Legal
Privacy Policy
This policy explains how DME GmbH processes personal data in connection with the meetadrian.ai website and the ADRIAN software. ADRIAN is a business-to-business service offered exclusively to companies. This is a translation for convenience; the German version prevails.
Last updated: February 2026
1. Controller
DME GmbH
Innsbruckerstraße 53, 6380 St. Johann in Tirol, Austria
Commercial register: FN 606779y (Regional Court Innsbruck)
VAT ID: ATU79531614
Email: support@meetadrian.ai
Data protection contact: Daniel Gruber, privacy@gruber-dme.com. DME GmbH is not required to appoint a data protection officer under Art. 37 GDPR; the contact named above handles all data protection matters.
2. Two processing roles
- DME as controller: website delivery, pre-contractual communication, registration and administration of user accounts, billing, support and platform security.
- DME as processor (Art. 28 GDPR): all content data our customers submit to ADRIAN or retrieve through connected advertising and analytics accounts. For that data the customer is the controller; we process it solely on the customer's instructions under a data processing agreement that forms part of the service contract. Requests concerning such data should be addressed to the relevant customer; we support them in responding.
3. Categories of data
3.1 Website and service delivery
- Server and log data: IP address, timestamp, requested resource, referrer, user agent, status code. This data is technically unavoidable when a page is requested.
- Content of enquiries sent to support@meetadrian.ai or sales@meetadrian.ai.
3.2 Account and contract data
- Identification and access data: name, business email address, password hash, role and tenant assignment, sign-in timestamps.
- Contract and billing data: selected plan, billing period, invoicing address, VAT ID, payment status. Full payment instrument data (for example card numbers) is processed exclusively by our payment service provider; we do not receive it.
- Support correspondence and security-relevant logs (sign-in attempts, permission changes).
3.3 Content data inside ADRIAN (processing on instruction)
- Aggregated campaign, account and performance data from connected advertising and analytics platforms (Google Ads, Meta, TikTok, Snapchat, LinkedIn, Pinterest, Google Analytics 4, Google Search Console) — such as impressions, clicks, cost, conversions, reach and metrics at campaign, ad group or creative level.
- Access tokens for connected platform accounts. These are stored encrypted and used only to retrieve the metrics the customer has authorised.
- Report files uploaded by the customer (for example CSV exports). These are parsed in the user's browser and not stored as raw files on our systems.
- Free-text input in analysis dialogues, which is transmitted to our processing infrastructure in order to produce an answer.
ADRIAN is designed for aggregated marketing metrics. Submitting special categories of data under Art. 9 GDPR, data relating to minors, or individual personal profiles of end customers is not a purpose of the service and is contractually prohibited.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing, stabilising and securing the website | Art. 6(1)(f) GDPR (legitimate interest in secure operation) |
| Responding to enquiries, pre-contractual steps | Art. 6(1)(b) and (f) GDPR |
| Account management, performance of the contract, support | Art. 6(1)(b) GDPR |
| Billing, accounting, statutory retention | Art. 6(1)(b) and (c) GDPR (incl. § 132 BAO, §§ 190 ff. UGB) |
| Abuse prevention and security logging | Art. 6(1)(f) GDPR |
| Processing customer content in ADRIAN | Customer instruction, Art. 28 GDPR (legal basis held by the customer) |
| Email marketing to existing customers | Art. 6(1)(f) GDPR with § 174 TKG 2021; objection possible at any time |
5. Recipients and processors
We use carefully selected service providers who process on our behalf under Art. 28 GDPR agreements. Categories:
| Category | Function |
|---|---|
| Hosting and application operations | Delivery of the application, compute and network capacity |
| Database and authentication service | Storage of account, role and metric data, sign-in management |
| Connectors to advertising and analytics platforms | Retrieval of campaign and analytics data authorised by the customer |
| Neural Context Engine processing service | Generation of analyses and answers to analysis requests |
| Payment service provider | Handling of subscription and invoice payments |
| Email delivery service | Transactional and system messages |
| Context services (weather and geocoding data) | Enrichment of analyses with location and weather context |
A current, named list of sub-processors including processing locations is provided to customers and data subjects on request at privacy@gruber-dme.com; it forms part of the data processing agreement. New sub-processors are announced to customers in advance together with a right to object.
We also disclose data to tax advisers, auditors, legal counsel or authorities where legally required or necessary to establish and defend legal claims.
6. Transfers to third countries
Some providers — in particular advertising platforms, payment processing and processing infrastructure — are established in the United States or process data there. Such transfers rely on an adequacy decision of the European Commission (EU-US Data Privacy Framework) or on Standard Contractual Clauses under Art. 46(2)(c) GDPR, in each case supplemented by technical and organisational measures such as encryption in transit and at rest and data minimisation. Copies of the safeguards are available on request.
Where customers connect their own advertising platform accounts, requests are issued directly to those platforms; the platforms' own privacy terms apply to processing within their systems.
7. Retention
- Server logs: deleted or anonymised within 30 days unless longer retention is required to investigate a security incident.
- Account and content data: for the term of the contract. After termination, data is deleted or returned on the customer's instruction within 30 days unless statutory retention obligations apply. Backups are overwritten according to our providers' rotation cycles.
- Access tokens of connected platforms: deleted immediately when a connection is removed or an account is deleted.
- Invoices and accounting records: seven years under § 132 BAO, longer where proceedings are pending.
- Support correspondence: three years after closure of the matter for traceability and defence of claims.
8. Cookies, browser storage and analytics
This website does not set cookies for advertising, tracking or profiling. Within the application we use strictly necessary entries in the browser's local storage, in particular to maintain the session and store the language preference. This storage is necessary to provide the service explicitly requested by the user (§ 165(3) TKG 2021) and therefore does not require consent. No consent banner is displayed as long as no non-essential technologies are used.
Web fonts are served from our own infrastructure; no request is made to third-party font providers and no IP address is transmitted to them.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on Art. 6(1)(f) GDPR (Art. 21). Consent, where given, can be withdrawn at any time with effect for the future.
Please send requests to privacy@gruber-dme.com. We respond within one month; for complex requests the period may be extended by two months, and we will inform you. If your request concerns data a customer submitted to ADRIAN, we forward it to that customer as controller.
You may lodge a complaint with the supervisory authority: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
10. No automated decision-making
We do not carry out automated decision-making, including profiling, producing legal effects within the meaning of Art. 22 GDPR. Analyses and recommendations produced by the Neural Context Engine are decision support; every action is decided and executed by the customer.
11. Security of processing
We implement technical and organisational measures under Art. 32 GDPR, in particular transport encryption (TLS), encryption of stored access tokens, tenant-level access separation at database level, role-based permissions, logging of security-relevant events, least-privilege administrative access and periodic review of these measures. In the event of a personal data breach we comply with the notification duties under Art. 33 and 34 GDPR and inform affected customers without undue delay.
12. Obligation to provide data
Providing account and billing data is necessary to enter into and perform the contract; without it the service cannot be provided. There is no further statutory obligation to provide data.
13. Changes to this policy
We update this policy when processing activities, service providers or legal requirements change. The version published on this page applies; customers are additionally notified by email about material changes.
In case of discrepancies between the German and English versions, the German text prevails.