Skip to content

Privacy Policy

The protection of your personal data matters to us. Below we explain the nature, scope and purpose of the collection and use of personal data on our website.

1. Controller

The controller responsible for data processing under the GDPR is the provider named in the imprint. Contact: felix@vectimo.ai.

2. Data we collect

Depending on how you use our site, we collect different categories of personal data:

Newsletter signup

Email address, timestamp of consent (consentAt) and IP address at the time of signup (consentIp, stored to document consent and prevent abuse).

AI Readiness tool

Optional: your email address and the resulting maturity tier tag (e.g. ai-readiness-vorreiter). Individual answers are processed exclusively in your browser and are never transmitted to us.

Server logs

Our hosting provider records technical logs (truncated IP address, user agent, timestamp, requested URL). They are stored solely to ensure trouble-free operation and to defend against attacks.

3. Purposes of processing

We process your data to (a) deliver the newsletter, (b) operate the AI Readiness tool and send the requested report, (c) ensure the availability, security and stability of our website, and (d) comply with statutory documentation obligations.

4. Legal basis

Processing is based on your consent (Art. 6 (1) lit. a GDPR — in particular for the newsletter and report delivery) and on our legitimate interest in operating a secure and efficient website (Art. 6 (1) lit. f GDPR — in particular server logs and abuse prevention).

5. Retention periods

Newsletter data is retained until you unsubscribe or withdraw your consent. Server logs are deleted or anonymised after no more than 30 days. Tool data is kept only to the extent required for newsletter delivery.

6. Processors and third-party services

We use carefully selected service providers, each under a data processing agreement pursuant to Art. 28 GDPR:

Resend (email delivery)

Resend, Inc. (USA). Transfers to the US take place under the EU-US Data Privacy Framework (EU-US DPF). Purpose: delivery of confirmation and newsletter emails.

Neon (database)

Neon, Inc. — Postgres database hosting in the Frankfurt (EU) region. Purpose: storage of newsletter subscriber data.

Vercel (hosting)

Vercel Inc. — hosting of this website, primarily executed in the Frankfurt (EU) region. A current subprocessor list is available at vercel.com/legal/subprocessors.

Cloudflare R2 (object storage)

Cloudflare, Inc. — not currently in active use for personal data. Listed here for completeness and will be activated once we need asset hosting (e.g. for images or course videos).

PostHog (EU, product analytics)

We use PostHog to understand how visitors interact with this site (e.g. which pages are visited, which forms are submitted). PostHog is hosted on servers in the EU (posthog.com, EU region). Processing only occurs with your explicit consent via our consent banner. No data is transmitted to PostHog without your consent. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw consent at any time by clearing this site's browser storage.

7. Cookies and tracking

We use strictly necessary technical cookies to keep the site functional, and — only after your explicit consent via the consent banner — cookies/local storage for product analytics with PostHog (see section 6). No analytics cookies are set without your consent.

8. Your rights

You have the following rights regarding your personal data at any time:

  • Right of access to stored data (Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 16 GDPR)
  • Right to erasure ("right to be forgotten", Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent with effect for the future
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

9. Contact for privacy requests

For access requests, deletion, or withdrawal of consent, please email felix@vectimo.ai. We will respond within the statutory timeframes.