Privacy policy
Last updated: 2026-09-16
This policy explains what we collect, why, and what your rights are under the GDPR. It is deliberately short, because we collect very little.
Who is responsible
The controller for the purposes of the GDPR is the operator named in the imprint.
What we collect, and why
When you run the AI readiness audit. We first send a six-digit code to the address you enter, to confirm it is yours — nothing is generated until you enter that code. We then process the answers you give, plus the email address and company name you supply, in order to generate and send you the report. The answers are sent to our language-model provider (OpenRouter, routing to the model named in our configuration) purely to produce your report; they are not used to train any model. We keep the submission so we can follow up on it. Legal basis: Article 6(1)(b) — steps taken at your request prior to entering a contract — and Article 6(1)(f), our legitimate interest in responding to business enquiries.
When you email us. We process your message and address in order to reply. Legal basis: Article 6(1)(f).
When you visit the site. Our host processes standard server request data (IP address, user agent, requested URL, timestamp) to deliver the site and keep it secure. We use privacy-friendly, cookieless analytics that does not track you across sites and does not build a profile of you. Legal basis: Article 6(1)(f).
What we do not do
We do not set advertising or tracking cookies. We do not sell or share your data with advertisers. We do not add you to a marketing list because you ran an audit — if you get an email from us that you did not ask for, it will be a person writing to you about your enquiry, and you can tell us to stop.
Storage in your browser
The audit stores your in-progress answers in your browser's sessionStorage so that a page refresh does not lose them. This never leaves your device, is not readable by us, and is cleared when you close the tab. Your language preference is stored in a NEXT_LOCALE cookie so the site remembers which language you chose. Neither is used for tracking.
Processors
- Vercel Inc. — hosting and delivery
- Resend — transactional email
- OpenRouter — language-model routing for audit report generation
- Upstash — rate limiting
Where a processor is outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses.
How long we keep things
Audit submissions and email correspondence are kept for as long as needed to deal with your enquiry and to meet German commercial and tax retention obligations, then deleted.
Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to data portability. You also have the right to complain to a supervisory authority — in our case the Hamburgische Beauftragte für Datenschutz und Informationsfreiheit.
To exercise any of these, email us at the address in the imprint. We will respond within one month.