Privacy Policy
As of August 2026
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is: Mihaela Nompleggio, Josef-Selders-Str. 20, 41462 Neuss, Germany, email: info@futurepresence.de.
2. Data Protection Officer
We are not legally required to appoint a company data protection officer, as fewer than 20 persons are permanently involved in the automated processing of personal data (§ 38 BDSG). For data protection questions, please contact us directly at the address above.
3. Hosting and server logs
This website is delivered by: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you access the website, Cloudflare processes connection data (including IP address, time of access, page accessed, referrer, browser type) in order to deliver the website and ensure system security. Your IP address is additionally used as a counting key for an abuse limiter on the form and chat endpoints and is not stored persistently for that purpose.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and functional website).
Third-country transfer: the transfer to the USA relies on the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR as part of the Data Processing Agreement concluded with Cloudflare pursuant to Art. 28 GDPR.
Provider's privacy policy: https://www.cloudflare.com/privacypolicy/
4. Contact form
If you submit a request via the contact form, we process the data you provide there (including name, email address, phone number, company, message text) as well as technical metadata (the page URL you were on, browser identifier) in order to process and respond to your request.
Legal basis: Art. 6(1)(b) GDPR (handling your request or the initiation of a contract), or, where the request is not directed at concluding a contract, Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).
Recipients: Cloudflare (see Section 3) for receipt of the submission; Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany as the operator of the servers we use (server location: Germany); and Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France for delivery of the notification email. Data Processing Agreements pursuant to Art. 28 GDPR have been concluded with all of them; apart from the case described in Section 3, no third-country transfer takes place.
5. Chat assistant
This website optionally offers our chat assistant "Fin". If you use the chat, we process the messages you enter, a session-scoped chat ID, and technical metadata (page URL, language setting) in order to generate a response and continue the conversation within the session.
The transcript is additionally stored locally in your browser and is cleared when you close the browser tab.
Legal basis: Art. 6(1)(a) GDPR (consent). Using the chat is voluntary; you give your consent by sending a message and withdraw it by discontinuing use of the chat. Anonymized usage events for the chat (e.g. opened, message sent) are recorded only if you have consented to the "Analytics" category (see Section 7).
Recipients: Cloudflare and Hetzner (see Sections 3 and 4) for forwarding and processing your messages, and Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Azure OpenAI Service) for generating the responses. Processing at Microsoft takes place on servers within the European Union; no third-country transfer takes place. Data Processing Agreements pursuant to Art. 28 GDPR have been concluded. Privacy policy: https://privacy.microsoft.com/privacystatement
6. Self-Audit request
If you request our Self-Audit, we collect your first and last name, your email address and — each optionally — your company and your answer about where your company currently stands, in order to send you the Self-Audit document once by email.
Legal basis: Art. 6(1)(a) GDPR (consent). Providing the mandatory fields is necessary for delivery.
Recipients: Cloudflare and Hetzner (see Sections 3 and 4) for receipt and processing of your request and for storing the document, and Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France for delivery of the emails. Data Processing Agreements pursuant to Art. 28 GDPR have been concluded.
7. Cookies and consent
We use only strictly necessary cookies and storage entries: for your cookie preferences (the "cookie_preferences" cookie and a "cookie-preferences" local-storage entry, up to 12 months) and, if you use the chat, for the chat ID and the transcript of the ongoing conversation (session storage, cleared when you close the browser tab).
Access to your device is strictly necessary for this and therefore does not require consent under § 25(2) no. 2 TDDDG. The subsequent processing relies on Art. 6(1)(f) GDPR for the cookie preferences and on your consent under Art. 6(1)(a) GDPR for the chat (see Section 5).
We use optional categories only with your prior, explicit consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG): "Analytics" drives the anonymized usage events for the chat assistant; "Marketing" and "Personalization" are currently unused.
You can grant, change, or withdraw your consent at any time via "Cookie settings" in the footer, with effect for the future. Withdrawal stops the affected processing immediately and does not affect the lawfulness of processing carried out before it (Art. 7(3) GDPR).
8. Retention periods
We store personal data only for as long as is necessary for the purposes described or as statutory retention obligations require.
Your contact request reaches us as an email and remains in our mailbox until you ask us to delete it, withdraw your consent to its storage, or the purpose for storing it ceases to apply — for example once your request has been dealt with. Mandatory statutory provisions, in particular the retention periods under § 257 HGB and § 147 AO, remain unaffected.
For the Self-Audit request we create no record of our own beyond delivery; your details remain in the dispatch logs of our email service provider until we delete them there.
Server logs: a few days. Intermediate data from our form and chat processing: 72 hours. Chat transcripts: 30 days.
9. Development and technical operation of the website
Nickle AI – Oreshin, Platon und Scheffler, Daniel GbR, Ludwig-Erhard-Strasse 10, 34131 Kassel, Germany — Purpose: development, delivery, and technical operation of this website on behalf of the controller. Legal basis: Art. 6(1)(b) GDPR. No third-country transfer (EU-based entity). A Data Processing Agreement has been concluded pursuant to Art. 28 GDPR. Privacy policy: https://nickle.ai/privacy
10. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection to processing (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out before the withdrawal remains unaffected.
11. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. Generally, the competent authority is that of your habitual residence or of our registered seat. For our seat in North Rhine-Westphalia, this is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de.
12. Contact
For data protection questions, reach us at info@futurepresence.de.