Legal
Privacy policy
What happens to your data when you visit this website, write to us, ask the chat assistant or use OTP-Link. This English version is provided for convenience. The German version is legally binding.
Last updated: 3 October 2026
01Key points at a glance
- This policy applies to all pages under aevum-intelligence.de/.
- We do not use any analytics, tracking or advertising tools, and we do not set any cookies ourselves.
- We serve fonts and scripts ourselves through our hosting at Cloudflare. When you visit, no data goes to Google Fonts, third-party script or font services, or social networks.
- We only process personal data to deliver the site, show your approximate city, answer your enquiry, prevent abuse, run the OTP-Link tool, answer your questions in the chat, improve the website based on unanswered chat questions and meet statutory retention obligations.
- We do not store your IP address or your location. The only exception is the chat assistant: for its rate limiter, it stores a check value for no more than three days, derived from your IP address and different every day (Section 08). As our processor, Cloudflare retains access data for a certain period (Section 03).
- Hosting, the chat assistant and email delivery run through service providers in the USA, and our mailbox is with Google (Sections 10 and 11).
- Access, erasure, objection: an informal email to info@aevum-intelligence.de is enough (Sections 12 and 13).
02Controller
Aevum IntelligenceOwner: Dmitrij Stavropolskij
Wiener Str. 63
60599 Frankfurt am Main
Germany
Email: info@aevum-intelligence.de
The law does not require us to have a data protection officer (Section 38 of the German Federal Data Protection Act), so we have not appointed one. We answer questions about data protection at the address above.
03Visiting the website and hosting
The website is hosted by Cloudflare (Cloudflare, Inc., USA). Cloudflare acts as our processor, which means it works only on our instructions, on the basis of a contract under Art. 28 GDPR.
Data: your IP address, the date and time, the address requested, the page visited before (referrer), browser and operating system (user agent) and the response code.
Purpose: to deliver the site, keep operations stable and fend off attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is a secure, fast and functioning website.
Retention period: We do not analyse or store any access logs ourselves. According to Cloudflare, it keeps the data for at least 31 days for analytics on requests and security events (as of October 2026).
04Showing your approximate city
On the home page, we show the approximate city you are visiting the site from.
Data: the approximate city as well as the latitude and longitude, which Cloudflare derives from your IP address. Our server writes these three values only into the page that is sent to your browser. There is no external location service and no location request in your browser.
Purpose: a more personal page design: the town sign and the globe that turns to your city.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is this more personal design. The information is coarse, Cloudflare already has it for delivering the page, and we discard it after delivery. You can object (Section 13).
Retention period: none. We do not store the values, do not pass them on and do not create a profile. The page is not cached, so that nobody else sees your city.
05Contact form and email
Data: what you enter in the form, that is, your name, your phone number or email address and your message. If you email us directly, your email address and the content.
How your message travels: Your browser sends the details to our service at Cloudflare. The service does not store them but passes them on to the email delivery service Resend, which delivers them as an email to our mailbox. Our mailbox is with Google (Gmail).
Purpose: to answer your enquiry.
Legal basis: Art. 6(1)(b) GDPR if your enquiry is aimed at concluding a contract. Otherwise Art. 6(1)(f) GDPR, in which case our legitimate interest is answering enquiries. For retention after an order, Art. 6(1)(c) GDPR. You can object to processing under point (f) (Section 13).
Retention period: We delete your enquiry as soon as it has been dealt with. If it leads to an order, we keep records for as long as tax law requires: business letters for six years, invoices and other accounting documents for eight years, in each case from the end of the calendar year (Section 147 of the German Fiscal Code). Resend stores sent emails for 30 days, and backups exist there for no more than 7 further days.
Voluntary: You do not have to tell us anything. Without your name, a way to reach you and a message, however, we cannot reply to you.
06Protection against abuse
So that nobody floods the contact form or OTP-Link with automated requests, our service passes your IP address to Cloudflare’s rate limiter. It counts the requests per IP address within a one-minute window. In addition, a field in the form that humans cannot see keeps bots out.
Data: your IP address, only as a counting key. We also count in a database how many messages and links are created per day in total, without reference to any individual.
Purpose: protection against spam, abuse and overload.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is this protection.
Retention period: We ourselves do not store your IP address in this process. The counters at Cloudflare only cover the current one-minute window.
07OTP-Link tool
With OTP-Link, you share a password or another confidential message via a link that only works once. The message is encrypted in your browser. After the “#” character, the link contains the link’s identifier, part of the key and the encrypted content. The browser never sends the key part or the content to a server.
Data: When you create a link, the page sends our service at Cloudflare only the validity period you chose. When the link is opened, the identifier and, where applicable, the check value go to the service (for the IP address, see Section 06). For each link, it stores the identifier, the expiry time, the number of failed attempts and, where applicable, the hash of the check value. It does not store the content, your IP address or the time the link was opened.
Purpose: to provide the one-time link and make it unusable once it has been opened.
Legal basis: Art. 6(1)(b) GDPR, because you use the free tool. For the rate limiter, Section 06 applies.
Retention period: The entry is deleted as soon as the link is opened or revoked, or after five failed attempts at the additional password. An hourly clean-up run deletes expired entries (validity of one week at most). Cloudflare automatically keeps a recovery history of no more than 30 days for the database. This does not contain any content either, and we never restore data from it.
Without the full link, we cannot read what you write in the message. Only share other people’s data if you are entitled to do so.
08Chat assistant
On the home page, a chat assistant answers questions about Aevum Intelligence. It is an AI, not a human, and only answers from the content of this website: the home page, the legal notice and this privacy policy. Its answers may contain errors. The pages themselves and our reply to your enquiry are binding.
Data: your question, up to four previous questions and answers from the same conversation so that follow-up questions still make sense, and your IP address.
How your question travels: Your browser sends it to our chat service at Cloudflare. There, a language model (Gemma 4 by Google) generates the answer via Cloudflare’s Workers AI service. According to Cloudflare, it does not use the content to train AI models. So that nobody floods the chat, the service counts the questions per visitor. To do this, it uses a secret key to create a check value from your IP address, and this value changes every day. It does not store the IP address itself. Section 03 also applies to the access data at Cloudflare.
Unanswered questions: If the assistant cannot answer a question from the website, we store it together with the previous question, the assistant’s answer and the time, without the IP address and without the check value. Before that, we redact any phone numbers and email addresses in it. This shows us what is still missing from the website.
Purpose: to answer your questions about our services, improve the website based on unanswered questions and protect the service from abuse and overload.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is exactly this purpose. You can object (Section 13).
Retention period: We delete the check value after three days at the latest, and unanswered questions after 90 days. A daily clean-up run takes care of both. We do not store answered questions or the answers to them. Cloudflare automatically keeps a recovery history of no more than 30 days for the database; we never restore data from it. Only your browser stores the history in the chat window, and only until you close the tab (Section 09).
Voluntary: You do not have to use the chat; everything is also on the website. Please do not enter personal data such as names, phone numbers or health information in the chat. For a personal enquiry, use the contact form.
09Storage in your browser
Cookies: We do not set any. There is no cookie banner because this website does not store anything in your browser that would require your consent. Cloudflare may set a security cookie to protect against bots, for example “cf_clearance” after you pass a security check or “__cf_bm” for bot detection. It is technically necessary and permitted without consent (Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG).
List in the OTP-Link tool: Only this page uses your browser’s local storage, for the list “Your links on this device”.
- What is stored on your device: for each link, the identifier, creation and expiry time and the status, for older entries also your note, never the content or the key.
- What goes to our service: when you open the page, only the identifiers of your links, so that the list shows their current status; when you revoke a link, only the identifier of that one link. The service does not store the request.
- When it disappears: The page removes entries whose link expired more than 30 days ago the next time you open it.
- How to delete it: via “Clear list”, on the page Cookies and storage or in your browser settings.
Technically, this is localStorage with the key “aevum-otp-links”. When you open the page to create a link, it briefly creates a test entry and deletes it again immediately to check whether your browser allows the storage.
History in the chat assistant: So that the conversation is not lost when you reload the home page, the chat window stores your questions and its answers in your browser’s session storage (sessionStorage, key “aevum-chat-v1”, at most the last twelve). The history disappears as soon as you close the tab. Of this, only the last four pairs go to our service when you ask your next question (Section 08).
Home page without the intro: If the language button (EN/DE) or a link on one of the subpages takes you to the home page, the site stores the destination and the time for this one switch in your browser’s session storage (sessionStorage, key “aevum-ohne-lader”). The home page reads the entry when it loads, deletes it straight away and then does not show the intro animation again; after 15 seconds the entry no longer counts. It is gone at the latest when you close the tab. It contains no personal data and never leaves your browser.
Legal basis: Access to the storage is strictly necessary for the function you have requested (Section 25(2) No. 2 TDDDG). The processing of the data is based on Art. 6(1)(b) GDPR for OTP-Link and on Art. 6(1)(f) GDPR for the chat assistant. The entry for the home page involves no personal data.
See for yourself: The page Cookies and storage shows which of these entries are in your browser right now. You can also remove them there.
10Recipients
Cloudflare and Resend act as processors for us. Google is not a processor but processes the emails under its own responsibility. Beyond that, we only pass on data if a law requires us to.
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA
Hosting, server functions, database, abuse protection, the chat assistant’s language model (Workers AI). Processor under Art. 28 GDPR.
Plus Five Five, Inc. (Resend)
2261 Market Street #5039, San Francisco, CA 94114, USA
Sending the emails from the contact form. Processor under Art. 28 GDPR.
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Our email inbox (Gmail, private account). There is no contract under Art. 28 GDPR for this. Google processes the emails as an independent controller under its terms, including at Google LLC in the USA.
11Transfer to the USA
Cloudflare and Resend are based in the USA. The transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795, Art. 45 GDPR). Both companies are certified under it, which you can verify at dataprivacyframework.gov.
With Resend, the European Commission’s standard contractual clauses have also been agreed (Implementing Decision (EU) 2021/914, Art. 46(2)(c) GDPR). The contract with Cloudflare provides for them in case a transfer does not fall under the Data Privacy Framework. Both arrangements are part of the data processing agreements linked above.
Google Ireland transfers emails under its own responsibility to Google LLC in the USA, which is also certified under the Data Privacy Framework.
12Your rights
You have the right to
- access the data we process about you (Art. 15 GDPR),
- rectification of incorrect data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object (Art. 21 GDPR, see Section 13).
An informal email to info@aevum-intelligence.de is enough. We do not store your location. We have no access to individual IP addresses in the access data at Cloudflare. Stored chat questions contain no IP address, and a name only if you write it in yourself. Without further information, we cannot attribute either of these to you. For this data, the rights under Art. 15 to 20 GDPR therefore only apply if you give us information that makes such attribution possible, such as the time and wording of your question (Art. 11(2) GDPR).
13Right to object
You can object at any time. An informal email to info@aevum-intelligence.de is enough.
If we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). This applies to hosting (03), the display of your city (04), enquiries not related to a contract (05), protection against abuse (06) and the chat assistant (08).
We will then no longer process the data, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
14Complaint to a supervisory authority
You can lodge a complaint with any data protection supervisory authority, in particular in the EU member state where you usually reside or work, or where the alleged infringement took place (Art. 77 GDPR).
The supervisory authority responsible for us is in Hesse:
The Hessian Commissioner for Data Protection and Freedom of InformationWilhelmstraße 7
65185 Wiesbaden
datenschutz.hessen.de
15Further information
- Obligation to provide data: No law and no contract obliges you to give us data. However, the page cannot be delivered without an IP address, and without a way to contact you we cannot reply.
- No automated decision-making: We do not make decisions based solely on automated processing and do not create profiles (Art. 22 GDPR).
- Security: The connection to the website is encrypted with TLS (recognisable by “https”), and requests via “http” are redirected. OTP-Link additionally encrypts messages in your browser.
- Changes: We update this policy when the website, our service providers or the legal situation change. The version published here applies.