Privacy Policy
Information on Data Processing Pursuant to GDPR & TDDDG • Effective: August 2026
1. Data Controller
The Data Controller responsible for data processing on this website pursuant to the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
Maximilian Doepp
operating under the commercial name “AI Shift Solutions”
Moosmühlenweg 3a
85375 Neufahrn bei Freising
Germany
Phone: +49 15679 817183
E-Mail: office@ai-shift.solutions
Website: https://ai-shift.solutions/
2. Overview of Data Processing
We process personal data in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the Telecommunications Digital Services Data Protection Act (TDDDG).
3. Web Hosting & Server Log Files (Cloudflare & Google Cloud Run)
When accessing our website or application API endpoints, our hosting service providers automatically collect and process technical request information in server log files.
The processed technical data includes:
- IP address of the requesting device
- Date and time of access
- Name and URL of the accessed file / API endpoint
- Website from which access was initiated (Referrer URL)
- Browser type, operating system, and name of access provider
- HTTP status code and volume of data transferred
Infrastructure Service Providers:
- Cloudflare: Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) for Content Delivery Network (CDN), DNS management, email routing, and Cloudflare Pages web hosting.
- Google Cloud Run: Google Ireland Limited (Dublin, Ireland) / Google LLC (USA) as a managed serverless container platform to run backend services and API endpoints.
Legal Basis: Art. 6(1) lit. f GDPR. Our legitimate interest lies in ensuring secure, error-free website operation, load distribution, and system resilience.
4. Contacting Us (Contact Form & Email)
When you contact us via email or our website contact form, the data you provide (such as name, email address, area of interest, and message content) is processed to handle your inquiry.
Legal Basis: If your inquiry relates to pre-contractual measures or contract fulfillment, processing is based on Art. 6(1) lit. b GDPR. In all other cases, processing is based on our legitimate interest in processing incoming inquiries efficiently pursuant to Art. 6(1) lit. f GDPR.
Retention Period: The data is deleted once the inquiry has been fully processed and no statutory retention obligations or legitimate interests in continued storage apply.
5. Cookies & Device Storage (§ 25 TDDDG)
Our website utilizes technologies to store information on your terminal device or access information already stored on your device.
- Essential Storage: A technically necessary cookie is used to store your cookie consent preference (§ 25(2) No. 2 TDDDG in conjunction with Art. 6(1) lit. f GDPR).
- Consent-Based Storage: Non-essential technologies (such as web analytics) are loaded exclusively after receiving your explicit prior consent pursuant to § 25(1) TDDDG in conjunction with Art. 6(1) lit. a GDPR.
6. Web Analytics via Google Analytics 4 (GA4)
Subject to your explicit consent, we use Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland / Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Google Analytics 4 is configured to process IP addresses in accordance with Google's current EU data-processing mechanisms. Further information is available in Google's privacy documentation.
Legal Basis: § 25(1) TDDDG (device storage access) and Art. 6(1) lit. a GDPR (data processing).
Revocation: You can adjust or withdraw your consent at any time with future effect via the cookie settings on our website.
7. Payment Processing on Website (Stripe)
For web service payments, we utilize Stripe (Stripe Payments Europe, Ltd., Ireland / Stripe, Inc., USA).
Stripe processes payment and transaction data in accordance with its own data protection responsibilities and applicable contractual arrangements.
Legal Basis: Art. 6(1) lit. b GDPR (Contract Fulfillment) and Art. 6(1) lit. f GDPR (Legitimate Interest in secure transactions).
8. International Data Transfers (USA / DPF & SCCs)
Some service providers (e.g. Cloudflare, Google, Stripe) may process personal data in the United States.
Where applicable, transfers to the United States are based on an adequacy decision under the EU-U.S. Data Privacy Framework (DPF) for providers participating in the framework. Where the DPF does not apply, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) pursuant to Art. 46(2) lit. c GDPR.
9. Data Retention & Storage Criteria
Personal data is erased as soon as the relevant processing purpose ceases to apply. Where statutory retention obligations exist, the affected data is retained for the legally required duration.
10. Data Subject Rights Under GDPR
You hold the following statutory rights regarding your personal data under the GDPR:
- Right of Access (Art. 15 GDPR)
- Right to Rectification (Art. 16 GDPR)
- Right to Erasure („Right to be Forgotten“) (Art. 17 GDPR)
- Right to Restriction of Processing (Art. 18 GDPR)
- Right to Data Portability (Art. 20 GDPR)
- Right to Object (Art. 21 GDPR) – applicable to processing based on Art. 6(1) lit. e or f GDPR, subject to the conditions set out therein
- Right to Withdraw Consent (Art. 7(3) GDPR)
To exercise your rights, please submit an informal email request to: office@ai-shift.solutions.
11. Right to Lodge a Complaint with the Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority. The competent supervisory authority for non-public entities at our business seat in Bavaria is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Website: https://www.baylda.bayern.de
12. Requirement to Provide Personal Data
Providing personal data is partly required by law (e.g. tax laws) or contractual provisions. To enter into a contract with us, you must provide the data necessary for contract execution. Failure to provide such data would prevent us from concluding a contract.
13. Automated Decision-Making
We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
14. Data Security (Encryption)
For security reasons and to protect confidential content in transit, our site enforces TLS / HTTPS encryption. You can verify an encrypted connection by observing the "https://" prefix and lock icon in your browser URL bar.
15. Updates & Amendments
This Privacy Policy is effective as of August 2026. Future developments of our website or changes in legal regulations may necessitate periodic updates.