Ava Ora

Privacy Policy

Last updated: August 2026

Protecting your personal data matters to us. This policy explains which data we process when you visit our website and use the “Ava Ora” platform, for what purpose and on what legal basis.

1. Controller

ComSat Media GmbH

Headquarters Germany: Waldstrasse 1, 63150 Heusenstamm, Germany · +49 6106 2857-200

Office Austria: Achenweg 22, 6370 Kitzbühel, Austria · +43 5356 20408-0

Email: contact@comsatmedia.com

Managing Directors: António Rodrigues Duarte, Thomas Becke · HRB 34249, Amtsgericht Offenbach am Main

2. Data protection officer

You can reach our data protection officer at privacy@comsatmedia.com or by post at the headquarters address, marked “Data Protection”.

3. Roles: website and platform

For our website and prospect communication we act as controller within the meaning of Art. 4 (7) GDPR.

Where a customer uses the platform for their own events and conversations, we process the resulting participant data solely as a processor on behalf of that customer (Art. 28 GDPR). The customer is the controller; a data processing agreement (DPA) forms part of the contract.

4. Visiting the website (server logs)

When you access our website, technical information is processed automatically: IP address, date and time, requested resource, referrer, browser type and operating system. This data is required for delivery, stability and security.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure operation). Retention: max. 30 days.

5. Cookies and consent

We use strictly necessary cookies (session, security, language preference). Optional cookies — in particular for analytics and convenience features — are only set with your explicit consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR).

You can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the footer. We log the time, version and scope of consent for accountability purposes.

6. Demo requests and contact

If you request a demo or contact us, we process the data you provide (name, business email address, company, message) in order to handle your request.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures) or Art. 6 (1) (f) GDPR. Retention: 24 months after the last contact if no contract is concluded; statutory retention periods remain unaffected.

7. User accounts

To use the platform we create an account containing name, email address, role, language and sign-in logs. Sign-in is possible via email/password or Google (business accounts); with Google sign-in we receive name, email address and profile picture.

Legal basis: Art. 6 (1) (b) GDPR. Retention: for the term of the contract plus statutory retention periods.

8. Conversations with the AI assistant (video, audio, chat)

During a conversation we process your input (text, speech, optionally video), the resulting transcript, technical metadata, an automatically generated summary and an interest classification.

Video and audio recordings only take place after prior, explicit consent (Art. 6 (1) (a) GDPR). Without consent no recording takes place; a text-based conversation remains available.

Content is transmitted to the AI services used in order to generate responses. Use of your content to train third-party models is contractually excluded.

Retention: recordings and transcripts are deleted according to the period configured by the customer, by default no later than 90 days after the event. Anonymised analytics may be retained beyond that.

9. Automated processing and transparency

The platform generates automated summaries and classifies interest (e.g. “cold”, “warm”, “hot”). This classification serves internal prioritisation only and has no legal effect on you within the meaning of Art. 22 GDPR. You may request human review at any time.

Before a conversation starts you are informed that you are interacting with an AI system (transparency obligation under Art. 50 EU AI Act).

10. Recipients and processors

We use carefully selected service providers with whom data processing agreements pursuant to Art. 28 GDPR are in place:

ProcessorPurposePlace of processing
Supabase (hosting & database, EU region)Database, authentication, file storageEU
Lovable (application hosting & AI gateway)Application delivery, routing of AI requestsEU / USA (SCC)
MuxVideo hosting and deliveryEU / USA (SCC)
TavusVideo avatars for the “video” conversation modeUSA (SCC)
ElevenLabsSpeech synthesis and recognition for the “audio” conversation modeEU / USA (SCC)
Google (Gemini) / OpenAIGeneration of answers, summaries and translationsEU / USA (SCC)
ResendTransactional and notification emailsEU / USA (SCC)
StripePayment processing for paid plansEU / USA (SCC)

Where data is processed outside the EU/EEA, this is based on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and supplementary technical measures (encryption, pseudonymisation, access restrictions).

11. Security

We protect your data with transport encryption (TLS), encryption at rest, tenant-separated storage with row-level access policies, role-based permissions, tamper-evident audit logs and regular access and security reviews. Our organisation is ISO 9001:2015 certified and TISAX assessed.

12. Retention and deletion

We store personal data only as long as necessary for the respective purposes or as required by statutory retention obligations (in particular §§ 147 AO, 257 HGB: 6 or 10 years). Afterwards the data is deleted or anonymised.

13. Your rights

  • Access to the data processed (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)

To exercise your rights, a message to privacy@comsatmedia.com is sufficient. If your request concerns data we process on behalf of a customer, we forward it to that customer without undue delay.

Right to complain: you may lodge a complaint with a supervisory authority, for example the Hessian Commissioner for Data Protection and Freedom of Information (Postfach 3163, 65021 Wiesbaden, Germany) or the Austrian Data Protection Authority (Barichgasse 40-42, 1030 Vienna).

14. Changes to this policy

We update this privacy policy when our processing activities or the legal situation change. The version published on this page applies.