Privacy Policy
Last updated: 2025/25/11
1. Controller
This website is operated by:
STD.DEV / Standard Deviation / Standardabweichung
Represented by:
Daniel Kuhnlein
Herzogstr. 115
80796 Munich, Germany
Email:
design@standardabweichung.de
2. Purpose of the Website
This website is designed to provide interested visitors and potential business partners with information about the competencies, services, and solutions offered by STD.DEV.
It focuses on the interplay between visual design and modern Web-, Cloud-, and XR technologies to create digital products that are aesthetically sophisticated, interactive, and technologically advanced.
Content is presented through a voice-controlled real-time knowledge graph, which analyzes user requests and visually displays relevant topics dynamically.
3. Processing of Audio, Text, and Usage Data
3.1 Speech Input (voluntary)
When you activate the voice assistant, your device captures short audio fragments identified as speech by the local Voice Activity Detection (VAD). These fragments are transmitted in encrypted form to STD.DEV’s server solely for the purpose of forwarding them to OpenAI Whisper (OpenAI, L.L.C., USA) for speech-to-text conversion.
The following data is processed:
Audio fragments containing spoken content
The resulting transcription generated by OpenAI Whisper
STD.DEV does not store audio data. Audio fragments exist only transiently in server memory for the duration of the technical processing step required to relay them to OpenAI Whisper.
Once the transcription request is completed, they are immediately discarded. Only the transcribed text is used to continue the interaction.
Legal basis:
Consent (Art. 6(1)(a) GDPR)
3.2 Session and Chat Data (ephemeral processing)
To enable the interaction, the system processes the following temporarily during the active session:
Transcribed user inputs
System responses
Technical metadata (timestamps, internal session identifiers)
Sessions are strictly ephemeral. Data is stored only for the duration of active use.
Automatic deletion:
If no activity occurs for 10 minutes, the system:
Generates a fully anonymized summary for internal analytics
Permanently deletes the entire chat history
After deletion, no personal data remains.
Legal bases:
Contractual necessity (Art. 6(1)(b) GDPR — responding to your inquiry)
Legitimate interest (Art. 6(1)(f) GDPR — ensuring system stability)
3.3 Processing by Google AI
For generating contextual responses, the website uses the Google AI API (Gemini) to process:
The text content of your current message
Relevant parts of the temporary chat history
No audio data, personal identifiers, cookies, or persistent user profiles are transmitted.
Once your session expires and is deleted, no further processing takes place.
Legal basis:
Consent (Art. 6(1)(a) GDPR)
Further information:
https://policies.google.com/privacy
3.4 Usage Data (Google Analytics 4 — optional)
If you consent, this website uses Google Analytics 4 (GA4) to measure and analyze usage patterns.
Processed data may include:
Browser and device information
Interaction data
Pseudonymized analytics identifiers
Data may be transferred to the United States.
Legal basis:
Consent (Art. 6(1)(a) GDPR)
Privacy information:
https://policies.google.com/privacy
3.5 Usage Data (Microsoft Clarity — optional)
If you consent, this website uses Microsoft Clarity to analyze user interaction and improve usability.
Processed data may include:
Interaction and movement data (scrolling, clicks, cursor paths)
Device and browser data Anonymous or pseudonymized session replays
Viewed content and page elements
Data may be transferred to the United States.
Legal basis:
Consent (Art. 6(1)(a) GDPR)
Privacy information:
https://privacy.microsoft.com/privacystatement
3.6 Bot Protection (Cloudflare Turnstile)
This website uses Cloudflare Turnstile for bot detection and security purposes.
Turnstile may process:
Browser and device characteristics
Interaction patterns
Technical metadata
No personal identifiers are used, and no cookies are set for advertising.
Legal basis:
Legitimate interest (Art. 6(1)(f) GDPR — prevention of abuse and system security)
Privacy information:
https://www.cloudflare.com/trust-hub/privacy-and-data-protection/
4. International Data Transfers
Data transfers to the USA may occur in the context of:
OpenAI
Google AI
Google Analytics
Microsoft Clarity
Cloudflare Turnstile
All transfers rely on the EU–US Data Privacy Framework.
5. Processors
| Service | Purpose | Location | Legal Basis |
| OpenAI Whisper (OpenAI, L.L.C.) | Speech-to-Text | USA | Consent |
| Google AI / Gemini | LLM processing | EU/USA | Consent |
| Google Analytics (Google Ireland / Google LLC) | Analytics | EU/USA | Consent |
| Microsoft Clarity (Microsoft Corp.) | UX analytics | USA | Consent |
| Cloudflare Turnstile | Bot protection | EU/USA | Legitimate interest |
Appropriate data processing agreements are in place with all providers.
6. Your Rights
You have the following rights at any time:
Access (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Objection (Art. 21 GDPR)
Withdrawal of consent (Art. 7 GDPR)
Because all session data is deleted after 10 minutes of inactivity, requests will often be answered with:
"No personal data is stored at this time."
7. Withdrawal of Consent
You may withdraw your consent at any time by:
Disabling microphone access in your browser
Changing your cookie and analytics preferences
Ending your use of the service
8. Security
STD.DEV uses comprehensive technical and organizational security measures, including:
TLS encryption Ephemeral sessions (automatic deletion after 10 minutes)
Strict access controls
No audio storage
No profiling or personalized targeting
No use of third-party frontend libraries that could introduce security risks
9. Automated Processing
The website uses automated processing solely to enable the technical functions of the voice interface:
Speech-to-text processing via OpenAI Whisper (OpenAI, L.L.C.)
Generation of contextual responses using Google AI (Gemini)
No automated decision-making with legal or similar effects occurs, and no user profiling is performed.