LegalAirLST GmbH

Privacy policy: what this website stores and what it does not

This website uses no cookies for advertising or analytics and loads no third-party services into your browser. Only if you object to visit counting do we store your decision in a strictly necessary cookie. This page explains which data arises when you visit, chat or fill in a form, what we use it for, how long we keep it and what rights you have. The German version is the binding one.

Updated
October 8, 2026
For
Visitors of airlst.com
The short answer

In short: When you visit, we process technically necessary connection data. In addition we measure the use of our website with our own data-minimizing method without cookies; you can object to visit counting and company identification with the switch further down. We load no tracking or advertising services from Google, Meta or other providers into your browser. If you use the chat, the forms or the newsletter, we also process what you enter; the chat uses the AI service of Anthropic for its answers. Purposes, legal bases, recipients and retention periods are in the sections below. The controller is AirLST GmbH in Munich, Germany; our data protection officer answers questions.

Controller and data protection officer

AirLST GmbH
Seitzstraße 23
80538 Munich, Germany
Phone +49 89 54 04 55 720
Email kontakt@airlst.com

Data protection officer: Mr. Jürgen Recha, c/o interev GmbH, Robert-Koch-Straße 55, 30853 Langenhagen, Germany, email datenschutz@interev.de, phone +49 511 89 79 84 10. You can contact him directly with any privacy question.

What this website does not do

  • No cookies when you visit. Neither our own nor third-party ones. The only cookie on this website is the opt-out cookie you set yourself if you object to measurement (see storage in your browser). That is why there is no cookie banner: there is nothing to consent to.
  • No tracking or advertising services. No Google Analytics, no Google Ads or Tag Manager, no Meta pixel, no LinkedIn Insight Tag, no reCAPTCHA.
  • No content from other servers. Fonts, icons, images and scripts are served from our own server. Your browser does not connect to Google Fonts, Font Awesome, Calendly or similar services when you visit.
  • No visitor profiles. We cannot recognize a person from one day to the next and do not build user profiles.

There are service providers in the background nonetheless: Amazon Web Services for hosting and email delivery, and Anthropic for the chat answers. Both are described in their sections.

Links to our profiles on LinkedIn, Instagram and Facebook and to the app stores are plain links. Only when you click them do you leave our website; from then on the privacy policy of that provider applies.

Storage in your browser

The website only stores entries in your browser that you triggered yourself, and it reads no other information from your device. These entries are strictly necessary for the function you asked for (Section 25 (2) no. 2 of the German TDDDG, no consent required). A campaign tag has not been stored in the browser since October 8, 2026.

Entries in browser storage
EntryContentPurposeLifetime
Themelight or darkremembers your color schemeuntil you delete it
Chat historya random token (only once you start the chat)shows your previous conversation when you reopen the chatuntil you delete it or the conversation is closed
Time zonea note that the meeting booking asked for your time zoneavoids asking again at every stepuntil you close the tab
Opt-outcookie al_optout=1 (only if you switch measurement off below)remembers your objection to visit counting and company identificationone year

You delete all entries through the site data settings of your browser.

Visiting the website: server logs and hosting

Serving the website

For your browser to receive the page, our server processes your IP address and writes the usual access logs.

Data
IP address, date and time, page requested, referring page, browser and operating system, bytes transferred, status code
Purpose
delivering the page, operational security, defending against attacks, troubleshooting
Legal basis
Art. 6 (1) (f) GDPR (legitimate interest in secure operation)
Recipients
hosting provider as processor: Amazon Web Services EMEA SARL, Luxembourg, data center in Frankfurt am Main, Germany (region eu-central-1), managed via Laravel Forge, Art. 28 GDPR agreement
Retention
server logs 14 days. Server backups are kept encrypted at AWS in Frankfurt and Paris and deleted automatically after 30 days; data we delete therefore disappears from the backups within 30 days at the latest

Visit counting without identifiers

Counting page views

We measure the use of the website ourselves, without cookies and without a third-party service. When you leave a page, a small script reports which page was open for how long. To add up the views of one visit, the server builds a hash from IP address, browser and a random value that changes every day. The IP address is processed at the moment of the request but not stored; the random value is deleted after 32 days, after which the hash can no longer be attributed. Until then the hash is a pseudonymous value, not an anonymous one. We use the same daily hash to relate a chat conversation or a meeting request of the same day to the page views (source and pages read); beyond that day no attribution is possible.

Data
page viewed, referring page, campaign tag from the link (UTM), scroll depth, time on page, a daily hash
Purpose
knowing which pages are read and how visitors find us
Legal basis
Art. 6 (1) (f) GDPR (legitimate interest in evaluating our own site). The script stores nothing on your device and reads no information stored there (no cookies, no storage, no device identifiers); it only determines the state of the displayed page (scroll position, duration). In our assessment Section 25 TDDDG is therefore not engaged; the assessment is with the data protection officer
Recipients
none; the evaluation runs on our own server
Retention
views 24 months (automatic deletion run); the random value used to build the daily hash is deleted after 32 days, and until then we treat the hash as pseudonymous data

Objection (Art. 21 GDPR): The switch turns off visit counting and company identification for this browser. For that we set a single cookie (al_optout=1, one year) so the server recognizes your objection on every request. Status: checking.

Company identification through public network registries

Attributing a visit to a company

AirLST serves businesses. Many companies run their network under their own publicly registered address block. When a page is requested, our server compares your IP address with these public registries. If it falls into a company block, we note the company name with the page view. Connections of private individuals, mobile networks, home offices and data centers are discarded; the IP address is never stored.

Data
your IP address at the moment of the request (not stored); what we store is the name of the company that owns the network block according to the public registry, attached to the page view. For very small companies the company name may allow inferences about individuals, which is why we treat the attribution as personal data, not as anonymous
Purpose
knowing which companies are interested in AirLST so we can approach them (B2B sales)
Legal basis
Art. 6 (1) (f) GDPR (legitimate interest in marketing to businesses); the balancing of interests is documented and held by the data protection officer. The registry data on network blocks comes from public sources (Art. 14 GDPR); it mostly concerns companies and network operators. Where it allows inferences about natural persons, for example sole proprietors, we treat that data as personal data
Recipients
none; the registries (RIPE, ARIN and others) are only queried, no data is sent to them. The company name is not linked to contact data from forms or the CRM unless you contact us yourself on behalf of that company
Retention
company name per page view 12 months; registry data on network blocks 30 days

You can object to this processing at any time (Art. 21 GDPR): for your browser with the switch in the visit counting section, for your company by email to datenschutz@interev.de; name the company whose attribution we should delete.

Chat with AI assistant

Website chat

The chat in the bottom right corner answers questions first through an AI assistant. The chat window says so before you send the first message. If you want to talk to a person, the AirLST team reads along and takes over; the AI then stops answering.

Data
your messages, the replies, the page on which you opened the chat, timestamps; plus the daily hash from visit counting so our team can relate the chat to a visit
Purpose
answering your questions about AirLST, handover to a team member on request
Legal basis
Art. 6 (1) (b) GDPR (pre-contractual inquiry), otherwise (f) (legitimate interest in answering inquiries). The transfer to the USA rests on the European Commission adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), under which Anthropic is certified
Recipients
Anthropic, PBC, San Francisco, USA, directly through the Anthropic API (operator of the Claude language model, processor under its Commercial Terms and Data Processing Addendum); only the conversation text is transmitted, no IP address. Anthropic does not use API inputs to train its models. The AirLST team can read all conversations in our own back end, not only after a handover
Retention
conversations on our server 6 months; at Anthropic, API inputs and outputs are deleted by default within 30 days according to its documentation; the token in your browser until you delete it

Please do not enter anything in the chat that you do not want to transmit, in particular no data about third parties and no credentials. The conversation is tied to a random token in your browser, not to your name; if you mention your name or email address in the chat, they become part of the stored conversation. To have a conversation deleted early, send us the date, approximate time and the wording of your first message; that lets us find it without an identifier.

Forms: newsletter, contact, meeting, free trial

Newsletter

Sign-up uses double opt-in: you receive a confirmation link, and only after clicking it are you subscribed. Every issue contains an unsubscribe link.

Data
email address, time of sign-up and of confirmation, page of sign-up
Purpose
sending our newsletter with news about AirLST and attendee management
Legal basis
Art. 6 (1) (a) GDPR (consent, evidenced by the confirmation click)
Recipients
email delivery through Amazon Simple Email Service (Amazon Web Services EMEA SARL, Frankfurt region) as processor
Retention
until you unsubscribe; unconfirmed sign-ups 14 days

Contact form and meeting booking

Data
name, company, email address, topic and message; for a meeting booking also the requested slot, time zone and a note; plus the campaign tag if it was part of the link to the form, and for a meeting request the source (channel, campaign, landing page) from the same day's page views via the daily hash
Purpose
handling your inquiry, holding the meeting, follow-up questions
Legal basis
Art. 6 (1) (b) GDPR (pre-contractual inquiry), otherwise (f) (answering inquiries)
Recipients
none besides email delivery (see newsletter); meetings are managed on our own server, not with Calendly or another scheduling service
Retention
12 months after the inquiry is settled; meetings with confirmation and cancellation likewise 12 months after the meeting

Free trial

The link "Start free trial" leads to the AirLST platform at airlst.app. The privacy policy there and the terms apply to the platform.

Data
the details you enter when registering on the AirLST platform
Purpose
setting up your account
Legal basis
Art. 6 (1) (b) GDPR (contract)
Recipients
none; the platform is operated by AirLST
Retention
according to the platform terms

We protect all forms without reCAPTCHA: a hidden field, a timestamp and a limit on requests per hour keep spam out. For this, a hash of your IP address is stored briefly and deleted after two days.

Recipients and transfers outside the EU

Within AirLST only the staff handling your inquiry have access. The processor is Amazon Web Services (hosting and email delivery in Frankfurt); an agreement under Art. 28 GDPR is in place. A transfer to a country outside the EU takes place only for the chat to Anthropic (USA, adequacy decision for the Data Privacy Framework, see above). The web server and email delivery run at AWS in Frankfurt, Germany, inside the EU. We do not sell data and do not share it for advertising.

Your rights

Regarding your personal data you have the following rights against us:

  • Access (Art. 15 GDPR) to the data we process about you.
  • Rectification (Art. 16) of inaccurate and completion of incomplete data.
  • Erasure (Art. 17), unless a retention obligation applies.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20) for data you provided based on consent or a contract.
  • Objection (Art. 21) to processing based on legitimate interest, in particular visit counting and company identification.
  • Withdrawal of consent (Art. 7 (3)) with effect for the future, for example through the unsubscribe link in the newsletter.

Contact kontakt@airlst.com or the data protection officer. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for AirLST is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, lda.bayern.de. US residents: this website does not sell or share personal information; the rights above apply to you as well.

Changes to this policy

We update this policy when the website or the law changes; the version published here with the date above is the one that applies. The version of December 2, 2024 described the previous website with analytics and advertising services that have not been used since the rebuild.

Events made easy

Your next event. One source of truth.

In 15 minutes, we will show you how AirLST is set up for your event. Or start for free with up to 50 guests per event.