Privacy Policy

This policy explains how personal data is processed on david-schaupp.com in accordance with the General Data Protection Regulation (GDPR).

1. Data Controller

David Schaupp
Sonntagbergerstrasse 6
3332 Rosenau am Sonntagberg, Austria
Email: schauppdavid@gmail.com

2. Purposes and Legal Bases

Personal data is processed for the following purposes:

  • Handling contact form submissions and communication (Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR).
  • Newsletter subscription management and delivery (Art. 6(1)(a) GDPR, consent).
  • Website security, reliability, and abuse prevention (Art. 6(1)(f) GDPR, legitimate interests).
  • Operating the optional David AI portfolio assistant, retaining conversation context, troubleshooting failed requests, and preventing misuse (Art. 6(1)(f) GDPR, legitimate interests).
  • Aggregated analytics and performance measurement (Art. 6(1)(f) GDPR, legitimate interests).

3. Categories of Data

  • Contact form data: name, email address, and message content.
  • Newsletter data: email address and subscription status.
  • Technical data: IP address, browser and device metadata, request timestamps, and logs.
  • David AI data: messages submitted by the visitor, assistant responses, timestamps, selected suggestion, model identifier, token usage where available, response latency, moderation and rate-limit outcomes, coarse browser/device information, country code, referrer hostname, and a pseudonymous session identifier.

David AI does not store raw IP addresses, raw cookies, complete user-agent strings, authorization headers, API keys, or complete referrer URLs. IP addresses are transformed into short-lived keyed hashes for abuse prevention.

4. Recipients and Processors

Data may be processed by trusted service providers required to operate this website and communication features, including hosting, storage, email delivery, and newsletter tooling. Processing is based on data processing agreements where required by law.

David AI conversation and request records are stored in Neon Postgres. The website and server-side API are operated on Vercel. Chat messages and recent conversation context are sent by the server-side API to OpenRouter, which routes the request to the model provider selected by the website operator. OpenRouter and the model provider receive the message content required to generate a reply, but do not receive the David AI browser-session token or the website's provider API credential as conversation content.

5. International Data Transfers

Where service providers process data outside the EEA, transfers are safeguarded by appropriate mechanisms such as adequacy decisions or Standard Contractual Clauses, as applicable.

6. Retention Periods

Personal data is stored only for as long as necessary for the stated purposes, contractual/legal obligations, or legitimate interests:

  • Contact requests are retained until the inquiry is resolved, then archived only as needed for legal documentation.
  • Newsletter data is retained until consent is withdrawn or the newsletter service is discontinued.
  • Technical logs are retained for security and operational purposes for a limited period.
  • David AI conversations and request metadata are automatically deleted after 30 days. Short-lived pseudonymous IP hashes and expired rate-limit buckets are deleted after they are no longer required for abuse prevention, normally within 7 days.

7. David AI Controls

Before the first message, visitors are shown the storage notice and AI-processing notice and must acknowledge them. While the browser session remains available, the chat interface provides controls to export the current conversation and to delete all David AI conversation and request records associated with that anonymous session. Visitors can also contact the data controller using the address below.

Visitors should not submit confidential information, credentials, special-category personal data, or information about third parties.

8. Your Rights Under GDPR

You have the right to request:

  • Access to your personal data (Art. 15 GDPR).
  • Rectification of inaccurate data (Art. 16 GDPR).
  • Erasure of data (Art. 17 GDPR).
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR).
  • Objection to processing (Art. 21 GDPR).
  • Withdrawal of consent at any time for consent-based processing (Art. 7(3) GDPR).

To exercise your rights, contact: schauppdavid@gmail.com

9. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent supervisory authority. In Austria this is the Austrian Data Protection Authority (Datenschutzbehoerde).

10. Policy Updates

This policy may be updated when legal, technical, or organizational changes require it.

Effective date: August 24, 2026