WebDrift

LOADING DIGITAL SYSTEMS

LEGAL

Privacy Policy

How and why we process personal data on this website, in accordance with the EU General Data Protection Regulation (GDPR).

Legal note for the site owner: Note: this English version is a translation for convenience only — the German version is legally binding, and this page must be reviewed by a lawyer before launch.

1. Controller

The controller within the meaning of the GDPR for data processing on this website is:

Name
Hamada Ameen / WEBDRIFT
Address
Katzsteinstraße 13, 01219 Dresden, Deutschland
Email
start@webdrift.io
Phone
+49 170 8146615

2. Hosting

This website is hosted by Hostinger International Ltd. (Node.js hosting). When you access the site, the hosting provider automatically processes technical connection data (see “Server log files”) in order to deliver it. This processing is based on our legitimate interest in a secure and stable delivery of the website (Art. 6(1)(f) GDPR).

Where required, a data processing agreement (Art. 28 GDPR) is in place with the hosting provider. A transfer of data to third countries (e.g. the USA) cannot be fully excluded for technical reasons; we rely on appropriate safeguards (e.g. EU standard contractual clauses) provided by the vendor.

3. Server log files

When you access this website, the hosting provider automatically collects information that your browser transmits in so-called server log files. These are:

  • browser type and version
  • operating system used
  • referrer URL (page visited previously)
  • IP address (shortened/anonymized)
  • date and time of the server request

This data is technically necessary to deliver the website without errors and to ensure system security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). This data is not combined with other data sources.

4. Analytics

We measure the reach of this website with Umami, an open source statistics tool that we run ourselves on our own server in the EU (stats.webdrift.io). No data is passed to third parties.

Umami sets no cookies and stores nothing in your browser. Only anonymous page views are recorded: the page visited, the referring website, browser and device type, screen size, language and the country (derived from the IP address). Your IP address is not stored; to count unique visits it is turned into a non reversible hash together with a random value that changes every day. Recognising you across days or across other websites is therefore not possible.

The legal basis is our legitimate interest in a data minimising analysis of how our website is used (Art. 6 (1) (f) GDPR). As nothing is stored on or read from your device, no consent under § 25 TDDDG is required. You can object by enabling “Do Not Track” in your browser or by using a content blocker.

5. Cookies and local storage

This website uses no third party cookies. There is no cross site tracking, no advertising cookies and no analytics cookies (the audience measurement in section 4 works without cookies). Everything stored in your browser during a visit comes from WebDrift itself and serves only to run the site.

WebDrift sets no cookies for visitors. Data is kept only in your browser's local storage (localStorage and sessionStorage). These entries stay on your device and are not sent to third parties. Only the chat session ID (wd-buddy-sid) reaches us, with each message you write to Drifty. The table below lists every entry:

NamePurposeTypeLifetimeSet by
wd-themeRemembers your choice between light and dark mode.localStorageuntil you delete itWebDrift, theme switch
wd-loader-seenShows the intro animation only once per visit.sessionStorageuntil the tab is closedWebDrift, intro animation
wd-offer-seenRemembers that the offer window was already shown.sessionStorageuntil the tab is closedWebDrift, offer window
wd-guide-stateRemembers whether the scroll guide is minimised or closed.sessionStorageuntil the tab is closedWebDrift, scroll guide
wd-lang-posKeeps your scroll position when you switch between German and English.sessionStoragea few seconds, deleted when readWebDrift, language switch
wd-rk-landFlag for the landing animation when you change pages.sessionStoragea few seconds, deleted when readWebDrift, page transition
wd-start-brief-v2 (and the older entry wd-start-brief-v1)Keeps your answers in the project questionnaire if you reload the page. The draft stays in your browser until you send it.sessionStorageuntil the tab is closedWebDrift, project questionnaire
wd-work-buddyRemembers whether the astronaut on the Work page is on or off.localStorageuntil you delete itWebDrift, Work page
wd-buddy-offRemembers that you hid the helper Drifty.localStorageuntil you delete itWebDrift, helper Drifty
wd-buddy-boxRemembers the position of the helper Drifty.localStorageuntil you delete itWebDrift, helper Drifty
wd-buddy-seenRemembers which hints Drifty has already shown.sessionStorageuntil the tab is closedWebDrift, helper Drifty
wd-buddy-hiRemembers that Drifty has already greeted you.sessionStorageuntil the tab is closedWebDrift, helper Drifty
wd-buddy-sidRandom ID of your chat session with Drifty. It is sent to our server with every chat message so Drifty knows the conversation so far.sessionStorageuntil the tab is closedWebDrift, helper Drifty
wd-buddy-logThe messages of your chat with Drifty (at most 30), so the conversation is still there after you reload the page.sessionStorageuntil the tab is closedWebDrift, helper Drifty
wd-storage-noticeRemembers that you confirmed the privacy notice (value v1).localStorageuntil you delete itWebDrift, privacy notice
wd_adminLogin to the admin area. Set only after the site operator signs in, never for visitors.Cookie (HttpOnly, WebDrift only)12 hoursWebDrift, admin area

The only cookie on the site is wd_admin. It belongs to the admin area, is set only after the site operator signs in, and has no meaning for visitors.

External runtime hosts: for some animated background effects (WebGL) your browser loads a script from cdn.jsdelivr.net and the scene data from Unicorn Studio (storage.googleapis.com or assets.unicorn.studio, Google Cloud Storage). Technically this requires your IP address to be transmitted to these servers. These hosts set no cookies through our site and no tracking takes place. More in section 7.

Legal basis: the entries above are technically necessary so that the functions you ask for, such as the theme choice or the language switch, work (Section 25(2) no. 2 TDDDG, therefore no consent is required). Any further processing rests on our legitimate interest in a secure and stable operation of the website (Art. 6(1)(f) GDPR).

How to delete these entries: open your browser settings and clear the site data for webdrift.io (depending on the browser under Privacy, Cookies and site data, or Clear site data). Session entries also disappear when you close the tab. The privacy notice then appears again on your next visit.

6. Fonts (Google Fonts)

We use Google Fonts for consistent typography. The font files are not loaded from Google's servers; instead they are bundled locally at build time via next/font and served from our own server (self-hosted). No connection to Google's servers is made and your IP address is never transmitted to Google for this purpose.

7. Visual effects (Unicorn Studio / jsDelivr CDN)

For some animated background effects (WebGL) we load a script from the provider Unicorn Studio via the public content delivery network jsdelivr.net. This technically requires your IP address to be transmitted to jsDelivr's servers so the script can be delivered.

The scene data of some effects is delivered by Unicorn Studio through Google Cloud Storage (storage.googleapis.com) or assets.unicorn.studio. Here too your IP address is technically transmitted to these servers.

The legal basis is our legitimate interest in a fast, reliable delivery of these design elements (Art. 6(1)(f) GDPR). No cookies are set and no personal data beyond delivering the script is processed.

8. Contact form, AI check & email

When you use our contact form, offer form, project questionnaire or booking form, we process the details you provide (in particular your name, email address, and, where supplied, phone number, company, message and chosen appointment) to answer your enquiry, prepare an offer or hold the meeting. We store the enquiry and related correspondence in our internal CRM. The legal basis is Article 6(1)(b) GDPR for pre-contractual steps or performance of a contract. Where consent is requested, Article 6(1)(a) GDPR also applies to the purpose stated there. You may withdraw consent at any time for the future.

Hostinger International Ltd. hosts the website, CRM database and our business mailbox. Forms are transmitted to our server over an encrypted connection. We send confirmations and replies through start@webdrift.io; incoming business email may be imported into the CRM to handle your enquiry. We share data with other recipients only where needed to handle the enquiry or meet legal obligations. A data-processing agreement with the hosting provider must be in place; the data-centre location and subprocessors must be checked before publication. Transactional emails contain no open or click tracking.

Contacts without a project or invoice are normally anonymised 24 months after their last activity, unless an open enquiry or another legal obligation requires longer retention. Email content and enquiry fields associated with an anonymised contact are removed. Booking slots without personal details are deleted after another 12 months. Finalised invoices and the recipient details needed to substantiate them are retained for tax-law purposes; copies of issued invoices generally must be kept for eight years from the end of the year of issue. Other business correspondence may have different periods. Backups rotate under the documented backup schedule; data in a backup disappears when that copy expires.

Subject to applicable legal conditions, you may request access, correction, erasure, restriction and portability of your data. Erasure may be limited where a legal retention duty applies (Article 17(3)(b) GDPR). Contact start@webdrift.io. You may also complain to a data-protection supervisory authority. We do not use enquiry correspondence as a newsletter list.

External AI services (Anthropic) and a locally operated model (Qwen) may help prepare editorial blog content. Personal data from customer enquiries is not supplied to these tools. This notice must be updated if that practice changes.

9. Chat assistant Drifty (AI)

On our website you can write to the chat assistant Drifty. Drifty is an AI: its answers are generated automatically and can contain mistakes. If you would rather talk to a person, write to start@webdrift.io.

In doing so we process:

  • your chat messages and Drifty's answers
  • the page of our website on which you use the chat
  • a random session ID (see Cookies and local storage)
  • your name and email address, if you send the contact form in the chat
  • voice notes, if you use the recording function
  • simple signals of the session, for example whether you asked about prices or opened the booking

Purposes and legal bases: we answer your questions and handle pre-contractual requests such as offers, callbacks and appointments (Article 6(1)(b) GDPR). We also have a legitimate interest in a helpful website and in protecting the chat against abuse (Article 6(1)(f) GDPR).

AI provider: Drifty answers many questions, for example about prices, contact or booking, with fixed rules and no AI at all. Only when the rules have no fitting answer do we send your message, the conversation so far in this chat session and the page you are on to Google's Gemini API (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA) so that an answer is generated there. Data may be transferred to the USA in the process. The transfer is based on the EU US Data Privacy Framework, under which Google LLC is certified. If the AI cannot be reached, Drifty answers with the fixed rules only. Please do not enter sensitive data in the chat, such as health data, bank details or passwords.

Voice notes: a recording only starts when you tap the microphone and your browser allows access. The recording is sent to our own server and turned into text there. The audio file is not stored afterwards and is not passed on to third parties. The text first appears in your input field. Only when you send it do we process it like a written message.

Retention: we delete chat conversations without contact details automatically 90 days after the last message. If you ask to be contacted through the form in the chat or book an appointment in the chat, we store your request together with the conversation in our customer system (CRM), just like a request by email. The periods described in the section on the contact form apply.

We use the email address from the chat only to reply to your request. The checkbox in the form is not consent to advertising, and we do not send you a newsletter.

From the signals of the session we calculate a simple score that shows us how concrete a request is. If you have given us your contact details, our team may receive an internal email about it. No automated decision with legal effect for you is based on it.

We do not store your IP address for the chat. For abuse limits, such as too many messages in a short time, our server uses it only as a hash value and only in memory.

10. Your rights as a data subject

Subject to statutory requirements, you have the right at any time to:

  • Access to your stored personal data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)

Please simply contact us by email. This website does not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

11. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data. The competent authority is:

Authority
Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte)
Address
Postfach 11 01 32, 01330 Dresden, Germany
Phone
+49 351 85471-101
Email
post@sdtb.sachsen.de
Web
datenschutz.sachsen.de

12. Changes to this privacy policy

We update this privacy policy whenever our data processing or the legal situation changes. The version published on this page is always the current one.