Privacy policy
This policy covers this website. It does not describe the sandbox platform itself — that processing is governed by the written agreement made with each design partner.
Controller
The controller for the processing described here is Hanna Novikova, Amselweg 1, 69231 Rauenberg, Germany — info@ainclave.com. The full details are in the imprint.
For any request under this policy, including the rights listed below, write to that address or use the contact form.
Design partner application
If you apply through the design partner form, we process the email address you enter and the fact that you gave consent. Both are stored in our Postgres database. We use them for one purpose: to contact you about the design partner programme.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future; we then delete the entry. We keep the entry until you withdraw or until the programme ends.
The form contains a hidden field that is invisible to you and only ever filled in by automated submissions. When it is filled, the submission is discarded and nothing is stored.
Abuse prevention
When a valid application or contact form submission is processed, your IP address is hashed with SHA-256. Separate hashes are used for each form. Only those hashes are stored with a 15-minute window and an attempt count, and they are used solely to prevent abuse. The IP address itself is never written to our database. Expired limit records are removed by the next hourly cleanup after they become 24 hours old. The legal basis is our legitimate interest in keeping the forms usable (Art. 6(1)(f) GDPR).
Contact form
The name, email address and message you submit are sent to our contact mailbox so that we can answer you. The legal basis is our legitimate interest in responding to enquiries, or the steps prior to a contract at your request (Art. 6(1)(b) and (f) GDPR). We keep the correspondence for as long as it takes to deal with your enquiry.
Server logs
Our hosting provider processes the technical data that any web request carries — IP address, timestamp, requested URL, referrer and user agent — to deliver the page and to keep the service available and secure. This is standard operation of a web server and rests on our legitimate interest (Art. 6(1)(f) GDPR).
Website analytics
We use a self-hosted instance of Umami to understand which pages are used and to improve this website. The analytics data remain on our own infrastructure and are not sent to an external analytics cloud service. For each page view, we process the requested page including its campaign parameters, the referring page, timestamp, browser language, user agent and IP address. When the design partner form is submitted successfully, we also record that conversion and attribute it to the same pseudonymous session. The user agent provides general browser, operating system and device categories. Umami may derive an approximate location from the IP address.
For analytics, the IP address delivered by our trusted reverse proxy is processed only in memory while the page-view request is handled. Umami uses it to derive an approximate location and combines it with the user agent, website ID and a salt that changes monthly to calculate a pseudonymous session identifier. The raw IP address is never written to the analytics database; only the pseudonymous identifier and derived location data are stored. The monthly change prevents visits in different calendar months from being linked. We do not set analytics cookies, use browser storage, load a tracking script, or read information from your device.
The legal basis is our legitimate interest in measuring and improving the usefulness and reliability of this website (Art. 6(1)(f) GDPR). Analytics records are deleted after twelve months. You may object to this processing at any time by writing to the controller address above.
Cookies
All of the following are strictly necessary: they exist so that a feature you asked for works. They store a setting or a session, never a profile.
| Name | Purpose | Scope |
|---|---|---|
| theme | remembers whether you chose light or dark mode. | |
| lang | remembers your language selection. | |
| sidebar_state | remembers whether the navigation sidebar is expanded | in the signed-in area only. |
| Authentication session | set by our authentication provider after you sign in, so that you stay signed in. | Only present in the signed-in area. |
Strictly necessary cookies do not require consent, because they are needed to provide the service you requested. Since we set nothing beyond them, there is nothing to consent to.
You can delete or block cookies in your browser settings. Blocking these will not break the site, but it will forget your theme and language choices, and it will prevent you from staying signed in.
Recipients
We use service providers to host this website, run our database, and deliver email. They process data on our instructions only. The formal subprocessor list is in preparation and is not published yet; we will not pretend otherwise. Ask us and we will name the providers in scope for your case.
Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to have processing restricted, to data portability, and to object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of what happened before. You also have the right to lodge a complaint with a supervisory authority.
Changes
We update this policy when what the site does changes. The version you are reading is the one in force.
What we do not do
- No third-party analytics, tracking pixels, advertising networks, or client-side analytics scripts. The limited self-hosted analytics are described above.
- No cross-site identifiers. We do not embed third-party widgets that set cookies of their own.
- No profiling and no automated decision-making.
- No sale or sharing of your data for anyone else’s marketing.