Privacy Policy
Data Protection Declaration according to GDPR (Datenschutz-Grundverordnung)
1. Overview
This Privacy Policy explains how we process personal data when you visit this website, contact us, or use our AI-powered funding assistant.
Personal data means any information relating to an identified or identifiable natural person.
We process personal data in accordance with the General Data Protection Regulation (GDPR) and the applicable German data protection laws.
2. Controller
The controller responsible for data processing on this website is:
WillowRiver Ingenieurbüro Frank Sahlbach
Owner: Frank Sahlbach
An der Aue 24
04758 Oschatz
Germany
Email:
Phone: +49 176 85152124
3. How We Collect Data
We collect personal data in the following ways:
- automatically when you visit this website, for example technical access data;
- when you contact us by email or phone;
- when you submit a question to our AI-powered funding assistant.
4. Website Access and Server Log Files
When you visit this website, technical information is processed automatically in order to provide the website securely and reliably. This may include in particular:
- IP address
- date and time of access
- browser type and browser version
- operating system
- referrer URL
- requested pages/files
- host name of the accessing device
This processing is necessary for the technical provision, stability and security of the website.
Legal basis:
Art. 6(1)(f) GDPR (legitimate interests in secure and technically stable website operation).
Storage period:
Server log data is stored only for as long as necessary for security, troubleshooting and technical administration, and is then deleted unless longer retention is required by law or necessary to investigate misuse.
5. Contact by Email or Telephone
If you contact us by email or telephone, we process the information you provide to handle your inquiry. This may include in particular:
- name
- contact details
- content of your message
- any project-related information you voluntarily provide
Legal basis:
- Art. 6(1)(b) GDPR, if your inquiry is related to the initiation or performance of a contract;
- Art. 6(1)(f) GDPR, for the efficient handling of general inquiries.
Storage period:
We store your inquiry data only for as long as necessary to process your request and any follow-up communication, unless statutory retention obligations require longer storage.
6. AI-Powered Funding Assistant
This website provides an AI-powered assistant that helps users with general questions about funding and grant programs.
When you use this function, we process the data you enter in the chat interface as well as the generated response. This may include:
- your question or prompt
- any personal data you include in the prompt
- technical metadata required to provide the service
- the AI-generated response
Purpose of processing:
The processing is carried out in order to provide the requested AI-supported answer and to operate, secure and improve the functionality of the service.
Important notice:
Please do not enter sensitive personal data or confidential third-party information into the chat unless this is strictly necessary. The AI assistant is intended for general informational support and does not replace an individual professional review.
Legal basis:
- Art. 6(1)(b) GDPR, where the use of the assistant is part of requested pre-contractual or service-related communication;
- Art. 6(1)(f) GDPR, based on our legitimate interest in providing an efficient digital information service for funding-related inquiries.
Recipients:
To provide the AI function, input data and generated output may be processed by OpenAI as our service provider under the contractual framework applicable to our business/API use.
International data transfers:
In connection with the use of the AI service, personal data may be transferred to recipients outside the European Economic Area. Where this occurs, we rely on the safeguards required by Chapter V GDPR, in particular the contractual safeguards applicable to the service used, such as Standard Contractual Clauses where necessary.
Storage period:
We store chat content only for as long as necessary to provide the service, handle follow-up questions, ensure technical security, and comply with legal obligations. Processing by OpenAI is subject to the contractual and technical settings applicable to the API/business service used.
No solely automated decision-making:
The AI assistant does not make legally binding decisions about you and is not intended to produce decisions based solely on automated processing within the meaning of Art. 22 GDPR.
7. Recipients and Processors
We use service providers where necessary for the technical operation of the website and the provision of the AI function. Such service providers process personal data on our behalf and in accordance with applicable data protection law.
Recipients may include in particular:
- technical hosting and IT service providers;
- communication service providers;
- AI service providers used to generate responses.
Where required by law, we conclude data processing agreements pursuant to Art. 28 GDPR.
8. Cookies and Similar Technologies
This website uses only technically necessary cookies or similar technologies to the extent required for the secure and functional operation of the website.
Legal basis:
Art. 6(1)(f) GDPR, insofar as technically necessary cookies are used to ensure website functionality and security.
If additional non-essential cookies, analytics or similar technologies are implemented in the future, this Privacy Policy will be updated accordingly and, where required, consent will be requested before such processing takes place.
9. Data Security
We use appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Please note, however, that data transmission over the Internet may involve security risks and complete protection against access by third parties cannot be guaranteed in every case.
10. Storage Duration
Unless a more specific storage period is stated in this Privacy Policy, we store personal data only for as long as necessary for the respective processing purpose.
Data will be deleted when the purpose no longer applies, unless:
- statutory retention obligations require longer storage;
- further storage is necessary for the establishment, exercise or defense of legal claims.
11. Your Rights
You have the following rights under the GDPR, subject to the applicable legal requirements:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR)
- right to withdraw consent at any time with effect for the future, where processing is based on consent (Art. 7(3) GDPR)
If you wish to exercise any of your rights, you can contact us using the contact details above.
12. Right to Lodge a Complaint
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
The competent supervisory authority for us is:
Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
Germany
Email: [email protected]
13. No Obligation to Provide Data
You are generally not legally or contractually obliged to provide personal data when using this website. However, certain functions may not be available or usable without the processing of technical data, contact data, or the content you actively submit.
14. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy so that it always complies with current legal requirements and reflects changes to our website or services. The version published on this website shall apply.