1. Controller
Vazghen Vardanian (Einzelunternehmen (Kleingewerbe)), trading as Advi Systems
Morsestraße 1, 50769 Köln, Germany
Email: iamvazghen@gmail.com · Phone: +49 176 22070509
We have not appointed a data protection officer because the conditions of § 38 BDSG are not met. Please send all privacy questions to the address above or use our data request form.
2. Summary
- We collect only what we need for the purpose in question. Our forms require only name, email, and your message.
- We don't use analytics, advertising cookies, or tracking pixels on this website.
- Our website chat loads only after you consent in the cookie banner or chat launcher.
- We don't sell personal data and don't use customer content to train AI models.
- Our database is hosted in Frankfurt (EU). Some service providers are in the USA; section 11 explains the safeguards.
3. Visiting this website
When you open a page, our hosting provider processes your IP address, date and time, the page requested, referrer, and browser information to deliver the page and protect it against attacks. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, working delivery). Server logs are deleted by the hosting provider after its standard period, usually within 30 days.
Fonts are served from our own server. No request is sent to Google or any other font service.
4. Cookies, local storage, and consent
We store your cookie choice in your browser (advi_consent_v1), which is technically necessary (§ 25(2) No. 2 TDDDG). The record also serves as proof of your consent (Art. 7(1) GDPR, legal basis Art. 6(1)(c)). If you sign in to the software, our sign-in provider sets session cookies that are necessary to keep you signed in. Details and a full list are in the Cookie Policy. You can change your choice at any time via “Cookie settings” in the footer.
5. Website chat (with consent)
If you consent, our chat assistant (Advi AI) loads on this website. It stores a random visitor ID and conversation ID in your browser, and processes the messages you send, the page you are on, and any contact details you choose to share. Messages are sent to an AI model through our AI gateway to generate answers (see section 10). Legal basis: consent, Art. 6(1)(a) GDPR and § 25(1) TDDDG; if you ask about our services, also Art. 6(1)(b). You can withdraw consent at any time in the cookie settings; stored IDs are then removed from your browser. Chat conversations are kept for up to 12 months and then deleted. Please don't share sensitive data (for example health data) in the chat.
6. Contact form, free strategy call, and email
When you request a strategy call or contact us, we process your name, email address, your message, and any optional details you add (phone, company, website, services of interest), plus your confirmation that you are at least 16. Purpose: answering your enquiry and preparing a possible contract. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) and Art. 6(1)(f) for general enquiries. Enquiries that don't lead to a contract are deleted 12 months after submission. If you email or call us directly, the same applies.
7. Data requests, cancellations, withdrawals, and unsubscribes
When you use our data request form, cancellation page, withdrawal function, or unsubscribe page, we process the details you enter to handle the request and to prove we did (Art. 6(1)(c) GDPR in connection with Art. 12–22 GDPR, §§ 312k, 356a BGB, and § 7 UWG). Data requests and withdrawals are kept for 3 years; cancellation records as long as statutory retention requires; unsubscribe entries for as long as needed to make sure we don't email you again (suppression list). We don't store your IP address with these requests.
8. Agency clients
For our clients and their contact persons we process contact details, contract and billing data, communication, and the access details needed to run the agreed services. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) (tax and commercial retention duties).
When we process personal data of our clients' customers on their behalf (for example leads, review requests, chat conversations, pipeline data), the client is the controller and we act as processor under a data processing agreement (Art. 28 GDPR). The client's own privacy policy applies to those people.
9. Advi AI software users
If you create an account for the Advi AI software, we process your account data (name, email, organisation and role), billing data from our payment provider (card numbers never reach us), your content (prompts, agents, knowledge-base items, conversations), and usage and security logs. Legal basis: Art. 6(1)(b) GDPR, Art. 6(1)(f) for security and abuse prevention, and Art. 6(1)(c) for retention duties. Visitors who talk to an agent on a customer's website are processed on behalf of that customer (Art. 28 GDPR); the customer is the controller.
10. Recipients and service providers
- Supabase Inc.: database and storage, hosted in Frankfurt, Germany.
- Hosting provider (Vercel Inc. and/or Railway Corp.): website and application hosting, server logs.
- Clerk Inc. (USA): sign-in, accounts, and subscription billing for the software.
- Payment provider connected to Clerk (Stripe): payment processing for software subscriptions.
- OpenRouter Inc. (USA) and the AI model provider selected for a request (for example OpenAI, Anthropic, Google, Meta, Z.AI, Arcee AI, Liquid AI): generating AI answers. Where a provider offers it, we use settings that exclude retention and training.
- OpenAI (USA): creating search embeddings of knowledge-base content.
- Suppliers for agency services (for example ad platforms, CRM or accounting software chosen by the client, hardware rental and coffee service providers): only the data needed for the service the client ordered.
- Tax adviser and authorities, where the law requires it.
All service providers acting on our behalf are bound by data processing agreements.
11. Transfers outside the EU
Some providers above are based in the USA. Transfers rely on the EU-US Data Privacy Framework where the recipient is certified (Art. 45 GDPR), and otherwise on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures. You can request a copy of the safeguards using the contact details above.
12. Marketing emails
We send marketing emails only with your consent, confirmed by double opt-in (Art. 6(1)(a) GDPR, § 7(2) UWG), or to existing clients about similar services as allowed by § 7(3) UWG. Every marketing email contains a one-click unsubscribe link, and you can also unsubscribe at /unsubscribe at any time. We record when and how consent was given.
13. Applicants
If you send us an application, we process it to decide on the collaboration (§ 26 BDSG, Art. 6(1)(b) GDPR) and delete it 6 months after the decision, unless you agree to a longer period.
14. Retention overview
- Enquiries without a contract: 12 months.
- Website chat conversations: 12 months.
- Client and contract data: for the contract term, then as long as statutory retention requires (up to 10 years for accounting records, § 147 AO, § 257 HGB).
- Software account data: while the account exists; deleted within 30 days after closure, except records we must keep by law.
- Software conversations: according to the retention of the customer's plan, or until deleted by the customer.
- Data requests and withdrawals: 3 years. Unsubscribe entries: as long as needed to honour the opt-out.
15. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to withdraw consent at any time with effect for the future (Art. 7(3)).
Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests, you can object at any time for reasons arising from your particular situation. You can object to direct marketing at any time without giving reasons.
Use our data request form or email us. We respond within one month (Art. 12(3) GDPR) and may ask you to confirm your identity first. You also have the right to lodge a complaint with a supervisory authority, for example the authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf.
16. Children
Our services are aimed at businesses and adults. We don't knowingly process data of children under 16. Our forms ask you to confirm that you are at least 16 (Art. 8 GDPR). If you believe a child has sent us personal data, please contact us and we'll delete it.
17. Automated decisions and AI
We don't make decisions with legal or similarly significant effects based solely on automated processing (Art. 22 GDPR). AI-generated chat answers and suggestions are information, not decisions. Before you enable our website chat, we tell you that its answers are generated by AI.
18. Security
We use encrypted connections (HTTPS), encryption at rest by our database provider, strict access controls, and database row-level security. See the Security page for details.
19. Changes
We update this policy when our processing changes. The current version is always available on this page.
Last updated: 2026-09-30