ViennaSOSدليلك في المدينة
الرئيسية
VIENNA SOS

الخصوصية

تطبيق الهاتف

يحفظ التطبيق رمز جلسة موقّعاً في التخزين الآمن لنظام التشغيل. تُنسخ الملفات التي تختارها عبر منتقي النظام إلى ذاكرة التطبيق المؤقتة الخاصة؛ اختيار الملف لا يرفعه، والرفع يحتاج إلى إجراء صريح منك. يزيل تسجيل الخروج الرمز المحلي والملفات المؤقتة الخاصة بالتطبيق، ولا يحذف حسابك أو سجلك على الخادم. قد يحصل عارض الملفات أو المستلم الذي تختاره على نسخة عند فتح أو مشاركة ملف PDF أو تأكيد، ولا يزيل تسجيل الخروج تلك النسخة. إذا أرسلت ملاحظات عن تقرير الذكاء الاصطناعي صراحةً، يتلقى المشغّل السبب المختار والتعليق الاختياري المرتبطين بحسابك وحالتك وتقريرك؛ وهذا لا يمنح إذناً بقراءة التقرير كاملاً. يتطلب تطبيق الهاتف الحالي مدخلات منقّحة دون بيانات صحية؛ وتقديم معلوماتك الصحية الخاصة يتطلب مسار الموافقة المنفصل على الموقع.

معالجة الذكاء الاصطناعي وإذنك في iOS

في iOS 0.2.0 (6) والإصدارات الأحدث، يحدد التطبيق خدمة Microsoft Azure OpenAI قبل بدء الحالة ويطلب إذناً منفصلاً لإرسال السؤال والرسائل والنص المستخرج من المستندات المختارة، بما في ذلك البيانات الشخصية المتبقية فيها. تُعالج أيضاً مراجع الحالة وأسماء المستندات ولغة التقرير ومستوى التحليل ومواد المصادر لإعداد التقرير ومراجعته. لا يبدأ رفع ملف أو إنشاء مسودة أو شراء تحليل هذه المعالجة. خانة الإذن غير محددة مسبقاً. يمكنك الرفض أو الإلغاء قبل الإرسال ومواصلة استخدام حسابك. تستضيف Hetzner الملفات الأصلية واستخراج النص محلياً في ألمانيا؛ وتتم معالجة الذكاء الاصطناعي داخل الاتحاد الأوروبي. يوضح الإشعار الكامل أدناه حماية البيانات لدى المعالجين والاحتفاظ بها وحقوقك.

النص الكامل أدناه باللغة الإنجليزية. لم تتوفر بعد ترجمة كاملة إلى اللغة المختارة.

Privacy information · Updated 30 September 2026

EM Consulting · Elshan Musayev
Lichtentaler Str. 33
76530 Baden-Baden
Germany
consulting@elshanmusayev.com
+49 176 84512159

Status and controller

The controller is Elshan Musayev trading as EM Consulting, at the address and contact shown above. This notice describes the processing for Vienna SOS. Updated 24 September 2026.

Information the application processes

Account information includes name, email address, password authentication records, verification status and session records. Case information includes your questions, messages, uploaded documents, extracted document text, generated reports and associated activity. Documents may contain information about other people; remove unnecessary identifiers and only submit material you are entitled to share.

The service also maintains operational records such as processing status, AI usage and cost, access controls, support-access consent and deletion records. Payment and entitlement records are used to administer purchases and access to paid services. For a purchase, the application records the accepted offer and terms, their versions and displayed text, language, and separate choices requesting early performance and acknowledging the consequences of full performance. These records support purchase administration and evidence of the actions taken.

Reporting an AI response

If you report a response from your account, we store the reason you select, your optional comment, the related account, case and report references, and the submission time. Authorised operators can read this complaint information to investigate service problems. The complaint does not include a copy of the report or uploaded documents and does not itself grant access to them. Do not put unnecessary personal or sensitive information in the comment. Complaint records are deleted when the associated case history or account is deleted; separate report-access consent remains a separate choice.

Purchase confirmations and receipt records

The application keeps an immutable purchase confirmation and its content hash. It separately records when the confirmation document is served and when the user expressly acknowledges receipt of that exact confirmation. Acknowledgment does not establish that a file was saved to disk. Transactional email includes the confirmation and a text attachment; mail records distinguish acceptance by the mail server from errors. Mail-server acceptance does not establish delivery to the recipient inbox or that the message was read.

Contract declarations and correspondence

If you submit a withdrawal or termination declaration, the application records your name, email, contract reference, declaration text, language, submission time and requested termination details where relevant. It also stores receipt and payload hashes, pseudonymous email/network hashes used to limit abuse, mail status and operator handling records. A declaration does not require an account and is handled separately from account deletion.

The receipt records its original expiry. After that time, public receipt access and acknowledgment email attempts stop. An unresolved declaration remains accessible to authorised operators until it is handled; once handled and past its original expiry, it is eligible for removal by maintenance. The public receipt and acknowledgment-email period is 180 days from receipt. Handled declarations become eligible for removal after that period; unresolved declarations remain with the operator until handling is completed. Deleting the application record does not delete copies already delivered by email or records retained separately for a specific obligation.

Purposes and legal bases

Account access, processing your requested questions and documents, delivering explanations, administering purchases and resolving service problems are used to perform the requested service or take steps at your request before a contract (Article 6(1)(b) GDPR). Records required by applicable accounting, tax or other specific legal obligations are retained for those obligations (Article 6(1)(c)); this does not turn all case content into a financial record. Security, abuse prevention, access auditing and reliable deletion/recovery serve the legitimate interests of protecting the service and its users (Article 6(1)(f)), with data minimisation and restricted access. Optional campaign attribution uses your consent (Article 6(1)(a)). Acceptance of the terms is not blanket privacy consent.

Your own health information

General insurance or medical-information questions and redacted materials remain available without health consent. If you choose to submit necessary information about your own health, the application asks separately for explicit consent before you upload the material or save the question. This covers storing and extracting the selected information and sending its text to Microsoft Azure OpenAI for the requested explanation and related follow-ups (Articles 6(1)(a) and 9(2)(a) GDPR). Remove unnecessary details and other people’s health information: your consent does not authorise processing for them. The application relies on your choice; it does not claim to detect every sensitive detail.

The consent record contains your account reference, language, version and displayed purpose, the grant time and any withdrawal time; selected documents and cases link to it. You can withdraw through the health-consent controls on case creation or a case page, including consents from unfinished forms. Withdrawal blocks further processing on that consent and acceptance of pending results. It cannot recall information already sent to a provider or undo prior processing. History/account deletion is a separate control. A withdrawn scope cannot be reactivated simply by replacing its consent identifier.

Permission before AI processing in the iOS app

From iOS version 0.2.0 (6), the app displays a separate disclosure and an initially unchecked permission control before each case is started. The recipient is Microsoft, operating Microsoft Azure OpenAI. The information sent comprises the case question and messages, text extracted from the selected documents (including personal information left in that text), document labels and source references, case identifiers, report language, analysis tier, retrieved evidence, and generated output used for the report and its quality checks. The purpose is to prepare and check the requested informational AI report. Account passwords and payment-card details are not part of this AI request. Do not include those secrets in a question or document.

Selecting a file keeps a copy in the app cache. An explicit upload sends the file to Vienna SOS hosting and private storage at Hetzner in Germany; extraction and OCR run on the application server. Upload, draft creation, sign-in and purchase do not themselves start the case AI pipeline. Original document binaries are not sent to the AI model in this pipeline. The app asks for permission to send the extracted text before starting, and requires a further affirmative start confirmation. Declining or cancelling keeps the case unstarted and does not prevent access to the account or stored reports. Permission is not preselected, inferred from payment or reused as a blanket permission for other cases. A completed transmission cannot be recalled; the deletion and data-rights procedures below remain available. Health-related cases are excluded from this mobile flow.

Protection provided by third-party recipients

We require third parties receiving personal data to provide the same or an equivalent level of protection as described in this notice and required by applicable data-protection law. Processing on our behalf is governed by data-processing terms covering confidentiality, documented purposes, security, restricted access, subprocessors, international-transfer safeguards, deletion and assistance with data-subject rights. Microsoft Azure processing is governed by the Microsoft Products and Services Data Protection Addendum: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Microsoft states that Azure OpenAI inputs and outputs are not provided to OpenAI or other customers and are not used to train foundation models without customer permission or instruction; Vienna SOS does not enable such training. The standard abuse-monitoring and provider-retention limitations below still apply.

Hetzner and Resend process service data under their data-processing terms; Stripe and Apple also have independent responsibilities for payment and platform data under their own privacy notices and applicable law. Equivalent protection does not mean identical storage locations or retention periods. The recipient-specific purposes, transfer safeguards and retention limits described in this notice remain applicable. We do not sell case content or provide it to third parties for their advertising.

AI document analysis and recipients

The configured AI provider is Microsoft Azure OpenAI. The dedicated resource is located in Sweden Central, with DataZoneStandard deployments of GPT-6 Luna and GPT-6 Sol. When free-question navigation is enabled, the submitted question is sent to Microsoft Azure OpenAI to select relevant official information from the service directory or request clarification. Questions detected as immediate emergencies are routed directly to emergency information without this AI call. Do not include private documents or sensitive information in free questions. Relevant case questions and extracted document text may also be transmitted for analysis when that feature is enabled. For these EU DataZone deployments, prompts and responses may be processed in other EU member states, not only Sweden. Microsoft operates separate abuse monitoring, which may include storage and authorised review of flagged prompts and responses. Disabling conversation storage in the application does not establish zero provider retention. This notice describes the standard abuse-monitoring arrangement; no modified-monitoring exemption or zero-retention arrangement is claimed. Microsoft explains these processes at https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy.

The hosting provider is Hetzner. Vienna SOS uses a dedicated server in Nuremberg, Germany, with PostgreSQL on that server and private Hetzner Object Storage in Nuremberg for uploaded documents. Transactional email is sent through Resend using no-reply@viennasos.at, with Ireland (eu-west-1) configured as the sending region. Resend states that message content, delivery logs, webhook payloads and account records are stored in the United States; the sending region does not change that storage location. Its published policy describes international-transfer safeguards: https://resend.com/security/gdpr. The active transactional email account uses Resend Pro. Its standard data processing agreement takes effect on signup, as stated on its account Documents page. The published default for active Pro accounts is 30 days for email and log data; this is not a promise that every account record, backup or legally retained copy is deleted within that period. No bespoke retention exception has been verified. This notice does not assume that all email processing stays in Ireland.

Payment takes place on hosted Stripe Checkout. Vienna SOS sends Stripe the account email, a local user reference and purchase/order references. Stripe collects the billing name and address and saves them to the Stripe Customer record, and handles the payment details entered there. Vienna SOS does not receive full card numbers through this integration. The application stores customer and payment references, amounts and payment, subscription, refund and entitlement status to administer purchases and reconcile payment events. Depending on the activity, Stripe acts as a processor or as an independent controller, including for its own fraud prevention and legal obligations. Stripe describes international transfers and retention in its privacy policy: https://stripe.com/privacy. Deleting a Vienna SOS account does not automatically delete records Stripe must retain for its own obligations.

Cookies and browser storage

Free services use the necessary vienna_free cookie to recognise a free session and enforce usage limits. It contains a signed identifier, lasts up to 24 hours and is renewed on use. It is HttpOnly, SameSite=Lax and Secure in production. The application records quota request times and last activity against the session identifier, or the account identifier for signed-in users. Where trusted proxy handling is configured, it also derives a daily-changing pseudonymous network identifier from a truncated IP address for shared-network usage limits. These records are not anonymous and are separate from the text sent for AI processing.

Authentication uses necessary session cookies; the configured session lifetime is seven days, with periodic renewal. Optional campaign attribution uses the vienna_attribution cookie for up to 30 days, only after consent, and can be withdrawn using the attribution control. The browser also remembers the attribution choice in local storage under vienna-analytics. Declining optional attribution must not prevent ordinary service use.

The application can install a service worker that caches a generic offline page and public app icons. It does not cache account pages, API responses or uploaded documents for offline access. When a page cannot be loaded from the network, it displays the generic offline page.

Retention and deletion

The application implements expiry of original documents after 12 months of inactivity in all linked active histories, subject to a recorded warning and at least 30 further days. Unattached documents are eligible for removal after 24 hours. Cleanup is performed by background processing, not necessarily at the exact eligibility time. A recorded warning does not by itself establish delivery of an email warning. Scheduled encrypted backups are stored separately from the application server. Snapshots in the designated Vienna SOS backup namespaces become eligible for pruning after 30 days; pruning runs with the scheduled backup process. Scheduled execution depends on the backup computer being available. This does not promise deletion of every historical or separately retained copy exactly on day 30.

Deleting a history clears its questions, messages, saved evidence, processing checkpoints and report content, and removes associated document text and stored files. Account deletion also removes login sessions and authentication records and replaces the account name and email. Identifiers, purchase confirmations, acceptance and receipt records, billing and some operational records remain. Failed file removals can be retried using a deletion journal. Expiry of an original document does not itself delete every derived report. Deletion does not promise immediate erasure of all backup copies. Saved reports support the history you request until you delete that history or account; there is no additional automatic report-inactivity deletion timer. Minimum account, order and entitlement references remain while needed for outstanding purchases, subscription periods, refunds or documented disputes. Financial evidence is retained according to the obligation applicable to its actual record category; full case reports and health information are not automatically treated as accounting records. Operational identifiers and consent records remain while needed for unresolved processing, reconciliation, scoped-consent evidence or deletion recovery. A deletion or withdrawal record must remain available while linked data or recoverable backups depend on it. These residual categories have no general automatic purge: their removal requires a category-specific check that the purpose and applicable obligation have ended.

Quota and correspondence cleanup

Quota requests older than one hour are removed when the same subject next uses the service. Maintenance removes free-session records after 24 hours without activity and their linked request records. Optional campaign attribution records expire after 30 days and are removed by maintenance. These rules do not determine how long account, report or billing records are kept.

Declaration cleanup leaves aggregate counts by declaration type and handling status for 30 days; these counts cannot reconstruct a deleted declaration. Restoring an older backup requires checking current deletion and handling records before access is reopened.

Temporary document processing files

Document extraction and OCR use temporary files on the application server. The extractor removes its temporary directory when processing finishes, including on a handled error. A background cleanup also removes stale temporary directories. These temporary copies are distinct from uploaded originals and saved extracted text.

Support and your choices

The application provides a separate control to grant and revoke support access to a generated report for 15 minutes. This permission does not grant access to the original uploaded files. Support access is not implied by use of the service. Contact consulting@elshanmusayev.com for privacy questions or requests concerning access, correction, deletion, restriction, portability, withdrawal of consent or objection, where applicable. You may complain to a data protection supervisory authority, including in the EU country of your habitual residence, workplace or the alleged infringement. For the operator in Baden-Württemberg, you can contact the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI), Heilbronner Straße 35, 70191 Stuttgart, Germany; poststelle@lfdi.bwl.de. Complaint instructions: https://www.baden-wuerttemberg.datenschutz.de/beschwerde/. The operator checks the scope of a request and any records that must remain for a specific unresolved matter or applicable obligation. History or account deletion is distinct from handling independent contract correspondence and copies held by recipients or providers.

Automated output

AI-generated explanations can contain mistakes and should be checked against the cited official source. The service does not decide eligibility for public benefits, immigration status, medical treatment or other official outcomes. The explanations do not themselves determine those outcomes.