Privacy Policy
SETTER AI LTD
Last updated: June 2026
In the event of any discrepancies between this English version and the German version of this Privacy Policy, the German version shall prevail.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
SETTER AI LTD
Email: team@trysetter.ai
The full provider details (postal address, registration number and authorised representative) can be found in our Legal Notice.
2. General Information on Data Processing
We process the personal data of our website visitors and clients only insofar as this is necessary for the provision of our website and our services. The processing of personal data generally takes place only with consent or where the processing is permitted by statutory provisions. No automated decision-making producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR) takes place.
3. Hosting and Technical Provision
Our website (trysetter.ai) and our application (App) are hosted by Vercel Inc. (USA). When accessed, information is automatically collected in server log files transmitted by your browser (e.g. IP address, date and time of access, page accessed, browser and operating system). For the operation of our backend, we additionally use a further external infrastructure service provider.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable and secure provision). Vercel Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); for further transfers to third countries, see Section 9.
4. Cookies
We do not use any analytics, tracking or marketing cookies. Insofar as technically necessary cookies are used in the operation of our website and application (e.g. for session management, login and security), this is based on Art. 6(1)(f) GDPR. These cookies are required for provision and do not require consent.
5. Contacting Us
If you contact us by email, the data you provide (e.g. name, email address, content of the message) is processed and stored for the purpose of handling your request.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest).
6. Transactional Emails
For sending transactional emails (e.g. registration confirmations, password resets) we use an external email delivery service provider. Where this provider is based in a third country, Section 9 applies.
7. Processing on Behalf of Our Clients
When we provide our services to a client, we process personal data exclusively on that client's behalf. In this case, the respective client is the controller within the meaning of the GDPR; we act as a processor on the basis of a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR. This processing does not concern visitors to this website. Details — including the sub-processors used — are governed by the DPA.
8. Further Services and Infrastructure
For the operation of our application and the management of client accounts, we use external database and infrastructure service providers. For booking initial calls via our website, we use Calendly LLC (USA); the data processed in this context (e.g. name, email address, requested time) is used to arrange and conduct the call. Calendly LLC is certified under the EU-US Data Privacy Framework (Art. 45 GDPR).
9. Transfer of Data to Third Countries
Some of our service providers are based in the USA. The transfer takes place on the basis of the EU-US Data Privacy Framework (DPF) pursuant to Art. 45 GDPR or on the basis of Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. You may request a copy of the agreed safeguards (Standard Contractual Clauses) as well as further information on the recipients via the contact details provided in Section 1.
10. Retention Period
We store personal data only for as long as is necessary for the respective purposes:
- Server log files are stored only for as long as necessary to ensure operation and security and are deleted thereafter.
- Data from your contact request or appointment booking is stored until your request has been conclusively handled or the call has taken place, unless further retention is required.
- Data within a contractual or client relationship is stored for its duration.
Beyond this, we store data insofar and for as long as we are obliged to do so under statutory retention requirements (in particular commercial and tax law obligations under Cypriot law). Upon expiry of the respective periods, the data is deleted.
11. Your Rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
Where processing is based on your consent, you also have the right to withdraw that consent at any time with effect for the future.
To exercise your rights, please contact: team@trysetter.ai
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is:
Office of the Commissioner for Personal Data Protection (Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kypranoros 15, 1061 Nicosia, Cyprus
Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus
Tel.: +357 22 818 456
Email: commissioner@dataprotection.gov.cy
Web: www.dataprotection.gov.cy
Notwithstanding the above, you may also lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement.
13. Changes
We reserve the right to amend this privacy policy in order to adapt it to current legal requirements or to implement changes to our services.