Privacy Policy
This page explains what personal data Virtual Marketer processes, why, and what rights you have under the GDPR. It is a translation of the authoritative German-language Datenschutzerklärung.
Controller
SGS Virtual Marketer GmbH
Frankfurter Landstr. 50
61352 Bad Homburg, Germany
Email: info@virtual-marketer.de
What data we process
We process personal data you provide directly (e.g. via contact forms, demo bookings or account registration), technical data generated by using our website and products, and the data you submit to our AI products for processing on your behalf (e.g. prompts, uploaded files, product and catalogue data, and the content generated from them).
Website, server logs and cookies
This website embeds no external tracking, analytics or reach-measurement services, loads no third-party scripts, builds no user profiles for advertising, and sets no analytics or advertising cookies. Fonts, icons, stylesheets and scripts are served from our own server, so opening a page establishes no connection to a third-party server that could receive your IP address. Because no consent-requiring cookies are set, this site needs no cookie banner.
That does not mean no data is recorded. Every request produces a server log entry (IP address, date and time, the address requested, volume of data transferred, referrer, browser and system details). We evaluate these server logs solely for troubleshooting, stability and security monitoring, and abuse prevention – never to analyse the behaviour of individual visitors, for reach measurement, or for marketing. The legal basis is our legitimate interest in the secure and reliable operation of the site (Art. 6(1)(f) GDPR). Logs are deleted once they are no longer needed for those purposes; individual entries are kept longer only where they are needed to investigate a specific security incident.
AI processing & sub-processors
We provide AI-assisted marketing services ("AI as a Service"), generating and editing text, images, video and structured product data. Processing serves the performance of the agreed services, the technical operation of the platform, and the prevention of abuse and fraud. The legal bases are performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR), our legitimate interests in the secure, stable and economical operation of our services (Art. 6(1)(f) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR) and, where required, your consent (Art. 6(1)(a) GDPR). Where we process personal data on behalf of a customer, we do so under a data processing agreement pursuant to Art. 28 GDPR; in that case the customer is the controller.
We use both our own models, developed and operated by us, and infrastructure, models and services from external providers. Those providers are sub-processors within the meaning of Art. 28(2) and (4) GDPR and are disclosed here in accordance with Art. 13(1)(e) GDPR. They currently are:
Infrastructure, hosting and operations
- STRATO AG, Berlin (Germany) – server, storage and email infrastructure.
- Microsoft Azure – cloud infrastructure, storage and computing capacity.
- Google Cloud – cloud infrastructure, storage and computing capacity.
AI models and services
- Anthropic – language and text models for generating and editing content.
- Google – language, image and video models and the associated computing capacity.
- OpenAI – language, text and image models.
- Hugging Face – hosting and execution of open models (model hosting and inference).
The contracting entity is in each case the provider's group company responsible for the service used. We will supply the exact company name and address, and the full current sub-processor list, on request at info@virtual-marketer.de; intended changes are notified to customers as provided for in the applicable data processing agreement.
Data processing agreements under Art. 28 GDPR are in place with every provider named above. For the AI services we use only their business interfaces (API/enterprise offerings), under which the content transmitted is contractually not used to train that provider's models.
Nor do we ourselves use customer data to train models for other customers. Content a customer submits to us is processed for that customer only. It is not used to train or fine-tune our own models for other customers, and it is not fed into any cross-tenant analysis. Customer data is not passed to any third party for the purpose of model training.
We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). AI-generated content is a suggestion and must be reviewed by the user before publication.
Transparency under the EU AI Act
Our AI systems fall under Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI", in force since 27 July 2026). The transparency obligations of Art. 50 of the AI Act have applied since 2 August 2026.
- Notice that you are interacting with an AI system (Art. 50(1)): you are informed clearly and distinguishably, and no later than the time of the first interaction, that you are interacting with an AI system and that the output shown is generated by artificial intelligence (Art. 50(5)).
- Machine-readable marking of generated content (Art. 50(2)): as a provider of generative AI systems we are required to mark their outputs in a machine-readable format and make them detectable as artificially generated or manipulated. We implement this through machine-readable origin and provenance information in the metadata of the generated files. A visible label ("Created by Virtual Marketer AI") can additionally be enabled; a visible label does not replace the machine-readable marking. For AI systems placed on the market before 2 August 2026, Regulation (EU) 2026/1744 provides a transition period until 2 December 2026; we are completing the machine-readable marking for those systems within that period.
- Exception: the marking obligation under Art. 50(2) does not apply where an AI system performs an assistive function for standard editing or does not substantially alter the input data you provide or their semantics.
- Deployer obligations (Art. 50(4)): anyone who publishes text generated or manipulated with our systems in order to inform the public on matters of public interest must disclose that the text was artificially generated or manipulated. The same applies to image, audio or video content constituting a deep fake. That obligation rests with the deployer – our customers – and we provide the notices and labelling functions needed to meet it.
- AI literacy (Art. 4): Art. 4 of the AI Act has applied since 2 February 2025. We take measures to support the AI literacy of our staff and of persons operating our AI systems on our behalf – in particular training, internal guidelines on the use of generative AI, and explicit guidance that output must be reviewed by a human.
Scope of these statements: on our own assessment we operate neither practices prohibited under Art. 5 of the AI Act nor high-risk AI systems within the meaning of its Chapter III, whose application dates were in any case deferred by Regulation (EU) 2026/1744. This section describes the state of our implementation as at the date given below. It is neither a certification nor a conformity assessment by an authority or notified body.
Storage and processing location
This website runs on cloud infrastructure within the European Union, so requests to it are served and processed from an EU data centre. We will name the infrastructure provider on request.
The exact storage and processing location of personal data is determined individually per contractual agreement. Upon request and by separate agreement, SGS Virtual Marketer GmbH will process and store customer data exclusively in Germany or in other data centres within the EU/EEA. Absent such a separate agreement, SGS Virtual Marketer GmbH selects a cost-efficient processing location. Germany-only hosting is therefore an option you can agree with us, not a blanket property of our services.
Transfers to third countries
Some of the providers named above are established, or operate individual processing locations, outside the European Union and the European Economic Area – in particular in the United States. STRATO AG is a German company and operates its data centres in Germany; where the service allows it, we use Microsoft Azure and Google Cloud in European regions. Where a transfer to a third country takes place, we base it either on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), where the recipient concerned is certified under it, or on the European Commission's Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. We apply supplementary measures in addition, in particular encryption in transit and at rest, data minimisation and strict access controls. Where a service allows it, we give preference to processing regions inside the EU/EEA. If an adequacy decision ceases to apply, we rely on Art. 46 GDPR. A copy of the relevant safeguards is available on request.
Virtual Marketer Android app (microphone, camera, voice mode)
Alongside the web interface we offer an Android app. It is a way into the same platform and the same accounts; no account is created in the app – accounts are provisioned by us. Everything above applies to the app as well; the following is in addition.
Device permissions
The app requests two device permissions, and only at the moment you actually use the feature concerned:
- Microphone – for voice mode only. Outside voice mode the microphone is not activated.
- Camera and selection of individual files – only to attach a photo, a picture from the gallery, a PDF or a text file to a message to an agent. The app does not scan your gallery or your device storage; only what you pick yourself in the operating system's own chooser is transmitted.
No location data, contacts, calendar, SMS or call data, and no device or advertising identifiers are processed. The app contains no analytics, crash-reporting or advertising libraries; there is no reach measurement and no tracking. Your credentials – the session token and your tenant's key – are held encrypted in the operating system's key store and deleted when you sign out.
Voice mode: how microphone audio is processed
In voice mode you speak to an agent and receive a spoken answer, so the microphone is recorded while voice mode is running. One of two technical modes is used, depending on what is enabled for your account: a turn-by-turn mode that records one utterance at a time, and a continuously connected mode that transmits in both directions at once.
Transfer to a sub-processor. In both modes the audio is transmitted to our servers and forwarded unchanged to one of the AI model providers named above, which performs speech recognition and speech synthesis. The Art. 28 processing agreements, third-country safeguards and the contractual exclusion of training use described above apply.
The audio is not stored on our servers. It passes through them in memory only; it is not written to any file, object store or database, and no audio content is logged. The agent's spoken answer is played on your device and is not stored either.
On the device, the turn-by-turn mode briefly writes each utterance to a file in app-private cache, because that is the only way the operating system records. The app deletes that file immediately after reading it, and it is never readable by other apps. The continuously connected mode creates no file at all.
The recording is not kept; the words are. In turn-by-turn mode your utterance is converted to text, and that text is the message the agent receives. Like any typed message it therefore becomes part of the stored conversation record. In the continuously connected mode no conversation record is written at all; there the transcript stays in memory for the duration of the exchange only. That difference is not visible on screen; we will tell you which mode your account uses on request.
Camera and attachments
If you attach a photo, an image, a PDF or a text file to a message, the file's content is passed to the agent and therefore to the AI provider. We do not store the content – it is processed in memory and is gone once the answer is produced. The file name, file type and file size are stored as part of the conversation record, so that the record does not conceal that a file was involved. Note that a file name can itself contain personal data.
Conversation records and retention
For every task given to an agent – from the chat, through a webhook or from a schedule – we store a record. It contains your message in full (up to 8,000 characters), the agent's complete answer, the tenant and agent-instance identifiers, trigger, status and timestamps, the metadata of any attached files, and for every tool the agent called its name plus a 200-character extract of the parameters passed. That extract can contain content the agent passed on to a connected system such as a CRM or ERP.
The legal bases are performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in being able to trace automated processes and investigate faults (Art. 6(1)(f) GDPR).
There is currently no automatic retention limit for these records. They are stored indefinitely until they are deleted on request or together with the company account. We state this rather than assert a retention period that does not exist. The records belong to the tenant – the company account – and not to an individual: within a team they are visible to every member of that tenant and cannot be deleted for one team member separately.
Deleting your account
You can delete your account yourself, without installing an app, at https://login.virtual-marketer.de/konto-loeschen. Two things are distinguished there:
- Deleting your user account removes your personal account: first and last name, email address, password hash, two-factor secret, profile picture, usage statistics and the mailbox credentials stored on it. If other people belong to the same company account, its shared data – including the conversation records – remains: it is not yours alone, and one person should not be able to delete their colleagues' data along with their own.
- Deleting the entire company account additionally removes all tenant data: every conversation record, the agents together with their credentials for third-party systems, product catalogues, generated media and campaigns, and the user accounts of all members. This is open to administrators of the company account and to anyone deleting their account as the last remaining member of their tenant. It is the only deletion that reaches the conversation records.
Both deletions are final and are carried out only after an explicit confirmation: you must be signed in, enter a current code from your two-factor app, and type a confirmation phrase. That is deliberately stricter than signing in – a deletion route secured more weakly than the login itself would be a route to taking over other people's accounts. If you no longer have access to your two-factor app, write to info@virtual-marketer.de: we will verify your identity by other means and carry out the deletion for you.
Your rights under the GDPR
- Right of access to your personal data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Right to object: where we base processing on a legitimate interest (Art. 6(1)(f) GDPR) you may object to it at any time on grounds relating to your particular situation (Art. 21(1) GDPR). This expressly includes the processing of your data by the AI services named above. You may object to processing for direct marketing purposes at any time and without giving reasons (Art. 21(2) GDPR). An informal message to us is sufficient.
Contact
For any privacy-related request, contact us at info@virtual-marketer.de.
Last updated: 9 September 2026.
This page is a translation of the German-language privacy policy at /datenschutzerklaerung/, which remains the authoritative version for legal purposes.