Privacy Policy

How we handle your data

Published

June 22, 2026

1. Controller

The controller responsible for data processing on this website is:

Dr. Tobias Vlćek

Email: vlcek@beyondsimulations.com

This policy covers the AI chat assistant (“Oshu”) embedded on this website and the privacy-friendly web analytics (Umami) used to measure site usage. To exercise your rights or for any questions about data processing, please contact us using the details above.

2. AI chat assistant (Oshu)

On this website we use an embeddable AI chat assistant operated on our behalf by BeyondSimulations GmbH, Am Eich 9d, 22113 Oststeinbek, Germany (“Oshu”) as our processor. A data processing agreement under Art. 28 GDPR is in place with Oshu.

Purpose: the assistant answers visitor questions based on content we have provided.

Data processed: when you use the chat, the messages you enter, the generated responses, and a conversation identifier are processed. Technical data such as your IP address is processed only transiently for security and abuse prevention and is not stored permanently with the conversation. Please do not enter special categories of personal data (Art. 9 GDPR) into the chat.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in answering enquiries efficiently). If the chat forms part of a contractual service, Art. 6(1)(b) GDPR.

3. Hosting and inference

Data is processed on servers of Hetzner Online GmbH in Falkenstein, Germany. Responses are generated via the EU API of Mistral AI SAS in Paris, France. There is no transfer to a third country, and the content is not used to train AI models.

4. Cookies

The widget sets two strictly necessary first-party cookies so a conversation can be resumed:

  • cw_conv_<agent> — conversation identifier
  • cw_conv_session_<agent> — signed session token to retrieve the conversation history

Both last approximately 24 hours, with SameSite=Lax and the Secure flag. No tracking, marketing, or third-party cookies are set.

Legal basis: § 25(2) TDDDG (strictly necessary cookies).

5. Retention

Conversation logs are automatically deleted after at most 12 months. If “private mode” is enabled, the content of visitor messages is not stored.

6. Web analytics (Umami)

To understand how this website is used and to improve its content, we use Umami, a privacy-friendly web analytics tool. Umami is self-hosted on our own infrastructure (umi.byndsim.com) on servers of Hetzner Online GmbH in Germany; usage data is not shared with third parties and there is no transfer to a third country.

No cookies, no tracking across sites: Umami does not set cookies and does not store any information on your device. It does not create a persistent identifier and does not track you across other websites.

Data processed: Umami collects aggregated, anonymized usage statistics such as the pages viewed, the referring website, and general information about your browser, operating system, device type, and country. Your IP address is used only transiently to derive this information and is not stored.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analyzing and improving our website). Because Umami does not store or access information on your device, no consent under § 25(1) TDDDG is required.

7. Your data protection rights

Under the EU General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

  • Right to access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restrict processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise any of these rights, please contact us as the controller using the details in Section 1. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.

8. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the date at the top. We encourage you to review this policy periodically.