Privacy Policy

This is a convenience translation. The German version is the legally binding version.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection provisions is:

SH Engineering

Owner: Hünkar Sönmez

Wittelsbacherstraße 36

90584 Allersberg

Germany

Email: info@sh-eng.de

2. General information on data processing

As a matter of principle, we process personal data of our users only to the extent necessary to provide a functional website and our content and services. Personal data is regularly processed only with the user’s consent. An exception applies in cases where obtaining prior consent is not possible for practical reasons and the processing of the data is permitted by statutory provisions.

3. Hosting & technical provision

The CE-Copilot web application (frontend, server-side rendering and server log files) is provided via the platform of Railway Corp. (San Francisco, California, USA); delivery takes place preferably via data centres within the EU.

When you access our website, information is automatically recorded in so-called server log files, which your browser transmits automatically. This information comprises:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the file retrieved
  • Volume of data transferred
  • Browser type and browser version
  • Operating system used
  • Referrer URL

This data is collected on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the technically error-free, secure presentation and optimisation of our services. A data processing agreement pursuant to Art. 28 GDPR is in place with Railway; any transfers of data to the USA are safeguarded by the EU-US Data Privacy Framework or standard contractual clauses (Art. 46 GDPR).

We operate the database, authentication and file storage via Supabase (Supabase Inc.). The servers used for this purpose are located within the EU or the EEA. A data processing agreement pursuant to Art. 28 GDPR is also in place with Supabase.

4. Collection of personal data

a) Account data

When you register for CE-Copilot, we collect the following personal data:

  • Email address
  • Name (first and last name)
  • Company (optional)
  • Password (stored in encrypted form)

The legal basis for processing this data is Art. 6(1)(b) GDPR (performance of a contract). Without this data, we cannot perform the contract for the use of CE-Copilot.

b) Registration and sign-in with Google

As an alternative to registering with an email address and password, you can register and sign in with your Google account (“Sign in with Google”). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA). We receive the following data from Google: name, email address, Google account ID and, where applicable, your profile picture. No password is stored with us for this sign-in method.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Using Google to sign in is voluntary; registration with an email address and password is available as an alternative. Insofar as data is processed by Google LLC in the USA, Google LLC is certified under the EU-US Data Privacy Framework. Further information can be found in Google’s privacy policy: policies.google.com/privacy.

c) Usage data

When you use CE-Copilot, we automatically record usage data in order to ensure the functionality and quality of our service:

  • Projects and documents created within the application
  • Time and duration of use
  • Functions and features used
  • Technical error messages

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving our service).

d) Files uploaded by you

As part of individual functions, you can upload files, such as photos for documentation purposes, technical documents and full texts of standards (PDF) licensed by you. We store these files in the file storage of our processor Supabase on servers within the EU or the EEA (see Section 3). Access is technically restricted to your own account (separate access rights per user); we do not make the files publicly accessible and do not pass them on to other users.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract). We do not analyse stored full texts of standards using AI and do not feed them into our public standards database. You can delete uploaded files at any time within the application; when a file is deleted, the associated file is also removed from storage. You are yourself responsible for being entitled to store uploaded content (see Section 12 of the Terms and Conditions).

5. Cookies, consent & audience measurement

a) Strictly necessary cookies

CE-Copilot uses strictly necessary cookies that are required for the operation of the application, in particular session cookies (e.g. sb-…-auth-token) to keep you signed in. These are set on the basis of Art. 6(1)(f) GDPR and Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) (strictly necessary) and do not require consent.

b) Consent for optional cookies

We use optional technologies that are not strictly necessary, in particular the audience measurement described below, exclusively with your prior consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). On your first visit, we ask for this consent via a consent banner. As long as you do not consent, no analytics cookies are set and no analytics service is loaded. You can change or withdraw your decision at any time with effect for the future via the “Cookie settings” link in the footer.

In the banner you can choose between three levels:

  • Accept: audience measurement including anonymised session recording (session replay, see below).
  • Audience measurement only: anonymous usage statistics without session recording; no session replay takes place.
  • Decline: strictly necessary cookies only, no analytics service.

c) Audience measurement with PostHog

With your consent, we use PostHog to analyse the use of our services (e.g. pages visited, functions used) in order to improve CE-Copilot. Only if you additionally consent to the full level (“Accept”) do we also record sessions (session replay) in order to identify usability problems. At the “Audience measurement only” level, no session recording takes place. The provider is PostHog, Inc.; the data is stored and processed in PostHog’s EU cloud on servers within the EU. PostHog uses cookies or comparable technologies for this purpose.

We have configured PostHog in a privacy-friendly manner: during session recording, all inputs and texts are automatically masked so that no entered content (e.g. names, email addresses, document content) is transmitted; only page structure and interaction patterns are recorded. In addition: no personal profiles for anonymous visitors, and your browser’s “Do Not Track” setting is respected.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). A data processing agreement pursuant to Art. 28 GDPR is in place with PostHog. Processing takes place exclusively in PostHog’s EU cloud; no transfer to a third country (in particular the USA) takes place.

6. AI processing (Claude AI)

CE-Copilot uses the AI service Claude from Anthropic (Anthropic, PBC, San Francisco, USA) to analyse and create CE-relevant documents, risk assessments and other content.

When you use AI-assisted functions in CE-Copilot, the data you enter (e.g. machine descriptions, hazard analyses, technical parameters) is transmitted to Anthropic’s servers and processed there. Anthropic processes the data exclusively for the provision of the service (generation of the AI response).

Important notice: your data is not used by Anthropic to train AI models.

We have concluded a data processing agreement with Anthropic that meets the requirements of Art. 28 GDPR. Data is transferred to the USA on the basis of standard contractual clauses (Art. 46(2)(c) GDPR).

The legal basis for the processing is Art. 6(1)(b) GDPR (performance of a contract), as AI processing is a core component of the CE-Copilot service.

Operating instructions in dialogue: if you use the dialogue mode of the operating instructions, we store your chat messages, the AI author’s replies, the fact sheet derived from them and the review findings on a per-project basis in your account so that you can continue and retrace the dialogue. This data is deleted together with the project and forms part of your data subject access. Here too, only the content required for the respective reply (message, project data, chapter texts) is sent to Anthropic.

7. Rights of data subjects

Under the GDPR, you have the following rights with regard to your personal data:

  • Right of access (Art. 15 GDPR): You have the right to request information about the personal data we process about you.
  • Right to rectification (Art. 16 GDPR): You have the right to request without undue delay the rectification of inaccurate personal data or the completion of your personal data stored by us.
  • Right to erasure (Art. 17 GDPR): You have the right to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression, for compliance with a legal obligation or for reasons of public interest.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of the processing of your personal data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format.
  • Right to object (Art. 21 GDPR): You have the right to object at any time to the processing of your personal data where the processing is based on Art. 6(1)(e) or (f) GDPR.
  • Right to withdraw consent (Art. 7(3) GDPR): You have the right to withdraw consent you have given at any time with effect towards us. The lawfulness of processing carried out on the basis of the consent until its withdrawal is not affected.
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The competent supervisory authority is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA).

To exercise your rights, please contact: info@sh-eng.de

8. Disclosure of data to third parties

Your personal data is not transferred to third parties for purposes other than those listed below. We pass on your personal data to third parties only if:

  • you have given your express consent pursuant to Art. 6(1)(a) GDPR,
  • the disclosure is necessary pursuant to Art. 6(1)(f) GDPR for the establishment, exercise or defence of legal claims,
  • there is a legal obligation pursuant to Art. 6(1)(c) GDPR, or
  • this is necessary for the performance of the contract pursuant to Art. 6(1)(b) GDPR.

We currently use the following service providers as processors:

  • Supabase Inc.: hosting, database, authentication
  • Anthropic, PBC: AI processing (Claude AI)
  • IONOS SE: email dispatch via SMTP (transactional emails, contact enquiries); German provider
  • Railway Corp. (USA): hosting & delivery of the web application
  • Stripe Payments Europe, Ltd. (Dublin, Ireland) or Stripe, Inc. (USA): payment processing
  • PostHog, Inc. (EU cloud, servers in the EU): audience measurement/web analytics, only with your consent

Insofar as processors process personal data outside the EU or the EEA (in particular in the USA), an adequate level of data protection is ensured by the EU-US Data Privacy Framework and/or the conclusion of EU standard contractual clauses (Art. 46 GDPR). Data processing agreements pursuant to Art. 28 GDPR are in place with all of the service providers named.

9. SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the padlock symbol in your browser bar. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

10. Retention periods

Personal data is stored only for as long as is necessary for the respective processing purpose. After the end of the contractual relationship, your data is deleted unless statutory retention obligations exist.

In particular, the following periods or criteria apply to individual categories of data:

  • Server log files: stored only for the period necessary to ensure security and operational stability; deletion or anonymisation takes place regularly, at the latest after 30 days.
  • Audience measurement (PostHog): the analytics data is automatically deleted after expiry of the retention period configured in the analytics service.
  • Contact enquiries: deletion as soon as the enquiry has been finally dealt with and no statutory retention obligations stand in the way.
  • Account and contract data: deletion after the end of the contractual relationship, subject to the statutory retention obligations set out below.

Statutory retention obligations exist in particular under:

  • German Commercial Code (HGB): 6-year retention obligation for commercial letters (Section 257(4) HGB)
  • German Fiscal Code (AO): 10-year retention obligation for accounting records, invoices and documents relevant for tax purposes (Section 147(3) AO)

After expiry of the statutory retention periods, your data is deleted without undue delay.

11. Contact & email dispatch

If you contact us via the contact form or by email, we process the data you provide (name, email address, company and telephone number where applicable, and the content of your message) in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). This data is deleted as soon as it is no longer required to achieve the purpose and no statutory retention obligations stand in the way.

For sending transactional emails (e.g. registration confirmation, password reset) and contact enquiries, we use the SMTP service of IONOS SE (Elgendorfer Str. 57, 56410 Montabaur, Germany).

Transactional emails are necessary for the performance of the contract (Art. 6(1)(b) GDPR). Emails relating to contact enquiries are sent on the basis of your consent (Art. 6(1)(a) GDPR) or for the implementation of pre-contractual measures (Art. 6(1)(b) GDPR).

When emails are sent, your email address and, where applicable, your name are processed via the IONOS SMTP servers. The servers are located in Germany.

12. Payment processing

If paid services are used, payment processing is carried out via Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland; for certain processing operations Stripe, Inc., USA). In the course of payment processing, the data required for this purpose (e.g. name, email address, billing address, payment information) is transmitted to Stripe.

This data is processed on the basis of Art. 6(1)(b) GDPR (performance of a contract). Your complete payment data (e.g. credit card numbers) is processed exclusively by Stripe and is not accessible to us. Any transfers of data to the USA are safeguarded by the EU-US Data Privacy Framework.

13. Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy so that it always complies with the current legal requirements or in order to implement changes to our services in the Privacy Policy. The new Privacy Policy will then apply to your next visit.

Last updated: July 2026