With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and in external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: February 26, 2026
The AI SHIFT Consulting is a brand of
Umbrella Holding UG (haftungsbeschränkt)
Rosenstraße 13
92648 Vohenstrauß
Germany
Managing Director: Patrick Meier
Email address: contact@the-ai-shift.consulting
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects.
Relevant legal bases under the GDPR: The following provides an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR, national data protection regulations may apply in your or our country of residence or domicile.
National data protection regulations in Germany: In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz — BDSG).
We use cookies and similar technologies that store or retrieve information on your device (e.g. cookies, local storage). The legal basis for this is § 25 TDDDG. Technically necessary technologies are used to provide the website; all others only on the basis of your consent.
You can withdraw or adjust a given consent at any time via the cookie settings. The lawfulness of processing until revocation remains unaffected.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing.
Securing online connections via TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology.
Vercel BotID / Bot Protection (Abuse and Fraud Prevention)
We use security features provided by Vercel (Vercel Inc.) on our website, specifically "BotID" and "Bot Protection", to detect and block automated access (bots) and to ensure the stability and security of our online offering (e.g. protection against spam via forms, credential stuffing, scraping or DDoS-like access patterns).
The following technical usage and connection data may be processed:
Legal basis: Legitimate interest in the secure provision of the website and protection against abusive access (Art. 6 para. 1 lit. f GDPR).
Service provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.
Third-country transfer: Processing in the USA cannot be excluded. Where data is transferred to third countries, this is done on the basis of legal requirements (e.g. EU standard contractual clauses).
Further information: Vercel Privacy Policy
Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), this is always done in compliance with legal requirements.
For data transfers to the USA, the EU-U.S. Data Privacy Framework (DPF, adequacy decision of the EU Commission dated 10.07.2023) may serve as a basis depending on the provider. In addition or alternatively, we conclude standard contractual clauses with the respective providers. Further information on the DPF and the list of certified companies can be found at: https://www.dataprivacyframework.gov/
We delete personal data that we process in accordance with legal requirements as soon as the underlying consent is revoked or no further legal basis for processing exists.
Retention and deletion of data: The following general retention periods apply under German law:
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, arising in particular from Art. 15 to 21 GDPR:
We process users' data to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the contents and functions of our online services to the user's browser or device.
Further information on processing operations:
Collection of access data and log files
Access to our online offering is logged via server log files. The server log files may include the address and name of web pages accessed, date and time of access, data volumes transferred, browser type and version, operating system, referrer URL and IP addresses. Log file information is stored for a maximum of 30 days and then deleted or anonymized.
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Vercel
Services in the field of information technology infrastructure (e.g. storage space and/or computing capacity).
Service provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Website: https://vercel.com
Privacy policy: https://vercel.com/legal/privacy-policy
Data Processing Agreement: https://vercel.com/legal/dpa
Basis for third-country transfers: Standard Contractual Clauses (https://vercel.com/legal/dpa).
Vercel Analytics
Privacy-friendly website visit statistics without cookies or cross-site tracking; page requests, referrers and aggregated usage data are processed.
Service provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Privacy policy: https://vercel.com/legal/privacy-policy
Basis for third-country transfers: Standard Contractual Clauses.
Sentry (Error Logging / Monitoring)
We use Sentry to monitor stability and analyse errors (e.g. to detect and resolve technical errors and improve the reliability of our website). The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in the secure and error-free provision of our online service).
In the event of an error, technical data may be processed, including IP address (where applicable truncated or pseudonymised), device/browser information, timestamps, affected page/request information and diagnostic data required for error analysis. Content from input fields or form data is only processed if technically transmitted in the error context; we minimise this through appropriate configuration.
Service provider: Functional Software, Inc. (Sentry), 132 Hawthorne Street, San Francisco, CA 94107, USA.
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Privacy policy: https://sentry.io/privacy/
Basis for third-country transfers: Standard Contractual Clauses.
When contacting us (e.g. via contact form or email) and in the context of existing user and business relationships, the information of the persons making enquiries is processed insofar as this is necessary to respond to the contact enquiries.
Further information:
Contact form
When contacting us via our contact form or email, we process the personal data transmitted to us in order to respond to and process the respective request. We use this data exclusively for the purpose of communicating with the inquirer.
Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers, including interactive 3D scenes, fonts, an AI voice assistant and a consent management platform.
The integration always requires that the third-party providers of this content process the IP address of users, as without the IP address they could not send the content to the user's browser.
Further information on processing operations:
Google Material Symbols (Fonts CDN)
Display of icon symbols on our website. The font files are retrieved from Google's servers when a page is accessed; Google processes the user's IP address.
Service provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Website: https://fonts.google.com
Privacy policy: https://policies.google.com/privacy
Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Spline (3D Scenes / 3D Viewer)
We integrate interactive 3D scenes from Spline into our website, as these are an essential part of the presentation and user experience of our website. When accessing pages with 3D scenes, a connection is established with Spline's servers; in particular, the IP address and technical device/browser and usage data (e.g. user agent, technical requests/diagnostic data) are processed to deliver and render the 3D content.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a modern, interactive and stable presentation of our online offering).
Note on cookies / device: To the extent that Spline stores or reads information on your device as part of the integration, this is done in accordance with § 25 TDDDG; no consent is required for technically necessary operations, and for others only with consent.
Service provider: Spline Design Inc.
Privacy policy: https://spline.design/privacy
Third-country transfer: Where processing takes place outside the EU/EEA, this is carried out in accordance with the GDPR (e.g. appropriate safeguards).
Cookiebot (Consent Management Platform)
We use Cookiebot as a consent management platform (powered by Usercentrics) to manage and document consents for the use of cookies and similar technologies. In particular, the consent status and the time of your decision as well as technical information (e.g. browser, anonymized IP address) are processed to implement your choices and to comply with statutory documentation requirements.
Legal bases: Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Service provider: Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany.
Website: https://www.cookiebot.com
Privacy policy: https://www.usercentrics.com/privacy-policy/
Data Processing Agreement: Provided by the service provider.
ElevenLabs (AI Voice Assistant / Voice Agent)
Our website offers an optional AI voice assistant (voice agent) based on ElevenLabs voice technology. Use of the voice assistant takes place exclusively on the basis of your explicit consent, which is obtained before the conversation starts; you may withdraw your consent at any time with effect for the future by ending the conversation or not starting a new one. When using the voice assistant, your voice inputs are transmitted live to ElevenLabs and processed there to enable speech recognition and response generation; we do not store any audio recordings or transcripts. Technical connection data (e.g. session ID, timestamps, and where applicable IP address) is also processed to the extent necessary for establishing, conducting and securing the connection.
Device access: To the extent that information is stored on or read from your device for the provision of the voice assistant (e.g. session management), this is done in accordance with § 25 TDDDG on the basis of technical necessity (strictly necessary).
No training: Based on the settings we have configured in our ElevenLabs account, the use of data for training purposes ("Data Use/Training") is disabled.
Legal basis: Consent (Art. 6 para. 1 lit. a GDPR), § 25 TDDDG.
Service provider: ElevenLabs Inc., 169 Madison Avenue, Suite 2895, New York, NY 10016, USA.
Privacy policy: https://elevenlabs.io/privacy-policy
Third-country transfer: Data is transferred to the USA; for this purpose, we have concluded a Data Processing Agreement with ElevenLabs including appropriate safeguards (EU Standard Contractual Clauses).
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, please note that addresses may change over time and please verify the information before contacting us.
This section provides an overview of the terms used in this privacy policy. Where terms are legally defined, their legal definitions apply.