Skip to main content
Resonance Labs
Legal

Privacy policy

Last updated 18 August 2026

This policy explains what Open Telos GmbH (operating as Resonance Labs) does with personal data — what we collect, why, who we share it with, how long we keep it, and what you can require of us. It includes what we do for marketing and retargeting, stated plainly rather than buried.

01Who we are

The controller responsible for the personal data described in this policy, within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR), is:

  • Open Telos GmbH (operating as Resonance Labs)
  • Grotfeldsweg 55, 47506 Neukirchen-Vluyn, Germany
  • Represented by Severin Deutschmann
  • Commercial register: Amtsgericht Düsseldorf, HRB 86630
  • VAT identification number: DE325263947
  • Email: atlas@resonancelabsai.com

For anything concerning your personal data — including the rights set out in section 11 — write to atlas@resonancelabsai.com. Full company details are on our Impressum.

We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG, and have not appointed one. Requests are handled by the management at the address above.

02What this policy covers

This policy explains what personal data we collect when you visit this website, talk to the agent on it, submit an enquiry or booking, or buy a ticket to one of our events — and what we then do with it. It applies to our own processing as a controller.

It does not cover the websites of other organisations that we link to, and it does not cover data we process on behalf of a client under a services agreement. Where we build or run a system for a client, the client is the controller for the data in that system and their own privacy notice applies; we act as a processor under a data processing agreement concluded pursuant to Art. 28 GDPR.

Your use of this website is also governed by our terms and conditions.

03The personal data we collect

Data you give us

  • Conversations with our agent. The messages you type, and anything you choose to tell it — typically your name, work email address, role, company name and website, what your business does, and the problem you are trying to solve.
  • Enquiry details. Your name, email address, company, role, what you are trying to achieve and the stage you are at — given to the agent in the course of the conversation, or to us directly if you write to us.
  • Event and ticket purchases. When you buy a place on a bootcamp or workshop through our Academy pages: your name, email address, the item purchased and the amount paid. We never see or store your card details — see section 08.
  • Correspondence. The content of emails and messages you send us, and our replies.

Data collected automatically

  • Server and request data. Your IP address, the browser and operating system you are using (user agent), the page requested, the referring URL, and the date and time. This is generated by our hosting provider whenever any browser requests any page, and is technically unavoidable.
  • Abuse-prevention data. A short-lived record derived from your IP address, used to rate-limit requests to the agent so it cannot be automated against. The address is put through a SHA-256 hash first, so what is stored is a fingerprint rather than the address itself, and it expires automatically at the end of a short window.
  • Your display preference. Whether you chose the light or dark theme, stored in your browser — see section 07.

Data we look up

If you give the agent your company website, it retrieves that public website and runs a single web search to build a picture of your business before responding. This is research about a company, not about you personally, but a small company website may name individuals — so publicly available business information about you may enter the conversation record this way.

We do not ask for and do not want special categories of personal data (Art. 9 GDPR) — health, political opinions, religious beliefs, trade union membership, biometric or sexual orientation data. Please do not put such data into the agent or a form.

04Why we use your data, and our legal basis

We only process personal data where the GDPR gives us a basis to do so. The table sets out each purpose against its basis.

What we doWhyLegal basis
Serve this website and keep it available and secureWithout it there is no website, and unprotected endpoints get abusedArt. 6(1)(f) — our legitimate interest in operating and protecting our own site
Run the agent conversation and produce the analysis it shows youIt is the thing you came to use, and it is a step taken at your request before any contractArt. 6(1)(b) — pre-contractual steps at your request
Respond to your enquiry, arrange and hold a callYou asked us toArt. 6(1)(b) — pre-contractual steps at your request
Assess whether we are a good fit for your business, and prioritise our follow-upWe can only take on work we can actually do well, and we would rather say so earlyArt. 6(1)(f) — our legitimate interest in qualifying enquiries; yours in not being sold something unsuitable
Sell and administer event and workshop ticketsTo perform the purchase contract with youArt. 6(1)(b) — performance of a contract
Deliver and support services under a client agreementTo perform that contractArt. 6(1)(b) — performance of a contract
Measure our advertising and build retargeting audiencesTo understand which campaigns produce real enquiries, and to reach people who showed interestArt. 6(1)(a) — your consent, which you can withdraw at any time (section 06)
Send marketing emails about our services and eventsTo stay in contact with people who want to hear from usArt. 6(1)(a) — your consent; or § 7(3) UWG for existing customers, with an opt-out in every message
Keep records required by tax and commercial lawWe are legally obliged toArt. 6(1)(c) — legal obligation (§ 147 AO, § 257 HGB)
Establish, exercise or defend legal claimsTo protect our position if a dispute arisesArt. 6(1)(f) — our legitimate interest in defending claims

Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that our processing does not override them. You can ask us for the details of that assessment, and you can object to it — see section 11.

05The AI agent on this site

This site offers a conversational agent. It is worth being precise about what happens to what you type into it.

  • Your messages are sent to our server, and from there to a large language model hosted by our model provider, OpenRouter, Inc., which routes the request to the underlying model that generates the reply.
  • If you provide your company website, our server fetches that public page and runs one search through Parallel Web Systems, Inc. to gather public context about the company.
  • The state of the conversation is signed by our server and held by your browser between turns, so that the conversation can continue.
  • Before a conversation starts, Cloudflare Turnstile checks that you are a person rather than a bot. Cloudflare receives your IP address and signals about your browser in order to make that assessment. Without it the agent would be an open, billable endpoint for anyone to automate against.
  • We keep a record of conversations — including the full transcript — so that we can follow up on enquiries, and so that we can debug and improve the agent when it behaves badly. These records are delivered to a private internal channel that only our team can read.
Treat the agent as a conversation with a company, not as a private notepad. A person on our team will read what you write. Please do not enter confidential information belonging to your employer or a third party, credentials, payment details, or any special category data.

The agent produces an assessment of fit and a suggested direction. That output has no legal or similarly significant effect on you: it does not decide whether you may buy anything, and any decision to work together is taken by people at both companies. We therefore do not carry out automated decision-making or profiling within the meaning of Art. 22(1) GDPR.

We do not use your conversations to train foundation models, and our model provider is contractually engaged as a processor on our behalf.

06Marketing, retargeting and measurement

We advertise our services, and we want to know which advertising actually works. That means two things, and we will describe both honestly.

Nothing described in this section happens unless you accept it. Until you press Accept on the cookie banner, no advertising script is loaded and no data reaches any advertising network. A visitor who declines, or who simply ignores the banner, is treated the same way: declined. There is no “legitimate interest” fallback here.

The Meta Pixel, in your browser

When you press Accept, we load Meta’s advertising script (“fbevents.js”, the Meta Pixel) from connect.facebook.net into your browser. On loading, it reports a single PageView event to Meta Platforms Ireland Limited — the page you were on when you accepted — together with your IP address and your browser user agent. It also sets its own cookies; see section 07.

Once you have accepted, the Pixel loads on each of your later visits too, for as long as that choice is stored in your browser. One further limit is worth stating because it is narrower than the wording usually found in a policy of this kind: the Pixel does not report each page you move to within a visit. It reports the page it loaded on, and after that only the specific actions below.

Beyond that first page view, one action is reported: clicking a button to book a call sends a Schedule event, telling Meta that a visitor reached the point of booking.

The Conversions API, from our server

Separately, when you give the agent your email address and have consented, our server sends a Lead event to Meta through the Conversions API. That event includes your email address in hashed form only — converted with SHA-256 on our server, so the plain address never leaves it — along with your IP address, your browser user agent, and the page you were on.

The browser half and the server half report different things — a booking click from your browser, an email capture from our server — so they are two separate signals rather than one event counted twice.

Meta matches this data against its own users in order to attribute an enquiry to an advertising campaign, to build audiences of people who resemble those who enquired, and to show our advertising again to people who have already shown interest in it. That last one is what retargeting means, and it is the substance of what we are asking you to agree to.

For this processing, we and Meta act as joint controllers within the meaning of Art. 26 GDPR in respect of the collection and transmission of the event data, under Meta’s controller addendum. Meta’s own processing after receipt is governed by its data policy at facebook.com/privacy/policy. The essence of our joint controller arrangement is that we are responsible for obtaining your consent and for providing this information, and Meta is responsible for the subsequent processing and for honouring your rights against it.

Email marketing

If you consent, we may send you occasional emails about our services, events and workshops. Where you are already a customer, we may send you information about similar services on the basis of § 7(3) UWG. Every message contains a one-click unsubscribe, and unsubscribing costs nothing beyond your basic transmission charges.

Withdrawing your consent

You can withdraw consent at any time, with effect for the future, by emailing atlas@resonancelabsai.com or by using the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before it. You also have an unconditional right to object to processing for direct marketing under Art. 21(2) GDPR, after which we will stop.

07Cookies and local storage

The site’s own storage is deliberately minimal. Advertising cookies exist only if you accept them, and are listed separately below so the distinction is visible rather than buried.

Set no matter what you choose

WhatPurposeDuration
Theme preferenceRemembers whether you chose the light or dark appearance, so the site does not flash the wrong one on your next visitUntil you clear your browser storage
Agent conversation stateHolds the signed state of an in-progress agent conversation so it can continue from one message to the nextFor the duration of the conversation
Consent record (rl-consent-v1)Remembers the choice you made on the cookie banner, so we neither ignore it nor ask you again on every visitUntil you clear your browser storage

All of the above are strictly necessary to provide a service you have expressly requested, or are required to record a legal choice you made. Under § 25(2) TDDDG they therefore do not require consent.

Set only if you accept

These are set by the Meta Pixel described in section 06. They are advertising cookies. Nothing here is loaded until you press Accept, and § 25(1) TDDDG is why: storing or reading anything on your device for this purpose requires your consent.

WhatPurposeDuration
_fbp (Meta)Identifies your browser to Meta so a visit can be connected to an advertising campaign and used to build retargeting audiencesUp to 3 months
_fbc (Meta)Records the Meta ad click that brought you here, so a later enquiry can be attributed to itUp to 3 months

You can change your mind at any time by clearing this site’s storage in your browser, which removes the consent record and makes the banner ask again.

You can delete this storage at any time in your browser settings. If you delete the theme preference, the site will simply follow your operating system’s appearance setting again.

08Who we share your data with

We do not sell personal data. We share it with the service providers we need in order to run the site and the business, each bound by a data processing agreement under Art. 28 GDPR unless noted otherwise, and with public authorities where the law requires it.

RecipientWhat they do for usWhat they receive
Vercel Inc. (USA)Hosting, content delivery and serverless functions for this siteAll request data — IP address, user agent, pages requested — and anything submitted through the site as it passes through
Upstash, Inc. (USA)Short-lived key-value storage used for rate limiting and usage capsYour IP address, for at most 60 seconds
OpenRouter, Inc. (USA)Routes agent messages to the language model that generates repliesThe content of your conversation with the agent
Parallel Web Systems, Inc. (USA)One web search for public context about the company you nameThe company name or domain you provided — not your personal contact details
Discord Netherlands B.V. / Discord, Inc. (USA)The private internal channels our team uses to receive enquiries and sales notificationsYour enquiry details and the full conversation transcript; and, when you buy a ticket, your name, email address and the amount paid
Stripe Payments Europe, Ltd. (Ireland)Payment processing for event and workshop ticketsYour name, email, billing and card data, which you give to Stripe directly. Stripe is an independent controller for payment data
Cloudflare, Inc. (USA)Turnstile — the bot check that protects the agent from automated abuseYour IP address and signals about your browser, at the moment a conversation starts
Meta Platforms Ireland Ltd. (Ireland)Advertising measurement and retargeting — only with your consentFrom your browser: page views, IP address, user agent and the Pixel cookies. From our server: your hashed email address, IP address and user agent (section 06)
Email and calendar providersSending our replies and scheduling callsYour name, email address and the content of the correspondence

We may also disclose personal data to our accountants, auditors and legal advisers, who are bound by professional confidentiality, and to courts or public authorities where we are legally obliged to do so. If our business is ever sold or reorganised, data may pass to the acquirer, who would remain bound by this policy.

09International transfers

Several of the providers above are established in the United States, or process data there. That means personal data about you may be transferred outside the European Economic Area.

Where a provider is certified under the EU–US Data Privacy Framework, the transfer is covered by the European Commission’s adequacy decision of 10 July 2023. Where it is not, we rely on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures — including the fact that data in transit is encrypted, and that the email address we send to Meta is hashed before it leaves our server.

You should be aware that United States law may give public authorities access to data held there, and that the remedies available may not match those in the EEA. You can request a copy of the safeguards we rely on by writing to atlas@resonancelabsai.com.

10How long we keep your data

We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires. In practice:

DataKept for
Server and request logsUp to 30 days, then deleted
Rate-limiting records60 seconds, then deleted automatically
Agent conversations and transcripts where no enquiry followed12 months
Enquiries, bookings and the correspondence around them24 months from our last contact, unless a contract follows
Client contract recordsFor the duration of the contract, then up to the end of the statutory limitation period (generally 3 years from the end of the year in which the claim arose, § 195, § 199 BGB)
Invoices, accounting and tax records10 years, as required by § 147 AO and § 257 HGB
Marketing consent and objection recordsFor as long as we do marketing, plus 3 years — we have to be able to prove what you chose

Where data must be retained for tax or accounting reasons but is no longer needed for anything else, we restrict its processing rather than continue to use it: it is kept for that legal purpose alone.

11Your rights

The GDPR gives you the following rights over your personal data. They are free to exercise, and we will respond within one month.

  • Access (Art. 15) — to be told whether we hold data about you, and to receive a copy of it.
  • Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17) — to have your data deleted where one of the grounds in the Regulation applies.
  • Restriction (Art. 18) — to have processing limited while, for example, a dispute about accuracy is resolved.
  • Data portability (Art. 20) — to receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
  • Objection (Art. 21) — to object to processing based on legitimate interests on grounds relating to your particular situation. Where the processing is for direct marketing, the right is unconditional and we will stop without needing a reason.
  • Withdrawal of consent (Art. 7(3)) — to withdraw any consent at any time, with effect for the future.

To exercise any of them, write to atlas@resonancelabsai.com. We may need to ask for information to confirm your identity, so that we do not disclose your data to someone else.

12How we protect your data

We take appropriate technical and organisational measures under Art. 32 GDPR. Among them: all traffic to this site is encrypted in transit with TLS; the email address sent for advertising measurement is hashed before transmission; conversation state passed between your browser and our server is cryptographically signed so it cannot be tampered with; our form endpoints are rate-limited; and access to enquiry data is limited to the people on our team who need it.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours under Art. 33 GDPR, and will inform you directly where Art. 34 requires it.

13Whether you have to provide data

Providing personal data is voluntary. You are neither legally nor contractually required to give us anything in order to read this website.

However, some of it is necessary for a particular purpose: we cannot reply to an enquiry without a contact address, cannot hold a call without arranging one with you, and cannot issue a ticket or an invoice without the details tax law requires. If you choose not to provide those, we simply will not be able to do that specific thing — there is no other consequence.

14Children

This website and our services are directed at businesses and the people who run them. They are not intended for children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to atlas@resonancelabsai.com and we will delete it.

15Changes to this policy

We will update this policy when what we do with data changes — for example if we add an analytics tool, a new provider, or a new marketing channel. The date at the top of this page always shows when it was last substantively revised.

Where a change materially affects processing that relies on your consent, we will ask for that consent again rather than assume the old one carries over.

16Complaints

If you think we have handled your personal data wrongly, please tell us first at atlas@resonancelabsai.com — most things are quickest to fix directly.

You also have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement. The authority competent for us is:

  • Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
  • Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
  • www.ldi.nrw.de