Skip to main content

Legal

Privacy policy

Information on the processing of personal data pursuant to Art. 13 GDPR.

Last updated: September 25, 2026

This English version is provided for convenience only. The German version is the legally binding one — in case of any discrepancy, the German text prevails.

In short

This website sets exactly one cookie that requires consent: the one that credits a referral — and only if you agree to it. Opening a page contacts no third party: no embedded outside services, no external fonts, no analytics or tracking tool. Two features that you trigger yourself do pass data outward — the AI assistant and, where set up, our push notification; each has its own section below. We ask you on your first visit and record your answer in a single cookie — otherwise the same question would return on every page view. It holds nothing but your decision and a version number.

We process personal data only when you actively approach us: through the contact form, through the project configurator with its appointment booking, through the partner application form, or by email. In addition, technically necessary server logs are generated when the site is accessed, as with any website.

If you arrive through a partner's referral link, their code sits in the address bar and is stored along with any form you submit. Something is placed on your device for that only if you have consented to the “Referral” category — see “Partner program and referral code”.

Controller

The controller for data processing on this website is:

Company
Awelior LLC
Address
30 N Gould St, Ste R Sheridan, Wyoming 82801 United States
Email
contact@awelior.com

Representative in the EU

Awelior LLC has no establishment in the European Union. A representative under Art. 27 GDPR has therefore been designated for data subjects in the European Economic Area and for the supervisory authorities.

For any data protection matter you may contact either the representative or us directly. The designation does not affect our own responsibility as controller.

Representative
[not yet designated — an EU representative under Art. 27 GDPR must be appointed]

Hosting

This website is hosted with an external service provider. Personal data collected on this website is stored on that provider's servers.

The provider is used in the interest of secure, fast and reliable delivery of our offering (Art. 6 (1) (f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.

Server log files

When this website is accessed, the host automatically collects information transmitted by your browser. This comprises:

This data is not merged with other data sources. Collection takes place on the basis of Art. 6 (1) (f) GDPR; we have a legitimate interest in the technically error-free presentation and security of our website.

Retention period: 14 Tage.

  • browser type and version
  • operating system used
  • referrer URL
  • hostname of the accessing device
  • time of the server request
  • IP address

Contact form

If you send us inquiries via the contact form, the details you provide there — including the contact data you enter — are stored by us for the purpose of processing the inquiry and in case of follow-up questions.

The inquiry is additionally stored as a file on our server and sent to us by email. You receive an automatic acknowledgement at the email address you provided.

To protect against automated submissions we use an additional field invisible to you as well as a check of how long the form took to complete. For this we also store, with each inquiry, your browser identification (which your browser sends of its own accord) and the time between opening and submitting the form. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is fending off automated bulk submissions. Both are held in the same file as the inquiry, are not passed to third parties, and are deleted together with it.

The legal basis is Art. 6 (1) (b) GDPR where your inquiry relates to the initiation of a contract. In all other cases processing is based on our legitimate interest in effectively handling inquiries addressed to us (Art. 6 (1) (f) GDPR).

For processing purposes we record internally what stage your inquiry is at (for example "answered" or "quote sent") and add a note where needed. These records are visible only to us, serve solely to process the inquiry and are deleted together with it.

Retention period: we keep the data until you ask us to delete it, withdraw your consent or the purpose ceases to apply — at the latest after 24 months. Mandatory statutory retention periods remain unaffected.

  • subject (website, app, automation, AI agent, phone assistant or not sure)
  • your message
  • budget range (voluntary)
  • name
  • email address
  • phone number (voluntary)

Project configurator and appointment booking

In the project configurator you answer questions about your project, choose an appointment for a call and then see a non-binding indicative price. The following data is processed:

  • type of project, starting point, desired features and integrations
  • scope (such as the number of pages or workflows), project languages and time frame
  • date and time of the requested call as well as the language of the call
  • name and email address, and voluntarily company and phone number

Your details are stored on our own server: the answers as a file, the appointment in a database on the same server. No third-party booking service and no third-party calendar is involved.

On the day before the call you receive a single reminder by email stating the date, the time and how to cancel. You do not receive any further automated messages; in particular we send no newsletter and no advertising.

The legal basis is Art. 6 (1) (b) GDPR where your inquiry relates to the initiation of a contract, otherwise our legitimate interest in handling your inquiry (Art. 6 (1) (f) GDPR). The same basis covers the reminder for an appointment you booked yourself — it is part of carrying out the agreed call.

Retention period: as for the contact form, at most 24 months. After that the inquiry, the appointment and the internal notes are deleted.

Partner program and referral code

We only set a cookie to credit a referral if you have consented to the “Referral” category in the consent notice. Without your consent the code exists only in the address bar.

Third parties may recommend us and receive a referral code for doing so. When someone opens a page through such a link, the code appears as a parameter in the address bar (for example /en/project?partner=example-code). When a form is submitted, it is stored together with your inquiry so that we can attribute the recommendation.

Since 22 September 2026 there is also an attribution cookie: it is called awelior_partner, expires after 30 days and contains the partner code and, where applicable, a campaign label — no identifier that would allow a person to be recognized. It is set ONLY if you have consented to the “Referral” category in the consent notice; the legal basis is your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw it at any time via the consent notice.

Without consent things stay as before: the code exists only in the address bar, and anyone who leaves the site and returns without the link arrives without attribution. That is the weaker but more data-frugal attribution — and it remains the default.

When someone opens a partner’s promotional link, we count the click: we store the day, the partner code, a campaign label and a number. No IP address, no device identifier, no time of day. That shows which poster works, but identifies no one.

The form visibly states that a recommendation is attached. You can remove it there with one click; the parameter then disappears from the address bar and is not transmitted.

The recommending partner is not told by us who inquired through their link. They get no access to this application, no names, no contact details and no content of your inquiry; for settlement it is enough for us to state whether a project went ahead.

The presentation mode at /en/partners/presentation is a display page only. A partner can enter their own code there so that the onward links carry it; nothing is stored on the device for that either. No input is transmitted, and it is not recorded how long or how often the page was viewed.

If someone applies as a partner through the form at /en/partners, we process their name and email address as well as the company, website and description of how they intend to recommend us, where given voluntarily. The legal basis is Art. 6 (1) (b) GDPR (initiation and performance of the partner agreement). These data remain stored for as long as the cooperation lasts; once it has ended or did not come about, we generally delete them after a waiting period of up to 24 months, unless a statutory retention period applies.

Project status for clients

Anyone holding the link we sent can see the status of the project concerned — there is no sign-in. Here too, no cookie is set and nothing is stored on your device. You can have the link revoked at any time.

Once you have commissioned us, we set up a page at /order on request where you can check the status of your project. The address contains an access token of 32 random bytes which we send to you once. There is no account, no password and no session for it — so there is nothing for you to create, remember or have reset.

What is shown is only this: the name of the project, its state, the date it was commissioned, any planned completion date, the agreed stages with their state and due dates, and the time of the last change. What is not shown: the project fee, internal notes, the internal history, the names of the people working on it, internal identifiers and your contact details. The legal basis is Art. 6 (1) (b) GDPR (performance of the contract).

No information on your device is accessed in the process: for this page we store neither a cookie nor data in your browser's local or session storage. Consent under section 25 TDDDG is therefore not required. It is the same construction as the referral code — the token sits in the address bar and nowhere else.

Because there is no sign-in, anyone in possession of the link can view the status shown there. Please do not pass it on. With 32 random bytes the token cannot be guessed; should a link nevertheless end up in the wrong hands or become obsolete, we will revoke it on your word and send you a new one. A revoked link then produces exactly the same response as a made-up address.

The page is barred from search engines: it carries the instruction "noindex, nofollow", appears in no sitemap and is excluded from retrieval in our robots.txt. Opening it produces the usual server log files described in the corresponding section.

The project data remain stored for as long as the project runs, and beyond that within the retention period for the underlying inquiry; if that inquiry is deleted, the project including its stages and its access link goes with it. Further detail on periods and on your rights is set out in the sections "Contact form" and "Your rights".

Customer account

A customer account is optional. The previous route — the link under /order — continues to work unchanged, with or without an account. If you delete your account, your projects remain reachable through that link.

If you register for a customer account, we store your email address, a password hash (not a readable password — more on that below) and the name you provide when creating it. We also record when you last signed in, and per session technical details such as your browser's identifier, so that a sign-in can remain valid for up to 30 days without you having to sign in again during that time.

We do NOT store your password in plain text, but as a hash (scrypt) with its own random salt — the same method that also protects sign-in to our administration area. The password cannot be recovered from the stored value.

Through your account, you can link an existing project link (see the section "Project status for clients") to your account to see several projects in one place. What is shown is exactly the same information the individual link already shows — title, status, dates, stages and the status of any recorded payments; not the project total, internal notes, the internal history or staff names.

We temporarily count failed sign-in attempts to detect and block automated password guessing; for this, the email address used is recorded in plain text as the identifier. This record serves solely to protect your account against automated password guessing and is not linked to any other use of your address. The legal basis for this is our legitimate interest in the security of accounts (Art. 6(1)(f) GDPR); the count itself lapses after 15 minutes and is not kept separately. For creating, maintaining and linking the account otherwise, the legal basis is Art. 6(1)(b) GDPR (performance or initiation of the contractual relationship).

You can reset a forgotten password using a link we send you by email; it is valid for one hour and can only be used once. When resetting, we sign out all existing sessions of your account — on every device where you were signed in at that time.

You can delete your account yourself at any time under "My account". Doing so deactivates the account and removes the link to your projects — the projects themselves remain and stay reachable through the individual link you already have. Retention period: the account record itself is NOT removed from our database — "deleting" here means deactivating it and detaching it from your projects, not removing the row. As a direct consequence, the same email address can never be used again afterwards to register a new account.

A customer account is never a requirement: the previous route via /order/<access token> continues to work unchanged and without any sign-in. More on that is in the section "Project status for clients".

Quote and acceptance

If you accept a quote via the link we send you, we record as evidence WHO accepted WHAT and when — including your IP address and your browser identification. Without that record the acceptance could not be proven later.

We send quotes to you as a link under /offer. The address contains an access token of 32 random bytes; there is no account, no password and no session for it. As long as you neither accept nor decline, the page merely retrieves the text of the quote and stores nothing about you.

At the moment of acceptance we store: the name you entered in the form; the time recorded by our server (not by your device); the checksum (SHA-256) of the content you accepted — including line items, totals and discounts; your IP address; and the browser identification your program sends. If you decline, we store the time and, if you give one, the reason.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual steps and performance of the contract) and our legitimate interest in reliable evidence under Art. 6(1)(f) GDPR.

If we withdraw a quote, the access token expires immediately; afterwards the link leads to the same error page as an invented address. Retention follows the same periods as for contracts.

Signing a contract

If you sign a contract via the link we send you, we record as evidence WHO signed WHAT and when — including your IP address and your browser identification. Without that record the signature would be worthless as evidence. We delete those two technical details after three years.

We send contracts to you as a link at /contract. The address contains an access token of 32 random bytes; there is no account, no password and no session for it. As long as you do not sign, the page merely retrieves the contract text and stores nothing about you.

At the moment of signing we store: the name and email address you entered in the form; the time recorded by our server (not by your device); the checksum (SHA-256) of the text that was signed; your IP address — in full for IPv4, only the /64 network for IPv6; the browser identification your program sends; and each individual consent together with its exact wording.

Legal bases: name, email, time and checksum are processed under Art. 6 (1) (b) GDPR, because they constitute the contract itself. IP address and browser identification are processed under Art. 6 (1) (f) GDPR. Our legitimate interest is securing evidence: an electronic signature under Art. 25 eIDAS Regulation is admissible in court, but it is worth only as much as what it can prove. We have weighed this up and limited those two details to what is necessary — the IPv6 address is truncated, and both are deleted after three years (1,095 days), while the contract itself remains.

We retain the signed contract from the date of signature: seven years, or ten years for clients established or resident in the European Union. Awelior LLC is a US company — the German retention obligations under § 257 HGB and § 147 AO do not apply to us directly. Seven years cover the tax retention and audit periods under US law as well as the usual limitation periods for contractual claims; we choose the longer period where there is an EU connection so that the document remains available for your own retention obligations. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is tax record-keeping and the establishment, exercise or defense of legal claims. During this period, a request for erasure under Art. 17 GDPR does not prevail for the contract (Art. 17 (3) (e) GDPR) — it does for the IP address and the browser identification, and we delete those earlier in any case.

For this page we set no cookie and store nothing in your browser’s local or session storage. No information on your device is accessed, so consent under section 25 TDDDG is not required. The page carries "noindex, nofollow", appears in no sitemap and is excluded from retrieval in our robots.txt.

After signing, the same link becomes your copy: the contract text, the time and the checksum remain available there. You also receive a confirmation by email; it contains the time, the checksum and the link, but not the contract text itself. That lets you verify at any time that the text is unchanged — which is what the checksum is for. Anyone holding the link can view the contract; please do not pass it on. A withdrawn link then responds exactly like a made-up address.

Customer records and contact history

Once we do business with you, we keep a record of it — kept separately for the company and for the person we speak with. For the company we store the name, address, country, tax number, website and an internal note. For the contact person we store the first and last name, email address, phone number, position within the company, the language we speak with you in, and likewise an internal note. A record without a company is possible and is the normal case for private clients.

These details come from your inquiry or from our conversation with you. We do not buy in address lists, we do not fill in gaps from public registers, and we do not create a record for anyone whose details we did not receive from them directly.

We also keep a note of what was discussed between us: the kind of contact (call, email, note, meeting), a heading, the note itself and the date on which it took place. These notes are visible to us alone. Their only purpose is to let us follow the course of our business relationship in one place. The language on file also determines the language in which quotes and contracts go out to you.

The legal basis is Art. 6 (1) (b) GDPR insofar as the details serve to initiate or perform a contract with you. In all other cases the processing rests on our legitimate interest in handling our business contacts in an orderly manner (Art. 6 (1) (f) GDPR).

A record is removed in two steps. First it is archived: it disappears from the lists but remains findable for existing documents. After that it can be deleted for good, and its entire contact history and the associated internal tasks go with it. Only what has been archived beforehand can be deleted — the second step keeps an accidental click from becoming data loss.

Documents already issued — projects, contracts, invoices — do not disappear in the process. They carry the recipient details that applied when they were issued within themselves and are subject to retention periods; all that is severed is their link to the removed record. Further detail on periods and on your rights is set out in the sections "Contact form" and "Your rights".

For every final deletion we keep a note: when it was deleted, by whom, whether it concerned a company or a person, and how many history entries were removed with it. This note deliberately contains no name and no contact details — a log that preserves names preserves exactly what was meant to be deleted.

These data are not passed on to third parties.

Messages via WhatsApp and Telegram

Email is part of the business relationship. WhatsApp and Telegram only if you have expressly consented — and your withdrawal ends both immediately.

We send confirmations, receipts, payment reminders and project updates by email. The legal basis is Art. 6(1)(b) GDPR: without these messages the contract cannot be performed.

In addition you may choose WhatsApp or Telegram — when filling in a form, in conversation with us, or through a partner. For that we store the number you give for it (it may differ from your phone number), the time of your consent, the way it was given, and the exact wording you agreed to. The legal basis is your consent under Art. 6(1)(a) GDPR.

Through these channels we send messages about your matter only — no advertising. For WhatsApp we use templates approved by the provider; for Telegram you establish the connection yourself via a link, because Telegram does not allow a bot to make the first move.

You may withdraw at any time — on the payment page of your matter or informally to us. Withdrawal deletes the stored number AND the consent; afterwards only emails reach you. A withdrawal applies to all kinds of messages, not only to the one in which you declared it.

Recipients are WhatsApp Ireland Limited or Meta Platforms, Inc. and Telegram FZ-LLC. What these companies process beyond this is governed by their own terms.

Contact by email

If you write to us directly by email, your message together with all resulting personal data is stored by us for the purpose of handling your inquiry. The legal bases correspond to those for the contact form.

Cookies and local storage

There are no statistics cookies and no third-party cookies on this website. A single cookie serves advertising — crediting a referral — and it is set only if you consent. Only what the site needs in order to work is stored: your answer to the consent notice, the language we serve it to you in, and your color scheme. On top of that comes what you trigger yourself — your voice choice in the phone assistant demo and, if you sign in, your session in the customer, partner or administration area. The complete list appears further down. The language is recorded in the cookie on every visit; on the very first visit, before that cookie exists, we determine it first from your IP address, falling back to whatever your browser states — more on this below.

Access to information on your terminal equipment is governed by § 25 TDDDG. Whatever is strictly necessary in order to provide the service you asked for requires no consent under § 25 (2) no. 2 TDDDG. Anything beyond that is set only after your express consent — and at present there is exactly one of the kind: the cookie that credits a referral (section “Partner program and referral code”).

An additional step applies to the language before that cookie exists: on your very first visit, with no cookie set yet, we first work out the likely language from your IP address, using a bundled database that is looked up purely locally on our own server. This establishes no connection to a third party, and your IP address is not stored for this purpose — it serves only the one-off, momentary assignment to a country and, from that, a language, in addition to the logging that in any case takes place as described in “Server log files”. If no country can be determined, we fall back to the language your browser sends instead. Once the cookie is set — through this determination or through your own choice in the language switcher — this step is skipped, and every further visit uses the cookie directly.

On your first visit a notice appears offering three equally weighted routes: accept all, necessary only, or open the settings. We record your decision in the cookie “awelior_consent” listed below. That cookie itself requires no consent, because it does precisely what you asked for — without it the question would return on every page view. It contains nothing but the categories you chose and a version number: no name, no identifier, no IP address, nothing by which you could be recognized. It is shared with nobody.

You can change or completely withdraw your decision at any time through “Cookie settings” in the footer of every page. Withdrawing is therefore exactly as easy as giving consent. Withdrawing deletes the cookie and brings the notice back. If the categories listed here change, the version number is raised and we ask you again; consent to a list that no longer exists in that form is not consent to the present one.

You can also delete every item at any time through your browser settings. The complete list — with name, provider, purpose and lifetime — appears here and is generated from the same file as the notice and the settings dialog:

Always on

  • awelior_consent

    Provider
    Awelior (this website)
    Purpose
    Stores your decision from this notice together with the version number of this list. Without it the notice would reappear on every page view. It contains no name, no identifier and nothing by which you could be recognized — only the categories you chose and a number. It is not shared with third parties.
    Storage
    Cookie
    Lifetime
    182 days
  • AWELIOR_LOCALE

    Provider
    Awelior (this website)
    Purpose
    Records which language the site is served to you in. It is set or renewed on every page view — after that with the language last used. On the very first visit, before this cookie exists, the language is first determined from your IP address (looked up purely locally on our server, with no connection to a third party), falling back to the language your browser sends. Switching languages changes its value.
    Storage
    Cookie
    Lifetime
    365 days
  • awelior-theme

    Provider
    Awelior (this website)
    Purpose
    Remembers whether you chose the light or the dark color scheme. It is only written once you switch, lives in your browser's local storage and is never transmitted to a server.
    Storage
    Local storage
    Lifetime
    Until you delete it in your browser
  • awelior-stimme-de / -en / -ru / -tg

    Provider
    Awelior (this website)
    Purpose
    Remembers which reading voice you chose in the telephone demo — separately per language, hence four entries. It is only written once you pick a voice there, lives in your browser's local storage and is never transmitted to a server. All that is stored is the voice identifier as your browser names it.
    Storage
    Local storage
    Lifetime
    Until you delete it in your browser
  • awelior-stimme-nur-lokal

    Provider
    Awelior (this website)
    Purpose
    Records that you want the telephone demo to use only voices that run on your own device. Some reading voices from Microsoft and Google convert the text on a server belonging to the browser vendor; with this entry set they are not offered at all. It lives in your browser's local storage and is never transmitted to a server.
    Storage
    Local storage
    Lifetime
    Until you delete it in your browser
  • awelior_kunde

    Provider
    Awelior (this website)
    Purpose
    Session identifier for the customer account. It is set only after signing in at /konto and never on an ordinary visit. Without it a signed-in account is technically impossible; it serves no analysis of any kind.
    Storage
    Cookie
    Lifetime
    30 days
  • awelior_partner

    Provider
    Awelior (this website)
    Purpose
    Session identifier for the partner account. It is set only after signing in at /partner-konto and never on an ordinary visit. Without it a signed-in account is technically impossible; it serves no analysis of any kind.
    Storage
    Cookie
    Lifetime
    30 days
  • awelior_mitarbeiter

    Provider
    Awelior (this website)
    Purpose
    Session identifier for the staff portal. It is set only after signing in at /staff-account and never on an ordinary visit. Without it a signed-in portal session is technically impossible; it serves no analysis of any kind.
    Storage
    Cookie
    Lifetime
    30 days
  • awelior_admin

    Provider
    Awelior (this website)
    Purpose
    Session identifier for the internal editing area at /admin. It is set only after signing in there and never when visiting the public pages. Listed here so that this register is complete.
    Storage
    Cookie
    Lifetime
    12 hours

Nothing in it

This category is empty — so there is nothing here for you to consent to. We do count page views, but without a cookie, without an identifier and without anything being stored on your device. What exactly is recorded is described in the privacy notice under “Visitor statistics”.

Nothing in it

This category is currently empty. All content on this website comes from our own server; opening it establishes no connection to third parties. Here too we will ask again before that changes.

Consent required

  • awelior_partner

    Provider
    Purpose
    Storage
    Cookie
    Lifetime
    30 days

No tracking, no third-party services

We deliberately use no analytics tools, no tracking pixels, no advertising networks and no social media embeds. No profiles of your behavior are created. This promise covers viewing this website. There are exactly two places where you yourself can call on a third-party service — the assistant (section "AI assistant") and online payment (section "Payment link for clients"). Both are described there individually, both require an action from you, and merely opening a page establishes no connection to either.

Fonts are served from our own server and not loaded from an external provider. Accessing this website therefore establishes no connection to third-party servers.

The AI agent demos shown on this website are entirely scripted simulations that run in your browser; for these demos, no language model and no external service is called. This does not apply to the real website assistant described in the section "AI assistant" — that one does call a genuine, server-side AI language model.

The phone assistant demo has no connection to a telephony provider, and nothing is recorded, nothing is transmitted to us and nothing is evaluated — the transcript is stored text revealed in sequence. Unlike the AI agent demos above, however, it does contain audio: the audio files were pre-produced — generated once, before publication, using an external speech service, and served ever since from our own server like any other media file. What is external there is the tool used for that one-time production, not the ongoing operation: accessing the demo does not call that service. If a given turn in the conversation exceptionally has no such file, or it cannot be played, the speech synthesis built into your browser reads it instead — a feature of your own device, which we do not trigger. If an “Online” or “Natural” voice is selected there, your browser transmits the displayed conversation text to its own provider for conversion, on its own initiative; the demo's controls always name which voice is currently playing and whether it works locally or transmits. Anyone who wants to rule this out can restrict the voice choice there to voices that run exclusively on their own device.

Where this website shows reviews from our own Google Business Profile, they were fetched server-side on a schedule and cached. Visiting this website itself establishes no connection to Google, and no data about you is transmitted to Google in the process.

AI assistant

For our website assistant we use a server-side AI language model. Without signing in, it answers your questions solely from our own published content — with no personal data involved. Inside your customer account, it additionally answers questions about your own orders and payments; it never sees another customer's data. We do not store any conversation history.

This website offers an assistant that answers your questions using an AI language model. The model is called exclusively server-side — never directly from your browser. Which provider and which model are used is configured in the admin area and can be changed there at any time.

If you use the assistant without signing in — for example on a public page — the language model receives, for your question, only this website's own published content: services, pricing and frequently asked questions. No personal data is transmitted in the process. The legal basis is our legitimate interest in providing pre-contractual customer service (Art. 6 (1) (f) GDPR).

If you use the assistant inside your customer account (under /konto), the language model additionally receives your own order and payment data — your name, the details of your orders and the status of any recorded payments ("Open" / "Paid on …") — so that the assistant can also answer account-specific questions. This is determined solely by your signed-in session; the model never receives another customer's data. The legal basis is Art. 6 (1) (b) GDPR (performance of the contractual relationship).

Depending on which provider we have configured in the admin area, your request may be transmitted to a provider outside the EU or the EEA. Which provider and which location that is depends on our current configuration and cannot be stated conclusively here.

Voice input: A microphone button may appear next to the assistant’s input field. If you tap it, your browser’s speech recognition turns what you say into text. This recognition is a feature of your browser, not ours: depending on the browser, it sends the recording to its provider — Chrome to Google, Safari to Apple — possibly to countries outside your own. We only receive the recognized text, as if you had typed it; we never receive an audio recording. Before the first use, the button tells you this, and nothing is recorded without your click. The legal basis is your consent by tapping it (Art. 6(1)(a) GDPR where applicable); you can always type instead.

Retention period: we do not store any conversation history server-side. Each request to the language model carries the conversation so far with it; once the response has been sent, we do not retain it.

Newsletter

You only receive the newsletter if you signed up AND confirmed with the link in our confirmation email. Every issue contains a link to unsubscribe with one click. We do not track opens or clicks.

Purpose: We occasionally send news about our services and projects. For this we store your email address, the language you signed up in, the time of sign-up and confirmation, and the wording of the consent you agreed to — so that we can prove your consent.

Confirmation (double opt-in): After you sign up we send a single email with a confirmation link. You are only subscribed once you click it. Without confirmation we delete the sign-up after 30 days at the latest.

No tracking: Our newsletter is plain text. It contains no tracking pixel and no redirected links; we do not learn whether or when you open it or what you click.

Sending: We send the emails through our own mail server or the mailbox provider of our domain; we do not share your address with anyone else.

The legal basis is your consent (Art. 6(1)(a) GDPR where applicable). You can withdraw it at any time — with the unsubscribe link in every issue or with a short message to us. This does not affect the lawfulness of emails sent before. Every issue also contains our postal address.

Retention: As long as you are subscribed. After unsubscribing we keep your address and the time of unsubscribing so that we do not write to you again by mistake; on request we delete that too.

Visitor statistics

Only when we switch this feature on in the admin area is a page view logged once — timestamp, city, country and the path visited, nothing else. No cookie is set, no IP address is stored, and no visitor is re-identified across multiple visits.

This logging is switched off by default and only takes effect once we explicitly enable it. While it is off, visiting this website creates no additional record at all — and this section itself does not appear.

When it is switched on, we store for each visit to a content page: the time, the city and the country derived from your IP address (the same local, connectionless lookup described in “Cookies and local storage”), and the path visited. The IP address itself is not stored for this purpose, nor is any identifier, cookie or other feature that could link several visits to the same person. The admin area, technical requests and the personalized pages at /order, /contract and /payment are not counted.

We use these figures solely for a rough sense of how much the website is visited and from which countries — for our own operations, not for marketing or profiling. The legal basis is our legitimate interest in this operational evaluation (Art. 6 (1) (f) GDPR); since no link to an identifiable person is made beyond the single visit, we see no overriding interest of yours standing against it.

If we have additionally set up a push notification for ourselves, a logged visit with a recognized country or city briefly notifies our own device. Delivery for this runs through the push service of the provider Expo (expo-server-sdk), which forwards the notification to Apple's or Google's push infrastructure — this means data is passed to third parties outside our own system, unlike the rest of the cookie- and identifier-free logging described in this section. Only the notification text itself is transmitted, containing the city and/or country derived from your IP address — no IP address, no cookie and no other identifier that could link visits to you. The legal basis is the same legitimate interest as above (Art. 6 (1) (f) GDPR); since Apple and Google may also process outside the EU/EEA, this transfer can involve a third country.

Retention: these records are not subject to a separate deletion period and are removed once we switch the feature off or clean up the database; in any case they cannot be linked to a specific person.

Your rights

You have the right at any time:

  • to request information about the data stored about you (Art. 15 GDPR)
  • to request rectification of inaccurate data (Art. 16 GDPR)
  • to request erasure of your data (Art. 17 GDPR)
  • to request restriction of processing (Art. 18 GDPR)
  • to receive your data in a common format (Art. 20 GDPR)
  • to object to processing (Art. 21 GDPR)
  • to withdraw consent given at any time (Art. 7 (3) GDPR)

An informal message to the email address given above is sufficient for all of these requests.

Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). As Awelior LLC has no establishment in the EU, there is no authority competent by reference to our seat: the competent authority is the one of your habitual residence, your place of work, or the place of the alleged infringement.

Encrypted transmission

For security reasons this site uses SSL/TLS encryption. You can recognize an encrypted connection by the browser address bar changing from "http://" to "https://". While encryption is active, the data you transmit to us cannot be read by third parties.

Changes to this policy

We update this privacy policy whenever the processing changes — for example because a new feature is added. The version available on this page is the applicable one.