1. Scope and purpose of this policy
This Privacy Policy applies to the public website at qusmos.com, including its publication and blog pages, general contact form, and demo-access form. It describes the nature, scope and purposes of processing personal data through the website and explains the rights of the people whose data is processed.
“Personal data” means information relating to an identified or identifiable natural person. “Processing” covers any operation involving personal data, such as collecting, recording, storing, using, disclosing or deleting it.
2. Controller
The controller responsible for deciding why and how personal data is processed through this website is:
Dr. Hamzeh Alavirad
QUSMOS project
Douglasstraße 36
76133 Karlsruhe
Germany
Email: h.alavirad@qusmos.com
QUSMOS is currently a project name and is not an incorporated or registered company. Dr. Hamzeh Alavirad is therefore identified as the individual controller of this website.
3. Categories of personal data
Depending on how you use the website, we may process:
- Technical and usage data: IP address, request date and time, requested page or file, referrer URL, HTTP status, data volume, browser type and version, operating system, device information and internet service provider.
- General enquiry data: name, email address, message and any other information you voluntarily include.
- Demo-request data: first name, last name, company, email address, optional telephone number, message and any other information you voluntarily include.
- Communication data: correspondence history, requested follow-up, and information needed to respond to or manage a possible business relationship.
- Consent and preference data: records showing whether and when consent was provided or withdrawn, where consent is used.
Please do not submit confidential information or special categories of personal data—such as health, biometric, political or religious information—unless it is genuinely necessary and you have agreed the appropriate communication method with us.
4. Website hosting and server log files
When you visit this website, the web server processes technical data needed to establish the connection, deliver the requested content, maintain the website, detect faults, and protect the website and underlying systems against misuse or attacks.
The categories of log data may include the technical and usage data listed in section 3. We do not use ordinary server log information to identify a visitor unless this is necessary to investigate a security incident, misuse or a legal claim.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and efficient operation of the website, troubleshooting, and the protection of our systems and users.
The website is hosted by IONOS SE, which processes hosting data on our behalf. For its WebHosting service, IONOS states that visitor information, including the IP address, is anonymised when collected and retained for eight weeks. IONOS also states that this visitor data is not transferred to a country outside the European Union. IONOS may perform anonymised SiteAnalytics processing as part of the hosting service.
5. General contact form and email enquiries
The general contact form currently asks for your name, email address and message. If you contact us through that form or directly by email, we process the information you submit, the time of the communication, and any technical information required to transmit and protect the form.
We use this data to understand and answer your enquiry, communicate with you, prevent misuse of the form, and document the communication where necessary.
If the enquiry is intended to enter into or perform a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interests are responding to communications addressed to us, developing professional relationships, and keeping an appropriate record of the correspondence.
6. Demo-access requests
The demo-access form currently requests your first name, last name, company and email address. A telephone number and message may also be provided. We use this information to assess your request, contact you, prepare a relevant demonstration, arrange follow-up discussions, and manage a possible pre-contractual or business relationship.
Processing needed to respond to a demo request or take steps at your request before entering into a contract is based on Article 6(1)(b) GDPR. Where the request does not relate to a potential contract, processing is based on Article 6(1)(f) GDPR. Our legitimate interests are presenting the QUSMOS project, evaluating genuine business enquiries, and protecting the form against misuse.
The forms are provided using the Otter Blocks plug-in for WordPress. Valid submissions are stored in the WordPress database before delivery actions are performed. Depending on the form configuration, a submission may also be sent as an email notification to the configured QUSMOS recipient. Website and database storage is hosted by IONOS.
Email addressed to @qusmos.com, including form
notifications sent to a QUSMOS mailbox, is received and processed
using Google Workspace, provided in the European Economic Area by
Google Cloud EMEA Limited.
Enquiry and demo-request data is retained only for as long as necessary to respond, manage the requested follow-up, and document a possible business relationship. It is then deleted unless a contractual relationship develops, a legal retention obligation applies, or continued storage is necessary to establish, exercise or defend legal claims.
7. Matchmaker (AI assistant)
We offer a “Matchmaker” on our website. You describe an operational decision in your own words, the assistant asks a small number of follow-up questions, and it then indicates whether the problem looks suitable for a conversation with us. Use of it is voluntary and requires no account.
We process the free-form text you submit, the replies the assistant returns, and a short technical record of the exchange, namely the number of turns, the number of questions asked and the assessment reached. We store no IP address, device details, cookie or other identifier alongside a conversation, so the record contains nothing identifying you other than what you write yourself. Please do not enter personal data about yourself or others: the Matchmaker is designed to discuss an operational problem and does not need it.
To generate the replies, your text is transmitted to OpenAI, which processes it on our behalf under an Article 28 GDPR agreement; see the sections on recipients and on international data transfers below. Under OpenAI’s terms for its business interfaces, data submitted this way is not used to train its models unless we opt in, which we have not, and is retained by OpenAI for a limited period, currently up to 30 days, in order to detect misuse.
We also record conversations in order to improve the Matchmaker, in particular to understand whether it interpreted problems correctly, whether its questions were useful, and whether its assessments are appropriate. Within 30 days we use an automated process to remove or replace identifying details, and the original text is then deleted as described under “Retention and deletion” below. Two limitations should be stated openly: that removal is performed using the same service provider, so it reduces what we retain but does not avoid the transmission described above; and a description of an operational process can allow conclusions about the organisation concerned even once names are removed. We therefore treat the processed text as pseudonymised rather than anonymous and continue to apply this policy to it. Only aggregate statistics permitting no conclusion about any individual or organisation are treated as anonymous.
Processing your submission in order to respond to it and operate the feature is based on Article 6(1)(b) GDPR where it takes place at your request before entering into a contract, and otherwise on Article 6(1)(f) GDPR. Recording and analysing conversations in order to improve the Matchmaker is based on Article 6(1)(f) GDPR. Our legitimate interests are responding to enquiries directed to us, operating the feature securely, and improving an assistant offered free of charge.
Because no identifier is stored, we are generally unable to link a conversation to a particular person. Where we cannot identify you within the data we hold, the rights under Articles 15 to 20 GDPR do not apply, in accordance with Article 11(2) GDPR, and we will tell you so if you ask. If you would nevertheless like a conversation removed, or wish to object under Article 21 GDPR, please write to us at the address given in the “Controller” section describing the enquiry and approximately when you made it; where that allows us to identify it with reasonable certainty, we will act on your request.
The assessment produced by the Matchmaker is an informal initial indication of whether a conversation appears worthwhile. It has no legal effect, does not determine whether we will work with you, and is not automated decision-making within the meaning of Article 22 GDPR. Every genuine assessment is made by a person.
8. Email updates and direct marketing
Messages needed to answer an enquiry or arrange a requested demo are not marketing messages. Promotional email is sent only where there is a valid legal basis. Where we rely on consent, processing is based on Article 6(1)(a) GDPR. Consent is voluntary and may be withdrawn at any time with effect for the future by emailing h.alavirad@qusmos.com or using an unsubscribe method provided in the message.
Where direct marketing is permitted on another legal basis, you may object at any time. After an objection, the relevant personal data will no longer be used for direct marketing.
9. Images delivered through Lovable
At the time this policy was reviewed, some images on qusmos.com were
loaded from a lovable.app domain provided by Lovable.
The relevant European provider is Lovable Labs AB.
To display these images, your browser connects directly to Lovable’s infrastructure. Lovable and its service providers may therefore receive technical data such as your IP address, browser information, referring page, requested file, and the date and time of the request.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is displaying and delivering website content efficiently. Further information is available in Lovable’s privacy information.
10. Links to LinkedIn and other external websites
The website contains ordinary links to LinkedIn profiles and may link to other third-party websites. No embedded LinkedIn feed or social-media plug-in was identified when this policy was prepared. A connection to the external provider is generally made only after you choose to follow the link.
The operator of the destination website is independently responsible for its processing. Its own privacy policy applies after you leave qusmos.com. An external link does not by itself mean that we control or endorse the destination provider’s data-processing practices.
11. Cookies and similar technologies
No public analytics, advertising, behavioural-tracking or social media plug-in was identified on the QUSMOS website when this policy was reviewed. WordPress, security measures and form functionality may nevertheless use technically necessary cookies, tokens or comparable storage to provide requested functions, maintain security, balance requests, or prevent forged submissions.
Where storing information on or accessing information from your device is strictly necessary to provide a service you explicitly request, this is permitted under § 25(2) no. 2 TDDDG. If optional analytics, advertising, embedded media, CAPTCHA, marketing or other non-essential technology is added, we will request consent in advance where required, offer appropriate settings, and update this policy.
The technical configuration is reviewed when the website or its plug-ins are changed. If a new service uses non-essential cookies or other device storage, its use and provider will be disclosed here and an appropriate consent choice will be provided before activation.
12. Recipients and service providers
Personal data is made available only to people and organisations that need it for the purposes described in this policy. Depending on the relevant processing, recipients may include:
- IONOS SE as website, WordPress and database hosting provider;
- Google Workspace as the QUSMOS email provider;
- OpenAI as the provider generating the Matchmaker’s replies;
- CRM, scheduling, anti-spam or automation providers, if used;
- authorised QUSMOS project members handling the enquiry;
- professional advisers such as legal or tax advisers; and
- courts, regulators or public authorities where disclosure is legally required.
Service providers acting on our instructions process personal data under appropriate contractual arrangements, including an Article 28 GDPR agreement where required. We do not sell personal data.
13. International data transfers
If a provider processes personal data outside the European Economic Area, the transfer must be supported by a lawful mechanism. Depending on the destination and provider, this may include an adequacy decision of the European Commission, the EU Standard Contractual Clauses, or another safeguard permitted by Chapter V GDPR.
IONOS states that visitor data processed through its WebHosting service is not transferred outside the European Union. Google Workspace may use Google group companies and approved subprocessors in countries outside the EEA. Where such processing involves an international transfer, Google relies on the safeguards described in its Cloud Data Processing Addendum, including adequacy decisions or Standard Contractual Clauses where applicable. Google’s current subprocessor list provides further information.
Text submitted to the Matchmaker is processed by OpenAI in the United States. That transfer is based on the EU Standard Contractual Clauses contained in OpenAI’s data processing addendum, together with the supplementary measures described there. OpenAI’s current subprocessor list provides further information.
14. Legal bases used for processing
Depending on the activity, processing may be based on:
- Article 6(1)(a) GDPR — consent: for an optional activity where you have freely provided specific consent.
- Article 6(1)(b) GDPR — contract or pre-contractual steps: for enquiries and demo requests connected with a possible or existing contractual relationship.
- Article 6(1)(c) GDPR — legal obligation: where processing is required by applicable law.
- Article 6(1)(f) GDPR — legitimate interests: for secure website operation, responding to other communications, preventing misuse, documenting business correspondence and protecting or defending legal claims, provided your interests and fundamental rights do not override those interests.
15. Retention and deletion
We retain personal data only for as long as it is needed for the purpose for which it was collected. We then delete or anonymise it unless continued storage is required by law or is necessary to establish, exercise or defend legal claims.
The applicable period depends on the data and context. Relevant factors include whether an enquiry remains active, whether a business or contractual relationship develops, statutory commercial and tax retention duties, limitation periods, and the need to investigate a security incident. IONOS states that WebHosting visitor data is retained for eight weeks. Enquiry and demo-request data is deleted when the relevant communication and any reasonable follow-up have concluded, unless one of the longer-retention reasons described above applies. Text submitted to the Matchmaker is kept in its original form for a maximum of 30 days and is then deleted irreversibly, whether or not the automated removal of identifying details described in that section has succeeded.
Data deleted from the active WordPress database or webspace may remain temporarily in restricted technical backups until the backup is overwritten. IONOS states that its recoverable webspace backups are available for no more than 14 days.
16. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected with regard to the nature, scope and purposes of processing, the available technology, implementation costs and the risks to individuals.
The website uses HTTPS encryption in transit. Access to personal data should be limited to authorised recipients on a need-to-know basis. No method of electronic transmission or storage can, however, guarantee absolute security.
17. Your data-protection rights
Subject to the conditions and limitations in the GDPR, you may exercise the following rights:
Access and confirmation
You may ask whether we process personal data concerning you and request access to that data and the information required by Article 15 GDPR.
Rectification
You may request correction of inaccurate personal data and completion of incomplete data under Article 16 GDPR.
Erasure
You may request deletion under Article 17 GDPR, for example where data is no longer needed, consent has been withdrawn and no other basis applies, or the data was processed unlawfully. The right does not apply where continued processing is legally permitted or required.
Restriction of processing
You may request restriction under Article 18 GDPR, including while the accuracy of data or the grounds for processing are being checked.
Data portability
Where processing is automated and based on consent or contract, you may have the right under Article 20 GDPR to receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller.
Withdrawal of consent
You may withdraw consent at any time with effect for the future under Article 7(3) GDPR. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise a right, email h.alavirad@qusmos.com. We may need to request information reasonably necessary to verify your identity and protect personal data from unauthorised access.
18. Right to object
If personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
You may object to processing for direct marketing at any time and without giving reasons. Personal data will no longer be processed for direct marketing after such an objection.
19. Right to lodge a complaint
If you believe that processing of your personal data infringes the GDPR, you may lodge a complaint with a competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the alleged infringement.
20. Whether you must provide personal data
You are not legally required to use the contact or demo forms. However, the fields marked as required are needed to transmit and respond to the relevant request. Without the required contact information, we may be unable to answer your enquiry, arrange a demo, or take requested steps toward a possible contract. Optional fields may be left blank.
21. Automated decision-making and profiling
Personal data collected through this public website is not used for decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
22. Changes to this policy
We may update this policy when the website, forms, service providers, processing activities or legal requirements change. The version published on this page is the current version. Material changes affecting an existing processing activity will be communicated where required.
