PRIVACY POLICY
Privacy.
Effective: September 23, 2026
Controller within the meaning of GDPR:
Forge12 Interactive GmbH, Josefstr. 37, 78166 Donaueschingen, Germany
Phone: +49 771 175 14272 · Email: dsb@silentchat.de
We collect data in the following contexts:
When visiting our website: browser type and version, OS, referrer URL, hostname, time. IP address is stored after 7-bit masking (e.g. 91.204.5.0). Retention: 14 days in server logs.
When creating an account: name, email, company, subdomain, password (Argon2id hash). Optional: phone, logo, branding colors. In addition, how you found us: the campaign details in the link you came through (utm parameters), the page on which you entered our website and the domain of the referring page — and, voluntarily, your answer to the question “How did you hear about us?”. We only evaluate this in aggregate, to see which routes lead to sign-ups (Art. 6 (1) (f) GDPR). The details are deleted together with your account.
When you join the waitlist: email address, language, the time of your consent and a SHA-256 checksum of your IP address (not in plain text) — as proof of consent and to detect abuse. We use the address solely to let you know once a place becomes available. We do not store your browser type for this.
When downloading and updating the desktop app: We deliver the installation file of the desktop app for Windows and its updates via our server api.forge12.com. This server is connected through the network of Cloudflare, Inc. (San Francisco, USA). When you download the file and when the app checks for updates, Cloudflare processes your IP address and the technical details of the request (browser or app version, time) in order to deliver the file and protect the server against attacks (Art. 6 (1) (b) and (f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework. For your work, the app then connects exclusively to SilentChat's servers in Germany.
When using the product: conversations, tickets, survey responses, workflow configurations, KB content. Audit log over every administrative action. Sign-in log with time, IP address and browser of every sign-in — to fend off abuse.
Team chat: messages a customer’s staff write to each other, including attachments, mentions, a reference to a customer conversation and read status. They are visible only to the members of the respective chat — the customer’s administrators cannot read other people’s direct messages either. Here, too, we act as the customer’s processor.
When the widget is embedded by one of our customers: here, we are the processor, the customer is the controller. Which data is collected exactly is governed by the respective customer's privacy policy.
Reach measurement: On silentchat.de and app.silentchat.de we use Matomo to measure how our pages are used: pages viewed, time on page, approximate origin, device type and the referring address. On silentchat.de we also count individual interactions as events — for example clicks on buttons such as “Start for free”, submitting a form, and using the live demo and the chat window (opened, hint shown, clicked, closed). Only fixed names of these steps are sent, never what you type. The measurement runs without cookies and without recognising you across sessions — we cannot tell whether you have been here before. Your IP address is shortened by two bytes before storage (e.g. 91.204.5.0). If your browser sends a “Do Not Track” signal, we do not measure at all. We run Matomo on our own server; the data is not passed on to anyone.
Live chat on this website: You can open a chat window at the bottom right. It is our own product — here we are both the vendor and the operator. As long as you do not start a chat, no identifier and no chat session is created. The chat window only remembers in your browser storage whether it has already shown you a hint or its name tag; these markers contain no identifier and are not sent to us (see §7). Once you start a conversation we process your messages, the page you are writing from, your language choice, and your name and email address if you choose to provide them. So that your conversation survives a page reload, we store an identifier in your browser local storage; it is derived from browser type, language, screen size, time zone and the moment you first opened the chat. There is no canvas fingerprinting, and recognising you on other websites is therefore not possible. We do not store your IP address with the conversation; it is used only in hashed form to prevent abuse. If our AI assistant answers first, your message is sent to our AI provider IONOS (data centres in Germany, see §4); on request, or when the assistant is unsure, it hands over to a human. We currently have no fixed retention period for chat histories — you can request deletion at any time via the contact details below (Art. 17 GDPR). The legal basis is Art. 6 (1) (b) or (f) GDPR (responding to your enquiry).
Processing is based on:
· Art. 6 (1) b GDPR — contract performance (e.g. account management, tool usage)
· Art. 6 (1) c GDPR — legal obligation (taxes, AO §147 retention)
· Art. 6 (1) f GDPR — legitimate interest (security, fraud prevention, product improvement)
· Art. 6 (1) a GDPR — consent (newsletter, waitlist, optional marketing cookies)
We use the following subprocessors, each under a DPA per Art. 28 GDPR. Current list:
- Hetzner Online GmbH (Falkenstein/Vogtland, DE) — hosting of the application, database, website and widget
- Strato AG (Berlin, DE) — offsite store for encrypted backups (HiDrive); delivery of the DPA documents
- IONOS Cloud GmbH (Karlsruhe, DE) — AI model hub, LLM inference in German data centers
- Stripe Payments Europe Ltd. (Dublin, IE) — payment processing
- Matomo (self-operated, Germany) — cookieless reach measurement. No third party has access; the data never leaves our own servers.
- Cloudflare, Inc. (San Francisco, USA) — delivery of the desktop app only (download and updates), see §2; EU-US Data Privacy Framework
IONOS is our only AI provider, which keeps AI processing entirely in Germany. We do not use AI providers based outside the EU.
We store personal data only as long as necessary for the respective purpose. Details see Data lifecycle.
Concretely: account data while the account exists + 30 days; conversations default 180 days (configurable 7–365); team chat messages and their attachments after the same period as chat messages, counted from sending (default 180 days, at most 365); audit log and activity log 12 months (up to 24 months on plans with a longer viewing period); records of data protection requests and deletions 3 years; the acceptance of the data processing agreement for the term of the contract and 3 years beyond; sign-in log 90 days; backups 30 days rolling; server logs with 7-bit-masked IP (website access, see §2) 14 days; separately, the SHA-256-hashed IP for technical deduplication (never plain text) 24 hours.
Deletion and trash. When you delete something in the dashboard — a contact, a company, a ticket, a tag, a team member or a file — the entry disappears from all views immediately. It is permanently removed no earlier than 30 days later, by a daily cleanup run; uploaded files are deleted from file storage at the same time. During that period an accidental deletion can be undone.
If you request immediate erasure of your data (Art. 17 GDPR), this period does not apply — the data is then removed straight away, without any waiting time.
Waitlist. An entry is permanently deleted as soon as you register with the same email address, at the latest 12 months after you joined if no place has become available by then, and 90 days after we notified you of an available place. You can withdraw your consent at any time with effect for the future, for example by email to dsb@silentchat.de; we will then delete the entry without undue delay.
You have the right at any time to:
· Access (Art. 15) — we deliver within 30 days, usually within 24h
· Rectification (Art. 16) — self-editable in account settings
· Erasure (Art. 17) — self-service, 30 days primary, 60 days incl. backups
· Restriction (Art. 18)
· Data portability (Art. 20) — JSON export, signed
· Objection (Art. 21)
· Complaint to the competent supervisory authority (Baden-Württemberg State Commissioner for Data Protection and Freedom of Information)
Requests to: dsb@silentchat.de
We use no tracking cookies, no analytics cookies, no advertising cookies.
In the dashboard (app.silentchat.de) the login session is kept in localStorage — no server-side cookie. The marketing site (silentchat.de) may set a NEXT_LOCALE cookie via the i18n layer to remember the visitor's language (1 year, strictly necessary under TTDSG § 25 (2)).
If you embed the visitor widget on your site with consent mode enabled, the browser may also store a technical session identifier for the widget after the visitor consents — see the widget documentation for details and configuration.
Our own live chat on this site (see §2) sets no cookies. As soon as you start a conversation it stores a few entries in your browser local storage: the identifier, the session, a resume marker, your language choice and the notification-sound setting. This happens only through your active choice and is strictly necessary for this service you explicitly requested (TTDSG § 25 (2)) — we do not need separate consent for it. You can remove these entries at any time by clearing your browser local storage for this site.
Even before you start a conversation, the chat window may store up to three small markers in your browser storage so that it does not approach you repeatedly: whether a hint has already been shown in this tab (sessionStorage, ends when you close the tab), when you closed a hint (localStorage, no hint for seven days afterwards) and whether the name tag on the chat button has been shown before (localStorage). The markers contain only “1” or a point in time — no identifier and no information about you — and are not sent to us. They serve solely to show hints as unobtrusively as you may expect; we therefore consider them strictly necessary (TTDSG § 25 (2)). You can remove them at any time by clearing your browser storage for this site.
Reach measurement (see §2) also works without cookies. That is why we do not ask for consent for it: nothing is stored on your device and nothing is read from it — § 25 (1) TTDSG does not apply. The legal basis is our legitimate interest in improving our pages (Art. 6 (1) (f) GDPR); you can object at any time by enabling “Do Not Track” in your browser.
Encryption in transit (TLS 1.3) and at rest (AES-256-GCM). Tenant isolation enforced at the repository layer. Full security documentation: silentchat.de/security
We version our privacy policy. The version on this page applies; the date at the top shows when it took effect. To stay informed about changes, please check this page.
Changes since August 26, 2026:
- September 23, 2026 (§2, §4): Downloading and updating the desktop app via api.forge12.com and Cloudflare added.
- September 21, 2026 (§2): Origin of the sign-up and the voluntary answer to “How did you hear about us?” added.
- September 19, 2026 (§2, §5): Retention periods for logs added — audit and activity log, records, sign-in log.
- September 17, 2026 (§2, §5): Team chat added — internal staff messages, attachments and retention.
- September 16, 2026 (§9): No longer promises to announce changes by email in advance; this list added.
- September 16, 2026 (§4): Server location corrected: Falkenstein (Vogtland).
- September 16, 2026 (§4): Two US AI providers removed — IONOS is our only AI provider.
- September 16, 2026 (§2, §3, §5): Waiting list added: data, legal basis, retention and withdrawal.
- September 14, 2026 (§2, §7): Chat window markers before a chat starts and counted interactions described.
- September 7, 2026 (§2, §4, §7): Cookieless analytics with Matomo added.
- September 7, 2026 (§4): Hetzner named as operator of the application; Strato only for encrypted backups and the DPA documents.
- August 26, 2026 (§5): Trash described: deleted items disappear after 30 days at the earliest; a request under Art. 17 GDPR is not subject to that delay.
Earlier changes are not listed individually; the first version dates from June 1, 2026.