Privacy Policy
This privacy policy applies to the website trusttroiai.eu und trusttroiai.com. A supplementary policy applies to the TrustTroiAI Inspector browser extension at trusttroiai.eu/inspektor-privacy. For the Cronos platform, we will publish a separate policy at trusttroiai.eu/plattform-privacy once the platform becomes publicly available. In the event of a conflict between this policy and one of the more specific policies, the more specific policy prevails.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of personal data on this website is:
TrustTroiAI
Grünewalder Straße 29–31
coworkit (SG-Grünewald)
42657 Solingen
Germany
Contact for data protection matters:
Email: privacy@trusttroiai.eu
General contact: hallo@trusttroiai.eu
Data Protection Officer
We have not appointed a data protection officer. Under Section 38 of the German Federal Data Protection Act (BDSG), a data protection officer only needs to be appointed if, as a rule, at least 20 persons are permanently engaged in the automated processing of personal data. We do not reach this threshold. No obligation arises under Article 37 GDPR either, as we do not carry out regular and systematic monitoring of data subjects on a large scale and do not process special categories of personal data on a large scale. Please address data protection enquiries directly to privacy@trusttroiai.eu.
Principles and scope of processing
This website is an information and contact site. It does not require a user account, sign-in, or payment. We process personal data only where this is necessary to provide the website and its functions, or where you actively submit data to us, for example via a form. We do not process special categories of personal data and do not carry out automated decision-making. Persons under the age of 16 are not part of our audience; we do not knowingly collect data from minors.
Hosting
Description. This website is hosted by Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) via the Cloudflare Pages service. When the website is accessed, Cloudflare processes technically necessary access data, in particular the IP address, in order to deliver the site and to ensure security and availability.
Legal basis. Article 6(1)(f) GDPR (legitimate interest in the secure and efficient operation of the website).
Purpose. Delivery of the website, security, defence against attacks.
Third-country transfer. Cloudflare is based in the United States. See Section 13 for the transfer safeguards.
Server log files
Description. Each request automatically generates access data stored in server log files: the IP address, date and time of access, the page requested, the volume of data transferred, the browser and operating system used, and the previously visited page (referrer). We do not merge this data with other sources and do not use it to identify individuals.
Legal basis. Article 6(1)(f) GDPR.
Purpose. Technical delivery, error analysis, defence against attacks.
Retention. 14 days, after which the log files are automatically overwritten or deleted.
Right to object. You may object to this processing under Article 21 GDPR. As the processing is essential for the technical provision of the website, an objection would mean that use of the website is no longer possible.
Fonts
This website uses only locally hosted fonts. The font files are served from our own server. There is no connection to third-party servers, in particular not to Google Fonts, and no transmission of your IP address to third parties for the purpose of font rendering.
Analytics
Description. To improve our service, we use Cloudflare Web Analytics. This analytics service works without cookies and without cross-device recognition. It produces aggregated statistics that cannot be traced back to individual persons, such as page views and approximate regions of origin. No profiles are created.
Legal basis. Article 6(1)(f) GDPR (legitimate interest in privacy-preserving measurement of reach).
Purpose. Needs-based design and continuous improvement of our service.
Retention. Only aggregated statistics; no personal data is stored.
Right to object. You may object to this processing under Article 21 GDPR by sending a message to privacy@trusttroiai.eu.
Contact and Information Security Officer form
Description. When you use our contact form or Information Security Officer (ISO) form, we process the data you provide in order to handle your enquiry. We collect: first name, last name, email address, telephone number, role, and your message. The mandatory fields are required to process the enquiry. For sending and delivering these messages, we use the service provider Resend (Plus Five Five, Inc., USA). Notification of your enquiry reaches us at hallo@trusttroiai.eu.
Legal basis. Article 6(1)(b) GDPR (performance of pre-contractual measures or of a contract) and Article 6(1)(f) GDPR (legitimate interest in responding to enquiries). Optionally, you may consent to receiving further information from us; the legal basis in that case is Article 6(1)(a) GDPR. This consent is voluntary, separate from the enquiry, and not a condition for processing it.
Purpose. Handling your enquiry and, subject to separate consent, sending further information.
Retention. Enquiry data is kept until the enquiry has been finally handled and for a further six months to respond to follow-up questions. Data processed on the basis of consent is kept until consent is withdrawn.
Right to object and to withdraw consent. You may withdraw any consent you have given at any time with effect for the future, for example by email to privacy@trusttroiai.eu. The lawfulness of processing carried out until the withdrawal remains unaffected.
Third-country transfer. Resend is based in the United States. See Section 13.
Request of the ENISA Playbook Compass
Description. On the results page of the CRA Quick-Check, you may request the ENISA Playbook Compass. To do so, you provide your email address and give explicit consent. Delivery takes place via Resend.
Legal basis. Article 6(1)(a) GDPR (consent).
Purpose. Sending you the Compass and, unless withdrawn, informing you of updates.
Retention. Until you withdraw your consent, at most 24 months from the date of the request.
Withdrawal. You may withdraw your consent at any time with effect for the future, for example by email to privacy@trusttroiai.eu.
Booking a call
In selected places we offer the option to arrange a call via a link. This link leads to Google Calendar, a service of Google Ireland Limited. Only when you actively click the link and book an appointment there will your details be processed by Google. This is an external service with its own responsibility for processing; there is no embedding and no automatic data transfer merely by visiting our website. Google's privacy terms apply.
Local storage in your browser
Description. For selected functions we store small amounts of information locally in your browser (localStorage). This concerns the state of the cookie notice, so it does not reappear on every visit, and your progress in the CRA Quick-Check, so that you can pause and resume it. This information remains solely on your device and is not transmitted to us.
Legal basis. Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) — strictly necessary for the provision of the service you have expressly requested.
Purpose. Resumability of the Quick-Check; one-time display of the cookie notice.
Retention. Until you remove the data yourself. You can delete it at any time in your browser settings or, in the case of the Quick-Check, via the "Clear answers" button inside the application.
Cookies
This website does not use non-essential cookies and does not use tracking or marketing cookies. No cookies are set for analytics or advertising. A consent banner for the selection of non-essential cookies is therefore not required; we merely inform you about our data-minimising approach.
Recipients and transfers to third countries
Recipients of personal data are exclusively the service providers named above: Cloudflare for hosting and analytics, and Resend for email delivery. Both providers are based in the United States, meaning a transfer to a third country takes place. We do not disclose your data to other third parties unless we are legally required to do so.
As the basis for the third-country transfer we rely on the Standard Contractual Clauses under Article 46(2)(c) GDPR. Where providers are certified under the EU–U.S. Data Privacy Framework, this complements the Standard Contractual Clauses. Additional technical and organisational measures by the providers apply.
Retention
We process personal data only for as long as is necessary for the respective purposes. The specific retention periods are stated with the individual processing operations in this policy. In addition, statutory retention obligations apply, in particular the commercial and tax retention periods of six or ten years pursuant to Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO).
Your rights
Under the GDPR you have the following rights against us:
- Access (Article 15 GDPR) — which data we process about you
- Rectification (Article 16 GDPR) — correction of inaccurate data
- Erasure (Article 17 GDPR) — deletion of your data stored with us, unless a statutory retention obligation prevents it
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR) — release of the data you provided in a commonly used, machine-readable format
- Objection (Article 21 GDPR) — against processing based on our legitimate interest
- Withdrawal of consent given (Article 7(3) GDPR) — with effect for the future. The lawfulness of processing carried out until the withdrawal remains unaffected.
To exercise your rights, an informal message to privacy@trusttroiai.eu is sufficient. We will respond without undue delay and at the latest within one month.
Right to lodge a complaint with a supervisory authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Article 77 GDPR), in particular in the Member State of your residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
www.ldi.nrw.de
No automated decision-making
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place on this website. The result of the CRA Quick-Check is calculated exclusively locally in your browser from your own inputs and serves as guidance. Your answers are not transmitted to us.
Data security
We take technical and organisational measures to protect your data. In particular, all connections to this website are encrypted via TLS/HTTPS. Access to the systems on which enquiry data is processed is restricted to a limited group of people and is logged.
Changes to this privacy policy
We update this privacy policy when data processing changes or when legal requirements make it necessary. In particular, this policy will be extended by references to the policies for the TrustTroiAI Inspector and for the Cronos platform once these are published. The version published on this page applies in each case.