Privacy Policy
Here you will find our privacy policy. Please read this statement carefully. You are welcome to contact us at any time if you have any questions about it.
Data protection is particularly important to us:
Vimmera AI Solutions GmbH implements even more extensive measures for data protection and data security than are required by law. Company data and personal data are sensitive and must be protected at all costs. We therefore rely on encryption and additional security measures for data transmission and data storage (if we store data at all).
Please feel free to contact us if you have any questions about this as well.
Fully encrypted and confidential communication with us is possible by email. We use OpenPGP for this purpose. The public keys for encryption can be found on the relevant key servers.
Privacy Policy
Vimmera AI Solutions GmbH, Löwestrasse 66, 14612 Falkensee, Germany
1. General information on data protection
The protection of your personal data is a matter of particular concern to us. We treat personal data confidentially and process it exclusively in accordance with the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), the Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG), as well as other relevant data protection regulations.
With this privacy policy, we inform you about which personal data we collect, how and for what purposes we process it, on what legal basis the processing takes place, how long we store data, and what rights you have as a data subject.
We process personal data only to the extent necessary, in particular to provide a functioning website, for communication, for initiating and carrying out contractual relationships, for providing our services, for security and abuse prevention, and for fulfilling legal obligations.
If we do not collect personal data directly from you, such data originates – where applicable – from publicly accessible sources, business relationships, business partners, service providers, intermediaries, platforms, or existing contractual relationships. In such cases, we will inform you in accordance with legal requirements, in particular pursuant to Art. 14 GDPR, unless a legal exception applies.
The provision of personal data may be required by law or contract or necessary for the conclusion of a contract or the implementation of pre-contractual measures. Failure to provide such data may mean that we cannot process inquiries, conclude contracts, or provide services. Where data is provided voluntarily, there are generally no adverse consequences if it is not provided, unless the respective processing is mandatory for the intended purpose.
2. Definitions
This privacy policy uses the terms defined in Art. 4 GDPR. These include in particular:
- Personal data means any information relating to an identified or identifiable natural person.
- Data subject means any identified or identifiable natural person whose personal data is processed.
- Processing means any operation performed in connection with personal data, in particular collection, recording, storage, use, disclosure, transmission, or erasure.
- Restriction of processing means the marking of stored personal data with the aim of limiting its future processing.
- Profiling means any form of automated processing of personal data used to evaluate personal aspects relating to a natural person.
- Pseudonymization means the processing of personal data in such a way that it can no longer be attributed to a specific person without additional information.
- Controller means the natural or legal person who determines the purposes and means of the processing.
- Processor means an entity that processes personal data on behalf of the controller.
- Recipient means an entity to which personal data is disclosed.
- Third party means any entity other than the data subject, controller, or processor.
- Consent means any freely given, informed, and unambiguous indication of the data subject’s wishes.
3. Controller
Vimmera AI Solutions GmbH
represented by the managing director: Rasmus Abromeit
Löwestrasse 66
14612 Falkensee
Germany
Phone: +49 (0)163 8353802 or +49 (0)3322 8310939
Email: info@vimmera.de
Website: www.vimmera.de
4. Data Protection Officer
A data protection officer is currently not appointed pursuant to Art. 37 GDPR, as the legal requirements for this are not met. If you have any data protection concerns, please contact the contact details listed above.
5. Competent data protection supervisory authority
The State Commissioner for Data Protection and for the Right to Inspect Files Brandenburg
Stahnsdorfer Damm 77
14532 Kleinmachnow
Germany
Email: poststelle@lda.brandenburg.de
Website: https://www.lda.brandenburg.de
6. Legal basis for processing
We process personal data on the basis of
- Art. 6(1)(a) GDPR (consent)
- Art. 6(1)(b) GDPR (contract / pre-contractual measures)
- Art. 6(1)(c) GDPR (legal obligations)
- Art. 6(1)(f) GDPR (legitimate interests)
Our legitimate interests consist in particular in providing a functioning website and IT infrastructure, providing modern AI-based functions, communicating with customers, prospects, and partners, optimizing and further developing our services, and preventing security incidents and abuse.
Withdrawal of consent in general:
Where we process personal data on the basis of consent pursuant to Art. 6(1)(a) GDPR, you may withdraw this consent at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Recipients/categories of recipients, Art. 13(1)(e) GDPR:
Depending on the purpose of processing, personal data may be transferred to recipients or categories of recipients, in particular to hosting providers, IT and cloud service providers, communication service providers, support and maintenance service providers, newsletter distribution service providers (if used), as well as authorities and public bodies, insofar as we are legally obliged to do so. Where processors are used, this is done on the basis of data processing agreements pursuant to Art. 28 GDPR.
7. Data collection on our website
7.1 Server log files
When you access our website, the following data is automatically processed
- IP address
- Date and time of access
- pages and files accessed
- referrer URL
- browser type and version
- operating system used
- internet service provider
This data is processed for technical provision, system security, cyber defense, error analysis, and statistical evaluation.
No merging with other personal data takes place.
Legal basis Art. 6(1)(f) GDPR
Storage period maximum 14 days, unless there is a security-related necessity.
Hosting is provided by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin.
A data processing agreement exists pursuant to Art. 28 GDPR.
Processing takes place exclusively in EU data centers with certified security standards.
7.2 Cookies, local storage, and similar technologies
Our website may use technologies that store or read information on your device (e.g. cookies, local storage) in order to technically provide the website, operate it securely, and enable functions.
Technically necessary technologies:
Where cookies/similar technologies are required for the operation of the website (e.g. security functions), processing is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR and on the basis of the relevant provisions of the TDDDG.
Consent-required technologies:
Where we use cookies/similar technologies for analysis or marketing purposes, this is done only with your prior consent. The legal basis is then Art. 6(1)(a) GDPR in conjunction with the TDDDG. You may withdraw consent given at any time for the future, e.g. via your browser settings or a consent tool that may be used.
Note: If analysis or marketing cookies are currently used on our website, we will disclose this transparently in the respective consent banner or in the cookie settings.
8. Feedback forms and other forms
On our website, we provide forms through which users can submit feedback or information (e.g. feedback on events, reviews, suggestions, or other comments). Our forms are designed – unless expressly stated otherwise – so that no personal data is requested.
No entry of personal data
Personal data is generally neither required nor intended for the use of these forms. In the forms, we expressly point out that no personal data (e.g. name, contact details, or specific personal references) should be entered.
Categories of data processed
We process only the content entered by you (e.g. free text, ratings, selection fields). If, contrary to the notice, you submit personal or sensitive information, we will process it only to the extent necessary to review and remove such content.
Purpose of processing
Processing takes place exclusively for the respective stated purpose, in particular for evaluation, quality assurance, and improvement of offers, services, or events.
Legal basis
Processing is carried out on the basis of our legitimate interest in quality assurance, evaluation, and optimization of our services pursuant to Art. 6(1)(f) GDPR.
Recipients / disclosure
Disclosure of the content takes place only to the extent necessary to achieve the respective purpose, in particular to responsible parties or organizers (e.g. in the case of event feedback). Before disclosure, trained, instructed, and confidentiality-bound personnel review the submitted content. We remove personal data or sensitive content if such content was entered contrary to the instructions.
Access restrictions and confidentiality
Only authorized persons have access to the form data (need-to-know principle). Access is protected by appropriate authorization and access concepts.
Storage period and deletion
We store form data only as long as necessary for the respective purpose and then delete it. For event feedback, deletion takes place no later than 3 months after the respective event, unless statutory retention obligations prevent this.
Voluntariness
Use of the forms is voluntary. There are no disadvantages if you do not use a form.
Technical notes (where applicable)
When using the website and its forms, server log data may arise for technical reasons (e.g. IP address, time of access, browser/device information) in order to ensure the security and operation of the website. This processing is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR and is subject to the general provisions of this privacy policy on server logs.
9. Contacting us
If you contact us by email, telephone, or via a contact form, we process the personal data you provide to handle your request and communicate with you.
Depending on the contact method, we process in particular the following data:
- Name
- Email address
- Telephone number (optional)
- Message content
Purpose of processing
Handling your request, communication, and, if applicable, initiating or carrying out a contractual relationship.
Legal bases
Processing is carried out pursuant to Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient handling of inquiries and communication).
Storage period
We generally store the data processed in the course of contacting us until your request has been fully handled. Beyond that, we store data only insofar as statutory retention obligations exist or this is necessary for the assertion, exercise, or defense of legal claims.
Consequences of not providing data
Providing the data marked as required is necessary in order to process your request or to initiate or carry out a contract. Without this information, it is generally not possible to process your request.
10. Newsletter
If you subscribe to our newsletter, we process the following data as part of the registration and newsletter distribution: email address as well as technical verification data (e.g. IP address, date and time of registration and confirmation).
We use the double opt-in procedure.
Legal basis: Art. 6(1)(a) GDPR.
Withdrawal: possible at any time with effect for the future (e.g. via the unsubscribe link).
Storage period: until you withdraw your consent.
The newsletter is currently sent via our own systems or via the technical services used for this purpose within our IT infrastructure.
11. Application Process
If you apply to us, we process your application data to carry out the application process.
Processed data: contact details, application documents, qualification data, communication data.
Legal bases: Section 26 BDSG and Art. 6(1)(b) GDPR.
Storage period:
If an application is rejected, we delete application data no later than after 6 months, unless longer storage is required for the assertion, exercise or defense of legal claims. If you are hired, we transfer the data to the personnel file.
Obligation to provide data:
Providing the application data is necessary in order to carry out the application process.
12. Social Media
12.1 Company profiles on social media
We operate company profiles on LinkedIn, XING, Facebook, Instagram and GitHub. When you visit our social media profiles, the respective platform operators process personal data on their own responsibility. The privacy policies of the respective providers apply. Data transfers to third countries may occur.
To the extent that we receive statistical evaluations (e.g. page insights) via the platforms, joint controllership pursuant to Art. 26 GDPR may exist with the respective platform operator. The platform operators provide the essential content of the agreements in their privacy/insights information.
Legal basis for our processing in connection with operating the profiles: Art. 6(1)(f) GDPR (public relations, information and communication).
12.2 Social media / social plugins on our website
We have integrated the social plugins of the social media services embedded on our website using the so-called “two-click solution”. These are the plugins of the following providers:
- Facebook, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Facebook”)
- LinkedIn, operated by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (“LinkedIn”)
- Twitter, operated by Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (“Twitter”)
- Pinterest, operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”)
- YouTube, operated by Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“YouTube”)
- XING, operated by XING, a product of New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany (“XING”)
“Two-click solution” means that when you visit our website and click on the social plugin of the respective social media service, no automated data transfer to the social media provider begins; instead, it only starts after you click again on the link that opens and redirects you to the social media provider’s page. Please note that the privacy policy of the respective social media provider applies to data processing on the social media service’s page.
12.3 Data collected, purpose of data processing, legal basis:
We process the data you enter in the respective social media service, in particular your username and the content published under your account, insofar as we may comment on your posts or refer to your presence in our posts. The legal basis for this processing is our legitimate interest (Art. 6(1)(f) GDPR). The data published by you in the social media service is incorporated into our offering and made accessible to our followers/fans and subscribers.
13. AI Systems, Microsoft Azure and OpenAI
On our website and as part of our digital services, functions based on artificial intelligence (AI) may be used. This may include, in particular, an AI-supported website chat through which users can receive general information about our company, our services, our offers, the content of our website and other information provided.
The AI-supported chat serves to provide information in a user-friendly manner, support general inquiries, improve the discoverability of content, and enable efficient communication with users.
Notice of AI-supported interaction
If users interact with functions of Vimmera AI Solutions GmbH that are based on artificial intelligence, it is expressly pointed out that this is an AI-supported interaction and not communication with a natural person.
The labeling of the AI interaction is transparent and clear for users, in particular through corresponding notices in the user interface, in the system information, in the terms of use and, where applicable, within the dialogue itself.
The content generated by the AI is created automatically. It is based on probabilistic models and may, despite careful technical design, be incorrect, incomplete, outdated or misleading. The output content does not constitute binding statements, assessments, recommendations or decisions and does not replace legal, tax, medical, technical or other professional advice. Users are obliged to check AI results on their own responsibility before reusing them or making decisions based on them.
The use of AI is exclusively for assisting and supporting purposes. No automated decision-making with legal effect or similarly significant impact on users takes place.
Transparency under the AI Act
The AI systems we use are subject, where applicable, to the transparency requirements of the Regulation (EU) on Artificial Intelligence (AI Act). We therefore inform users when they interact with an AI system or use AI-generated content.
According to their current mode of operation, the systems used are classified as systems with limited risk or as assisting AI systems. The systems are used to support information, communication and the handling of general requests. They are not designed to make legally binding decisions about users independently.
We comply with the relevant transparency, documentation and due diligence obligations, in particular with regard to informing users, purpose limitation, traceability, and the responsible design and use of the AI systems employed. The corresponding transparency information is reviewed regularly and adjusted if the scope of functions, the systems used, the legal situation or the regulatory framework changes.
Data processed when using AI functions
When using AI-supported functions, the following data may be processed in particular:
- the content entered by users,
- any personal data contained in the input,
- technical metadata,
- communication data,
- chat histories or communication histories, insofar as this is necessary for provision, security, error analysis or traceability,
- time of use,
- browser and device information,
- system and connection information,
- IP address.
Entering personal data is generally not required to use the AI-supported website chat. Users should, if possible, not enter any sensitive personal data, no special categories of personal data within the meaning of Art. 9 GDPR, no confidential business secrets and no third-party data into the chat unless this is absolutely necessary for the respective request.
If users nevertheless enter personal or sensitive information, it will only be processed within the scope of the respective request and in accordance with this privacy policy.
The entered content is not used for training purposes without an express agreement, express consent or separate information to the affected users.
Purposes of processing
The processing of personal data in connection with AI-supported functions takes place in particular for the following purposes:
- provision and operation of AI-supported functions,
- provision and operation of the AI-supported website chat,
- answering general user inquiries,
- supporting navigation and information search on our website,
- improving the user-friendliness of our digital offerings,
- technical provision, stability and security of the systems,
- IT security, abuse detection and abuse prevention,
- error analysis, maintenance and technical improvement,
- traceability of system functions, where necessary,
- fulfillment of legal documentation, security or evidence obligations, where applicable.
Legal bases for processing
The processing of personal data in connection with AI-supported functions is based, insofar as the use serves general information and communication, on Art. 6(1)(f) GDPR. Our legitimate interest lies in the user-friendly provision of information, the improvement of communication, the efficient handling of general inquiries, ensuring technical operation and guaranteeing IT security.
If an inquiry is aimed at initiating or performing a contractual relationship, processing is additionally based on Art. 6(1)(b) GDPR.
If consent is required for certain functions or use is expressly voluntary and based on consent, processing is based on Art. 6(1)(a) GDPR. Any consent given may be withdrawn at any time with effect for the future.
Technical service providers and infrastructure used
We use technical service providers to operate AI-supported functions. These include in particular hosting providers, cloud and AI infrastructure providers, IT service providers, maintenance and support service providers, and providers of technical security and logging functions.
To the extent that service providers process personal data on our behalf, this is done on the basis of corresponding data processing agreements pursuant to Art. 28 GDPR. In this case, the service providers process personal data only on our instructions and only for the agreed purposes.
The following infrastructures and service providers may be used in particular for the technical provision of AI-supported functions:
Microsoft Azure
Microsoft Ireland Operations Limited, Dublin, Ireland.
Processing takes place, where possible, in data centers within the European Union. Microsoft Azure provides certified security and cloud infrastructures for this purpose. To the extent that Microsoft processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
OpenAI
OpenAI Ireland Limited, Dublin, Ireland.
To the extent that services or models from OpenAI are used and personal data is processed in the process, processing takes place in accordance with the European legal structure and the applicable contractual data protection provisions. Personal data is transferred to a third country only if the requirements of Art. 44 et seq. GDPR are met.
Processing takes place within the European Union or the European Economic Area wherever possible. Internal systems, such as calendar or administration systems, are operated on our own servers or on contractually bound servers within the European Union.
Third-country transfers and appropriate safeguards
If, in individual cases, personal data is transferred to a third country outside the European Economic Area (EEA), this is done exclusively in compliance with the requirements of Art. 44 et seq. GDPR.
Where necessary, appropriate safeguards are used. These include in particular adequacy decisions of the European Commission, EU Standard Contractual Clauses (SCCs) or comparable mechanisms, insofar as these are required and permissible under the respective circumstances.
Storage and deletion
User inputs, chat histories and associated log data are stored only for as long as is necessary for providing the function, processing the request, technical security, traceability, error analysis, abuse prevention or compliance with legal obligations.
Thereafter, the data is deleted or anonymized, unless statutory retention obligations or legitimate interests in further storage prevent this.
Server and security logs are generally stored only for a limited period, unless longer storage is required to investigate security incidents, to defend against abuse, or to assert, exercise or defend legal claims.
Voluntariness and alternative contact options
The use of AI-supported functions and the AI-supported website chat is voluntary. Users can alternatively contact us via the contact channels stated in this privacy policy or in the legal notice.
14. Disclosure of personal data
Personal data is disclosed only if there is a legal basis for doing so, in particular in the event of a legal obligation, for the performance of a contract, in the context of data processing on behalf of a controller, or on the basis of your consent.
Transfer to third countries (countries outside the EU or EEA) takes place only in compliance with the requirements of Art. 44 et seq. GDPR, in particular where an adequacy decision, appropriate safeguards (e.g. EU Standard Contractual Clauses) or explicit consent are in place.
15. Storage period and deletion
We delete or block personal data as soon as the purpose of processing no longer applies and no statutory retention obligations prevent this. If no specific storage periods are stated in this privacy policy, the storage period is determined by the purpose of processing and by statutory retention obligations (e.g. commercial and tax retention periods).
Examples:
- Server log files: generally a maximum of 14 days.
- Application data in the event of rejection: no later than after 3 months.
- Newsletter data: until consent is withdrawn.
- Contract and billing data: in accordance with statutory retention obligations, then deletion.
16. Rights of data subjects
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR).
Right to object (Art. 21 GDPR):
To the extent that we process data on the basis of Art. 6(1)(f) GDPR, you may object to this processing at any time for reasons arising from your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise, or defense of legal claims.
17. Data security
We take appropriate technical and organizational measures (TOM) in accordance with Art. 32 GDPR to protect personal data against accidental or intentional manipulation, loss, destruction, as well as against unauthorized access. In doing so, we take into account the state of the art, implementation costs, the nature, scope, circumstances, and purposes of processing, as well as the varying likelihoods and severity of the risks to the rights and freedoms of natural persons.
Our measures include in particular:
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, our website uses SSL/TLS encryption. You can recognize an encrypted connection in your browser’s address bar (e.g., “https://”) and by the lock symbol. Data you transmit to us cannot be read by third parties.
Access protection and authorization concepts
Access to personal data is restricted to those persons who need it to fulfill their tasks (need-to-know principle). We use role-based authorization concepts and suitable authentication procedures.
Integrity and availability
We use measures to ensure the integrity and availability of data, in particular regular backups, logging, and protective mechanisms against unauthorized access and attacks.
Training and confidentiality
Our employees are regularly trained in data protection and data security and are obliged to maintain confidentiality.
Continuous improvement
We regularly review and update our security measures to adapt them to technical developments and risk situations.
18. No automated decision-making
No profiling pursuant to Art. 22 GDPR.
There is no automated decision-making, including profiling within the meaning of Art. 22 GDPR. In particular, personal data is not used to make decisions that have legal effects concerning you or similarly significantly affect you.
19. Updates
This privacy policy is reviewed and updated regularly.
20. Status
Status: 09 June 2026