Back to chat

Privacy Policy

The protection of your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, Austrian Data Protection Act – DSG). This privacy policy informs you about data processing within this chat application.

This English version is provided for convenience only. The German version is legally authoritative.

Controller

Novogenia Marketing GmbH
Strass 19
5301 Eugendorf, Austria
Email: service@novogenia.com
Web: novogenia.com

Data Protection Officer

[PLACEHOLDER: Name and contact details of the data protection officer, if appointed]

Core Principle: Anonymous Use

This chat application is an assistant for frequently asked questions and product knowledge. It is used anonymously: there is no end-user account, no login, and no registration. Responses are generated with the help of large language models (LLM) from provided content.

No special categories of personal data (e.g. health or genetic data) are requested or processed. Conversation contents are only personal data if you voluntarily enter personal data. We therefore ask you not to enter personal data (e.g. name, address, contact details) into the chat.

Data Processed

Data typeContentStorage location
Conversation dataYour messages and the assistant's responsesEU infrastructure (AWS, EU region)
Session dataTechnical session identifier (token hash), timestampsEU infrastructure (AWS, EU region)
Technical connection dataIP address and similar request data (abuse protection, security)Security logs (AWS, EU region)
Prompt logsComposed requests to the language model (audit trail)EU infrastructure (AWS, EU region)
Error and operations logsTechnical error and performance eventsSentry (EU region)
Usage and analytics dataAggregated, anonymous usage statistics (page views, events, browser/device/language settings, IP-derived country); no contentUmami (self-hosted, AWS EU region)
  • Provision of the chat: processing of your chat messages and session data to answer your requests and provide the conversation history within a session. The legal basis is the performance of the usage relationship (Art. 6(1)(b) GDPR) and our legitimate interest in providing the service (Art. 6(1)(f) GDPR).
  • Security and abuse protection: processing of technical connection data (in particular the IP address) to fend off harmful or abusive requests (web application firewall, request limiting). The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
  • Error and performance monitoring: processing of technical error events to maintain and improve the stability of the service (see section "Error and Performance Monitoring"). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
  • Web analytics: creation of anonymous, aggregated usage statistics using self-hosted, cookieless web analytics (Umami) to improve the service (see section "Web Analytics"). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

Recipients and Processors

We use the following service providers as processors (Art. 28 GDPR). Data processing agreements are in place with all listed services.

ServicePurpose and data receivedLocation
AWSHosting of the application and storage of data (application, databases, file storage)EU region
AWS Bedrock (Anthropic models, Claude)Generation of chat responses; receives the composed request including your messageEU region eu-central-1 (Frankfurt); processing remains within the EU, no transfer to the USA
Voyage AI (MongoDB)Conversion of your request into technical search vectors (embeddings) for content searchUSA (see "Third-Country Transfer")
SentryError and performance monitoring; processes the IP address and, incidentally, technical request contextEU region

Data is not transferred to other third parties unless we are legally obliged to do so.

Third-Country Transfer

For content search, your request is converted into technical search vectors by Voyage AI in the USA. Permanent storage of the transmitted data at Voyage AI is technically disabled. The transfer takes place on the basis of [PLACEHOLDER: appropriate safeguards, e.g. EU standard contractual clauses].

The generation of chat responses by the Anthropic language models takes place via AWS Bedrock entirely within the EU (region eu-central-1, Frankfurt); in this respect, no transfer to the USA takes place.

Error and Performance Monitoring (Sentry)

To maintain stable operation, we use the Sentry service (EU region). Processing is based on our legitimate interest in detecting and fixing technical errors (Art. 6(1)(f) GDPR). The following data-minimizing measures are technically implemented:

  • No automatic transmission of IP addresses, cookies, headers, or user context by the SDK.
  • Request contents, query parameters, and sensitive headers are scrubbed or removed before transmission.
  • Server-side scrubbing rules (including removal of IP addresses) as a second layer of protection.
  • Session replay and profiling are disabled.
  • Error events are deleted after 90 days.

You may object to processing based on legitimate interest at any time (see "Your Rights").

Web Analytics (Umami)

To analyze usage statistically and improve the service, we use the self-hosted, cookieless web analytics software Umami. Umami runs exclusively on our own EU infrastructure (AWS, region eu-central-1, Frankfurt). No external analytics provider is involved and no data is transferred to third parties. The legal basis is our legitimate interest in a needs-based and secure design of the service (Art. 6(1)(f) GDPR).

The following data-minimizing measures are technically implemented:

  • No cookies and no cross-device recognition; nothing is stored on your device for this purpose.
  • No storage of the IP address: an anonymous daily identifier is derived from the IP address and browser signature using a daily-rotating, non-reversible key; the IP address itself is not stored.
  • Only aggregated usage data is collected: pages visited, referrer source, approximate IP-derived location (country), and browser, operating system, device, and language settings.
  • For individual features (e.g. starting a chat, sending a message), technical events are counted. These contain only the identifier of the respective tenant and technical attributes (e.g. yes/no flags) — never the content of your messages.
  • Your browser's "Do Not Track" setting is honored; if it is enabled, no data is collected.
  • Session Replay and heatmaps are disabled.

Data collected through web analytics is deleted after 6 months. You may object to this processing at any time (see "Your Rights") — most easily by enabling "Do Not Track" in your browser.

Retention Period

DataPeriod
Conversation and session dataOnly as long as necessary, then deletion
Anonymous browser session (browser_session_token)7 days
Security and access logs (stored encrypted)6 months (180 days)
Error events (Sentry)90 days
Web analytics data (Umami)6 months
Interface cookies (see cookie table)6 months

Beyond that, we store personal data only for as long as is necessary for the stated purposes or as required by statutory retention obligations.

Cookies

This application uses only strictly necessary and functional cookies and local storage entries. No advertising cookies are used and no cross-site trackers are employed. The web analytics in use (Umami, see section "Web Analytics (Umami)") is fully cookieless and self-hosted by us; no third-party analytics service is loaded, and it sets no cookies.

NameTypePurposeDuration
nuxt-sessionCookieStores the encrypted login session of logged-in users (administration area only)Session
browser_session_tokenCookieStores the session identifier for anonymous chat usage and abuse protection7 days
cookie-notice-acknowledgedCookieStores that you have acknowledged the cookie notice6 months
disclaimer-acceptedCookieStores that you have acknowledged the usage notice6 months
latest-changelog-acknowledgedCookieStores which release notes you have already seen6 months
i18n_localeCookieStores your language selection6 months
chat:lastSessionIdLocal storageStores the most recently active chat session so the conversation can be resumedUntil deleted by you
SentryCookie / Local storageTechnical error and performance monitoringSee section "Error and Performance Monitoring"

Strictly necessary cookies may be set without your consent (§ 165(3) Austrian Telecommunications Act 2021). Functional entries (e.g. language selection) are only set when you actively use the corresponding feature. You can delete or block cookies at any time in your browser settings; however, this may limit the functionality of the application.

Technical Security Measures

Among others, the following measures are implemented to protect your data:

  • Web application firewall (WAF) in front of the application; blocking and throttling of harmful or abusive requests.
  • Removal of sensitive data (request contents, query parameters, sensitive headers) from the security logs before storage.
  • Encrypted storage of logs.
  • Request limiting (rate limiting) per IP address on public endpoints.
  • Anonymous use as a core principle; no end-user account.
  • Hosting and storage of conversations exclusively on EU infrastructure.

Your Rights

You generally have the rights of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR).

Please note: since usage is anonymous, we are generally unable to attribute individual conversations to a person. To exercise your rights, please contact: service@novogenia.com

Right to Lodge a Complaint

If you believe that the processing of your data violates data protection law, you may lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42, 1030 Vienna, Austria
www.dsb.gv.at

Changes to This Privacy Policy

We reserve the right to amend this privacy policy to reflect changes in the legal situation or in the service. The current version published here applies.

Last updated: [PLACEHOLDER: date of legal approval]