1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Weisscam GmbH
Osterwaldstr. 53, 80805 Munich, Germany
+49 179 671 6336
datenschutz@weisscam.com
Website: weisscam.com
2. Data Protection Officer
Currently there is no statutory requirement to appoint a data protection officer, therefore we have not appointed one. For any data‑protection‑related questions, please use the contact details above.
3. General Information on Data Processing
3.1 Legal Bases
We process personal data only insofar as this is permitted. The legal bases are in particular:
- Art. 6 para. 1 lit. a GDPR (consent)
- Art. 6 para. 1 lit. b GDPR (contract / pre‑contractual measures)
- Art. 6 para. 1 lit. c GDPR (legal obligation)
- Art. 6 para. 1 lit. f GDPR (legitimate interests)
For accesses to end devices (e.g., cookies, local storage, fingerprinting) we additionally observe § 25 TDDDG.
3.2 Recipients / Processors
Where we employ service providers (e.g., hosting, e‑mail dispatch, analytics), they process personal data on our behalf (processor) or as joint controllers. We conclude, where required, processor agreements in accordance with Art. 28 GDPR.
3.3 Transfers to Third Countries
We do not transfer data to service providers located in third countries as defined by Art. 44 ff. GDPR.
We transfer data within the EU (Art. 13 para. 1 lit. e GDPR) to the following recipients for the indicated purposes and on the following legal bases:
Country: Germany
Recipient: Ionos AG
Purpose: Hosting
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in secure operation).
Retention Period: 7–30 days
Country: Netherlands
Recipient: Nebius B. V.
Purpose: Processing of user inputs for generation of AI results.
Legal Basis: Art. 6 para. 1 lit. b GDPR (use of the platform).
Retention Period: No permanent storage (“Zero retention activated”)
Training of LLMs: No training of LLMs through the processing of user inputs (“User inputs are NOT used to train LLMs enabled”)
OpenSource Models: We exclusively use opensource models like gpt-oss-120b
docs.nebius.com/legal/privacy
4. Data Processing When Visiting the Website
4.1 Server Logfiles
For each access to our website the server (or hosting provider) processes the following data:
- IP address (possibly truncated)
- Date and time of the request
- Requested URL/file
- Referrer URL
- Browser type/version, operating system
- Status codes and transferred data volume
Purpose: operation, stability, IT security, abuse/error analysis.
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in secure operation).
Retention Period: 7–30 days.
4.2 Hosting / Data Centre
Our website/application is hosted by:
IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
Data‑centre location: Berlin.
Legal Basis: Art. 6 para. 1 lit. f GDPR (operation/security) and Art. 28 GDPR (processor agreement).
5. Contact
5.1 Contact via E‑mail
When you contact us by e‑mail, we process the data you provide (e.g., name, e‑mail address, content).
- Purpose: handling of the inquiry.
- Legal Basis: Art. 6 para. 1 lit. b GDPR (pre‑contractual/contractual) or lit. f GDPR (general inquiries).
- Retention Period: 6–24 months; longer retention if required for legal disputes.
5.2 Contact Form
Currently there is no contact form on our websites.
6. Newsletter and Direct Advertising
6.1 Newsletter (Double‑Opt‑In)
We presently do not offer a newsletter with a double‑opt‑in procedure.
6.2 Newsletter Tracking (if used)
No newsletter tracking is used at the moment.
6.3 Existing‑Customer Advertising (Soft‑Opt‑In)
We may use an e‑mail address that you provided in connection with the purchase of a product or service to send you information solely about our own products (security notices, new features, update information, etc.), provided you have not objected. At the time of collection and each use we clearly inform you that you can object at any time without incurring more than the basic postage rates.
Objection: unsubscribe from newsletter / opt‑out.
7. Cookies, Consent and Tracking Technologies
7.1 General
We use only technically necessary cookies to provide the website functions you explicitly request. No non‑essential cookies or tracking technologies are used.
7.2 Consent Management
We do not use a consent‑management tool because we do not employ non‑essential cookies or tracking technologies.
7.3 Cookie / Tracking Overview
Not applicable (see 7.1 and 7.2).
7.4 Web‑Analytics
No web‑analytics tools are currently used.
8. Social Media and Embedded Content
8.1 Social Media Links
Currently we do not link to any social‑media channels.
8.2 Social Plugins / Embeds
No videos, maps or feeds are embedded at present.
9. Customer Account / Login / Contractual Processing
9.1 Customer Account
Purpose: creation and administration of the user account, authentication (login/security), provision of the platform (AI services), communication related to the account, invoicing/payments, support/customer queries, abuse and security prevention, system stability.
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract fulfilment) and Art. 6 para. 1 lit. f GDPR (legitimate interest).
Retention Period: as long as the account exists; thereafter the data are deleted, respecting statutory obligations.
9.2 Payment Processing
For fee‑based services booked via our platform, we process personal data necessary for payment handling.
- Purpose: execution of payments, invoicing, management of bookings and contracts, prevention of payment defaults and abuse.
- Processed Data: depending on the payment method, typically name, e‑mail address, billing address, payment details (e.g., IBAN, credit‑card data, payment status).
- Payment Service Providers: VR Payment GmbH, Platz der Republik, 60325 Frankfurt am Main.
- Legal Basis: Art. 6 para. 1 lit. b GDPR (contract fulfilment).
- Third‑Country Transfers: If a payment provider processes data outside the EU, this occurs only under the conditions of Art. 44 ff. GDPR.
- Retention Period: accounting‑relevant data are retained for the statutory retention periods (generally 6–10 years) according to commercial and tax law.
10. Security
We implement appropriate technical and organisational measures (Art. 32 GDPR) to protect data against loss, misuse and unauthorised access, including access concepts, backups, patch management, permission structures and logging.
11. Retention and Deletion Concept
Personal data are deleted as soon as the purpose has been fulfilled and no legal retention obligations remain.
12. Your Rights
You have – insofar as the legal prerequisites are met – the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR), especially to direct advertising
- Withdrawal of consent (Art. 7 para. 3 GDPR) with future effect
How to exercise: please contact datenschutz@weisscam.com
13. Right to Lodge a Complaint
You may lodge a complaint with the competent supervisory authority:
Bavarian Data Protection Authority (BayLDA)
Promenade 18
91522 Ansbach, Germany
Website: www.lda.bayern.de
14. Changes to This Privacy Policy
We will update this privacy policy whenever the legal situation or data processing activities change.
