Privacy policy
Version 1.0 · Last updated: 17 July 2026 · Information under Articles 13 and 14 GDPR
1. Controller and privacy contact
Zaina Jaber, trading as “Televora”
Löher Weg 20, 51545 Waldbröl, Germany
Email: info@televora.de
No data protection officer is currently appointed. Privacy enquiries may be sent to the address above.
2. Website and server logs
When the website is accessed, we process the IP address, time, destination address, referrer, browser/operating-system details, HTTP status and amount of data transferred. The purposes are delivery, stability, error analysis and defence against attacks. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is secure operation. Security logs are generally retained for up to 14 days, or, in the event of a specific incident, until it is resolved and any necessary legal action is completed.
The website and API currently run on IONOS SE infrastructure in Germany. Recipients may include hosting, network and support providers. Details appear in the service-provider register.
3. Contact, demos and sales
Depending on the form, when you contact us we process your name, company/practice, business email address, telephone number, message, requested callback period, technical transmission data and source. The purposes are handling the enquiry, scheduling, pre-contractual communication and abuse prevention. The legal bases are Article 6(1)(b) GDPR and Article 6(1)(f) GDPR for general B2B communication and form security.
Enquiries are generally deleted 12 months after completion. If a contract is formed, relevant communication and master data are retained for its duration and then in accordance with statutory evidence and retention periods. Required fields are necessary to process the request; without them it cannot be submitted.
4. AI sales assistant
The chat is identified as an AI system. When opened, a random session ID is stored in Session Storage. When used, we process messages, language, timestamps, session ID and voluntarily supplied contact details. The system creates a summary and sales classification. The purposes are answering product questions, identifying concrete enquiries and human follow-up. The legal basis is Article 6(1)(b) GDPR for pre-contractual use and otherwise Article 6(1)(f) GDPR; our interest is efficient B2B sales.
Processing currently uses self-hosted Ollama. Chat histories are not used for general model training. Do not enter health data, payment data, secrets or data concerning uninvolved third parties. Chat leads are deleted no later than 12 months after the last interaction where there is no active business relationship; spam may be blocked and stored for a shorter period or, where necessary, longer to prevent abuse.
The classification does not result in a solely automated decision with legal or similarly significant effects within the meaning of Article 22 GDPR.
5. Customer accounts and contract administration
For registration and contracts, we process names, business contact details, company, roles, login identifier, password hash, session data, contract/plan data, invoice and payment status, support communications and accepted versions of legal documents. The purposes are account administration, authentication, contract performance, billing, support, security and evidence. The legal bases are Article 6(1)(b), (c) and (f) GDPR.
Account data is stored for the contract term and a short winding-down period. Invoices and accounting records are generally kept for eight years, certain commercial and organisational records for ten years and business correspondence generally for six years; longer retention may be required for unresolved claims or audits.
6. Platform, players, media and telemetry
Televora is the controller for its own contract, billing and security purposes. Where customers process content or user, patient, visitor or integration data for their own purposes, Televora acts as processor under the DPA.
The platform processes users/roles, tenant and screen IDs, pairing and authentication data, device/software information, IP address, status/heartbeat, location assignment, schedules, playback and interaction events, media, metadata, data sources and support data. Players store device/tenant identifiers, tokens, manifests, schedules and media locally for operation and offline playback. The standard player does not use a camera or sensors to observe people in front of the screen; separate interactive quiz/camera features are not covered by this statement and must be separately assessed and explained before production activation.
7. Integrations and AI creation
When integrations are enabled, only data required for the function is transferred. Canva is used only after an OAuth connection; this may process account identifiers, access tokens, design/template metadata and exports. Self-hosted Ollama/Open Design features remain within the operated environment. If a customer activates an external AI provider such as Anthropic or OpenAI, prompts, brand context and input media may be transferred to that provider; before activation, the provider, region, role and transfer basis will be shown in the service-provider register and product dialogue.
Televora does not use customer content or prompts to train general models unless this is expressly agreed separately. The customer must minimise confidential and personal-data inputs.
8. Cookies, Local/Session Storage and Google Analytics
Necessary storage includes the language setting (cookie, up to 12 months), consent decision (Local Storage, until changed/versioned) and chat session ID (Session Storage, until the browser tab is closed). They support explicitly requested functions; the legal basis for personal-data processing is Article 6(1)(f) GDPR and device access is based on § 25(2)(2) German Telecommunications Digital Services Data Protection Act (TDDDG).
Google Analytics 4 (Google Ireland Limited) is loaded only after voluntary consent. It may process online identifiers, truncated/technical IP information, device/browser data, pages visited and events, and may set cookies. The legal bases are § 25(1) TDDDG and Article 6(1)(a) GDPR. Google may process data through affiliates in the USA; Google LLC participates in the EU-US Data Privacy Framework. Consent may be withdrawn at any time for the future through “Cookie settings” in the footer.
9. Recipients and third countries
Recipients are limited to authorised employees/contractors and contractually bound hosting, email, support, analytics and integration providers. The current list, including purpose, location and transfer basis, appears under Subprocessors and service providers.
Transfers outside the EU/EEA occur only under an adequacy decision or appropriate safeguards, particularly EU standard contractual clauses and supplementary measures. Copies of appropriate safeguards may be requested at info@televora.de.
10. Rights and complaints
- Access, rectification, erasure, restriction and, where applicable, data portability;
- objection to processing based on Article 6(1)(f) GDPR for reasons arising from your particular situation and objection to direct marketing at any time;
- withdrawal of consent with effect for the future.
You may lodge a complaint with a data protection supervisory authority. The authority generally responsible for our registered place is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, ldi.nrw.de.
11. Required information and updates
Information required by law or contract is marked as mandatory. Without it, we may be unable to process an account, contract or enquiry. We update this policy when procedures change; customers will be informed through appropriate channels of material changes.