Zum Inhalt springen

Legal

Privacy

This notice informs you under Article 13 GDPR which personal data is processed when you visit this website and contact us. It applies to devonaut.ai and all subpages. This translation is provided for convenience; the German version is legally binding.

As of September 2026

1. Controller

The controller within the meaning of Article 4(7) GDPR is:

Devonaut Sole proprietorship Owner: Sascha Denis Blömer Grünewalder Straße 29–31, Haus 4 42657 Solingen Germany Email: hallo@devonaut.ai Phone: +49 177 6458886

No data protection officer has been appointed, as the requirements for mandatory appointment under § 38 BDSG and Article 37 GDPR are not met. Please direct all privacy questions to the address above.

2. Overview

This website provides information about our services and projects. It has no newsletter, no user accounts, no embedded videos, no maps and no social media buttons. It sets no analytics or advertising cookies and loads no fonts or scripts from Google, Meta or other advertising networks.

Personal data arises in three situations: when the page is technically retrieved (sections 3 and 4), when you write to us through the enquiry chat (section 6) and when you contact us by email or phone (section 7).

3. Hosting

This website runs on the Onepage platform, provided by Onepage GmbH, Hanauer Landstraße 172, 60314 Frankfurt am Main, Germany. The website is generated and delivered entirely by Onepage, so all access is technically processed by Onepage.

Onepage uses data centres of Amazon Web Services and Google Cloud which, according to the provider, are located exclusively in the European Union. The fonts on this website are served by Onepage itself; there is no connection to Google Fonts or other font services.

A data processing agreement under Article 28 GDPR is in place with Onepage. The legal basis is our legitimate interest in providing the website securely and reliably (Article 6(1)(f) GDPR).

4. Access data and logs

When you open a page, your browser technically transmits your IP address, date and time of access, the address requested, status code, amount of data transferred, and browser type and operating system. This data is required to deliver the page to your device.

For error analysis and system security, Onepage stores the IP address, request type and status code of a small share of requests for one month. It is not combined with other data or analysed in relation to you. Onepage also provides us with reach statistics that count page views without storing IP addresses or other personal data.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and uninterrupted operation of the website.

5. Cookies and storage on your device

This website sets no cookies that require consent. No analytics, marketing or tracking cookies are used, which is why we do not show a consent banner.

When you switch language using the toggle in the header, we store your choice in your browser’s local storage so you land on the site in your language next time. For the duration of the page change we also keep the scroll position in session storage so you can continue reading at the same spot. This storage is strictly necessary for the function you explicitly requested and requires no consent under § 25(2) No. 2 TDDDG. It contains no personal data and is not transmitted to us. You can delete it at any time in your browser settings.

Onepage may set technically necessary cookies required to deliver the page and protect it against attacks (§ 25(2) No. 2 TDDDG).

6. Enquiries through the enquiry chat

When you write to us through the enquiry chat, we process the details you provide: topic, description of your request, name, email address and optionally your company. We use this data only to answer your enquiry and, where relevant, to prepare an offer. The chat is a guided flow with fixed questions; no artificial intelligence is used.

Your details are only transmitted when you tap send in the last step. They are stored in Onepage’s customer management system, which we use as part of the hosting under the data processing agreement.

The legal basis is Article 6(1)(b) GDPR insofar as your enquiry concerns a contract, otherwise Article 6(1)(f) GDPR. Our legitimate interest lies in answering your enquiry. Retention is governed by section 11.

7. Contact by email or phone

When you contact us by email or phone, we process your contact details and the content of your enquiry to answer it and, where relevant, to prepare a contract. The legal basis is Article 6(1)(b) GDPR insofar as your enquiry concerns a contract, otherwise Article 6(1)(f) GDPR.

For sending and receiving email we use an email service provider as a processor with servers in the European Union.

8. Contact via WhatsApp

This contact option is not yet enabled. In the enquiry chat it is shown as “coming soon” and cannot be selected. Before we enable it, we will complete this section with all details on the provider, technical service provider, third-country transfers and any AI-assisted replies.

9. Recipients

We only pass on personal data where necessary to provide this website and answer your enquiry. Recipients are:

– Onepage GmbH, Frankfurt am Main, as processor for hosting and customer management, with sub-processors Amazon Web Services and Google Cloud (data centres in the EU) – our email provider as processor with servers in the EU

Agreements under Article 28 GDPR are in place with all processors. Data is only passed to other third parties if we are legally obliged to do so.

10. Transfers to third countries

Processing takes place within the European Union. Onepage’s sub-processors Amazon Web Services and Google Cloud are subsidiaries of US groups. According to the provider, data is processed exclusively in EU data centres. In case of access from the USA, both parent companies are certified under the EU-US Data Privacy Framework, for which an adequacy decision of the European Commission under Article 45 GDPR exists.

11. Retention

We only keep personal data as long as needed for the respective purpose or required by statutory retention periods:

– access logs at Onepage: at most one month – enquiries without a contract: until resolved, at most twelve months – contract-related correspondence: six to ten years under § 257 HGB and § 147 AO – language choice in your browser: until you delete it; scroll position: until the end of the session

The data is deleted afterwards.

12. Systems we operate for clients

We develop and operate software for other companies. If you come into contact with a system we operate as a customer, applicant or employee of such a company, that company is the controller for your data. We then act as a processor under Article 28 GDPR based on a contract with the company.

In that case you receive the information under Articles 13 and 14 GDPR from the company itself. You exercise your rights towards it, and we support it in doing so. Requests that reach us directly are forwarded to the controller.

13. Your rights

You have the following rights regarding personal data concerning you:

– access (Article 15 GDPR) – rectification (Article 16 GDPR) – erasure (Article 17 GDPR) – restriction of processing (Article 18 GDPR) – data portability (Article 20 GDPR) – withdrawal of consent with effect for the future (Article 7(3) GDPR)

An informal message to hallo@devonaut.ai is enough. We reply within one month.

14. Right to object

Where we process your data on the basis of a legitimate interest under Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation (Article 21(1) GDPR). We will then stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

We do not carry out direct marketing through this website. Should we nevertheless send you promotional messages, you may object at any time without giving reasons (Article 21(2) GDPR).

15. Right to lodge a complaint

Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or place of the alleged infringement (Article 77 GDPR). The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2–4 40213 Düsseldorf, Germany www.ldi.nrw.de

16. No automated decision-making

We make no decisions based solely on automated processing and carry out no profiling within the meaning of Article 22 GDPR.

You are under no statutory or contractual obligation to provide personal data. Without your contact details, however, we cannot answer an enquiry.

17. Encryption

This website is delivered exclusively over an encrypted connection (TLS), shown by the padlock in your browser’s address bar.

18. Changes

We update this notice when the law, the technology of this website or our services change. The version published here applies; the date is shown at the top.