Privacy Policy

1. Data Controller

Daniel Weller
DW Digital Ventures
Hauptstraße 18
36341 Lauterbach-Maar, Germany
Email: [email protected]

2. Overview of Data Processing

We only process personal data to the extent necessary to provide a functional website and our content and services. Personal data is regularly processed only with the user's consent or in cases where prior consent cannot be obtained for practical reasons and the processing of data is permitted by law.

3. Hosting

Our website is hosted on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Germany. Hetzner processes access data (IP addresses, access times) on our behalf under a data processing agreement pursuant to Art. 28 GDPR.

For more information, see the Hetzner privacy policy: https://www.hetzner.com/legal/privacy-policy

4. Content Delivery Network (Cloudflare)

We use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as a Content Delivery Network (CDN) and to secure our website. Your requests are routed through Cloudflare servers. Cloudflare may collect access data (including IP address, pages visited). This is based on our legitimate interest in secure and efficient delivery of our website (Art. 6(1)(f) GDPR).

Cloudflare is certified under the EU-U.S. Data Privacy Framework. More information: https://www.cloudflare.com/privacypolicy/

5. Server Log Files

The hosting provider automatically collects and stores information in server log files that your browser transmits to us. These include:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname of the accessing device
  • IP address
  • Time of the server request

This data cannot be attributed to specific individuals. This data is not merged with other data sources. Collection is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of the website. Server log files are automatically deleted after 14 days.

6. Registration and User Account

You can create a user account on our website. We collect the following data:

  • Name
  • Email address
  • Password (stored encrypted)

Data processing is based on your consent (Art. 6(1)(a) GDPR) or for the performance of pre-contractual measures and contract fulfilment (Art. 6(1)(b) GDPR). Data collected during registration is stored as long as you are registered on our website. You can request deletion of your account at any time.

7. Payment Processing (Stripe)

We use Stripe (Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA) for payment processing. When you subscribe to a paid plan, your payment data is processed directly by Stripe. We do not receive full credit card or account details. Processing is based on contract fulfilment (Art. 6(1)(b) GDPR).

Stripe is certified under the EU-U.S. Data Privacy Framework. More information: https://stripe.com/privacy

8. Email Delivery (Resend)

For transactional emails (e.g. registration confirmation, password reset) we use Resend (Resend, Inc., San Francisco, CA, USA). Your email address is transmitted to Resend. Processing is based on contract fulfilment (Art. 6(1)(b) GDPR) or our legitimate interest (Art. 6(1)(f) GDPR).

Resend is certified under the EU-U.S. Data Privacy Framework.

9. Cookies and Session Storage

Our website uses technically necessary cookies for authentication and session management. These cookies are required for the operation of the website and cannot be disabled. They do not contain personal data and are deleted at the end of the browser session or after their configured lifetime.

We do not use tracking cookies, marketing cookies, or analytics services.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technically error-free delivery of the website).

10. Data Processing in the Application

When you use NIS2coPilot, we process the data you enter (e.g. gap analysis responses, generated documents, training results) solely to provide our service. This data is stored on German servers and is not shared with third parties.

For AI-powered analysis and document generation, your inputs are transmitted to OpenAI (OpenAI, Inc., San Francisco, CA, USA). Transmission occurs solely to process your requests. OpenAI does not permanently store data from API requests.

Legal basis: Art. 6(1)(b) GDPR (contract fulfilment).

OpenAI is certified under the EU-U.S. Data Privacy Framework.

11. Applicability Check (result delivery and lead capture)

When you use our free applicability check, we store your classification inputs (sector, company size, special cases and the computed result) and the source of the visit (campaign parameters such as utm_source). These details initially contain no personal data.

If you ask us to email your result, we additionally process your email address to send you the result and next steps, and possibly to contact you about your NIS2 implementation. The legal basis is your request or consent (Art. 6(1)(a) GDPR) and our legitimate interest in reaching potentially affected companies (Art. 6(1)(f) GDPR).

The optional newsletter is only sent with separate consent; you can unsubscribe at any time via the link in every email. You may object to the processing at any time and request deletion of your data.

12. SSL/TLS Encryption

This site uses SSL/TLS encryption for security and to protect the transmission of confidential content. You can recognise an encrypted connection by the browser address bar changing from “http://” to “https://” and the lock icon in your browser bar.

13. Your Rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

To exercise your rights, please contact: [email protected]

14. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.

The supervisory authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163, 65021 Wiesbaden, Germany
https://datenschutz.hessen.de

15. Changes to this Privacy Policy

This privacy policy is currently valid as of February 2026. Due to the ongoing development of our website or new technologies, it may become necessary to update this privacy policy.