Book a consultation
Privacy
Privacy policy
This privacy policy explains, in accordance with Articles 12 and 13 of the General Data Protection Regulation (GDPR), which personal data are processed when you visit this website or contact us.
1. Controller
MEZGER AI Solutions GmbH
Sven-Wingquist-Str. 2
97424 Schweinfurt
Germany
Phone: +49 (0)9721 655 - 0
Email: info@mezger-ai.de
2. Website delivery and server logs
To deliver the website to your device, the web server processes technically necessary connection data. These may include your IP address, the date and time of access, the page or file requested, the amount of data transferred, the referrer URL (if transmitted by your browser), browser type and version, operating system and HTTP status code.
These data are processed to provide the website securely and reliably, prevent attacks and analyse errors. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and functional operation of our website.
Routine storage of access logs on the web server is disabled for this website. Technical errors may be recorded in the server's central error log. These logs are rotated daily and deleted after no more than 14 days, unless a security-related incident exceptionally requires longer retention for investigation or legal action.
3. Hosting
The website and internal CRM system run on servers provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, at the Nuremberg server location. Hetzner processes the data necessary for hosting on our behalf. This hosting does not involve any planned transfer to a third country.
4. Contact form
When you use the contact form, we process the following information:
- first name, last name and email address;
- company and phone number, if provided voluntarily;
- selected area of interest and the contents of your message, if provided voluntarily;
- the time and technical source of the enquiry; and
- the recorded confirmation that you have acknowledged this privacy policy.
The information marked with an asterisk is required to identify and answer your enquiry. Company, phone number, area of interest and message are optional. The checkbox records only your acknowledgement of this privacy policy; it is not consent under data protection law.
We process this information to handle your enquiry, communicate with you, prepare a consultation and, if requested, initiate a quotation. If the enquiry concerns a contract or pre-contractual steps, the legal basis is Article 6(1)(b) GDPR. Otherwise, processing is based on our legitimate interest in handling business enquiries under Article 6(1)(f) GDPR.
5. Transfer to the CRM and lead mailbox
After submission, the website attempts to transfer the information via encrypted HTTPS to our CRM system at crm.mezger-ai.de and additionally by encrypted email to the internal lead mailbox at leads@mezger-ai.de . Both channels support reliable processing; if one temporarily fails, the other remains available for delivery.
The web application does not additionally store form contents in its own local database and does not write message contents or other form information to server logs. In the event of technical delivery errors, only the affected delivery channel and, where available, a technical status code are logged. Access to the CRM and lead mailbox is restricted to people who need to handle the enquiry or administer the systems.
The selected area of interest is used for internal assignment and to prepare relevant service components. No decision based solely on automated processing is made that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).
6. Contact by email or phone
If you contact us by email or phone, we process your contact details and the contents and context of your communication to the extent necessary to handle it. The same legal bases apply as for the contact form.
We use Google Workspace for email communication. The provider in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes email and account data as a processor. Access by Google LLC and other sub-processors outside the European Economic Area cannot be entirely ruled out. Where required, transfers rely on an adequacy decision under Article 45 GDPR or standard contractual clauses under Article 46(2)(c) GDPR.
7. Recipients
Recipients of personal data may include the responsible employees and managing directors, Hetzner as hosting provider, Google as email provider and carefully selected IT service providers where needed for maintenance or support. Data are disclosed to other recipients only where necessary to handle your enquiry or perform a contract, where you have consented or where there is a legal obligation.
8. Retention periods
Enquiries that do not result in a contract are generally deleted six months after processing is completed. Where data are necessary for the establishment, exercise or defence of legal claims, we may retain them until the applicable statutory limitation periods expire. The standard limitation period is three years and generally begins at the end of the relevant calendar year.
If a contract is concluded or the correspondence forms part of documents subject to tax or commercial retention requirements, we retain the relevant data for the applicable statutory period. In particular, these periods are six years for commercial and business correspondence, eight years for accounting vouchers and ten years for commercial books, inventories and annual financial statements. The legal basis is Article 6(1)(c) GDPR in conjunction with the applicable retention provisions.
9. Cookies, analytics and external content
This website currently uses no cookies and no analytics, marketing or profiling services. Fonts and images are served locally from our own server, so visiting a page does not establish a connection to Google Fonts. There is currently no access to information on your device requiring consent under section 25 TDDDG.
Links to external websites, such as LinkedIn, establish a connection to the respective provider only when you actively open the link. The external provider's privacy policy then applies.
10. Encryption in transit
This website uses TLS encryption to protect content transmitted between your browser and our server against interception in transit. You can recognise an encrypted connection by 'https://' in your browser's address bar.
11. Your data protection rights
Subject to the legal requirements, you have the rights of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR) and data portability (Article 20 GDPR).
You may object at any time to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation (Article 21 GDPR). To exercise your rights, send a message to info@mezger-ai.de.
12. Right to lodge a complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. For private companies based in Bavaria, the authority generally responsible is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
13. Use of artificial intelligence on this website
This website currently includes no AI system that interacts directly with visitors or generates content for them. In particular, neither a chatbot nor a Voice Agent is currently part of the website. The transparency obligations for direct interaction with an AI system under Article 50 of Regulation (EU) 2024/1689 (EU AI Act) are therefore not triggered by the current website. Before activating such a feature, we will visibly provide the required information and adapt this privacy policy to the specific data processing involved.
14. Updates to this privacy policy
We update this privacy policy when features, service providers or legal requirements change. The version published on this page is the applicable version.
Last updated: 12 September 2026