1. Controller
The controller responsible for processing personal data on this website within the meaning of the GDPR is:
Lirux [Legal Entity TBD]
[Street and number]
[Postcode City]
Germany
Email: [email protected]
Data protection officer: [to be completed — or state that no DPO is required]
2. Scope
This policy covers the website lirux.ai and enquiries you send us through it or by email. It does not cover customer content processed through our AI services. For that processing we usually act as processor on behalf of our customers under a Data Processing Agreement — see Data processing and DPA.
3. Server logs
When you visit the website, our hosting infrastructure automatically processes technical data that your browser transmits: IP address, date and time of the request, requested URL, referrer URL, HTTP status code, transferred data volume, and browser and operating system information (user agent).
Purpose: delivering the website, ensuring its security and stability, and detecting and defending against attacks and abuse. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the website. Logs are not combined with other data sources to identify individual visitors.
4. Contact forms and email
When you use a form on this website (for example to request a deployment, a pilot, an architecture recommendation or a partnership) or email us, we process the information you provide: typically your name, business email address, company, country, company size, your message and any technical details you choose to enter. We also record the page the form was sent from and the time of submission. Fields marked as required are needed to respond to your enquiry.
Purpose: responding to your enquiry, preparing an offer, and managing the business relationship. Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to entering into a contract; otherwise Art. 6(1)(f) GDPR, our legitimate interest being to answer business enquiries addressed to us.
Form submissions are stored in our customer relationship management (CRM) system and/or delivered by email through an email service provider.
5. Bot protection
To protect our forms against spam and automated abuse, we may use a bot-protection service. Where enabled, it processes technical information about your browser and device, including your IP address, to assess whether the form is being submitted by a person. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is protecting our systems and staff from spam and abuse. Additional anti-abuse measures (such as rate limiting) operate on our own servers.
6. Analytics and cookies
This website does not use cookies for advertising or cross-site tracking. Fonts and other assets are served from our own infrastructure, not from third-party content delivery networks.
Website analytics are optional and currently configurable. If enabled, we use a privacy-friendly, cookieless analytics service that does not store information on your device and records aggregated statistics (for example page views, referrers, country and device type) without building individual profiles. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is understanding how the website is used in order to improve it. Should we ever introduce technologies that store or access information on your device and are not strictly necessary, we will ask for your consent first (§ 25 TDDDG, Art. 6(1)(a) GDPR).
Analytics provider currently in use: [none / to be completed if enabled]
7. Recipients and processors
We share personal data only where necessary for the purposes above, with the following categories of recipients:
- Website hosting and content delivery provider;
- CRM provider and email service provider;
- Bot-protection service, where enabled;
- Cookieless analytics provider, where enabled;
- Professional advisers (e.g. tax advisers, auditors, lawyers) bound by confidentiality, where required;
- Public authorities, where we are legally obliged to disclose data.
Service providers act as processors on our behalf under data processing agreements in accordance with Art. 28 GDPR. A current list of the specific providers is available on request from [email protected].
8. International transfers
Some of our service providers may process personal data outside the European Economic Area. Where this is the case, we ensure an appropriate level of protection in accordance with Chapter V GDPR — for example on the basis of an adequacy decision of the European Commission or Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can request information about the safeguards in place using the contact details above.
The website is hosted in: [hosting location — to be completed]. Please note that the compute infrastructure for our AI services is located in Georgia, outside the EEA; this is relevant to customer workloads and is described on our Data processing page.
9. Retention
- Server logs: deleted after [X days — to be defined], unless needed longer to investigate a specific security incident.
- Enquiries: deleted when they have been dealt with and no business relationship follows, normally after [X months — to be defined].
- Business correspondence and contract data: retained for the periods required by commercial and tax law (in Germany typically six or ten years under § 257 HGB and § 147 AO).
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21);
- withdraw any consent you have given, with effect for the future (Art. 7(3)).
To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is: [to be completed — depends on registered office].
11. Other information
Automated decision-making: we do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR on this website.
Obligation to provide data: you are not obliged to provide personal data. Without the information marked as required in a form, however, we cannot respond to your enquiry.
Changes: we will update this policy when our processing changes. The date at the top shows the latest version.