Privacy Policy
The protection of your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Data Protection Act – DSG). This privacy policy informs you about data processing within this chat application.
This English version is provided for convenience only. The German version is legally authoritative.
Controller
Novogenia Marketing GmbH
Strass 19
5301 Eugendorf, Austria
Email: service@novogenia.com
Web: novogenia.com
Data Protection Officer
[PLACEHOLDER: Name and contact details of the data protection officer, if appointed]
Core Principle: Anonymous Use
This chat application is an assistant for frequently asked questions and product knowledge. It is used anonymously: there is no end-user account, no login, and no registration. Responses are generated with the help of large language models (LLM) from provided content.
No special categories of personal data (e.g. health or genetic data) are requested or processed. Conversation contents are only personal data if you voluntarily enter personal data. We therefore ask you not to enter personal data (e.g. name, address, contact details) into the chat.
Data Processed
| Data type | Content | Storage location |
|---|---|---|
| Conversation data | Your messages and the assistant's responses | EU infrastructure (AWS, EU region) |
| Session data | Technical session identifier (token hash), timestamps | EU infrastructure (AWS, EU region) |
| Technical connection data | IP address and similar request data (abuse protection, security) | Security logs (AWS, EU region) |
| Prompt logs | Composed requests to the language model (audit trail) | EU infrastructure (AWS, EU region) |
| Error and operations logs | Technical error and performance events | Sentry (EU region) |
| Usage and analytics data | Aggregated, anonymous usage statistics (page views, events, browser/device/language settings, IP-derived country); no content | Umami (self-hosted, AWS EU region) |
Purposes and Legal Bases of Processing
- Provision of the chat: processing of your chat messages and session data to answer your requests and provide the conversation history within a session. The legal basis is the performance of the usage relationship (Art. 6(1)(b) GDPR) and our legitimate interest in providing the service (Art. 6(1)(f) GDPR).
- Security and abuse protection: processing of technical connection data (in particular the IP address) to fend off harmful or abusive requests (web application firewall, request limiting). The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
- Error and performance monitoring: processing of technical error events to maintain and improve the stability of the service (see section "Error and Performance Monitoring"). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
- Web analytics: creation of anonymous, aggregated usage statistics using self-hosted, cookieless web analytics (Umami) to improve the service (see section "Web Analytics"). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Recipients and Processors
We use the following service providers as processors (Art. 28 GDPR). Data processing agreements are in place with all listed services.
| Service | Purpose and data received | Location |
|---|---|---|
| AWS | Hosting of the application and storage of data (application, databases, file storage) | EU region |
| AWS Bedrock (Anthropic models, Claude) | Generation of chat responses; receives the composed request including your message | EU region eu-central-1 (Frankfurt); processing remains within the EU, no transfer to the USA |
| Voyage AI (MongoDB) | Conversion of your request into technical search vectors (embeddings) for content search | USA (see "Third-Country Transfer") |
| Sentry | Error and performance monitoring; processes the IP address and, incidentally, technical request context | EU region |
Data is not transferred to other third parties unless we are legally obliged to do so.
Third-Country Transfer
For content search, your request is converted into technical search vectors by Voyage AI in the USA. Permanent storage of the transmitted data at Voyage AI is technically disabled. The transfer takes place on the basis of [PLACEHOLDER: appropriate safeguards, e.g. EU standard contractual clauses].
The generation of chat responses by the Anthropic language models takes place via AWS Bedrock entirely within the EU (region eu-central-1, Frankfurt); in this respect, no transfer to the USA takes place.
Error and Performance Monitoring (Sentry)
To maintain stable operation, we use the Sentry service (EU region). Processing is based on our legitimate interest in detecting and fixing technical errors (Art. 6(1)(f) GDPR). The following data-minimizing measures are technically implemented:
- No automatic transmission of IP addresses, cookies, headers, or user context by the SDK.
- Request contents, query parameters, and sensitive headers are scrubbed or removed before transmission.
- Server-side scrubbing rules (including removal of IP addresses) as a second layer of protection.
- Session replay and profiling are disabled.
- Error events are deleted after 90 days.
You may object to processing based on legitimate interest at any time (see "Your Rights").
Web Analytics (Umami)
To analyze usage statistically and improve the service, we use the self-hosted, cookieless web analytics software Umami. Umami runs exclusively on our own EU infrastructure (AWS, region eu-central-1, Frankfurt). No external analytics provider is involved and no data is transferred to third parties. The legal basis is our legitimate interest in a needs-based and secure design of the service (Art. 6(1)(f) GDPR).
The following data-minimizing measures are technically implemented:
- No cookies and no cross-device recognition; nothing is stored on your device for this purpose.
- No storage of the IP address: an anonymous daily identifier is derived from the IP address and browser signature using a daily-rotating, non-reversible key; the IP address itself is not stored.
- Only aggregated usage data is collected: pages visited, referrer source, approximate IP-derived location (country), and browser, operating system, device, and language settings.
- For individual features (e.g. starting a chat, sending a message), technical events are counted. These contain only the identifier of the respective tenant and technical attributes (e.g. yes/no flags) — never the content of your messages.
- Your browser's "Do Not Track" setting is honored; if it is enabled, no data is collected.
- Session Replay and heatmaps are disabled.
Data collected through web analytics is deleted after 6 months. You may object to this processing at any time (see "Your Rights") — most easily by enabling "Do Not Track" in your browser.
Retention Period
| Data | Period |
|---|---|
| Conversation and session data | Only as long as necessary, then deletion |
Anonymous browser session (browser_session_token) | 7 days |
| Security and access logs (stored encrypted) | 6 months (180 days) |
| Error events (Sentry) | 90 days |
| Web analytics data (Umami) | 6 months |
| Interface cookies (see cookie table) | 6 months |
Beyond that, we store personal data only for as long as is necessary for the stated purposes or as required by statutory retention obligations.
Cookies
This application uses only strictly necessary and functional cookies and local storage entries. No advertising cookies are used and no cross-site trackers are employed. The web analytics in use (Umami, see section "Web Analytics (Umami)") is fully cookieless and self-hosted by us; no third-party analytics service is loaded, and it sets no cookies.
| Name | Type | Purpose | Duration |
|---|---|---|---|
nuxt-session | Cookie | Stores the encrypted login session of logged-in users (administration area only) | Session |
browser_session_token | Cookie | Stores the session identifier for anonymous chat usage and abuse protection | 7 days |
cookie-notice-acknowledged | Cookie | Stores that you have acknowledged the cookie notice | 6 months |
disclaimer-accepted | Cookie | Stores that you have acknowledged the usage notice | 6 months |
latest-changelog-acknowledged | Cookie | Stores which release notes you have already seen | 6 months |
i18n_locale | Cookie | Stores your language selection | 6 months |
chat:lastSessionId | Local storage | Stores the most recently active chat session so the conversation can be resumed | Until deleted by you |
| Sentry | Cookie / Local storage | Technical error and performance monitoring | See section "Error and Performance Monitoring" |
Strictly necessary cookies may be set without your consent (§ 165(3) Austrian Telecommunications Act 2021). Functional entries (e.g. language selection) are only set when you actively use the corresponding feature. You can delete or block cookies at any time in your browser settings; however, this may limit the functionality of the application.
Technical Security Measures
Among others, the following measures are implemented to protect your data:
- Web application firewall (WAF) in front of the application; blocking and throttling of harmful or abusive requests.
- Removal of sensitive data (request contents, query parameters, sensitive headers) from the security logs before storage.
- Encrypted storage of logs.
- Request limiting (rate limiting) per IP address on public endpoints.
- Anonymous use as a core principle; no end-user account.
- Hosting and storage of conversations exclusively on EU infrastructure.
Your Rights
You generally have the rights of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR).
Please note: since usage is anonymous, we are generally unable to attribute individual conversations to a person. To exercise your rights, please contact: service@novogenia.com
Right to Lodge a Complaint
If you believe that the processing of your data violates data protection law, you may lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at
Changes to This Privacy Policy
We reserve the right to amend this privacy policy to reflect changes in the legal situation or in the service. The current version published here applies.
Last updated: [PLACEHOLDER: date of legal approval]