Skip to content

Artificial intelligence is changing digital products. See what it can do for your business.

Last updated 24 August 2026

Privacy Policy

1. Controller

Dominik Weber, SimplifyVision
Jöllenbecker Str. 143, 33613 Bielefeld, Germany
Email: [email protected]
Phone: +49 521 44812504

2. Principles and legal bases

We process only data needed for website operation, communication, pre-contract steps and service delivery. Legal bases include GDPR Art. 6(1)(b) for contract steps, (c) for legal obligations, (f) for secure economic operation and B2B communication, and (a) for consent, particularly optional analytics.

3. Website operation and logs

When the site is accessed, infrastructure processes IP address, time, requested address, status, transferred volume and browser/system information under GDPR Art. 6(1)(f). Our legitimate interests are secure, stable and error-free delivery and attack detection. Security logs are normally retained for no more than 14 days unless a concrete incident requires longer retention for investigation or legal claims. The website and managed infrastructure may be operated with netcup in German data centers.

4. Contact and digital check

For contact and the digital check, we process name, company, contact details, industry, optional messages and calculator values under GDPR Art. 6(1)(b) where the request concerns a contract, otherwise Art. 6(1)(f) and our interest in handling business inquiries. The estimate uses affected people × manual hours × internal hourly cost × 46 weeks. The 25–50% range is not a guarantee. Data is sent by SMTP to the SimplifyVision mailbox and is not stored in a website database. Unsuccessful inquiries are normally deleted twelve months after the last contact.

5. Offer check and upload

Under GDPR Art. 6(1)(b), we process contact details, offer date, message and an uploaded PDF, JPG or PNG up to 10 MB. Files are checked in memory and not stored on the web server. They are delivered to our mailbox by SMTP. Files for projects that do not proceed are normally deleted no later than 30 days after review; related correspondence after twelve months unless claims or legal duties require longer retention.

6. Hosting order and contract

For B2B hosting orders, we process plan, application care, billing, company and contact details, address, VAT ID, domain and technical notes under GDPR Art. 6(1)(b) and (c). Data is used for review, acceptance, provisioning, invoicing and support. Accounting vouchers are normally retained for eight years and commercial correspondence for six years from the end of the relevant calendar year; longer retention applies where records remain relevant for tax, legal claims or statutory evidence. Operational application data is processed under a data processing agreement.

7. Email and SMTP

Form content, confirmations and references are sent through SimplifyVision’s configured business mailbox. The mail provider processes sender, recipient, timing, delivery information and message content as processor. The legal basis follows the communication purpose under GDPR Art. 6(1)(b) or (f). Credentials remain in protected runtime configuration. The specific mail provider must be added here before form delivery is activated.

8. Cookies, Google Tag Manager, Analytics and Ads

Necessary consent storage records and controls your choice under TDDDG § 25(2) and GDPR Art. 6(1)(f). Google Tag Manager and configured Google Analytics 4 or Google Ads measurement load only when an ID is configured and you consent under TDDDG § 25(1) and GDPR Art. 6(1)(a). Google Ireland Limited and Google LLC may then receive device, usage, event and campaign data. US transfers may rely on the EU–US Data Privacy Framework and, additionally, standard contractual clauses. Consent can be withdrawn at any time. Without consent, no analytics or Ads conversion events are fired. Specific Google services, identifiers, retention periods and cookies will be added before activation.

9. WebChatAgent and AI transparency

A WebChatAgent AI assistant is embedded. Loading the widget may process IP address, browser information, page and time; the chat additionally processes messages, responses and contact details you provide. The assistant generates automated replies but does not make decisions with legal or similarly significant effects. Chat replies do not create binding declarations or contracts. Do not enter special-category data or confidential credentials.

10. Recipients

Data is available only to people and providers that need it for operations, email, infrastructure, contracts or analytics. These may include netcup as hosting processor, the business mail provider to be named, WebChatAgent and the configured AI model provider, and—only with consent—Google. Processing agreements are used where required. The specific model provider and processing location must be added before production chat use.

11. Required data, automated decisions and your rights

Fields marked as required are needed to handle the relevant request or order; without them it cannot be processed. No solely automated decision within GDPR Art. 22 takes place. Subject to the GDPR, you have rights of access, rectification, deletion, restriction and portability. You may object under GDPR Art. 21 to processing based on Art. 6(1)(f) for reasons arising from your particular situation. Consent may be withdrawn. You may complain to a supervisory authority, particularly the North Rhine-Westphalia data protection authority.

12. Security and changes

We use access restrictions, encryption, updates, logging and backups appropriate to risk. This policy is updated when services, law or processing materially changes.