Privacy
Controller and contact
The controller for this Verbison website is ProWebSolutions GmbH, Aurelienstr. 48, 04177 Leipzig, Germany. You can contact us at info@verbisonai.com, info@prowebsolutions.de or +49 176 10347813.
Visiting the website
To deliver a page or file, the server processes connection data, particularly the IP address, time and requested address. Depending on server configuration, logs may also contain browser information, operating system, response status and a supplied referring address. This supports delivery, troubleshooting and security under Article 6(1)(f) GDPR. Technical logs are retained only as needed for operation, security review or investigation of a specific incident.
Trial and contact enquiries
An enquiry includes your name, company or organisation, email address and website. CMS, languages, content volume, plan interest and message are optional. Required details let us identify the enquiry, understand the proposed website use and reply. The form cannot be submitted without them; you may contact us directly by email instead.
We process enquiries to respond and, for a trial or offer, prepare a possible business relationship. Article 6(1)(b) GDPR applies when you enquire about a contract on your own behalf. Enquiries as a company representative and other correspondence are handled under Article 6(1)(f) GDPR and our interest in business communication. The checkbox acknowledges this notice; it is not consent to advertising.
Form data is validated on the server and sent through the configured SMTP connection to info@verbisonai.com. The website does not create a separate enquiry database. Correspondence is deleted once the matter is resolved and there is no continuing reason to retain it. Legal retention duties or the establishment, exercise or defence of claims may require longer retention. Please do not send passwords or sensitive personal information.
Protecting the form
Opening a form page sets a necessary session cookie containing a random identifier. It helps verify that a submission belongs to the previously opened form. It is not used for advertising or visitor analysis and expires with the browser session. Server-side form authorisation lasts one hour. The legal bases are section 25(2)(2) TDDDG for necessary storage and Article 6(1)(f) GDPR for protection against abusive submissions.
To limit repeated submissions, the IP address is transformed into a check value using a secret server key. The file stores that value, a counter and an expiry time. The association is used for at most one hour; expired entries are cleaned on the next form access. Names, email addresses and messages are not stored in this rate-limit file.
Free trial and expiry email
When we set up a trial with you, we use your contact details for setup and related communication. After 14 days, we email you about the end of the trial and the option to book the service. There is no automatic paid contract. This website does not subscribe you to a newsletter.
Audio samples, images and events
Audio samples and images are served by this website. A recording is requested only following a playback action; visiting a page does not generate new speech. No analytics or advertising cookies, external font providers or tracking platforms are included.
The page may expose interactions such as play, voice switching or a pricing page view as technical events within the browser. These contain no form content, email addresses or visitor identifiers. Without a separately configured analysis system, they are not transmitted to an analytics service or persistently stored.
Recipients and technical providers
People handling your enquiry and the hosting and email providers may receive data as required for their tasks. Where they act as processors, Article 28 GDPR governs their engagement. This website adds no analytics or advertising recipient. Transfers to a third country must meet the requirements of Articles 44 onwards GDPR.
Your rights
Subject to the statutory conditions, you may request access, rectification, erasure, restriction of processing and data portability. You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. Where processing relies on consent, you may withdraw it for the future. Use the contact details above to exercise these rights.
You may also complain to a data protection supervisory authority, particularly where you habitually reside, work or consider an infringement to have occurred. This website makes no automated decisions with legal or similarly significant effects and does not create visitor profiles.
Customer account and workspace
In the customer area at /app/, we process your email address, optional name, verification status and organisation memberships with their assigned permissions. Password sign-in stores a secure password hash only. Workspace data includes websites, page URLs, spoken texts and revisions, language editions, chosen voices, uploaded or generated audio, approvals and service status. These records are held in a relational database and protected file storage. Organisation members have access according to their role.
This enables the requested service and performance or preparation of a contract under Article 6(1)(b) GDPR. For an organisation’s employees and representatives, processing is based on Article 6(1)(f) GDPR and our legitimate interest in the agreed cooperation. Verification and password-reset messages use the existing mail service. Verification links are valid for 24 hours and reset links for 30 minutes; each can be used once.
The necessary verbison_core cookie contains a random session identifier. Sign-in expires after at most twelve hours or 30 minutes of inactivity. Security records contain expiry times, protected check values for repeated requests and selected administrative events. Full spoken texts, passwords and sign-in tokens are excluded from the activity log. Necessary session storage is based on section 25(2)(2) TDDDG; abuse prevention relies on Article 6(1)(f) GDPR.
Account data and content are retained for the duration of use or required contract administration. Archiving a page preserves its texts and audio and does not delete them. To request erasure, contact info@verbisonai.com. Data no longer needed is deleted unless legal retention requirements or necessary evidence justify continued storage. Responsibilities and, where applicable, data-processing arrangements for personal content you process on behalf of others are agreed separately.
Optional Google sign-in
Sign-in pages and account linking use Google Identity Services. Loading the Google sign-in button establishes a connection to Google, which receives technical connection and browser information. You can instead use email and password sign-in. After your confirmation, Google provides a signed identity assertion. We use the stable Google account identifier, email address and verification status. We do not receive Google passwords or request Gmail, contacts or Google Drive content.
Association with your Verbison account enables your chosen sign-in method under Article 6(1)(b) GDPR or, for organisation members, Article 6(1)(f) GDPR. An existing password account is not automatically linked solely because the email matches. Google’s own processing, the responsible Google entity and possible international transfers are described at https://policies.google.com/privacy. The Google sign-in dialogue also provides information and choices.
Scope
This notice covers the Verbison website, its contact functions and the customer area. Agreements on processing customer content supplement this notice. Last updated: 10 September 2026.