Skip to content

Legal information

Privacy Policy

Information on the processing of personal data pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR).

1. Controller

Neuraway AI GmbH
Bismarckstraße 10-12
10625 Berlin
Germany
team@neuraway.de

Further details are set out in our legal notice.

2. Data protection officer

We are not required to appoint a data protection officer (Art. 37 GDPR, Section 38 BDSG): fewer than twenty people work with personal data at Neuraway AI, and none of our processing is subject to a data protection impact assessment. The founders are responsible for data protection themselves. For any question or request concerning your data, write to team@neuraway.de.

3. Server log files

This website runs on a server located in Germany, operated for us by a hosting provider with whom we have concluded a data processing agreement under Art. 28 GDPR. Each time you open a page, the web server automatically records the following in a log file: the IP address of your device, the date and time of the request, the address of the page requested, the HTTP status and the amount of data returned, the page you came from (referrer), and the browser and operating system you use (user agent). This data is not merged with other sources and is not used to identify you.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the site: the log is what lets us detect attacks, abuse and technical faults. Log files are deleted automatically after seven days. Entries are kept longer only where they are needed as evidence of a specific security incident, and then until that incident has been resolved.

4. Cookies and local storage

We distinguish between storage that is strictly necessary and storage that requires your consent. Nothing in the second group is loaded until you have actively agreed to it.

Strictly necessary (no consent required)

Two values in your browser’s local storage: neuraway-theme records whether you chose light or dark mode, and neuraway-consent records your decision on the cookie banner together with the date, so that we do not ask you again and can demonstrate what you agreed to (Art. 7(1) GDPR).

Both are written only in response to your own action, contain no personal data, and never leave your device. Under Section 25(2) TDDDG they require no consent, because without them the service you asked for cannot be provided.

Consent based

The analytics and marketing tools described in section 5 set cookies of their own. They are only loaded once you agree, and you can withdraw that agreement at any time via “Cookie settings” in the footer of every page. Withdrawal takes effect immediately, but does not undo processing that already happened.

Google Analytics sets the cookies _ga and _ga_*, which distinguish returning browsers and are stored for up to two years. The LinkedIn Insight Tag sets li_sugr, bcookie, lidc and UserMatchHistory, stored for between one day and one year. The exact set may change with the providers’ software; the current lists are published by Google and LinkedIn in their own cookie documentation. Rejecting or withdrawing consent means none of them are set, and you can delete any that already exist in your browser settings.

5. Analytics and marketing

If, and only if, you consent, we load the following third-party services. The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Refusing has no effect on your use of this website.

Google Analytics 4

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It records which pages you visit, how long you stay, roughly where you are, and how you reached us. We use it to understand which parts of this site are useful. IP addresses are shortened before storage and are not stored by Google Analytics 4. Event data linked to a browser is kept for 14 months and then deleted automatically; aggregated reports contain no personal data. Google acts as our processor under the Google Ads Data Processing Terms; where Google uses data for its own purposes, it is independently responsible under its privacy policy at policies.google.com/privacy.

LinkedIn Insight Tag

Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. It tells us which campaigns bring visitors here and which industries they come from, and it allows us to show our content to people who have already visited this site. The tag transmits the page address, referrer, IP address, device and browser properties, a timestamp and, if you are logged in to LinkedIn, your LinkedIn cookie identifiers. We only ever see aggregated reports; we cannot identify individual visitors. LinkedIn removes direct identifiers within seven days and deletes the pseudonymised data within 180 days. LinkedIn is independently responsible for the processing it carries out under its own privacy policy at linkedin.com/legal/privacy-policy, and LinkedIn members can object to the use of their data for advertising in their LinkedIn account settings.

6. What we do not do

No content is loaded from third-party servers unless you have consented. Our fonts are delivered from our own server, every icon is bundled with the site, and even the booking calendar is ours rather than an embedded widget, so opening a page without consenting contacts nobody but our hosting provider. There is no tag manager, no advertising network beyond the tools named above, and no profiling of you as an individual.

7. Booking a call

Our booking calendar runs on Microsoft Bookings, part of the Microsoft 365 subscription we already use for our own email and calendars. Microsoft Ireland Operations Limited acts as our processor under Art. 28 GDPR.

Nothing is embedded from Microsoft. Your browser only ever talks to this website; we query the free slots and create the appointment from our own server. Microsoft therefore never sees your IP address or your browser, and the calendar sets no cookies and needs no consent.

When you book, we pass the name, email address and anything else you chose to add to Microsoft Bookings, so that the appointment can be created and the invitation sent to you. The legal basis is Art. 6(1)(b) GDPR: the booking is the service you asked for. Only a name and an email address are required; a company name, phone number and description are optional and not a condition of booking (Art. 13(2)(e) GDPR).

Microsoft processes this data for us under the Microsoft Products and Services Data Protection Addendum, which is part of our Microsoft 365 subscription and covers Bookings. The data is stored in Microsoft’s EU data centres. We delete booking records twelve months after the appointment unless a business relationship has followed from it, in which case the data becomes part of that relationship and is kept for as long as it requires.

8. Contacting us

If you write to us, whether by email or through our contact form, we process the data in your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract, and otherwise Art. 6(1)(f) GDPR, our legitimate interest in responding to enquiries.

Only your message and the means of replying to it are required. Anything else you choose to tell us is voluntary and not a condition of getting an answer (Art. 13(2)(e) GDPR).

Messages sent through the contact form are delivered to our mailbox by an email relay acting as our processor under Art. 28 GDPR; the form itself stores nothing on the web server. We delete enquiries twelve months after the matter has been dealt with. Correspondence that is part of a contract or that we are required to keep under commercial or tax law (Sections 257 HGB, 147 AO) is kept for the statutory period of six or ten years and then deleted.

9. Transfers outside the EU

If you do not consent to analytics or marketing, no data leaves the European Union: the site is hosted in Germany and contacts no third-party server.

If you do consent, Google and LinkedIn may transfer data to the United States, where authorities have access rights that have no equivalent under EU law and against which you may have no effective legal remedy. This is a consequence of consenting, and withdrawing consent stops further transfers.

Both transfers rest on an adequacy decision: Google LLC and LinkedIn Corporation are certified under the EU-US Data Privacy Framework (Art. 45 GDPR), which the European Commission has recognised as providing adequate protection. In addition, both providers have concluded the European Commission’s standard contractual clauses with their European entities (Art. 46(2)(c) GDPR), which apply should the Framework cease to be in force. The current certifications can be checked at dataprivacyframework.gov.

10. Security

This website is served exclusively over an encrypted TLS connection, so what you send and receive cannot be read in transit. We apply technical and organizational measures appropriate to the risk, as required by Art. 32 GDPR.

In particular: the site is served only over HTTPS with current TLS versions; the contact form and the booking flow are protected against automated abuse by rate limiting and anti-bot tokens; credentials for the mail relay and the Microsoft interface exist only on the server and never in the code delivered to your browser; access to the server and to our Microsoft 365 tenant is limited to the founders and secured with multi-factor authentication; and the software the site is built on is kept up to date. No payment data is processed on this website.

11. External links

Our team page links to profiles on LinkedIn. These links are only followed when you click them. Once you do, LinkedIn receives your data under its own privacy policy, over which we have no influence.

12. Your rights

You have the right to obtain information about the personal data we hold about you (Art. 15 GDPR), to have it corrected (Art. 16 GDPR) or erased (Art. 17 GDPR), to restrict its processing (Art. 18 GDPR), to data portability (Art. 20 GDPR), and to object to processing based on legitimate interest (Art. 21 GDPR). To exercise any of these, write to the address above.

Where we process data on the basis of your consent, you may withdraw it at any time with effect for the future (Art. 7(3) GDPR), and it must be as easy to withdraw as it was to give. That is what “Cookie settings” in the footer is for. Withdrawal does not affect the lawfulness of processing carried out beforehand.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59-61, 10555 Berlin, Germany, telephone +49 30 13889-0, email mailbox@datenschutz-berlin.de. You may also complain to the authority of the EU member state in which you live or work.

13. Changes to this policy

We update this policy whenever changes to the website, to the tools we use or to the law make it necessary. The version published here always applies. This version is dated 25 August 2026.