EurDesign DG
Privacy notice
Last updated: 23 September 2026. This notice covers our website, our interface for AI agents and the email, fax and telephone communication described here.
1. Controller
EurDesign DGDaniel Delgado
Paulstr. 24
10557 Berlin
Germany
info@eurdesign.com
You can also contact this address with privacy enquiries and requests to exercise your rights.
2. Website, hosting and technical logs
Our server processes technical connection data, including your IP address, to deliver requested pages and files. Registration is not required. Without the data necessary for transmission, the website cannot be delivered.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to make our services accessible online, maintain the website and identify and resolve faults and misuse.
Our server is provided by ORACLE Deutschland B.V. & Co. KG, Riesstraße 25, 80992 München, as our processor (Oracle Cloud Infrastructure, Frankfurt am Main region). Oracle and its subprocessors may process technical data to provide, maintain and secure the infrastructure.
We do not keep a complete access log of every page visited. Our separately maintained web application operational and error logs may contain a timestamp, affected service, error and status information and, in case of a fault, technical connection context. They support diagnosis and security, not visitor profiling. Routine retention is limited to 30 days; older entries are automatically removed. Housekeeping runs regularly, rather than only once a month.
This period applies to the separate web logs we manage. Oracle also describes its own systems operations data, including for infrastructure security and operation, in its Services Privacy Policy. The responsibilities and conditions described there govern that processing and retention; our deletion routine does not control those data.
Shared system and public-entry proxy error logs may also contain technical request data. These logs, including historical entries, are separate from the web application logs and are not covered by their automatic 30-day deletion routine.
We also maintain encrypted external backups and restricted-access maintenance copies for recovery. These can contain earlier versions of operational data, including data deleted from the live system. The manual backup preserves replaced files and files deleted at the source; it currently has no automatic time-based deletion. Deletion in the live system does not immediately delete these copies. Their retention is not covered by the web-log limit above.
3. Cookies, content and our own statistics
We do not embed external analytics or marketing services, or create individual usage profiles. Our website does not set visitor identifiers in cookies, local storage or session storage. Images, videos and fonts are delivered through our own hosting, without embedded external video, map or font services.
Your language preference
When you explicitly choose a language using our language selector, we store that preference in a cookie named __Host-lang. It contains only the selected language code, for example de or es, and no unique visitor identifier. We use it to remember your choice when you return through the website’s language-selection entry point. Opening a URL that explicitly names a language does not by itself change the stored preference; that URL is displayed in its own language.
We now set this preference as a session cookie, without an expiry date or Max-Age. The browser determines when its session ends; session restoration can preserve the cookie after a restart. It is transmitted using HTTPS and has the Secure, HttpOnly and SameSite=Lax attributes. You can select another language or delete the cookie in your browser settings. It is not used for advertising, statistics or individual profiles.
Storing and reading this session preference serves the language choice you expressly requested (section 25(2)(2) TDDDG). Where personal data are processed, the basis is Article 6(1)(f) GDPR; our interest is to provide the requested language consistently during your visit. A language cookie set by the previous version may retain its original expiry of up to one year until you select a language again or delete it.
If the stored language is one we no longer offer, our server deletes the cookie with the next request to the language-selection entry point and shows the page in another available language.
Randomly changing visual elements are selected server-side without an identifier to recognise a returning visitor. External links are accessed only when you open them; the destination provider’s information then applies.
Our own server-side statistics store daily totals of successful page responses completed server-side for a fixed set of pages, error categories and broad time bands until our web application’s response headers arrive. We produce internal summaries by page, division, content language, week and month. This measures neither unique visitors nor full browser loading time; a Contact page request does not establish an enquiry.
Known bots and identified prefetches are filtered; the User-Agent header may be processed temporarily for that purpose. The filter is incomplete. Repeated requests and caches affect the figures. Completion on the server does not confirm receipt or display in the browser.
The statistics store contains no individual access records, IP addresses, visitor identifiers, complete URLs, URL parameters, referrers or User-Agent values. We use no cookies, browser storage, tracking pixels or browser analytics scripts for it. Daily aggregates are kept internally for no more than 365 calendar days; older aggregates are automatically removed. We do not combine them with emails or security logs.
Where personal connection data is temporarily processed for this analysis, the basis is Article 6(1)(f) GDPR. Our interest is to understand content use in aggregate and improve technical operation.
4. Email and fax enquiries and retention
Faxes to +49 30 2232 6113 are received by dus.net GmbH and forwarded directly to our email inbox, without passing through our Oracle server. We process the fax contents and accompanying sender and transmission details to handle your enquiry. The legal bases and retention criteria in this section also apply to fax correspondence in our mailbox. Processing and retention by the telecommunications provider are separate from our web-log deletion routine.
Our email links open your email application. Clicking alone does not send us a message. If you write to us, we process the content and accompanying details, such as email address, name, contact information and attachments, to handle your enquiry.
For contractual enquiries initiated by you, Article 6(1)(b) GDPR applies. For other enquiries and correspondence with representatives of a business, we rely on Article 6(1)(f) GDPR; our interest is to respond appropriately to enquiries about our services.
We use STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, as a processor for email. Correspondence is also handled with an email application on our own work device.
We delete enquiries not subject to statutory retention duties once the matter is closed: when it has been answered conclusively or otherwise resolved and no agreed follow-up or processing steps remain. If it becomes an order, the periods for the relevant contractual and business records apply. Records needed for a specific legal dispute are retained further only for the duration of that purpose.
Records subject to statutory retention are kept under Article 6(1)(c) GDPR. The usual periods are six years for commercial and business correspondence subject to retention duties, and eight years for invoices and accounting vouchers (section 147 AO, section 14b UStG and, where applicable, section 257 HGB), generally starting at the end of the relevant calendar year. Statutory extensions remain applicable. Not every email is subject to these duties. The 30-day period for technical web logs does not apply to this correspondence.
Contacting us is voluntary. Without enough information and a means of replying, we may be unable to deal with your enquiry. Please send only the necessary information.
5. Telephone enquiries and our AI voice assistant
Calls to our telephone number +49 30 2232 6112 are answered by an AI voice assistant that speaks on behalf of EurDesign DG. It provides information about our services, takes your enquiry and passes it to our team. It does not connect you to a person during the call and does not make decisions with legal or similarly significant effects. If you prefer not to speak with the assistant, please write to info@eurdesign.com.
During the call we process your telephone number, if it is transmitted, the time and duration of the call and what you say, including the details you provide, such as your name, company, email address and the content of your enquiry. Your voice is processed in real time so that the assistant can understand and answer you, and a transcript of the conversation is produced. Calls are limited to ten minutes. Calls identified as spam, phishing or fraud are ended.
We do not record calls. Audio is kept only if the assistant offers you the option of leaving a voice message and you accept; you can stop or cancel the message during the call.
Calls reach our server through our telephone provider dus.net GmbH, Kaiserswerther Straße 215, 40474 Düsseldorf. For speech processing and for preparing enquiries, the assistant uses services of OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, as our processor. According to OpenAI, data sent through its API is not used to train its models and may be retained by OpenAI for up to 30 days to provide the service and detect misuse. OpenAI may process data outside the European Economic Area, in particular in the United States; it states that such transfers are based on EU standard contractual clauses or an adequacy decision.
After the call, our server sends a summary of your enquiry, the transcript and any voice message by email to our team; section 4 applies to that email and its retention. When the receiving mail server confirms acceptance, the transcript and audio are deleted from the operational telephone application. This confirms acceptance for delivery, not final receipt in the inbox or that the message has been read. Summary and call details, such as time, duration, telephone number, language and reason, are normally deleted automatically after no more than 30 days, provided mail-server acceptance is confirmed and no associated delivery remains unresolved. Our team also receives a monthly overview by email.
If delivery fails, is uncertain or has not been confirmed, the affected message, attachments and associated processing records are not deleted solely because 30 days have elapsed. They are retained to resolve that specific delivery incident. Deletion requires confirmed mail-server acceptance or a documented individual decision to close the matter after checking whether any further processing or statutory retention is required. Uncertain messages are not automatically resent. This exception does not create a permanent correspondence archive.
For enquiries about our services, the legal basis is Article 6(1)(b) GDPR. Otherwise we rely on Article 6(1)(f) GDPR; our legitimate interest is to answer calls reliably and in the caller’s language, and to prevent misuse. A voice message is recorded on the basis of your consent under Article 6(1)(a) GDPR, which you can withdraw at any time, for example by stopping the message.
6. Interface for AI agents
We offer a read-only interface for AI assistants and agents based on the Model Context Protocol (MCP) at https://mcp.eurdesign.com/mcp. It returns the same public information as this website. It does not use AI models, does not set cookies and does not store the queries it receives.
To answer a request, our server processes technical connection data such as the IP address. The operational and error logs described in section 2 also apply to this interface. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is to make our public information available to AI assistants in a structured form.
7. International processing
The Frankfurt server location does not exclude necessary access outside the European Economic Area, for example for support or recovery. For transfers without an applicable adequacy decision, Oracle describes safeguards including binding corporate rules and EU standard contractual clauses. Information and documents on these safeguards are available in the Oracle data transfer annex and Services Privacy Policy. You may also ask us for information about the safeguards relevant to our processing.
8. Your rights
Subject to the legal conditions, you may request access, correction, erasure and restriction of processing. Data portability under Article 20 GDPR applies in particular to automated processing based on consent or a contract. You may withdraw consent with effect for the future. We do not make solely automated decisions with legal or similarly significant effects through this website or our telephone assistant under Article 22 GDPR.
Objection: You may object to processing under Article 6(1)(f) GDPR on grounds relating to your particular situation. Please contact info@eurdesign.com.
You may complain to a data protection supervisory authority, particularly where you habitually live, work or believe an infringement occurred. The authority for our establishment is the Berlin Commissioner for Data Protection and Freedom of Information.