Thank you for your interest in rillsoft.ai. Below we inform you about the processing of personal data when you visit this website and about your rights under the General Data Protection Regulation (GDPR). The German version of this page is the legally binding one; this English version is a translation and describes the same facts.
rillsoft.ai is a service of Rillsoft GmbH. The website is a static information website. It offers no accounts, no ordering or cloud functions, no contact form, no upload workflow and no AI chat. It can generally be used without actively providing personal data; technically necessary data (such as the IP address in server log files) is, however, processed with every request.
Controller#
The controller within the meaning of the GDPR and other data protection provisions is:
| Address: | Rillsoft GmbH |
| Mollenbachstr. 14 | |
| 71229 Leonberg, Germany | |
| Represented by: | Dimitri Sapunou (Managing Director) |
| Phone: | +49 7152 30725570 |
| E-mail: | [email protected] |
| Website: | www.rillsoft.de |
Further provider details can be found in the legal notice.
Hosting, DNS and TLS via Cloudflare#
The domain rillsoft.ai is registered with Cloudflare. The website is delivered as a static site via Cloudflare Pages; Cloudflare also provides name resolution (DNS) and TLS encryption of the connection. The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, represented for users in the European Economic Area by Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany.
When you access the website, Cloudflare processes on our behalf the server log files listed below and the connection data required for delivery and protection. This is based on a data processing agreement pursuant to Art. 28 GDPR. Cloudflare operates data centres worldwide; processing outside the European Economic Area is possible. For transfers to the USA Cloudflare relies on its certification under the EU-US Data Privacy Framework and on standard contractual clauses. Further information: https://www.cloudflare.com/privacypolicy/.
Server log files#
When the website is accessed, data is automatically collected and stored in server log files. This may include in particular:
- browser type and version
- operating system
- the previously visited page (referrer)
- name of the requested page and amount of data transferred
- date and time of access
- the IP address of the accessing system
This data serves solely the technically correct operation, security and delivery of the website. It is not merged with other data sources or evaluated in relation to individuals. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the secure and stable operation of the website). Log files are stored only as long as required for these purposes.
Local MCP server and third-party AI clients#
The MCP server described on this website is part of the Rillsoft Project software and runs exclusively on the user’s computer. The website establishes no connection to an MCP server, and a visitor’s browser does not reach any MCP server. A visitor’s planning data does not reach Rillsoft GmbH by visiting this website.
An AI assistant that a user connects to their Rillsoft Project is a third-party product. Which data this client transmits to its provider and how it is processed is governed solely by the client’s provider. Rillsoft GmbH makes no commitments in this regard and is not responsible for this processing.
Cookies and local storage#
This website uses only technically necessary means. Settings for display (such as the chosen light/dark mode) and the on-site search are stored in your browser’s local storage. This data remains in your browser and is not transmitted to us.
Web analytics or tracking for marketing or statistical purposes does currently not take place. Should audience measurement be used in the future, it will be described here and, where required, activated only after your prior consent (Art. 6 (1) (a) GDPR). Under no circumstances are prompt contents, API keys, project names or answers of an MCP server collected as website analytics.
Contact by e-mail#
If you contact us by e-mail, the data you provide (such as name and e-mail address) is stored for the purpose of handling your enquiry. It is not passed on for advertising purposes. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures or performance of a contract), otherwise Art. 6 (1) (f) GDPR (legitimate interest in handling enquiries). The data is deleted as soon as it is no longer required for processing and no statutory retention obligations apply.
Links to Rillsoft main domains#
Content on rillsoft.ai refers to https://www.rillsoft.de. This domain is also operated by Rillsoft GmbH; no personal data is transmitted from rillsoft.ai to it when pages of rillsoft.ai are accessed. Only when you follow a link do the privacy notices of the respective target website apply.
Transfer of data to third parties#
Your personal data is transferred to third parties only where there is a legal basis under data protection law, in particular if
- you have expressly consented pursuant to Art. 6 (1) (a) GDPR,
- this is necessary pursuant to Art. 6 (1) (b) GDPR to handle your enquiry,
- a legal obligation exists pursuant to Art. 6 (1) (c) GDPR,
- the transfer is necessary pursuant to Art. 6 (1) (f) GDPR to assert, exercise or defend legal claims, or
- we use service providers as processors pursuant to Art. 28 GDPR (Cloudflare, see above).
Retention period#
We process and store personal data only for the period necessary to achieve the respective purpose or as required by statutory retention obligations. Once the purpose no longer applies or the periods expire, the data is routinely deleted.
Data security#
We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access. TLS encryption is used when delivering the website. Internet-based data transmissions can, however, have security gaps in principle; absolute protection against access by third parties is not possible.
Your rights as a data subject#
Under the GDPR you have the following rights:
- right of access (Art. 15 GDPR)
- right to rectification (Art. 16 GDPR)
- right to erasure (Art. 17 GDPR)
- right to restriction of processing (Art. 18 GDPR)
- right to data portability (Art. 20 GDPR)
- right to object to processing (Art. 21 GDPR)
- right to withdraw consent at any time with effect for the future (Art. 7 (3) GDPR)
To exercise your rights or if you have questions about the processing of your data, you can contact [email protected] at any time.
Right to lodge a complaint with a supervisory authority#
Without prejudice to any other remedies, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection provisions.
Changes to this privacy policy#
We adapt this privacy policy when the legal situation or the actual data processing changes. The current version published here applies.
Version: 8 September 2026