Privacy Policy

Version 1 · effective 8 October 2026

This policy explains how personal data is processed on aio.gmbh, in line with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

1. Who is responsible

Michael König-Weichhardt, trading as aio (sole proprietor) Bachweg 10, 8410 Wildon, Styria, Austria Email: info@aio.gmbh

We are the controller for the data of visitors of aio.gmbh and of people who send us a request through the intake form or by email. aio.gmbh has no member accounts, newsletter or shop.

2. Intake form ("Custom solutions intake")

The form on the home page and on the custom solutions page asks for:

  • your name, your email address and the project type (required),
  • your company or organization (optional),
  • your project brief (required). Please do not include special categories of personal data or passwords in the brief.

Purpose: to read and answer your request and, if you wish, to prepare an offer. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). Without the required fields we cannot answer the request.

What happens when you send it:

  • The entries are sent by email to our inbox (info@aio.gmbh) through Cloudflare Email Service, and a copy is stored in our inbox on Cloudflare R2 storage.
  • A usage statistic records that a form was sent, with the form ID, country, device type and a short, truncated hash of the IP address (Cloudflare Analytics Engine). The entries themselves are not part of it.
  • To prevent abuse, the number of submissions per IP address is limited for about one minute (Cloudflare cache).

We read and answer requests with the help of an AI assistant (Claude by Anthropic), which reads the request and drafts and sends the reply on our behalf; we remain responsible for every answer. We answer from support@aioengine.io, the mailbox of the same operator. To track the request we keep an internal case record on GitHub with a reference to your message and a short summary of the request, without your email address.

Retention: we keep the request and our correspondence while we handle it and while a business relationship that follows from it exists. If a contract follows, the records needed for accounting and tax are kept for 7 years (section 132 BAO). You can ask us at any time to delete a request that did not lead to a contract.

3. Visiting the website

  • Technical connection data (IP address, browser, device) is processed by Cloudflare to deliver pages and protect the service (Art. 6(1)(f) GDPR, legitimate interest in a secure and working website).
  • Usage statistics in Cloudflare Analytics Engine: page or event, country, device type and a short, truncated hash of the IP address (Art. 6(1)(f) GDPR). Individual events are kept for 90 days, daily summaries for 1 year, monthly summaries for 7 years and yearly summaries while the site exists.
  • The pages do not load fonts, scripts or embeds from other providers.

4. Cookies and local storage

NamePurposeDuration
csrf_token (cookie)Protection against cross-site request forgerybrowser session
theme_mode (local storage)Remembers the light or dark mode you choseuntil you clear it

Both are strictly necessary for a function you use (Art. 5(3) ePrivacy Directive, section 165(3) TKG 2021). No tracking or advertising cookies are set.

5. Processors and other recipients

ProviderLocationPurposeData
Cloudflare, Inc.USA, global networkHosting and storage (Workers, R2), delivery and security, email sending (Cloudflare Email Service) and receiving (Email Routing), usage statistics (Analytics Engine)all data named in this policy
Anthropic, PBCUSAAI assistance in reading and answering requests (Claude)the content of your request
GitHub, Inc.USAInternal case trackinga reference to your message and a short summary of the request

Transfers to the USA are based on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the EU Standard Contractual Clauses in the provider's terms. We do not sell your data and do not use it for advertising.

6. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Write to info@aio.gmbh. We answer within one month.

You can lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.

No automated decision-making with legal or similarly significant effects (Art. 22 GDPR) takes place.

7. Changes

We publish a new version of this policy with a new version number and effective date.

Related: Imprint · aio platform privacy policy