Privacy Policy
Simon Weuffel
c/o POSTFLEX PFX-456-069
Emsdettener Straße 10
48268 Greven
Germany
hello@fennura.ai
This website uses no tracking, no analytics services and no advertising networks. Personal data is processed when you use the contact form, the risk check or the listening test, email us or book a call, and in the technical server logs. We store contact data in the CRM Brevo. You book calls via Calendly, and we hold them via Zoom. Only in our update emails do we measure, with your consent, whether they are opened.
1. General information
We take the protection of your personal data seriously. This policy explains which data is processed when you visit this website and when you get in touch with us, for what purpose, and which rights you have. The legal basis is the General Data Protection Regulation (GDPR).
Personal data is any information that can be used to identify you personally, such as your name, address, email address or IP address.
2. Hosting
This website is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA ("Netlify"). On our behalf, Netlify processes IP addresses, access times and information about the browser used, among other things, to the extent necessary for the technical operation and security of the website.
The legal basis is our legitimate interest in providing the website securely and reliably pursuant to Art. 6(1)(f) GDPR. We have concluded a data processing agreement with Netlify pursuant to Art. 28 GDPR.
Netlify operates a global content delivery network. Data may therefore be processed on servers outside the European Union, including in the United States. Netlify is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision. In addition, transfers are safeguarded by the European Commission's Standard Contractual Clauses. For more information, see Netlify's privacy policy at netlify.com/privacy.
Server log files
Each time you access the website, information transmitted by your browser is collected automatically:
- page accessed and time of access
- amount of data transferred and whether the request was successful
- browser type and operating system
- shortened or full IP address
- where applicable, the previously visited page
This data is not combined with other data sources and is used solely for technical operation and to defend against attacks. Netlify retains the logs depending on the plan; they are deleted automatically and stored for no longer than 30 days.
3. Contact form, risk check and email
Contact form. When you write to us via the contact form, we process the information you enter: first name, last name, email address, optionally your company, your message and the language of the page. We use this data to handle your request and any follow-up questions. If your request relates to entering into or preparing a contract, the legal basis is Art. 6(1)(b) GDPR. For all other requests, we rely on our legitimate interest in responding pursuant to Art. 6(1)(f) GDPR.
Risk check. When you submit the risk check, we process your name, your email address, optionally your company, the language of the page, your score, your seven answers and whether you would like to receive updates. We store the answers together with your contact details so that we can understand the assessment and reach you as requested.
Before submitting, you confirm that we may contact you about this topic. The legal basis for this contact is your consent pursuant to Art. 6(1)(a) GDPR. We send you the promised guide on the basis of Art. 6(1)(b) GDPR. You can withdraw your consent at any time with effect for the future by sending an informal message to hello@fennura.ai. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Updates. If you select "Get updates" and confirm your subscription via the link in the email (double opt-in), we will occasionally send you updates from Fennura: new schemes involving scam calls with cloned voices, briefly explained, as well as news about Fennura. This includes measuring whether the emails are opened and links are clicked (Section 4). The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). To document your consent, we store the time of subscription and confirmation as well as the IP address used. You can withdraw your consent at any time with effect for the future via the unsubscribe link in every email or by writing to hello@fennura.ai.
Required information. Your name and email address are required so that we can handle your request and reply to you. There is no legal or contractual obligation to provide them. Without this information, however, we cannot process your request.
Transmission and storage at Netlify. Data is transmitted in encrypted form via our hosting at Netlify. Submissions from the contact form and the risk check are stored in Netlify Forms. Netlify automatically stores technical information such as the IP address, browser identifier and the previously visited page. Processing may take place on servers in the United States under the safeguards described in Section 2. Once we have transferred the information to our CRM (Section 4), we delete the submissions at Netlify, at the latest after 30 days.
Spam protection. The forms contain a field that is invisible to visitors to fend off automated spam entries. It does not collect any personal data. In addition, Netlify automatically checks all submissions for spam using the Akismet service of Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. For this purpose, the form entries and technical data such as the IP address and browser identifier are transmitted to Akismet. The legal basis is our legitimate interest in preventing spam and abuse pursuant to Art. 6(1)(f) GDPR. Automattic is certified under the EU-U.S. Data Privacy Framework.
Email. If you email us directly, we process your information accordingly to handle your request. Our mailboxes are operated by Migadu-Mail GmbH, Rohnen 587, 9414 Schachen, Switzerland. Migadu stores and transmits emails on our behalf. The European Commission has recognized that Switzerland provides an adequate level of data protection (Art. 45 GDPR). The legal basis is Art. 6(1)(b) or (f) GDPR as described above.
4. CRM and email delivery via Brevo
We use Brevo as our CRM system and to send our emails. The contracting party for customers based in Germany is Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. The services are provided within the Brevo group, in particular by Sendinblue SAS, 17 rue de Salneuve, 75017 Paris, France.
In Brevo, we store the information from the contact form and the risk check as a contact, separated by form and language. This includes your name, email address, the optional information, the language of your request and, for the risk check, also your score and answers. The purpose is to handle your request, to communicate with you about it and to maintain our customer contacts.
We use Brevo to send the automated reply to your request. This email may include a link to our guide and a button for booking a call. The guide is hosted on this website. When you access it, the technical access data described in Section 2 is processed.
The legal basis is Art. 6(1)(b) GDPR where the communication serves to prepare or perform a contract, and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is the orderly handling of requests and the related customer care. For contact after the risk check and for updates, your consent as described in Section 3 applies.
Open and click tracking. In our update emails, we measure whether an email was opened and which links were clicked. For this purpose, the emails contain an invisible image (tracking pixel) that is loaded from Brevo's servers when you open the email, and links that are redirected via Brevo. On our behalf, Brevo records the time, the IP address and technical information about the email program used. The evaluation can be attributed to individual recipients. We use it to see which topics are of interest and to improve our updates, not to pass data on to third parties for advertising purposes. The legal basis is your consent to the updates (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Unsubscribing also ends the tracking. You can also prevent it by turning off the automatic loading of images in your email program. Our automated replies to contact requests and to the risk check do not use open or click tracking.
We have concluded a data processing agreement with Brevo pursuant to Art. 28 GDPR. Data is processed mainly within the European Union. Where a sub-processor in a third country is used, the transfer is based on the European Commission's Standard Contractual Clauses. For more information, see Brevo's privacy policy at brevo.com/legal/privacypolicy.
Retention. We store your contact in Brevo for as long as we need it to handle your request and for subsequent communication and, if you have consented to updates, until you withdraw your consent. We delete contacts without consent to updates no later than three years after the last contact, unless statutory retention obligations apply. If you unsubscribe from the updates, we keep your email address on a suppression list so that you do not receive any further updates. You can request deletion at any time via hello@fennura.ai.
5. Booking via Calendly and calls via Zoom
Calendly. Our emails may contain a link that lets you book a call with us. The link opens the Calendly website (Calendly LLC, 115 E Main Street, Suite A1B, Buford, GA 30518, USA). Calendly is not embedded on this website: no Calendly script or embedded window is loaded. Data only flows to Calendly once you click the link. The link may include an indication of how you found us, for example via the risk check.
When you open the page, Calendly processes the usual technical data, in particular your IP address, the time and information about your browser, and sets cookies on its own website. When you book a call, Calendly processes your information, usually your name, email address, company, preferred language for the call and the time, and forwards the booking to us so that the call can take place.
We are the controller for the booking data; Calendly processes it on our behalf. Calendly's customer terms apply, including the data processing addendum incorporated therein. Data is stored in the United States and, where applicable, in other countries of Calendly's sub-processors. Transfers are based on the EU-U.S. Data Privacy Framework, under which Calendly is certified, and additionally on the European Commission's Standard Contractual Clauses. Calendly may also act as an independent controller for operating its own platform, for example for accounts, security and preventing abuse. More information: calendly.com/legal/privacy-notice, calendly.com/legal/data-processing-addendum and the list of sub-processors at calendly.com/help/calendly-sub-processors-gdpr-ccpa.
Zoom. We hold booked calls as video conferences via Zoom (Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA). Zoom processes your display name, where applicable your email address, IP address, device and connection data and, during the call, video and audio if you turn on your camera and microphone. We do not record calls. Zoom is certified under the EU-U.S. Data Privacy Framework. We have a data processing agreement with Zoom. More information: zoom.us/privacy.
Calendar. Booked calls are stored with name, email address and time in our calendar at Microsoft (Outlook.com). The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Legal basis and retention. The legal basis is Art. 6(1)(b) GDPR where the call serves to prepare a contract, and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is organizing and holding the call you requested. We delete booking data in Calendly and in our calendar no later than twelve months after the call. Contact details we need for further communication are kept in our CRM as described in Section 4.
6. Listening test
When you play the listening test, we store the language of the page, your score and your five answers, without your name or email address, at Netlify in order to evaluate the test. Netlify automatically stores technical information such as the IP address and browser identifier (Section 3). We only evaluate the results in aggregated form and do not attribute them to any person. We delete the submissions no later than twelve months after submission. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is improving the listening test.
7. No tracking on the website, no advertising
This website does not use any analytics or audience measurement services. No profiling takes place on the website, no data is passed on to third parties for advertising purposes, and no social media content is embedded. All fonts are hosted on our own server; no font files are loaded from third-party servers. Open and click tracking only takes place in our update emails, with your consent (Section 4).
The services we use are hosting and forms via Netlify, including spam protection via Akismet (Sections 2 and 3), our mailboxes at Migadu (Section 3), the CRM and email delivery via Brevo (Section 4) and, once you open a booking link, Calendly, Zoom and our calendar at Microsoft (Section 5).
8. External links
Our website contains links to third-party websites. When you click on them, their privacy policies apply. We have no influence on how these providers process data.
9. Your rights
You have the following rights with regard to us:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- withdrawal of any consent given, at any time, with effect for the future (Art. 7(3) GDPR)
To exercise these rights, an informal message to hello@fennura.ai is sufficient.
Right to object (Art. 21 GDPR)
Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
10. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).
11. Security
This website is delivered exclusively in encrypted form via HTTPS. We use technical and organizational measures to protect your data against loss, destruction and unauthorized access.
12. Changes to this policy
We update this privacy policy whenever the legal situation, our offerings or the services we use change. The version published here applies. Last updated: September 2026.