Privacy Policy
1. Controller
RYM.AI Solutions
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
Phone: +49 151 29439334
Email: kontakt@rym-ai.solutions
Website: https://rym-ai.solutions
Legal Notice: https://rym-ai.solutions/en/imprint
2. General Information and SSL/TLS Encryption
Pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR), this Privacy Policy informs you about which personal data are collected, processed, and stored when you visit and use our website, for which purposes this takes place, and which rights you have as a data subject.
Personal data means any information relating to an identified or identifiable natural person (Article 4(1) GDPR). This includes, for example, name, address, and email address, and - according to the case law of the Court of Justice of the European Union (CJEU, judgment of 19 October 2016, C-582/14) - IP addresses as well, since in certain circumstances they can be attributed to a natural person.
SSL/TLS encryption: For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption (Secure Sockets Layer / Transport Layer Security). You can recognize an encrypted connection by the change in your browser's address bar from "http://" to "https://" and by the lock icon in your browser bar. If SSL/TLS encryption is enabled, data transmitted to us cannot be read by third parties.
3. Legal Bases for Processing
Article 6(1)(a)-(f) GDPR provides several legal bases of equal rank on which personal data may be processed lawfully. Depending on the type and purpose of processing, the following legal bases may apply:
- Article 6(1)(a) GDPR - Consent: The data subject has given consent to the processing of personal data for one or more specific purposes.
- Article 6(1)(b) GDPR - Performance of a contract / pre-contractual measures: Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Article 6(1)(c) GDPR - Legal obligation: Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Article 6(1)(d) GDPR - Vital interests: Processing is necessary in order to protect the vital interests of the data subject or of another natural person.
- Article 6(1)(e) GDPR - Public interest / exercise of official authority: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
- Article 6(1)(f) GDPR - Legitimate interests: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
The legal basis applicable in each individual case is specifically identified in the sections below for the relevant processing activities.
4. Cookies and Comparable Technologies
Cookies are small text files stored by a website on your end device. Comparable technologies include, for example, local storage, session storage, or fingerprinting procedures in which information is stored on or read from your end device.
Under Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), storing information on a user's end device or accessing information already stored there is generally permitted only with the user's prior express consent. Section 25(2) TDDDG provides an exception only for strictly necessary cookies that are required solely for transmitting a message over a public telecommunications network or that are strictly necessary to provide a service expressly requested by the user.
Non-essential cookies and comparable tracking technologies are set on this website only after the user's prior express consent via a consent management platform (CMP). You may access your consent choices at any time through the CMP provided on the website and modify or withdraw your consent for the future.
5. Hosting
GitHub Pages (GitHub Inc.)
This website is hosted on the servers of GitHub Inc. (88 Colin P. Kelly Jr. St, San Francisco, CA 94107, USA) through the "GitHub Pages" service. When you access our website, your browser establishes a connection to GitHub's servers. In the process, technically required data are transmitted and temporarily stored in server log files. This includes, in particular:
- IP address of the requesting end device (shortened/pseudonymized where possible)
- Date and time of access
- Name and URL of the requested file
- Website from which access originates (referrer URL)
- Browser used and, where applicable, operating system and name of the access provider
Purpose and legal basis: Processing is based on Article 6(1)(f) GDPR. The controller's legitimate interest lies in the technically stable, secure, and efficient provision of the website, as well as in the detection and prevention of attacks and misuse.
Storage period: According to GitHub, server log data are generally stored for a maximum of 30 days unless security incidents require longer retention.
Data processing agreement: A data processing agreement pursuant to Article 28 GDPR has been concluded with GitHub Inc. GitHub processes the data arising exclusively on behalf of and in accordance with the instructions of RYM.AI Solutions.
Transfer to a third country: As GitHub Inc. is based in the United States, data are transferred to a third country. GitHub Inc. is certified under the EU-US Data Privacy Framework (DPF) (European Commission adequacy decision of 10 July 2023 pursuant to Article 45 GDPR). This ensures an adequate level of data protection for the transfer. Further information on GitHub's privacy practices is available at: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement.
6. Overview of Third-Country Transfers
In connection with the operation of this website, personal data are transferred to the United States. The following overview identifies the recipient, recipient country, and the applicable transfer safeguard:
- GitHub Inc., 88 Colin P. Kelly Jr. St, San Francisco, CA 94107, USA
Recipient country: USA
Transfer safeguard: EU-US Data Privacy Framework (European Commission adequacy decision pursuant to Article 45 GDPR, effective since 10 July 2023)
Where adequacy decisions do not apply or are not sufficient in individual cases, EU Standard Contractual Clauses (Article 46(2)(c) GDPR) or other appropriate safeguards pursuant to Article 46 GDPR are additionally relied upon.
7. Retention Periods and Deletion Concept
Personal data are stored only for as long as necessary for the respective processing purpose or as required by statutory retention obligations. Once the processing purpose no longer applies and any applicable retention periods have expired, the data are deleted or processing is restricted. In detail:
- Server log files (hosting via GitHub): Generally up to 30 days from creation, unless security incidents require longer storage.
- Statutory retention periods: Where retention obligations under commercial or tax law (e.g., under the German Commercial Code (HGB) or Fiscal Code (AO)) apply, the relevant data are retained for the legally prescribed period - generally 6 to 10 years - and deleted thereafter.
8. Data Subject Rights
As a data subject, you have the following rights vis-a-vis the controller. To exercise your rights, please use the contact details provided above.
Right of access (Article 15 GDPR)
You have the right to obtain confirmation as to whether personal data concerning you are being processed. Where this is the case, you have the right of access to such data and to the information listed in detail in Article 15 GDPR (including processing purposes, categories of data, recipients, storage period, and origin of data).
Right to rectification (Article 16 GDPR)
You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you and, taking into account the purposes of processing, to have incomplete personal data completed.
Right to erasure (Article 17 GDPR)
You have the right to obtain the erasure of personal data concerning you without undue delay where one of the grounds set out in Article 17(1) GDPR applies (e.g., the data are no longer necessary for the purposes for which they were collected), provided that none of the exceptions in Article 17(3) GDPR applies.
Right to restriction of processing (Article 18 GDPR)
You have the right to obtain restriction of processing of your personal data where one of the conditions in Article 18(1) GDPR is met (for example, where you contest the accuracy of the data for the period required for verification by the controller).
Right to data portability (Article 20 GDPR)
You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used, and machine-readable format. You also have the right to transmit those data to another controller where processing is based on consent pursuant to Article 6(1)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR and is carried out by automated means.
Right to object (Article 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you based on Article 6(1)(e) or (f) GDPR. The controller will then no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims (Article 21(1) GDPR).
Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. Where you object to direct marketing, the personal data will no longer be processed for those purposes (Article 21(2) GDPR).
Right to withdraw consent (Article 7(3) GDPR)
Where processing of personal data is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Upon receipt of the withdrawal, the relevant processing will be discontinued.
9. Right to lodge a complaint with the competent supervisory authority (Article 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR (Article 77(1) GDPR).
The controller is based in Hungen (Hesse). The competent supervisory authority is therefore:
The Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
P.O. Box 3163
65021 Wiesbaden
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
You may also contact another supervisory authority, in particular the authority at your habitual residence or place of work.
10. Automated Decision-Making and Profiling
No automated decision-making, including profiling within the meaning of Article 22(1) and (4) GDPR, takes place on this website. No procedures are used that are based solely on automated processing of personal data - including profiling - and that produce legal effects concerning data subjects or similarly significantly affect them.
11. Currency and Amendments to This Privacy Policy
This Privacy Policy is current as of July 2026. As a result of further development of our website and services, or due to changes in legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version of this Privacy Policy can be accessed and printed at any time at https://rym-ai.solutions.
