At a glance
This privacy policy explains which personal data dcyphr.® GmbH ("we") processes when you visit our websites dcyphr.ai, dcyphr.io and aicon26.com, contact us, subscribe to our newsletter, attend one of our events (AICon, dcyphr.events) or work with us. It also applies, in addition, to the dcyphr.® and AICon presences on social networks.
The essentials
- Without your consent this website sets no tracking or marketing cookies. We load analytics and marketing services (Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn, TikTok, X) only if you agree via the consent banner.
- Fonts are served from our own server – nothing is requested from Google Fonts or other font services.
- Videos are not embedded but only linked. You leave our website only when you click the link (e.g. to YouTube).
- Newsletter subscriptions use double opt-in; every issue contains an unsubscribe link.
- Photos and videos are taken at our events. How to object is explained under "Photo and video recordings".
Controller
dcyphr.® GmbH
Hans-Thoma-Straße 40, 69121 Heidelberg, Germany
represented by the Managing Director Matthias Alexander Walenda
Phone: +49 (0) 6221 40 535 80 · E-mail: hello@dcyphr.io
Our contact person for data protection is our Managing Director Matthias Alexander Walenda. For privacy requests please contact hello@dcyphr.io. No data protection officer has been appointed, as the statutory conditions requiring one (Art. 37 GDPR, § 38 BDSG) are currently not met.
Principles and legal bases
We process personal data only where a legal basis permits it. The relevant laws are the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and – for access to terminal equipment such as cookies – the German Telecommunications Digital Services Data Protection Act (TDDDG). The legal bases in detail:
- Art. 6 (1) (a) GDPR – consent (e.g. newsletter, optional form fields). You may withdraw consent at any time with effect for the future.
- Art. 6 (1) (b) GDPR – contract or pre-contractual steps (e.g. ticket purchase, consulting engagement, exhibitor or sponsoring contract, enquiries).
- Art. 6 (1) (c) GDPR – legal obligation (e.g. commercial and tax retention duties).
- Art. 6 (1) (f) GDPR – legitimate interest (e.g. secure website operation, documentation of our events, direct marketing to existing customers, enforcing claims). You may object to processing on this basis at any time.
- § 25 TDDDG – storing or accessing information on your device (cookies, local storage). Without consent only where strictly necessary (§ 25 (2) TDDDG).
- § 26 BDSG – job applications and employment.
Website: hosting, server logs, fonts
Hosting
Our website dcyphr.ai is hosted by STRATO GmbH (Otto-Ostrowski-Straße 7, 10249 Berlin, Germany) in data centres in Germany. dcyphr.io is delivered via Webflow, Inc. (San Francisco, USA; certified under the EU-US Data Privacy Framework). Data processing agreements pursuant to Art. 28 GDPR are in place with both providers. The legal basis is our legitimate interest in the secure and efficient provision of our online offering (Art. 6 (1) (f) GDPR).
Server logs
Each time the site is accessed, the server automatically processes the following data transmitted by your browser: IP address (truncated), date and time, page or file requested, data volume, status code, referrer URL, browser type and version, operating system. This data is required to deliver the site, analyse errors and defend against attacks (Art. 6 (1) (f) GDPR). It is not combined with other data sources and is deleted after 14 days at the latest unless a security-related analysis is required.
Fonts
We use the Roboto typeface. The font files are hosted on our own server; no connection to Google servers is established when the page loads.
Analytics and marketing services
We load analytics and marketing services only with your consent; which services these are is explained in the section "Web analytics, tag manager and marketing pixels".
Cookies and consent
Without your consent this website sets no cookies. When you switch the language (DE/EN/FR) we remember your choice solely in your browser's local storage; this value never leaves your device and is strictly necessary for the "remember language" function (§ 25 (2) no. 2 TDDDG). You can delete it at any time via your browser settings.
Where links on our website take you to ticket shops or partner sites, the privacy notices and cookie settings of the respective provider apply there.
We use analytics and marketing services (see next section) only if you have consented via a consent banner. There you can change or withdraw your selection at any time; the banner can be reopened via the "Cookie settings" link in the footer of the respective website.
Web analytics, tag manager and marketing pixels
To measure reach and the success of our campaigns we use the following services on our websites – only with your consent given via the consent banner (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). Without consent these services are not loaded and no cookies are set. You can withdraw your consent at any time with effect for the future.
- Google Tag Manager (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland): controls the loading of the tags below. The tag manager itself sets no cookies and only fires the services you have consented to (Google Consent Mode v2).
- Google Analytics 4 (Google Ireland Ltd.): measurement of page views, time on site, traffic source and device based on truncated IP addresses; usage data is deleted after 14 months. Data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-US Data Privacy Framework. We link Google Analytics with Google Ads to measure conversions.
- Meta Pixel (Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland): conversion measurement for ads on Facebook and Instagram and creation of audiences (Custom Audiences). For the collection and transfer we are joint controllers with Meta (Art. 26 GDPR); Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework.
- LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland): conversion measurement and retargeting for LinkedIn campaigns; LinkedIn Corporation (USA) is certified under the EU-US Data Privacy Framework.
- TikTok Pixel (TikTok Technology Ltd., Dublin, Ireland): conversion measurement for ads on TikTok; transfers to third countries are based on EU standard contractual clauses.
- X Pixel (Twitter International Unlimited Company, Dublin, Ireland): conversion measurement for ads on X; transfers to the USA are based on EU standard contractual clauses.
The providers may link the data collected with your respective user account and use it for their own purposes; details can be found in the privacy notices of Google, Meta, LinkedIn, TikTok and X. In addition to withdrawing consent via the banner, you can disable personalised advertising in the settings of your respective account.
Contact by e-mail, phone or appointment booking
If you contact us by e-mail, phone or via an appointment link, we process the data you provide (name, contact details, content of the enquiry, company) to handle your request and follow-up questions. The legal basis is Art. 6 (1) (b) GDPR where the enquiry aims at a contract, otherwise Art. 6 (1) (f) GDPR (our interest in answering enquiries). For online appointment booking (“Book an intro call”) we use Microsoft Bookings; when you open the booking link you leave our website and Microsoft processes the data you enter (name, e-mail, preferred time, topic) on our behalf. We use Microsoft 365 (Microsoft Ireland Operations Ltd., Dublin) for e-mail, calendar and appointment booking; data is processed in EU data centres under a data processing agreement including EU standard contractual clauses. Enquiries are deleted once resolved and no retention duties apply, at the latest after three years.
Newsletter
For our newsletter (e.g. "Frontline" – applied AI, AICon event news) we need your e-mail address; further details are optional. Subscription uses double opt-in: you receive a confirmation e-mail with which you actively confirm your subscription. We log subscription, confirmation and IP address to be able to prove consent. The legal basis is your consent (Art. 6 (1) (a) GDPR, § 7 (2) no. 3 UWG). You can unsubscribe at any time via the link at the end of every issue or by e-mail to hello@dcyphr.io.
We use Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) for dispatch. Brevo processes the data on our behalf within the EU. We measure whether newsletters are opened and which links are clicked in order to improve content; you can object to this measurement by unsubscribing.
We occasionally send existing customers information on similar services of our own on the basis of § 7 (3) UWG (Art. 6 (1) (f) GDPR); you may object at any time free of charge.
Events: AICon and dcyphr.events
Ticket purchase and registration
For ticket sales and attendee registration we use the ticketing provider vivenu (vivenu GmbH, Völklinger Straße 33, 40221 Düsseldorf, Germany), which processes the data on our behalf in data centres within the EU (data processing agreement pursuant to Art. 28 GDPR). We collect name, e-mail address, company and position where applicable, ticket category, payment information (the payment itself is handled by the payment provider; we do not receive full card details) and invoicing data. The legal bases are performance of the contract (Art. 6 (1) (b) GDPR) and compliance with tax law (Art. 6 (1) (c) GDPR).
Attendee directory, badges and networking
Your badge shows your name and company. For networking formats (e.g. speed dating, matchmaking app) we process your details only if you sign up for them (Art. 6 (1) (a) or (b) GDPR). We do not pass attendee lists to third parties; sponsors and exhibitors receive contact details only if you expressly agree at their stand (e.g. via badge scan).
Speakers, exhibitors, sponsors, partners
From speakers and from contact persons at exhibitors, sponsors and partners we process name, role, company, contact details, short biography, photo and talk content in order to create, publish and promote the programme (Art. 6 (1) (b) GDPR). Programme publication on the web, in apps and in print is part of the agreed service.
Security and admission
Tickets are scanned for access control. In the event of security incidents we may pass data to the venue, the security service or the authorities (Art. 6 (1) (c) and (f) GDPR).
Photo and video recordings at events
Photo, video and audio recordings are made at AICon events and dcyphr.events (stage programme, exhibition, networking, atmosphere). We use them for documentation and reporting, for our media library, to promote future events and on social media and in press releases. The legal basis is our legitimate interest in public relations (Art. 6 (1) (f) GDPR) in conjunction with §§ 22, 23 of the German Art Copyright Act (KUG); we point out recordings at the entrance, on tickets and on signage.
Your objection: if you do not wish to be recognisably depicted, please say so at the entrance (you will receive a marker) or approach the photo team. You can object to a publication at any time afterwards at hello@dcyphr.io; we will remove the recording concerned as far as technically and legally possible. Talks are recorded and published only with the speakers' consent.
Clients, partners and suppliers
In the context of consulting, development, sponsoring and exhibitor contracts we process contract, contact and billing data as well as project-related content (Art. 6 (1) (b) and (c) GDPR). To manage contacts and projects we use the CRM and project management system monday.com (monday.com Ltd., Tel Aviv, Israel – the European Commission has recognised Israel as providing an adequate level of protection; data can be stored in EU data centres on request) as well as Microsoft 365. Data is stored for the duration of the business relationship and thereafter in accordance with statutory retention periods.
Job applications
We process application documents to decide on establishing an employment relationship (§ 26 BDSG, Art. 6 (1) (b) GDPR). After the process is completed we delete the documents after six months at the latest, unless you have consented to inclusion in our talent pool (then up to two years) or we are entitled to retain them longer.
Social media and video platforms
We maintain presences on LinkedIn (LinkedIn Ireland Unlimited Company, Dublin), YouTube and Instagram (Google Ireland Ltd. and Meta Platforms Ireland Ltd., Dublin), X (Twitter International Unlimited Company, Dublin) and TikTok (TikTok Technology Ltd., Dublin). When you use these services, the respective provider processes your data under its own responsibility; for page statistics ("insights") we are joint controllers with the provider (Art. 26 GDPR). No social media plugins are embedded on this website; videos are only linked. When you click a link to YouTube or LinkedIn, the privacy policy of the respective provider applies.
Use of AI tools
As an AI-first company we use AI-supported tools to assist with writing, translation, research, analysis and organisation. We enter personal data into such systems only to the extent required for the respective purpose and only with providers with whom a data processing agreement is in place and which do not use inputs to train their models. We make no automated decisions with legal effect within the meaning of Art. 22 GDPR. Where AI systems interact with you (e.g. voice or chat assistants), we make this transparent in accordance with Art. 50 of the EU AI Act (Regulation (EU) 2024/1689).
Specifically, we work with Claude (Anthropic PBC, San Francisco, USA; EU contracting entity: Anthropic Ireland, Limited, Dublin) and ChatGPT (OpenAI Ireland Ltd., Dublin, on behalf of OpenAI, L.L.C., San Francisco, USA). We use business or team plans under which the providers are contractually barred from using inputs to train their models and data processing agreements pursuant to Art. 28 GDPR are in place. Transfers to the USA are based on the EU-US Data Privacy Framework or EU standard contractual clauses. We enter personal data only to the extent required for the purpose and pseudonymise it wherever possible.
Transfers to third countries
Where we use service providers outside the EU/EEA, we ensure an adequate level of data protection: through an adequacy decision of the European Commission (e.g. the EU-US Data Privacy Framework for certified US providers, the adequacy decision for Israel), through EU standard contractual clauses (Art. 46 (2) (c) GDPR) with supplementary measures or – in individual cases – through your explicit consent (Art. 49 (1) (a) GDPR). A copy of the respective safeguards is available on request.
Retention periods
| Data | Retention |
|---|---|
| Server logs | max. 14 days |
| Enquiries by e-mail/phone | until resolved, max. 3 years |
| Newsletter data | until withdrawal; proof of consent 3 years after unsubscribing |
| Ticket, contract and invoicing data | 6 or 10 years (§ 257 HGB, § 147 AO) |
| Event photos/videos | until objection or as long as the documentation serves its purpose |
| Job applications | 6 months after completion; talent pool max. 2 years |
Your rights
With regard to personal data concerning you, you have the following rights against us:
- access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20);
- objection (Art. 21 GDPR) to processing based on legitimate interests – to direct marketing at any time without giving reasons;
- withdrawal of consent with effect for the future (Art. 7 (3) GDPR);
- complaint to a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany, baden-wuerttemberg.datenschutz.de.
An e-mail to hello@dcyphr.io is sufficient to exercise your rights.
Data security
Our website is delivered over TLS encryption (HTTPS). We apply technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access, and keep them in line with the state of the art.
Changes to this privacy policy
We review this policy at least once a year and update it when our processing or the legal situation changes. The version published on this page applies.
Last updated: September 2026 · In case of doubt the German version prevails.
