PRIVACY
Privacy policy.
This is a courtesy translation. The German version is legally binding.
1. Data protection at a glance
General information. The following gives a simple overview of what happens to your personal data when you visit this website or use the Alynivo chat assistant. Personal data is any data that can be used to personally identify you.
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. Their contact details can be found in the "Data controller" section of this privacy policy.
How do we collect your data?
Some data is collected when you provide it to us — for example, data you enter into the chat assistant or send us by email. Other data is collected automatically by our IT systems when you visit the website, in particular technical data such as browser, operating system, or time of access.
What do we use your data for?
Part of the data is collected to ensure the website is provided securely and reliably. Other data is used to answer your chat questions and to process other enquiries.
What rights do you have?
You have the right at any time to request information about the origin, recipients, and purpose of your stored personal data. You also have the right to request correction, blocking, or deletion of this data, as well as restriction of processing, data portability, and objection, subject to statutory provisions. You also have the right to lodge a complaint with the competent supervisory authority.
2. Data controller
The controller responsible for data processing on this website is:
Özgür Abuska
Mavilab Digitalagentur (operator of Alynivo)
Straße im Loh 21
63179 Obertshausen
Germany
E-Mail: hallo@alynivo.de
Phone: 0152 28365122
3. Hosting and server log files
Website. This website and its WordPress database are hosted by Spaceship, Inc. in a selected EU data centre. Spaceship is a US-based company; its data processing agreement and the EU Standard Contractual Clauses apply to processing and any required third-country transfers.
Alynivo API. The optional Managed AI endpoint at api.alynivo.de is operated in Germany by Alfahosting GmbH, Ankerstraße 3b, 06108 Halle (Saale), Germany.
When the website or API is accessed, technically necessary server logs are processed. These may include IP address, date and time, requested resource, amount of data transferred, browser type, operating system, and referrer URL. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure, stable, and error-free provision of the services. Data processing agreements are in place with the hosting providers.
4. Contacting us
If you contact us by email or phone, we process the information you provide in order to handle your enquiry and any follow-up questions. Depending on the enquiry, this may include your name, email address, phone number, and message. Processing is based on Art. 6(1)(b) GDPR where your enquiry relates to entering into or performing a contract. In all other cases, processing is based on our legitimate interest in efficiently handling enquiries under Art. 6(1)(f) GDPR. Your data remains with us until the purpose for storing it no longer applies, you ask us to delete it, or statutory retention obligations prevent this.
5. AI-powered chat assistant (Alynivo)
The Alynivo chat can provide local deterministic functions and, where explicitly enabled, AI-generated replies. When Managed AI is enabled, the current message, up to ten preceding messages, language, page title and page type, and the knowledge and persona context supplied by the website operator are first transmitted to api.alynivo.de in Germany. In AI-only operation, the Alynivo service does not persist message content; technical usage counters are processed without conversation content. Where the personal live chat is enabled on this website, section 6 applies in addition.
To generate a reply, this content is forwarded to the configured language-model provider. Anthropic, PBC, United States, is currently used. Anthropic does not use commercial API content for model training by default and generally deletes inputs and outputs within 30 days unless a different agreement, abuse review, or legal requirement applies. Processing may take place in the United States or other published processing regions. A data processing agreement including EU Standard Contractual Clauses applies.
OpenAI Ireland Ltd. is technically available as an alternative provider but is used only when expressly configured for the relevant customer and listed in that customer's DPA schedule. See the current subprocessor list.
The legal basis is Art. 6(1)(b) GDPR where the chat is used for a specific pre-contractual or contractual request. For general provision, security, and product demonstration, we rely on Art. 6(1)(f) GDPR following a balancing of interests. Do not enter passwords, complete payment data, health information, or other particularly sensitive information in the chat. Businesses receive a DPA listing the subprocessors applicable to their configuration before Managed AI is activated.
6. Personal live chat with a human
Where the personal live chat is enabled on this website, your conversation can be handed over to a person. Unlike AI-only operation, the exchanged messages are then stored permanently so that a member of staff can read and answer them.
We store the content of the messages you send and of the replies, the times, the language, and the title and address of the page on which the conversation started. The page address is stripped of credentials, query parameters, and fragments, so identifiers contained in them are not stored. Your chat session is identified by a random value that is stored only as a non-reversible hash.
What is explicitly not transmitted: text you type into the input field but do not send never leaves your browser and is stored nowhere. There is no analysis of your typing behaviour, no fingerprinting, no location tracking, and no cross-site profiling.
So that your request reaches a person at the right moment, the service automatically compares the text of the message you sent against a fixed list of keywords, for example an explicit request for a human or a complaint. This comparison serves only to route the conversation, creates no profile, and makes no decision about you; only a coarse reason in the form of a fixed code is recorded.
Whether a person is currently reachable is derived from a short-lived availability status of our staff that expires by itself. This gives you an honest indication instead of leaving you waiting for someone who is not there.
Conversations are stored on a server in Germany (api.alynivo.de) and are deleted automatically after 90 days by default. The legal basis is Art. 6(1)(b) GDPR where the chat serves to handle your specific request, and otherwise Art. 6(1)(f) GDPR based on the legitimate interest in providing personal support to prospective customers. Here too, please do not enter passwords, complete payment data, or health information.
For staff who operate the live chat we process name, email address, a password stored only as a hash, and login, responsibility, and availability data. This secures access and makes it traceable who took over a conversation.
7. Local funnel analytics
Alynivo records a small, fixed set of funnel events, such as starting the product planner, choosing a platform, viewing or selecting packages, and adding an item to the cart. The event type, platform, package identifier, language, time, and a daily rotating pseudonymous session value are stored. The IP address is processed only briefly to create this non-reversible value and for abuse prevention; the raw IP address is not stored in the analytics table.
The data remains exclusively in the relevant website operator's WordPress database, is not transferred to an external analytics service, and is automatically deleted after 90 days. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the data-minimised improvement of the advisory and ordering flow.
8. Contracts, subscriptions, and payment via Stripe
We use Stripe to conclude and manage paid Alynivo subscriptions. Providers for customers in the European Economic Area include Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, both based in Ireland. When you open Stripe Checkout and make a payment, Stripe processes data including your name, company name, email address, billing address, payment data, amount, selected plan, tax information, and technical device, browser, and fraud-prevention data. We do not receive complete card or bank-account details.
Processing is carried out to take steps before entering into and to perform a contract under Art. 6(1)(b) GDPR and to comply with commercial and tax obligations under Art. 6(1)(c) GDPR. Stripe also processes certain data under its own responsibility for payment processing, security, fraud prevention, and regulatory compliance. Stripe entities and service providers outside the European Economic Area may be involved; Stripe describes the applicable safeguards in its Privacy Center. We retain order, contract, and invoice data for the applicable statutory retention periods. More information: Stripe Privacy Policy and Stripe Privacy Center.
9. Technically necessary cookies and session storage
WordPress uses technically necessary cookies or comparable storage technologies to provide login, security, and session state. Alynivo uses browser session storage only to remember whether the one-time prompt bubble has already been shown; the entry ends with the browser session. When you proceed to the external Stripe Checkout, Stripe uses technically necessary storage technologies for payment processing, security, and fraud prevention. The legal basis is Art. 6(1)(b) or (f) GDPR in conjunction with § 25(2) TDDDG. In addition, we use statistics cookies for Google Analytics — these are set only after your active consent via our consent banner (see section 10). We do not use marketing or advertising tracking on this website.
10. Google Analytics
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics helps us understand how our website is used — for example which pages are viewed, how long visitors stay, and which source brought them to us. This evaluation is aggregated and serves solely to improve our offering.
Google Analytics uses cookies and comparable storage technologies that allow returning visits to be linked to a pseudonymous identifier. The data processed includes the pages viewed, date and time, approximate location, device and browser used, and the referring page. Google Analytics 4 truncates the IP address and does not store it permanently; we do not merge this data with any other data. Data stored at user level is deleted automatically from our Analytics account once the retention period configured there has elapsed.
The legal basis is exclusively your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Before you consent, no Google Analytics script is loaded and no data is transmitted to Google — the service remains blocked by our consent banner. You may withdraw your consent at any time with effect for the future by changing your selection via the “Manage consent” link at the end of this page.
A transfer of personal data to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. A data processing agreement under Art. 28 GDPR is in place with Google. For more information, see Google's privacy policy at policies.google.com/privacy and support.google.com/analytics.
11. Reach measurement with Burst Statistics
We use Burst Statistics to evaluate how this website is used. It is analytics software that we operate ourselves on this website's own web space. The data collected never leaves our server; it is not passed on to third parties and not transferred to a third country.
We run Burst Statistics in its cookieless mode. No cookies are set, and no information is read from or stored on your device; no fingerprinting takes place. What is recorded is the page viewed, time on page, the referring page, the approximate geographic origin, and the device type, browser and operating system. To tell visits apart, an anonymised check value is derived from the IP address and browser identifier; it changes daily. The IP address itself is not stored. Recognising someone beyond that day, or tracing the data back to an individual, is therefore not possible.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in evaluating usage statistically and shaping our offering accordingly. Because no cookies are set and no information is retrieved from your device, consent under § 25(1) TDDDG is not required. The measurement therefore runs regardless of your choice in the consent banner.
The resulting analyses are stored on our server and evaluated only in aggregated form. Under Art. 21 GDPR you have the right to object to this processing on grounds relating to your particular situation. An informal message to the email address given above is sufficient.
12. SSL / TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar changes from http:// to https:// and by the lock icon in your browser bar.
13. Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for processing it no longer applies. If you assert a legitimate right to erasure or withdraw consent, your data will be deleted, provided no statutory retention obligations prevent this.
14. Your rights
Under applicable statutory provisions, you have the right to access, rectification, erasure, restriction of processing, data portability, and objection to the processing of your personal data. You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data.