
As soon as you send a message, we process the content of that message and your IP address. We pass the message on to Anthropic, the provider of the AI language model we use, so that a reply can be generated. Your IP address is not sent along with it. It is used solely to limit excessive use and is not stored permanently.
You can attach a photo to a message. The image is stored unchanged; if it contains capture data such as the location, this data remains in it. The image is not passed on to the AI language model; only a note that one is attached is passed on. It is deleted together with the conversation, at the latest after 30 days. Please do not attach any images that you would not want to entrust to us.
The legal basis is our legitimate interest in demonstrating our product to you and protecting it against misuse, pursuant to Article 6(1)(f) GDPR. Using the chat is voluntary; the site can be used in full without it.
Conversations are deleted at the latest after 30 days. Please do not write anything in the chat that you would not want to entrust to us, in particular no health data, login credentials or information about other people.
Our server is operated by Hetzner Online GmbH in its Nuremberg data centre. Traffic to it is routed via Cloudflare, Inc. (for the address, see section 2). Both act for us as processors pursuant to Article 28 GDPR. Our server’s access log does not record your IP address but Cloudflare’s, together with the time, the file requested and the information sent by your browser; this log serves operations and the defence against attacks and is deleted after 15 days at the latest. We hold your own IP address only in working memory in order to limit the number of requests; it is discarded at the latest 65 minutes after your last request and is not written to our database.
Your messages are not used to train AI models, not even by Anthropic.
Anthropic PBC is based in the USA. Processing takes place on the basis of a data processing agreement pursuant to Article 28 GDPR. For the transfer to the USA, the standard contractual clauses of the European Commission pursuant to Article 46(2)(c) GDPR have been agreed; they form part of Anthropic’s Data Processing Addendum.
6. The demo shop for trying things out
At veradicta.com/demo/werkzeughaus there is a fictitious tool retailer. The business, its products and its prices are made up; there is nothing to buy there and no ordering. The page exists to show our chatbot working as it would on a real customer’s site.
As soon as you open this page, we create a demo business of your own for you. This is a copy of the fictitious tool retailer with its catalogue and its texts, and for the duration of your visit it belongs only to you. That way nobody else sees what you write, and you do not see what others write. Initially, no information about you is generated, only this copy and your IP address, which we use to limit the number of copies per connection; for this purpose it is held only in working memory and is not stored.
We store the identifier of your demo business in your browser’s session storage so that you keep the same one as you click through the shop. It disappears as soon as you close the tab, is not sent to any other server and is not used to recognise you. It implements a function that you requested by opening the page and is strictly necessary for that purpose (§ 25(2) no. 2 TDDDG, the German Telecommunications Digital Services Data Protection Act).
If you write to the bot, the same applies as for the chat on our other pages: we process the content of your message, pass it on to Anthropic to generate a reply and use your IP address only to limit excessive use. Six messages are possible in one conversation; after that the bot no longer replies.
During the conversation the bot may ask you for your name and a way to contact you, for example if you ask for a call back, and creates an enquiry from this in your demo business. The tool retailer is fictitious, so nobody will call you back. Please do not enter any information here that you would not want to entrust to us.
Your demo business, with everything in it, is deleted completely at the latest twenty-four hours after it was created: the conversation, the messages, any enquiry and the access to it. This happens automatically and without any action on anyone’s part.
Using the button ‘Ins Kundenportal sehen’ (‘View in the customer portal’) you can look at your demo business in our customer portal. One click logs you in there without a password; for this we set a session cookie on bot.veradicta.com that carries only this login and is deleted together with the demo business. You see only your own data there. If you were logged in to an account of your own in this browser, you will be logged out of it; the page before the portal points this out to you.
The legal basis is our legitimate interest in demonstrating our product and protecting it against misuse, pursuant to Article 6(1)(f) GDPR. Use is voluntary; the shop can be viewed in full without writing to the bot.
7. The contact form
When you fill in and submit the form on this site, your entries are transmitted to us: your email address and your message, plus your name and your company if you have filled in these two optional fields. For technical reasons, your browser also transmits its IP address. We need your email address and message in order to reply to you; without them we cannot deal with your enquiry. Name and company are optional, and you will not suffer any disadvantage if you leave them out.
We process this information exclusively in order to answer your enquiry. The legal basis is Article 6(1)(b) GDPR if your enquiry is aimed at a contract with us, and otherwise our legitimate interest in answering enquiries pursuant to Article 6(1)(f) GDPR.
Sending is handled for us by a small program at Cloudflare, Inc. (for the address, see section 2), which forwards your entries directly as an email to the mailboxes of the two people who deal with enquiries at our company. These mailboxes are hosted by 1&1 Mail & Media GmbH, Elgendorfer Str. 57, 56410 Montabaur, Germany (GMX) and by Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); Google may also process your message on servers outside the EU. The program does not create its own copy of your message. To prevent mass submissions, it counts how many enquiries come from the same IP address; for this, your IP address is held at Cloudflare for no more than thirty minutes, after which the entry expires automatically. If delivery fails, this is logged so that we notice; this log contains only our own addresses and the error, not your message. Cloudflare also acts as a processor pursuant to Article 28 GDPR for this purpose, under the same conditions as described in section 2.
In addition, this program passes your entries on to our own server (Hetzner Online GmbH, Nuremberg data centre), where they appear in our list of enquiries so that no enquiry is overlooked. We delete this entry at the latest twelve months after the last contact, and earlier if you object.
The form contains a field that is invisible to you and that only automated programs fill in. If it has been filled in, we discard the enquiry immediately. This serves solely to fend off mass submissions; it does not allow any conclusions to be drawn about you.
Before your enquiry is sent, a security check (‘Cloudflare Turnstile’) verifies that it comes from a human. This check is only loaded when you click on or tab into the form. Anyone who only reads the site is not affected. In the process, your browser retrieves a script from challenges.cloudflare.com and transmits its IP address and technical information about your device and browser to Cloudflare, Inc. (for the address, see section 2). From this, Cloudflare recognises whether the request is automated. The legal basis is our legitimate interest in protecting our mailboxes from mass automated submissions, Article 6(1)(f) GDPR; consent is not required, because the check is strictly necessary for the sending you have requested. Without a passed check, we do not accept the enquiry via the form; you can still email us instead.
What exactly Cloudflare processes during this check is described by the provider itself in the privacy policy for Turnstile.
Cloudflare also acts as a processor pursuant to Article 28 GDPR for this check, under the same conditions as described in section 2, including the possible transfer to the USA on the basis of the adequacy decision and the standard contractual clauses agreed in addition. When checking the result, our sending program transmits your IP address to Cloudflare once more so that the check can be matched to the same request. The check result can be used only once and expires after a short time; we do not store it and do not keep a list of checked requests. Cloudflare does not specify a fixed period for how long it keeps the information involved, but bases it on operational and security purposes; for Turnstile, Cloudflare expressly undertakes not to build advertising profiles from it.
Should sending ever fail, the site offers you the option of using your device’s email program instead. What happens to your message once it is in our mailbox is described in the next section.
8. If you request a quote for the Ultimate plan
On the page veradicta.com/en/quote you can request a quote for our Ultimate plan. Because we calculate the price of this plan individually for each business, we ask for more information there than in the contact form. Three details are mandatory: your email address, the address of your website and the expected number of messages per month, the latter selected from ranges.
The following are optional: whether you run an online shop with a product catalogue and roughly how many items it has, the languages you would like, whether you need a live chat with your own staff and how many that would be, whether you would like appointment booking and with which system, any special retention periods, your name as contact person, your telephone number and a free-text message. This information serves solely to calculate a quote for you that is not guesswork.
For the way your entries reach us, what is said above about the contact form applies, including the security check and the entry in our list of enquiries. The legal basis is Article 6(1)(b) GDPR, because the information serves to prepare a contract that you yourself have enquired about.
9. If you request the free trial
On the page veradicta.com/en/free-trial you can try out our chatbot free of charge for fourteen days on your own website. For this we ask for the name of your business, the address of your website, your name and your email address; telephone number, preferred plan and a message are optional. For the way your entries reach us, what is said above about the contact form applies, including the security check and the entry in our list of enquiries.
Setup then runs on our server without any action on our part (Hetzner Online GmbH, Nuremberg data centre, see the section on the customer portal): your details are used to create a customer record and an account for the customer portal, whose username is your email address. You set a password yourself via a link that we send you by email; it is valid for seven days and can be used only once. We also store the name of your business, your website, your name, your email address, your telephone number and your message where provided, the chosen plan and the last day of the trial period.
So that the bot knows your business from the start, our server retrieves the publicly accessible pages of your website, at most forty, and stores their text as your bot’s knowledge. It reads only the website you have specified, and only pages that any visitor can see without logging in. You can see what it has stored in the portal under ‘Wissen’ (‘Knowledge’) and can switch off or delete each page individually. If your website contains personal data, such as the names of your staff or your legal notice, this data is thereby also contained in your bot’s knowledge; you are responsible for this as operator of the website, and we process it on your behalf pursuant to Article 28 GDPR, as described in the section on the customer portal.
You will receive three emails from us: a confirmation straight away, within one hour the line of code for your website together with the link for your password, and on the day after the trial period ends a message asking for your feedback and showing the way to our plans. They are sent via the email delivery service Brevo, under the conditions set out in the section on the customer portal. Whether we contact you beyond that is decided by a human; you can object to this at any time.
The legal basis is Article 6(1)(b) GDPR: the trial period is a step prior to a possible contract, taken at your own request. Without the business, website, name and email address we cannot set it up; the other details are optional, and you will not suffer any disadvantage if you leave them out.
The trial period ends automatically after fourteen days; on the following day we switch the bot off and it no longer appears on your website. Your knowledge, your settings and your account then remain for a further thirty days so that you can continue without loss if you book a plan; after that we delete them. If you never open the link for your password, we end the access one week after the end of the trial period and likewise delete everything thirty days later. Your enquiry itself remains in our list of enquiries for as long as described above for the contact form.
The feedback form after the trial period is optional; any question may be left blank. What you enter there is stored together with the name of your business for twelve months so that we can learn from it, and is then deleted. Any rating you give there has no consequences for you.
10. If you book a plan
The ‘Book’ button on our pricing page leads to the payment page of our payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland). There you enter your company name, billing address, email address, the address of your website, your VAT identification number if you wish, and your payment details. Payment details such as card number or IBAN are seen exclusively by Stripe and your bank, never by us. Stripe processes the payment under its own responsibility in accordance with its privacy notice (stripe.com/de/privacy); in the process, data may reach Stripe, Inc. in the USA, which is certified under the EU-U.S. Data Privacy Framework.
After payment, we receive from Stripe: company name, name of the person placing the order, email address, your website, the plan booked, the payment interval, the amount and the status of the subscription, together with the identifiers under which Stripe keeps you and your subscription. We store this on our server (Hetzner Online GmbH, Nuremberg data centre) in order to perform the contract and activate your bot. The legal basis is Article 6(1)(b) GDPR.
Setup then runs without any action on our part, just as for the free trial, see the section above: a customer record and portal account are created from your details, your website is imported, and you receive two emails via Brevo, a confirmation of your booking with plan and price straight away, and within one hour the line of code for your website together with the link for your password. If you previously had a trial period, your bot simply remains in place with its knowledge and settings; you only receive the confirmation.
Stripe creates your invoices and makes them available in the customer portal. Whether you also receive an email from Stripe for each payment depends on a setting in our Stripe account and is governed there. We keep invoices and the associated booking records for six or ten years respectively, as long as commercial and tax law requires. If you cancel, the contract ends at the end of the paid period; we delete knowledge, settings, conversations and accounts thirty days later, as described in the section on the customer portal.
11. If you write to us
If you send us an email, we process the information in your message in order to reply to it: your email address, your name and anything else you tell us.
The legal basis is Article 6(1)(b) GDPR if your enquiry is aimed at a contract with us, and otherwise our legitimate interest in answering enquiries pursuant to Article 6(1)(f) GDPR.
Our address kontakt@veradicta.com is not a mailbox of its own but a forwarding address via Cloudflare Email Routing. Your message passes through the servers of Cloudflare, Inc. (for the address, see section 2) and is delivered to the same two mailboxes as an enquiry via the contact form; which these are is stated in the section on the contact form. The data processing agreement with Cloudflare also applies to this.
We delete your enquiry as soon as it has been dealt with and no statutory retention obligation prevents this. If we also add your enquiry to our prospect records in order to come back to it later, we delete this entry at the latest twelve months after the last contact. If a contract is concluded, we keep your order as a received business letter for six years from the end of the contract; this is required by § 147(1) no. 2 in conjunction with (3) of the German Fiscal Code (Abgabenordnung). For business emails that count as commercial letters, commercial and tax law provide for retention periods of six or ten years respectively; we keep such messages until these periods expire and do not process them further after that. You can object to the storage at any time. If you tell us at the same time that you do not wish to be contacted again, we keep only the name of your business, this note and its date; this is necessary so that we do not inadvertently write to you again.
Your enquiry reaches the two people who deal with enquiries at our company. To receive them, we use mailboxes from common email providers. Beyond this, we do not pass your enquiry on.
12. If you send us a letter
Our postal address is a rented business address. It is managed for us by Clear-Media UG (haftungsbeschränkt), Europaring 90, 53757 Sankt Augustin, Germany.
Items sent to us are received there, opened and digitised and then made available to us. This also applies to letters from authorities and courts. The legal basis is our legitimate interest in a reliable business address at which items can be served, pursuant to Article 6(1)(f) GDPR; if your letter relates to a contract, it is Article 6(1)(b) GDPR.
If you would like to tell us something that nobody other than us should read, please send us an email first. We will then agree on another way.
13. If we write to your business
We approach businesses for which our offer may be of interest and write to them once by post for this purpose. For this we store the name of the business, the postal address, the website address and, where stated there, a contact address, a telephone number and the name and position of the responsible person named in the legal notice (Impressum). We need this information for the salutation in the letter.
This information comes from the publicly accessible website of the respective business, usually from its legal notice (Impressum). We do not buy addresses and do not take them from third-party directories.
The legal basis is our legitimate interest in approaching potential business customers pursuant to Article 6(1)(f) GDPR. Because we did not collect the data from you yourself, Article 14 GDPR applies; the same information is therefore also given in the letter.
You will not receive a second letter from us. If you do not get in touch, we delete your data at the latest three months after the letter was sent. If contact does take place, the twelve-month period from the previous section applies.
You can object to the processing at any time; a short message to our contact address is sufficient. We keep only the name of your business, your website address, the note of your objection and its date, so that we do not inadvertently write to you again. This is permitted by Article 21(3) GDPR, and without this remainder the objection would be forgotten again in the next run.
14. If we email your business in the United Kingdom
This section applies only to emails we send to businesses in the United Kingdom. In Germany we write to businesses by post only (see the previous section), so this section has no counterpart in the German version of this policy.
We contact businesses in the United Kingdom for which our service may be of interest, by email. For this we store the name of the business, its legal form, registered address and industry code as listed in the Companies House register, the address of its website, the business email address we write to and, where stated on the website, the name and role of a contact person. We write only to limited companies, public limited companies and limited liability partnerships, not to sole traders or partnerships.
The company details come from the public Companies House register; the email address and any contact name come from the business’s own publicly accessible website, usually its contact page or legal information. We do not buy email addresses and do not take them from third-party lists.
We send these emails from the domains veradicta-ai.com and teamveradicta.com, using Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), which acts for us as a processor. Google covers any transfers outside Europe with standard contractual clauses under EU and UK law.
The legal basis is our legitimate interest in approaching potential business customers (Article 6(1)(f) GDPR and UK GDPR). Because we did not collect the data from you yourself, Article 14 GDPR and UK GDPR applies; a short notice with a link to this section is therefore included in every email.
If you do not reply, we delete your data no later than three months after our last email. If you do reply, the twelve-month period from the section on writing to us applies.
You can object at any time, without giving reasons: reply to the email with the word ‘unsubscribe’, use the unsubscribe link in the email, or write to kontakt@veradicta.com. We will then not email you again. We keep only the name of your business, the email address, the note of your objection and its date, so that we do not contact you again by mistake (Article 21(3) GDPR and UK GDPR).
Your other rights are set out in the section ‘Your rights’. You may also complain to the UK data protection regulator: Information Commission (ICO), 4th Floor, No.3 Circle Square, 5 Hawkshaw Street, Manchester, M1 7BL, United Kingdom; telephone 0303 123 1113; ico.org.uk.
15. If you use our customer portal
The customer portal is located at portal.veradicta.com and is a separate service from this website. What is said above about cookies, measurement and third-party servers applies to veradicta.com. This section applies to the portal. Access is available to our customers and to the people who work there on their behalf. Since 20 September 2026, anyone who views their demo business in the demo shop also enters it; what happens in that case is described in the section on the demo shop.
For an account, we store your email address as your username, your password exclusively as a hash and never in plain text, your name if you have provided one, which areas of the portal you are permitted to use and whether your access is temporarily suspended, the time at which the account was created, and the time of your last login. For each customer, we also store the name of their business, the settings of their chat window, their website, a contact person with email address and, where applicable, telephone number and postal address, the plan booked, the contract start date and price, and the end of a trial period.
If you upload an image in the portal, such as the logo for your chat window, we store it and deliver it to the visitors to your website so that it appears in the chat window. This generates the same technical connection data on our side as loading the chat window itself. If you replace or remove the image, we replace the stored one accordingly.
If you submit a support request in the portal, we store the subject, category and the history of messages with their times, together with the account that wrote them and our replies. You can attach up to three files to each message, each up to 4 MB, as PNG, JPEG or PDF; they are kept in the same database as the request. Please attach only what relates to the question: a screenshot from the portal often shows more than the point in question. Requests and attachments are kept for as long as your account exists and are deleted with it.
As long as you only open the login page, no cookie is set. When you log in, we set a session cookie. It contains a random value and nothing else; our database holds only a hash of it. The session ends after seven days without use, and at the latest after thirty days; after that you log in again. This cookie is strictly necessary for logging in, which is why we do not ask for consent for it (§ 25(2) no. 2 TDDDG).
The second and last cookie that the portal itself sets remembers your choice of display, that is light, dark or our own colour scheme. It contains only this choice, is valid for one year and is not used to recognise you.
In addition to these two cookies, the portal stores some information in your browser’s storage. This records whether you have muted the notification sound, whether you have dismissed the notice about the end of your trial period, whether you have postponed the suggestion to add the portal to your device as an app, and which cards you have collapsed. If you have marked yourself as available so that visitors can reach a member of staff, it also records the time of your last activity in the portal; from this we can tell whether you are still there, and otherwise we end your availability automatically. This information remains on your device, is not sent to any server and is not used to recognise you. Each entry implements a decision you have made yourself and is strictly necessary for that purpose (§ 25(2) no. 2 TDDDG); you can delete it at any time by removing this website’s data in your browser.
Every login is logged: the time, the username entered, whether it was successful, and the IP address. This serves solely to defend against attacks in which someone tries out passwords; without this log we could not slow down such attempts, and a restart would forget every failed attempt. We delete the entries after seven days.
When you set a password, we check whether it appears in known data breaches. For this, our server queries the Have I Been Pwned service and sends it only the first five characters of a hash of your password; a few hundred possible endings are returned, and the comparison again takes place on our side. Your password therefore never leaves our server, and the service does not learn your IP address, because the request comes from our server and not from your browser.
The portal is operated on a server of Hetzner Online GmbH in its Nuremberg data centre. Traffic to it is routed via Cloudflare, Inc. (for the address, see section 2), under the same conditions as described there.
We send emails from the portal: notification of a new enquiry, confirmation of a changed address, messages about cancellation and payment, weekly and monthly reports, replies to support requests and the three messages of the free trial. For this we use the email delivery service Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany). We transmit to it the recipient address and the content of the message. Brevo processes the data within the EU as our processor pursuant to Article 28 GDPR. So that a message is not lost if sending fails, we keep it available on our own server for seven days and try again during this time; after that, this copy is deleted. Beyond this, we do not pass anything on from the portal, unless the customer sets up the interface described in the next paragraph themselves.
From the Big plan upwards, a customer can store an address of their own in the portal to which we report events from their chatbot so that they arrive in the customer’s own software. The following are reported: the bot has handed over to a human, a visitor has left contact details, an appointment has been provisionally booked, a member of staff has taken over a conversation or handed it back, plus a test delivery at the push of a button.
Depending on the event, the following are transmitted: the identifier of the conversation together with a link into the portal, the reason for the handover, the name the visitor reads in the chat window at the handover, a provisionally booked appointment, and the information a visitor has given of their own accord: name, telephone number, email address, request, preferred appointment, other information they provided during the conversation and the page on which the conversation began.
The sole recipient is the address that the customer enters themselves; it must begin with https. Where it leads and who has access there is determined solely by the customer. The customer is the controller for their visitors’ data; we act as their processor pursuant to Article 28 GDPR. We keep a log of deliveries and delete it after seven days.
From the Medium plan upwards, a customer can connect their chatbot to a WhatsApp account in the portal so that it also answers questions there. If someone writes to this number, Meta transmits to us the sender’s telephone number and the name they have stored with WhatsApp; the chatbot’s reply goes back the same way. Both are stored with the conversation and deleted with it.
Whether this access exists at all is decided solely by the customer: they set it up with Meta and enter the access details in the portal. The customer is the controller for their visitors’ data; we act as their processor pursuant to Article 28 GDPR. What applies between the sender and Meta is governed by Meta’s terms and lies outside our influence.
If you switch it on in the portal for a device, we send notifications to that device, for example for a new enquiry, an appointment request or when a visitor needs a human. For this, for each device we store the address that your browser gives us for this purpose, two keys, the name you give the device, when it was registered, when a notification last arrived and, if one could not be delivered, the reason. The notification is sent via the push service of the respective browser manufacturer; its content is encrypted in transit and the service cannot read it. The notification contains the visitor’s name and request, never their telephone number or email address. You can switch notifications off again for each device in the portal under ‘Einstellungen’ (‘Settings’); we then delete the information about that device.
The legal basis is our legitimate interest in giving access to the people the business designates for this purpose and in protecting it against attacks (Article 6(1)(f) GDPR). At the same time, the access is part of the contract we have concluded with that business (Article 6(1)(b) GDPR).
The account remains in place as long as the business you work for uses the access. If our contract with that business ends, we remove the accounts of its staff, its stored content and the conversation histories once thirty days have passed since the end of the contract, at the latest in the first daily deletion run thereafter. We retain the master data of the business itself beyond that, that is company name, address, contact person and contact details: they form part of our business relationship and of the records we must keep for the tax office, for which the retention periods of up to ten years under commercial and tax law apply.
An account will be removed on request, together with its sessions. The owner account of the business you work for can do this itself in the portal under ‘Einstellungen’ (‘Settings’). You cannot remove your own account there yourself: let the business or us know and it will be done.
The portal also contains the conversations and enquiries of visitors who have talked to a customer’s chatbot. The respective business is the controller for this data, not us; we process it on its behalf pursuant to Article 28 GDPR. If you are a visitor to such a website and would like access to or erasure of your data, please contact the business whose chatbot you used.
16. Encryption
This site is transmitted exclusively in encrypted form (TLS, recognisable by the ‘https’ and the padlock in your browser’s address bar).
A normal email, by contrast, is not encrypted end to end. If you would like to tell us something confidential, please let us know and we will agree on another way.
17. Backups
Our database is backed up every night; the 14 most recent versions are kept. Before any change to the database structure, an additional copy is made, which is deleted after 14 days. In addition, our data centre backs up the entire server daily and keeps seven versions.
When we delete data, it remains in these backups for up to 22 days in normal operation. We do not remove individual data from them; we only use backups to restore an earlier state after an outage or an error. After that, the data disappears with the respective backup version.
18. Your rights
You have the following rights against us:
- access to information about which of your data we process (Article 15 GDPR)
- rectification of inaccurate data (Article 16 GDPR)
- erasure of your data (Article 17 GDPR)
- restriction of processing (Article 18 GDPR)
- receipt of your data in a portable format (Article 20 GDPR)
- objection to processing based on our legitimate interest (Article 21 GDPR)
- withdrawal of consent given, with effect for the future (Article 7(3) GDPR)
To exercise any of these rights, an informal message to us is sufficient. You do not need to give reasons, except when objecting to processing based on our legitimate interest. In that case, the reasons must arise from your particular situation.
19. Right to lodge a complaint
If you believe that we are not processing your data lawfully, you can lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
The competent authority is the one at the location of our main establishment, which is in Bavaria. The postal address given in section 1 is a rented business address in another federal state; it is not relevant for determining competence.
You can also contact the supervisory authority at your own place of residence or work. A list of all authorities with their addresses is maintained by the Federal Commissioner for Data Protection and Freedom of Information (in German).
20. No automated decision-making
We do not make any decisions about you that are taken solely by a machine, and we do not create any profiles within the meaning of Article 22 GDPR. Although the free trial is set up without any action on our part, this is not a decision about you: you receive exactly what you requested, and whether we then offer you a contract is decided by a human.
21. Changes to this policy
We update this policy when something changes on our website, for example when a new function is added that involves data. The version published here applies in each case. You will find the date of its current version at the top.