Privacy Policy

Responsible

Philipp Weihrauch
Am Pfisterhölzli 34
8606 Greifensee
Switzerland
Telefon: 0041779175678
E-Mail: scriptvoiceai@gmail.com

I. Introduction

In the following statement, the data controller (hereinafter also referred to as ‘we’ or the ‘provider’) informs you about the nature, scope and purposes of the collection, processing and use of your data when you contact the data controller via telecommunications or exchange data with them.

This privacy policy relates in particular to our Script Voice AI app, which is available via the Apple iOS Store and the Google Play Store, and to our other digital services such as company websites, social media profiles and video channels. Where we handle data processing uniformly across the digital services we use, we have summarised the relevant information on the purposes of processing, the applicable legal bases and the retention periods for your benefit. The necessary details regarding the digital services we use and their third-party providers (hereinafter referred to as ‘service providers’) can be found following the summary section.

Your point of contact for all data protection matters is the data controller named above, whom you can contact at the address and using the contact details provided above.

II. Legal basis

We process your personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation), as we store your personal data within the European Union. Where the Swiss Data Protection Act (DSG) applies, data processing is also carried out in accordance with Swiss data protection law. The Swiss Data Protection Act applies where the data processing has an impact in Switzerland. Furthermore, we also comply with the provisions of any national data protection law that may apply to you.

The definitions set out in Article 4 of Regulation (EU) 2016/679 (General Data Protection Regulation) apply.

Legal basis: Consent

The legal basis for the processing of data is Article 6(1)(a) of the General Data Protection Regulation (GDPR) if you have given us your consent. You may withdraw your consent to the processing of personal data at any time. Further information can be found in the section below on data subjects’ rights.

Legal basis: performance of a contract

If the purpose of data processing is to enter into or perform a contract, Article 6(1)(b) of the GDPR serves as the legal basis for the data processing.

Legal basis: Legitimate interests

We are entitled to process your personal data where this is necessary for the purposes of legitimate interests pursuant to Article 6(1)(f) of the GDPR. However, such data processing will not be carried out if your interests or fundamental rights and freedoms, which require the protection of personal data, take precedence. Our legitimate interests include, amongst other things, promoting our business, carrying out advertising activities and ensuring IT security. However, we will always carry out data processing based on our legitimate interests in a manner that is proportionate to the purpose and limited to what is strictly necessary.

You have the right at any time to object to data processing that is necessary to safeguard the legitimate interests of the controller or a third party. Further information can be found in the section below on data subjects’ rights.

Legal basis for fault detection and prevention of misuse

The legal basis for data processing to detect faults or errors in telecommunications systems is Article 6(1)(c) of the GDPR, insofar as action is required for reasons of information security.

Where there are factual indications of the unlawful use of a telecommunications network or service, in particular in the case of unreasonable harassment, we may, in order to protect end-users, process traffic data necessary to detect and prevent the unlawful use of the telecommunications network or service.

Applicability of further legal bases

If, in addition to the General Data Protection Regulation, another data protection law applies to you, its legal bases shall apply to you in addition.

III. Definitions

Definition of user data

User data refers to a user’s personal data that is required for the establishment, content or amendment of a contractual relationship between the service provider and the user regarding the use of digital services.

Definition of cookies

Cookies are small text files that are stored on the user’s device. Cookies always have a validity period, which may be limited to the end of the user’s session (so-called session cookies) or may remain in place for a longer period (so-called persistent cookies). These persistent cookies remain on the user’s device and enable the provider or its partner companies (so-called third-party cookies) to recognise the device on your next visit. You can configure your browser so that you are notified when a cookie is set and can decide on a case-by-case basis whether to accept it, or refuse the setting of cookies in specific cases or in general. If you do not accept cookies, the functionality of the website may be restricted.

Definition of service provider

A provider of digital services (hereinafter also referred to as a ‘digital service provider’) is any natural or legal person who provides their own or third-party digital services, contributes to the provision of such services, or facilitates access to the use of their own or third-party digital services.

Definition of a digital service

A digital service is an information society service, i.e. any service normally provided for remuneration, electronically, at a distance and at the individual request of a recipient. For the purposes of this definition, the term ‘service provided at a distance’ means a service provided without the simultaneous physical presence of the contracting parties; ‘service provided electronically’ means a service which is transmitted from the point of origin and received at the point of destination by means of equipment for the electronic processing (including digital compression) and storage of data, and which is transmitted, relayed and received entirely by wire, radio, optical or other electromagnetic means; “service provided at the individual request of a recipient” means a service provided through the transmission of data in response to an individual request.

Log data consists of usage and traffic data which, for technical reasons, is automatically transmitted from the user’s device to the provider’s server when the user accesses the provider’s website. This data is stored in so-called log files.

Definition of ‘user’

A user is a natural person who uses digital services, in particular to obtain or make information available, such as a person who visits the provider’s website. A user is always a data subject within the meaning of the GDPR.

Definition of usage data

Usage data refers to a user’s personal data that is necessary to enable the use of digital services and to bill for them. This includes, in particular, characteristics used to identify the user, details of the start and end times as well as the scope of the respective use, and details of the digital services used by the user.

Definition of Personal Data

Personal data is any information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Definition of pseudonymisation

Pseudonymisation is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

Definition of processing

Processing means any operation or set of operations which is carried out on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, the alignment or combination, the restriction, erasure or destruction.

Definition of traffic data

Traffic data is data whose collection, processing or use is necessary for the provision of a telecommunications service.

Definition of a website

A website, also known as a web presence, is the presence – grouped under a specific internet address – of a private or commercial provider of digital services on the World Wide Web. A web presence comprises web pages or sub-pages and, optionally, downloadable documents as well as other accessible audiovisual media services.

IV. Our data processing activities and their purposes

1. Processing for the purpose of general business communication

We process the following data in order to be able to communicate with you for business purposes. This includes, for example, responding to your enquiry. If you contact us via the email address, messaging services or telephone numbers provided by us, or if you write to us by post, we will store your data in our data processing systems and process it until the intended purposes have been fulfilled or until the retention periods have expired.

Data collected by us (master data):
– Title, first name and surname,
– Company name,
– Address details (relating to contact and billing addresses) such as street, postcode, town and country,
– Contact details such as telephone number (landline and mobile), fax number and email address,
– Website.

If you send us an email, a message via a messaging service or contact us by telephone, we will process the aforementioned personal data if you expressly provide it to us.

Legal bases

– Your consent,
– our legitimate interests (company presentation, targeted advertising),
– the fulfilment of contractual obligations or the initiation of a contract.

Retention period

Data provided by you will be deleted immediately after your enquiry has been dealt with; if it has not been dealt with, it will be deleted no later than 3 months after the last contact, unless your data is subject to a longer retention period for a separate reason (e.g. the storage of information required for the performance of a contract). The enquiry is deemed to have been dealt with when it is clear from the circumstances that the matter in question has been conclusively resolved.

2. Processing in connection with your use of our website

When you visit our website scriptvoice.eu (hereinafter referred to as the ‘website’), we process the data you provide whilst using the site in order to enable you to use our website. We publish information about our company and our services via the website.

Processing of data for the purpose of monitoring faults and misuse

We analyse log data for the purpose of monitoring faults and misuse. A fault occurs in the event of a malfunction of a digital service. Misuse of a digital service occurs, for example, where there is unreasonable harassment. The measures we take include the analysis of error conditions and system monitoring to detect and prevent system threats.

Data collected by us (traffic data):

– Browser type and version
– Operating system used
– Referrer URL
– Hostname of the accessing computer
– Time of the server request
– IP address

We do not combine this data with other data sources.

Legal basis:
– our legitimate interests (protection of our IT systems)
– Fault monitoring and prevention of misuse

Right to object:

As we process your data on the basis of our legitimate interests, you have the right to object. The collection of data for the provision of the digital service and the storage of data in log files is strictly necessary for its operation and may also be justified on other legal grounds. However, you may exercise your right to object by means of automated procedures using technical specifications, such as when your IP address is anonymised by a VPN provider.

Retention period:

Where data is stored in log files, it will be deleted after 7 days at the latest. Storage beyond this period is possible in accordance with data protection regulations.

3. Use of the iOS app

You can download our app from the iOS App Store and install it on your device. When you use the app, we store the texts, draft translations, transcripts, templates, images, videos and other content you provide on your device. Furthermore, your device establishes a data connection to our servers and transmits the data you have saved to our server in order to generate texts using artificial intelligence. Your device establishes data connections to our servers for the download and upload of texts.

Data collected by us (inventory data):

 


– Customer number
– User’s app ID
– Email address
– First name and surname
– App data (including app version)
– Contractual data (including credits, start date of the contractual relationship, date of last login, total number of texts generated, number of texts generated per month).

Legal basis:

– Your consent
– The fulfilment of contractual obligations

Retention period:
The data you provide will remain stored on your device for as long as is necessary to provide the relevant function.

We will otherwise process your data until the contract ends and will then delete it immediately, unless your data is subject to a longer retention period for a separate reason.

4. Use of the Google Play app

You can download our app via the Google Play Store and install it on your device. When you use the app, we store the texts, draft speeches, transcripts, templates, images, videos and other content you provide on your device. Furthermore, your device establishes a data connection to our servers and transmits the data you have stored to our server in order to generate texts using artificial intelligence. Your device establishes data connections to our servers for the download and upload of texts.

Data collected by us (master data):

– Customer number
– User’s Google ID
– Email address
– First name and surname
– App data (including app version)
– Contractual data (including credits, start date of the contractual relationship, date of last login, total number of texts generated, number of texts generated per month).

Legal basis:

– Your consent
– Fulfilment of contractual obligations

Retention period:

The data you provide will remain stored on your device for as long as is necessary to provide the relevant function.

We will otherwise process your data until the contract ends and will then delete it immediately, unless your data is subject to a longer retention period for a separate reason.

V. Data processing on behalf of a client

1. OpenAI

We use the artificial intelligence provided by OpenAI Ireland Limited, with its registered office at 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (hereinafter ‘OpenAI’), to generate text.

OpenAI may engage further sub-processors to provide its services. The processing of personal data outside the European Union or the European Economic Area cannot be ruled out in this context. In such cases, the transfer takes place on the basis of appropriate safeguards in accordance with Article 44 et seq. of the GDPR.

We have entered into a data processing agreement with OpenAI.
OpenAI Privacy Policy: https://openai.com/de-DE/policies/privacy-policy/

2. Supabase

We use the services of SUPABASE PTE. LTD., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 (hereinafter ‘Supabase’) to provide our database, authentication, storage of user data and technical infrastructure. In particular, user accounts, login details, usage data and user-generated content may be processed in this context. Supabase is configured so that we use its servers in Germany. A transfer to Supabase locations outside the European Union or the European Economic Area, or to sub-processors in third countries, cannot be completely ruled out.

We have entered into a data processing agreement (Data Processing Addendum) with Supabase.
Supabase Privacy Policy: https://supabase.com/privacy

VI. Existence of appropriate safeguards

1.

Pseudonymisation

Where we collect usage data, we always store it under pseudonyms (in the case of cookies, for example, using a unique session key). We do not link pseudonymous data to data relating to the person behind the pseudonym (such as master data).

2. Use of encryption technologies

When data is transferred between your computer or mobile device and our server, we use modern encryption methods (TLS/SSL). This technology is designed to protect your data from being read by unauthorised third parties and offers a very high standard of security. You can tell that your data is being transmitted in encrypted form by the closed key or padlock symbol displayed in the status bar at the bottom of your browser.
*** Translated with

VII. Recipients and further processing

1. Distribution via app stores

Our app is available via the iOS App Store and the Google Play Store. When downloading, installing and using the app, personal data may be processed by the respective platform operators.

Apple iOS App Store

When you download our iOS app via the Apple App Store, personal data is processed by the Apple group of companies. The data controller responsible for this processing is, in particular, Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. The processing is carried out, in particular, for the purposes of providing the App Store, managing user accounts, processing payments, preventing fraud, and ensuring the provision and security of the platform.

Further information on the processing of personal data by Apple can be found in Apple’s Privacy Policy: https://www.apple.com/de/privacy/

Google Play Store

When you download our Android app via the Google Play Store, personal data is processed by the Google group of companies. The data controller for this processing is, in particular, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The processing is carried out in particular to provide the Google Play Store, to manage user accounts, to process payments, to ensure the security of the platform and to prevent misuse.

Further information on the processing of personal data by Google can be found in Google’s Privacy Policy: https://policies.google.com/privacy

2. Other recipients of personal data within the EU

We transfer your data to the following companies when you use our app:

– OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland,

These companies act as our data processors in connection with the use of the app, in particular for data processing relating to the generation of texts. As data processors, they are bound by our instructions.

3. Recipients of personal data in third countries

We process your contact and payment details within the EU or within the European Economic Area.

We transfer your data to the following entities outside the EU or the European Economic Area when you use our app:

– SUPABASE PTE. LTD., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513

This company acts as our data processor in connection with the use of the app, in particular for data processing to generate texts. It operates as a data processor and is bound by our instructions.

When using our services, further personal data may be transferred to recipients in third countries outside the European Union or the European Economic Area. Where this occurs, the transfer is carried out on the basis of appropriate safeguards in accordance with Article 44 et seq. of the GDPR, in particular through the conclusion of standard contractual clauses.

4. Further processing for other purposes

Unless otherwise stated above, your data will not be disclosed to third parties nor will it be further processed for purposes other than those specified.

VIII. Rights of those affected

You have the right:
– pursuant to Article 7(3) of the GDPR, to withdraw your consent at any time. As a result, we may no longer continue to process data on the basis of that consent in future;
– pursuant to Article 15 of the GDPR, to request information about your personal data processed by us. In particular, you may request information regarding the purposes of processing, the categories of personal data, the categories of recipients to whom your data has been or will be disclosed, the intended storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data where it was not collected by us, and the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding its details;
– to request, in accordance with Article 16 of the GDPR, the rectification of inaccurate personal data or the completion of your personal data stored by us without delay;
– to request, in accordance with Article 17 of the GDPR, the erasure of your personal data stored by us, unless processing is necessary for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
– in accordance with Article 18 of the GDPR, to request the restriction of the processing of your personal data, provided that you contest the accuracy of the data, the processing is unlawful but you oppose its erasure and we no longer require the data, but you require it for the establishment, exercise or defence of legal claims, or you have objected to the processing in accordance with Article 21 of the GDPR;
– in accordance with Article 20 of the GDPR, to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller; and
– in accordance with Article 77 of the GDPR, to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority for your usual place of residence or work, or for our registered office.

Right to object

Where your personal data is processed on the basis of legitimate interests pursuant to Article 6(1), first sentence, point (f) of the GDPR, you have the right, pursuant to Article 21 of the GDPR, to object to the processing of your personal data, provided there are grounds for doing so arising from your particular situation.

If you wish to exercise your right to object, simply leave a message by telephone or send an email to scriptvoiceai@gmail.com

Last updated: June 2026

Scroll to Top