Home Privacy Policy
Legal Document

Privacy Policy

This policy explains how VisionAI Platform GmbH collects, processes, stores, and protects your personal data when you use our website and services.

Last Updated: January 15, 2026

1 Introduction

VisionAI Platform GmbH ("VisionAI," "we," "us," or "our") is the data controller responsible for your personal data collected through our website at www.visionai-platform.com and our AI-powered data analysis and automation platform. We are a company registered in Germany with our principal office located at Friedrichstraße 68, 10117 Berlin, Germany.

We are committed to protecting the privacy and security of every person who interacts with our services. This Privacy Policy describes the types of personal information we collect, why we collect it, how we process and store it, who we share it with, and the choices and rights available to you regarding your data.

This policy applies to all visitors of our website, users of our platform, recipients of our marketing communications, and anyone who contacts us through our forms, email, or phone. By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any aspect of this policy, please refrain from using our website and services.

We comply with the European Union General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG), and other applicable data protection legislation. Where our services are used by individuals in other jurisdictions, we also take steps to comply with local data protection requirements.

2 Data We Collect

We collect several categories of personal data depending on how you interact with our website and services. Below is a detailed breakdown of each category:

Identity and Contact Data

  • Full name (first name and last name) as provided in contact forms, registration forms, or during account creation
  • Email address used for account registration, newsletter subscriptions, or correspondence
  • Phone number if voluntarily provided through our contact form or during sales consultations
  • Company name, job title, and business address when provided in the context of enterprise inquiries

Technical and Usage Data

  • IP address (anonymized where feasible for analytics purposes)
  • Browser type and version, operating system, device type, and screen resolution
  • Pages visited, time spent on each page, referring URLs, and exit pages
  • Click patterns, scroll depth, and interaction data with specific interface elements
  • Date and time of access, time zone setting, and language preferences

Cookie and Tracking Data

  • Cookie identifiers stored on your device (see Section 10 for full details)
  • Data from analytics tools such as Google Analytics, including session identifiers and user interaction events
  • Pixel data from Meta Pixel if applicable, used for measuring the effectiveness of our advertising campaigns

Communication Data

  • Content of messages sent through our contact form or email, including any attachments
  • Records of communication preferences and marketing consent choices
  • Feedback, survey responses, and testimonial submissions when voluntarily provided

3 How We Collect Data

We collect personal data through the following methods:

Direct Interactions

You provide data directly when you fill out our contact form, subscribe to our newsletter, request a product demonstration, create an account on our platform, or communicate with us via email or phone. Every form on our website clearly indicates which fields are required and which are optional. We only ask for information that is necessary to fulfill your specific request.

Automated Technologies

When you visit our website, we automatically collect technical data using cookies, server logs, and analytics tools. Our web servers record standard access log information including your IP address, browser details, and the pages you request. Google Analytics (with IP anonymization enabled) helps us understand traffic patterns and user behavior in aggregate. If you have consented to marketing cookies, Meta Pixel may collect interaction data for advertising measurement purposes.

Third-Party Sources

In limited circumstances, we may receive professional contact information from business partners or event organizers when you attend industry conferences or webinars where we are a participating company. We only process such data if there is a legitimate basis to do so, and we always inform you of the source at the first point of direct contact.

5 How We Use Your Data

We use the personal data we collect for the following specific purposes:

  • Service Delivery: To provide access to our AI-powered data analysis platform, manage your account, process your data according to your configuration, and deliver the insights and automation results you have requested.
  • Communication: To respond to your inquiries, send service-related notifications (such as maintenance updates or security alerts), and provide customer support during your use of our platform.
  • Marketing (with consent): To send you our monthly newsletter containing insights on machine learning trends, product updates, and practical guides. You may unsubscribe from marketing emails at any time using the link provided in each message.
  • Website Improvement: To analyze aggregate usage patterns, identify areas for user experience improvement, diagnose technical issues, and ensure the stability and performance of our website and platform.
  • Security: To detect, prevent, and respond to security incidents, fraudulent activity, unauthorized access attempts, and violations of our terms of service.
  • Legal Compliance: To maintain records required by tax authorities, respond to lawful requests from regulatory bodies, and fulfill our obligations under applicable law.
  • Business Analysis: To understand market demand for our services, evaluate the effectiveness of our website content, and make informed decisions about product development priorities.

We do not use your personal data for automated individual decision-making or profiling that produces legal effects or similarly significant effects on you. Our analytics activities process data in aggregate and do not target specific individuals.

6 Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Below are our specific retention periods by data category:

Data Category Retention Period
Contact form submissions 2 years from submission date
Platform account data Duration of active account plus 12 months after closure
Newsletter subscription data Until unsubscription, then deleted within 30 days
Website analytics data 14 months (Google Analytics default with anonymization)
Cookie data Up to 13 months depending on cookie type (see Section 10)
Server access logs 90 days
Invoicing and billing records 10 years (German commercial and tax law requirement)
Support ticket records 3 years from resolution

When data reaches the end of its retention period, it is securely deleted or irreversibly anonymized so that it can no longer be associated with an identifiable individual. We conduct regular reviews of our data holdings to ensure compliance with these retention schedules.

7 Data Sharing

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share personal data only with the following categories of recipients, and only to the extent necessary for the purposes described in this policy:

  • Cloud Hosting Providers: Our platform and website are hosted on infrastructure provided by established cloud service providers located within the European Economic Area (EEA). These providers process data on our behalf under strict data processing agreements that comply with GDPR Article 28.
  • Analytics Providers: Google Analytics (Google Ireland Limited) processes anonymized usage data to help us understand website traffic patterns. IP anonymization is enabled, meaning your full IP address is not stored by Google.
  • Email Service Providers: We use a GDPR-compliant email platform to manage our newsletter and transactional communications. This provider stores your email address and delivery records under a data processing agreement.
  • Payment Processors: If you purchase a subscription, your payment is processed by a PCI-DSS certified payment processor. We do not store your full credit card details on our servers; the processor handles payment data directly.
  • Professional Advisors: In limited cases, we may share data with our legal counsel, auditors, or tax advisors when necessary for legal compliance or dispute resolution.
  • Law Enforcement or Regulators: We may disclose personal data if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

All third-party service providers are contractually bound to handle your data securely and in accordance with applicable data protection laws. We conduct regular reviews of our vendor relationships and their security practices.

8 International Transfers

We primarily process and store personal data within the European Economic Area (EEA). However, some of our service providers may process data in countries outside the EEA. When personal data is transferred outside the EEA, we ensure that appropriate safeguards are in place to protect your data to the same standard required by European data protection law.

These safeguards include:

  • European Commission Adequacy Decisions: We transfer data to countries that the European Commission has determined provide an adequate level of data protection.
  • Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision, we use the European Commission's Standard Contractual Clauses (adopted June 2021) as the legal mechanism to ensure appropriate protection.
  • Supplementary Measures: Where required by the transfer impact assessment, we implement additional technical measures such as encryption in transit and at rest, pseudonymization, and access controls to further protect transferred data.

You may request a copy of the relevant safeguards or information about the countries where your data is processed by contacting us using the details provided in Section 13.

9 Your Rights

Under the GDPR (Articles 15 through 22), you have the following rights regarding your personal data. These rights are not absolute and may be subject to certain conditions and exceptions as set out in the applicable law:

Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you, along with information about how we process it, the purposes of processing, the categories of recipients, and the retention periods applicable to your data.

Right to Rectification (Article 16)

If any personal data we hold about you is inaccurate or incomplete, you have the right to request correction or completion without undue delay.

Right to Erasure (Article 17)

You may request that we delete your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when there is no overriding legitimate ground for continued processing. Note that we may need to retain certain data for legal compliance purposes.

Right to Restriction of Processing (Article 18)

You can request that we restrict the processing of your data in certain circumstances, such as when you contest the accuracy of data or object to processing based on legitimate interest, pending verification.

Right to Data Portability (Article 20)

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

Right to Object (Article 21)

You have the right to object to processing based on legitimate interest, including profiling. You also have an absolute right to object to direct marketing at any time.

Right to Withdraw Consent

Where we process data based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal. You can withdraw consent by contacting us or, for email marketing, using the unsubscribe link in any marketing message.

To exercise any of these rights, please contact our privacy team at [email protected] or write to us at the address listed in Section 13. We will respond to your request within 30 days. If your request is complex or if we receive a large number of requests, we may extend this period by a further 60 days, and we will inform you of any such extension within the initial 30-day period.

If you believe that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority. For individuals in Germany, the relevant authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Friedrichstr. 219, 10969 Berlin. You also have the right to lodge a complaint with the supervisory authority in your country of residence or place of work.

10 Cookies

Cookies are small text files placed on your device when you visit our website. They serve various functions, from remembering your preferences to helping us understand how visitors use our site. Below is a description of the cookie categories we use:

Essential Cookies

These cookies are necessary for the website to function properly. They enable core features such as page navigation, access to secure areas, and remembering your cookie consent preferences. Essential cookies cannot be disabled because the site cannot operate correctly without them. They do not store any personally identifiable information beyond what is needed for functionality.

  • visionai_cookie_consent - Stores your cookie consent choice. Duration: 12 months.
  • session_id - Maintains your session state while browsing. Duration: expires when browser is closed.

Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information in aggregate. We use Google Analytics with IP anonymization enabled. Analytics cookies are only set if you have given your consent through our cookie banner.

  • _ga - Distinguishes unique users. Duration: 13 months.
  • _ga_[ID] - Maintains session state for Google Analytics. Duration: 13 months.

Marketing Cookies

These cookies may be set through our site by advertising partners to build a profile of your interests and show you relevant content on other sites. They are only activated with your explicit consent. If you do not allow these cookies, you will not experience targeted advertising from our campaigns on other platforms.

  • _fbp - Meta Pixel identifier for ad delivery and measurement. Duration: 3 months.

Managing Cookies

You can manage your cookie preferences at any time through our cookie consent banner, which appears when you first visit the site and can be accessed again through the cookie settings link in our footer. You can also control and delete cookies through your browser settings. Please note that disabling essential cookies may affect the functionality of the website.

Most web browsers allow you to block all cookies, accept all cookies, or block specific types. To learn how to manage cookies in your browser, consult your browser's help documentation. If you use multiple devices or browsers, you will need to adjust your settings on each one separately.

11 Children's Privacy

Our website and platform services are designed for business professionals and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16 years of age. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at [email protected].

Upon verification, we will promptly delete any personal data that has been collected from a child under 16. We take this obligation seriously and have internal procedures in place to handle such situations with appropriate urgency.

12 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will update the "Last Updated" date at the top of this page and take reasonable steps to notify affected individuals.

For significant changes that affect how we process your data or your rights, we will provide prominent notice through one or more of the following methods:

  • A notification banner displayed on our website for a minimum of 14 days
  • An email notification sent to registered users and newsletter subscribers
  • An in-platform notification for active account holders

We encourage you to review this page periodically to stay informed about our data protection practices. Your continued use of our website and services after changes are posted constitutes your acknowledgment of the revised policy. If you do not agree with any changes, you may exercise your rights as described in Section 9, including requesting the deletion of your data.

13 Contact Details

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us using the following details:

VisionAI Platform GmbH

Friedrichstraße 68, 10117 Berlin, Germany

For privacy-specific inquiries, please use the [email protected] email address to ensure your request is routed to our data protection team promptly.

We aim to acknowledge all privacy-related inquiries within 5 business days and to provide a substantive response within 30 days, as required by the GDPR. If you are not satisfied with our response, you have the right to escalate your concern to the relevant data protection supervisory authority as described in Section 9.

Related Legal Documents