SHELL-AFFECT
HomeOnline PresenceCyber SecurityPricingContactAbout us
EN/DE
Start Project
Menu
01Home02Online Presence03Cyber Security04Pricing05Contact06About us
EN / DE
Start Project
Skip to content
This legal document is provided in German as it applies under German law.

Version: 1.0

Effective from: 30/07/2026, 21:52

Privacy Policy

1. Controller

The controller for data processing on shell-affect.com is SHELL-AFFECT. Contact details are in the Imprint. Email: support@shell-affect.com.

2. Overview of processing

We process personal data only as needed to operate the website, handle enquiries, deliver projects, apply security measures, process payments or meet legal duties.

Data categories

  • Master and contact data (name, email, company, billing address)
  • Address data from project requests
  • Content data (forms, questionnaire, messages, uploads)
  • Optional: requests and technical logs linked to the questionnaire AI assistant (see section 7a)
  • Contract, project, invoice and payment status data
  • Optional: VAT ID and VIES verification results (see section 7b)
  • Optional: Web Push subscription data (endpoint, keys; see section 7c)
  • Usage, device, log and security data (IP, timestamps, browser, security events)
  • Consent, authentication and session data

Data subjects

  • Website visitors
  • Prospects and communication partners
  • Customers, clients and invited project participants
  • Administrators with access to internal areas

Purposes

  • Operate, secure and improve the website
  • Handle contact, project and security requests
  • Customer account, authentication, project communication and file exchange
  • Optional AI-assisted questionnaire helper (filling support, audit, abuse prevention)
  • B2B identity and VAT verification (VAT ID / VIES)
  • Optional browser push notifications for account and project events
  • Invoicing, payments and statutory retention
  • Abuse prevention, error analysis, audit and security evidence
  • Optional consent-based reach measurement (Cloudflare Web Analytics)

3. Legal bases

  • Art. 6(1)(a) GDPR – consent (e.g. optional analytics)
  • Art. 6(1)(b) GDPR – contract and pre-contractual steps
  • Art. 6(1)(c) GDPR – legal obligations (e.g. retention)
  • Art. 6(1)(f) GDPR – legitimate interests (security, abuse prevention, efficient communication)
  • Sec. 25(2) no. 2 TDDDG – technically necessary storage/access on end devices

4. Hosting, Cloudflare and storage locations

We use Cloudflare, Inc. (USA) as technical processor for hosting, edge delivery, database, object storage, caching, logs, email sending and security functions.

For configured preview and production resources, Cloudflare D1 (database) and R2 (object storage) jurisdiction is set to EU. Master, project and file data stored there is therefore kept in the EU. KV is used for short-lived technical state (rate limits, cache, circuit breakers).

As a global edge and network provider, Cloudflare may also process personal data outside the EEA in connection with edge delivery, DNS, caching, logs, email and security functions. Where that occurs, processing is based on Cloudflare’s DPA, appropriate safeguards under Art. 46 GDPR (in particular EU Standard Contractual Clauses) and, where applicable, the EU-US Data Privacy Framework.

Legal bases: Art. 6(1)(b)/(f) GDPR, Art. 28 GDPR, Art. 44 et seq. GDPR.

5. Cookies and storage technologies

Cookies, local storage and similar technologies are used only when technically necessary or after consent. Non-essential access is activated only after consent.

Technically necessary

  • Session and authentication data
  • Locale and cookie-consent storage
  • Local UI state (e.g. questionnaire drafts)
  • Abuse and security checks (rate limits, Turnstile)

Legal basis: Art. 6(1)(b)/(f) GDPR and Sec. 25(2) no. 2 TDDDG.

Optional analytics

Where configured and you have consented to the Statistics category, we use Cloudflare Web Analytics (Cloudflare, Inc.). It provides privacy-preserving reach measurement for public pages. We do not run storage-heavy first-party marketing pageview collection in our own database.

Legal basis: Art. 6(1)(a) GDPR and Sec. 25(1) TDDDG. Withdrawal is possible at any time via cookie settings; without statistics consent the analytics script is not loaded.

6. Contact form and project requests

We process the data you enter (name, email, company, message, optional address) plus technical abuse-prevention data (e.g. hashed IP).

Legal basis: Art. 6(1)(b) and (f) GDPR.

7. Customer account and dashboard

For login (magic link), project communication, uploads, invoices and profile we store the necessary account and content data.

Security-relevant inputs may be scanned for attack patterns and security events (including IP, category, trigger) may be logged. Severe or repeated violations may lead to account lock.

Legal basis: Art. 6(1)(b) and (f) GDPR.

7a. Questionnaire assistant (AI)

In the customer dashboard you may optionally use an AI-assisted helper for the project questionnaire (chat and suggested form values). Use is voluntary; the questionnaire can be completed fully without the assistant.

What we process locally (at SHELL-AFFECT)

  • Your chat or fill requests and related technical metadata (e.g. time, status, model id, section/step)
  • where applicable a short response preview and abuse/security indicators
  • Account data (email, name, user id, IP) in our systems and AI audit log for security and support — these account identifiers are not sent to the AI inference service

Legal bases: Art. 6(1)(b) GDPR (pre-contractual/contractual questionnaire support) and Art. 6(1)(f) GDPR (security, abuse prevention, quality, audit).

There is no automated decision-making with legal effect under Art. 22 GDPR. AI suggestions are applied to the questionnaire only after your explicit confirmation.

What is sent to Cloudflare Workers AI

To generate answers we use Cloudflare Workers AI (Cloudflare, Inc.) as a technical provider for model inference.

Minimising personal data toward the AI service: We do not send account identifiers to the inference endpoint (no email, name, user id, or IP). Typical natural-person questionnaire fields (e.g. stakeholder/contact person) are removed before transmission. In free text and chat messages we redact recognisable patterns such as email addresses, phone numbers and similar contact data (placeholders). Please do not enter personal data of natural persons into the assistant (private names, private emails, phone numbers, home addresses, ID numbers).

Company-related, project-related and technical information (e.g. desired features, design preferences, public company URLs) may remain in the inference context where needed after filtering.

No training on your chat / questionnaire content

  • SHELL-AFFECT does not use your chat messages, fill requests or questionnaire context to train or improve our own AI models.
  • Cloudflare Workers AI: Based on Cloudflare’s published Workers AI data-usage documentation known to us, Cloudflare does not use your inputs/outputs (Customer Content) to train models available on Workers AI or to improve Cloudflare or third-party services, unless you give Cloudflare separate explicit consent. The current Cloudflare terms and privacy notices remain decisive.

Retention (AI audit)

AI request logs are typically retained similarly to security/access logs (usually up to 12 months), longer only where required for ongoing security investigations, legal enforcement or statutory retention; then deletion or anonymisation.

Recipients / third countries

Cloudflare may process inference and related technical data (as part of the Workers AI service) also outside the EEA. Where a third-country transfer occurs, appropriate safeguards under Art. 46 GDPR apply (in particular EU Standard Contractual Clauses) and, where applicable, the EU-US Data Privacy Framework, together with Cloudflare’s data processing terms. Legal bases: Art. 6(1)(b)/(f), Art. 28, Art. 44 et seq. GDPR.

7b. VAT ID and VIES verification

During B2B registration, billing-data maintenance and project requests you may provide an EU VAT identification number. To check validity and — where returned by the interface — the registered name, we submit the VAT ID (with country code) to the European Commission’s VAT Information Exchange System (VIES).

  • Recipient: European Commission, Taxation and Customs Union — VIES (public verification service)
  • Data we store: VAT ID, verification result (valid/invalid), any returned name, verification timestamp, link to the user profile
  • Purposes: establishing and documenting entrepreneurial status, correct invoicing, abuse and identity checks in a B2B context
  • Legal bases: Art. 6(1)(b) GDPR (pre-contractual/contractual steps) and Art. 6(1)(c) GDPR (tax/VAT duties where applicable)
  • Retention: with account data and tax-relevant records under section 10

Without a valid VAT ID or VIES verification, alternative B2B evidence (e.g. small-business statements) may be used during onboarding.

7c. Web Push notifications

In the customer dashboard you may optionally enable browser push notifications (e.g. for project or account messages). After your consent and browser permission we store a push subscription:

  • Data: push endpoint URL, cryptographic keys (p256dh, auth), link to your user account, timestamp
  • Purpose: delivering optional notifications to your device
  • Legal bases: Art. 6(1)(a) GDPR and Sec. 25(1) TDDDG (end-device access / push subscription via the browser)
  • Technology: delivery via the browser/OS push infrastructure (VAPID); subscription data stored in our EU-jurisdiction D1 database
  • Retention: until withdrawal of consent, disablement in notification settings, revocation of browser permission, deletion of the subscription or the account
  • Withdrawal: at any time in dashboard notification settings and/or browser settings; related subscriptions are then deleted or no longer used

Without consent and browser permission no push subscriptions are stored and no push messages are sent.

8. Payments (Stripe)

Payments are processed via Stripe under Stripe’s terms/privacy notice.

9. Email

Transactional emails (login links, invoices, legal-text change notices, system messages) are sent via the configured mail transport (e.g. Cloudflare Email / Resend).

10. Retention

  • Account data: for the business relationship and statutory periods
  • Invoices and tax-relevant data: statutory retention (typically 6–10 years)
  • Security and access logs: typically up to 12 months; longer only where required for ongoing security investigations, legal enforcement or statutory retention, then deletion or anonymisation (scheduled deletion of non-retained security events after 12 months)
  • AI request logs: typically up to 12 months (see section 7a)
  • VIES / VAT ID verification data: with account data and tax-relevant records
  • Web Push subscriptions: until withdrawal, disablement or account deletion (see section 7c)
  • Consent data: until withdrawal or for proof purposes

11. Recipients and processing on behalf

Recipients may include Cloudflare (hosting/infra, optional Web Analytics after consent, and — when the questionnaire assistant is used — Workers AI / inference), Stripe (payments), email transport providers, the European Commission (VIES VAT ID checks), browser/push services when Web Push is enabled, and professionally bound advisers where necessary.

Where SHELL-AFFECT processes third-party personal data on the customer’s instructions, a DPA under Art. 28 GDPR is concluded before processing begins. Pure local development without access to the customer’s personal data stores does not constitute processing on behalf.

12. Data subject rights

You have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent under the GDPR. You may lodge a complaint with a supervisory authority.

Contact: support@shell-affect.com.

13. Security

We apply appropriate technical and organisational measures (transport encryption, access control, rate limits, input scanning, session management). Absolute security cannot be guaranteed.

14. Changes

We update this privacy policy when law, services or processing change. Material changes may be announced by email and/or dashboard.


Version 1.0 · Last updated: July 2026

Last updated: 30/07/2026 · v1.0

SHELL-AFFECT

Digital presence and security from a single source — for the DACH market.

info@shell-affect.com
Usually replies within 48 business hours
Based in Germany

Online Presence

  • Web design
  • Web applications

Cybersecurity

  • Cyber Attack Surface Profiling
  • Executive Exposure
  • Penetration Tests
  • IT Security Audit

Company

  • About us
  • Pricing
  • Contact
  • Home
© 2019-2026 SHELL-AFFECT · All rights reserved
ImprintPrivacyTermsTerms of Use