Privacy Policy
Last updated: August 2026
Protecting your personal data matters to us. This policy explains which data we process when you visit our website and use the “Ava Ora” platform, for what purpose and on what legal basis.
1. Controller
ComSat Media GmbH
Headquarters Germany: Waldstrasse 1, 63150 Heusenstamm, Germany · +49 6106 2857-200
Office Austria: Achenweg 22, 6370 Kitzbühel, Austria · +43 5356 20408-0
Email: contact@comsatmedia.com
Managing Directors: António Rodrigues Duarte, Thomas Becke · HRB 34249, Amtsgericht Offenbach am Main
2. Data protection officer
You can reach our data protection officer at privacy@comsatmedia.com or by post at the headquarters address, marked “Data Protection”.
3. Roles: website and platform
For our website and prospect communication we act as controller within the meaning of Art. 4 (7) GDPR.
Where a customer uses the platform for their own events and conversations, we process the resulting participant data solely as a processor on behalf of that customer (Art. 28 GDPR). The customer is the controller; a data processing agreement (DPA) forms part of the contract.
4. Visiting the website (server logs)
When you access our website, technical information is processed automatically: IP address, date and time, requested resource, referrer, browser type and operating system. This data is required for delivery, stability and security.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Retention: max. 30 days.
5. Cookies and consent
We use strictly necessary cookies (session, security, language preference). Optional cookies — in particular for analytics and convenience features — are only set with your explicit consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR).
You can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer. We log the time, version and scope of consent for accountability purposes.
6. Demo requests and contact
If you request a demo or contact us, we process the data you provide (name, business email address, company, message) in order to handle your request.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR. Retention: 24 months after the last contact if no contract is concluded; statutory retention periods remain unaffected.
7. User accounts
To use the platform we create an account containing name, email address, role, language and sign-in logs. Sign-in is possible via email/password or Google (business accounts); with Google sign-in we receive name, email address and profile picture.
Legal basis: Art. 6 (1) (b) GDPR. Retention: for the term of the contract plus statutory retention periods.
8. Conversations with the AI assistant (video, audio, chat)
During a conversation we process your input (text, speech, optionally video), the resulting transcript, technical metadata, an automatically generated summary and an interest classification.
Video and audio recordings only take place after prior, explicit consent (Art. 6 (1) (a) GDPR). Without consent no recording takes place; a text-based conversation remains available.
Content is transmitted to the AI services used in order to generate responses. Use of your content to train third-party models is contractually excluded.
Retention: recordings and transcripts are deleted according to the period configured by the customer, by default no later than 90 days after the event. Anonymised analytics may be retained beyond that.
9. Automated processing and transparency
The platform generates automated summaries and classifies interest (e.g. “cold”, “warm”, “hot”). This classification serves internal prioritisation only and has no legal effect on you within the meaning of Art. 22 GDPR. You may request human review at any time.
Before a conversation starts you are informed that you are interacting with an AI system (transparency obligation under Art. 50 EU AI Act).
10. Recipients and processors
We use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR are in place:
| Processor | Purpose | Place of processing |
|---|---|---|
| Supabase (hosting & database, EU region) | Database, authentication, file storage | EU |
| Lovable (application hosting & AI gateway) | Application delivery, routing of AI requests | EU / USA (SCC) |
| Mux | Video hosting and delivery | EU / USA (SCC) |
| Tavus | Video avatars for the “video” conversation mode | USA (SCC) |
| ElevenLabs | Speech synthesis and recognition for the “audio” conversation mode | EU / USA (SCC) |
| Google (Gemini) / OpenAI | Generation of answers, summaries and translations | EU / USA (SCC) |
| Resend | Transactional and notification emails | EU / USA (SCC) |
| Stripe | Payment processing for paid plans | EU / USA (SCC) |
Where data is processed outside the EU/EEA, this is based on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and supplementary technical measures (encryption, pseudonymisation, access restrictions).
11. Security
We protect your data with transport encryption (TLS), encryption at rest, tenant-separated storage with row-level access policies, role-based permissions, tamper-evident audit logs and regular access and security reviews. Our organisation is ISO 9001:2015 certified and TISAX assessed.
12. Retention and deletion
We store personal data only as long as necessary for the respective purposes or as required by statutory retention obligations (in particular §§ 147 AO, 257 HGB: 6 or 10 years). Afterwards the data is deleted or anonymised.
13. Your rights
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
To exercise your rights, a message to privacy@comsatmedia.com is sufficient. If your request concerns data we process on behalf of a customer, we forward it to that customer without undue delay.
Right to complain: you may lodge a complaint with a supervisory authority, for example the Hessian Commissioner for Data Protection and Freedom of Information (Postfach 3163, 65021 Wiesbaden, Germany) or the Austrian Data Protection Authority (Barichgasse 40-42, 1030 Vienna).
14. Changes to this policy
We update this privacy policy when our processing activities or the legal situation change. The version published on this page applies.