Privacy Policy

Effective: November 1, 2025 | Last updated: 2/20/2026

1. Data Controller

Controller: Faultrix GmbH

Business Address: Linz, Austria
Country: Austria
Contact: support@faultrix.com
Website: https://www.faultrix.com

This data controller is the operator and owner of this website and is responsible for data processing.

2. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Art. 6(1)(a) GDPR (Consent): You have explicitly consented to the processing
  • Art. 6(1)(b) GDPR (Contract): Processing is necessary for contract performance
  • Art. 6(1)(c) GDPR (Legal Obligation): We are legally required to process this data
  • Art. 6(1)(f) GDPR (Legitimate Interest): We have a legitimate interest in data processing

3. Data Collected and Purpose

👤 Account Data

Purpose: Authentication and account management

  • Email address
  • Name (optional)
  • Password (hashed)
  • Profile picture (if uploaded)

Legal Basis: Contract performance (Art. 6(1)(b) GDPR)

📸 Uploaded Photos

Purpose: AI-powered construction defect analysis

  • Original photos
  • EXIF metadata (date, time, GPS if available)
  • Image analysis results

Legal Basis: Contract performance, Consent for EXIF data

📊 Usage Data

Purpose: Improving our services

  • Access times
  • Features used
  • Error messages
  • Device type and browser

Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR)

💳 Payment Data

Purpose: Processing payments via Stripe

  • Transaction ID
  • Purchase date
  • Amounts
  • Payment status

Legal Basis: Contract performance. Stripe processes card data directly.

4. Cookies and Similar Technologies

🔒 Essential Cookies

Technically necessary for basic functionality

CookiePurposeDuration
__clerk_sessionAuthenticationSession
cookie_consentStores your cookie preferences1 Year
__Host-next-authSession securitySession

📊 Analytics Cookies (optional)

Only activated with your consent

Vercel AnalyticsAnonymous usage statisticsSession

You can change your cookie preferences at any time. Manage Cookie Settings

5. Subprocessors

We use the following providers for specific processing activities:

ProviderPurposeLocationData CategoriesTransfer Mechanism
ClerkAuthentication and session managementUSAAccount data, Session tokens, Login metadataSCCs (EU 2021/914), where required
ConvexApplication database and backend operationsUSAAccount records, Analysis metadata, Technical usage dataSCCs (EU 2021/914), where required
Cloudflare R2File storage for uploaded photos and exportsCloudflare (region konfigurierbar)Photos, EXIF metadata (where available), Object metadata (e.g., hash, upload timestamp)Depends on configuration; SCCs (EU 2021/914) where required
VercelHosting, delivery, and operational monitoringWeltweitRequest metadata, Technical logsSCCs (EU 2021/914), where required
StripePayment processing and fraud preventionUSATransaction data, Payment status, Billing metadataSCCs (EU 2021/914), where required
Open BigModel (GLM)AI analysis of uploaded image content (primary model provider)ChinaImage content, Analysis prompts and context dataSCCs (EU 2021/914), where required
OpenAI (Fallback)Fallback AI processing if GLM is unavailableUSAImage content, Analysis prompts and context dataSCCs (EU 2021/914), where required
Google Maps PlatformMap display, address autocomplete, and location verification (optional)WeltweitGPS coordinates, Address/map requests, Technical usage dataSCCs (EU 2021/914), where required
PostHog (Analytics)Website/product analytics (consent-based)EU (Server verfuegbar) / WeltweitPseudonymous user IDs, Events and properties, Usage metadataDepends on configuration; SCCs (EU 2021/914) where required
Sentry (Error Tracking)Error reporting and diagnostics (consent-based)USAError events, Stack traces, Session diagnostics (on errors only, if enabled)SCCs (EU 2021/914), where required

All providers are contractually bound to data protection and security obligations.

For detailed subprocessors and vendor information, see our Subprocessors page. Subprocessors page.

Last verified: 2026-02-11

We use DPAs under GDPR Article 28 with subprocessors where required and provide information upon request.

International transfers:

Personal data may, depending on the vendors used and your usage/consent, be processed outside the EU/EEA (e.g., hosting, authentication, AI analysis, analytics). Where required, transfers to third countries rely on appropriate safeguards, in particular Standard Contractual Clauses (SCCs) pursuant to EU Commission Decision 2021/914 plus supplementary technical measures. See the subprocessors list for vendor locations and mechanisms.

6. Data Retention

Account dataUntil account deletion + 30 days backup
Photos & Analyses2 years after last activity
Invoice data7 years (legal requirement)
Server logs90 days
Cookie preferences1 year

When you delete your account:

  • Day 0: Your account is deactivated and your data becomes inaccessible.
  • Day 1-30: Grace period. You can contact support to recover your account.
  • Day 30: Photos, analyses, and personal data are permanently deleted.
  • Exception: Invoice data is retained for 7 years under Austrian tax law (BAO §132), anonymized, and no longer linked to your account.
  • Exception: Anonymized audit logs may be retained for security purposes.

7. Your Rights under GDPR

You have the following rights regarding your personal data:

📋 Right of Access (Art. 15 GDPR)

You can request what data we store about you. To receive a data copy, contact us at support@faultrix.com

✏️ Right to Rectification (Art. 16 GDPR)

You can have incorrect data corrected. In your account settings, you can change much data yourself.

🗑️ Right to Erasure / Right to be Forgotten (Art. 17 GDPR)

You can request deletion of your data via account settings ("Delete Account") or by contacting us. support@faultrix.com

⏸️ Right to Restriction (Art. 18 GDPR)

Under certain circumstances, you can request restriction of processing.

📤 Data Portability (Art. 20 GDPR)

You have the right to receive your data in a machine-readable format.

🚫 Right to Object (Art. 21 GDPR)

You can object to the processing of your data, especially for direct marketing.

Right to Erasure (Art. 17 GDPR)

  • You can request complete deletion of your personal data under GDPR Article 17.
  • Requests can be sent by email to the data controller at: support@faultrix.com
  • We respond to erasure requests within 30 days in line with GDPR requirements.
  • Records that must be retained by law cannot be deleted, especially invoice data under BAO §132.

⚖️ Right to Complain

In case of privacy violations, you can contact the Austrian Data Protection Authority:

Austrian Data Protection Authority
Barichgasse 40-42, 1030 Vienna
https://www.dsb.gv.at

8. Data Security

We protect your data through:

🔐TLS 1.3 encryption for all transmissions
💾Encrypted storage of sensitive data
🔑Secure authentication via Clerk
🧪Regular security audits
📋Security policies: Staff trained in data protection

9. Privacy Contact

For questions or requests about your data, contact us:

Data Protection Officer:
Faultrix GmbH
support@faultrix.com

General Contact:
support@faultrix.com