PurePortal

Privacy Policy

This policy covers pureportal.io, including the contact form and AI chat. When you follow an external link, that provider’s privacy notice applies.

Last updated: August 9, 2026

01Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Andreas Ehrhardt, trading as PurePortal

Hohenzollernstraße 17

72172 Sulz am Neckar

Germany

02Hosting, DNS, and delivery

The website, its application services, and database run on servers provided by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. In particular, Hetzner processes connection and operational data as a processor.

We use Cloudflare for DNS, reverse proxy, network, CDN, and security functions. Requests therefore first pass through systems operated by Cloudflare, Inc. and its affiliates. Cloudflare processes data including the IP address, destination, date and time, HTTP and device information, and routing, performance, and security data.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are secure, stable, and efficient delivery and protection against attacks. Processors are subject to the requirements of Article 28 GDPR.

03Connection, security and application logs

When you access the website, Cloudflare, Hetzner, and our systems process the data required to establish the connection. This may include IP address, time, requested path or URL, referrer (if sent), browser and operating system, HTTP headers, response status, and security and routing events. Our application records only shortened IP addresses and avoids request content in routine logs.

Processing is based on Article 6(1)(f) GDPR for error analysis, operation, abuse prevention, and protection against attacks. Routine logs are deleted or overwritten once they are no longer needed for these purposes. Data relating to a specific security incident may be retained until the incident is resolved and legal claims can no longer be brought or defended.

For the daily limits on contact form and chat use, we store a pseudonymous hash of the IP address along with the date and function used. Entries older than seven days are erased during the next cleanup run.

04Cookies and browser storage

Section 25 TDDDG applies when information is stored on or accessed from your device. We use non-essential technologies only with your consent. You can withdraw it at any time through “Cookie settings” in the footer. Withdrawal does not affect the lawfulness of earlier processing.

When relevant security checks are active, Cloudflare may set technically necessary cookies such as __cf_bm or cf_clearance. They protect against bots and abuse and are used only where the relevant security function requires them. Device access is based on Section 25(2)(2) TDDDG and the subsequent processing on Article 6(1)(f) GDPR.

  • pp_cookie_settings: stores your selection and its timestamp for six months; necessary under Section 25(2)(2) TDDDG, with processing based on Article 6(1)(f) GDPR to respect and document your selection.
  • pp_chat_state_v3 in local storage: used only when you enable “Save this chat on this device for 7 days”; contains the chat and session counter. Seven days after the last change, it is treated as expired and removed the next time the chat loads. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

05Audience measurement with Swetrix

After you consent, we use the self-hosted open-source software Swetrix at swetrix.pureportal.io. Requests to this service pass through Cloudflare. Analytics data is not disclosed to an external analytics provider.

The data processed includes the page path, time, referrer without query parameters or fragments, campaign parameters, language, time zone, browser and device information, performance timings, and static event names for interactions with the contact form and AI chat and for their outcomes. Client-side error reports may include the error name, message, source location, and stack trace. The server also receives the IP address and user agent required for the connection. Swetrix uses these with rotating salts to derive pseudonymous identifiers; the raw values are not retained as analytics data.

Swetrix does not set analytics cookies or use browser storage. The legal bases are your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. The Swetrix client is not initialized and no analytics request is sent before consent. Withdrawing consent stops further page-view, performance, event, and error reporting. Raw analytics data is deleted or anonymized once it is no longer required for audience measurement; aggregated reports may be retained for longer.

06Contact form and email

If you contact us, we process your first and last name, email address, message, and company (if provided), together with communication and transmission data. We need the required fields to identify and answer your request; the form cannot be sent without them.

Requests are transmitted by SMTP to our Zoho Mail inbox. The provider is Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. The message is stored in our email inbox.

For pre-contractual inquiries, the legal basis is Article 6(1)(b) GDPR. Article 6(1)(f) GDPR applies to general inquiries and secure form operation; our interests are handling communications and preventing abuse. If commercial or tax law requires us to retain a message, processing is additionally based on Article 6(1)(c) GDPR.

07AI chat

When you use the AI chat, we send your current message and up to ten previous messages from the same chat to the OpenAI API. The provider for users in the EEA is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI processes inputs and outputs for us. Under its API terms, this data is not used for training by default; abuse-monitoring data may generally be retained for up to 30 days unless a different account setting or legal obligation applies.

We do not retain a complete chat history on the server. If the assistant cannot answer a business-related question, a topic limited to 120 characters may be retained. Before storage, we automatically remove recognizable email addresses, phone numbers, and web addresses and compare the topic with existing topics locally. Topics whose last occurrence was more than 31 days ago are erased during the next cleanup run.

Chat history is stored on your device only after you enable this option in the chat. The stored entry expires seven days after its last change and is removed the next time the chat loads. You can disable local storage and delete the history there at any time. If you expressly ask the assistant to arrange contact and provide the required contact details, it can send us an email on your behalf.

The legal basis for project-related requests is Article 6(1)(b) GDPR and otherwise Article 6(1)(f) GDPR. Our legitimate interests are providing the requested assistant, improving its quality, and limiting abuse. Do not submit credentials or special categories of personal data in the chat.

08Recipients and international transfers

Recipients of personal data, where required for the relevant purpose, are Hetzner (hosting), Cloudflare (DNS, network and security), Zoho (email), OpenAI (AI chat), our IT service providers, and public authorities or other bodies where disclosure is legally required. Any other disclosure requires a legal basis.

Processing by Cloudflare and OpenAI in the United States and other countries outside the EEA cannot be ruled out. Zoho may allow limited support access from outside the EEA. Transfers rely on an adequacy decision under Article 45 GDPR, including the EU-US Data Privacy Framework where the recipient is validly certified, or Standard Contractual Clauses under Article 46 GDPR and supplementary safeguards. You can request information or a copy of the relevant safeguards through our contact address.

09Retention and local backups

Where no fixed period is stated above, we keep personal data only for as long as necessary for the relevant purpose. We then erase or anonymize it unless a statutory retention obligation or a legitimate need to establish, exercise, or defend legal claims requires further retention.

Contact and business correspondence is erased after the request is complete once no statutory retention or limitation period remains relevant. Provider logs are additionally subject to the provider's contractual deletion and security periods.

Backups are currently stored only locally on systems or media under our control; no separate cloud backup provider is used. They support restoration and secure availability under the legal basis of the original processing and Articles 6(1)(f) and 32 GDPR. Erased data may remain in backup copies until the next scheduled overwrite; backups are used only for restoration.

10Your rights

Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection (Article 21). Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.

You may withdraw consent at any time with effect for the future. Manage your Swetrix consent through “Cookie settings” in the footer and your local chat storage in the chat itself. For any other request, email [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority.

11Competent supervisory authority

Our competent authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg. You may also contact another supervisory authority competent under Article 77 GDPR.

Heilbronner Straße 35

70191 Stuttgart

Germany

12Voluntary provision, automated decisions, and changes

You can view the website’s informational pages without submitting any content. Using the contact form and chat is voluntary. To provide the function you request, we need the required form information or your chat messages. We do not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR; AI chat responses provide non-binding assistance only.

We update this policy when the law, providers, or processing change. The version published here applies.