Privacy Policy

This policy explains the processing of personal data on startvisor.ai and ailoft.de, including the AI chat, appointment booking, and support portal.

1. Controller

NC AGENTIC GmbH
Lilienstraße 11
20095 Hamburg
Germany

Represented by: Gerald Fehringer
Privacy contact: dsb@startvisor.ai

2. Hosting, page requests, and security

The websites and application data are operated by a hosting processor in the European Union. On access, we process in particular a truncated IP address, time, requested URL, referrer, browser/device information, and response status. The purpose is secure delivery, troubleshooting, and attack prevention under Article 6(1)(f) GDPR. Our legitimate interest is secure and stable operation.

Web access logs rotate daily and are deleted after no more than 30 days. Full IP addresses may be processed temporarily in memory for abuse and rate controls; entries expire after a few minutes and no later than 24 hours, depending on the security function.

3. Cookies and local storage

We use no analytics, marketing, or tracking cookies and serve web fonts locally. We therefore do not display a consent banner. The following strictly necessary storage may be used:

  • access_token: authentication cookie for the support portal; HttpOnly, Secure in production, SameSite=Lax; 24 hours or until logout.
  • preferred_locale: local browser storage for your actively selected language; until changed or deleted by you.

Access to the device is based on § 25(2) no. 2 TDDDG because storage is necessary for the expressly requested login or language selection. Subsequent processing relies on Article 6(1)(b) GDPR where contractually necessary and otherwise Article 6(1)(f). A legacy, no longer read cookie_consent entry may remain from an earlier version and can be deleted.

4. AI chat, image analysis, and voice

When you actively use the AI assistant, we process your input, conversation context, voluntarily uploaded images, and technical security data. For voice, after microphone permission, audio and transcript are sent over an encrypted connection to a specialised AI processor. No chat, image, or audio data is transferred without active use.

The AI processor and its subprocessors process data to provide and secure the service and detect abuse. Under the terms we use, content is not used for general training or improvement of third-party products; security logs and transient caches are retained only for limited periods.

The purpose is to answer your request, analyse images, provide voice interaction, and—at your request—assist with booking. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual enquiries and otherwise Article 6(1)(f) (our interest in a usable information and support service). Our server does not persist chat history; the browser retains it only for the current session. Do not submit trade secrets or special-category data under Article 9 GDPR.

5. Booking, contact, and email

For bookings, we process name, email, optional phone and notes, selected service, date, time, and time zone. A booking and communications processor handles this data. We use an email processor for confirmations and one-time codes.

For contact enquiries, we process your contact details and message to respond. The basis is Article 6(1)(b) GDPR for steps toward or performance of a contract and otherwise Article 6(1)(f). Booking and communication data is deleted after completion unless statutory retention, evidence, or limitation interests require continued storage.

6. Support portal, login, and tickets

The portal is for registered business customers. For accounts, we process email, a derived hash, customer assignment, role, and last login in an access-restricted database. One-time codes are stored only as hashes, normally remain valid for five minutes, and are deleted after use, expiry, or too many failed attempts. The login cookie expires after 24 hours.

Ticket subject, description, comments, and voluntary attachments are stored in an access-restricted support system operated by a processor. The AI processor also analyses ticket content to suggest priority, category, and sentiment for the support team. Humans decide handling and priority; there is no solely automated decision under Article 22 GDPR.

The basis is Article 6(1)(b) GDPR. Accounts, tickets, and attachments remain for the support relationship and afterwards only while contractual documentation, statutory retention, or limitation purposes require them. Deletion requests are assessed against those duties.

7. Recipients and international transfers

Apart from named providers, only personnel and service providers receive access where necessary for operation, communication, support, or legal duties. Transfers outside the EEA rely, depending on the recipient, on an adequacy decision under Article 45 GDPR—particularly the EU-US Data Privacy Framework for certified recipients—or safeguards under Article 46 such as EU Standard Contractual Clauses. Copies or details can be requested from the privacy contact.

Recipient categories are hosting, AI processing, booking and communications, email delivery, and access-restricted support infrastructure. Details about the current recipients and safeguards are available from the privacy contact on request.

8. External links and social networks

Links to booking services, social networks, video or developer platforms, and other external services generally transfer data only when you follow them. The relevant provider is responsible afterwards. We embed no social-media tracking pixels.

9. Retention

Where no period is specified above, we delete or anonymise data once its purpose ends. Longer storage occurs only for statutory retention duties, establishing or defending claims, or contract documentation requested by you. Relevant periods include commercial, tax, and statutory limitation periods.

10. Your rights

Subject to statutory conditions, you have rights of access (Article 15 GDPR), rectification (16), erasure (17), restriction (18), portability (20), and objection (21). Consent can be withdrawn at any time for the future. Contact dsb@startvisor.ai.

Objection: Where processing relies on Article 6(1)(f), you may object for reasons arising from your particular situation. You may object to direct marketing at any time without reasons; we currently conduct no website direct marketing based on usage profiles.

11. Complaint

You may complain to a supervisory authority, particularly the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, mailbox@datenschutz.hamburg.de, datenschutz-hamburg.de.

12. Required data and automated decisions

No additional data is required for an informational visit. Without the information needed for contact, booking, or support, however, we cannot process that request. We conduct no solely automated decisions producing legal or similarly significant effects and no profiling for that purpose.

13. Security and updates

We use appropriate technical and organisational measures, including TLS, access controls, protected support systems, short-lived login tokens, and security limits. We update this policy if the law or processing changes materially.

Version: July 2026