Privacy Policy
Last updated: 23 August 2026
This is a courtesy English translation. The legally binding version is the German one. Protecting your personal data is important to us. The following explains how we process your data in accordance with the General Data Protection Regulation (GDPR).
1. Controller
The controller within the meaning of the GDPR is:
Bavaros UG (haftungsbeschränkt)
Gablonzer Ring 13
87600 Kaufbeuren, Deutschland
Email: kontakt@bavaros.de
For privacy questions, contact us at datenschutz@bavaros.de.
2. Your rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
3. Data collected when visiting our website
Each time our website is accessed, our system automatically collects technical data (browser type and version, operating system, referrer URL, host name, time of the request and the shortened/anonymized IP address). The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the technical provision, stability and security of our website. Log data is deleted after no later than 30 days.
Hosting
Our website and platform are hosted with a provider operating data centers in Germany (« insert hosting provider »). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place.
4. Cookies and local storage
This website uses no tracking or marketing cookies. We only use technically necessary local storage in your browser to remember your language and theme (light/dark) preferences. This data stays on your device and is not transmitted to us.
5. Contacting us
If you contact us via the contact form or by email, we process the data you provide (name, email address, optionally company, subject and your message) to handle your request and get back to you. Details submitted through the contact form are stored on our server; to prevent abuse and spam we additionally store the IP address and browser identifier (user agent) of the submitting device. Access is restricted to the people handling the request; the data is not shared with third parties. Legal basis: Art. 6(1)(b) or (f) GDPR. We delete the data once it is no longer required, at the latest after statutory retention periods expire.
To handle your request we forward it automatically to our own BavarOS platform, where an AI agent picks the case up and prepares it for processing. Only the form fields you provided are transmitted (name, email address, company, subject, message) - not your IP address or browser identifier. We operate that platform ourselves and host it in Germany, so no recipient outside our company is involved, and the transfer is encrypted (TLS) throughout. A human always decides on the outcome; there is no solely automated decision within the meaning of Art. 22 GDPR.
The copy of your request stored on the web server is deleted automatically no later than 30 days after receipt. Requests that could not be handed over to the platform for technical reasons are kept until handled manually, so your inquiry is not lost.
Once handed over to our platform, your request is stored there for as long as it is being handled and for the duration of any business relationship arising from it, and is deleted afterwards unless statutory retention obligations apply (in particular § 257 German Commercial Code and § 147 German Fiscal Code for business correspondence). A fixed period cannot be given for this part because it depends on how your inquiry develops; the criteria above are what determine it.
5a. Support requests
Through our support form (support.bavaros.de) and its API, you - or an AI agent acting on your behalf - can report a fault. We process the details of the report (tenant, name of the reporting person, affected process, severity, description, contact email) as well as the IP address and browser identifier to prevent abuse. Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract) and Art. 6(1)(f) GDPR (abuse prevention).
Error output and logs may optionally be submitted. These can contain personal data where they reproduce content from your cases. Please do not submit passwords, keys or credentials. Submitted logs are deleted automatically after 30 days; the ticket itself is deleted after 365 days at the latest. Where a report is made under a data processing agreement, we process the data it contains solely on your documented instructions pursuant to Art. 28 GDPR.
6. Registration and use of the platform
Using the BavarOS platform requires an account. We process master data (e.g. name, email, company), credentials and the content/usage data arising from use. Legal basis: Art. 6(1)(b) GDPR. Where we process personal data on behalf of our business customers, we act as a processor under Art. 28 GDPR; in that case the respective customer is the controller.
7. AI processing of content
Content you enter (prompts, uploaded documents) is processed to provide the AI features for the purpose of performing the contract (Art. 6(1)(b) GDPR). Inputs are not used to train third-party general-purpose AI models. Where sub-processors are used, this is based on Art. 28 GDPR agreements and, where required, appropriate safeguards for third-country transfers (Art. 44 et seq. GDPR, EU standard contractual clauses).
8. Recipients and disclosure
Your data is only disclosed to third parties where legally permitted, where you have consented, or where necessary to perform the contract. Service providers we use (e.g. hosting) are carefully selected and contractually bound under Art. 28 GDPR.
9. Retention
We store personal data only as long as necessary for the respective purpose or as required by statutory retention periods. Afterwards the data is deleted or restricted.
In practice the standard periods are: contact requests on the web server 30 days; support logs 30 days; support tickets 365 days; technical records of obvious attack and scanning attempts 7 days. For server log files see section 3.
No single period can be given for cases stored in our platform. What determines it is the duration of handling and of any business relationship arising from it, together with statutory retention obligations (§ 257 German Commercial Code, § 147 German Fiscal Code); the data is deleted afterwards. For data we process on behalf of our customers, the deletion rules of the relevant data processing agreement apply in addition.
10. Data security
We take state-of-the-art technical and organizational measures (Art. 32 GDPR), including transport encryption (TLS/HTTPS), encrypted storage of sensitive data, strict access controls and strictly separated data storage.
11. Updates to this policy
This privacy policy is currently valid. As our website evolves or due to changed legal requirements, it may become necessary to amend this policy.
