Privacy Policy
(Last updated: August 8, 2026 · Version 3)
This Privacy Policy provides information pursuant to the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the Telecommunications Act 2021 (TKG 2021) about the processing of personal data on drefrajo.dev, through the Interview Service available at interview.drefrajo.dev, and in connection with direct communications and business dealings with me.
This Privacy Policy covers three distinct processing contexts:
- the public website
drefrajo.dev; - Creator accounts and my own communications, billing, and other business activities;
- the Interview Service at
interview.drefrajo.dev.
Not every processing activity described below applies to every person. The processing that takes place depends on which parts and functions of the service are used.
1. Controller and Allocation of Roles
Franz Josef Drexler
Address: see Imprint
Email: contact@drefrajo.dev
I am the controller for the operation of the website and for my own purposes relating to Creator accounts and the Interview Service, in particular authentication, billing, IT security, abuse prevention, and my own communications.
For the contents of an interview, the logged-in Creator generally determines the purposes and framework of the processing as well as the persons invited to participate. In this respect, the Creator is generally the controller and I process the interview content as a processor pursuant to Article 28 GDPR.
This processing on behalf of the Creator is governed by a Data Processing Agreement, which applies where a Creator uses the Interview Service as a controller.
This Privacy Policy does not replace the Creator’s own privacy information. In particular, the Creator is responsible for informing invited Clients about the Creator’s processing activities, establishing an appropriate legal basis, and complying with the data protection requirements applicable to the specific use of the interview.
The actual circumstances of each individual use remain decisive.
2. Personal Data Processed and Its Sources
Website Visitors
When visiting drefrajo.dev, the following data may in particular be processed:
- technical connection and log data such as timestamp, public IP address, requested URL, HTTP headers, browser, operating system, device type, and response status;
- cookieless website usage data such as page views, referrers, and device, browser, and country information.
Creators
When creating or using a Creator account and in connection with business transactions, the following data may in particular be processed:
- account data received from the selected OAuth provider, such as provider ID, verified email address, name or profile name, and, where applicable, profile picture;
- authentication and session data, including necessary session cookies or tokens, expiry times, IP address, and user agent;
- Creator profile, display name, language preferences, a contact email address optionally made available to Clients, and a privacy policy URL;
- private interview templates;
- project names, interview instructions, interview links, and interview content and results managed by the Creator;
- usage and operational data such as timestamps, processing status, token usage, estimated AI costs, and error messages;
- payment, transaction, refund, and dispute information, including corresponding reference numbers.
I do not receive complete card or bank account details.
This data originates from the Creator, the selected OAuth provider, and, in the case of payments, the payment provider used.
Interview Clients
Clients do not need to create an account.
In connection with an interview, the following data may in particular be processed:
- the interview link or its access token and technical access data;
- all inputs and chat messages as well as timestamps;
- requested changes to the project document;
- optional information regarding a visual direction or inspiration links;
- the selection of a visual concept and the time of submission;
- content generated from the conversation, such as the interview plan, AI responses, project document, image prompts, visual concepts, and Project Submission.
The Interview Service does not specifically ask Clients to provide their name or email address. Free-text fields may nevertheless contain personal data relating to the Client or third parties.
The Interview Service is not intended for special categories of personal data within the meaning of Article 9 GDPR, data relating to criminal convictions or offences, login credentials, or comparably sensitive information. Such information should not be entered into the service.
3. Purposes and Legal Bases
| Area | Processing | Purpose | Legal basis |
|---|---|---|---|
| Website | Website delivery and server logs | Technical provision, troubleshooting, security, and prevention of attacks | Article 6(1)(f) GDPR |
| Website | Cookieless website analytics | Measuring reach and improving the website | Article 6(1)(f) GDPR |
| Creator Area | Creator account, OAuth login, settings, and service functionality | Account creation and performance of the user contract | Article 6(1)(b) GDPR; additionally Article 6(1)(f) for security and abuse prevention |
| Interview Service | Interview content of a Client | Conducting, storing, and making available an interview created by the Creator | generally processing on behalf of the Creator pursuant to Article 28 GDPR; the legal basis in relation to the Client is determined by the Creator |
| Interview Service | AI-assisted conversations and creation of documents and images | Responding to messages and creating and revising project results | same as the respective interview content |
| Creator Area | My own preparatory or administrative AI functionality | Providing functionality requested by the Creator | Article 6(1)(b) GDPR |
| Business Operations | Billing and Interview Passes | Checkout, allocation of payments, credit management, refunds, and disputes | Article 6(1)(b) and (c) GDPR |
| Interview Service | Submission notification to the Creator | Notification that a Project Submission is available | Article 6(1)(b) GDPR |
| General | Support and other communications | Handling enquiries and contractual communications | Article 6(1)(b) or (f) GDPR |
| General | Legal enforcement and statutory obligations | Accounting, documentation, and establishment, exercise, or defence of legal claims | Article 6(1)(c) and (f) GDPR |
4. Interview Process and Visibility
The Creator creates an interview, defines the project name, language, and instructions, and shares a non-guessable link with the Client.
Anyone who has access to the link can open and continue the corresponding interview without creating an account and can view the content made available through that link. Creators and Clients should therefore keep the link confidential.
The Creator can generate a new link, thereby invalidating the previous one.
Before the interview begins, the Client is informed that they are interacting with an AI system.
The Creator’s display name, the contact email address provided by the Creator for this purpose, and a link to the Creator’s privacy information are also displayed.
The Creator can view and download the complete chat history, project document, inspiration links, generated visual concepts, selected concept, and Project Submission.
After submission, the Creator receives a notification containing the project name, submission status, and a link to the protected Creator area.
The notification does not contain the chat history, project document, visual concepts, Client messages, or the secret interview link.
5. Processing by AI Models
External AI models are accessed through an AI gateway provider for AI-assisted conversations and the creation of text and visual concepts.
Depending on the processing step, interview instructions, previous Client and AI messages, internal interview planning, project documents, requested changes, or image prompts derived from them may be transmitted to the AI gateway provider and the relevant model provider.
Generated responses and images are subsequently stored within the Interview Service.
Model requests are configured so that only provider routes are permitted where, according to the applicable policies, transmitted inputs and outputs are not used for training or improving the relevant models (data_collection: deny).
This does not constitute a guarantee of complete zero-data retention by the model provider. Depending on the provider, data may temporarily be retained in particular for security, abuse prevention, or compliance with legal obligations.
According to the documentation of the AI gateway provider used, prompt and response content is not stored by default unless corresponding logging has been enabled. Technical metadata relating to model requests, such as token counts or latency, may be stored.
Within the Interview Service, the AI does not make decisions based solely on automated processing that produce legal effects concerning a Creator or Client or similarly significantly affect them.
The AI providers currently used are listed in the current Subprocessor List.
6. Cookies, Local Storage, and Server Logs
The protected Creator area uses only technically necessary authentication and session cookies or comparable tokens.
They are used for login, session management, and account security and are stored until logout, until the relevant session expires, or until they are deleted in the browser.
The legal basis for the processing is Article 6(1)(b) and (f) GDPR.
To the extent required, storing or accessing information on the end user’s device is necessary to provide the service expressly requested by the user pursuant to Section 165(3) TKG 2021.
Clients do not require an account, and the Interview Service does not set its own login cookie for Clients. Access is provided through the token contained in the interview link.
No advertising or marketing trackers are used.
When the website or Interview Service is accessed, hosting, infrastructure, and security providers used for the relevant service may process technical server and security data.
Regular access logs under my control are generally retained for no longer than 30 days.
Security-related data may be retained for longer in the event of a specific incident until the matter has been resolved and, where necessary, until the expiry of applicable limitation periods.
Service providers may maintain their own technical logs in accordance with their respective contractual and legal requirements.
7. Cookieless Website Analytics
On drefrajo.dev, I use a self-hosted instance of Umami Analytics on infrastructure located in Germany.
The Interview Service at interview.drefrajo.dev does not use Umami.
Umami does not use analytics cookies and does not permanently store the public IP address as such.
During processing, the IP address may be used to generate a pseudonymous session identifier and to derive technical or approximate geographical information.
Stored data may in particular include information about page views and sessions as well as referrer, browser, operating system, device, and country information.
No cross-website tracking or recognition takes place.
Analytics data is retained only for as long as necessary to measure reach and improve the website and is deleted when it is no longer required for those purposes.
The legal basis is Article 6(1)(f) GDPR. My legitimate interest consists in measuring the reach of and improving my website.
Data subjects may object to this processing pursuant to Article 21 GDPR on grounds relating to their particular situation.
8. Service Providers and Recipients
The recipients of personal data depend on which part of the service is used.
Merely visiting drefrajo.dev does not, in particular, result in website content or usage data being disclosed to AI model providers or payment providers.
Public Website
When operating drefrajo.dev, the following categories of recipients may in particular be used:
- hosting, infrastructure, and IT security providers;
- providers used for the self-hosted website analytics infrastructure.
Creator Accounts and My Own Business Activities
For Creator accounts, authentication, payments, and direct communications, the following categories of recipients may in particular be used:
- hosting, backend, database, and IT security providers;
- authentication providers selected by the Creator;
- payment and billing providers;
- email and communication providers.
Interview Service
When conducting an interview, the following categories of recipients may in particular be used:
- hosting, backend, database, and IT security providers;
- AI gateway and AI model providers used to process interview content and generate project results;
- communication providers where required for notifications relating to an interview.
Where an interview has been created by a Creator, that Creator also receives the interview content described in Section 4.
Professional advisers, public authorities, or courts may receive personal data where required by law or necessary for the establishment, exercise, or defence of legal claims.
Where I process interview content on behalf of a Creator, the subprocessors used for that processing, including their respective functions and processing locations, are listed in the current Subprocessor List.
9. International Data Transfers
Depending on which part of the service is used, some of the service providers involved may process personal data outside the European Economic Area, in particular in the United States.
Not every use of the service therefore results in the same international data transfers.
Where an adequacy decision of the European Commission pursuant to Article 45 GDPR applies to the relevant recipient and processing activity, the transfer is based on that decision.
This may in particular apply to appropriately certified US organisations participating in the EU-US Data Privacy Framework.
Where no applicable adequacy decision exists, appropriate safeguards pursuant to Article 46 GDPR are used, in particular the European Commission’s Standard Contractual Clauses and, where required, supplementary technical and organisational measures.
Information about the subprocessors used for processing carried out on behalf of Creators and their processing locations is available in the current Subprocessor List.
A copy of the safeguards applicable to a specific transfer may be requested using the contact details provided in Section 1.
10. Retention and Deletion
Personal data is generally retained only for as long as necessary for the relevant purpose.
| Data | Retention period or criterion |
|---|---|
| Regular server logs | generally no longer than 30 days; longer only in the event of a specific security or legal matter |
| Creator account and profile | for the duration of the account; subsequently deleted unless statutory or legal retention requirements apply |
| OAuth and session data | for as long as required for login and account security; sessions until logout or expiry |
| Private interview templates | until deleted by the Creator or the Creator account is deleted |
| Completed interviews, including chat history, project documents, and images | deleted no later than 24 months after submission, unless deleted earlier by the Creator |
| Incomplete interviews | deleted no later than 24 months after the last activity |
| Billing and accounting data | documents subject to statutory retention requirements are generally retained for seven years from the end of the relevant calendar year; potentially longer where proceedings are pending |
| Other payment and transaction data | for as long as required for payment processing, refunds, disputes, or legal claims |
| Support and email communications | until the matter has been finally resolved and thereafter only for as long as necessary for contractual purposes, evidence, legal claims, or statutory obligations |
| Umami analytics data | for as long as necessary to measure reach and improve the website; deleted thereafter |
When a Creator deletes an interview or its automatic retention period expires, the active interview record, chat history, and stored concept images are removed from the product and the interview link becomes invalid.
Temporary residual copies may remain in service-provider backups until they are overwritten as part of the provider’s regular backup cycle.
Billing and other records required by law are not deleted together with an interview.
Clients may contact either the Creator or me regarding deletion of interview content.
Where the Creator is the controller, requests are generally handled in accordance with the Creator’s instructions; mandatory data subject rights remain unaffected.
11. Data Security
Appropriate technical and organisational measures are used to protect personal data.
These include, in particular, encryption in transit, access controls, secure authentication, non-guessable and revocable interview links, and measures designed to prevent abusive access.
These measures are reviewed and adapted as appropriate in light of the relevant risks and technological developments.
12. Data Subject Rights
Subject to the applicable legal requirements, data subjects have in particular the following rights:
- access pursuant to Article 15 GDPR;
- rectification pursuant to Article 16 GDPR;
- erasure pursuant to Article 17 GDPR;
- restriction of processing pursuant to Article 18 GDPR;
- data portability pursuant to Article 20 GDPR;
- objection to processing based on legitimate interests pursuant to Article 21 GDPR;
- withdrawal of consent, where consent has been given, with effect for the future; and
- the right to lodge a complaint with a competent supervisory authority pursuant to Article 77 GDPR.
For data relating to the website, Creator accounts, billing, direct communications, or security, you may contact me directly using the contact details provided in Section 1.
For interview content, the inviting Creator is generally the controller and therefore the primary point of contact.
The Creator’s contact details and privacy information are displayed within the interview.
You may also contact me. Where I act as a processor, I will assist the responsible Creator in handling data subject requests.
To prevent unauthorised disclosure, appropriate proof of identity or authority may be required.
Complaints may in particular be submitted to the Austrian Data Protection Authority:
Barichgasse 40–42
1030 Vienna
Austria
dsb@dsb.gv.at
https://www.dsb.gv.at/
Alternatively, you may lodge a complaint with another competent supervisory authority within the European Union.
13. Requirement to Provide Data
Data required for Creator accounts, authentication, billing, and performance of the contract must be provided where the relevant functionality is used.
For the technical performance of an interview, Clients must provide the information required to produce the requested project results.
Whether the Client is subject to any additional statutory or contractual obligation towards the Creator to provide particular personal data, and the consequences of failing to provide such data, are determined by the respective Creator.
14. Changes to this Privacy Policy
This Privacy Policy may be updated where the processing activities, service providers, or applicable legal requirements materially change.
The date and version number stated at the beginning indicate the current version.