Legal
Privacy on changemaker.ai
We process as little personal data as possible. This page shows what is running on your device right now, who sees which data, and how to adjust your consent at any time.
What is running on this page right now?
Live state from your browser:
Cookie categories
We group cookies into four categories – compatible with the Cookiebot taxonomy used by many DACH businesses.
Storing and reading information on your device is governed by Section 25 of the German TDDDG: for the Preferences and Statistics categories we ask for your consent (Section 25(1) TDDDG); the functional entries pm-cookie-consent and theme are strictly necessary for the service you request (Section 25(2) no. 2 TDDDG). The same applies to the live chat's session key – it only comes into existence once you open the chat yourself, and is then necessary for exactly that service you asked for (details below). The cookieless baseline stores nothing on your device and is therefore outside the scope of Section 25 TDDDG.
Functional (always active)
Required for the site to work – consent record, security, language and theme. Cannot be turned off.
| Name | Storage | Retention | Purpose |
|---|---|---|---|
pm-cookie-consent | localStorage | 365 days | Stores your consent choice. Prevents the banner from re-prompting. |
theme | localStorage | Persistent | Light or dark mode preference. |
crisp-client/* | localStorage / cookie | 24 hours from last use | Live-chat session key, so your conversation survives a page change. Only written once you click the chat button – before that the chat does not load and stores nothing. |
Preferences
Non-essential convenience storage (e.g. recurring UI state). Opt-in.
| Name | Storage | Retention | Purpose |
|---|---|---|---|
cs-preloader-seen | localStorage | Persistent | Marks that the brand-mark preloader has played once. |
Statistics
Anonymous reach measurement via PostHog. Without consent, a cookieless baseline runs (page views, page transitions, clicks on demo buttons, use of the site search and the calculators, progress through the demo form): it stores nothing on your device, honours "Do Not Track", and cannot be switched off via this toggle – your right to object is described below. With consent: full mode with session replay, heatmaps and autocapture.
| Name | Storage | Retention | Purpose |
|---|---|---|---|
ph_<key>_posthog | localStorage | 365 days | PostHog distinct_id, session counter, feature flags. Only with consent. |
ph_<key>_window_id | sessionStorage | Session | PostHog tab/window ID for session recording. |
Marketing
Currently not used on this site. Category kept for transparency in case future tools are added.
No cookies in this category are used on this site right now.
Processors
- PostHog – product analytics (cookieless by default, opt-in for identified sessions). EU hosting in Frankfurt, DPA on file at eu.posthog.com. Provider with a US parent (PostHog Inc.); third-country access (e.g. support) cannot be fully excluded. PostHog Inc. is certified under the EU-U.S. Data Privacy Framework (including the UK and Swiss extensions); EU standard contractual clauses (2021/914) apply as an additional safeguard.
- Cloudflare – hosting + DDoS protection. EU traffic routing; the provider is Cloudflare, Inc. (USA), and third-country access (support, telemetry) cannot be fully excluded. Cloudflare is certified under the EU-U.S. Data Privacy Framework (including the UK and Swiss extensions); EU standard contractual clauses apply as an additional safeguard.
- Microsoft (Bookings & Teams) – appointment booking and video meeting for demo requests. Processes only the details submitted in the booking form (name, work e-mail, company, role, optional phone/agenda) to create the appointment and generate the Teams meeting link. PRINCIPIA MENTIS GmbH M365 tenant within the EU Data Boundary. Microsoft Corporation (USA) is certified under the EU-U.S. Data Privacy Framework (including the UK and Swiss extensions); for any processing outside the EU Data Boundary, EU standard contractual clauses apply as an additional safeguard.
- Crisp IM SAS – live chat. The provider is Crisp IM SAS, 2 boulevard de Launay, 44100 Nantes, France (SIREN 833 085 806). Conversation content is stored in the EU (France); a data processing agreement under Art. 28 GDPR is in place. To establish the connection, Crisp also operates relay servers outside the EU (USA, United Kingdom, Singapore); these log IP address, date, user agent and the originating website. The United Kingdom is covered by an adequacy decision (Art. 45 GDPR); for the remaining third countries, EU standard contractual clauses (2021/914) under Art. 46 GDPR apply. The chat loads only after your click – without a click no request reaches Crisp.
Legal bases (Art. 6 GDPR)
| Processing | Legal basis |
|---|---|
| Serving the website, security, DDoS protection (Cloudflare) | Art. 6(1)(f) GDPR – legitimate interest in secure, stable operation |
| Cookieless baseline measurement (PostHog: page views, page transitions, clicks on demo buttons, site search, calculator use, progress through the demo form) | Art. 6(1)(f) GDPR – legitimate interest in anonymous reach and conversion measurement without profiling; right to object, see "Your rights" |
| Session replay, heatmaps, autocapture (PostHog, only after consent) | Art. 6(1)(a) GDPR; device storage additionally Section 25(1) TDDDG |
| Demo booking (Microsoft Bookings & Teams) | Art. 6(1)(b) GDPR – pre-contractual steps at your request |
| Contact by e-mail or phone | Art. 6(1)(b) GDPR for pre-contractual matters, otherwise Art. 6(1)(f) GDPR – interest in answering your request |
| Live chat (Crisp, only after a click, see below) | Art. 6(1)(b) GDPR for pre-contractual matters, otherwise Art. 6(1)(f) GDPR – interest in answering your request; the device storage needs no consent under Section 25(2) no. 2 TDDDG because you explicitly request the chat yourself |
| OpenStreetMap map service (two-click, see below) | Art. 6(1)(a) GDPR – consent given by actively loading the map |
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. Providing personal data is neither legally nor contractually required; without the details requested in the booking form, however, we cannot set up a demo appointment.
Map service OpenStreetMap (two-click)
On the About us page we embed a location map from OpenStreetMap. The provider is the OpenStreetMap Foundation (OSMF), St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom.
The map uses a two-click pattern: when the page loads, no data is transferred to OpenStreetMap. Only once you click the "Load map" button does your browser connect to OSMF servers; this technically transfers your IP address and browser-related data (e.g. user agent), and OpenStreetMap may set its own cookies. The legal basis is your consent given through actively loading the map (Art. 6(1)(a) GDPR). The consent applies to the current page view; without loading the map, the page remains fully usable – the address is also shown as text.
The United Kingdom is covered by an adequacy decision of the European Commission (Art. 45 GDPR). Details: OSMF Privacy Policy.
Live chat (Crisp)
Every page carries a live-chat button in the bottom-right corner. The provider is Crisp IM SAS, 2 boulevard de Launay, 44100 Nantes, France.
The button belongs to this website and loads nothing on its own: as long as you do not click it, no Crisp script is loaded, no connection to Crisp is established, and nothing is stored on your device. The chat starts only with your click. Because you explicitly request the service that way, the device storage needs no consent under Section 25(2) no. 2 TDDDG – which is why the chat deliberately does not appear in the cookie banner, and why it remains available to you even if you chose "Reject all".
Once the chat is running, Crisp processes on our behalf: your messages and any attachments, the timestamp, a random session key, your IP address, browser and device details (user agent, language), the page you are on, and – only if you enter them yourself – your name and e-mail address. Please do not send special categories of personal data (Art. 9 GDPR) or credentials through the chat.
We delete conversations no later than 12 months after the last message, and immediately on request. The session key on your device is capped at 24 hours from your last use of the chat; after that it is no longer used and a new key is issued the next time you chat. Using the chat again within those 24 hours extends the period accordingly. The Crisp default is six months – we lower it deliberately, because the Section 25(2) no. 2 TDDDG exemption only covers storage that remains necessary for the service you requested. You can remove the key at any time via your browser's storage settings.
The chat is not a precondition for using this website. You can reach us equally by e-mail at [email protected] or through the demo booking. Details on the provider's processing: Crisp privacy policy.
What data do we see?
Cookieless default: IP address (truncated to country/region before storage), user agent, page path, referrer, plus these interaction events without any device identifier: clicks on demo buttons (cta_clicked, lp_cta_click: target path, page section, button label, topic page), use of the site search (site_search: only the length of the query and the number of hits; the query itself only with statistics consent), use of the calculators (calculator_used: only the rounded size class of the modelled company, never an input value) and progress through the demo form (demo_form_started, demo_form_error, demo_form_submitted: language, lead time to the appointment, the project type picked from a fixed list, the name of the empty required field or the error reason; never field contents, never name, e-mail or company). No identifiers, no cookies. With consent: additional heatmap data (aggregated mouse, scroll and click positions), session replay (with PII input masking) and localStorage-based recognition for up to 365 days.
Data retention
Event data (page views and interactions) is deleted 12 months after collection. Session replays are deleted after 30 days. The lifetimes listed in the table above apply only to storage on your own device and are independent of this: in cookieless default mode nothing is stored on your device at all, yet the event data is subject to the same retention period.
Live chat: we delete conversations no later than 12 months after the last message, earlier on request; the session key on your device expires 24 hours after your last use (see the "Live chat (Crisp)" section).
Demo bookings: we keep the details submitted in the booking form for the duration of the business initiation and delete them no later than 12 months after the last contact if no business relationship is established. E-mail correspondence is deleted once handled; where statutory retention duties under German commercial or tax law apply (six to ten years), the affected correspondence is kept for that period with restricted processing only.
Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw any consent at any time with effect for the future (Art. 7(3) GDPR) – via the button above or the "Manage cookies" link in the footer. Send requests to [email protected].
Right to object (Art. 21 GDPR): You may object at any time, on grounds relating to your particular situation, to processing we base on legitimate interests (Art. 6(1)(f) GDPR) – here in particular the cookieless baseline measurement via PostHog. After an objection we no longer process the affected data unless we can demonstrate compelling legitimate grounds. An informal e-mail to [email protected] is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for instance at your habitual residence. The authority responsible for us: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, lda.bayern.de.
Switzerland and Austria
This offering addresses the whole DACH region. For visitors from Austria the GDPR applies directly; the complaint authority there is the Austrian Data Protection Authority (dsb.gv.at). For visitors from Switzerland we additionally observe the revised Swiss Data Protection Act (revFADP); the US providers named above are also certified under the Swiss-U.S. Data Privacy Framework, with standard contractual clauses as an additional safeguard. The Swiss complaint authority is the Federal Data Protection and Information Commissioner (FDPIC).
Controller
PRINCIPIA MENTIS GmbH
Paradiesstraße 9 - 10, 80538 München, Germany
Dr. Alexander Ploghaus, Managing Director
Data protection officer: Dr. Jochen Notholt, comp/lex – reachable via [email protected] (subject "data protection")
Full legal notice
Last updated: 19 August 2026