Privacy Policy
Note: This is an English translation of the original German privacy policy. The German version is legally binding.
1. At a Glance
This is the company website of Haven AI Solutions UG (haftungsbeschränkt). It provides information about our consulting services and offers a contact form. It does nothing else.
We process personal data in two contexts only:
- Server log files generated for technical reasons when the website is accessed.
- The details you enter in the contact form, if you write to us.
This website sets no cookies. It embeds no analytics services, no advertising networks, no social networks, no external fonts and no third-party content. There is no user area, no login and no user account. We do not process any data using AI systems, and we do not use any data from this website to train AI models.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Haven AI Solutions UG (haftungsbeschränkt)
Reekamp 34
22415 Hamburg
Germany
Email: privacy@haven-ai.eu
Further company details can be found in the Legal Notice.
Data Protection Officer
We have not appointed a data protection officer, and we are not required to. Under § 38(1) BDSG (German Federal Data Protection Act), an appointment is only required where at least 20 people are constantly engaged in the automated processing of personal data. We are below that threshold, and none of the headcount-independent cases in § 38(1) sentence 2 BDSG applies. For any data protection matter you can reach us at privacy@haven-ai.eu.
3. Scope
This privacy policy applies to the website available under the domain haven-ai.eu, including its subdomains.
Where we process personal data on a client's behalf in the course of a consulting engagement, that processing is governed by the contract concluded with the client under Art. 28 GDPR. You can find more on this under Data Processing.
Applications and services that we provide as separate offerings each have their own privacy notice. These are provided within the respective service.
4. Processing Activities in Detail
4.1 Visiting the Website (Server Log Files)
When you access this website, our systems process technically necessary access data. There are two separate logs:
a) Web server access log
- shortened IP address of the requesting device
- date and time of the request
- requested address and HTTP status code
- volume of data transferred
- previously visited page (referrer), where transmitted
- browser type and operating system (user agent)
The IP address is shortened before it is written to the log file: for IPv4 the final octet is set to zero, and for IPv6 the address is truncated to its first three blocks. A complete IP address is never stored.
b) Application log
In addition, the application itself logs each request with its time, path, status code and processing duration. Instead of the IP address, it stores a hash value formed using a secret additional value. This value is pseudonymised, not anonymised — it remains personal data within the meaning of Art. 4(5) GDPR, and we treat it accordingly. Its sole purpose is to recognise repeated requests from the same sender (abuse protection for the contact form).
Purpose and legitimate interest: We process this data to ensure the technical operation of the website, to detect and isolate faults and errors, to defend against attacks and automated bulk submissions through the contact form, and to maintain the stability of the website. That is precisely where our legitimate interest lies.
Legal basis: Art. 6(1)(f) GDPR.
Storage period: Log files are deleted after seven days at the latest. Where a specific security-relevant incident means individual entries are needed for investigation, we retain only those entries until the investigation is concluded, and delete them afterwards.
Recipients: The servers are operated by our hosting provider (see section 6).
4.2 Contact Form and Email Contact
You can send us a message using the contact form.
Mandatory fields: first name, last name, email address and your message. Optional fields: company, and the selection of what you are interested in.
Also transmitted are the time of submission, your device's browser identifier (user agent) and the pseudonymous sender identifier described in 4.1 b). These serve to attribute the message and to protect against abuse.
Are you obliged to provide this data? No. Providing it is neither legally nor contractually required. Without the mandatory fields, however, we cannot process your enquiry or reply to you, and the form cannot be submitted.
What happens to your message: Your details are delivered by email to our mailbox and handled there. There is no database and no other storage within the website itself — the application does not write your details anywhere, it sends them on directly.
Legal basis:
- Where your enquiry concerns a possible consulting engagement, the legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract).
- For all other enquiries the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is being able to answer enquiries addressed to us and to communicate with interested parties.
We do not obtain consent for this, and we do not need to.
Storage period: We delete your enquiry once it has been conclusively dealt with and no follow-up is expected. Our mailbox is reviewed regularly for this purpose, at least once a year. If your enquiry leads to a contractual relationship, the associated correspondence is subject, as commercial correspondence, to the retention periods under commercial and tax law (six years under § 257(4) HGB, § 147(3) AO, running from the end of the calendar year). For as long as such a retention obligation applies, erasure is excluded under Art. 17(3)(b) GDPR; we restrict processing under Art. 18 GDPR instead.
Spam protection: The form includes a simple arithmetic question and a field invisible to you that detects automated submissions. Both run entirely on our own server; no third-party service (such as an external captcha provider) is embedded, and no data is transmitted to third parties in the process.
4.3 Language and Colour Scheme Preference (Your Browser's Local Storage)
When you switch the website's language or colour scheme, we store your choice in your browser's local storage so that it is retained on your next visit.
- Only two non-identifying values are stored: the chosen language (
enorde) and the chosen colour scheme (lightordark). - No identifier and no ID is assigned.
- The values remain on your device and are never transmitted to us at any point. We do not process them.
- They are stored only when you operate the relevant switch yourself. Simply visiting the website writes nothing.
Why we do not obtain consent for this: Under § 25(2) no. 2 TDDDG, consent is not required where storage is strictly necessary in order for us to provide a service you have expressly requested. By operating the language or colour switch, you request precisely that function; without storing the value we could not provide it. Since only a non-identifying value is stored, the storage is also limited to what is necessary.
You can delete these values at any time via your browser settings.
5. Cookies, Tracking and Third-Party Content
Cookies
This website sets no cookies — neither our own nor third-party cookies. No cookie banner is therefore required.
No Tracking, No Third-Party Content
Beyond that, we expressly confirm:
- There is no reach measurement and no web analytics. Neither Google Analytics nor Matomo nor any comparable service is embedded.
- There are no tag managers, no advertising or tracking pixels and no profiling.
- There are no social network buttons or plugins.
- No content is loaded from third-party servers — in particular no external fonts and no content delivery network. The fonts used are held on our own server. We chose this deliberately so that your IP address is not disclosed to third parties when you visit this website.
- There is no newsletter and no sending of promotional email.
6. Processors
We engage the following service providers. Both process personal data solely on our instructions, and a data processing agreement under Art. 28 GDPR is in place with each.
Website hosting
Scaleway SAS, 8 rue de la Ville l'Évêque, 75008 Paris, France
Scaleway operates the servers on which this website runs and processes the access data described in 4.1 in doing so. Processing takes place exclusively in data centres within the European Union.
Email
Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland
Contact form messages are delivered through Proton and managed in our mailbox there. The details described in 4.2 are processed in the course of this.
We engage no further service providers with access to personal data for this website.
7. Transfers to Third Countries
The email service is provided by Proton AG, which is established in Switzerland. Switzerland is a third country within the meaning of Chapter V GDPR. An adequacy decision of the European Commission under Art. 45 GDPR is in place for Switzerland; the level of data protection there is therefore recognised as adequate, so no additional safeguards under Art. 46 GDPR are required. Proton undertakes contractually to transfer data only within Switzerland, the EU, or to countries covered by an adequacy decision.
Beyond that, personal data is not transferred to any country outside the European Union or the European Economic Area, nor to any international organisation. In particular, no transfer to the USA takes place.
8. No Automated Decision-Making
Automated decision-making, including profiling, within the meaning of Art. 22(1) and (4) GDPR does not take place. Your enquiries are read and answered by people.
9. Your Rights
You have the following rights against us in respect of personal data relating to you:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR — see section 10 separately)
An informal message to privacy@haven-ai.eu is sufficient to exercise them. Exercising these rights is free of charge for you.
Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Strasse 22, 7th floor
20459 Hamburg, Germany
Telephone: +49 40 428 54-4040
Email: mailbox@datenschutz.hamburg.de
You may also contact the supervisory authority of your place of residence, your place of work or the place of the alleged infringement.
10. Right to Object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR.
This concerns the processing described in this policy under 4.1 (server log files) and, in so far as it is based on Art. 6(1)(f) GDPR, under 4.2 (contact form).
If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Send your objection informally to: privacy@haven-ai.eu
11. Data Security
This website is accessible only over an encrypted connection (TLS); requests over unencrypted HTTP are redirected to the encrypted connection. Your contact form entries are therefore encrypted in transit to us. In addition, we take appropriate technical and organisational measures under Art. 32 GDPR to protect your data against loss, alteration and unauthorised access.
12. Changes to This Privacy Policy
If our website, our services or the legal requirements change, we will amend this privacy policy. The version available on this page applies in each case.
Status: August 2026