LEGAL
Privacy Policy
How we handle your personal data on webtrics.ai – transparently and in line with the GDPR.
I. Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection provisions is:
WebtricsFliederweg 122556 SchwadernauSwitzerlandEmail: hello@webtrics.comWeb: www.webtrics.aiII. Name and Address of the Data Protection Officer
The controller's data protection officer is:
WebtricsFliederweg 122556 SchwadernauSwitzerlandEmail: hello@webtrics.comWeb: www.webtrics.aiIII. General Information on Data Processing
1. Scope of the processing of personal data
We process our users' personal data only to the extent necessary to provide a functional website as well as our content and services. The processing of our users' personal data takes place regularly only with the user's consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of the data is permitted by law.
2. Legal basis for the processing of personal data
Insofar as we obtain the consent of the data subject for processing operations involving personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis. For the processing of personal data necessary for the performance of a contract to which the data subject is a party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary for carrying out pre-contractual measures. Insofar as the processing of personal data is necessary to comply with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis. If the processing is necessary to safeguard a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not override the former interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.
3. Data erasure and storage duration
The personal data of the data subject will be erased or blocked as soon as the purpose of storage ceases to apply. Storage beyond this may take place if provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. The data will also be blocked or erased if a storage period prescribed by the aforementioned norms expires, unless there is a need for further storage of the data for the conclusion or performance of a contract.
IV. Provision of the Website and Creation of Log Files
1. Description and scope of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer. The following data is collected:
- Information about the browser type and the version used
- The user's operating system
- The user's internet service provider
- The user's IP address
- Date and time of access
- Websites from which the user's system reaches our website
- Websites that are accessed by the user's system via our website
This data is also stored in the log files of our system. This data is not stored together with other personal data of the user.
2. Legal basis for data processing
The legal basis for the temporary storage of the data is Art. 6(1)(f) GDPR.
3. Purpose of data processing
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session. The storage in log files takes place in order to ensure the functionality of the website. In addition, the data serves us to optimize the website and to ensure the security of our information technology systems. No evaluation of the data for marketing purposes takes place in this context. Our legitimate interest in data processing pursuant to Art. 6(1)(f) GDPR also lies in these purposes.
4. Duration of storage
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended. In the case of the storage of data in log files, this is the case after seven days at the latest. Storage beyond this is possible. In this case, the users' IP addresses are erased or anonymized so that attribution to the accessing client is no longer possible.
5. Right of objection and removal
The collection of data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. Consequently, there is no possibility of objection on the part of the user.
V. Use of Cookies
a) Description and scope of data processing
Our website uses cookies. Cookies are text files that are stored in or by the internet browser on the user's computer system. If a user accesses a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is accessed again. We use cookies to make our website more user-friendly. Some elements of our website require that the accessing browser can be identified even after a change of page. The following data is stored and transmitted in the cookies:
- Language settings
- Items in a shopping cart
- Login information
In addition, we use cookies on our website that enable an analysis of the users' browsing behavior. In this way, the following data can be transmitted:
- Search terms entered
- Frequency of page views
- Use of website functions
When our website is accessed, the user is informed about the use of cookies for analysis purposes and their consent to the processing of the personal data used in this context is obtained. In this context, reference is also made to this privacy policy.
b) Legal basis for data processing
The legal basis for the processing of personal data using technically necessary cookies is Art. 6(1)(f) GDPR. The legal basis for the processing of personal data using cookies for analysis purposes, where the user has given consent to this, is Art. 6(1)(a) GDPR.
c) Purpose of data processing
The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after a change of page. The user data collected by technically necessary cookies is not used to create user profiles. The use of analysis cookies takes place for the purpose of improving the quality of our website and its content. Through the analysis cookies, we learn how the website is used and can thus continuously optimize our offering.
d) Duration of storage, right of objection and removal
Cookies are stored on the user's computer and transmitted from it to our site. Therefore, as a user you also have full control over the use of cookies. By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be erased at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all functions of the website to their full extent.
VI. Newsletter
1. Description and scope of data processing
On our website, there is the possibility to subscribe to a free newsletter. When registering for the newsletter, the data from the input mask is transmitted to us. This concerns at minimum the user's email address. In addition, the following data is collected upon registration:
- The IP address of the accessing computer
- Date and time of registration
For the processing of the data, your consent is obtained during the registration process and reference is made to this privacy policy. No data is passed on to third parties in connection with the data processing for sending the newsletter. The data is used exclusively for sending the newsletter.
2. Legal basis for data processing
The legal basis for the processing of the data after the user registers for the newsletter, where the user has given consent, is Art. 6(1)(a) GDPR.
3. Purpose of data processing
The collection of the user's email address serves to deliver the newsletter. The collection of other personal data during the registration process serves to prevent misuse of the services or of the email address used.
4. Duration of storage
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. The user's email address is therefore stored for as long as the subscription to the newsletter is active. The other personal data collected during the registration process is generally erased after a period of seven days.
5. Right of objection and removal
The subscription to the newsletter can be canceled by the affected user at any time. For this purpose, a corresponding link can be found in each newsletter. This also enables a revocation of the consent to the storage of the personal data collected during the registration process.
VII. Registration
1. Description and scope of data processing
On our website, we offer users the possibility to register by providing personal data. The data is entered into an input mask and transmitted to us and stored. The data is not passed on to third parties. The following data is collected as part of the registration process:
- The IP address of the user
- Date and time of registration
As part of the registration process, the user's consent to the processing of this data is obtained.
2. Legal basis for data processing
The legal basis for the processing of the data, where the user has given consent, is Art. 6(1)(a) GDPR. If the registration serves the performance of a contract to which the data subject is a party or the implementation of pre-contractual measures, the additional legal basis for the processing of the data is Art. 6(1)(b) GDPR.
3. Purpose of data processing
Registration of the user is required for the provision of certain content and services on our website.
4. Duration of storage
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. This is the case for the data collected during the registration process when the registration on our website is canceled or changed.
5. Right of objection and removal
As a user, you have the possibility to cancel the registration at any time. You can have the data stored about you changed at any time.
VIII. Contact Form and Email Contact
1. Description and scope of data processing
A contact form is available on our website, which can be used for electronic contact. If a user makes use of this option, the data entered in the input mask is transmitted to us and stored. At the time the message is sent, the following data is also stored:
- The IP address of the user
- Date and time of registration
For the processing of the data, your consent is obtained during the sending process and reference is made to this privacy policy. Alternatively, contact is possible via the email address provided. In this case, the user's personal data transmitted with the email will be stored. In this context, no data is passed on to third parties. The data is used exclusively for processing the conversation.
2. Legal basis for data processing
The legal basis for the processing of the data, where the user has given consent, is Art. 6(1)(a) GDPR. The legal basis for the processing of data transmitted in the course of sending an email is Art. 6(1)(f) GDPR. If the email contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6(1)(b) GDPR.
3. Purpose of data processing
The processing of the personal data from the input mask serves us solely to process the contact request. The other personal data processed during the sending process serves to prevent misuse of the contact form and to ensure the security of our information technology systems.
4. Duration of storage
The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and that which was sent by email, this is the case when the respective conversation with the user has ended. The additional personal data collected during the sending process is erased after a period of seven days at the latest.
5. Right of objection and removal
The user has the possibility to revoke their consent to the processing of personal data at any time. If the user contacts us by email, they can object to the storage of their personal data at any time. In such a case, the conversation cannot be continued. All personal data stored in the course of making contact will be erased in this case.
IX. Web Analysis by Matomo (formerly PIWIK)
1. Scope of the processing of personal data
On our website, we use the open-source software tool Matomo (formerly PIWIK) to analyze the browsing behavior of our users. The software sets a cookie on the users' computer. If individual pages of our website are accessed, the following data is stored:
- Two bytes of the IP address of the user's accessing system
- The website accessed
- The website from which the user reached the accessed website (referrer)
- The subpages that are accessed from the accessed website
- The time spent on the website
- The frequency of access to the website
The software runs exclusively on the servers of our website. Storage of the users' personal data takes place only there. The data is not passed on to third parties. The software is set so that the IP addresses are not stored in full, but two bytes of the IP address are masked (e.g.: 192.168.xxx.xxx). In this way, attribution of the shortened IP address to the accessing computer is no longer possible.
2. Legal basis for the processing of personal data
The legal basis for the processing of the users' personal data is Art. 6(1)(f) GDPR.
3. Purpose of data processing
The processing of the users' personal data enables us to analyze the browsing behavior of our users. By evaluating the data obtained, we are able to compile information about the use of the individual components of our website. This helps us to continuously improve our website and its user-friendliness. By anonymizing the IP address, the users' interest in the protection of their personal data is sufficiently taken into account.
4. Duration of storage
The data is erased as soon as it is no longer needed for our recording purposes.
X. Rights of the Data Subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
1. Right of access
You can request confirmation from the controller as to whether personal data concerning you is being processed by us. If such processing is taking place, you can request information about the purposes of processing, the categories of personal data processed, the recipients, the planned storage duration, the existence of a right to rectification or erasure, the existence of a right to lodge a complaint with a supervisory authority, the origin of the data, and the existence of automated decision-making including profiling.
2. Right to rectification
You have a right to rectification and/or completion vis-à-vis the controller, insofar as the processed personal data concerning you is incorrect or incomplete. The controller must carry out the rectification without delay.
3. Right to restriction of processing
Under certain conditions, you can request the restriction of the processing of the personal data concerning you – for example, if you dispute the accuracy of the data, if the processing is unlawful, if the controller no longer needs the data but you need it for legal claims, or if you have objected to the processing.
4. Right to erasure
You can request the controller to erase the personal data concerning you without delay, and the controller is obliged to erase this data without delay where one of the legal grounds applies – for example, if the data is no longer necessary, if you revoke your consent, or if the data was processed unlawfully. The right to erasure does not exist insofar as processing is necessary, e.g. to exercise the right to freedom of expression, to comply with a legal obligation, or for the establishment, exercise or defense of legal claims.
5. Right to be informed
If you have asserted the right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is obliged to notify all recipients to whom the personal data concerning you has been disclosed, unless this proves impossible or involves a disproportionate effort.
6. Right to data portability
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format, and the right to transmit this data to another controller without hindrance, provided the processing is based on consent or a contract and is carried out by automated means.
7. Right to object
You have the right, on grounds relating to your particular situation, to object at any time to the processing of the personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. If the personal data is processed for direct marketing purposes, you have the right to object at any time to such processing.
8. Right to revoke the data protection consent declaration
You have the right to revoke your data protection consent declaration at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the revocation.
9. Automated decision-making in individual cases including profiling
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you, unless one of the statutory exceptions applies.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, place of work or place of the alleged infringement, if you consider that the processing of the personal data concerning you infringes the GDPR.
XI. Storage of Chat Data and End-to-End Encryption
1. Storage of your workspace
When you use the Webtrics AI tool, your workspace – in particular your chats, folders, saved prompts and app settings – is stored so that it is available across your devices. Storage takes place on our infrastructure (database and file storage) on the basis of Art. 6(1)(b) GDPR for the performance of the usage relationship. Your API keys for third-party providers are always stored encrypted.
2. Optional end-to-end encryption (zero-knowledge)
You can optionally enable end-to-end encryption for your private workspace in the settings. When enabled, your chats, folders, prompts and settings are encrypted in your browser (AES-256-GCM) using a key derived from a passphrase you choose (PBKDF2). Only the resulting ciphertext is transmitted to and stored on our servers. Your passphrase and the derived key are never sent to us and are not known to us. As a result, with encryption enabled neither we nor any third party with access to the stored data can read your workspace contents – only you can, with your passphrase.
3. No recovery of the passphrase
Because we never receive your passphrase, we cannot reset it or recover your data. If you lose the passphrase, the encrypted workspace data becomes permanently inaccessible. Please store your passphrase safely.
4. Local storage on your device
For fast loading and offline availability, a copy of your workspace is also cached locally in your browser. This local copy is not covered by the end-to-end encryption and is stored in plain form on your own device. You can remove it at any time via 'Delete all data' in the settings or by clearing your browser storage.
5. Shared chats
If you deliberately share a chat (e.g. via a share link or with team members), a copy of that chat is stored so that the intended recipients can read it. Shared chats are therefore, by their nature, not end-to-end encrypted and remain readable for their recipients and, technically, for us. Only your private, unshared workspace is protected by end-to-end encryption.
XII. Connected Data Sources (Google and Microsoft)
1. Scope and purpose
You can optionally connect third-party accounts so that the AI can work with your own data. These connections are made only at your explicit request and can be revoked at any time. We currently support the following connections:
- Google Drive (file selection): you pick individual files in Google's own selector; only the files you actively choose are made available to us.
- Microsoft OneDrive: import of documents from a folder you specify for your knowledge base.
- Microsoft Outlook (Exchange): searching, reading, drafting and – only after your explicit confirmation – sending emails on your behalf.
The data retrieved from these sources is used exclusively to provide the feature you requested (building your knowledge base or assisting with your mailbox). It is not used for advertising, is not sold, and is not used to train generative AI models.
2. Authorisation and token storage
Access is granted via the provider's official OAuth flow. We store the resulting access and refresh tokens in encrypted form and use them solely to perform the actions you initiate. We never receive or store your account password. The legal basis is Art. 6(1)(b) GDPR (performance of the usage relationship) and, where applicable, your consent under Art. 6(1)(a) GDPR.
3. Google API Services – Limited Use
Webtrics' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. For Google Drive we request only the 'drive.file' scope, which limits access to the specific files you select via the Google Picker; we cannot see any other files in your Drive.
4. Revocation and deletion
You can disconnect any data source at any time under Settings → Plugins (or Knowledge), which deletes the stored tokens on our side. In addition, you can revoke access directly with the provider (Google Account → Security → Third-party access, or your Microsoft account settings). Once disconnected, we no longer access the respective source.