1. Controller
The controller under the General Data Protection Regulation (GDPR) is: Nexaluna AI Solutions UG (haftungsbeschränkt) Renkenweg 23 83209 Prien am Chiemsee Germany Email: info@nexaluna.ai Phone: +49 151 28858234
2. Scope
This policy applies to the corporate website at nexaluna.ai, including its English-language pages, and to the communication channels we operate: telephone, including our AI voice assistant, web chat and WhatsApp Business.
It documents our approach to the transparency obligations under Article 50 of Regulation (EU) 2024/1689 (the EU AI Act), which have applied since 2 August 2026. The required disclosure is additionally given immediately before the first interaction with our AI systems; required machine-readable markings are provided on the relevant content. Wherever we use AI systems we say so at the relevant point; section 14 summarises what this means for conversations and for published content.
Linked products and platforms—particularly PostMaestro.ai—are governed by their own privacy notices.
3. Hosting and delivery
The website is delivered using Amazon Web Services EMEA SARL (AWS). Static content is stored in Amazon S3 and delivered over encrypted connections through Amazon CloudFront. Primary resources run in the Europe (Frankfurt) region. CloudFront uses a global network of edge locations.
When you access the site, technically necessary connection data may be processed, including IP address, date and time, requested resource, referrer and browser or device information. Processing is based on our legitimate interest in secure and efficient delivery under Article 6(1)(f) GDPR.
We have concluded data processing terms with AWS. Where processing outside the EEA cannot be excluded, appropriate safeguards, including EU Standard Contractual Clauses, are used.
4. Technical logs
Logs for the contact interface and error diagnosis are limited to what is necessary. Message content is not written to application logs. Logs are generally deleted after a short period unless security-related retention is required.
5. Contact requests
If you contact us by email or form, we process your contact details, company information and message to respond to your request.
The form is processed through Amazon API Gateway and AWS Lambda and delivered to our inbox through Amazon Simple Email Service (SES). We do not operate a separate database for form messages.
Processing is based on Article 6(1)(b) GDPR where it relates to pre-contractual steps and otherwise on Article 6(1)(f) GDPR. Data is deleted when no longer required, subject to statutory retention duties.
6. Telephony, web chat and WhatsApp (Twilio)
We use the Twilio communications platform (Twilio Ireland Limited, 3 Dublin Landings, North Wall Quay, Dublin 1, Ireland) for inbound and outbound calls, for the web chat on our website and for WhatsApp Business communication. Our business phone number is also provided through Twilio.
The web chat on our website is run by an AI system, not by a human. In accordance with Article 50(1) of the EU AI Act we tell you this before you write your first message: the notice sits visibly in the header of the chat window and stays there for the entire conversation. You may ask for a human to take over at any time, and we will then respond by email or call you back.
Depending on the channel, we process your phone number or WhatsApp identifier, the date, time and duration of the connection, connection and delivery status, the content of chat and WhatsApp messages and—for calls handled by our AI voice assistant—the audio of the conversation and the transcripts generated from it.
When a member of our staff takes over in the web chat, the subsequent conversation history, including visitor and staff messages, timestamps and delivery status, is stored in our internal CRM system on a server operated by us. Staff access it through the internal console; it is not permanently stored on the local computer of the individual staff member.
Twilio processes this data as our processor. We configure Twilio so that processing and storage take place in the EU region (Ireland data residency). The basis is the Twilio Data Protection Addendum, including the EU Standard Contractual Clauses, available at https://www.twilio.com/en-us/legal/data-protection-addendum. Processing in third countries, for example for support or operational purposes, cannot be entirely excluded and is then based on appropriate safeguards under Chapter V GDPR.
When you use WhatsApp, the underlying infrastructure is operated by WhatsApp Ireland Limited and Meta Platforms Ireland Limited. Metadata such as your phone number, timestamps and device data is processed there under the provider’s own responsibility, and transfers to the United States are possible. If you wish to avoid this, please use email, telephone or our contact form.
Processing is based on Article 6(1)(b) GDPR where the communication relates to pre-contractual steps or contract performance, and otherwise on our legitimate interest in efficient customer communication and availability under Article 6(1)(f) GDPR. Call recordings and analysis that goes beyond the immediate handling of the conversation are based solely on your express consent under Article 6(1)(a) GDPR. Recording starts technically only after your express consent; no prior buffer is saved retrospectively. You may withdraw consent at any time with future effect, end the call at any time or contact us by email instead.
Where we call consumers for advertising purposes, we do so only with their prior express consent under Section 7(2)(2) German Unfair Competition Act (UWG). We document and retain evidence of that consent in accordance with Section 7a UWG.
7. AI voice assistant (ElevenLabs)
Our voice assistant uses services provided by ElevenLabs Inc., 169 Madison Ave #2484, New York, NY 10016, USA, for speech recognition, dialogue handling and speech synthesis.
Transparency under Article 50(1) of the EU AI Act: at the beginning of every conversation the assistant identifies itself as an artificial intelligence—in the greeting when you call, and additionally as a visible notice in the header of the window in the browser. This disclosure is provided before any substantive conversation begins. If you ask, the assistant confirms unambiguously that it is not a human. It never presents itself as a human being.
This involves processing the audio of your contributions to the conversation, the resulting transcripts and the context needed to answer your request (for example your concern, a requested appointment or contact details you provide). ElevenLabs processes this data solely on our instructions.
We have concluded a data processing agreement with ElevenLabs, including the EU Standard Contractual Clauses as an appropriate safeguard for transfers to the United States (Article 46(2)(c) GDPR). Contractually, your conversation data is not used to train the provider’s general AI models.
No conversation data is stored at ElevenLabs. We operate the assistant with zero retention at the provider: audio and transcripts are processed there only transiently, for as long as the immediate answer within the running conversation requires, and are not retained afterwards. No conversation archive or recording is created at ElevenLabs that we or anyone else could access later.
Transcripts and audio recordings are only stored permanently if you expressly agree before recording begins. Recording starts technically only after that consent; no prior conversation buffer is saved retrospectively. In that case the transcript and the recording are held solely on our own server in Germany (AWS Europe, Frankfurt region) in the CRM system we developed ourselves—not at ElevenLabs and not with any other third party. Without your agreement we keep neither audio nor transcripts.
Processing is based on Article 6(1)(b) or (f) GDPR and, for storing transcripts and voice recordings, on Article 6(1)(a) GDPR. You may withdraw your agreement at any time with future effect, and we will delete the recording. You can also ask to speak to a human at any time, in which case we handle your request without AI assistance.
8. CRM system and customer data
We manage enquiries, conversation outcomes and customer relationships in a CRM system we developed ourselves. We do not use third-party CRM software.
We store in particular your name, company, contact details, the channel and time of contact, the content or a summary of your enquiry, and the processing and proposal status.
If a human takes over in the web chat, we store the subsequent live-chat history in our internal CRM system on our own server. This includes, in particular, visitor and staff messages, timestamps, delivery status and the processing status of the session. The internal console displays this data; it is not permanently stored on the local computer of the individual staff member.
Transcripts and audio recordings from calls and chats with our AI assistant only reach the CRM if you agreed to them being stored before recording begins. They are then held solely on our own server in Germany; no conversation data remains with the provider of the voice assistant (ElevenLabs).
The CRM runs on Amazon Web Services EMEA SARL (AWS) infrastructure in the Europe (Frankfurt) region. Data is encrypted in transit and at rest; access is limited to authorised staff and is logged. We have concluded a data processing agreement with AWS, and the EU Standard Contractual Clauses apply to any third-country elements that cannot be excluded.
Processing is based on Article 6(1)(b) GDPR for initiating and performing contracts and on Article 6(1)(f) GDPR for our legitimate interest in orderly customer and enquiry management. We delete data once the purpose ceases to apply, at the latest after statutory commercial and tax retention periods of up to ten years. Data from enquiries that do not lead to a contract is generally deleted within 24 months.
9. Newsletter
We use a double opt-in procedure for our newsletter: after you sign up, we send an email to the address you provided and ask you to confirm it. Only once you click the confirmation link do we add the address to the distribution list. If confirmation is missing, we delete the sign-up after seven days.
We process your email address, the language you selected, the time of sign-up and confirmation, the place on the website where you signed up and a non-reversible hash of your IP address. This information is used solely to send the newsletter and to evidence your consent; we do not store the IP address itself.
Processing is based on your consent under Article 6(1)(a) GDPR and, for logging the sign-up, additionally on our legitimate interest in being able to evidence it under Article 6(1)(f) GDPR. Delivery uses Amazon Simple Email Service (SES) provided by Amazon Web Services EMEA SARL; the distribution data is held in our own system in the Europe (Frankfurt) region.
We do not measure success using tracking pixels, open rates or click tracking.
You can withdraw your consent at any time with future effect: via the unsubscribe link at the end of every newsletter email, via the form below, or informally to info@nexaluna.ai. After you unsubscribe we remove the address from the distribution list; evidence of the sign-up and the unsubscription is kept for up to 90 days and then deleted.
10. Cookies, consent and analytics
On your first visit, a bar at the bottom of the page asks which services may run. Until you decide, we only store entries that are indispensable for operating the website: your privacy choice itself, the link between a running chat and its session, and the detection of technical faults. This is based on Section 25(2)(2) TDDDG in conjunction with Article 6(1)(f) GDPR.
All other services are grouped into the purposes "Functional", "Analytics" and "Marketing" and stay disabled until you consent. The legal basis is then your consent under Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. Declining puts you at no disadvantage; all content remains fully accessible.
For analytics we use Google Analytics 4 once you have consented, and Google Ads to measure how our advertising performs. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This involves processing the pages you visit, time on page and interactions, the source of your visit, an approximate location at city level and device and browser details. Your IP address is truncated before it enters the analysis, and we do not combine it with other data sets or with your Google account. Google retains the event data for a maximum of 14 months.
We use Google Consent Mode v2. Before you consent, no Google script is loaded and no connection to Google servers is established. Once consent is given, a transfer to Google LLC in the United States cannot be excluded. Google LLC is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023), and the EU Standard Contractual Clauses apply in addition. Please note that US authorities may be able to access this data and that you may not have legal remedies comparable to those in the EU.
We keep your choice for twelve months, together with the time and a reference number, in your browser’s local storage so that we can honour and evidence it. Withdrawal takes effect for the future, and we delete the cookies belonging to the purposes you switched off.
Our cookie policy lists every service with its provider, cookie names, retention periods and purposes. You can also change or withdraw your choice directly there.
11. External links and social media
The website links to external services and our social profiles. Data is only sent to the relevant provider when you actively open a link. The external provider is responsible for subsequent processing.
12. Your rights
Where the statutory conditions are met, you have rights including:
- access to your personal data
- rectification of inaccurate data
- erasure or restriction of processing
- data portability
- objection to processing based on legitimate interests
- withdrawal of consent with future effect
13. Right to complain
You may complain to a data protection authority. Our competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, poststelle@lda.bayern.de, www.lda.bayern.de.
14. AI transparency and AI-generated content
This section documents how we implement the transparency obligations set out in Article 50 of the EU AI Act. The statements on this page supplement, but do not replace, the disclosure immediately before the first interaction and marking on the relevant content; these technical measures have applied since 2 August 2026.
Conversations with an AI system (Article 50(1)): our web chat and our voice assistant are AI systems. They identify themselves as such before any substantive exchange and confirm it when asked. You may ask for a human to take over at any time, without any disadvantage to your request.
Roles in relation to AI systems: for the voice assistant operated under our name, Nexaluna is the provider within the meaning of Article 3(3) and Article 25 of the EU AI Act. ElevenLabs provides the underlying speech and model services. Where we operate a voice assistant for a customer through that customer’s phone number or communication channel, that customer is generally the controller for the processing of personal data and the deployer of that use; the customer’s own privacy notice applies to the particular conversation. Roles and instructions are set out contractually.
Emotion recognition and biometric categorisation (Article 50(3)): we do not use such systems. We do not analyse voice or images to infer emotional state, personality or group membership.
Synthetic content (Article 50(2)): the images and illustrations on this website are largely created with generative AI. They are produced under human responsibility and are reviewed and approved before publication. Under Article 50(2) of the EU AI Act, marking such output in a machine-readable format is the duty of the providers of the generators we use. The transition period ending on 2 December 2026 applies exclusively to generative AI systems placed on the market before 2 August 2026; systems placed on the market later are subject to the marking obligation without that transition period. We prefer tools that include machine-readable markings—for example, using the C2PA standard or IPTC metadata. Where content is cropped, re-encoded, rendered into our own templates or otherwise post-processed, we publish it only where the marking demonstrably remains in the processing chain or has been applied again using an appropriate, technically reliable measure. A merely visible label is not a substitute for a machine-readable marking.
Deepfakes (Article 50(4)): we do not publish content that convincingly imitates real people, places or events. The motifs we create with AI support are recognisably illustrative and do not depict real, identifiable people. Should we ever publish content that qualifies as a deepfake, we will disclose directly at that content that it has been artificially generated or manipulated.
Text on matters of public interest (Article 50(4), second subparagraph): this obligation only concerns text published to inform the public on matters of public interest. Our newsroom articles are produced under editorial responsibility: where AI supports drafting, a natural person reviews and takes responsibility for the text before publication. Pure product marketing does not fall within this specific transparency obligation.
Automated decisions: a human always decides on your request. There is no decision based solely on automated processing that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR.
If you have questions about our use of AI, write to info@nexaluna.ai.
European Commission: Quick facts on transparency rules for AI systems
15. Updates
We update this policy when technical functions or legal requirements change. The published version is authoritative.
