Privacy Policy
This is a convenience translation. In case of any discrepancy, the German version at solarisagents.com/datenschutz prevails.
This policy explains how personal data is processed on solarisagents.com and konfig.solarisagents.com, in accordance with the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Controller
- Solaris Agent e.U.
- Lilienfelderstraße 54/2/1, 3150 Wilhelmsburg, Austria
- Email: office@solarisagents.com
2. Hosting, server logs and audience measurement
This website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). When you access the site, Vercel processes technically necessary server log data (IP address, timestamp, requested resource, user agent) in order to deliver and secure the site. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning web presence).
Place of processing: Server-side processing (page rendering, sign-in, form and chat requests) takes place in the European Union — data centre Dublin, Ireland, right next to our database, which is also operated in Ireland. Vercel Inc. is nevertheless a US company as the provider, so access from the USA (for example during support or maintenance) cannot be ruled out. For that case, transfers are safeguarded under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.
All fonts, videos and other assets on this website are served from our own servers. Simply visiting the website triggers no requests to third parties — no external CDNs, no Google Fonts, no advertising networks and no cross-site tracking.
Audience measurement: On our public pages we use Vercel Web Analytics to count how often each page is opened. The service comes from the same provider that hosts this website and is served from our own address, so no request goes to an external server. No cookies are set, and no data is stored on or read from your device. Recorded per page view are: timestamp, the address opened, the referring page, filtered address parameters, approximate origin (country, region, city), operating system, browser and device type. Repeat views are grouped by a check value computed from the request, which expires after 24 hours; your IP address is neither stored nor linked to these figures. We only ever see aggregated reports and cannot identify an individual person from them — nor follow anyone across websites. No audience measurement takes place in the signed-in client and partner area. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing which content is in demand). You may object to the measurement at any time — a message to the address given above is sufficient; common content blockers also prevent it.
3. Contact form
If you use our contact form, we process your name, email address, optionally your phone number and the content of your message in order to handle your enquiry and any follow-up questions. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures). The data is stored in our database (section 8); our team is notified by email (email delivery provider Resend) and, for urgent enquiries, additionally by a short messenger notification — that message contains no personal data, only an internal reference ID. To prevent abuse, your IP address is processed by a rate-limiting counter for a maximum of 60 seconds (Art. 6(1)(f) GDPR).
Marketing consent (optional): Below the form — including on the "AI check" page — you can separately allow us to contact you about AI assistants, chatbots and automation by phone and email. This consent is not a condition for handling your enquiry. It only takes effect once you click the confirmation link in the email we send for that purpose (double opt-in); until then we keep your details in a queue for at most 7 days and delete them afterwards. On confirmation we store, as evidence, the wording of the consent, the time, the chosen channels, the browser type and a non-reversible check value of your IP address (Art. 6(1)(a) GDPR; § 174 of the Austrian Telecommunications Act 2021). You may withdraw at any time by an informal message to the address above — the withdrawal is documented as well.
Source tag: If you reach us via an ad or a post, the link carries a short campaign tag (e.g. "meta-ki-check-09"). It is stored with your submission so we know which channel brought the enquiry. Nothing is stored on or read from your device, and no data flows back to advertising networks (Art. 6(1)(f) GDPR).
4. Price configurator
In the configurator we process the services and details you select together with your email address in order to produce and send your non-binding quote (Art. 6(1)(b) GDPR). The enquiry is stored in our database; the internal notification about it is sent by email via Resend (see section 8).
5. AI chatbot
An AI chatbot is available on our website. In accordance with Art. 50 of the EU AI Act it is clearly labelled as an AI — you are not communicating with a human being.
- Processing: your chat messages are transmitted to our processor Anthropic (Claude language model, USA) to generate responses; for searching our knowledge base, queries are additionally processed as mathematical text representations (embeddings) by OpenAI (USA).
- Storage: chat histories are stored in our database together with a randomly generated conversation ID in order to ensure service quality, detect abuse and — if you request contact — pass your enquiry to our team. Stored histories are deleted automatically after 12 months. The history is additionally kept in your browser's localStorage so that it survives a page reload. We only access it once you open the chat window — if you never use the chat, we do not touch your device. Locally stored histories are discarded after 30 days; you can also delete them yourself at any time.
- No model training, but not without storage: according to Anthropic and OpenAI, data from commercial API use is not used to train their models. That is not the same as “not stored”: both providers retain content for a limited period for abuse monitoring. The 12-month period above applies to our own database only.
- Handover of contact details: only if you actively provide your contact details in the chat and request to be contacted will an enquiry with a summary of your request be passed to our sales team (processing as in section 3).
- Please do not enter sensitive data (Art. 9 GDPR) in the chat.
Legal basis: Art. 6(1)(f) GDPR (providing an advisory service), or Art. 6(1)(b) GDPR where you request to be contacted.
6. Client and partner area
For the protected area (login) we process the email address, password (stored solely as a cryptographic hash, never in plain text) and roles assigned to our clients and sales partners (Art. 6(1)(b) GDPR). Sign-in uses technically necessary session cookies.
6a. Appointments and calls
If you arrange an appointment with us, we store the time, the type of appointment (call, on-site meeting, video call or follow-up), a short note on the occasion, and the link to your enquiry (Art. 6(1)(b) GDPR). This information is held solely in our own database (section 8); it is not transferred to any external calendar service.
For video calls we operate no service of our own. You receive the access link with the appointment confirmation, and it states which provider handles the call technically. We have no influence over that provider's processing — by joining, you decide whether to use it. A phone call or an in-person meeting is always available as an alternative.
7. Disclosure to sales partners
Enquiries may be passed to one of our independent sales partners for the purpose of preparing a quote. The partner receives the details you provided (name, contact details, requested services or your enquiry) and uses them solely to handle your request and prepare a quote for you. Legal basis: Art. 6(1)(b) GDPR. You can object to this disclosure at any time — write to the address above and we will handle your enquiry ourselves.
8. Processors and third-country transfers
- Vercel Inc. — hosting and audience measurement (section 2); provider USA, processing in the EU (Dublin, Ireland).
- Supabase — database and authentication; data located in the EU (AWS Ireland).
- Anthropic — AI language model for the chatbot (USA).
- OpenAI — text embeddings for knowledge search, speech recognition for the dictation function and speech synthesis for the read-aloud function in our internal sales tool (USA). Nothing is stored for speech synthesis: the text goes out, the audio comes back.
- Resend — delivery of internal notification emails (USA).
- Upstash — technical abuse protection (rate limiting; IP counters stored for a maximum of 60 seconds or 1 hour).
- Telegram — internal signalling channel for urgent enquiries; receives no personal data, only an internal reference ID.
Data processing agreements are in place with these providers where required. Transfers to third countries (e.g. the USA) are safeguarded under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.
9. Cookies and local storage
We use no tracking, analytics or marketing cookies. We use only: (a) technically necessary session cookies for signing in to the client and partner area, and (b) localStorage for the chatbot history (section 5). Both are required for the respective function (§ 165(3) Austrian Telecommunications Act 2021; Art. 6(1)(f) GDPR) — a cookie banner is therefore not required. We only access localStorage once you open the chat window: if you never open the chat, nothing is written to or read from your device.
The audience measurement described in section 2 likewise works without cookies and without storing anything on your device. Because no information is placed on or read from your terminal equipment, the consent requirement of § 165(3) Austrian Telecommunications Act 2021 does not apply.
10. Retention periods
Enquiries and lead data are stored for the duration of processing and thereafter for any applicable statutory retention period (in particular § 132 of the Austrian Federal Fiscal Code: 7 years for business records). Chat histories are deleted automatically after 12 months, rate limit counters after a maximum of 60 seconds or 1 hour. Account data is retained for the duration of the business relationship.
10a. Researched business contact data
For business development we additionally collect business contact data from publicly accessible sources — the Austrian commercial register, the Chamber of Commerce company directory and public company websites. As this data is not collected from you directly, the information duty under Art. 14 GDPR applies; the required details — in particular the data source and your right to object — are on a separate page (in German): Woher wir Ihre Kontaktdaten haben.
Holding such data does not mean we will contact you: in Austria, calls and emails for advertising purposes are permitted only with prior consent under § 174 of the Telecommunications Act 2021, also between businesses.
10b. Email information for customers
If you have commissioned a service from us, we use the email address provided in that context to inform you occasionally about our own similar services (§ 174(4) Telecommunications Act 2021; Art. 6(1)(f) GDPR). We point this out on the quote and the invoice. You can decline at any time free of charge — by an informal message to the address above or via the unsubscribe note in every such message (right to object under Art. 21(2) GDPR, no reasons required). We record the objection in a block list so that it takes lasting effect.
11. No automated decision-making
Incoming enquiries are prioritised automatically for internal purposes (lead scoring). This serves internal work organisation only and has no legal effect on you within the meaning of Art. 22 GDPR.
12. Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). To exercise these rights, please contact office@solarisagents.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (www.dsb.gv.at).
13. Social media presences
We run pages on LinkedIn and on Facebook and Instagram (Meta Platforms Ireland Ltd.). When you visit or interact with these pages, the respective provider processes your data under its own terms; for the page statistics ("Insights") we are joint controllers with the provider (Art. 26 GDPR; CJEU C-210/16). We only receive aggregated statistics without personal reference. Ads we place there lead to our website; no data flows back from our website to these providers (section 2). The easiest way to exercise your rights is directly with the provider; for our part, section 12 applies.
Last updated: 31 August 2026. This policy is updated whenever our processing changes.