Legal

Privacy policy

Information under Art. 13 and 14 GDPR. How the product handles data technically is explained in plain language on Privacy & GDPR — this page is the legally binding text.

English translation. This is a convenience translation. The legally binding version is the German original.

1. Controller

CertoClav Sterilizer GmbH
Peintner Straße 10, 4060 Leonding, Austria
Commercial register: FN 122912d, Landesgericht Linz
Phone: +43 732 674 278 22
Email: contact@chatflamingo.com

No data protection officer has been appointed. There is no obligation to do so under Art. 37 GDPR: our core activity consists neither of regular and systematic monitoring of data subjects on a large scale nor of large-scale processing of special categories of personal data. For all data protection questions you can reach us at contact@chatflamingo.com.

2. Principle

We process personal data only in so far as this is necessary to operate this website and to provide our service. This website uses no analytics cookies, no advertising cookies and no tracking pixels. That is why there is no consent banner here.

3. Visiting this website

3.1 Hosting and server logs

This website is delivered through the network of Cloudflare, Inc. When you visit it, the operator of the infrastructure processes technically necessary connection data, in particular IP address, date and time, the address requested, the volume of data transferred, the status message and the identifier transmitted by the browser.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and trouble-free operation of the website.

Cloudflare processes this data as our processor. The basis is the data processing agreement that Cloudflare provides as part of its terms of business and which includes the European Commission's standard contractual clauses.

We do not keep server logs of our own. The connection data arises in Cloudflare's network and is held there only briefly to fend off attacks and to troubleshoot. We do not evaluate it and do not combine it with other data.

3.2 Fonts

The fonts used are served from our own server. No connection is made to an external font provider, in particular not to Google Fonts.

3.3 No statistics, no audience measurement

We use neither Google Analytics nor any comparable audience measurement, and we embed no advertising networks.

4. Getting in touch

If you write to us or call us, we process your details in order to handle the enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry is directed at a contract, otherwise Art. 6(1)(f) GDPR.

We delete enquiries and the associated correspondence twelve months after our final reply. Where the enquiry leads to a contract, the periods in point 10 apply instead.

5. Account and use of the service

For a ChatFlamingo account we process the details you provide when creating it — in particular email address, display name and the address of your website — as well as data that arises during use, such as the number of sign-ins and of AI answers consumed. The legal basis is Art. 6(1)(b) GDPR.

A free account whose widget has not been loaded for 90 days is shut down after prior notice and the associated data is deleted.

Payment processing is not currently set up; no payments are accepted through this website. As soon as paid plans can be booked, we will add the payment service provider, the data processed in that context and the legal basis here. Even then we will not process payment data such as card numbers ourselves — only the commissioned payment service provider will.

6. Data of your website visitors

If you use ChatFlamingo on your own website, you are the controller for your visitors' data under data protection law. We process this data exclusively on your behalf and on your instructions. The details are governed by the data processing agreement, which forms part of the contract with us.

Processed on your behalf are, in particular:

  • the content of chat messages and the conversation history
  • details visitors provide voluntarily, such as name, email address or phone number
  • pages visited, time on site, browser and operating system
  • approximate location from the IP address — can be switched off in the dashboard
  • files and images uploaded by visitors

The conversations are held in a database assigned to your account. You set the retention periods for attachments and whole conversations yourself.

7. Artificial intelligence

Where questions are to be answered automatically, the content of the question, the conversation so far and the matching extract from your knowledge base are transmitted to our language model provider in order to generate the answer.

For this we use language models from Anthropic PBC, San Francisco, USA, and OpenAI Ireland Ltd., Dublin, Ireland. OpenAI also processes via OpenAI, L.L.C. in the USA. Which model answers is set by you in the dashboard.

Both providers are our processors and — in so far as data of your website visitors is affected — sub-processors within the meaning of the data processing agreement. Data processing agreements including the European Commission's standard contractual clauses are in place with both. The legal basis is Art. 6(1)(b) GDPR, and for visitor data your instruction under Art. 28 GDPR.

The transmitted content is not used to train the models. This is excluded in the contracts with both providers. The providers store the content only temporarily for abuse monitoring and delete it afterwards.

Asked directly, the bot points out that it is an AI. This satisfies the transparency obligation under Art. 50 of the AI Regulation (EU) 2024/1689.

8. Recipients and processors

We pass data on only to service providers we have bound as processors under Art. 28 GDPR. These are:

Cloudflare, Inc. delivery of this website, protection against attacks · San Francisco, USA · DPA with standard contractual clauses
Salesforce, Inc. (Heroku) operation of the application and the databases · San Francisco, USA, data centre in the EU · DPA with standard contractual clauses
Anthropic PBC language model for the AI's answers · San Francisco, USA · DPA with standard contractual clauses
OpenAI Ireland Ltd. language model for the AI's answers · Dublin, Ireland · DPA with standard contractual clauses for processing in the USA

We do not currently use external error monitoring or payment processing. If further service providers are added, we will name them here before they are used.

Beyond that we pass data on only where we are legally obliged to do so or where it is necessary to enforce our rights.

9. Transfers to third countries

Cloudflare, Salesforce, Anthropic and OpenAI also process data in the United States. The basis for the transfer is the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR. In so far as a recipient is certified under the EU-US Data Privacy Framework, the transfer is additionally based on the Commission's adequacy decision of 10 July 2023 under Art. 45 GDPR.

In addition, the following have been agreed: encryption in transit and at rest, limiting the transmitted data to what is necessary for the particular answer, and an obligation on the recipient to inform us about official requests for information, in so far as that is legally permitted.

10. Retention periods

Server logsno storage of our own, see point 3.1
Enquiries by email or phone12 months after the final reply
Account datafor the term of the contract, then 30 days, then deletion
Free account without use90 days after the widget was last loaded, after prior notice
Conversations of your website visitorsafter the period you set in the dashboard; in the free account 60 days at most
Invoices and vouchers7 years after the end of the calendar year (§ 212 UGB, § 132 BAO)

If a period expires while litigation is pending or threatened, we continue to retain the data concerned on a restricted basis until the matter is resolved.

11. Your rights

Under the GDPR you have the right to

  • access to the data concerning you (Art. 15)
  • rectification of inaccurate data (Art. 16)
  • erasure (Art. 17)
  • restriction of processing (Art. 18)
  • data portability (Art. 20)
  • object to processing based on legitimate interests (Art. 21)
  • withdraw consent given, with effect for the future (Art. 7(3))

To exercise them, write to contact@chatflamingo.com.

You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

12. Obligation to provide data

The details requested are necessary to conclude a contract and to create an account. Without them we cannot provide the service.

13. No automated individual decision-making

Automated decision-making with legal effect within the meaning of Art. 22 GDPR does not take place. The bot's answers are information, not decisions about people.

14. Changes

Version of this policy: 21 September 2026. We adapt it when the processing changes.