This privacy policy explains how personal data is processed when you visit paulinai.dev or use our contact, demo and appointment services. PaulinAI and paulinai.dev are a brand and digital service of High-Definition Development & Networks GmbH.
1. Controller
High-Definition Development & Networks GmbH,
Kappl 14, 6677 Schattwald, Austria
Email: [email protected]
Company email: [email protected]
Phone: +43 5675 43295
References to “we” or “us” in this policy mean the company named above as controller.
2. Legal bases
We process personal data only where a legal basis under the General Data Protection Regulation (GDPR) applies. Depending on the processing, these bases are in particular:
- Article 6(1)(a) GDPR (consent),
- Article 6(1)(b) GDPR (contract or steps taken before entering into a contract),
- Article 6(1)(c) GDPR (legal obligation), and
- Article 6(1)(f) GDPR (legitimate interests, particularly secure operation, communication and error analysis).
3. Hosting and server logs
When you access our website, your browser transmits technically necessary data to our web servers. This may include your IP address, date and time, requested page or file, amount of data transferred, status code, referring page and information about your browser and operating system (user agent).
We process these data to operate the website reliably, maintain IT security, analyse errors and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Log data are retained only for as long as required for these purposes. Data relating to a specific security incident may be retained until the incident has been resolved and as required by law.
The public website runs on server infrastructure administered by High-Definition Development & Networks GmbH and is delivered through secured reverse-proxy systems.
4. Public verification of PaulinAI labels
At paulinai.dev/check/ we provide a free service for checking machine-readable PaulinAI labels in image files. When you actively start a check, the selected image is transferred to the verification service over an encrypted connection and analysed. The processing involves the image and technically required connection data such as the IP address, time, status code and browser information.
The data are processed solely to provide the check you requested, protect the service against misuse and address technical faults. The legal bases are Article 6(1)(b) GDPR for the free service requested by you and Article 6(1)(f) GDPR for secure and reliable operation. No additional consent checkbox is therefore required to use the checker.
The image is not permanently retained by the verification service, evaluated for advertising, used for AI training or transferred to lead management. Application-level processing takes place only during the check and the file content is then discarded. Necessary security logs do not contain the uploaded image and are kept only for as long as required to investigate misuse and faults. Reverse proxies are configured so that file content is not intentionally recorded in access logs and the request is forwarded without temporary file buffering wherever possible.
The verification page does not load Google Analytics, Google Maps, Cloudflare Turnstile, marketing tags or the cookie-consent module. It sets no advertising or analytics cookies. The service currently supports only PNG, JPEG and WebP images up to 15 MB. Video, audio and text content are not represented as verified.
Do not upload confidential, particularly sensitive or personal content unless the check is necessary and the transmission is lawful. See the verification terms for further information about the meaning of the result.
5. Cookies, consent management and Google Analytics
We use technically necessary cookies, tokens or local browser storage for security, forms and consent management. In particular, your privacy selection is stored so that the website can respect it on later visits. These storage operations are necessary for the requested function and secure website operation. The legal basis is Article 6(1)(f) GDPR or Article 6(1)(b) GDPR. Consent is requested again after no more than 180 days. The website font is served locally and does not connect to Google Fonts.
With your explicit consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The measurement helps us understand which pages are viewed, how visitors navigate the website and which devices or browsers are used. Data processed may include page views, time, referrer, approximate region, device and browser information and an identifier stored in a first-party cookie. Google Analytics may use cookies named _ga and _ga_<identifier> for this purpose.
The Google Analytics tag on paulinai.dev is loaded only after you select “Accept all” or enable statistics in the cookie settings. Before then, our implementation does not transfer Analytics data to Google. Advertising storage, advertising personalisation and Google Signals remain disabled. The lifetime of Analytics cookies configured by us is limited to 180 days. The legal basis is solely your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time through the cookie icon at the bottom left; this also removes Google Analytics cookies detectable for paulinai.dev. Withdrawal does not affect the lawfulness of processing before withdrawal.
Google may also process data on servers of affiliated companies outside the European Economic Area. Transfers to third countries take place only in accordance with Articles 44 et seq. GDPR. For more information, see the Google Privacy Policy and Google Analytics privacy information.
6. Contact and demo enquiries
If you contact us by email, telephone, contact form or demo form, we process the data you provide to handle your enquiry and any necessary follow-up. This may include your name, business email address, company, region, company size, systems involved, intended use case and message.
The purposes are responding to your enquiry, consultation, preparing an offer and preparing a possible business relationship. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters and otherwise Article 6(1)(f) GDPR based on our legitimate interest in handling business enquiries. Consent given in a form may be withdrawn at any time with effect for the future.
Forms are processed through a server endpoint operated by High-Definition Development & Networks GmbH and are not sent through a public form-delivery service. Email delivery uses the grommunio mail system operated by High-Definition Development & Networks GmbH.
7. Direct appointment booking and grommunio
When you book an appointment, we process your name, business email address, company, selected time and an optional message. The designated grommunio calendar is queried to determine available times. Once booked, the appointment is created in that calendar and a calendar invitation is sent to your email address. An individual grommunio Meet link is generated in our own environment for the video meeting.
This processing is necessary to take steps at your request before entering into a contract or to organise the meeting you requested under Article 6(1)(b) GDPR.
8. Form protection with Cloudflare Turnstile
We use access restrictions, an invisible honeypot and Cloudflare Turnstile to protect our forms against automated submissions and misuse. The provider is Cloudflare, Inc. and its affiliated companies.
Turnstile evaluates technical browser and device signals to distinguish human input from automated access. Data processed may include the IP address, browser and device information, operating system, referring page, and the time and outcome of the check. The verification token is validated by our server through Cloudflare’s interface. The legal basis is Article 6(1)(f) GDPR based on our legitimate interest in protecting the website and its forms against spam and misuse.
For more information, see the Cloudflare Privacy Policy and the Cloudflare Turnstile documentation.
9. Google Maps
The contact page can load a map from Google Maps. For users in the European Economic Area, the provider is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map is activated only after you allow “External media” in the cookie settings or accept all optional services. Loading the map establishes a connection to Google. Data transmitted may include your IP address, browser and device information and usage data. If you are signed in to Google, Google may associate these data with your account. Using the map or route planning may also involve location-related data.
The map provides a clear view of our location and convenient route planning. The legal basis is your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time through the cookie icon at the bottom left with effect for the future. Processing by Google LLC in the United States cannot be ruled out.
For more information, see the Google Privacy Policy and the Google Maps additional terms.
10. Central lead processing
Data from contact, demo and appointment forms are transferred server-to-server to a lead-management system operated by High-Definition Development & Networks GmbH. The technical endpoint is https://update.paulinai.dev/api/v1/leads; your browser does not connect directly to this system and the access key remains on the web server.
Depending on the form, the data may include contact details, company, message, intended use case, region, company size, systems involved, selected appointment, language, page, campaign or UTM data, consent status and version, submission time and a randomly generated case identifier. We use these data to receive, assign, handle and document enquiries centrally, prevent duplicate submissions and protect the interface. The legal bases are Article 6(1)(b) GDPR for requested meetings and pre-contractual measures and Article 6(1)(f) GDPR for secure and traceable handling. Where a form requests explicit consent, Article 6(1)(a) GDPR also applies.
The data are processed within infrastructure controlled by HDN. Technical hosting or operations providers receive access only where required and contractually safeguarded. Retention depends on processing status, evidential requirements and statutory retention obligations; the data are then deleted or anonymised.
11. Search-engine management and website verification
We may use Google Search Console and Bing Webmaster Tools to monitor discoverability, indexing and technical availability. Ownership is verified through static files or meta tags. Verification itself does not set cookies or load an analytics script in the browser. The portals primarily provide aggregated information about search queries, indexing and technical issues. Normal crawler requests are recorded in server logs like other requests. The legal basis is Article 6(1)(f) GDPR.
12. AI transparency and automated decisions
The public website describes PaulinAI but does not itself provide an AI chat to visitors and does not make solely automated decisions producing legal or similarly significant effects. Form and demo enquiries are handled by people.
AI-generated editorial images on this website are visibly labelled as such. Purely schematic illustrations, logos and clearly graphical product or process visualisations are not presented as real photography.
Where PaulinAI is deployed as an interactive AI system for a customer, the notices, permissions, human approvals, logs and, where required, labels for AI-generated content must be implemented in the relevant product and operating concept. The specific assessment under the GDPR and EU AI Act depends on the purpose, data, model, risk class, user group and configuration of the relevant project. This website policy therefore does not replace project-specific privacy information or a risk assessment for the deployed system.
13. Customer and project data for PaulinAI services
Depending on the engagement, consultation, implementation, operation, maintenance and further development of PaulinAI may involve processing contact and contract data, user and permission data, log data, content data and communications.
The purposes are service delivery, project implementation, error analysis, security, documentation, support and billing. The legal bases are Article 6(1)(b), (c) and (f) GDPR. Where we process personal data on behalf of a customer, we do so under a data processing agreement pursuant to Article 28 GDPR and the customer’s documented instructions.
14. Recipients and processors
Personal data are disclosed only where required for the purposes described above, where an appropriate agreement is in place or where required by law. Possible categories of recipients include hosting and server providers, email and calendar services, technical service providers, authorities and other public bodies where legally required.
Where necessary, we enter into agreements with processors under Article 28 GDPR. Transfers to third countries take place only in accordance with Articles 44 et seq. GDPR, for example on the basis of an adequacy decision or appropriate safeguards.
15. Retention
We retain personal data only for as long as required for the relevant purpose. Enquiries and form data are retained until fully handled and thereafter only as required for evidence or statutory retention duties. Appointment and communication data are retained according to business requirements and legal obligations. The data are then deleted or anonymised.
16. Data security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access and unlawful alteration. These include TLS/SSL encryption, access restrictions, secured server and proxy configurations, logging, backups and controlled permissions.
17. PaulinAI’s local-first principle
PaulinAI is designed as local-first software. In local operation, knowledge and company data are processed within the respective customer’s infrastructure. Optional external services or cloud models are used only according to the customer’s selected configuration and permissions. This public website is separate and is governed by the rules for website visitors described in this policy.
18. Your rights
Subject to the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability and objection to certain processing. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.
To exercise your rights, contact [email protected] or [email protected].
You also have the right to lodge a complaint with a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority.
19. External links and social networks
Our website contains links to external websites and our profiles on social networks. A connection to the relevant provider is established only when you follow such a link. The respective provider is responsible for personal-data processing on its service, and its privacy policy applies.
20. Changes to this policy
We update this privacy policy when legal requirements, the services we use or the website’s functions change. The version published on this page applies.
Last updated: August 2026