Privacy policy
Last updated 18 August 2026
This policy explains what Open Telos GmbH (operating as Resonance Labs) does with personal data — what we collect, why, who we share it with, how long we keep it, and what you can require of us. It includes what we do for marketing and retargeting, stated plainly rather than buried.
01Who we are
The controller responsible for the personal data described in this policy, within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR), is:
- Open Telos GmbH (operating as Resonance Labs)
- Grotfeldsweg 55, 47506 Neukirchen-Vluyn, Germany
- Represented by Severin Deutschmann
- Commercial register: Amtsgericht Düsseldorf, HRB 86630
- VAT identification number: DE325263947
- Email: atlas@resonancelabsai.com
For anything concerning your personal data — including the rights set out in section 11 — write to atlas@resonancelabsai.com. Full company details are on our Impressum.
We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG, and have not appointed one. Requests are handled by the management at the address above.
02What this policy covers
This policy explains what personal data we collect when you visit this website, talk to the agent on it, submit an enquiry or booking, or buy a ticket to one of our events — and what we then do with it. It applies to our own processing as a controller.
It does not cover the websites of other organisations that we link to, and it does not cover data we process on behalf of a client under a services agreement. Where we build or run a system for a client, the client is the controller for the data in that system and their own privacy notice applies; we act as a processor under a data processing agreement concluded pursuant to Art. 28 GDPR.
Your use of this website is also governed by our terms and conditions.
03The personal data we collect
Data you give us
- Conversations with our agent. The messages you type, and anything you choose to tell it — typically your name, work email address, role, company name and website, what your business does, and the problem you are trying to solve.
- Enquiry details. Your name, email address, company, role, what you are trying to achieve and the stage you are at — given to the agent in the course of the conversation, or to us directly if you write to us.
- Event and ticket purchases. When you buy a place on a bootcamp or workshop through our Academy pages: your name, email address, the item purchased and the amount paid. We never see or store your card details — see section 08.
- Correspondence. The content of emails and messages you send us, and our replies.
Data collected automatically
- Server and request data. Your IP address, the browser and operating system you are using (user agent), the page requested, the referring URL, and the date and time. This is generated by our hosting provider whenever any browser requests any page, and is technically unavoidable.
- Abuse-prevention data. A short-lived record derived from your IP address, used to rate-limit requests to the agent so it cannot be automated against. The address is put through a SHA-256 hash first, so what is stored is a fingerprint rather than the address itself, and it expires automatically at the end of a short window.
- Your display preference. Whether you chose the light or dark theme, stored in your browser — see section 07.
Data we look up
If you give the agent your company website, it retrieves that public website and runs a single web search to build a picture of your business before responding. This is research about a company, not about you personally, but a small company website may name individuals — so publicly available business information about you may enter the conversation record this way.
We do not ask for and do not want special categories of personal data (Art. 9 GDPR) — health, political opinions, religious beliefs, trade union membership, biometric or sexual orientation data. Please do not put such data into the agent or a form.
04Why we use your data, and our legal basis
We only process personal data where the GDPR gives us a basis to do so. The table sets out each purpose against its basis.
| What we do | Why | Legal basis |
|---|---|---|
| Serve this website and keep it available and secure | Without it there is no website, and unprotected endpoints get abused | Art. 6(1)(f) — our legitimate interest in operating and protecting our own site |
| Run the agent conversation and produce the analysis it shows you | It is the thing you came to use, and it is a step taken at your request before any contract | Art. 6(1)(b) — pre-contractual steps at your request |
| Respond to your enquiry, arrange and hold a call | You asked us to | Art. 6(1)(b) — pre-contractual steps at your request |
| Assess whether we are a good fit for your business, and prioritise our follow-up | We can only take on work we can actually do well, and we would rather say so early | Art. 6(1)(f) — our legitimate interest in qualifying enquiries; yours in not being sold something unsuitable |
| Sell and administer event and workshop tickets | To perform the purchase contract with you | Art. 6(1)(b) — performance of a contract |
| Deliver and support services under a client agreement | To perform that contract | Art. 6(1)(b) — performance of a contract |
| Measure our advertising and build retargeting audiences | To understand which campaigns produce real enquiries, and to reach people who showed interest | Art. 6(1)(a) — your consent, which you can withdraw at any time (section 06) |
| Send marketing emails about our services and events | To stay in contact with people who want to hear from us | Art. 6(1)(a) — your consent; or § 7(3) UWG for existing customers, with an opt-out in every message |
| Keep records required by tax and commercial law | We are legally obliged to | Art. 6(1)(c) — legal obligation (§ 147 AO, § 257 HGB) |
| Establish, exercise or defend legal claims | To protect our position if a dispute arises | Art. 6(1)(f) — our legitimate interest in defending claims |
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that our processing does not override them. You can ask us for the details of that assessment, and you can object to it — see section 11.
05The AI agent on this site
This site offers a conversational agent. It is worth being precise about what happens to what you type into it.
- Your messages are sent to our server, and from there to a large language model hosted by our model provider, OpenRouter, Inc., which routes the request to the underlying model that generates the reply.
- If you provide your company website, our server fetches that public page and runs one search through Parallel Web Systems, Inc. to gather public context about the company.
- The state of the conversation is signed by our server and held by your browser between turns, so that the conversation can continue.
- Before a conversation starts, Cloudflare Turnstile checks that you are a person rather than a bot. Cloudflare receives your IP address and signals about your browser in order to make that assessment. Without it the agent would be an open, billable endpoint for anyone to automate against.
- We keep a record of conversations — including the full transcript — so that we can follow up on enquiries, and so that we can debug and improve the agent when it behaves badly. These records are delivered to a private internal channel that only our team can read.
The agent produces an assessment of fit and a suggested direction. That output has no legal or similarly significant effect on you: it does not decide whether you may buy anything, and any decision to work together is taken by people at both companies. We therefore do not carry out automated decision-making or profiling within the meaning of Art. 22(1) GDPR.
We do not use your conversations to train foundation models, and our model provider is contractually engaged as a processor on our behalf.
06Marketing, retargeting and measurement
We advertise our services, and we want to know which advertising actually works. That means two things, and we will describe both honestly.
The Meta Pixel, in your browser
When you press Accept, we load Meta’s advertising script (“fbevents.js”, the Meta Pixel) from connect.facebook.net into your browser. On loading, it reports a single PageView event to Meta Platforms Ireland Limited — the page you were on when you accepted — together with your IP address and your browser user agent. It also sets its own cookies; see section 07.
Once you have accepted, the Pixel loads on each of your later visits too, for as long as that choice is stored in your browser. One further limit is worth stating because it is narrower than the wording usually found in a policy of this kind: the Pixel does not report each page you move to within a visit. It reports the page it loaded on, and after that only the specific actions below.
Beyond that first page view, one action is reported: clicking a button to book a call sends a Schedule event, telling Meta that a visitor reached the point of booking.
The Conversions API, from our server
Separately, when you give the agent your email address and have consented, our server sends a Lead event to Meta through the Conversions API. That event includes your email address in hashed form only — converted with SHA-256 on our server, so the plain address never leaves it — along with your IP address, your browser user agent, and the page you were on.
The browser half and the server half report different things — a booking click from your browser, an email capture from our server — so they are two separate signals rather than one event counted twice.
Meta matches this data against its own users in order to attribute an enquiry to an advertising campaign, to build audiences of people who resemble those who enquired, and to show our advertising again to people who have already shown interest in it. That last one is what retargeting means, and it is the substance of what we are asking you to agree to.
For this processing, we and Meta act as joint controllers within the meaning of Art. 26 GDPR in respect of the collection and transmission of the event data, under Meta’s controller addendum. Meta’s own processing after receipt is governed by its data policy at facebook.com/privacy/policy. The essence of our joint controller arrangement is that we are responsible for obtaining your consent and for providing this information, and Meta is responsible for the subsequent processing and for honouring your rights against it.
Email marketing
If you consent, we may send you occasional emails about our services, events and workshops. Where you are already a customer, we may send you information about similar services on the basis of § 7(3) UWG. Every message contains a one-click unsubscribe, and unsubscribing costs nothing beyond your basic transmission charges.
Withdrawing your consent
You can withdraw consent at any time, with effect for the future, by emailing atlas@resonancelabsai.com or by using the unsubscribe link in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before it. You also have an unconditional right to object to processing for direct marketing under Art. 21(2) GDPR, after which we will stop.
08Who we share your data with
We do not sell personal data. We share it with the service providers we need in order to run the site and the business, each bound by a data processing agreement under Art. 28 GDPR unless noted otherwise, and with public authorities where the law requires it.
| Recipient | What they do for us | What they receive |
|---|---|---|
| Vercel Inc. (USA) | Hosting, content delivery and serverless functions for this site | All request data — IP address, user agent, pages requested — and anything submitted through the site as it passes through |
| Upstash, Inc. (USA) | Short-lived key-value storage used for rate limiting and usage caps | Your IP address, for at most 60 seconds |
| OpenRouter, Inc. (USA) | Routes agent messages to the language model that generates replies | The content of your conversation with the agent |
| Parallel Web Systems, Inc. (USA) | One web search for public context about the company you name | The company name or domain you provided — not your personal contact details |
| Discord Netherlands B.V. / Discord, Inc. (USA) | The private internal channels our team uses to receive enquiries and sales notifications | Your enquiry details and the full conversation transcript; and, when you buy a ticket, your name, email address and the amount paid |
| Stripe Payments Europe, Ltd. (Ireland) | Payment processing for event and workshop tickets | Your name, email, billing and card data, which you give to Stripe directly. Stripe is an independent controller for payment data |
| Cloudflare, Inc. (USA) | Turnstile — the bot check that protects the agent from automated abuse | Your IP address and signals about your browser, at the moment a conversation starts |
| Meta Platforms Ireland Ltd. (Ireland) | Advertising measurement and retargeting — only with your consent | From your browser: page views, IP address, user agent and the Pixel cookies. From our server: your hashed email address, IP address and user agent (section 06) |
| Email and calendar providers | Sending our replies and scheduling calls | Your name, email address and the content of the correspondence |
We may also disclose personal data to our accountants, auditors and legal advisers, who are bound by professional confidentiality, and to courts or public authorities where we are legally obliged to do so. If our business is ever sold or reorganised, data may pass to the acquirer, who would remain bound by this policy.
09International transfers
Several of the providers above are established in the United States, or process data there. That means personal data about you may be transferred outside the European Economic Area.
Where a provider is certified under the EU–US Data Privacy Framework, the transfer is covered by the European Commission’s adequacy decision of 10 July 2023. Where it is not, we rely on the European Commission’s Standard Contractual Clauses under Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures — including the fact that data in transit is encrypted, and that the email address we send to Meta is hashed before it leaves our server.
You should be aware that United States law may give public authorities access to data held there, and that the remedies available may not match those in the EEA. You can request a copy of the safeguards we rely on by writing to atlas@resonancelabsai.com.
10How long we keep your data
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires. In practice:
| Data | Kept for |
|---|---|
| Server and request logs | Up to 30 days, then deleted |
| Rate-limiting records | 60 seconds, then deleted automatically |
| Agent conversations and transcripts where no enquiry followed | 12 months |
| Enquiries, bookings and the correspondence around them | 24 months from our last contact, unless a contract follows |
| Client contract records | For the duration of the contract, then up to the end of the statutory limitation period (generally 3 years from the end of the year in which the claim arose, § 195, § 199 BGB) |
| Invoices, accounting and tax records | 10 years, as required by § 147 AO and § 257 HGB |
| Marketing consent and objection records | For as long as we do marketing, plus 3 years — we have to be able to prove what you chose |
Where data must be retained for tax or accounting reasons but is no longer needed for anything else, we restrict its processing rather than continue to use it: it is kept for that legal purpose alone.
11Your rights
The GDPR gives you the following rights over your personal data. They are free to exercise, and we will respond within one month.
- Access (Art. 15) — to be told whether we hold data about you, and to receive a copy of it.
- Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17) — to have your data deleted where one of the grounds in the Regulation applies.
- Restriction (Art. 18) — to have processing limited while, for example, a dispute about accuracy is resolved.
- Data portability (Art. 20) — to receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection (Art. 21) — to object to processing based on legitimate interests on grounds relating to your particular situation. Where the processing is for direct marketing, the right is unconditional and we will stop without needing a reason.
- Withdrawal of consent (Art. 7(3)) — to withdraw any consent at any time, with effect for the future.
To exercise any of them, write to atlas@resonancelabsai.com. We may need to ask for information to confirm your identity, so that we do not disclose your data to someone else.
12How we protect your data
We take appropriate technical and organisational measures under Art. 32 GDPR. Among them: all traffic to this site is encrypted in transit with TLS; the email address sent for advertising measurement is hashed before transmission; conversation state passed between your browser and our server is cryptographically signed so it cannot be tampered with; our form endpoints are rate-limited; and access to enquiry data is limited to the people on our team who need it.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours under Art. 33 GDPR, and will inform you directly where Art. 34 requires it.
13Whether you have to provide data
Providing personal data is voluntary. You are neither legally nor contractually required to give us anything in order to read this website.
However, some of it is necessary for a particular purpose: we cannot reply to an enquiry without a contact address, cannot hold a call without arranging one with you, and cannot issue a ticket or an invoice without the details tax law requires. If you choose not to provide those, we simply will not be able to do that specific thing — there is no other consequence.
14Children
This website and our services are directed at businesses and the people who run them. They are not intended for children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to atlas@resonancelabsai.com and we will delete it.
15Changes to this policy
We will update this policy when what we do with data changes — for example if we add an analytics tool, a new provider, or a new marketing channel. The date at the top of this page always shows when it was last substantively revised.
Where a change materially affects processing that relies on your consent, we will ask for that consent again rather than assume the old one carries over.
16Complaints
If you think we have handled your personal data wrongly, please tell us first at atlas@resonancelabsai.com — most things are quickest to fix directly.
You also have the right under Art. 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement. The authority competent for us is:
- Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
- Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
- www.ldi.nrw.de