Privacy
This privacy policy will be reviewed before go-live. It covers general information and the AI assistant (Ask box).
General information
Controller
The controller pursuant to Art. 4(7) GDPR is better decisions group GmbH, Mittelstraße 3 B, 12529 Schönefeld, Germany, email: info@bdg.io. Legally represented by Lukas Schomberg, Ina Schwarzenberg and Sabrina Wolter. The data protection officer can be reached via heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, email: datenschutz@heydata.eu.
Legal bases for processing
The following provisions may serve as the legal basis for data processing:
- Art. 6(1)(1)(a) GDPR for processing for which consent is obtained.
- Art. 6(1)(1)(b) GDPR where processing is necessary to perform a contract.
- Art. 6(1)(1)(c) GDPR where processing fulfils a legal obligation.
- Art. 6(1)(1)(f) GDPR in the case of legitimate interests.
Processing outside the EEA
Where data is transferred to countries such as the United Kingdom, Canada or Israel, adequacy decisions of the EU Commission under Art. 45(3) GDPR safeguard the data. For the USA, the legal basis is an adequacy decision of the EU Commission where the provider is additionally certified under the EU-US Data Privacy Framework. Otherwise, Standard Contractual Clauses are the legal basis.
Retention period
Data is deleted as soon as it is no longer required for its purpose and no statutory retention obligations prevent deletion. For other permissible purposes, the data is restricted and not processed for other purposes.
Data subject rights
Data subjects have the following rights:
- Right of access
- Right to rectification or erasure
- Right to restriction of processing
- Right to object to processing
- Right to data portability
- Right to withdraw consent at any time
There is also the right to lodge a complaint with a data protection supervisory authority about the processing of personal data.
Obligation to provide data
Customers, prospects or third parties only need to provide the personal data required to establish, perform and end the business relationship, or that there is a legal obligation to collect. Without this data, the conclusion of a contract or the provision of services will generally be refused.
No automated decision-making
As a rule, no solely automated decision-making within the meaning of Art. 22 GDPR is used to establish and conduct a business relationship. In individual cases, separate information is provided where legally required.
Contact
If you contact us, the data you provide is stored in order to answer your enquiry. The legal basis is our legitimate interest (Art. 6(1)(1)(f) GDPR) in answering enquiries addressed to us. The data is deleted or its processing restricted once storage is no longer necessary or where statutory retention obligations apply.
Processing on this website
Web hosting
This website is hosted by an external provider (Hostinger). When you access the site, the host automatically collects server log files (including IP address, date and time of access, the file requested, the amount of data transferred, browser type and operating system). The legal basis is Art. 6(1)(1)(f) GDPR (legitimate interest in secure and stable provision). [PLACEHOLDER: host's legal name/address, DPA status and log-file retention to be confirmed by the DPO]
Cookies and consent
We use technically necessary cookies so the website works; these cannot be deselected (Art. 6(1)(1)(f) GDPR). Any analytics beyond that is used only with your consent via our consent banner (Art. 6(1)(1)(a) GDPR). You can withdraw your consent at any time with effect for the future. [PLACEHOLDER: specific cookie list, purposes and retention to be added by the DPO]
Usage analytics (bdgSignal)
To analyse usage we use bdgSignal, an analytics tool operated by bdg itself. bdgSignal is loaded only after your consent (Art. 6(1)(1)(a) GDPR). Usage data is processed to understand and improve the website. Processing takes place on bdg's own infrastructure (api.signal.bdg.io); data is not shared with third parties for advertising. [PLACEHOLDER: specific data categories, retention and any cookies set to be confirmed by the DPO]
AI assistant (Ask box)
On some pages we offer an AI assistant. You can type a question into an input field and send it actively. Your input is processed only once you send it. Nothing is transmitted without your active sending.
What is processed
We process only the text you enter and send yourself. We do not request personal data. Please do not enter personal or confidential data into the field.
Recipient and third-country transfer
To answer your question, we transmit your input to Anthropic PBC, San Francisco, USA, as a processor. Processing therefore takes place in a third country (USA). The transfer is safeguarded by Standard Contractual Clauses (SCC). [PLACEHOLDER: reference to the specific DPA/SCC status, to be confirmed by the DPO]
Legal basis
The legal basis is Art. 6(1)(b) GDPR (performance of the service you requested) and Art. 6(1)(f) GDPR (legitimate interest in providing the feature). [PLACEHOLDER: final assessment by the DPO]
Retention period
Your input is processed to answer your question and is not stored by us beyond answering it. [PLACEHOLDER: retention on the processor's side to be confirmed by the DPO]
Your rights
Your data subject rights under the GDPR apply. Details and contact information are in the general sections of this privacy policy.