Privacy Policy
Last updated: October 2026
Privacy at a Glance
- We collect only data necessary to provide our robot teleoperation services
- Your data is processed in accordance with GDPR and German data protection laws
- We do not sell your personal data to third parties
- We never sell or rent our website analytics data. Our own measurement stays on our own servers; only if you accept analytics in the cookie banner does a part of those events also go to Google Analytics
- You have full control over your data with rights to access, correct, and delete
- We use industry-standard security measures to protect your information
1. Introduction and Overview
AY Robots ("we," "our," or "us"), operated by Philipp Schmid, is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains in detail how we collect, use, store, share, and protect your personal information when you use our robot teleoperation platform, website, and related services (collectively, the "Services").
This Privacy Policy applies to all users of our Services, including robot operators, clients, website visitors, and anyone who interacts with our platform. By using our Services, you acknowledge that you have read and understood this Privacy Policy.
We process your personal data in strict compliance with the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG), the German Telemedia Act (Telemediengesetz - TMG), and other applicable data protection legislation.
2. Data Controller Information
The data controller responsible for the processing of your personal data is:
AY Robots
Philipp Schmid
Steinenberg 10
88339 Bad Waldsee
Baden-Wurttemberg, Germany
Email: info@ay-robots.com
Website: www.ay-robots.com
For all data protection inquiries, you may contact us directly at the above address or via email at info@ay-robots.com. We aim to respond to all data protection requests within 30 days.
3. Categories of Personal Data We Collect
We collect and process various categories of personal data depending on how you interact with our Services. Below is a comprehensive overview of the data we may collect:
3.1 Account and Identity Data
- Full name (first and last name)
- Email address
- Password (stored in encrypted/hashed form only)
- Profile picture (optional)
- Username or display name
- Account creation date and status
- User role (operator, client, administrator)
- Language and timezone preferences
3.2 Contact and Communication Data
- Phone number (optional)
- Mailing address (for billing purposes)
- Company name and position (for business accounts)
- Support ticket content and correspondence
- Feedback and survey responses
- Marketing communication preferences
3.3 Teleoperation and Session Data
- Session recordings (video, audio if applicable)
- Robot control commands and inputs
- Session timestamps, duration, and metadata
- Task descriptions and instructions
- Performance metrics and quality assessments
- Robot identification and configuration data
- Sensor data collected during teleoperation
3.4 Technical and Usage Data
- IP address β used to deliver your request. It is not stored in plain text in our reach measurement; there we keep only the keyed hash described at the end of this section and in Section 3.6
- Browser type and version
- Operating system and device type
- Screen resolution and viewport size
- Pages visited and navigation patterns
- Referral source (how you found us)
- Session duration and interaction data
- Error logs and diagnostic information
- Network latency and connection quality metrics
Our own website reach measurement (see Section 3.6) records the following additional categories. Each of them is stored in a deliberately coarse form so that a single record says as little as possible about an individual visitor:
- Country at state level β derived from the time zone your device reports or, if that is not conclusive, from the language preference your browser sends. Ahead of both, our code accepts a country code that a content delivery network or proxy placed in front of our servers may add to the request; no such service is in front of them today, so in practice only the two sources named above are used. What we never do ourselves is a location lookup: we send no GPS or geolocation request, and we query no third-party IP geolocation service. We also store which of these sources a given country value came from, because they differ in reliability.
- Device class (desktop, mobile, tablet, or automated client) and the browser and operating system family without any version numberβ these are the values our statistics are built on. The raw user agent string your browser sends, which does contain version numbers, is stored alongside them for 180 days and is then removed (see Retention in Section 3.6)
- Viewport width, rounded to the nearest 10 pixels
- Time zone of your device (IANA identifier, e.g. Europe/Berlin)
- Interface language you selected in the language switcher, including the regional variant β this is your explicit choice, not the language setting of your browser
- Campaign parameters utm_source, utm_medium and utm_campaign, if the link you arrived through carried them
- Active time on page and maximum scroll depth
- Account ID and account role β only while you are signed in, and only resolved on our server from your existing session (see Section 3.6)
What is deliberately not stored in these records: your IP address in plain text, your email address, your name, and the contents of any form or message. Instead of the IP address we store a keyed hash of it: we hash your IP address together with the current date (UTC) and a secret key (a "pepper") that exists only in the environment of our server, never in the database and never in our source code, and we keep only the first 32 hexadecimal characters of the result. Without that key the value cannot be turned back into an IP address, and anyone who obtained a copy of the database alone could not do so either. Because the date is part of what we hash, the value changes every day β see Section 3.6 for what that does and does not mean.
Search terms entered on our site are stored, because we want to know what people look for. Two separate rules apply to them, and they do different things. First, a search term that contains an "@" character is replaced in full by a placeholder β not merely shortened. That is the rule which keeps an email address typed into a search box out of our analytics. Second, a search term is cut off at 60 characters. That cut does not protect against email addresses β a typical address is far shorter than 60 characters, so the cut never reaches it; what it does is limit how much free text a single record can carry at all. Search terms are removed when the record is depersonalized (see Retention in Section 3.6), and they are never sent to Google Analytics (see Section 9.2).
3.5 Financial and Transaction Data
- Billing name and address
- Payment method type (card brand, last 4 digits only)
- Transaction history and amounts
- Invoice records and payment status
- Tax identification numbers (for businesses)
- Refund and dispute records
Note: We do not store complete credit card numbers, CVV codes, or other sensitive payment credentials. All payment processing is handled by our PCI-DSS compliant payment processor, Stripe.
3.6 First-Party Analytics and Account Linkage
We operate our own reach and conversion measurement. The records described here are stored on our own infrastructure, are never sold, rented, or enriched with data from outside sources, and are never handed to a third party for that party's own purposes.
One qualification, so that this is not misread: if β and only if β you accept analytics in the cookie banner, part of these events is additionally sent to Google Analytics as it happens, in the reduced form described in Section 9.2. Those are the events that arise in your browser: a download you start, a click on a call-to-action, a click on a link leading off our site, a form submission, a language change, joining a live session, the fact that a search took place, and landing on a page that does not exist. Page views are counted by Google's own script; we do not send a second page view of our own, and scroll depth and time on page are not sent either.
The events that decide whether something actually succeeded do not reach Google at all, in no case: a registration, a sign-in, a started checkout, a completed purchase, a delivered download, and an installer run. They arise on our server, never pass through your browser, and our code refuses to accept them from a browser at all. The database records themselves never leave our servers either. Without your consent nothing of ours reaches Google, and the Google Analytics script is not even loaded.
Linkage with your account. While you are signed in, the events described in Section 3.4 are stored together with your account ID and your account role (for example client or operator). This linkage is established exclusively on our server from the session that already accompanies your request; an account ID sent by a browser is ignored. For visitors who are not signed in, no account ID is stored and the records remain without a direct identifier.
Purposes. We use this linkage to improve the product (understanding which parts of the platform are actually used and where people get stuck), to measure conversions (whether a download, a registration, or a purchase actually completed after the corresponding step), and to detect abuse (for example automated mass downloads).
Legal basis. Art. 6(1)(f) GDPR (legitimate interest). Our interest is the operation, financing, and improvement of the platform. We consider this interest not to be overridden by your rights because the measurement is first-party only, is never combined with external data sources, does not build advertising profiles, and does not follow you onto other websites.
What this does not mean. The keyed IP hash described in Section 3.4 rotates daily: because the calendar date is hashed along with your IP address, the same connection produces a different value tomorrow, and two values from two different days cannot be related to each other. Within one day the value is stable, and our internal reach figures are built on it. For that day it is therefore a pseudonym with recognition value: requests from the same connection are counted as one visitor, and several devices behind the same household or office connection produce the same value. What we count is consequently visitor-days, not visitors followed over time. We neither use it to build a profile nor claim it makes a record anonymous β the value stays in the record until it is overwritten with a fixed placeholder at depersonalization after 180 days.
Right to object. You may object to this processing at any time under Art. 21 GDPR by contacting info@ay-robots.com. We will then delete the records that are linked to your account. Please note that this is currently a manual step on our side, carried out within the period of Art. 12(3) GDPR: there is no automatic switch that stops the linkage for future visits, so records may be created again while you remain signed in. If you want the linkage to stop immediately, sign out β visits without a session are never linked to an account. We will tell you when your objection has been carried out.
Storage on your device. The measurement keeps a random session ID on your device for every visitor; only the language marker below depends on your answer in the cookie banner:
- For every visitor, whatever your answer: we store a randomly generated session ID in your browser tab's session storage together with the campaign parameters of your entry page, and we set one cookie (ayr_sid_link) carrying that same ID. We need it to operate our services: it ties the pages of one visit together and relates a click in your browser to the corresponding server-side event of the same visit (for example a download or a checkout). The session storage entries end when you close the tab. The cookie carries no expiry date and is therefore deleted when you close your browser β note that browsers configured to restore the previous session (for example Chrome's "Continue where you left off") may keep such cookies across restarts. Neither value contains anything about you; both are random. Two further things may be written to your device, and neither belongs to the measurement. The first is your own answer: the moment you answer the banner, it is stored in your browser's local storage under the key
cookie_consent. That entry is what keeps us from asking again on every page; it holds nothing but the words βacceptedβ or βrejectedβ, and deleting it simply brings the banner back. The second appears only if a script on the page actually fails: our error reporting (Section 5.1) then keeps two counters in your browser's session storage β how many error reports this tab has already sent, capped at ten, and when it last reloaded the page after a failed code download. They hold no identifier, they end when you close the tab, and their sole purpose is to stop a broken page from reporting itself in a loop. - Only if you accept: besides Google Analytics (Section 9.2), if you use the language switcher we remember that one choice in your browser's local storage, so that we can tell an actively chosen interface language from a merely preset one. That entry outlasts the tab, holds nothing but a language code, and is deleted again when you withdraw your consent.
If one of our short surveys (Section 3.8) is shown to you, the tab's session storage additionally remembers that it was shown (ayr_umfrage_intent) or on which pages you have already answered "Was this page helpful?" (ayr_umfrage_hilfreich, a list of at most 30 page paths), so that we do not ask again. These entries hold no identifier and end when you close the tab.
In neither case do we store a persistent identifier that would recognize you on a later, separate visit.
Retention. From day 180 onwards every record is depersonalized β whether or not it was ever linked to an account. This is done by a scheduled automated job that works through the due records in batches, so the step happens shortly after the 180-day mark rather than at that exact minute. Removed at that point are: the account ID, the account role, the time zone, the viewport width, the raw user agent and the session ID; the IP hash is overwritten with a fixed placeholder. At the same time the event details are cut down to a fixed list of coarse values, and everything not on that list is removed β among it the text of a search, the internal target of a click, the identifier of a marketplace listing, and the amount, currency and plan of a transaction.
What remains is the reach statistic itself: the kind of event and the page path, the language prefix of that path and the interface language you had selected, the referring website (host name only), the country together with the source it was derived from, the device class, the browser and operating system family, the campaign parameters, the active time on page and the scroll depth, the timestamp, and the coarse event details just described. None of those values identifies you, and none of them ties two records together as the same visitor. These depersonalized records are deleted after 26 months (790 days). See Section 7.
Interaction events. As part of the same measurement we also record how the interface is used: which buttons and functions in the dashboard are clicked (on the public pages only specially marked elements), repeated rapid clicks on the same spot (a sign that something does not respond), and whether a form was started, sent or left unfinished. For a button we store its visible caption or accessibility label, shortened to 60 characters, after removing anything that looks like an email address, an ID or a number with four or more digits. For forms we store only the name of the form and of the field that was focused last, the number of fields touched and the time spent β never what you typed into them. These events are records like those described above, with the same linkage, legal basis and retention.
Page performance. For each page you open we also measure how quickly and smoothly it loaded and responded, using the performance interface built into your browser (the so-called Core Web Vitals): the time until the first byte and the first content arrived, the time until the largest element was displayed, how much the layout shifted while you were on the page, and how long the page took to react to your clicks and key presses. Each value is stored as a number (milliseconds, layout shift as a score) together with a rating of good, needs improvement or poor. Nothing about the content of the page and nothing you type is recorded; which element you clicked is not part of these values either.
Further events of the same kind. For a search on our marketplace we also store how many results it returned. Whether one of our short surveys (Section 3.8) was shown, answered or closed is recorded as an event as well; the answer itself is stored separately as described there. When a Remote Data Collector sets up payouts, we record whether Stripe's embedded onboarding was opened and closed and whether Stripe reports information that is still missing β never what is entered there, which goes directly to Stripe. All of these are records like those described above, with the same linkage, legal basis and retention. The performance, survey and payout-setup events are never sent to Google Analytics; of a search, Google learns at most what Section 9.2 describes.
3.7 Voluntary Feedback
You can send us feedback at any time β through the feedback button in the dashboard, the "Give feedback" link at the bottom of every page, or a short question that the dashboard shows at most once every 90 days to accounts that have been active on several days. Sending feedback is entirely voluntary.
What we store: your rating (1β5 stars or 0β10), the kind of feedback you chose, the text you write, the page you sent it from, your interface language, and the same coarse context as in Section 3.4 (device class, browser and operating system family without version, country, the keyed daily IP hash and the session ID of the visit). If you are signed in, the feedback is linked to your account ID and account role; this link is made on our server, never from what a browser sends. If you dismiss the question in the dashboard, we store only that it was dismissed, so that we do not ask again for 90 days.
Replies: we only reply to feedback if you are signed in and tick "You may reply to my account email address". We then answer to the email address of your account; the form does not ask for any other address.
Purpose and legal basis: improving the platform, Art. 6(1)(f) GDPR (legitimate interest); where you ask us to reply, Art. 6(1)(b) GDPR. Feedback is only read by our team, is not shared with third parties and is not sent to Google Analytics. It is deleted no later than 24 months after it was sent; you can ask for earlier deletion at any time via info@ay-robots.com.
3.8 Short Surveys
On some pages we ask a single, optional question. On the page for robot operators (/teleoperator) and on the list of Remote Data Collectors (/operators) we ask "What brings you here?" with five fixed answers; the question appears at most once per browser tab, after about 20 seconds on the page or once you have scrolled halfway down, and you can close it without answering. At the end of blog articles, documentation pages and guides we ask "Was this page helpful?" (yes or no); after "no" you may tell us what was missing.
What we store when you answer: the answer you clicked and, only if you write and send one, your comment (the form allows up to 500 characters); the page, your interface language, the device class, the country (derived as described in Section 3.4), the keyed daily IP hash and the session ID of the visit, the host name of the website that referred you to us, and the campaign source (utm_source) of your entry page if it had one. If you are signed in, the answer is linked to your account ID and account role; this link is made on our server, never from what a browser sends. Your answer is saved as soon as you click it; a comment you add afterwards is attached to that same record, which is only possible from the same visit and within 30 minutes. Closing a question without answering stores no answer.
Purpose and legal basis: understanding what visitors are looking for and which pages actually help them, so that we can improve the platform; Art. 6(1)(f) GDPR (legitimate interest). Answers are only read by our team, are not shared with third parties and are not sent to Google Analytics. They are deleted 24 months after they were given; you can ask for earlier deletion at any time via info@ay-robots.com.
3.9 Live Robot Arm (/live)
On /live anyone can control a real, physical robot arm from the browser, one person at a time. Your browser keeps a random ID for this page and the display name you choose in its local storage. Chat messages you post are visible to everyone watching and are stored on our server for 7 days together with your display name and that random ID; emoji reactions are deleted with the message. Voice messages are not written to our database; they are held only in our server's memory and can no longer be played after 30 minutes.
What we store when you take control: for every control session (from the moment you take over the arm until you release it, close the tab, lose the connection, become inactive or hand over to the next person) we store a record with the start and end time and how the session ended, how many commands the arm accepted and how many it rejected, the time of the last command, your display name and the random ID of the page, the session ID of your visit (Section 3.6), your IP address in plain text, the raw user agent of your browser, the country (derived as described in Section 3.4), the host name of the website that referred you to us, the campaign parameters of your entry page, whether you took over directly or from the queue, and which robot and arm were controlled. If you are signed in, the record also contains your account ID and the email address of your account; this link is made on our server from your existing session, never from what a browser sends. If the request comes from a browser our team has marked as its own, the record is flagged as internal.
Unlike our reach measurement (Section 3.4), this record contains your IP address in plain text. The arm is a physical machine: if it is misused or damaged, we need to be able to trace and block the source.
Availability email: while the arm is offline, you can leave your email address on /live to receive a single email once it is available again. We store the address, when you signed up and when the email was sent. The link in that email carries a marker of your waiting-list entry. When you open it, the page keeps the marker for that browser tab only (session storage), removes it from the address bar, and we record when the link was first opened; if you then take control, the control session is linked to your entry and we record when that first happened. We do this to find out whether the email actually brings people back to the arm. We use your address for nothing else.
Purpose and legal basis: operating a physical robot safely, preventing and investigating misuse, and understanding how visitors reach the arm; Art. 6(1)(f) GDPR (legitimate interest). These records are only read by our team, are not shared with third parties and are not sent to Google Analytics. Control session records are deleted automatically 90 days after the session started. Waiting-list entries are not yet deleted automatically; you can have yours deleted at any time via info@ay-robots.com.
4. Purposes of Data Processing and Legal Basis
We process your personal data only for specific, explicit, and legitimate purposes. Below we explain each purpose along with the corresponding legal basis under Article 6 of the GDPR:
4.1 Service Provision (Contract Performance - Art. 6(1)(b) GDPR)
- Creating and managing your user account
- Providing access to the teleoperation platform
- Facilitating connections between operators and clients
- Recording and storing teleoperation sessions as requested
- Processing payments and managing subscriptions
- Providing customer support and resolving issues
4.2 Platform Improvement (Legitimate Interest - Art. 6(1)(f) GDPR)
- Analyzing usage patterns to improve user experience
- Identifying and fixing technical issues and bugs
- Developing new features and capabilities
- Conducting internal research and analytics
- Optimizing platform performance and reliability
- Measuring conversions β whether a download, registration, or purchase actually completed after the corresponding step, including for signed-in users (see Section 3.6)
- Measuring the effectiveness of our own campaigns via the utm_source, utm_medium and utm_campaign parameters of the link you arrived through
4.3 Security and Fraud Prevention (Legitimate Interest - Art. 6(1)(f) GDPR)
- Detecting and preventing unauthorized access
- Identifying fraudulent or abusive behavior
- Protecting against security threats and attacks
- Maintaining audit logs for security purposes
- Enforcing our Terms of Service
4.4 Legal Compliance (Legal Obligation - Art. 6(1)(c) GDPR)
- Retaining records as required by tax and commercial law
- Responding to lawful requests from authorities
- Fulfilling anti-money laundering obligations
- Complying with court orders and legal proceedings
4.5 Marketing and Communications (Consent - Art. 6(1)(a) GDPR)
- Sending newsletters and product updates (with consent)
- Informing you about new features and services
- Conducting surveys and gathering feedback
- Personalizing content and recommendations
You may withdraw your consent for marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.
Robot availability emails (Remote Data Collectors): only if you turn them on yourself, we email your account address when a robot you may drive has been available for a few minutes, at most once per day. For each such email we record which robot it was about, when it was sent and whether sending worked, and delete this record after 90 days. You can turn these emails off in your settings or with the unsubscribe link in every one of them; it takes effect immediately and leaves your other settings unchanged.
5. Data Sharing and Third-Party Recipients
We share your personal data only when necessary and with appropriate safeguards. The following categories of recipients may receive your data:
5.1 Service Providers and Processors
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication | EU (Germany) |
| Vercel | Website hosting, CDN | Global (US-based) |
| Stripe | Payment processing | US (EU data in EU) |
| Resend | Transactional emails | US |
| admin.webgantic.com (operated by us) | Automatic error reports. If a script on this site fails, your browser sends the error message, the technical stack trace, the address of the page you were on and your browser identification to our own error collector. This happens regardless of your cookie choice, because it is what tells us the site is broken. Note that the page address can contain what you typed into a search field, if the error happens on a results page. | EU (Germany) |
| Google Ireland Ltd. (Google Analytics 4) | Website analytics β only if you consent (Section 9.2); not contacted at all otherwise | Ireland, with onward processing in the US |
All service providers are bound by data processing agreements (DPAs) that ensure they process your data only according to our instructions and maintain appropriate security measures.
5.2 Business Partners
When you use our platform to connect with operators or clients, we share necessary information to facilitate the service (e.g., operator availability, session details). This sharing is essential for the performance of our contract with you.
5.3 Legal and Regulatory Authorities
We may disclose your data to law enforcement agencies, courts, regulators, or other authorities when required by law or to protect our legal rights. We will notify you of such disclosures where legally permitted.
5.4 Corporate Transactions
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will provide notice before your data becomes subject to a different privacy policy.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
6. International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA). When we transfer your data internationally, we ensure appropriate safeguards are in place:
- Adequacy Decisions: Transfers to countries with adequate data protection (as determined by the EU Commission)
- Standard Contractual Clauses: EU-approved contractual terms that bind recipients to protect your data
- Data Processing Agreements: Comprehensive agreements with all processors covering security and confidentiality
- Supplementary Measures: Additional technical and organizational measures where necessary
The one transfer that depends on your own decision is Google Analytics: it takes place only after you accept analytics in the cookie banner, and it then rests on your consent under Art. 49(1)(a) GDPR in addition to the Standard Contractual Clauses and Google's certification under the EU-U.S. Data Privacy Framework. Without your consent the Google script is not loaded and no data of yours reaches Google (Section 9.2).
You may request a copy of the safeguards we use for international transfers by contacting us.
7. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are as follows:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data | Duration of account + 30 days | Service provision |
| Session recordings | 90 days (default) or as agreed | Contract fulfillment |
| Transaction records | 10 years | German tax law (AO Section 147) |
| Invoices and contracts | 10 years | German commercial law (HGB Section 257) |
| Support communications | 3 years | Statute of limitations |
| Security logs | 12 months | Security and fraud prevention |
| Analytics data | 26 months (anonymized) | Service improvement |
| Web analytics events β account ID and role, IP hash, raw user agent, time zone, viewport width, session ID, and the event details apart from a fixed list of coarse values (search terms, click targets, listing IDs and transaction amounts are among those removed) | 180 days, then removed or overwritten (all records, not only those with an account link) | Product improvement and conversion measurement |
| Web analytics events β depersonalized remainder (path, country, device, campaign, timestamp) | 26 months (790 days) from the event | Long-term trend analysis |
| Voluntary feedback (rating, text, page, context, account link if signed in) | 24 months from sending, or earlier on request | Product improvement, replies you asked for |
| Short survey answers (answer, optional comment, page, context, account link if signed in) | 24 months from answering, or earlier on request | Product improvement |
| Live arm control sessions (start and end, command counts, display name, page ID, session ID, IP address in plain text, user agent, country, referring host, campaign, waiting-list marker, account ID and email if signed in) | 90 days from the start of the session | Safe operation of the physical robot, abuse prevention |
| Live arm chat messages and reactions | 7 days | Showing the recent chat |
| Live arm availability email (address, sign-up and sending time, first opening of the link and first control through it) | No automatic deletion yet; deleted on request | Sending the one notification and checking that it works |
| Marketing consent records | Until withdrawal + 3 years | Proof of consent |
After the retention period expires, data is securely deleted or anonymized so that it can no longer be associated with you.
8. Your Data Protection Rights
Under the GDPR and German data protection law, you have the following rights regarding your personal data. We are committed to facilitating the exercise of these rights:
8.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is processed. We will provide this information free of charge within 30 days of your request.
8.2 Right to Rectification (Art. 16 GDPR)
You have the right to request correction of inaccurate personal data and completion of incomplete data. You can update most account information directly through your account settings.
8.3 Right to Erasure / Right to be Forgotten (Art. 17 GDPR)
You may request deletion of your personal data when:
- The data is no longer necessary for the purposes collected
- You withdraw consent and there is no other legal basis
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required by law
Note that we may retain certain data where required by law or for legitimate purposes (e.g., defending legal claims).
8.4 Right to Restriction of Processing (Art. 18 GDPR)
You may request that we restrict the processing of your data in certain circumstances, such as when you contest the accuracy of the data or have objected to processing.
8.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV), and to transmit that data to another controller. This applies to data processed by automated means based on consent or contract.
8.6 Right to Object (Art. 21 GDPR)
You have the right to object to processing based on legitimate interests or for direct marketing purposes. When you object, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
8.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where we process data based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated. The competent authority for AY Robots is:
Der Landesbeauftragte fur den Datenschutz und die Informationsfreiheit Baden-Wurttemberg
Lautenschlagerstrasse 20
70173 Stuttgart, Germany
Phone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
Website: www.baden-wuerttemberg.datenschutz.de
Exercising Your Rights
To exercise any of these rights, please contact us at:
- Email: info@ay-robots.com
- Mail: AY Robots, Steinenberg 10, 88339 Bad Waldsee, Germany
We may need to verify your identity before processing your request. We will respond within 30 days, or inform you if an extension is needed (up to 60 additional days for complex requests).
9. Cookies and Tracking Technologies
We use cookies and similar technologies to ensure our platform functions properly and to improve your experience. This section explains what cookies we use and how you can manage them.
9.1 What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites remember information about your visit, making subsequent visits easier and the site more useful.
9.2 Types of Cookies We Use
Strictly Necessary Cookies
These cookies are essential for the platform to function and cannot be disabled. They include:
- Authentication cookies (to keep you logged in)
- Session cookies (to maintain your session state)
- Security cookies (to prevent fraud and protect your account)
- Load balancing cookies (to ensure optimal performance)
Functional Cookies
These cookies remember your preferences and settings:
- Language preferences
- Theme settings (dark/light mode)
- Timezone settings
- Dashboard layout preferences
Google Analytics 4 (Optional β Only With Your Consent)
Google Analytics 4 is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with onward processing by Google LLC in the United States. It is used only if you press "Accept analytics" in the cookie banner. Legal basis: Art. 6(1)(a) GDPR and Β§ 25(1) TDDDG (consent). For the transfer to the United States we rely on the EU Standard Contractual Clauses and on Google's certification under the EU-U.S. Data Privacy Framework.
Nothing is loaded before you consent. The Google tag is not placed in the page while your answer is missing or negative β the script is not requested, so your browser makes no connection to googletagmanager.com or google-analytics.com at all, and no cookieless measurement ping reaches Google either. If you consent later, the script is loaded at that moment without a page reload; if you clear this site's data, the next page load starts again without it.
With your consent, Google receives your IP address, your user agent, the page URL and the referrer, plus the events listed in Section 3.6: downloads you start, clicks on calls-to-action, outbound clicks, form submissions, language changes, joining a live session, the fact that a search took place, and landing on a page that does not exist. Page views are recorded by Google's own script rather than passed on by us. What Google does not receive at all are the events that arise on our server β registrations, sign-ins, started checkouts, completed purchases, delivered downloads and installer runs. Google Analytics sets its own cookies for this.
What we never send to Google, in any case: your email address, your name, your IP hash, and the text of anything you searched for. The search term is blocked by name in our code before an event is handed to Google, and so is every other field that can carry free text; what Google learns about a search is that one took place, how long the query was and how many results it returned, never what it said. We use no third-party advertising or remarketing cookies, and our tag keeps Google's consent signals for advertising storage, advertising user data, and ad personalization set to "denied" even after you have consented to analytics.
Our Own Reach Measurement (No Consent Required)
Our own reach and conversion measurement (Section 3.6) is separate from Google Analytics and works without it. It runs on our own servers, is never read across websites, and the records stay with us. We rely on Art. 6(1)(f) GDPR for it rather than on your consent.
Because we need it to operate our services, we set the session cookie ayr_sid_link and the session storage entries described in Section 3.6 for every visitor, whatever your answer in the cookie banner. We consider them strictly necessary within the meaning of Β§ 25(2) no. 2 TDDDG. They hold only a random ID and the campaign parameters of your entry page, end with the tab or browser session, and are never read by third parties. Only the language marker described in Section 3.6 and Google Analytics depend on your consent.
9.3 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to:
- View what cookies are stored
- Delete individual or all cookies
- Block cookies from specific or all websites
- Configure notifications when cookies are set
Please note that disabling strictly necessary cookies may affect the functionality of our platform.
Withdrawing your analytics consent. Your answer to the cookie banner is kept in your browser's local storage under the key cookie_consent. To withdraw it, clear this site's data in your browser settings (or delete that single entry); the banner then asks again on your next visit, and until you accept once more no Google script is loaded and the measurement stores nothing on your device. Withdrawal has effect for the future and does not affect what was lawfully processed before it.
Drafts you have not submitted yet. If you start filling in a data request on /data-requests/new before you have an account, what you type is kept in your browser's local storage under the key ayr-collection-entwurf-v1 so that it survives the trip through sign-up. It stays on your device, is never sent to us until you publish the request yourself, is deleted automatically 30 days after you last touched it, and can be deleted at any time with the "Discard draft" button on that page or by clearing this site's data. This is functional storage that the feature cannot work without, so it does not depend on your analytics consent and is unaffected when you withdraw it.
10. Security Measures
We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
Technical Measures
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Secure password hashing (bcrypt)
- Regular security audits and penetration testing
- Web Application Firewall (WAF) protection
- DDoS protection and mitigation
- Automated vulnerability scanning
Organizational Measures
- Access controls based on the principle of least privilege
- Employee confidentiality agreements
- Regular security awareness training
- Incident response procedures
- Vendor security assessments
- Data protection impact assessments where required
For more details about our security practices, please visit our Security Page.
11. Automated Decision-Making and Profiling
We do not engage in automated decision-making that produces legal effects or similarly significantly affects you without human involvement. Any automated processing we perform (such as matching operators with tasks) is subject to human oversight.
If we introduce automated decision-making in the future, we will update this policy and ensure you are informed and can exercise your rights under Article 22 of the GDPR.
12. Children's Privacy
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information as quickly as possible.
13. Changes to This Privacy Policy
What changed in October 2026. Control sessions on the live robot arm (/live) are now recorded, including the IP address in plain text, and deleted after 90 days; the link in the availability email now carries a marker of the waiting-list entry (Section 3.9 and Section 7). Section 3.9 also describes the live chat, which was not covered here before.
What changed in September 2026. We rebuilt our own reach measurement. New since then: while you are signed in, website events are stored together with your account ID and role (Section 3.6); we additionally record country, time zone, device class, viewport width, the interface language you selected, and the campaign parameters of the link you arrived through (Section 3.4); and two retention steps now apply to these records β depersonalization after 180 days, deletion after 26 months (Section 7). At the same time Google Analytics is no longer loaded at all before you consent. From 1 to 23 September 2026 our own measurement also stored nothing on your device without your consent; since 23 September 2026 its session cookie and session storage entries are set for every visitor, because we need them to operate our services (Sections 3.6 and 9.2).
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
- We will update the "Last updated" date at the top of this page
- For significant changes, we will notify you by email or through a prominent notice on our platform
- We will provide you with the opportunity to review changes before they take effect
- Your continued use of our Services after changes take effect constitutes acceptance of the revised policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Contact
AY Robots
Philipp Schmid
Steinenberg 10
88339 Bad Waldsee, Germany
Email: info@ay-robots.com
General inquiries: info@ay-robots.com
We are committed to working with you to resolve any concerns about your privacy. Please allow up to 30 days for us to respond to your inquiry.