LEGAL

Privacy policy

This translation is provided for convenience. The German version is legally authoritative.

1. Privacy at a glance

General information

The following information provides a concise overview of what happens to your personal data when you visit this website. Personal data is any information that can be used to identify you personally.

2. Controller

The controller responsible for data processing on this website is:

Born Theoretical Software

Ardit Thaqi

Robert-Bosch-Straße 4

88427 Bad Schussenried

Germany

Email: info@bornsoftware.de

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.

3. Data collection on this website

Contact by email

If you contact us by email, we process the information you provide, including your contact details and the content of your message, in order to handle your enquiry and clarify possible follow-up questions. We do not pass this data to third parties without a legal basis or your consent.

This processing is based on Article 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in handling enquiries addressed to us effectively (Article 6(1)(f) GDPR).

Server log files

The website provider automatically collects and stores information in server log files that your browser transmits to us. This includes:

  • browser type and version
  • operating system used
  • referrer URL
  • hostname of the accessing device
  • time of the server request
  • IP address

This data is not combined with other data sources. It is collected on the basis of Article 6(1)(f) GDPR.

4. BornAI and AI-assisted assessment

BornAI lets you describe a potential software project in a message. Until you send it, the message remains in your browser. When you explicitly submit it, the project information is transmitted to our backend in encrypted form to create an initial, non-binding assessment.

For the AI-assisted assessment, the message and any later additions are transmitted to Anthropic as a processor and processed there using Claude. BornAI uses the commercial Claude API with structured outputs. According to Anthropic, prompts and responses are processed with Zero Data Retention; only the technical JSON schema may be cached for up to 24 hours after its last use. Content from the commercial API is not used to train models unless the customer explicitly participates in a corresponding programme. Nevertheless, please do not submit special categories of personal data, trade secrets or confidential credentials through BornAI.

Further information is available in Anthropic’s guidance on structured outputs, API data retention and the Anthropic Privacy Center.

In this first version, the assessment is not stored in a separate customer database. Contact details and the project enquiry are transmitted only when you explicitly submit the separate contact form. We use Twilio SendGrid for technical email delivery to Born Software. SendGrid processes in particular your name, email address, any company you provide, the project description, the generated assessment and technical delivery and message metadata.

According to Twilio SendGrid, email content is retained only for as long as is necessary for delivery and for no more than 72 hours during repeated delivery attempts. Most recipient and activity data is deleted after no more than 37 days. Certain pseudonymised event data may be stored for up to one year for security, fraud and abuse prevention; random content samples may be retained for up to seven days for security and error analysis. Activity data may be processed in the United States. Twilio’s data processing addendum provides for the EU–US Data Privacy Framework and, where required, EU Standard Contractual Clauses. Further information is available in Twilio’s guidance on data retention and its Data Protection Addendum.

The enquiry delivered to Born Software remains in our business email inbox for as long as necessary to handle it, carry out pre-contractual measures or comply with statutory documentation and retention obligations. It is then deleted.

To protect the service against automated mass use, no more than five assessments per IP address are available within 24 hours. The backend combines the IP address with a secret value to create a pseudonymised SHA-256 value. In production, only this counter value is processed in a Redis store connected to Vercel, with a maximum lifetime of 24 hours. The browser also stores the timestamps of successful assessments locally so that the remaining allowance can be displayed. This local information is not sent to Anthropic.

We also use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, to protect BornAI against automated and abusive access. The security check runs before an assessment and again before a contact enquiry is submitted. Cloudflare processes in particular the IP address, TLS fingerprint, browser information such as the User-Agent, the public sitekey and the requesting domain. The project description, generated assessment and contact details are not transmitted to Cloudflare as part of this security check.

Cloudflare processes these signals on our behalf to provide Turnstile and also under its own responsibility to improve bot detection. Technically necessary security cookies may be set in this process. Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to protect the service, the AI resources used and the contact channel against abuse. Data may be processed in the United States and the European Economic Area. Cloudflare relies on the EU–US Data Privacy Framework for transfers from the European Economic Area to the United States and otherwise on Standard Contractual Clauses. Further information is available in the Turnstile Privacy Addendum and Cloudflare’s cookie information.

Processing is carried out for pre-contractual measures on the basis of Article 6(1)(b) GDPR and for the secure and efficient provision of the service on the basis of Article 6(1)(f) GDPR.

5. Hosting

This website is hosted by Vercel. Personal data collected through this website is stored on the hosting provider’s servers. This may include IP addresses, contact enquiries, metadata and communication data, contract data, contact details, names, website access data and other information generated through a website.

We use the hosting provider to perform contracts with potential and existing customers (Article 6(1)(b) GDPR) and in our legitimate interest in providing our online service securely, quickly and efficiently through a professional provider (Article 6(1)(f) GDPR).

6. Cookies and local storage

Our website does not use analytics or marketing cookies. When BornAI is used, Cloudflare Turnstile may set technically necessary security cookies solely for security and abuse prevention.

To prevent the cookie notice from appearing again after you acknowledge it, the value “born-cookie-notice” is stored locally in your browser. It is not transmitted to Born Software and is not used to analyse your behaviour.

BornAI stores only the timestamps of completed assessments under “born-project-agent-usage”. They are used to display the limit of five assessments within 24 hours and are not used for marketing or user profiles.

7. Your rights

You have the right at any time to:

  • obtain information about your personal data stored by us
  • request the correction of inaccurate personal data
  • request the deletion of personal data stored by us
  • request restriction of data processing
  • object to the processing of your data
  • request data portability

If you believe that the processing of your personal data infringes data-protection law or otherwise violates your data-protection rights, you may lodge a complaint with the competent supervisory authority.

8. SSL or TLS encryption

For security reasons and to protect confidential content in transit, such as enquiries you send to us, this website uses SSL or TLS encryption. You can recognise an encrypted connection when the browser address changes from “http://” to “https://” and a lock symbol appears in the browser bar.

When SSL or TLS encryption is active, data you transmit to us cannot be read by third parties.