Privacy Policy

Last updated: 16 September 2026

1. General Information

This privacy policy provides information about the processing of personal data in connection with the use of eviral's services.

The processing of personal data is carried out in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection provisions.

Our services include, among other things, solutions in the areas of reputation management, creation and provision of websites, the management of our customers' social media accounts, and AI-supported communication solutions, for example telephone assistant systems.

2. Categories of Personal Data

Depending on the type of use, we process in particular the following categories of personal data.

Customer Data (B2B)

This includes business information provided during registration or use of our services, for example:

  • name
  • company
  • position
  • business address
  • business phone number
  • business email address
  • access data (login / username)
  • contract data
  • tariff information
  • contract terms
  • invoice data
  • internal notes regarding the business relationship

Payment Data

For payment processing, payment-related information may be processed, for example:

  • payment status
  • invoices
  • transaction identifiers

Payment processing may be carried out via payment service providers such as Stripe.

We do not receive full credit card data.

Further information:

https://stripe.com/privacy

Platform Usage Data

This may include:

  • logins
  • configurations
  • used workflows
  • created review requests
  • activities on landing pages
  • browser type
  • IP address
  • device information
  • timestamps
  • technical log data

This data is used for analysis, system stability, and system security.

End-Customer Data of Our Customers

As part of using our services, our customers may process data of their own customers.

This may include:

  • name
  • email address
  • phone number
  • reviews
  • feedback
  • video testimonials
  • reactions of the business owner
  • technical metadata

In these cases, our customers act as controllers within the meaning of the GDPR, while eviral acts as a processor.

Image and Video Material of Our Customers

For the management of social media accounts, our customers provide us with photos and videos from their business.

Persons may be identifiable in this material, for example employees or customers of the respective business, as well as vehicles and licence plates.

We store this material, edit it for publication, add text, subtitles, and speech, and publish the finished posts on our customer's accounts.

Our customer remains the controller for this material. The customer decides which recordings to provide and warrants to us that the persons depicted have consented to publication. In this respect, eviral acts as a processor.

Anyone depicted in a published post who wishes it to be removed should contact the business whose account shows the post. A message to us is equally sufficient, we forward it without delay and remove the post on the customer's instruction.

Once published, the respective platform operators process the content under their own responsibility and partly outside the EU.

Data from Phone Calls (AI Phone Assistant)

As part of our AI-based phone assistance, incoming calls may be processed automatically.

Among other things, the following data may be processed:

  • caller phone numbers
  • call content or call summaries
  • appointment requests or concerns
  • date/time and duration of calls
  • technical connection data

This data is processed exclusively to provide the respective phone service.

If our customers use the phone assistant to communicate with their own end customers, our customers act as controllers and eviral acts as a processor.

Data When Visiting Our Own Website

When www.eviral.de is accessed, our hosting provider processes technically necessary access data in server log files, in particular IP address, date and time, page accessed, volume of data transferred, and browser details. This data is required to deliver the site and to defend against attacks, the legal basis is Art. 6(1)(f) GDPR.

If you send us an enquiry via our contact form, we process the data provided there, namely name, email address, telephone number, and your message, in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR for general enquiries. The enquiry is delivered to our mailbox and additionally stored in a database so that no enquiry is lost. We delete it once it has been dealt with conclusively and no statutory retention obligations apply.

On our booking page we embed the appointment calendar of an external provider. When this page is accessed, a connection to that provider's servers is established, during which your IP address may be transmitted and the provider's cookies may be set, including outside the EU. This does not happen on the other pages of our website.

Data of Our Customers' Website Visitors

As part of the creation or provision of websites, data of website visitors may be processed.

This includes in particular:

  • IP addresses
  • server log files
  • browser information
  • device information
  • data from contact forms
  • usage data of the respective website

The respective website operator is responsible for the content of its website and for processing data of its visitors.

3. Purposes of Processing

Personal data is processed in particular for:

  • provision and operation of our services
  • operation of the reputation management platform
  • execution of automated review requests
  • analysis and display of reviews
  • AI-based response suggestions
  • integration of widgets on websites
  • management of customer accounts
  • billing and payment processing
  • IT security and abuse prevention
  • customer service and support

In addition, data may be processed for:

  • provision and operation of company websites
  • technical provision of hosting services
  • automated processing of incoming phone calls
  • forwarding customer inquiries
  • appointment management
  • creation and publication of social media posts for our customers
  • processing of the image and video material provided for this purpose

For certain functions, AI services of external providers may be used.

4. Legal Bases for Processing

Art. 6(1)(b) GDPR - performance of a contract

Provision of our services, payment processing, and support.

Art. 6(1)(f) GDPR - legitimate interest

Optimization of our systems, IT security, and abuse detection.

Art. 6(1)(c) GDPR - legal obligation

e.g. statutory retention obligations under tax law.

For end-customer data of our customers, the legal basis exists in the relationship between the customer and its own end customers.

5. Recipients of Personal Data

Recipients of personal data may include:

  • hosting and infrastructure providers
  • the provider of the database in which enquiries from our contact form are stored
  • platform providers
  • payment service providers (e.g. Stripe)
  • providers for email delivery, telephony, and messenger services
  • providers for online appointment booking
  • AI service providers
  • tax advisors or authorities within the framework of legal obligations

Data processing agreements pursuant to Art. 28 GDPR are in place with all service providers.

6. Data Transfers to Third Countries

Some service providers may also process data in third countries such as the USA.

An adequate level of data protection is ensured through suitable safeguards, for example:

  • standard contractual clauses under Art. 46 GDPR
  • technical and organizational protective measures

When using WhatsApp, data may be processed via Meta Platforms.

Where posts are published on Instagram, TikTok, or comparable platforms, their operators process the content under their own responsibility after publication, including in third countries.

Further information:

https://www.whatsapp.com/legal/privacy-policy/

7. Storage Period

Personal data is stored only as long as required for the respective purpose or as long as statutory retention obligations exist.

Typical retention periods:

  • contract and payment data: 10 years
  • technical log data: 90 days to 1 year
  • end-customer data: until deletion by the customer or until end of contract

After expiry, deletion or anonymization is carried out.

8. Rights of Data Subjects

Data subjects have the following rights:

  • access
  • rectification
  • erasure
  • restriction of processing
  • data portability
  • objection
  • withdrawal of granted consents

Requests may be sent to the contact details listed below.

9. Right to Lodge a Complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority.

Competent supervisory authority:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia

Kavalleriestraße 2-4

40213 Düsseldorf

10. Obligation to Provide Data

Certain personal data may be required for concluding a contract and for using our services.

Without providing this data, use of the services may not be possible.

11. Data Security

We implement technical and organizational measures to protect personal data, for example:

  • TLS encryption
  • access and authorization concepts
  • secure server locations
  • regular backups
  • security logging
  • system monitoring

12. Cookies and Tracking

Our website uses only technically necessary cookies that are required to operate the site and to store the language selection.

We do not use analytics, tracking, or marketing cookies, no tracking pixels, and no reach measurement tools.

Consent under Section 25(1) TDDDG is therefore not required, which is why our website does not display a cookie banner.

Our booking page is an exception. There, the embedded appointment calendar of an external provider may set its own cookies. If you wish to avoid this, please do not open that page and arrange an appointment by email instead.

13. Changes to This Privacy Policy

We reserve the right to update this privacy policy when necessary.

The current version is available at any time via our website.

Provider / Controller

eviral GmbH

Rheinpromenade 10

40789 Monheim am Rhein

Managing Director: Ömer Özcan

Düsseldorf Local Court, HRB 114450

Email: info@eviral.de