Skip to main content

    Privacy Policy

    Revision date: 12 August 2026

    Introduction

    I take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy. This privacy policy informs you pursuant to Art. 13 and 14 GDPR about the processing of your personal data.

    Data Controller (Art. 4 No. 7 GDPR)

    APRIXITY

    Melvin Voigtlaender

    Lathusenstr. 14a, 30625 Hannover, Germany

    [email protected]

    Data We Collect (Art. 13(1)(d) GDPR)

    • Contact form data: Name, email address, message, timestamp
    • Assessment data: Email, first name, company, and responses to 7 questions about the operational bottleneck
    • Homepage diagnostic: selected outcome path and six questions; contact data is collected only when the visitor voluntarily requests the private result link
    • Analytics data: Page views, clicks, scroll depth, time on page (anonymized)
    • Technical data: IP address (anonymized), browser type, operating system, device information
    • Cookies: Essential (session, deleted after browser close), Analytics (with consent, 14 months retention per Google Analytics standard)

    How We Use Your Data (Art. 13(1)(c) GDPR)

    • Responding to inquiries and communication
    • Rule-based calculation and delivery of a diagnosis from four bottleneck classes: context, process, action, and decision
    • Displaying the complete directional diagnostic on the website and optionally delivering a private, expiring result link
    • Improving website performance and user experience
    • Analyzing user behavior for service optimization
    • Marketing communication only after separate consent and confirmed double opt-in; withdrawal is available through the supplied link or [email protected]
    • Internal notification and prioritization of new inquiries using a rule-based lead-fit score

    Legal Basis (Art. 6 GDPR)

    • Consent (Art. 6(1)(a) GDPR) - for analytics and marketing, requested separately and voluntarily, with marketing activated only after double opt-in
    • Contract performance or steps requested before entering a contract (Art. 6(1)(b) GDPR) - for the requested assessment and delivery of its result
    • Legitimate interest (Art. 6(1)(f) GDPR) - for website operation, security, and internal processing and prioritization of inquiries; you may object to this prioritization

    Separate communication purposes

    Result delivery, finite result guidance, and the Aprixity Briefing are technically and legally separate purposes.

    • One-time result delivery sends only the requested private result link. It grants no permission for further messages.
    • Finite result guidance requires its own separate consent and confirmed double opt-in. It ends after the announced closed sequence and creates no briefing subscription.
    • The recurring Aprixity Briefing requires separate consent and confirmed double opt-in independent of finite guidance. Its topics are operating architecture, bottlenecks, AI-First practice, and dependable AI.
    • Withdrawal is available through the link in each authorized message or via [email protected]. Withdrawing one purpose does not change authority for the other purpose.
    • Unconfirmed contact data is erased when the confirmation window expires. After withdrawal, complaint, or suppression, the delivery address and send capability are erased; minimal consent and suppression evidence remains for compliance.

    Third-Party Services and Data Processors

    I use the following services that process personal data on my behalf:

    Google Analytics 4

    Anbieter: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

    Zweck: Website analytics and usage statistics

    Daten: Anonymized usage data, page views, events

    Rechtsgrundlage: Consent (Art. 6(1)(a) GDPR)

    Datenübermittlung: USA (EU-US Data Privacy Framework)

    Datenschutz:Link

    Hinweis: privacy.sections.thirdParty.ga4.note

    Opt-Out: Cookie consent banner or browser plugin

    Hotjar

    Anbieter: Hotjar Ltd., Level 2, St Julian's Business Centre, Elia Zammit Street, St Julian's STJ 3155, Malta

    Zweck: User behavior analysis (heatmaps, session recordings)

    Daten: Anonymized interaction data, mouse movements, clicks

    Rechtsgrundlage: Consent (Art. 6(1)(a) GDPR)

    Datenübermittlung: EU (Malta)

    Datenschutz:Link

    Hinweis: privacy.sections.thirdParty.hotjar.note

    Opt-Out: Cookie consent banner

    n8n Workflow Automation

    Anbieter: Self-hosted on own infrastructure (Hetzner Cloud, Germany)

    Zweck: Automated processing of assessment requests, email sending, lead scoring

    Daten: Assessment data (email, name, company, responses)

    Rechtsgrundlage: Contract performance (Art. 6(1)(b) GDPR)

    Datenübermittlung: Germany (EU)

    Hinweis: privacy.sections.thirdParty.n8n.note

    Opt-Out: privacy.sections.thirdParty.n8n.optOut

    Neo4j Database

    Anbieter: Self-hosted on own infrastructure (Hetzner Cloud, Germany)

    Zweck: Storage and management of lead data in graph database

    Daten: Contact data, assessment results, interaction history

    Rechtsgrundlage: Contract performance (Art. 6(1)(b) GDPR)

    Datenübermittlung: Germany (EU)

    Hinweis: privacy.sections.thirdParty.neo4j.note

    Opt-Out: privacy.sections.thirdParty.neo4j.optOut

    Google Sheets

    Anbieter: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

    Zweck: Backup and overview of lead data for internal management to ensure data security and redundancy

    Daten: Email, name, company, assessment segment, timestamp

    Rechtsgrundlage: Legitimate interest (Art. 6(1)(f) GDPR) - interest in data availability, redundancy, and proper documentation

    Datenübermittlung: USA (EU-US Data Privacy Framework per EU Commission adequacy decision of 10.07.2023, additionally secured by Standard Contractual Clauses per Art. 46(2)(c) GDPR)

    Datenschutz:Link

    Hinweis: privacy.sections.thirdParty.googleSheets.note

    Opt-Out: privacy.sections.thirdParty.googleSheets.optOut

    Gmail / Google Workspace

    Anbieter: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

    Zweck: Sending assessment results and communication

    Daten: Email address, name, message content

    Rechtsgrundlage: Contract performance (Art. 6(1)(b) GDPR)

    Datenübermittlung: USA (EU-US Data Privacy Framework, Standard Contractual Clauses)

    Datenschutz:Link

    Hinweis: privacy.sections.thirdParty.gmail.note

    Opt-Out: privacy.sections.thirdParty.gmail.optOut

    Anthropic Claude (possible downstream AI processing)

    Anbieter: Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA

    Zweck: Possible downstream analysis for individual consulting; the displayed V6.1 diagnosis itself is calculated by rules without Claude

    Daten: If activated: assessment responses and only contact data necessary for the expressly described consulting purpose

    Rechtsgrundlage: Downstream AI processing requires its own documented legal basis before activation; the mandatory assessment checkbox does not provide blanket consent

    Datenübermittlung: Any transfer to the USA will be activated only after the applicable transfer safeguards have been documented

    Datenschutz:Link

    Hinweis: Neither the website nor this notice asserts that a production Anthropic call occurs or what retention and training configuration currently applies.

    Opt-Out: privacy.sections.thirdParty.anthropic.optOut

    Perplexity AI

    Anbieter: Perplexity AI Inc., San Francisco, CA, USA

    Zweck: AI-powered research to enrich company information (corporate data only) for personalized consulting

    Daten: Publicly available company information based on company name (no personal contact data)

    Rechtsgrundlage: Legitimate interest (Art. 6(1)(f) GDPR) - interest in efficient sales preparation

    Datenübermittlung: USA (Standard Contractual Clauses)

    Datenschutz:Link

    Hinweis: Research is limited to publicly available corporate data (industry, size, location). Personal data of contact persons is not collected.

    Opt-Out: privacy.sections.thirdParty.perplexity.optOut

    Cal.com

    Anbieter: Cal.com Inc., San Francisco, CA, USA

    Zweck: Appointment booking for consultation calls

    Daten: Name, email address, selected appointment, optional notes

    Rechtsgrundlage: Contract performance (Art. 6(1)(b) GDPR)

    Datenübermittlung: USA (Standard Contractual Clauses)

    Datenschutz:Link

    Hinweis: privacy.sections.thirdParty.calcom.note

    Opt-Out: privacy.sections.thirdParty.calcom.optOut

    Aprixity Conversation Edge

    Anbieter: Self-hosted on Hetzner infrastructure in Germany

    Zweck: Secure result and briefing intake, encrypted storage, private result link, separate consent evidence, double opt-in, and explicitly requested internal inquiry notification

    Daten: Name, email address, optional company, diagnostic answers, consent state, and technical security and delivery evidence; result tokens are stored only as hashes

    Rechtsgrundlage: Steps requested before entering a contract for result delivery; separate consent for finite result guidance and the Aprixity Briefing

    Datenübermittlung: Germany (EU); email delivery uses Resend as separately disclosed

    Hinweis: privacy.sections.thirdParty.conversationEdge.note

    Opt-Out: privacy.sections.thirdParty.conversationEdge.optOut

    Resend

    Anbieter: Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA

    Zweck: Transactional delivery of the private result link, explicitly requested internal inquiry notification, confirmed finite result guidance, and the confirmed Aprixity Briefing

    Daten: Email address, name, subject, message content, and delivery, bounce, and complaint status

    Rechtsgrundlage: Steps requested before entering a contract for result delivery; separate consent for confirmed result guidance and briefing communication

    Datenübermittlung: USA; DPA and Standard Contractual Clauses must be documented for the production account

    Datenschutz:Link

    Hinweis: Result delivery, explicit human review, finite result guidance, and the Aprixity Briefing are technically separate purposes.

    Opt-Out: privacy.sections.thirdParty.resend.optOut

    Cloudflare Turnstile

    Anbieter: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA

    Zweck: Abuse and bot protection for the public result and briefing forms

    Daten: IP address, browser and device signals, hostname, user agent, and challenge outcome; validation occurs server-side

    Rechtsgrundlage: Legitimate interest in secure form operation and abuse prevention (Art. 6(1)(f) GDPR)

    Datenübermittlung: USA; applicable transfer and contract records must be documented

    Datenschutz:Link

    Hinweis: Turnstile is loaded solely as a security service, not as marketing analytics.

    Opt-Out: privacy.sections.thirdParty.turnstile.optOut

    Hetzner Cloud (Hosting)

    Anbieter: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

    Zweck: Hosting of website, databases, and automation workflows

    Daten: All data collected on the website is stored on Hetzner servers in Germany

    Rechtsgrundlage: Contract performance (Art. 6(1)(b) GDPR)

    Datenübermittlung: Germany (EU) - no third country transfer

    Datenschutz:Link

    Hinweis: privacy.sections.thirdParty.hetzner.note

    Opt-Out: privacy.sections.thirdParty.hetzner.optOut

    Data Processing Agreements (Art. 28 GDPR)

    Where a service provider processes personal data on my behalf, an appropriate contract and transfer record must be reviewed and archived before production use. The following list describes the required contract basis; it does not claim that every record has already been archived.

    • Google Ireland Limited: applicable DPA and transfer record required for each activated service
    • Hotjar Ltd.: DPA record required before activation
    • Anthropic PBC: accepted Commercial Terms/DPA version, SCC/TIA decision, and account configuration required before use
    • Perplexity AI Inc.: DPA and transfer record required before use
    • Cal.com Inc.: DPA and transfer record required before use
    • Plus Five Five, Inc. (Resend): DPA, SCCs, and production account configuration must be documented
    • Cloudflare, Inc.: applicable Turnstile contract and transfer record must be documented
    • Aprixity Conversation Edge: self-hosted processing; technical and organisational measures and the Hetzner processor agreement must be documented
    • Hetzner Online GmbH: processor agreement required for the hosting services actually used

    You may ask [email protected] for information about recipients actually used and available records.

    Data Transfer to Third Countries (Art. 44-49 GDPR)

    When using certain services, your data is transferred to countries outside the EU/EEA:

    • USA: Google, Anthropic, Perplexity, Cal.com, Plus Five Five, Inc. (Resend), and Cloudflare - transfer basis per service actually activated: EU-US Data Privacy Framework and/or Standard Contractual Clauses (Art. 46(2)(c) GDPR)

    The specific transfer basis and account configuration are documented for each recipient that is actually activated. This notice does not assert an unverified contract or SCC version.

    Automated Decision-Making and Profiling (Art. 22 GDPR)

    The homepage directional diagnostic and the existing V6.1 assessment are calculated by rules; no generative AI model is required for the displayed results. Apri is separately labelled as an AI assistant.

    Zweck: The homepage diagnostic maps six questions to an intervention class. The existing assessment maps seven answers to bottleneck classes and may create an internal processing priority.

    The diagnosis and priority have no legal or similarly significant effect. They do affect internal processing order and whether an appointment option is shown at a score of 4 or more.

    Logik: Homepage rules assess frequency, outcome variance, decision type, data readiness, exception load, and human value. The result recommends removal, simplification, standardisation, instrumentation, automation, augmentation, deliberate preservation of human judgment, or capacity reallocation.

    Erklärbarkeit: On request, I will explain the rules and data used for your diagnosis and internal prioritization.

    Menschliche Überprüfung: Questions about the evaluation or requests for human review may be sent to [email protected].

    Widerspruchsrecht: You may object to internal sales prioritization based on legitimate interests. Contact: [email protected].

    Audit-Trail: Conversation Edge stores contact and answers encrypted, separates result and purpose, and records delivery and consent evidence. Private result tokens are stored only as hashes. Legacy assessment paths remain technically separate.

    Kontakt: For questions about automated processing: [email protected]

    Data Protection Impact Assessment and risk review (Art. 35 GDPR)

    The need for a Data Protection Impact Assessment is reviewed again after material changes to the assessment process. No outdated assessment result is presented as current evidence for V6.1.

    Umfang: Current review scope: rule-based bottleneck diagnosis, internal lead prioritization, and possible downstream recipients or AI processing.

    Betroffene Personen: Categories of data subjects: Managing directors and decision-makers of SMEs in Germany who voluntarily participate in the assessment.

    Empfänger: Recipients are listed above according to the processing that is actually activated.

    No public DPIA conclusion is asserted without current process-specific documentation.

    Current protection priorities:

    • No legal effect on data subjects - result is non-binding guidance
    • The rule-based logic and its practical consequence are disclosed
    • Marketing consent and privacy acknowledgement remain separate
    • Data minimization: only data required for each purpose is transferred
    • No sensitive categories of personal data (Art. 9 GDPR) are processed
    • Data-subject rights, objection, and a human contact channel remain available

    Schutzmaßnahmen: Technical and organizational measures, recipient approvals, and contract records must be supported by current internal evidence; this notice does not replace that evidence.

    Review status: V6.1 reassessment required after a material process change

    Review again before activating additional AI recipients or materially changing the scoring logic

    Privacy enquiries: [email protected]

    Data Retention (Art. 13(2)(a) GDPR)

    • Assessment data: 3 years after last contact (reference date: Dec 31 of following year) or until deletion request
    • Homepage diagnostic: private result link, encrypted answers, and contact are removed at the configured expiry or earlier after withdrawal or a deletion request; the link can be revoked
    • Finite result guidance: unconfirmed contact data is erased when the confirmation window expires; confirmed authority ends on completion, withdrawal, or configured expiry
    • Aprixity Briefing: unconfirmed contact data is erased when the confirmation window expires; confirmed authority remains until withdrawal or suppression, with no claimed calendar deletion deadline
    • After withdrawal, complaint, or suppression, the delivery address and send capability are erased; minimal consent and suppression evidence remains to meet legal evidence duties
    • Contact form data: 3 years after processing the inquiry (reference date: Dec 31 of following year)
    • Analytics data: 14 months (Google Analytics standard, automatic deletion)
    • Booking data: According to legal retention requirements (up to 10 years for tax-relevant data per German fiscal code)

    Retention period is determined by necessity for processing purpose and legal retention requirements. Deletion occurs at year-end after retention period expires.

    Your Rights (GDPR Chapter III)

    • Right to access (Art. 15) - Receive a copy of your stored data
    • Right to rectification (Art. 16) - Correction of inaccurate data
    • Right to erasure (Art. 17) - 'Right to be forgotten'
    • Right to restriction of processing (Art. 18)
    • Right to data portability (Art. 20) - Receive your data in machine-readable format
    • Right to object (Art. 21) - Object to processing based on legitimate interests
    • Right to withdraw consent (Art. 7(3)) - At any time without giving reasons
    • Right to lodge complaint with supervisory authority (Art. 77) - Competent: State Commissioner for Data Protection Lower Saxony

    Competent Supervisory Authority

    State Commissioner for Data Protection Lower Saxony

    Prinzenstrasse 5, 30159 Hannover, Germany

    Phone: +49 511 120-4500

    Email: [email protected]

    https://lfd.niedersachsen.de

    Contact for Data Protection Inquiries

    Email: [email protected]

    Subject: 'Data Protection Inquiry'

    Response time: Maximum 30 days per GDPR Art. 12(3)

    To process your request, I may require proof of identity.

    Changes to this Privacy Policy

    I reserve the right to adapt this privacy policy to comply with changed legal requirements or changes to the service and data processing. The current version can always be found on this page.