Privacy Policy

Version 1.7 - September 2026

General Information and Your Rights

1) What is this about?

Aury is a conversational AI system that allows you to discuss topics related to your mental well-being.

In this Privacy Policy we explain:

  • what personal data we process,
  • for what purposes and on what legal basis,
  • how long we store it,
  • to whom we may disclose data,
  • and what rights you have.

This Privacy Policy applies to:

  • our consumer products (including the prevention offering "Digitale Stressbewältigung mit Aury" (Digital Stress Management with Aury)),
  • our website,
  • as well as all contact channels (e.g., email, social media).

Where a processing activity differs between the prevention offering "Digitale Stressbewältigung mit Aury" and other offerings, we mark that in the relevant section.

2) Who is responsible?

The controller responsible for data processing is:

Aury Care GmbH

Am Mühlenberg 11
14476 Potsdam
Germany

Email: info@aury.co

Managing Directors: Saskia Fester, Robert Wasenmüller, Maximilian Rank

3) Data Protection Officer

Frank Trautwein (external Data Protection Officer)

Fresh Compliance GmbH
Schönhauser Allee 43a
10435 Berlin
Germany
  • Data subject requests (e.g., access, erasure, data copy): dpo@aury.co
  • Confidential inquiries directly to the DPO: dsb@freshcompliance.de

4) What types of data do we typically process?

Depending on usage, we process in particular:

  • Account/contact details (e.g., email, name – if provided)
  • Communication content (e.g., chat messages, voice messages and contributions in voice mode as well as the transcripts generated from them, feedback)
  • Usage/log data (e.g., timestamps, technical logs, IP address)
  • Device/browser data (e.g., device type, operating system, app/browser information, push token of the mobile apps)

Important note on sensitive data (health data):

If you share information about your mental state, symptoms, or health in conversations, this may constitute health data. We only process such data to the extent necessary for the use of Aury and on the legal bases specified in the respective section.

5) On what legal basis do we process data?

Depending on the purpose, we rely in particular on:

  • Art. 6(1)(b) GDPR (contract / use of the application)
  • Art. 6(1)(a) GDPR (consent, e.g., newsletter, optional analytics/tracking)
  • Art. 6(1)(f) GDPR (legitimate interest, e.g., IT security, abuse/error analysis)
  • Art. 6(1)(c) GDPR (legal obligations, where applicable)

Where health data is involved, an additional exception under Art. 9 GDPR applies (e.g., explicit consent, where required).

6) To whom do we disclose data?

We use processors (e.g., hosting, infrastructure, analytics tools) that process data exclusively on our instructions.

All processors are contractually bound under Art. 28 GDPR to process personal data solely on our instructions and not for their own purposes, to keep it confidential, and to implement appropriate technical and organisational safeguards. They are thereby committed to a level of protection for your data that is at least equivalent to the protection described in this Privacy Policy.

In addition, third-party providers may be independently responsible (e.g., messenger/social media platforms) when you use those channels. Details are provided in the respective sections.

7) How long do we store data?

We store personal data only as long as necessary for the respective purpose or as long as statutory retention obligations exist.

Specific storage periods are stated for the respective processing activities (e.g., hosting logs, analytics, newsletter).

8) Your rights

You have – subject to the applicable conditions – the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR)

To exercise your rights, contact us at: dpo@aury.co.

9) Right to lodge a complaint with a supervisory authority

You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht (Brandenburg)

Dagmar Hartge
Stahnsdorfer Damm 77
14532 Kleinmachnow

https://www.lda.brandenburg.de/lda/de/ueber-uns/kontaktanreise/

10) Automated decisions / Profiling

Aury generates responses automatically (AI-powered). We do not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you.

11) Changes to this Privacy Policy

We may update this Privacy Policy if our processing, legal requirements, or products change. The current version is always available in the application or on our website.

The Application

1) Sub-processors

The following overview shows all sub-processors that we use for the data processing activities described in sections 2-5.

Sub-processorPurposeLocationMore Information
Scalingo SASApplication hosting, infrastructureFrance (EU)DPA
Outscale SASU (Dassault Systèmes SE)Infrastructure provider (servers)France (EU)--
Microsoft (Azure)AI model hosting; speech synthesis in voice mode (Azure Speech)EU Data Zone; speech synthesis: Germany (Azure region Germany West Central)Privacy Statement
Google (Vertex AI)AI model hostingEU Data ZoneZero Data Retention
Google (Cloud Speech-to-Text)Speech recognition (transcription of voice messages and in voice mode)EU (multi-region)Privacy
STACKIT (Schwarz Digits Cloud GmbH & Co. KG)Operation of the real-time audio infrastructure for voice mode (media server)Germany (EU)Privacy
Datadog, Inc.Infrastructure monitoringEU operation/regionPrivacy
PostHog, Inc.Product analyticsEU operation/regionPrivacy
Langfuse GmbHLLM observability, quality assuranceGermany (EU)Privacy
Proton AGQuality assuranceSwitzerlandPrivacy
Expo (650 Industries, Inc.)Delivery of push notifications (mobile apps)USAPrivacy
Apple Inc.Sign in with Apple (single sign-on); delivery of push notifications on iOS (Apple Push Notification service)USAPrivacy
Google Ireland Limited / Google LLCSign in with Google (single sign-on); delivery of push notifications on Android (Firebase Cloud Messaging)Ireland (EU) / USAPrivacy
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing at checkoutIreland (EU) / USAPrivacy

(All information as of: 05/09/2026)

2) Channels

We provide you with access to our applications through the following channels:

2.1 Web app and mobile apps (iOS and Android)

We provide Aury through a web app (in the browser) and through mobile apps for iOS and Android. In this Privacy Policy we refer to these access channels collectively as "the application". The processing described in this Privacy Policy applies equally to all of them.

  • Hosting of the application & infrastructure: Scalingo SAS as hosting provider; server operation via Outscale SASU (a brand of Dassault Systèmes SE) in France (EU). The mobile apps use the same infrastructure as the web app. The real-time audio infrastructure for voice mode (section 3.4) additionally runs on servers of STACKIT (Schwarz Digits Cloud GmbH & Co. KG) in Germany (EU).
  • Storage & processing of personal data: exclusively within the EU/EEA and — for the quality assurance described in section 5 — in Switzerland.
  • AI-powered features (model hosting): Microsoft Azure Cloud (EU Data Zone) and Google Vertex AI (EU Data Zone).
  • Third-country transfer: Your conversation content is processed exclusively within the EU/EEA and — for the quality assurance described in section 5 — in Switzerland. The European Commission has issued an adequacy decision for Switzerland under Art. 45 GDPR; the level of data protection is therefore equivalent to that of the EU. The only information transferred to the USA is what three clearly delimited features require: the delivery of push notifications in the mobile apps (6.3), signing in with Apple or Google (7) and checkout (8), all three in this section “The Application”. Each of these three features is optional for you: you do not have to enable push, the email sign-in route remains permanently available, and no checkout takes place unless you book a paid service. Conversation content is never affected by these transfers. No further transfers of personal data to third countries take place in connection with the application.

3) Hosting & AI infrastructure

These details describe our technical service providers ("processors") for hosting and AI features. For the prevention offering "Digitale Stressbewältigung mit Aury", processing takes place exclusively within the EU/EEA and — for the quality assurance described in section 5 — in Switzerland, for which an adequacy decision of the European Commission under Art. 45 GDPR exists. Transfers to other third countries are excluded there.

3.1 Application hosting (website & Aury application including the prevention offering)

Our website and our applications (web app and mobile apps, including the prevention offering "Digitale Stressbewältigung mit Aury") as well as the associated infrastructure (e.g., user management, database, backups, system logs) are operated by Scalingo SAS (hosting provider) using servers of Outscale SASU (a brand of Dassault Systèmes SE) as infrastructure provider exclusively in France (EU).

Data processed:

IP address, technical protocol/log data (e.g., timestamps, device/browser information), account/contact details (e.g., email; name, if provided), as well as content/information that you enter in the application, insofar as it is stored for usage purposes.

Purposes:

Operation and provision of the website/application, IT security, error/performance analysis, abuse and disruption prevention.

Legal basis:

Art. 6(1)(b) GDPR (provision/use of the application) and Art. 6(1)(f) GDPR (security, stability, abuse prevention).

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

Log/system data generally up to 180 days (security/error analysis), thereafter deletion/anonymization unless statutory obligations prevent it. Account and usage data stored in the application generally until deletion of the account or as long as required for usage.

3.2 AI model hosting in the EU (application including the prevention offering)

For AI-powered features in the application (including the prevention offering "Digitale Stressbewältigung mit Aury") we use model hosting in EU data zones at:

  • Microsoft Azure (EU): https://www.microsoft.com/de-de/privacy/privacystatement (as of 26.02.2026)
  • Google Vertex AI (EU): https://cloud.google.com/privacy/gdpr?hl=de (as of 26.02.2026)

Training:

Google does not process customer data on Vertex AI for training/fine-tuning without prior permission/instruction.

For Azure-based GenAI services, it is likewise described that content is not used for training and may be temporarily stored for security/abuse monitoring.

Data processed:

We transmit to the model hosts the content of your messages together with the context Aury needs in order to give a meaningful reply:

  • your conversation history so far and summaries of earlier conversations,
  • the name you give us, your language setting and your time zone,
  • a short profile that Aury derives from your conversations (e.g., your concern, your goal, details that matter to you, and your feedback about Aury),
  • your progress in courses and methods, and reminders you have set up.

This information may contain health data (see section 1, "Important information on sensitive data (health data)").

Your email address, your login credentials and your payment data are not transmitted.

Purposes:

Generating responses for chatting with Aury.

Legal basis:

Art. 6(1)(b) GDPR (provision of AI features as part of the application). Where health data is involved, additionally Art. 9 GDPR (see section on "sensitive data/health data").

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

Depending on the provider/service, content is temporarily stored for service assurance and abuse/security monitoring (typically up to 30 days) and subsequently deleted, unless statutory obligations prevent it.

3.3 Speech recognition (voice messages)

When you send Aury a voice message, the recording is automatically converted into text (transcription). Only that text is processed further — exactly like a typed message.

Service provider:

Google Cloud Speech-to-Text, EU multi-region. The recording is processed exclusively within the European Union.

Data processed:

The audio recording of your voice message, the text generated from it, technical details of the recording (e.g., duration, format) and your language setting (German or English), so that recognition is more accurate. Voice messages may contain health data.

What explicitly does not happen:

There is no voice identification — we do not identify you by your voice. There is no biometric analysis and no detection of emotions or moods from your voice. Only what you say is processed — not how it sounds.

Voluntary use:

Voice input is an additional option. All features remain fully usable by typing.

Purposes:

Converting your voice message into text so that Aury can respond to it.

Legal basis:

Your explicit consent under Art. 9(2)(a) GDPR, as voice messages may contain health data. You give it together with your consent to data processing before first use; voice input is expressly named there. Processing under this section only takes place if you actually send a voice message.

Training:

The content is not used to train or improve AI models.

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

We do not store the audio recording: it is processed only for the duration of the conversion and then discarded. Only the generated text is stored permanently, as part of your conversation history; the storage periods in section 3.1 apply to it. According to the provider, the recording and the text are not stored on their side after conversion either.

3.4 Voice mode (real-time voice conversation)

In voice mode you speak with Aury in real time. For the duration of the session there is a continuous audio connection: your spoken input is converted into text as you speak (speech recognition), that text is processed by the same dialogue logic as a typed message, and Aury's reply is played back to you as speech (speech synthesis). Voice mode is different from the voice message described in section 3.3.

Service providers:

Real-time audio infrastructure (media server) for the audio connection: STACKIT (Schwarz Digits Cloud GmbH & Co. KG), data centre in Germany. On that server we operate the open-source software LiveKit ourselves; no LiveKit cloud service is used. Speech recognition: Google Cloud Speech-to-Text, EU multi-region (as in section 3.3). Speech synthesis: Microsoft Azure Speech, Azure region Germany (Germany West Central). The dialogue logic itself runs on the same infrastructure as the rest of the application (section 3.1). Processing takes place exclusively within the European Union.

Data processed:

Your audio stream during the voice session, the text generated from it as you speak, Aury's reply text and the reply audio generated from it, plus technical connection data (e.g., timestamps and connection quality) and your language setting (German or English) so that recognition is more accurate. What you say in voice mode may contain health data.

What explicitly does not happen:

There is no voice identification — we do not identify you by your voice. There is no biometric analysis and no detection of emotions or moods from your voice. Only what you say is processed — not how it sounds.

Voluntary use:

Voice mode is an additional option and is being made available gradually. It starts only when you start it yourself and grant your browser microphone permission; if you decline, you can continue in writing without any restriction. Every feature is also fully available in text form.

Purposes:

Conducting a spoken dialogue with Aury: converting your spoken input into text, generating the reply and playing it back as speech.

Legal basis:

Your explicit consent under Art. 9(2)(a) GDPR, as what you contribute in voice mode may contain health data. You give it together with your consent to data processing before first use. Processing under this section only takes place if you actually use voice mode.

Training:

The content is not used to train or improve AI models.

Third-country transfer:

No transfer of data to third countries takes place.

Storage period:

We do not store the audio: it is processed only for the duration of the voice session and then discarded; the media server records nothing. Only the conversation in text form — the text recognised from your speech and Aury's replies — is stored permanently as part of your conversation history; the storage periods in section 3.1 apply. According to the providers, neither the recording transmitted for speech recognition nor the text transmitted for speech synthesis is stored on their side.

4) Information pursuant to the EU AI Act

When you chat with Aury, you are interacting with an AI-powered system, not a human.

Aury is designed to provide general support and information on mental well-being. Aury is not a substitute for professional (psycho-)therapeutic, medical, or psychological diagnosis or treatment.

Important notes on usage:

  • AI responses may be inaccurate, incomplete, or biased. Do not use them as the sole basis for important decisions, especially in health matters.
  • If you are in an acute crisis or believe you or others are at risk: please contact local emergency/crisis services.

Reporting problematic responses:

  • By email to support@aury.co.

Note: Aury is not intended to perform emotion recognition or biometric categorization.

5) Analytics and tracking

We only use analytics and product optimization tools if you have explicitly consented (opt-in).

Data processed (with opt-in):

  • Usage data (e.g., timestamps, duration, features used)
  • Technical events (e.g., error codes)
  • Pseudonymized usage identifier, where applicable
  • Anonymized or heavily pseudonymized excerpts from interactions (e.g., for quality measurement), where technically provided, where applicable

Recipients / service providers:

The data is transmitted in pseudonymized form to the following processors. Processing takes place in the EU; in the case of Proton AG it takes place in Switzerland (adequacy decision of the European Commission under Art. 45 GDPR):

  • DataDog, Inc. (EU operation/region): https://www.datadoghq.com/legal/privacy/ (as of 26.02.2026)
  • PostHog, Inc. (EU operation/region): https://posthog.com/privacy (as of 26.02.2026)
  • Langfuse GmbH: https://langfuse.com/privacy (as of 26.02.2026)
  • Proton AG: https://proton.me/legal/privacy (as of 26.02.2026)

Legal basis:

  • Art. 6(1)(a) GDPR (consent)
  • Insofar as terminal device access/cookies are concerned: Section 25(1) TDDDG (consent)

Withdrawal:

You may withdraw your consent at any time with effect for the future.

Storage period:

  • Usage data: generally up to 180 days after last activity
  • Pseudo-/anonymized interaction excerpts, where applicable: generally up to 7 days or until your deletion request

6) Reminders and marketing

We only contact you if it is necessary for the provision of the service (service messages) or if you have consented (e.g., newsletter).

6.1 Service messages (no marketing)

We may send you necessary messages regarding usage (e.g., security/feature notices, confirmations).

Legal basis: Art. 6(1)(b) GDPR (contract) and, where applicable, Art. 6(1)(f) GDPR (security).

6.2 Reminders from Aury (only when activated)

Aury can send you reminders that you have actively set up (e.g., during onboarding). You can stop them at any time via your settings in the application.

Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) GDPR (if part of a feature you activated).

In the mobile apps, reminders are delivered as push notifications (see section 6.3).

6.3 Push notifications (mobile apps)

In the mobile apps for iOS and Android you can enable push notifications. In addition to your consent, your device asks for permission; only then do notifications reach you. The web app does not send push notifications.

In the prevention offering “Digitale Stressbewältigung mit Aury”, too, push notifications reach you only in the mobile apps and only if you have enabled them; the web app is never affected. Reminders for course sessions that you set up yourself are additionally scheduled by the application on your device; no transfer to third parties takes place for that.

Service provider:

Delivery is handled by Expo (650 Industries, Inc., USA). From there the notification is passed to your operating system’s push service — Apple Push Notification service on iOS, Google Firebase Cloud Messaging on Android.

Data processed:

A push token that your device generates for our app, an internal identifier for your user account, the type of notification, and the notification text displayed. We store the push token in your user account.

Content of the notification:

The notification contains only a general prompt — for example "Aury has sent you a new message" or "Your session starts in 15 minutes". No content from your conversations is transmitted, and none appears on your lock screen.

Purposes:

Letting you know that Aury has written to you, or reminding you of a session you have set up.

Legal basis:

Art. 6(1)(a) GDPR (consent). You can switch push notifications off at any time in your device or app settings; the permission applies going forward only.

Third-country transfer:

The information listed above is transferred to the USA for delivery. Content from your conversations is not affected. Expo states that it participates in the EU-U.S. Data Privacy Framework.

Storage period:

We store the push token for as long as you have push notifications enabled. If it becomes invalid — for example because you uninstall the app — we delete it from your user account. We do not store the notification itself.

6.4 Newsletter

If you subscribe, we will send you updates and information about Aury. You can unsubscribe at any time via the link in each email or via support@aury.co.

Legal basis: Art. 6(1)(a) GDPR (consent).

6.5 User surveys

We may invite you (with your consent) to participate in voluntary surveys.

Legal basis: Art. 6(1)(a) GDPR (consent).

6.6 Storage period

We store contact information and preferences until you withdraw your consent. After withdrawal, we delete them unless retention is necessary for evidentiary purposes.

7) Registration and sign-in (account)

You need an account to use Aury. There are two routes and you are free to choose between them:

  • Sign in by email: you enter your email address and confirm it with a six-digit code that we send you by email. No password is required. This route is permanently available and works without an Apple or Google account.
  • Sign in with Apple or Google (single sign-on): you sign in with an account you already hold with Apple or Google. This is an additional option — you do not have to use it, and it unlocks no feature that email sign-in would keep from you.

Service providers:

Apple Inc. (Sign in with Apple) and Google Ireland Limited / Google LLC (Sign in with Google). The sign-in itself runs at the provider you choose; we receive only the information listed below.

Data processed:

When you sign in with Apple or Google, the provider transmits to us a persistent identifier for your account with them and an email address — with Apple, at your choice, a relay address generated by Apple, so that your actual address never becomes known to us. With Apple, the name you release there may also be transmitted. We store this information in your Aury account so we can recognise you the next time you sign in. At the provider itself, further data arises that it needs in order to verify your sign-in (e.g. time, device, IP address); we have no influence over that.

Purposes:

Setting up and securing your account, and recognising you on your next sign-in.

Legal basis:

Art. 6(1)(b) GDPR (providing the account as part of the application). Which sign-in route you take is your decision.

Third-country transfer:

If you sign in with Apple or Google, data is transferred to the USA in the process. Apple and Google base these transfers on the European Commission's standard contractual clauses and/or on certification under the EU-U.S. Data Privacy Framework; the details are set out in their privacy notices linked above. Conversation content is not transferred.

If you would rather not:

Use email sign-in. It is available to you at any time and permanently, offers the same functionality, and involves no transfer to the USA. For signing in with Apple or Google itself there is no equivalent alternative: anyone who wants to sign in with their Apple or Google account can only do so through those providers' services, and therefore only with a transfer to the USA.

The providers' own controllership:

For the processing inside their own services — that is, for verifying your sign-in and for obtaining our apps from the App Store or Google Play — Apple and Google are independent controllers. Their own privacy notices apply to that extent.

8) Checkout and payment

Paid services are handled through the payment service provider Stripe. For as long as the prevention offering “Digitale Stressbewältigung mit Aury” is undergoing certification, it is free of charge and nothing can be purchased in the application; no checkout takes place in that case.

Service provider:

Stripe Payments Europe, Ltd. (Ireland) for payments in the European Economic Area, together with its affiliate Stripe, Inc. (USA).

When Stripe is loaded:

Only once you start a checkout. Before that, no Stripe component is loaded and no Stripe cookie is set.

Data processed:

The payment details you enter in the payment form (e.g. card details) are processed by Stripe directly; we neither see nor store them. In addition, the amount, the service booked, your email address and technical information about your device including your IP address are transmitted to Stripe. From Stripe we receive a payment and customer identifier and the status of the payment.

Cookies:

For the checkout, Stripe sets its own cookies, including “__stripe_mid” with a lifetime of one year. They serve fraud prevention and are necessary for the secure handling of the payment.

Purposes:

Handling the payment, fraud prevention, and meeting commercial and tax-law obligations.

Legal basis:

Art. 6(1)(b) GDPR (performance of the contract), Art. 6(1)(c) GDPR (statutory retention and record-keeping duties) and Art. 6(1)(f) GDPR (fraud prevention). For the cookies necessary to process the payment: Section 25(2) TDDDG.

Third-country transfer:

Data may be transferred to the USA in the process. Stripe bases these transfers on the European Commission's standard contractual clauses and/or on certification under the EU-U.S. Data Privacy Framework; the details are set out in Stripe's privacy notices linked above. Conversation content is not transferred. If you do not book a paid service, none of this processing takes place.

Storage period:

We retain payment and invoice data for the periods required by commercial and tax law (as a rule up to ten years). Stripe's own privacy notices apply to storage at Stripe.

The Website

The following sections concern visits to our website (aury.co). The processing activities described here may involve third-country transfers and are independent of the application processing described in sections 2 and 3.

1) Server log files and website delivery

When you visit our website, we process server log data that is technically necessary to deliver and protect the website.

Data processed: IP address, date/time, page accessed, referrer URL, browser/OS, status codes, data volume.

Purposes: Delivery, IT security, error analysis, abuse prevention.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Storage period: Generally up to 180 days (security/error analysis), thereafter deletion or anonymization.

2) Cookies and consent management

We use (i) technically necessary cookies or similar technologies and (ii) optional technologies (e.g., analytics) only after consent.

  • Technically necessary: Required for the function you have expressly requested. Legal basis: Section 25(2) TDDDG; Art. 6(1)(f) GDPR (or Art. 6(1)(b) GDPR, depending on the function).
  • Optional (e.g., analytics): Only after opt-in. Legal basis: Section 25(1) TDDDG; Art. 6(1)(a) GDPR.

You can change your selection at any time via the consent tool or browser settings (where available).

3) Web analytics (Google Analytics)

If you consent, we use Google Analytics (Google LLC). This may involve transfers to the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework.

Data processed: Online identifiers (e.g., cookie IDs), device/browser data, usage data, truncated IP address (where enabled).

Purposes: Reach measurement, website optimization.

Legal basis: Art. 6(1)(a) GDPR (consent) and Section 25(1) TDDDG.

Third-country transfer: Transfers to the USA on the basis of the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission).

Storage period: According to settings in Google Analytics (configuration).

https://policies.google.com/privacy (as of 26.02.2026)

Customer Service and Inquiries

When you contact us, we process your information to handle the inquiry.

Data processed: Email, name (if provided), content of the message, IP address and metadata where applicable.

Purpose: Handling and responding to your inquiry.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or Art. 6(1)(f) GDPR (general communication).

Storage period: Up to 180 days after completion, unless longer retention is required.

Social Media

1) LinkedIn

We operate a company profile on LinkedIn. Provider: LinkedIn Ireland Unlimited Company.

LinkedIn processes personal data as an independent controller; processing may also take place in third countries (e.g., USA).

Communication via LinkedIn: If you contact us via LinkedIn, we process the data you provide to respond.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) or Art. 6(1)(f) GDPR (communication).

Storage period: As required; additionally, the platform's deletion/storage policies apply.

Page Insights / joint controllership: For so-called "Page Insights", we are jointly responsible with LinkedIn (Art. 26 GDPR). Within the scope of Page Insights, LinkedIn processes aggregated statistics about the use of our company page (e.g., page views, demographic characteristics of visitors, interactions with posts).

  • Agreement ("Joint Controller Addendum"): https://legal.linkedin.com/pages-joint-controller-addendum
  • LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy

Job Applications

If you apply to us (via email, form, or through platforms), we process your application data to carry out the recruitment process.

Data processed: Master data (name, contact details), application documents (CV, certificates), communication, salary expectations/start date where applicable; special categories (e.g., health data) only if you provide them voluntarily and to the extent permitted.

Purposes: Review and selection, communication, establishment of an employment relationship.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures); where applicable, Art. 6(1)(f) GDPR (legal defense). Where special categories are involved: Art. 9(2)(a) GDPR (explicit consent) or Art. 9(2)(b) GDPR (where required under employment law).

Recipients: Internal HR/recruiting staff; processors where applicable (e.g., email/hosting). Platform providers (e.g., LinkedIn) may be independently responsible.

Storage period: In the event of rejection, we generally delete application data within 180 days after completion of the process (including for defense against potential claims). In the event of hiring, relevant data is transferred to the personnel file and stored in accordance with statutory requirements.

Talent pool: Only with your consent; withdrawal possible at any time.

Business Contacts (B2B)

If you contact us as a representative of a company (e.g., via email, events, sales conversations), we process contact data for communication and contract initiation.

Data processed: Name, professional contact details, position, communication content.

Purpose: Communication, proposal preparation, contract initiation/performance.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) and/or Art. 6(1)(f) GDPR (legitimate interest in business communication).

Storage period: As long as required; business correspondence and contract-related communication may be retained under commercial/tax law requirements (up to 10 years).

Try it out: