Privacy Policy
Pursuant to Art. 13 GDPR · Last updated 2026-09-18 · Version 1.2 · Deutsche Version
1. Data Controller
The party responsible for processing personal data on this site is:
Vitali Zavadski
c/o GAM, Pappelallee 64, 10437 Berlin
Email for data-protection enquiries:
kontakt@ancore-engineering.com
AnCore is in a closed test phase (beta). Access is granted by invitation only; there is no public sign-up. Use during the beta is free of charge; no payment processing takes place.
Beta participants additionally accept the Beta Agreement. It governs in particular
the handling of project data, the pilot programme, consent to the use of project
content for AI training, and operator access to project content. It is available at
/beta-agreement.
2. What we process and why
2.1 Account data
- Categories: email, full name (if provided), bcrypt password hash, plan,
is_adminflag,last_seen_attimestamp. - Purpose: authentication, account administration, access to projects.
- Legal basis: Art. 6(1)(b) GDPR.
- Retention: for as long as the account is active. After an erasure request – in the account settings or by email – the account is deleted once 30 days have passed; until then you can cancel the deletion. Name and email address are removed; a pseudonymous account identifier is kept so that audit-log entries (§2.5) remain attributable. Backup copies are deleted no later than 16 days after that.
- Record of document acceptance: when you accept the Beta Agreement and this Privacy Policy, we store the document, its version, the time, a truncated IP address and the browser identifier (user agent) until the account is deleted.
2.2 Project content (FEM models, computation results)
- Categories: structural-engineering data you create or upload (geometry, loads, computed results); project and variant names and free-text descriptions you enter; the federal state (Bundesland) and city of the building project, used to derive applicable loading codes (snow, wind, seismic zones per DIN EN 1991/1998).
- Purpose: persistence so you can return to your work; serving you the results of your own computations.
- Legal basis: Art. 6(1)(b) GDPR.
- Retention: for as long as the account is active.
- Note on free-text fields: project and variant names and descriptions are free-form input fields. Under the Beta Agreement (Section 2), no identifying information about third parties may be entered there, such as names of clients, addresses or names of persons.
2.3 Reverse-proxy access log
- Categories: for each request, the reverse proxy (Caddy) logs the truncated IP address (IPv4: last octet zeroed; IPv6: shortened to /48), timestamp, requested URL, HTTP method, browser identifier (user agent), referrer and response status. The application itself keeps no access log of its own; it stores truncated IP addresses only in the audit log (§2.5) and in the record of document acceptance (§2.1).
- Purpose: secure operation of the service, abuse detection, debugging.
- Legal basis: Art. 6(1)(f) GDPR – legitimate interest in availability and security.
- Retention: 14 days, then automatically deleted as part of log rotation. The audit log is covered by §2.5.
2.4 Operator access to project content (support, pilot programme, debugging, security)
- Categories: project content (see §2.2) and account metadata (see §2.1).
- Purpose: technical support, support within the pilot programme, error analysis, investigation of service disruptions, and security incident response. The operator may also reset a user's password upon request and search the user database by email when handling a support request.
- Legal basis: Art. 6(1)(b) GDPR (operating the service) + Art. 6(1)(f) GDPR (legitimate interest in service reliability and security).
- Available operator actions, all logged:
- viewing a user's project list and opening a variant in read-only mode (
admin_view); - creating a debug copy of a variant (
admin_clone); - revealing a user's email (
admin_reveal_email); - revealing the stored, truncated IP address of a login event (
admin_reveal_ip); - resetting a user's password (
admin_reset_password); - viewing a screenshot attached to a feedback report (
feedback_screenshot_view); - recording a consent given or withdrawn in text form (§2.6), and setting or lifting a firm-wide exclusion from AI training for an account;
- exporting CSV reports of pseudonymised activity (metrics, logins, compute history).
- viewing a user's project list and opening a variant in read-only mode (
- Safeguards: access is role-based and limited to designated administrator accounts. Operator access does not extend project-data retention. Debug copies are marked as such, excluded from any AI training, and scheduled for automatic deletion after 30 days. Project content is never viewed without a specific reason.
2.5 Application audit log
- Categories: event records – timestamp, event type, acting user, where applicable affected user and object reference (project, variant), truncated IP. The following are logged:
- registration (with email address) and acceptance of legal documents;
- login and failed login;
- password and profile changes;
- creating and deleting projects (with project name);
- start of a computation;
- data export, and requesting or cancelling an account deletion;
- all operator actions listed in §2.4.
- Note on failed-login records: when an attempt fails, the entered email is stored in the audit log for brute-force detection. This may include the email of a person who does not have an AnCore account.
- Purpose: security monitoring, abuse detection, accountability for operator access (Art. 5(2) GDPR).
- Legal basis: Art. 6(1)(f) GDPR.
- Retention: operator-access events (§2.4) – 365 days; all other events – 90 days. Automatic deletion thereafter.
2.6 Use of project content for model development – only with your consent
We do not use your project content to train or develop machine-learning models unless you have expressly consented in advance. Consent is voluntary; without it you can use AnCore, the beta and the pilot programme without restriction. You give it per project in the project settings or in text form, for example by email to the address in §1, and can withdraw it the same way at any time with effect for the future. If your firm has excluded such use for its accounts, we do not use your project content even if consent has been given.
- Categories (only with consent): technical parameters derived from geometry, loads and computation results, including the federal state as the basis for the snow, wind and seismic zone. Identifying information – project and variant names, address details, user identifiers, file names, descriptions and comments – is removed at extraction and not added to the training data.
- Purpose: training and improving the machine-learning models used in AnCore.
- Legal basis: Art. 6(1)(a) GDPR (consent). Without consent we process project content solely to provide the service (§2.2).
- Withdrawal: after a withdrawal no further parameters are extracted from the project concerned. Parameters that have already been anonymised can no longer be traced to individual projects and therefore cannot be removed.
- Record of consent: we store the time, project and version of every consent and every withdrawal; for consent given by email, also the related message.
- Retention: the anonymised training data is retained for the duration of model development.
- Exclusion: administrator debug copies (see §2.4) are never used for training.
2.7 AI assistant features
The term “AI” in AnCore: in the interface, “AI” marks features that support you automatically in design and dimensioning – with machine-learning models or with rule-based algorithms. Only the features named in this section transmit data to Anthropic. All other features with “AI” in their name, such as AI Beam, AI Stability Support and AI Wall Optimizer, run on our servers or directly in your browser and do not transmit any data to Anthropic. In the “Full Building” view we compute the cost and CO₂ estimate on our servers; only the accompanying AI insight (short text) is generated via Anthropic.
- Features:
- AI Chat (“Basic” and “Smart” modes, including “Ask Smart AI to reduce the thickness”);
- Lazy Design – drafting a model from a text description, also as “Explore variants”;
- AI insight – a short text on cost and life-cycle assessment in the “Full Building” view.
- When requests are made: the AI insight is requested automatically as soon as you open the “Full Building” view, and again after each new computation while that view is open. The default view is “Structure only”; no AI insight is requested there. The structural computation itself works without any transmission to Anthropic.
- Categories: we transmit
- the texts you actively enter into these features (prompts), for AI Chat including the conversation so far in the current session, and
- where the feature requires it, an automatically generated technical summary of the current model and the latest computation (e.g. storeys, grid and axis labels, member dimensions, materials, loads, type of use, location (city), utilisation ratios, CO₂ and cost figures).
- Purpose: providing the features named above.
- Legal basis: Art. 6(1)(b) GDPR – you actively invoke AI Chat and Lazy Design; the AI insight is part of the “Full Building” view that you open.
- Recipient / transfer: Anthropic, PBC, USA (see §4 and §5).
- Retention: under its commercial terms Anthropic generally deletes transmitted inputs and outputs within 30 days and does not use them to train its models. Within AnCore, prompts and responses are not stored; the chat history exists only in your open browser window. Model changes you adopt from an AI response are saved like any other model change.
- Important note: because your inputs to these features are transmitted to a third-party service, please avoid entering confidential project, client, or personal data into these fields.
2.8 Service usage telemetry
- Categories: activity timestamp (
last_seen_at, updated at most once per minute), per-account counts of projects and computations, and per-run technical metadata (compute_runs: size of model, computation duration, CO₂ and cost results, snapshot of the building project's federal state and city at the time of computation). - Purpose: displaying "currently active users" and aggregated usage statistics to the operator for capacity planning; per-run records also support debugging.
- Legal basis: Art. 6(1)(f) GDPR. In the operator dashboard, identification is pseudonymised by default; the full email is revealed only by a logged operator action (
admin_reveal_email). - Retention: stored for the duration of the account.
2.9 Server metrics (no personal data)
- Categories: CPU, RAM, load, disk usage of the AnCore server (no account link).
- Purpose: infrastructure monitoring and capacity planning.
- Retention: 30 days.
2.10 Enquiries, pilot requests and appointment booking
- Data categories: name, e-mail address, firm/company and the content of your message; for an online booking additionally the slot you choose and what you state about your request. For the contact form on our landing page additionally the time, the version of this privacy policy you confirmed, your truncated IP address (last octet removed, or the second half for IPv6) and your browser identifier, each to prevent abuse.
- Purpose: answering your enquiry, arranging and holding demo appointments, and running the pilot programme.
- Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures); for enquiries without contractual context Art. 6(1)(f) GDPR (legitimate interest in communicating with prospective customers).
- Recipients: Microsoft (see §4) as operator of our mailbox and of the online booking page. Requests sent through the contact form on our landing page are stored in our database on our server in Germany (Hetzner, see §4); in addition we receive a notification with the details in our mailbox.
- Retention: until your enquiry has been dealt with; beyond that only where statutory retention periods require it. We delete earlier on request.
2.11 Business contacts and direct outreach
- Categories: name, role and business contact details (email address, phone number, postal address) of contact persons at planning offices and companies; name and website of the office; publicly known project and competition information; the history of our outreach; consents and objections you have given.
- Source: publicly accessible sources, in particular office websites, published competition results and professional networks such as LinkedIn.
- Purpose: business outreach about AnCore and the pilot programme – by letter, phone, email or via professional networks; record keeping so that we do not contact anyone repeatedly and respect objections.
- Legal basis: Art. 6(1)(f) GDPR – legitimate interest in initiating business relationships. If you agree to receive further information from us, we store the date, channel and wording of your agreement as proof.
- Recipients: Microsoft (see §4) as operator of our mailbox and as the storage location of our contact list (OneDrive).
- Retention: until you object, and at the latest 12 months after the last contact without a response. Records of agreements are kept for up to three years after the communication has ended. After an objection we keep only your contact address and your office's domain on a block list so that we do not contact you again.
- Objection: you can object to this processing at any time (Art. 21 GDPR); a short message to the address in §1 is sufficient.
2.12 Videos on our website (YouTube, two-click solution)
Our landing page embeds videos hosted on YouTube. Opening the page does not yet
connect to YouTube: you see a preview image hosted by us together with a notice.
Only when you click "Play" is the video loaded from
www.youtube-nocookie.com (privacy-enhanced mode). The link
"Watch on YouTube" takes you directly to YouTube.
- Data categories: from the click onwards your IP address, browser and device data, the page visited and your behaviour in the video player; if you are signed in to Google, Google may link the playback to your account. After the click YouTube may set cookies or similar technologies in your browser.
- Purpose: product demonstration by video.
- Legal basis: your consent given by the click, Art. 6(1)(a) GDPR and §25(1) TDDDG. Without the click no data is transmitted to YouTube.
- Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (see §4 and §5). Google processes this data as an independent controller; details in Google's privacy policy at policies.google.com/privacy.
- Retention: determined by Google. We ourselves store no data about the playback.
3. Cookies and local storage
We use only strictly necessary client-side storage:
- JSON Web Tokens (access + refresh) held in your browser's
localStorageto keep you signed in between page loads. - No tracking cookies, no advertising cookies, no third-party analytics on the production deployment.
- The only exception: after you click an embedded YouTube video (§2.12) YouTube may set cookies; this is based on your consent.
Because none of this storage is used for tracking or profiling, no cookie-consent banner is required under §25(2)(2) TDDDG (formerly TTDSG; renamed effective 14 May 2024, content unchanged).
4. Recipients and sub-processors
Your data is processed by the following sub-processors:
- Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany – server hosting and managed storage. AnCore's servers and backup copies are located in Germany. Data-processing agreement under Art. 28 GDPR is in place.
- Anthropic, PBC, San Francisco, USA – large-language-model API for the features described in §2.7. Scope: as described in §2.7 (your inputs and, where required, a technical summary of model and computation; no uploaded files). Data-processing agreement and EU Standard Contractual Clauses under Art. 46 GDPR are in place via Anthropic's terms.
-
Functional Software, Inc. ("Sentry"), EU instance hosted in Germany –
error tracking and exception reporting. Scope: stack traces and request
metadata; personal data collection is disabled (
send_default_pii=False). Data is processed exclusively on Sentry's EU infrastructure and does not leave the European Union. Data-processing agreement is in place via Sentry's terms. - Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland – operation of our mailbox, online appointment booking and the storage of our contact list (Microsoft 365 / Exchange Online / Bookings / OneDrive). Scope: the communication, contact and appointment data listed in §2.10 and §2.11; no project content or application account data is transmitted. Our tenant is registered in the EU and therefore falls under the Microsoft EU Data Boundary: customer data is stored and processed in datacentres within the EU/EFTA. Data-processing agreement and EU Standard Contractual Clauses are in place via the Microsoft Data Protection Addendum (DPA).
No other third-party analytics, advertising, or font CDNs are loaded on the production site. Fonts are self-hosted.
5. International transfers
The only recipient to which personal data is transferred to the United States as a matter of course is Anthropic, PBC (see §2.7).
After you click a YouTube video (§2.12) Google may transfer data to the United States. Google LLC is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR); in addition Google relies on the EU Standard Contractual Clauses.
Transfer to the United States is based on the EU Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR. Depending on the provider's configuration, processing may also take place in data centres outside the United States.
For e-mail communication, the contact list and appointment booking (see §2.10 and §2.11) the Microsoft EU Data Boundary applies: this data is stored and processed within the EU/EFTA. In limited cases documented by Microsoft – technical support, for instance – transfers to third countries can occur; these are covered by the EU Standard Contractual Clauses in the Microsoft DPA.
All other personal data (account data, project content, audit logs, server logs, backup copies) is held on servers in Germany (Hetzner).
6. Automated decision-making
AnCore provides engineering computation results and proposals that the user reviews and adjusts. No automated decision producing legal or similarly significant effects on a natural person within the meaning of Art. 22 GDPR is made.
7. Your rights
Under the GDPR you have the right to:
- access your personal data (Art. 15);
- rectify inaccurate data (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- data portability – receive your data in a structured, machine-readable format (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw any consent you have given (Art. 7(3)), without affecting the lawfulness of past processing;
- lodge a complaint with a supervisory authority – typically the data-protection authority of the federal state in which the controller resides.
You can send requests by email to the address in §1; data export and account deletion are also available in the account settings.
8. Security measures (Art. 32 GDPR)
We apply, among others, the following technical and organisational measures:
- passwords are stored only as bcrypt hashes;
- authentication via signed JSON Web Tokens (HS256) with expiry;
- transport encryption via TLS (Caddy / Let's Encrypt); HSTS with one year and
includeSubDomains; security headers (X-Frame-Options: DENY,X-Content-Type-Options: nosniff,Referrer-Policy); - IP addresses are truncated at storage on the application layer (IPv4: last octet zeroed; IPv6: /48); the reverse proxy is configured equivalently;
- rate limiting on the login endpoint (5 attempts per minute);
- role-based access control for administrator functions; every action is recorded in an audit log whose entries are not modified after they are written;
- error tracking on the EU-hosted Sentry instance with personal-data transmission disabled (
send_default_pii=False); - database backups (
pg_dump) encrypted with GPG-AES256 before transfer to off-site storage; the passphrase is held off-server (password manager); - secrets file (
.env) encrypted with GPG-AES256 in backups; the key is held off-server.
9. Changes to this policy
We may update this policy as the service evolves. The current version is always
available at /privacy; the "last updated" date and version number at the top
of this page reflect the most recent revision.