Legal information
Privacy Policy
Controller
Stefan Kohlweg
Stenografengasse 4, 1230 Wien, Austria
Email: contact@relateto.ai
What data we collect and why
Counseling case submissions
When you submit a counseling case (via contact form or after payment), we collect your name, email address, situation type, timezone, and the description of your situation. This data is used to provide asynchronous email counseling. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(a) GDPR (explicit consent).
Confidentiality of case content
Any personal information you share — including descriptions of your situation, context, and desired outcomes — is treated with strict confidentiality. It is not shared with third parties beyond what is technically necessary to deliver the service (see below).
Payment data
Payment is processed by Stripe (credit card, Apple Pay, Google Pay) or via x402 protocol (USDC on Base blockchain). We store only the payment session reference (Stripe session ID or x402 transaction hash) — not credit card numbers or financial account details.
Server and access logs
Technical data (IP address, browser type, access timestamp, pages visited) is processed automatically by Cloudflare for security and error analysis. Cloudflare may derive approximate geolocation (country-level) from your IP address for security purposes. These logs are retained by Cloudflare for up to 30 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and availability of the service).
AI-assisted processing
We use Anthropic Claude AI models, accessed via Google Cloud Vertex AI (Anthropic PBC, San Francisco, USA; Google Cloud region europe-west3, Frankfurt, Germany), to assist in drafting counseling responses. Your case content — situation description, context, and desired outcome — is transmitted to Google Cloud's EU infrastructure for this purpose. Your email address is never transmitted to the AI service. Google Cloud Vertex AI does not use customer data for model training. Anthropic's terms for Vertex AI also prohibit training on customer data.
This is AI-assisted processing, not automated decision-making under Art. 22 GDPR. Every counseling response is reviewed, edited where necessary, and approved by a qualified human counselor (MSc in Psychosocial Counseling) before delivery to you. No automated profiling or scoring takes place.
Third-party services
Cloudflare (hosting, database, serverless compute)
This website is hosted via Cloudflare Pages. Case data is stored in Cloudflare D1 (SQLite database). Cloudflare acts as a data processor under Art. 28 GDPR. A Data Processing Addendum (DPA/Auftragsverarbeitungsvertrag) is in place. Cloudflare is certified under the EU-US Data Privacy Framework. All connections are encrypted via TLS 1.2+ with HSTS enforced. SSL operates in strict mode with origin certificate validation.
Privacy policy: cloudflare.com/privacypolicy
DPA: cloudflare.com/gdpr
Cloudflare Turnstile is used on submission forms to prevent automated abuse. Turnstile processes minimal technical data (IP address, browser characteristics) without setting tracking cookies or persistent identifiers. This processing is covered by the Cloudflare DPA and certifications referenced above.
Stripe (payment processing)
Stripe processes payments as an independent data controller under its own GDPR obligations. Stripe receives your email and payment amount but does not receive counseling content. A separate DPA is in place with Stripe.
Privacy policy: stripe.com/privacy
Google Cloud / Vertex AI (AI-assisted counseling drafts)
Anthropic Claude AI models are accessed via Google Cloud Vertex AI (region europe-west3, Frankfurt, Germany) to generate draft counseling responses. Google Cloud acts as data processor under Art. 28 GDPR. Anthropic is a sub-processor under Google's Data Processing Agreement. Only case content (situation description, context, desired outcome) is transmitted — email addresses and payment data are never sent to the AI service. Data is processed in the EU (Frankfurt). Google Cloud does not use customer data for model training.
Google Cloud is certified under the EU-US Data Privacy Framework. The Google Cloud DPA incorporates EU Standard Contractual Clauses (Art. 46 GDPR).
DPA: cloud.google.com/terms/data-processing-addendum
Sub-processors: cloud.google.com/terms/subprocessors
Porkbun (email delivery)
Counseling responses are delivered via SMTP through Porkbun's email service over encrypted TLS connections (port 465, TLS 1.2+). Porkbun processes email addresses and email content for the purpose of delivery only. No formal Data Processing Agreement (Auftragsverarbeitungsvertrag) is currently in place with Porkbun. Migration to an EU-based email delivery provider with a published DPA is under evaluation.
Privacy policy: porkbun.com/legal/privacy_policy
Fonts
All fonts used on this website are self-hosted. No connections to external font services (such as Google Fonts) are made. No visitor data is transmitted to third parties for the purpose of loading fonts.
Data retention
Case data (including your situation description and our counseling response) is retained for 7 years from submission. This retention period is required by Austrian tax and accounting law (Bundesabgabenordnung, BAO §132), which mandates that business records be kept for seven years. Legal basis for retention beyond the contract period: Art. 6(1)(c) GDPR (compliance with a legal obligation).
After the 7-year period, closed cases are automatically and permanently deleted. You may request deletion of your case data at any time. Where no legal retention obligation applies, we will delete your data promptly. Where a legal retention obligation exists, we will restrict processing of your data to what is legally required and delete it as soon as the retention period expires.
Server logs processed by Cloudflare are typically retained for no longer than 30 days.
Paid advertising attribution (gclid)
When a visitor arrives on a landing page (/lp/tension, /lp/replaced) via a Google Ads click, a gclid URL parameter is present in the URL. This parameter is immediately captured into a first-party cookie named _gcl_aw_relateto (90-day TTL) and into sessionStorage under the key relateto_gclid.
The captured value is used exclusively server-side: when a Stripe payment succeeds, our backend reads the stored gclid and uploads it to Google Ads as a conversion event. This allows us to reconcile which ad click led to which paid session, purely for billing reconciliation and contract attribution — it is not used for behavioural profiling.
This capture is not gated by the cookie banner. It is necessary for the performance of the contract you enter when you pay for a session. Legal basis: Art. 6(1)(b) GDPR (contract performance).
In this layer, Google acts as data controller for its own purposes (operating the Google Ads platform) and as joint controller with us for the conversion measurement, per Google's Ads Data Processing Terms.
Analytics (Google Analytics 4)
This website uses Google Analytics 4 (property G-26S9ZP7FJ0), loaded site-wide under Google Consent Mode v2.
By default — before you make a choice on the cookie banner — all storage classes (ad_storage, ad_user_data, ad_personalization, analytics_storage) are set to denied. In this state GA4 sends only cookieless, aggregate "modeled conversions" pings; no persistent identifiers (_ga, _ga_* cookies) are set, and no cross-site tracking occurs.
If you click Accept all on the cookie banner, all storage classes are promoted to granted. GA4 then sets full identifiers and begins session-level analytics. If you click Reject all, the denied defaults remain in force for 12 months.
IP addresses are anonymized before storage. Data retention in Google Analytics is set to 14 months. Legal basis: Art. 6(1)(a) GDPR (explicit consent). You can withdraw consent at any time by clicking "Manage cookies" in the page footer.
Cookie and storage inventory
The following cookies and storage entries may be set on relateto.ai:
| Cookie / Storage | Set when | TTL | Purpose | Legal basis |
|---|---|---|---|---|
_gcl_aw_relateto (1st-party) | Landing page load with ?gclid= | 90 days | Paid-advertising click attribution → billing reconciliation | Art. 6(1)(b) |
relateto_gclid (sessionStorage) | Landing page load with ?gclid= | Session | Same as above, in-page state | Art. 6(1)(b) |
_relateto_consent (1st-party) | Banner accept or reject | 12 months | Remember consent choice | Art. 6(1)(c) |
_ga (1st-party, set by Google) | Banner accept | 24 months | GA4 client identifier | Art. 6(1)(a) |
_ga_<container> (1st-party, set by Google) | Banner accept | 24 months | GA4 session state | Art. 6(1)(a) |
_gcl_au (1st-party, set by Google, future) | Banner accept | 90 days | Google Ads conversion linker | Art. 6(1)(a) |
Stripe's cookies (__stripe_mid, __stripe_sid) are set on checkout.stripe.com — a separate domain operated by Stripe as an independent data controller and sub-processor. These cookies are outside the scope of the relateto.ai cookie banner.
Technical security measures (Art. 32 GDPR)
We implement the following measures to protect your data:
- All connections are forced to HTTPS — HTTP requests are automatically redirected
- HTTP Strict Transport Security (HSTS) is enabled with a 1-year max-age, including subdomains and preload
- TLS 1.2 is the minimum supported version; TLS 1.3 is enabled
- SSL operates in strict mode with full origin certificate validation
- X-Content-Type-Options: nosniff is set to prevent MIME-type sniffing
- Access to staging environments is restricted via Cloudflare Access (identity-based authentication)
- Administrative access requires two-factor authentication
- Email delivery uses encrypted TLS connections (SMTP over TLS 1.2+)
Your rights under GDPR
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Correction of inaccurate data (Art. 16)
- Deletion of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time where processing is consent-based (Art. 7)
To exercise any of these rights, contact: contact@relateto.ai
Right to lodge a complaint
You have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde):
Wickenburggasse 8, 1080 Wien
dsb@dsb.gv.at · dsb.gv.at
Changes to this policy
This privacy policy may be updated as the service evolves. The current version is always available at this URL. Last updated: 29 April 2026.