Privacy Policy
Effective: November 1, 2025 | Last updated: 2/20/2026
Table of Contents
1. Data Controller
Controller: Faultrix GmbH
Business Address: Linz, Austria
Country: Austria
Contact: support@faultrix.com
Website: https://www.faultrix.com
This data controller is the operator and owner of this website and is responsible for data processing.
2. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Art. 6(1)(a) GDPR (Consent): You have explicitly consented to the processing
- Art. 6(1)(b) GDPR (Contract): Processing is necessary for contract performance
- Art. 6(1)(c) GDPR (Legal Obligation): We are legally required to process this data
- Art. 6(1)(f) GDPR (Legitimate Interest): We have a legitimate interest in data processing
3. Data Collected and Purpose
👤 Account Data
Purpose: Authentication and account management
- • Email address
- • Name (optional)
- • Password (hashed)
- • Profile picture (if uploaded)
Legal Basis: Contract performance (Art. 6(1)(b) GDPR)
📸 Uploaded Photos
Purpose: AI-powered construction defect analysis
- • Original photos
- • EXIF metadata (date, time, GPS if available)
- • Image analysis results
Legal Basis: Contract performance, Consent for EXIF data
📊 Usage Data
Purpose: Improving our services
- • Access times
- • Features used
- • Error messages
- • Device type and browser
Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR)
💳 Payment Data
Purpose: Processing payments via Stripe
- • Transaction ID
- • Purchase date
- • Amounts
- • Payment status
Legal Basis: Contract performance. Stripe processes card data directly.
5. Subprocessors
We use the following providers for specific processing activities:
| Provider | Purpose | Location | Data Categories | Transfer Mechanism |
|---|---|---|---|---|
| Clerk | Authentication and session management | USA | Account data, Session tokens, Login metadata | SCCs (EU 2021/914), where required |
| Convex | Application database and backend operations | USA | Account records, Analysis metadata, Technical usage data | SCCs (EU 2021/914), where required |
| Cloudflare R2 | File storage for uploaded photos and exports | Cloudflare (region konfigurierbar) | Photos, EXIF metadata (where available), Object metadata (e.g., hash, upload timestamp) | Depends on configuration; SCCs (EU 2021/914) where required |
| Vercel | Hosting, delivery, and operational monitoring | Weltweit | Request metadata, Technical logs | SCCs (EU 2021/914), where required |
| Stripe | Payment processing and fraud prevention | USA | Transaction data, Payment status, Billing metadata | SCCs (EU 2021/914), where required |
| Open BigModel (GLM) | AI analysis of uploaded image content (primary model provider) | China | Image content, Analysis prompts and context data | SCCs (EU 2021/914), where required |
| OpenAI (Fallback) | Fallback AI processing if GLM is unavailable | USA | Image content, Analysis prompts and context data | SCCs (EU 2021/914), where required |
| Google Maps Platform | Map display, address autocomplete, and location verification (optional) | Weltweit | GPS coordinates, Address/map requests, Technical usage data | SCCs (EU 2021/914), where required |
| PostHog (Analytics) | Website/product analytics (consent-based) | EU (Server verfuegbar) / Weltweit | Pseudonymous user IDs, Events and properties, Usage metadata | Depends on configuration; SCCs (EU 2021/914) where required |
| Sentry (Error Tracking) | Error reporting and diagnostics (consent-based) | USA | Error events, Stack traces, Session diagnostics (on errors only, if enabled) | SCCs (EU 2021/914), where required |
All providers are contractually bound to data protection and security obligations.
For detailed subprocessors and vendor information, see our Subprocessors page. Subprocessors page.
Last verified: 2026-02-11
We use DPAs under GDPR Article 28 with subprocessors where required and provide information upon request.
International transfers:
Personal data may, depending on the vendors used and your usage/consent, be processed outside the EU/EEA (e.g., hosting, authentication, AI analysis, analytics). Where required, transfers to third countries rely on appropriate safeguards, in particular Standard Contractual Clauses (SCCs) pursuant to EU Commission Decision 2021/914 plus supplementary technical measures. See the subprocessors list for vendor locations and mechanisms.
6. Data Retention
When you delete your account:
- Day 0: Your account is deactivated and your data becomes inaccessible.
- Day 1-30: Grace period. You can contact support to recover your account.
- Day 30: Photos, analyses, and personal data are permanently deleted.
- Exception: Invoice data is retained for 7 years under Austrian tax law (BAO §132), anonymized, and no longer linked to your account.
- Exception: Anonymized audit logs may be retained for security purposes.
7. Your Rights under GDPR
You have the following rights regarding your personal data:
📋 Right of Access (Art. 15 GDPR)
You can request what data we store about you. To receive a data copy, contact us at support@faultrix.com
✏️ Right to Rectification (Art. 16 GDPR)
You can have incorrect data corrected. In your account settings, you can change much data yourself.
🗑️ Right to Erasure / Right to be Forgotten (Art. 17 GDPR)
You can request deletion of your data via account settings ("Delete Account") or by contacting us. support@faultrix.com
⏸️ Right to Restriction (Art. 18 GDPR)
Under certain circumstances, you can request restriction of processing.
📤 Data Portability (Art. 20 GDPR)
You have the right to receive your data in a machine-readable format.
🚫 Right to Object (Art. 21 GDPR)
You can object to the processing of your data, especially for direct marketing.
Right to Erasure (Art. 17 GDPR)
- You can request complete deletion of your personal data under GDPR Article 17.
- Requests can be sent by email to the data controller at: support@faultrix.com
- We respond to erasure requests within 30 days in line with GDPR requirements.
- Records that must be retained by law cannot be deleted, especially invoice data under BAO §132.
⚖️ Right to Complain
In case of privacy violations, you can contact the Austrian Data Protection Authority:
Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
https://www.dsb.gv.at
8. Data Security
We protect your data through:
9. Privacy Contact
For questions or requests about your data, contact us:
Data Protection Officer:
Faultrix GmbH
support@faultrix.com
General Contact:
support@faultrix.com