ProScoutAI Back to home
DE| EN| TR

Privacy Policy

This privacy policy describes the processing of personal data when you visit proscout-ai.com and contact ProScoutAI. Last updated: 22 August 2026.

This English version is a translation of the German privacy information.

1. Controller

Oguzhan Cosgun
ProScoutAI
Vorgebirgstr. 9A
50677 Köln
Germany

Email: contact@proscout-ai.com

2. Hosting and server logs

The website and email infrastructure are hosted by the following provider:

ALL-INKL.COM – Neue Medien Münnich
Hauptstraße 68
02742 Friedersdorf
Germany

When a website is accessed, web servers must technically process connection data. This may include, in particular, the IP address, date and time, the address or file accessed, HTTP method, amount of data transferred, status code, referrer, and browser and operating system information. This data may be processed in server logs to deliver the website, detect disruptions and ensure the security of the systems.

The legal basis is Article 6(1)(f) GDPR. The legitimate interests are the secure, stable and abuse-free operation of the website. According to the hosting provider’s publicly available privacy information, log files are generally deleted after no more than seven days; longer storage may be necessary in individual cases, for example in the event of an attack on IT systems. The specific log configuration may depend on the hosting package booked.

3. Our own privacy-conscious first-party reach statistics

ProScoutAI operates its own reach statistics in the same hosting environment. They are used to understand use of the website in broad categories, check its functionality and classify technical or automated access.

Only the following information is stored in our own statistics for a page view:

  • the page or language route accessed,
  • date and hour as an hourly category,
  • the source category email, linkedin, direct or other,
  • a coarse country code, where this can be derived on the server or from a local database,
  • the device class desktop, mobile or tablet,
  • a technical indication of whether the access may be from a bot, scanner or comparable automated system.

The full IP address is not stored in our own statistics. It may only be processed briefly in the server process to derive a coarse country code where this is locally possible. The full user agent is likewise not stored and is processed only temporarily to derive the device class and a possible bot indication.

There is no persistent visitor ID and no recognition across multiple page views. The statistics do not store a complete query string. The src parameter is reduced to the four categories listed above.

No dwell time, clicks, pointer, scroll, keyboard or touch interactions, visibility or pagehide events, browser language or referrer domain are collected for new page views. There is no cross-site tracking and no fingerprinting.

The legal basis is Article 6(1)(f) GDPR. The legitimate interests are privacy-conscious reach measurement, technical quality control and the detection of automated access. The data is generally stored for 90 days. Cleanup takes place whenever new statistics are stored and when the internal statistics dashboard is opened. During a longer period of complete inactivity, actual deletion may not take place until the next of these events.

Technical transition note: Legacy records created before 22 August 2026 may still contain earlier statistics fields until their 90-day period expires. These fields are no longer collected and are no longer displayed in the statistics dashboard.

4. Cookies and browser storage

The public website does not set cookies. It does not use LocalStorage, SessionStorage, IndexedDB or any comparable persistent browser identifier. There is therefore no cookie- or storage-based visitor recognition.

5. Contact form

When you use the contact form, the information you enter is processed: name, email address, club or organisation, role or position, area of interest, message and the language of the page used. Required fields are necessary so that the request can be meaningfully assigned and answered.

The information is transmitted to ProScoutAI by email and used to process your request. Where the request concerns a contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR. For other requests, the legal basis is Article 6(1)(f) GDPR; the legitimate interest is the processing of business and general enquiries.

Contact requests that do not result in a business relationship are generally deleted no later than six months after final processing, unless specific reasons, the establishment, exercise or defence of legal claims, or legal obligations require longer storage.

6. Abuse protection and rate limiting

The contact form uses an invisible honeypot, size and field validation, a simple check of the Origin or Referrer information transmitted by the browser, and server-side rate limiting.

For rate limiting, the source IP is processed only temporarily. The only data stored is a value generated using HMAC-SHA256 and a private server-side key, together with timestamps of accepted attempts. The full IP address and the key are not stored in the rate-limit file. The evaluation window is one hour; outdated entries are removed during the next relevant form request.

The legal basis is Article 6(1)(f) GDPR. The legitimate interest is to protect the form, email infrastructure and website against automated abuse and spam.

7. Direct email communication

If you contact ProScoutAI directly by email, your email address, the content and metadata transmitted, and any other information you provide may be processed to handle the message. Depending on the content, the legal basis is Article 6(1)(b) or (f) GDPR. For requests not followed by a business relationship, the deletion period stated in the contact form section generally applies.

8. External services and recipients

The public website does not embed third-party analytics, marketing trackers, external fonts, maps, videos or social media widgets. Website assets and reach statistics are delivered first-party.

The technical recipient of hosting and email data is the hosting provider named above. Other recipients receive data only where this is necessary to process a request or perform a contract, where there is a legal obligation, or where another legal basis permits it.

9. Transfers to third countries

The current website configuration does not provide for any targeted transfer of personal data to providers in countries outside the European Union or the European Economic Area. If a service involving a third country is used in the future, this policy will be updated before it is used and the necessary data protection safeguards will be reviewed.

10. Automated decision-making

No solely automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place in connection with visiting this website or making contact. Bot detection in the reach statistics is merely a technical heuristic and does not trigger any legal or similarly significant decision about an individual.

11. Rights of data subjects

Subject to the statutory requirements, you have the following rights in particular:

  • access to the personal data processed under Article 15 GDPR,
  • rectification of inaccurate data under Article 16 GDPR,
  • erasure under Article 17 GDPR,
  • restriction of processing under Article 18 GDPR,
  • data portability under Article 20 GDPR, where applicable,
  • objection to processing based on Article 6(1)(f) GDPR under Article 21 GDPR.

To exercise your rights, simply send a message to contact@proscout-ai.com. Statutory limitations and retention obligations remain unaffected.

12. Right to lodge a complaint

Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. This may in particular be the supervisory authority for your place of residence, place of work or the place of an alleged infringement.

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany

Email: poststelle@ldi.nrw.de

13. Security

ProScoutAI uses technical and organisational measures to protect data against accidental or unlawful processing, loss and unauthorised access. These include HTTPS redirection, browser security headers, access controls for private statistics data and the internal dashboard, input validation and restrictive file permissions for private keys. However, no transmission or storage system can guarantee absolute security.

14. Changes to this privacy policy

This privacy policy will be updated if the website, the procedures used or legal requirements change. The current English version is available at https://proscout-ai.com/privacy/.

© 2026 ProScoutAI
Legal Notice Privacy Contact