Skip to content

Your anonymity matters to us.
And so does the protection of your data.

Designed specifically for particularly confidential use with consistent data minimisation, a strong focus on anonymity and, of course, technical protection.

Triluma uses encrypted data transmission, secure access using anonymous codes, effective masking of sensitive data, pseudonymised identifiers and protected API processing.

Because for us, the protection of our users, their conversations and their data is not an optional feature, but the most important foundation of the entire Triluma system.

Erfreute junge Frau, die auf der Couch am Laptop sitzt.

Privacy policy

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data that can be used to identify you personally. Detailed information on data protection can be found in the privacy policy set out below.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section “Information on the controller” in this privacy policy.

How do we collect your data?

Some data is collected when you provide it to us, for example by entering information in a contact form.

Other data is collected automatically by our IT systems when you visit the website, or after you have given consent. This primarily includes technical data such as your browser, operating system or the time of access. This data is collected automatically as soon as you enter this website.

What do we use your data for?

Some data is collected to ensure that the website is provided correctly. Other data may be used to analyse user behaviour. Where contracts can be concluded or initiated through the website, submitted data is also processed for quotations, orders or other contractual enquiries.

What rights do you have regarding your data?

You have the right at any time to obtain free information about the origin, recipients and purpose of your stored personal data. You also have the right to request correction or deletion of this data. If you have consented to data processing, you may withdraw that consent at any time with future effect. Under certain circumstances, you also have the right to request restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time regarding these and other questions about data protection.

2. Hosting

We host the content of our website with the following provider:

Hetzner

The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hereinafter “Hetzner”).

For details, please refer to Hetzner’s privacy policy: https://www.hetzner.com/de/legal/privacy-policy/.

Hetzner is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be withdrawn at any time.

Data processing on behalf of the controller

We have concluded a data processing agreement for the use of the service named above. This agreement is required under data-protection law and ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.

3. General information and mandatory disclosures

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data-protection requirements and this privacy policy.

When you use this website, various items of personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect, what we use it for, and how and for what purpose this takes place.

Please note that data transmission over the internet, for example by email, can have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller responsible for data processing on this website is:

Hansjörg Kauschke
Am Bachfeld 12a
82041 Deisenhofen b. München

Telefon: +49 89 62830545
E-Mail: kontakt@triluma.de

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data such as names or email addresses.

Storage period

Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for processing no longer applies. If you make a justified request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing it, such as retention periods under tax or commercial law. In the latter case, deletion will take place once those reasons no longer apply.

General information on the legal bases for data processing on this website

Where you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of data under Art. 9(1) GDPR are processed. Where you have expressly consented to the transfer of personal data to third countries, processing is also based on Art. 49(1)(a) GDPR. Where you have consented to the storage of cookies or access to information on your device, such as device fingerprinting, processing is additionally based on section 25(1) TDDDG. Consent may be withdrawn at any time. Where your data is required for performance of a contract or pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. Where processing is required to comply with a legal obligation, it is based on Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interests under Art. 6(1)(f) GDPR. The legal bases applicable in individual cases are explained in the following sections of this privacy policy.

Data protection officer

We have appointed a data protection officer.

Michael Weber
Alter Bahnhofsplatz 36
83646 Bad Tölz

Telefon: +49 1520 3178108
E-Mail: mweber@nmsw.de

Information on transfers to third countries

When individual services are used, personal data may be transferred to recipients outside the European Union or European Economic Area. Such transfers take place only where there is a valid data-protection basis, in particular an adequacy decision by the European Commission, certification under the EU-US Data Privacy Framework, the European Commission’s standard contractual clauses or explicit consent.

Information about the services used and possible transfers to third countries can be found in the relevant sections of this privacy policy.

Recipients of personal data

As part of our business activities, we work with various external organisations. This may require personal data to be transferred to those organisations. We disclose personal data only where this is necessary for performance of a contract, where we are legally obliged to do so, for example to tax authorities, where we have a legitimate interest in disclosure under Art. 6(1)(f) GDPR, or where another legal basis permits disclosure. When using processors, we disclose our customers’ personal data only on the basis of a valid data processing agreement. Where processing is carried out jointly, a joint-controller agreement is concluded.

Withdrawal of your consent to data processing

Many data-processing operations are possible only with your express consent. You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)

WHERE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR).

WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING (OBJECTION UNDER ART. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of a GDPR infringement, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. This right is without prejudice to other administrative or judicial remedies.

Right to data portability

You have the right to receive data that we process automatically on the basis of your consent or in performance of a contract, or to have it provided to a third party, in a commonly used machine-readable format. Direct transfer to another controller will take place only where technically feasible.

Access, correction and deletion

Within the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of processing, and where applicable to have this data corrected or deleted. You may contact us at any time regarding this or other questions about personal data.

Right to restriction of processing

You have the right to request restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction applies in the following cases:

  • If you dispute the accuracy of personal data stored by us, we generally need time to verify it. During verification, you have the right to request restriction of processing.
  • If the processing of your personal data was or is unlawful, you may request restriction instead of deletion.
  • If we no longer need your personal data but you require it to establish, exercise or defend legal claims, you have the right to request restriction instead of deletion.
  • If you have objected under Art. 21(1) GDPR, your interests and ours must be weighed against each other. Until it has been determined whose interests prevail, you have the right to request restriction of processing.

Where processing has been restricted, such data may—apart from storage—be processed only with your consent, for the establishment, exercise or defence of legal claims, to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries sent to us, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the change from “http://” to “https://” in the browser address bar and by the padlock symbol.

When SSL or TLS encryption is enabled, data you transmit to us cannot be read by third parties.

Pseudonymisation, masking and technical safeguards

We use technical and organisational measures to protect personal data. These may include access restrictions, encrypted transmission, logging of security-relevant events, and pseudonymisation, hashing or masking of certain data.

Where sufficient for the respective purpose, data is not processed or displayed in plain text. For example, certain identifiers, telephone numbers, access codes or technical identifiers may be shortened, masked, pseudonymised or stored as hash values.

These measures are intended to make association with individuals more difficult, prevent unauthorised access and support data minimisation. Full anonymisation exists only where identification of the person concerned is permanently excluded.

Encrypted payments on this website

Currently inactive. This section will be activated only if and when the function is actually used.

4. Data collection on this website

Use of AI on the website

We use AI-supported services and/or applications on our website as follows:

The AI-supported functions are currently used exclusively for dialogue-based support in the protected chat area. They process user input and generate automated responses, reflection questions, guidance and information about suitable Triluma services. The AI does not send emails, make appointments independently, initiate payments or take independent action towards customers or third parties.

When you interact with elements on our website that use artificial intelligence, such as a chatbot, your input including metadata is processed to generate an appropriate response or reaction.

These AI-supported functions are used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in using modern technologies on our website to improve our services and identify new opportunities from interaction with customers. Where consent is required, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG. You may withdraw consent at any time.

Further information about data processing by this tool or service can be found in the relevant section of this privacy policy.

Technically necessary local browser storage

For certain website functions, we use technically necessary local browser storage, in particular Local Storage. Information is stored locally on your device so that protected areas can be provided, access can be managed and required notices or consent can be recorded.

The following entries may be used in particular:

  • triluma_client_code_v1: Storage of an access code where you actively use the “Remember code” function. This makes future access easier and is time-limited.
  • triluma_token: Storage of a technical login token to maintain protected login status during use.
  • triluma_consent_v1: Storage of the status that required notices and consent have been confirmed, so they do not have to be requested again on every page view.

Local storage is used to provide the website technically, control access, secure the application and document required notices. The legal basis is Art. 6(1)(f) GDPR. Where consent is required, processing is based on Art. 6(1)(a) GDPR and section 25(1) TDDDG. Consent may be withdrawn at any time with future effect.

You can delete locally stored data at any time through your browser settings. You may then need to enter access codes again or reconfirm notices.

Telephone number for callback or conversation requests

If you request a callback, telephone conversation or contact by a coach or authorised contact person through Triluma, we process the telephone number you provide and the information required to handle the request.

The telephone number is used solely to enable the requested callback or contact, handle the request organisationally and prevent misuse. It is not used for marketing unless you have separately and expressly consented.

Where the callback or contact is necessary for pre-contractual measures or performance of an existing contract, processing is based on Art. 6(1)(b) GDPR. In all other cases, processing is based on our legitimate interest in handling your request under Art. 6(1)(f) GDPR or, where consent is requested, on Art. 6(1)(a) GDPR.

The telephone number is stored only for as long as necessary to handle the request, conduct the conversation, document legitimate evidence or comply with statutory retention obligations. It is then deleted or anonymised where possible.

Enquiries by email or telephone

If you contact us by email or telephone, your enquiry, including all personal data arising from it such as your name and the enquiry itself, is stored and processed for the purpose of handling your request. We do not disclose this data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR where your enquiry relates to performance of a contract or is required for pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us under Art. 6(1)(f) GDPR or on your consent under Art. 6(1)(a) GDPR where requested. Consent may be withdrawn at any time.

Data sent to us in contact enquiries remains with us until you request deletion, withdraw consent to storage or the purpose of storage no longer applies, for example once your enquiry has been fully handled. Mandatory statutory provisions, in particular retention periods, remain unaffected.

5. Plugins and tools

YouTube with enhanced privacy

Currently inactive. This section will be activated only if and when the function is actually used.

Vimeo without tracking (Do Not Track)

Currently inactive. This section will be activated only if and when the function is actually used.

OpenAI API

We use AI services on our website through a server-side API connection. The provider is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, https://openai.com. Technical service delivery may involve affiliated companies and service providers, including outside the European Economic Area. We use the OpenAI API as follows:

  • We use the OpenAI API to process user input automatically in a protected chat area and provide suitable psychosocial orientation, structured conversation prompts and information about appropriate Triluma services. Processing does not take place through the publicly accessible ChatGPT web application, but through a server-side API connection. Users are advised not to enter unnecessary personal data. Triluma does not replace medical, psychotherapeutic or legal advice.

When you interact with AI-supported chat functions on our website, your input including technical metadata is processed and transmitted to OpenAI through our server-side API connection to generate an appropriate response.

We have configured the OpenAI API so that personal data entered is not used to train the ChatGPT algorithm.

The OpenAI API is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in efficient customer communication using modern technical solutions. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and section 25(1) TDDDG. Consent may be withdrawn at any time.

Further information is available here: https://openai.com/policies/privacy-policy.

Data processing on behalf of the controller

We have concluded a data processing agreement for the use of the service named above. This agreement is required under data-protection law and ensures that the provider processes the personal data of our website visitors only on our instructions and in compliance with the GDPR.

6. E-commerce and payment providers

Processing customer and contract data

We collect, process and use personal customer and contract data to establish, define and amend our contractual relationships. We collect, process and use personal data concerning use of this website only where necessary to enable the user to use the service or for billing. The legal basis is Art. 6(1)(b) GDPR.

Customer data collected is deleted after completion of the order or termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.

Payment services

Currently inactive. This section will be activated only if and when the function is actually used.

PayPal

Currently inactive. This section will be activated only if PayPal is actually integrated.