Privacy Policy
At FizzyFort, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, and protect your information in compliance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Data Controller
The data controller for the processing of your personal data is:
Sebastian Wißmüller
Hauptstraße 3
91741 Theilenhofen
Email: sebastian@fizzyfort.com
2. Data We Collect
We collect the following types of personal data:
2.1 Account and User Information
- Account Information: Name, email address, and password.
- Contact Details: Phone numbers and other contact information you provide voluntarily during conversations.
- Payment Information: Billing address and payment details (processed securely by third-party providers).
2.2 Device and Technical Information
- Device Information: Device type, model, operating system, browser type and version.
- Network Information: IP address (masked for privacy), internet service provider (ISP), connection type.
- Browser Capabilities: Supported features, language preferences, timezone settings.
- Device Fingerprinting: A unique identifier generated from your device configuration for security and analytics purposes.
2.3 Location Information
- Approximate Location: Country, region, city derived from IP address for service optimization.
- Timezone Data: To provide appropriate service hours and response timing.
2.4 Conversation and Usage Analytics
- Chat Interactions: Messages, response times, conversation duration, interface type (text/voice).
- User Behavior: Buying journey stage, communication style preferences, engagement patterns.
- Performance Metrics: System response times, error rates, feature usage statistics.
- Session Data: Visit frequency, returning user identification, activity patterns.
3. Purpose of Data Processing and Legal Basis
We process your data for specific purposes with appropriate legal basis under GDPR Article 6:
3.1 Service Provision and Performance
- Purpose: Provide AI chatbot services, process conversations, manage accounts
- Legal Basis: Contractual necessity (GDPR Art. 6(1)(b)) - necessary for performing our contract with you
- Data: Account information, conversation data, basic usage metrics
3.2 Payment Processing
- Purpose: Process subscription payments, manage billing, prevent fraud
- Legal Basis: Contractual necessity (GDPR Art. 6(1)(b)) + Legitimate interests (GDPR Art. 6(1)(f)) for fraud prevention
- Data: Payment information, billing address
3.3 Device Detection and Security
- Purpose: Prevent fraud, ensure platform security, detect unauthorized access
- Legal Basis: Legitimate interests (GDPR Art. 6(1)(f)) - protecting our systems and users from security threats
- Data: Device fingerprints, IP addresses, browser information
- Balancing Test: Our legitimate interest in security outweighs privacy impact as we use privacy-preserving techniques (IP masking, secure hashing)
3.4 Analytics and Service Improvement
- Purpose: Improve service quality, optimize performance, understand usage patterns
- Legal Basis: Legitimate interests (GDPR Art. 6(1)(f)) - improving our services for all users
- Data: Aggregated usage statistics, response times, conversation analytics
- Balancing Test: Data is anonymized/pseudonymized where possible; benefits to service improvement are proportionate
3.5 Marketing and Communications
- Purpose: Send product updates, marketing materials, newsletters
- Legal Basis: Consent (GDPR Art. 6(1)(a)) - you can withdraw consent at any time
- Data: Email address, communication preferences
4. Data Processing Principles
We adhere to GDPR data processing principles:
- Lawfulness, fairness, transparency: All processing has legal basis and is clearly explained
- Purpose limitation: Data used only for stated purposes
- Data minimization: We collect only necessary data
- Accuracy: We maintain data accuracy and allow corrections
- Storage limitation: Data retained only as long as necessary
- Security: Appropriate technical and organizational measures implemented
- Accountability: We can demonstrate compliance with these principles
5. Data Sharing
We may share your data with:
- Service Providers: Payment processors, hosting providers, and analytics services.
- Legal Authorities: When required by law or to protect our rights.
6. Data Retention
We retain your data only as long as necessary for the purposes outlined in this policy:
- Account Data: Until account deletion + 30 days for processing
- Conversation Data: 3 years for service improvement, or until account deletion
- Analytics Data: 2 years in aggregated/anonymized form
- Device Fingerprints: 1 year for security purposes
- Payment Data: 7 years for tax and legal compliance requirements
- Marketing Consent: Until consent is withdrawn
- Legal Requirements: Longer retention may be required by law
Upon data deletion, we ensure secure destruction using industry-standard methods.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
7.1 Right of Access (Article 15)
You can request a copy of all personal data we hold about you, including processing purposes and recipients.
7.2 Right to Rectification (Article 16)
You can request correction of inaccurate or incomplete personal data.
7.3 Right to Erasure (Article 17)
You can request deletion of your data when processing is no longer necessary, unlawful, or you withdraw consent.
7.4 Right to Restrict Processing (Article 18)
You can request limitation of processing in specific circumstances (e.g., while accuracy is verified).
7.5 Right to Data Portability (Article 20)
You can receive your data in a structured, machine-readable format and transfer it to another service.
7.6 Right to Object (Article 21)
You can object to processing based on legitimate interests or for marketing purposes.
7.7 Right to Withdraw Consent (Article 7(3))
Where processing is based on consent, you can withdraw it at any time without affecting lawfulness of prior processing.
How to Exercise Your Rights
To exercise these rights, contact us at sebastian@fizzyfort.com. We will respond within 30 days. If your request is complex, we may extend this by 60 days with notification.
Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, particularly in your country of residence. For Germany, this is the Federal Commissioner for Data Protection and Freedom of Information.
8. Security Measures
We implement technical and organizational measures to protect your data, including encryption, access controls, and regular security audits.
9. Cookies and Tracking Technologies
9.1 Types of Cookies We Use
- Essential Cookies: Required for basic website functionality (no consent needed)
- Analytics Cookies: Apollo.io tracking for website analytics (requires consent)
- Functional Cookies: Store preferences and settings (requires consent)
9.2 Device Fingerprinting
We use device fingerprinting for security and fraud prevention. This creates a unique identifier based on your device configuration without storing permanent cookies. Legal basis: Legitimate interests for security.
9.3 Your Cookie Choices
You can manage cookies through our consent banner or browser settings. Rejecting non-essential cookies may limit some functionality.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page, and we will notify you of significant updates.
11. Contact Us
If you have questions about this policy, contact us at sebastian@fizzyfort.com.