Last updated: September 24, 2026
Controller pursuant to Art. 4(7) GDPR
Context Studios UG (haftungsbeschränkt)
Represented by the managing director: Michael Kerkhoff
Kaiser-Friedrich-Str. 6
10585 Berlin, Germany
Phone: +49 30 96610664
Email: info [at] contextstudios [dot] ai
Commercial register: Amtsgericht Charlottenburg (Charlottenburg Local Court), HRB 280670 B
We have not appointed a data protection officer, as we are currently not legally required to do so. For data protection enquiries, please contact us at info [at] contextstudios [dot] ai or use our data protection request form.
1. Introduction and Scope
This privacy policy informs you, in accordance with Art. 13 and 14 GDPR, about the processing of personal data on our website contextstudios.ai and in our web applications.
We take the protection of your personal data seriously and process it only in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
2. What Data We Collect
2.1 Personal Data (Information You Provide Voluntarily)
We collect personal data that you provide to us voluntarily when you:
- Fill in a contact form
- Request our information pack (we send it to the email address you provide and store the request as a contact enquiry)
- Subscribe to our newsletter (with double opt-in confirmation)
- Book a discovery call via Cal.com
- Create an account with Clerk authentication
- Sign an offer or a non-disclosure agreement (NDA) electronically (section 2.9)
- Submit a data protection request (section 2.10)
- Communicate with us by email
- Use the AI chatbot (section 8)
This information may include:
- Name and email address
- Company name and position
- Phone number (if provided)
- Project requirements and preferences
Purpose and legal basis: Handling your enquiry and taking steps prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). Retention period: 2 years after the last contact, then deleted automatically, unless a business relationship exists (in which case the periods for contract data apply).
2.2 Server Log Files
When you visit our website, our hosting provider Vercel automatically records the following data in server log files:
- IP address
- Browser type and version
- Operating system
- Referrer URL
- Time of the server request
- Requested resource
Purpose, legal basis and retention period
The logs serve IT security, abuse prevention and error analysis. They are deleted automatically in accordance with Vercel’s specifications, to the best of our knowledge after 30 days at the latest. Security-relevant entries may be kept longer for the duration of an ongoing investigation.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and system stability).
2.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies in accordance with § 25 TDDDG. Cookies that are not strictly necessary are only set after you have given your express consent. You can find further details in our Cookie Policy.
2.4 Logging of Cookie Consents
To meet our obligation to demonstrate consent under Art. 7(1) GDPR, we log your cookie consents:
- Data collected: random consent ID, timestamp, selected categories, consent version, type of action (grant, change, withdrawal), language version and whether Global Privacy Control or Do Not Track was active
- Purpose: demonstrating consent to supervisory authorities
- Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 5(2) and Art. 7(1) GDPR
- Retention period: 3 years from logging, then deleted automatically
2.5 Content Delivery Network and Security Service (Cloudflare)
Our entire website is delivered via the content delivery network (CDN) and reverse proxy of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”). Every request to our website is first received by Cloudflare servers, which cache content, forward the request to our hosting provider and protect the website against attacks (e.g. DDoS attacks) and abusive access.
In doing so, Cloudflare processes in particular the following data:
- IP address
- Date and time of access and the requested resource (URL)
- Request data from the HTTP header (e.g. browser type and version, operating system, referrer URL, language setting)
- Log and event data for delivery and for detecting and defending against attacks
- the country or region derived from the IP address (HTTP header
cf-ipcountry); we use this information only to send you to the matching language version on your first visit
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, performant and reliable delivery of our website and in defending against attacks and abuse.
Processing on our behalf: Cloudflare acts as our processor on the basis of the Cloudflare Data Processing Addendum (DPA) pursuant to Art. 28 GDPR (Cloudflare Customer DPA).
Retention period: in accordance with Cloudflare’s specifications; Cloudflare deletes or anonymises log data automatically.
Third-country transfer: The transfer to the USA is based on Cloudflare’s certification under the EU-U.S. Data Privacy Framework or on the Standard Contractual Clauses agreed in the DPA.
Cookies: Cloudflare currently does not set any cookies on our website.
More information: www.cloudflare.com/privacypolicy
2.6 Google Maps on the Contact Page
On our contact page you can display an interactive map from the Google Maps service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The map is not loaded automatically: at first you only see a placeholder. Only when you click “Load map” does your browser connect to Google servers and load the map. Your choice is not stored; when you visit the page again, the placeholder is shown again.
After the click, in particular your IP address, the date and time of the request, the referring page and browser and device information are transmitted to Google; Google may use cookies or similar technologies. Data may also be transferred to Google LLC in the USA. We have no influence on the scope and further use of this data by Google.
Legal basis: your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG, which you give by clicking “Load map”.
Withdrawal: Consent applies only to the respective page view. You can withdraw it at any time with effect for the future by not loading the map again and deleting cookies set by Google in your browser.
Third-country transfer: Google LLC is certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses apply in addition.
More information: policies.google.com/privacy
2.7 Embedded Videos (YouTube, Vimeo, Loom)
In some blog posts we embed videos from the YouTube, Vimeo or Loom platforms. Here, too, only a placeholder is shown at first. Only when you click “Play video” does your browser connect to the servers of the respective provider, and the video is loaded and played. Your choice is not stored.
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use the privacy-enhanced mode (embedding via youtube-nocookie.com). Third-country transfer to Google LLC (USA): EU-U.S. Data Privacy Framework, supplemented by Standard Contractual Clauses. Privacy information: policies.google.com/privacy
- Vimeo: Vimeo.com, Inc., New York, USA. Videos are embedded with the parameter “dnt=1” (Do Not Track). Third-country transfer: Vimeo.com, Inc. is certified under the EU-U.S. Data Privacy Framework; supplemented by Standard Contractual Clauses. Privacy information: vimeo.com/privacy
- Loom: Loom, Inc., USA, a company of the Atlassian group (Atlassian, Inc.). Third-country transfer: the DPF certification of Atlassian, Inc. covers Loom, Inc. (EU-U.S. Data Privacy Framework); supplemented by Standard Contractual Clauses. Privacy information: atlassian.com/legal/privacy-policy
After the click, in particular your IP address, the date and time of the request, the referring page and browser and device information are transmitted to the respective provider; the provider may use cookies or similar technologies during playback. We have no influence on the scope and further use of this data by the provider.
Legal basis: your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG, which you give by clicking “Play video”.
Withdrawal: Consent applies only to the respective video and page view. You can withdraw it at any time with effect for the future by not loading the video again and deleting cookies set by the provider in your browser.
2.8 Abuse Protection for Forms (Rate Limiting)
To prevent our forms (contact, information pack, newsletter, chatbot, data protection request, signature) from being misused for mass email sending or automated attacks, we count requests per IP address and per recipient email address within short time windows. These counters are stored separately from the information you enter in the form and are deleted automatically when the time window expires, at the latest after 72 hours.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and in the secure operation of the website).
2.9 Electronic Signing of Offers and NDAs
You can accept offers and sign non-disclosure agreements (NDAs) electronically via a personal link. Before you sign, we send you a one-time code by email to confirm your identity.
- Data processed: name, email address, where applicable your role in the company, signature image, time of signing, IP address and browser identifier (user agent) when the code is requested and when you sign; the one-time code is stored only as a hash value
- Purpose: conclusion of the contract and proof that you signed it, and protection against misuse of the link
- Legal basis: Art. 6(1)(b) GDPR (conclusion of the contract) and Art. 6(1)(f) GDPR (legitimate interest in reliable proof); for retention Art. 6(1)(c) GDPR
- Recipients: Convex (storage), Resend (sending the code and the confirmation)
- Retention period: as part of the contract documents for the statutory retention periods (up to 10 years, § 147 AO, § 257 HGB); if no contract is concluded, we delete the data as soon as it is no longer needed for evidential purposes, as a rule after the standard limitation period of 3 years has expired
2.10 Data Protection Requests
If you exercise a data subject right via our data protection request form, by email or in the chat, we process your email address, the type of request, the information you enter in free text and the times and outcome of its handling.
Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 12 et seq. GDPR (fulfilling your rights) and Art. 5(2) GDPR (accountability).
Retention period: 3 years after the request has been closed, then deleted automatically.
2.11 Accounting and Processing of Receipts
For our accounting we process invoices and receipts from customers and suppliers. Receipts are uploaded in the protected administration area; to extract invoice data (issuer, amount, date, category) we use Google’s Gemini API. The uploaded original files are deleted after processing; we keep the booked data for the statutory periods.
Legal basis: Art. 6(1)(c) GDPR (§ 147 AO, § 257 HGB).
Retention period: 10 years.
3. Overview of Processing Activities
The following table gives a complete overview of our processing activities pursuant to Art. 13 and 14 GDPR:
| Processing | Purpose | Legal basis | Recipients | Retention period | Transfer |
|---|---|---|---|---|---|
| Contact enquiries and information pack | Handling your enquiry, sending the information pack | Art. 6(1)(b)/(f) | Convex, Resend | 2 years after last contact, then deleted automatically | SCCs (Convex), DPF or SCCs (Resend) |
| Newsletter | Sending information | Art. 6(1)(a) | Resend | Until unsubscription; then 30 days, then deleted automatically | DPF or SCCs |
| Appointment booking | Scheduling discovery calls | Art. 6(1)(b) | Cal.com | 2 years | SCCs |
| User accounts | Authentication | Art. 6(1)(b) | Clerk | Until account deletion | DPF |
| Electronic signing (offers, NDAs) | Conclusion of the contract, proof of signing | Art. 6(1)(b)/(c)/(f) | Convex, Resend | Up to 10 years (contract documents) | SCCs (Convex), DPF or SCCs (Resend) |
| Data protection requests | Fulfilling your data subject rights, accountability | Art. 6(1)(c) | Convex, Resend | 3 years after closure, then deleted automatically | SCCs (Convex), DPF or SCCs (Resend) |
| First-party analytics | Website optimisation | Art. 6(1)(a) | Convex | 13 months | SCCs |
| Google Analytics 4 | Audience measurement (only with consent) | Art. 6(1)(a) | Google Ireland/LLC | 14 months | DPF + SCCs |
| AI chatbot | Customer service | Art. 6(1)(a) | Google LLC (Gemini API) or Anthropic PBC (Claude), Convex, Resend | 90 days per message; browser cache 24 hours | DPF + SCCs (Google), SCCs (Anthropic, Convex), DPF or SCCs (Resend) |
| AI content optimisation | Content creation, SEO, transcription | Art. 6(1)(f) | OpenAI, Anthropic, Convex | Duration of processing | SCCs, DPF |
| Accounting and receipts | Statutory bookkeeping | Art. 6(1)(c) | Convex, Google LLC (Gemini API) | 10 years | SCCs (Convex), DPF + SCCs (Google) |
| Website hosting and server logs | Provision of the website, IT security | Art. 6(1)(f) | Vercel | In accordance with Vercel’s specifications, to the best of our knowledge 30 days at most | DPF |
| CDN / reverse proxy | Delivery, security, DDoS protection | Art. 6(1)(f) | Cloudflare | In accordance with Cloudflare’s specifications (logs) | DPF + SCCs |
| Abuse protection (rate limiting) | Preventing misuse of the forms | Art. 6(1)(f) | Convex | 72 hours at most | SCCs |
| Google Maps (contact page) | Displaying a map (only after a click) | Art. 6(1)(a) | Google Ireland/LLC | In accordance with Google’s specifications | DPF + SCCs |
| Video embeds (blog) | Playing videos (only after a click) | Art. 6(1)(a) | Google Ireland/LLC (YouTube), Vimeo, Loom (Atlassian) | In accordance with the provider’s specifications | DPF + SCCs |
| Consent logging | Obligation to demonstrate consent | Art. 6(1)(c) | Convex | 3 years, then deleted automatically | SCCs |
| Lead management | Sales prioritisation | Art. 6(1)(f) | Convex | 2 years after last contact, then deleted automatically (not where a business relationship exists) | SCCs |
Key: DPF = EU-U.S. Data Privacy Framework, SCCs = Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Role of recipients: The role of a recipient depends on the service used and its specific configuration. Many service providers are engaged as processors pursuant to Art. 28 GDPR; for individual services, in particular Google Analytics, separate or joint controllership may exist depending on the features enabled.
4. Legal Bases for Processing
We process your personal data on the basis of:
- Consent (Art. 6(1)(a) GDPR): newsletter, analytics, chatbot, cookie preferences, Google Maps and embedded videos (each after a click)
- Performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR): handling enquiries, providing the services you have requested, appointment booking, electronic signing
- Legal obligation (Art. 6(1)(c) GDPR): tax and accounting requirements, obligations to provide evidence, handling data protection requests
- Legitimate interest (Art. 6(1)(f) GDPR): IT security, abuse prevention, delivery via a content delivery network (Cloudflare), lead scoring, proof of electronic signatures
4a. Obligation to Provide Data
Providing personal data is partly required to conclude a contract and partly voluntary. There is no statutory obligation to provide data, except for billing details after a contract has been concluded:
| Area | Required? | Consequences of not providing the data |
|---|---|---|
| Contact form, information pack | Required for handling | Without contact details we cannot answer your enquiry or send the information pack. |
| Appointment booking (Cal.com) | Required for the booking | Without an email address no appointment can be booked. |
| Electronic signing | Required to conclude the contract | Without your name, email address and confirmation code, electronic signing is not possible. |
| Newsletter | Voluntary (consent) | No disadvantages. |
| Analytics, chatbot | Voluntary (consent) | The website can be used in full without consent; you will then not be able to use the chatbot. |
| Conclusion of a contract | Required by law (§ 14 UStG) | Without a billing address we cannot issue a proper invoice. |
5. Recipients and Processors
We use the following service providers. Where a service provider acts as a processor, processing takes place on the basis of a data processing agreement (DPA) or a comparable data protection agreement. Transfer mechanisms and certifications are reviewed regularly.
| Service provider | Purpose | Data | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. (USA) | Website hosting | Access logs | EU-U.S. DPF |
| Convex Inc. (USA) | Backend database | Enquiries, user, project and signature data, chat histories | SCCs + supplementary measures |
| Clerk Inc. (USA) | Authentication | Name, email, login data | EU-U.S. DPF |
| Resend Inc. (USA) | Email delivery (confirmations, information pack, newsletter, signature codes) | Email address, name | EU-U.S. DPF or SCCs |
| Cal.com (EU/USA) | Appointment booking | Name, email, appointment details | SCCs |
| Google Ireland Ltd. / Google LLC (USA) | Google Analytics 4 (only with consent) | Usage and device data (GA4 does not store IP addresses; Google signals and ad personalisation disabled) | EU-U.S. DPF + SCCs |
| Google LLC (USA) | Gemini API (AI chatbot, default; processing of receipts) | Chat messages and conversation history; invoice data | EU-U.S. DPF + SCCs |
| OpenAI, L.L.C. (USA) | AI content optimisation (SEO, transcription) | Content data entered (no advertising analysis) | SCCs + DPF |
| Anthropic PBC (USA) | AI content optimisation (content creation); alternative provider of the AI chatbot | Content data entered (no training on your data) | SCCs |
| Cloudflare, Inc. (USA) | CDN, reverse proxy, security/DDoS protection (processing on our behalf, DPA) | IP address, request data, logs | EU-U.S. DPF + SCCs |
| Google Ireland Ltd. / Google LLC (USA) | Google Maps on the contact page (only after a click) | IP address, browser/device data, referring page | EU-U.S. DPF + SCCs |
| Google Ireland Ltd. / Google LLC (USA) | YouTube videos in the blog (privacy-enhanced mode, only after a click) | IP address, browser/device data, referring page | EU-U.S. DPF + SCCs |
| Vimeo.com, Inc. (USA) | Vimeo videos in the blog (only after a click) | IP address, browser/device data, referring page | EU-U.S. DPF + SCCs |
| Loom, Inc. / Atlassian, Inc. (USA) | Loom videos in the blog (only after a click) | IP address, browser/device data, referring page | EU-U.S. DPF + SCCs |
Key: DPF = EU-U.S. Data Privacy Framework, SCCs = Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
6. Your Rights (GDPR)
Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6(1)(f) GDPR (for example lead scoring, server logs, abuse protection); this also applies to profiling based on those provisions (Art. 21(1) GDPR). We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where your data is processed for direct marketing purposes, you have the right to object at any time to such processing; this also applies to profiling to the extent that it is related to such direct marketing (Art. 21(2) GDPR). After an objection, we will no longer process your data for direct marketing purposes.
No particular form is required for the objection, e.g. by email to info [at] contextstudios [dot] ai, via our data protection request form or via the unsubscribe link in every marketing email.
Under the GDPR you also have the following rights:
- Access (Art. 15 GDPR): request a copy of your personal data
- Rectification (Art. 16 GDPR): have inaccurate data corrected
- Erasure (Art. 17 GDPR): request the deletion of your data
- Restriction (Art. 18 GDPR): restrict the processing of your data
- Data portability (Art. 20 GDPR): receive your data in a structured format
- Objection (Art. 21 GDPR): see above
- Withdrawal of consent (Art. 7(3) GDPR): withdraw your consent at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected
To exercise these rights, contact us at info [at] contextstudios [dot] ai or use our data protection request form.
We will handle your request within one month; for complex or numerous requests this period may be extended by up to two further months, in which case we will inform you (Art. 12(3) GDPR).
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59-61, 10555 Berlin
Website: www.datenschutz-berlin.de
7. First-Party Website Analytics
We operate our own privacy-friendly analytics system to improve our website. This processing only takes place after you have given your express consent.
Data collected
- Anonymous visitor ID: randomly generated UUID
- Session data: pages visited, time on page, scroll depth
- Geo data: country and city (derived at the edge from request metadata and converted to country/city; the underlying IP address is not stored in the analytics data)
- Device information: browser type, device type, operating system
- Performance metrics: Core Web Vitals (for 20% of visitors)
Privacy measures
- No IP storage in the analytics system: IP addresses are neither collected nor stored in our analytics system
- Consent-based: tracking only after explicit consent
- GPC support: Global Privacy Control is respected as an opt-out preference for non-essential tracking, where technically feasible
- Automatic deletion: 13 months (analytics), 3 months (error logs)
Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: possible at any time via the cookie banner or the cookie settings.
Google Analytics 4
In addition to our first-party analytics, we use – exclusively after your consent – Google Analytics 4 (GA4) for audience measurement. Without consent, GA4 is not loaded; if consent is withdrawn in the cookie banner, processing is immediately set to “denied” via Google Consent Mode.
- IP addresses: Google Analytics 4 does not log or store IP addresses; the IP address is used only briefly to determine an approximate location (country/region) and is then discarded.
- Google signals and ad personalisation: disabled (no cross-device matching, no use for advertising).
- Data retention in GA4: 14 months
- Lifetime of the _ga/_ga_* cookies: up to 2 years; current browsers limit them to 400 days at most. When consent is withdrawn, _ga/_ga_* and our own analytics identifiers are deleted immediately.
Legal basis: Art. 6(1)(a) GDPR (consent), § 25(1) TDDDG.
Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (where applicable Google LLC, USA). Third-country transfer: EU-U.S. Data Privacy Framework and Standard Contractual Clauses.
Withdrawal: possible at any time via the cookie banner or the cookie settings.
8. AI Chatbot “Cosmo” (Google Gemini)
Our website offers an AI chatbot. You are interacting with an AI system, not with a human being; you can switch to a member of our team at any time via “Talk to a human”. The chatbot is only used after you have given your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future – via “Delete my data” in the chat or via our data protection request form (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before it. General information on our use of AI is available on our AI Transparency page.
Data collected
- Your chat messages and the chatbot’s replies
- Anonymous visitor and session ID, timestamps, language
- The page you are on, device type and browser
- Your IP address – used only for abuse prevention (rate limiting) and stored separately from the conversation history
Purposes of processing
- Answering your questions about our services
- At your request: handover to a member of our team, appointment booking or sending information
- Evaluating conversations to improve the quality of the chatbot (identifying knowledge gaps and incorrect answers)
- Abuse prevention and operational security
Recipients and third-country transfers
- Google LLC, USA (Gemini API, Gemini Flash model): To generate an answer, we transmit your messages and the conversation history to the Gemini API. The transfer is based on the EU-U.S. Data Privacy Framework, supplemented by Standard Contractual Clauses.
- Anthropic PBC, USA (Claude): For availability or quality reasons we may run the chatbot with a Claude model from Anthropic instead of Gemini. Your messages and the conversation history are then sent to Anthropic; the basis is Standard Contractual Clauses. Anthropic does not use API data for training.
- Convex Inc., USA: storage of the conversation history in our database; processing on our behalf on the basis of Standard Contractual Clauses.
- Resend Inc., USA: sending confirmation and notification emails if you submit a contact or callback request; EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
Note on the Gemini API
Google processes the data in accordance with the Gemini API terms of service.
Retention period
- Conversation history in our database: each message 90 days from when it was sent, then deleted automatically
- Local cache in your browser: 24 hours
- Record of consent: 90 days, together with the data it covers
- Rate-limiting data (IP-based): up to 72 hours (24-hour window plus the deletion run)
Details from contact or callback requests that you leave in the chat are stored as an enquiry under section 2.1 and not according to this period.
Legal basis: Art. 6(1)(a) GDPR (consent); for rate limiting Art. 6(1)(f) GDPR (legitimate interest in preventing abuse). We record your consent with a timestamp and the version of the privacy policy (version 2026-09).
Deletion: at any time in the chat via “Delete my data”, via our data protection request form or by email to info [at] contextstudios [dot] ai.
9. International Data Transfers
Some of our service providers are located in third countries (in particular the USA). Where necessary, we base such transfers on appropriate safeguards such as:
- EU-U.S. Data Privacy Framework (DPF) – adequacy decision of the European Commission of 10 July 2023, for certified companies (verifiable at dataprivacyframework.gov)
- Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR (Implementing Decision (EU) 2021/914)
- Supplementary technical and organisational measures
- Transfer impact assessments (TIAs) as required and depending on the service configuration
The specific transfer mechanisms for each provider are set out in section 5.
10. Retention Periods
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations:
| Data category | Retention period | Reason |
|---|---|---|
| First-party analytics | 13 months | Year-on-year comparison + buffer |
| Google Analytics 4 (only with consent) | 14 months | GA4 retention setting |
| AI chatbot: conversation history | 90 days | Per message from when it was sent, deleted automatically |
| AI chatbot: local browser cache | 24 hours | Session continuity |
| Rate limiting (IP, forms and chatbot) | Up to 72 hours | Time window plus the deletion run |
| Server logs (Vercel) | In accordance with Vercel’s specifications, to the best of our knowledge 30 days at most | Error analysis, security |
| Lead/contact data, information pack requests | 2 years after last contact | Initiating business, legal claims; deleted automatically unless a business relationship exists (in which case the periods for contract data apply) |
| Consent logs | 3 years | Obligation to demonstrate consent (Art. 7 GDPR), deleted automatically |
| Data protection requests | 3 years after closure | Proof of handling (Art. 5(2) GDPR), deleted automatically |
| Newsletter subscriptions | Until unsubscription, then 30 days | Consent-based; the record is deleted automatically 30 days after unsubscription |
| User accounts | Until account deletion | Performance of the contract |
| Electronic signing (without conclusion of a contract) | As a rule 3 years | Proof, standard limitation period |
| Invoice/accounting and contract data (incl. proof of signature) | 10 years | Statutory retention obligation (§ 147 AO, § 257 HGB), Art. 6(1)(c) GDPR |
After the retention periods have expired, data is deleted or anonymised unless statutory retention obligations prevent this.
11. Data Security
We implement appropriate technical and organisational measures:
- TLS encryption for all data transfers
- Encryption of data at rest
- Secure authentication (Clerk: ISO 27001, SOC 2 certified)
- Regular security updates and monitoring
- Access controls and audit logging
- Data processing agreements or comparable data protection agreements with service providers, where required
Notification of personal data breaches
In the event of a personal data breach that affects you, we will inform you without undue delay in accordance with Art. 34 GDPR. Notifications to the supervisory authority are made within 72 hours in accordance with Art. 33 GDPR.
12. Children’s Privacy
Our services are not directed at persons under the age of 16. We do not knowingly collect personal data from children. If you, as a parent, become aware that your child has provided us with personal data, please contact us at info [at] contextstudios [dot] ai.
13. Automated Decision-Making and Profiling
We do not use automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
Lead scoring (profiling)
We use an internal lead scoring system to prioritise contact enquiries. This constitutes profiling within the meaning of Art. 4(4) GDPR, but is used exclusively for the internal prioritisation of our responses and does not produce decisions with legal effects or similarly significant effects.
Data sources used
- Information provided voluntarily in contact forms (company name, position, project details)
- UTM parameters and referrer information (if available)
- Interactions on the website (recorded with consent)
Scoring factors
- Company size and type
- Project scope and budget
- Engagement with our content
- Timeframe and decision status
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the efficient allocation of resources).
Your rights: You can request information about the data used for the assessment and object to the processing at any time (see Right to object under Art. 21 GDPR).
14. Changes to This Privacy Policy
We may update this privacy policy. Changes will be published on this page with an updated date. In the event of material changes, we will inform you by email or by a notice on our website.
15. Contact
If you have any questions about this privacy policy, please contact us:
Context Studios UG (haftungsbeschränkt)
Kaiser-Friedrich-Str. 6
10585 Berlin, Germany
Email: info [at] contextstudios [dot] ai
Annex: Additional Information for California and the United Kingdom
The following information supplements sections 1 to 15 for persons resident in California and other U.S. states (A.1, A.2) and in the United Kingdom (A.3). In all other respects, the privacy policy above applies.
A.1 California Consumer Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). This section supplements the information in this privacy policy.
Categories of personal information collected
In the past 12 months, we have collected the following categories of personal information as defined by the CCPA:
| Category | Examples | Collected? |
|---|---|---|
| A. Identifiers | Name, email address, IP address, online identifiers | YES |
| B. Personal information (Cal. Civ. Code § 1798.80) | Name, address, email, phone number | YES |
| C. Protected classifications | Age, gender, race, citizenship | NO |
| D. Commercial information | Products/services purchased, purchase history | YES |
| E. Biometric information | Fingerprints, faceprints, voiceprints | NO |
| F. Internet activity | Browsing history, search history, website interaction | YES |
| G. Geolocation data | Physical location or movements | YES (country/city derived at the edge from request metadata; no IP storage) |
| H. Sensory information | Audio, visual, thermal, olfactory | NO |
| I. Professional/employment information | Job title, employer, employment history | YES (if provided) |
| J. Education information | Education records, transcripts | NO |
| K. Inferences | Preferences, characteristics, behaviour | YES (from analytics) |
| L. Sensitive personal information | SSN, driver’s licence, financial account, precise geolocation | NO |
Business purposes for collection
We collect and use personal information for the following business purposes:
- Providing services and customer support
- Processing transactions and payments
- Communicating with you about services, updates and offers
- Analytics and improving our website and services
- Security, fraud prevention and legal compliance
- Marketing and advertising (with consent)
Categories of third parties we share with
We share personal information with:
- Service providers: hosting (Vercel), CDN (Cloudflare), database (Convex), authentication (Clerk), email (Resend), booking (Cal.com), AI services (Google Gemini, OpenAI, Anthropic)
- Analytics providers: Google Analytics (with consent)
- Professional advisors: lawyers, accountants, auditors
- Government authorities: when required by law
Sale and sharing of personal information
We do not sell your personal information for monetary consideration.
However, when you consent to analytics cookies (such as Google Analytics), this may constitute “sharing” under the CCPA because it enables cross-context behavioural advertising. Categories shared:
- Internet activity (browsing history, page views, clicks)
- Device information (browser type, device type, operating system)
- Geolocation data (approximate location derived at the edge; no IP storage)
You have the right to opt out of this sharing. See our Do Not Sell or Share My Personal Information page for instructions.
Retention by category
| Category | Retention period | Reason |
|---|---|---|
| Newsletter subscribers | Until unsubscription + 30 days | Consent-based processing |
| Contact enquiries | 2 years after last contact | Customer service, potential contract; deleted automatically |
| Client contracts and invoices | 10 years after the end of the contract | German tax law (§ 147 AO) |
| Analytics data (Google Analytics) | 14 months | Analytics retention setting |
| Consent records | 3 years | Proof of consent (Art. 7(1) GDPR); deleted automatically |
| Account data (Clerk) | Until account deletion | Service provision, security logs |
| Booking data (Cal.com) | 2 years after the meeting | Client relationship management |
Your California privacy rights
California residents have the following rights:
- Right to know: request disclosure of the personal information collected, used, disclosed and sold/shared
- Right to delete: request deletion of personal information (with exceptions)
- Right to correct: request correction of inaccurate personal information
- Right to opt out: opt out of the sale/sharing of personal information
- Right to limit: limit the use and disclosure of sensitive personal information
- Right to non-discrimination: not be discriminated against for exercising CCPA rights
How to exercise your rights
To exercise your California privacy rights:
- Email: info [at] contextstudios [dot] ai with the subject “CCPA Privacy Rights Request”
- Opt out of sharing: Do Not Sell or Share My Personal Information
- Cookie settings: use our cookie settings to reject analytics cookies
We will verify your identity before processing requests. We will respond within 45 days (extendable by a further 45 days if necessary). You may use an authorised agent to submit requests on your behalf.
Global Privacy Control (GPC)
We recognise and honour the Global Privacy Control (GPC) browser signal. When GPC is detected:
- we treat GPC as an opt-out of sale/sharing under CCPA § 1798.135(b)(2)
- we treat GPC as an opt-out preference for non-essential tracking, where technically feasible
- analytics and advertising cookies are not set without an explicit consent overriding it
- this applies to the specific browser and device on which GPC is enabled
Learn how to enable GPC on our Do Not Sell or Share page.
Financial incentives
We do not offer financial incentives or price differences in exchange for the collection, sale or retention of personal information.
A.2 Privacy Rights in Other U.S. States
In addition to California, the following U.S. states have enacted comprehensive privacy laws with similar consumer rights. If you are a resident of one of these states, you have rights similar to those described in section A.1:
| State | Law | Effective date |
|---|---|---|
| California | CCPA/CPRA | January 1, 2020 (CCPA) / January 1, 2023 (CPRA) |
| Colorado | CPA (Colorado Privacy Act) | July 1, 2023 |
| Connecticut | CTDPA (Connecticut Data Privacy Act) | July 1, 2023 |
| Delaware | DPDPA (Delaware Personal Data Privacy Act) | January 1, 2025 |
| Florida | FDBR (Florida Digital Bill of Rights) | July 1, 2024 |
| Indiana | ICDPA (Indiana Consumer Data Protection Act) | January 1, 2026 |
| Iowa | ICDPA (Iowa Consumer Data Protection Act) | January 1, 2025 |
| Kentucky | KCDPA (Kentucky Consumer Data Protection Act) | January 1, 2026 |
| Maryland | MOPDA (Maryland Online Data Privacy Act) | October 1, 2025 |
| Minnesota | MCDPA (Minnesota Consumer Data Privacy Act) | July 31, 2025 |
| Montana | MCDPA (Montana Consumer Data Privacy Act) | October 1, 2024 |
| Nebraska | NDPA (Nebraska Data Privacy Act) | January 1, 2025 |
| New Hampshire | NHDPA (New Hampshire Data Privacy Act) | January 1, 2025 |
| New Jersey | NJDPA (New Jersey Data Protection Act) | January 15, 2025 |
| Oregon | OCPA (Oregon Consumer Privacy Act) | July 1, 2024 |
| Rhode Island | RIDPA (Rhode Island Data Privacy Act) | January 1, 2026 |
| Tennessee | TIPA (Tennessee Information Protection Act) | July 1, 2025 |
| Texas | TDPSA (Texas Data Privacy and Security Act) | July 1, 2024 |
| Utah | UCPA (Utah Consumer Privacy Act) | December 31, 2023 |
| Virginia | VCDPA (Virginia Consumer Data Protection Act) | January 1, 2023 |
Common rights across these states
- Right to confirm whether we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to delete personal data you provided
- Right to data portability (obtain a copy in a portable format)
- Right to opt out of targeted advertising, sales and profiling
To exercise these rights, contact us at info [at] contextstudios [dot] ai with “State Privacy Rights Request” in the subject.
Appeal process
If we deny your request to exercise your privacy rights, you have the right to appeal. To appeal, reply to our denial email within 60 days. We will respond to your appeal within 60 days. If we deny your appeal, we will provide information on how to contact your state attorney general.
A.3 UK Privacy Rights (UK GDPR)
If you are a UK resident, you have specific rights under the UK GDPR and the UK Data Protection Act 2018.
Your UK rights
You have the following rights under the UK GDPR:
- Right of access: request a copy of your personal data (subject access request)
- Right to rectification: have inaccurate or incomplete data corrected
- Right to erasure: request deletion (“right to be forgotten”)
- Right to restrict processing: limit how we use your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making: not to be subject to decisions based solely on automated processing
UK supervisory authority
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Helpline: 0303 123 1113
Website: www.ico.org.uk
International transfers from the UK
Following Brexit, transfers of personal data from the UK to countries outside the UK (including the EEA) require adequate safeguards. We safeguard transfers from the UK through:
- UK adequacy decisions (e.g. EEA, Switzerland)
- UK International Data Transfer Agreement (IDTA)
- UK Addendum to the Standard Contractual Clauses
- Recognition of the EU-U.S. Data Privacy Framework in the UK (ICO)
PECR (Privacy and Electronic Communications Regulations)
For UK residents, we comply with PECR regarding:
- Cookies: we obtain consent before setting non-essential cookies
- Marketing communications: we send marketing emails only with your consent (opt-in)
- Caller ID: not applicable (we do not make marketing calls)
UK Consumer Contracts Regulations 2013
If you are a UK consumer purchasing services at a distance (online), you have:
- Right to pre-contractual information: clear information about services, prices and terms before purchase
- 14-day cancellation right: the right to cancel within 14 days of the contract (see our cancellation policy)
- Exceptions: the right may not apply if you request that the service begin immediately and we perform it in full
UK Consumer Rights Act 2015
For digital content and services, you are entitled to:
- digital content of satisfactory quality
- fitness for a particular purpose
- conformity with the description
- remedies if digital content is faulty (repair, replacement, price reduction, refund)
To exercise your UK privacy rights, contact us at info [at] contextstudios [dot] ai.