Privacy policy
Hosting and storage in the EU, AI processing explained transparently. Structured according to the GDPR, contents to be reviewed by legal counsel before launch.
This English text is a convenience translation. The binding version is the German one.
TODO: This privacy policy is a structured framework and must be reviewed and completed by legal counsel before launch.1. Controller
TODO: Name and address of the controller (as in the legal notice)2. What data we process
- Contact data: email address (for the account, delivery of the video, invoices)
- Brand material: logo, colors, fonts, optional brand guides and logo animations
- Your video script and the audio and video files generated from it
- Technical data: IP address, times of requests (abuse protection, rate limits)
- Payment data is processed exclusively by our payment partner (merchant of record). We do not receive any credit card data
3. Purposes and legal bases
- Performance of the contract (Art. 6 Abs. 1 lit. b DSGVO): production and delivery of your video
- Consent (Art. 6 Abs. 1 lit. a DSGVO): occasional contact about significant new developments in the system, only if you actively tick the checkbox and only after confirmation via the link in the confirmation email (double opt-in). The time, IP address, and confirmation are stored as evidence (Art. 7 Abs. 1 DSGVO), and withdrawal is possible at any time with one click.
- Legitimate interest (Art. 6 Abs. 1 lit. f DSGVO): abuse protection, fraud prevention
4. Processors and storage location
Hosting, database, and storage take place on servers in the EU. The only exception is the AI processing of your script described below.
- Hosting, database, and file storage: our own server at Hetzner Online GmbH, Falkenstein data center (DE). Your details, your script, uploaded brand files, and the finished videos are stored exclusively on this server. There are no password-protected customer accounts. You access your order via a link in your email.
- Email delivery: Resend (Resend Inc., USA) as a processor, delivery via Amazon Web Services data centers in Ireland (EU region). This involves processing your email address and the content of the message.
- Payment processing: TODO: Enter Paddle or Lemon Squeezy, link the data processing agreement
5. AI processing of your script (Anthropic)
To automatically shorten your script and produce your video, we use AI models from Anthropic (Claude). This means your script is processed via the Anthropic API. What this means for your data:
- Anthropic stores the transmitted requests and responses for up to 30 days exclusively for abuse and security monitoring and deletes them automatically afterward.
- Your content is not used by Anthropic to train AI models.
- Only the texts necessary for video production are transmitted, no account data, no payment data, no email addresses.
Transfer to the USA. Anthropic and ElevenLabs are based in the United States. A transfer there is only permitted if an adequate level of protection exists (Art. 44 ff. DSGVO). We base the transfer on a data processing agreement with the European Commission's standard contractual clauses (Implementing Decision 2021/914) together with the associated assessment of the legal situation in the recipient country. In addition, both providers are certified under the EU-US Data Privacy Framework, insofar as this is listed in the certification register of the US Department of Commerce.
Despite these safeguards, it cannot be ruled out that US authorities may demand access to data under certain conditions and that you may not have the same legal remedies against this as in the EU. We therefore transmit only what is necessary for the service: the text of your video, not your contact or payment data.
TODO before launch, only the operator can do this: (1) Conclude a data processing agreement with Anthropic (in the Anthropic Console under Settings, Data Processing Addendum) and with ElevenLabs (elevenlabs.io/dpa or request it via support), keeping a copy of each. (2) Look up both providers in the DPF register at dataprivacyframework.gov and document the result. If a provider is not listed there, delete the sentence about the Data Privacy Framework here, then the standard contractual clauses apply on their own. (3) Have both contracts and this section reviewed by a lawyer. (4) Set up a record of processing activities under Art. 30 DSGVO, the contracts and the assessment belong there.6. Retention period
We store personal data only for as long as is necessary for the respective purpose or for as long as statutory periods require. In detail:
- Invoices and accounting (invoice data, payment receipts, business correspondence related to accounting): seven years from the end of the calendar year in which the document was created. The basis is the statutory retention obligation under § 132 BAO in conjunction with Art. 6 Abs. 1 lit. c DSGVO. We do not delete this data early even on request. Instead, we restrict the processing to storage.
- Project data (script, brand assets such as logo, font, and images, finished videos): three years after the last order. This lets you order a follow-up video in your visual identity without a new upload, and we can answer warranty questions within the general limitation period. At your request we delete project data earlier at any time, provided it is not also an accounting document.
- Free previews without confirmation (the email address was never confirmed): 30 days, after which we delete the order and the data completely.
- Evidence of your consents (advertising consent, grant of rights to materials, each with a time stamp and IP address): three years from withdrawal or from the end of the business relationship. We need this evidence in order to prove the consent in the event of a dispute (Art. 7 Abs. 1 DSGVO).
- A check value derived from your IP address for abuse prevention in the order form: 90 days.
- Server logs (accesses to the website): 14 days.
- Email correspondence not related to accounting: three years from the last contact.
After the respective period expires, we delete the data or anonymize it so that it can no longer be linked to you. If you would like earlier deletion, write to us at hallo@motura.at.
TODO before launch: Implement these periods technically (automatic deletion run for unconfirmed orders after 30 days, for project data after three years) and reconcile the details with the tax advisor.7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection. Complaints can be addressed to the Austrian data protection authority (dsb.gv.at).
8. Cookies and local storage
We do not use cookies. This website uses neither advertising nor analytics cookies and includes no services that recognize you across websites. That is why you see no cookie banner here: there is nothing you would have to consent to.
We store two things locally in your browser, not on our servers:
- Your order draft. While you fill out the order form, we save your entries in your browser's storage so that nothing is lost if the page reloads or the tab closes. The draft does not leave your device and is deleted as soon as you submit the order, click “Start over”, or clear your browser storage. Legal basis: this storage is strictly necessary for the service you requested (§ 165 Abs. 3 TKG 2021), so it does not require consent.
- The access key in the internal area. Concerns only our own staff, not customers.
You can delete both at any time via your browser settings. The only downside: an order draft you started is then gone.
Audience measurement
We count how often our pages are viewed. This happens on our own server in Germany, without any third-party service and without a cookie. Nothing is stored on your device and nothing is read from it in the process.
For each view, we store: the page viewed, the name of the website you came to us from (without path and without search terms), whether you use a phone, a tablet, or a computer, and the time. In addition, we store an identifier calculated from your IP address, your browser identifier, a secret value, and today's date.
This identifier cannot be reversed and changes every night. It allows us to count several views by the same person on one day as a single visit, but it allows no one to recognize you across days, not even us. We do not store your IP address itself.
The legal basis is our legitimate interest in basic statistics about the use of our website (Art. 6 Abs. 1 lit. f DSGVO). No consent is required, because your device is neither accessed nor is anything stored on it (§ 165 Abs. 3 TKG). If your browser sends the “Do Not Track” signal, we do not count your visit at all. The data is deleted after six months at the latest.