Privacy Policy
Version 1.0 — effective from March 19, 2026
Controller
Thorsten Ahrens
Zillestr. 75
51067 Cologne, Germany
Email: contact@serahr.de
Data Collection on This Website
This website collects personal data exclusively in the context of contact requests. When communicating via email or the contact form, your data (name, email address, message content) is stored in order to process your enquiry.
Contact Form
When you send us enquiries via the contact form, the data you provide (your email address, your name, the selected topic, and your message) is stored in order to process your request. Your data will not be shared with third parties without your consent.
Legal Basis
Your data is processed on the basis of Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in the efficient handling of enquiries).
Storage Duration
Your contact data will be deleted as soon as it is no longer required for the purpose of processing and no statutory retention obligations apply.
Hosting
This website is hosted externally. Personal data collected on this website (e.g. IP addresses, contact requests) is stored on the servers of the hosting provider. Processing is carried out on the basis of Art. 6(1)(f) GDPR.
Sub-Processors and Third-Party Services
We use the following sub-processors to provide this website:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting, edge delivery | USA (EU data processing) |
| Resend Inc. | Email delivery (contact form) | USA (EU data processing) |
| Hetzner Online GmbH | Server hosting (chatbot on this website) | Germany |
| OpenRouter / Anthropic | AI language processing (chatbot responses) | USA |
Additional sub-processors (e.g. Supabase, Stripe) are listed in the product-specific privacy policies of our individual services (see below).
Data processing agreements pursuant to Art. 28 GDPR are in place with all sub-processors. Where data is transferred to the USA, this is done on the basis of EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) or an adequacy decision by the European Commission (Art. 45 GDPR, EU-US Data Privacy Framework).
Chatbot (SerahrChat)
This website uses an AI-powered chatbot (SerahrChat) that answers questions about our products and services. When using the chatbot, the following data is processed:
- Your chat messages
- Your IP address (stored in anonymized form)
- Timestamp of the request
Data is processed on a server hosted by Hetzner Online GmbH (Gunzenhausen, Germany). To generate responses, your questions are forwarded to an AI language service (currently OpenRouter/AI21). No personal data beyond the content of your question is transmitted.
Processing is based on Art. 6(1)(f) GDPR (legitimate interest in efficiently answering customer enquiries). Chat histories are not permanently stored and are not linked to any individual.
Disclosure to Law Enforcement
We may be legally required to disclose stored data to law enforcement authorities on the basis of a European Production Order or European Preservation Order pursuant to Regulation (EU) 2023/1543. Such disclosure is made exclusively on the basis of a lawful order and to the extent required by law. Legal basis: Art. 6(1)(c) GDPR (legal obligation).
Your Rights
You have the right to:
- Access your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).