Privacy policy
This policy covers the inbrix.ai website. For data our customers store inside the inbrix product, the data processing agreement we conclude with them applies in addition – there we act as processor, not as controller. This is a translation for convenience; in case of doubt the German version prevails.
Last updated: 3 September 2026
Controller
GOLLE Digital Solutions GmbH, Berger Straße 125, 60385 Frankfurt am Main, Germany, represented by Fabian Golle. Email: datenschutz@golle-it.de, phone: +49 69 348 789 10-0. We have not appointed a data protection officer, as the statutory conditions for doing so do not apply to us.
Hosting and server log files
Our website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Every page request is automatically logged with: browser type and version, operating system, referrer URL, host name of the requesting machine, date and time of the request, and the full IP address. This data is kept for 30 days and then deleted. The IP address is deliberately stored unshortened, because in the event of attacks or abuse it is needed for defence, error analysis and possible criminal prosecution. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and uninterrupted operation of the website.
Access logs of the product environment
Separately from this website, the inbrix product environment – including app.inbrix.ai and our customers’ help centre addresses – runs on our own infrastructure in Germany. Since 3 September 2026 its ingress records every request with IP address, time, requested address, HTTP status code, bytes transferred, browser identification and referrer. Headers that may carry credentials are discarded before the entry is written at all. We use these logs solely for secure operation, for detecting and investigating attacks and abuse, and for troubleshooting, and delete them automatically after 180 days; they are not used to analyse usage behaviour, to measure reach, or to train AI models. The legal basis is Art. 6(1)(f) GDPR. Where the logs concern requests to a customer’s help centre, we process them as processor under § 9(2b) of the data processing agreement. The 30-day period stated above applies to this website only, not to the product environment. These access logs are distinct from the sign-in and security logs for your user account, which we keep for 90 days; see “Customer account”.
Contact forms
Using the forms on our website – for example to register interest in an ISO 27001 certification on our security page – you can send us your name and business email address so that we can notify you about the stated matter. The legal basis is Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract), and otherwise our legitimate interest in handling your enquiry (Art. 6(1)(f) GDPR). Providing this is neither required by law nor by contract; without it, however, we cannot notify you. For internal handling we use our own systems as well as communication and automation services. We delete the data once your request has been handled and no contract comes about, at the latest twelve months after the last contact.
Customer account
If you use inbrix as a customer, we process your user account data as controller in our own right: name, business email address, role and organisation membership, sign-in and security logs (time, IP address, magic link used), as well as configuration and billing data. This is necessary to perform the contract, secure the accounts and invoice you (Art. 6(1)(b) and (f) GDPR). This processing is distinct from processing on your behalf: for the content you handle in the system – tickets, messages, your own end customers’ data – you are the controller and we act solely on your instructions under the data processing agreement. Sign-in and security logs for your user account are kept for 90 days. These are distinct from the records of which settings were in force for an AI teammate at what time and who changed them: we keep those on your behalf as processor, they contain no content data, they are available to you in your account at any time, and they are deleted after 24 months (§ 9(2a) of the data processing agreement). Account and billing data are retained after the contract ends within the applicable commercial and tax retention periods.
Appointment booking
For booking demo appointments we embed our own tool MeetBridge (booking.golle-it.de), which likewise runs on our infrastructure in Germany. Opening the booking window processes the technically necessary data; if you book an appointment, we additionally process your name, email address and the requested time. The legal basis is Art. 6(1)(b) or (f) GDPR.
Chat widget
Our own chat widget (app.inbrix.ai) runs on this website, hosted in Germany. When you open the chat, we process the content you enter in order to answer your enquiry. The widget stores two technical values in your browser's local storage (window size and whether the chat is open) so that navigating to another page does not throw you out of an ongoing conversation. This storage is necessary for the service you requested (§ 25(2)(2) TDDDG). Replies in the chat may come from an AI assistant; we indicate this in the chat, and you can ask for a human at any time.
Use of artificial intelligence
For AI features we use service providers named individually in our subprocessor list. Those providers process the transmitted content solely to generate the respective reply. Training models on your data is contractually excluded, as is any persistent storage of the content at the provider. Processing takes place exclusively on infrastructure within the European Union; this content is not transferred to any third country.
Payment processing (Stripe)
For paid inbrix subscriptions we process payments through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. We process your name, email address, billing address, VAT identification number where applicable, and the data of the payment method you choose (credit card or SEPA direct debit). You enter the full card details directly with Stripe; they never reach inbrix. The purpose of the processing is the performance of the contract and the billing of your inbrix subscription, including sending invoices and receipts; the legal basis is Art. 6(1)(b) GDPR. Stripe processes the data in the EU; where data is transferred to Stripe, Inc. in the USA, we rely on the European Commission's Standard Contractual Clauses. We retain invoicing and payment data in accordance with the statutory commercial and tax retention periods (in particular § 147 of the German Fiscal Code).
Fonts
The fonts used on this website are served from our own server. There is no connection to Google Fonts or any other external provider, and no data is transmitted to third parties in the process.
Analytics
To improve our website we measure its usage in pseudonymised form with PostHog (PostHog, Inc.), operated in the EU cloud in Frankfurt. By default this happens entirely without cookies and without storing anything on your device: no data is placed in your browser, and we do not link the session data to any individual. We record pages viewed, approximate origin, device type, clicks, scroll depth and performance metrics, plus aggregated heatmaps to optimise individual pages. No session recording takes place and we do not create person profiles. The legal basis for this measurement is our legitimate interest in a needs-based design of the website (Art. 6(1)(f) GDPR); you can object at any time via the switch at the bottom of this page. Only if you explicitly consent in the cookie notice do we additionally store an identifier in your browser's local storage to recognise you across visits – the legal basis for this is your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future. Data is transmitted to PostHog's EU cloud via a proxy on our own domain; no transfer to a third country takes place.
Recipients and transfers to third countries
A complete and current list of all providers processing personal data on our behalf is available under “Subprocessors”. For each provider it states the purpose, the place of processing and the legal basis for any transfer to a third country. We have concluded agreements pursuant to Art. 28 GDPR with all processors.
Retention
We store personal data only for as long as it is needed for the respective purpose or as statutory retention periods require – in particular the six- and ten-year periods under German commercial and tax law. After that the data is deleted.
Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20 GDPR). You may object under Art. 21 GDPR to processing we base on a legitimate interest. Any consent given can be withdrawn at any time with effect for the future. Please contact datenschutz@golle-it.de.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Hessischer Beauftragter für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, Germany.
No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
Changes to this policy
We adapt this privacy policy when our processing or the legal situation changes. The version published on this page at the time applies.