Birdwave Atlas.

Privacy Policy

Last updated: 6 October 2026

1. Who We Are

Birdwave Atlas is operated by Birdwave Automation GmbH i. G., Campus-Boulevard 55, 52074 Aachen, Germany (the “controller” under the GDPR). This policy covers atlas.birdwave.io; the birdwave.io website carries its own privacy notice.

2. Data We Collect

We collect data you provide directly and data generated through your use of the platform:

  • Account data: name, email address, and password hash when you create an account.
  • Profile data: the audience segment you pick at sign-up and whatever you add to your profile: headline, biography, location and time zone, profile photo, skills, tools and programming languages, education, publications, research interests, languages, seniority and years of experience, availability, relocation preferences, social links, organisation affiliations, and events you attend.
  • Usage data: pages visited, features used, timestamps, browser type, and IP address, plus the records your activity creates on the platform: bookmarks, follows, saved searches, reactions, and contribution points.
  • Search data: the words you type into a search box, which are sent to our servers to answer the search. We keep them with your account only if you save a search. Where they appear elsewhere — in counts (section 3), in analytics if you consent, in Search the web (section 5), and in our server logs (section 7) — each section says how.
  • Contributions and communication data: messages sent through the contact form; posts, comments, reviews, spec corrections, and edit suggestions you publish; and feedback you submit, which includes the page you were on, the last few pages visited in that session, and technical error details from your browser.
  • Quote and sourcing request data: the product or listing identifiers you ask about; your name, work email, company, requested quantity, region, timeline, and message; any use-case, invoice or delivery address, or competitive-offer details you include in the message; and operational records such as request status, source page URL, user agent, and submission or update timestamps.

3. How We Use Your Data

  • To provide, maintain, and improve the directory service.
  • To authenticate your identity and secure your account.
  • To display your profile in the directory. Profiles are public by default; you can make yours private at any time under Settings → Privacy, after which only admins and curators can see it.
  • To send service-related notifications (account verification, security alerts).
  • To respond to your inquiries submitted through the contact form.
  • To process quote and sourcing requests, contact you about your own request, and forward only the request details needed to obtain a quote to the suppliers named in section 5.
  • To arrange and document an order, where your request becomes one: agreeing the price and delivery with the supplier, and keeping a record of the order and its payments. We do not take payment from you for these orders.
  • To measure demand for products in aggregate, so we know which supplier relationships and catalog data to improve. We do not build per-person interest profiles from quote or sourcing requests.
  • To follow up on your own commercial request. Unrelated product marketing is sent only where legally permitted and, where required, with your consent.
  • To understand how Atlas is used, so we can improve the catalog and search. We count, per day, which pages and products are opened, which list layouts and filters are chosen, and what people search for — including searches that find nothing — split only into signed-in and signed-out visits. These totals contain no account, IP address or other identifier and cannot be traced back to you. Nothing is stored on your device for them, and only our team sees them.

4. Legal Basis (GDPR)

  • We process account and service data to perform our contract with you or take steps before entering into one.
  • We process quote and sourcing request data under Art. 6(1)(b) GDPR for pre-contractual steps at your request, including contacting you and obtaining quote information from suppliers. Where a request becomes an order, the same basis covers arranging it with the supplier and keeping the order record.
  • Where we transfer request details to a supplier outside the EEA and no other Chapter V safeguard applies, we rely on your explicit consent under Art. 49(1)(a) GDPR, having told you the risks. See section 5.
  • We process the usage totals (section 3), security data, server logs, and operational metadata under Art. 6(1)(f) GDPR for our legitimate interests in improving the catalog, search and the site, prioritizing supplier outreach, preventing abuse, and keeping records of commercial requests. The totals do not create a per-person profile. You can object to this processing (section 8).
  • We process analytics data (PostHog) only with your consent, under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You may withdraw consent at any time through “Cookie settings”, with effect for the future.
  • We process data where necessary to comply with legal obligations.

5. Data Sharing

We do not sell your personal data. We may share data with:

  • Infrastructure providers: Railway (application hosting, file storage, and server logs), Neon (our managed PostgreSQL database), and Resend (transactional email such as verification and password-reset messages).
  • Sign-in providers: if you sign in with Google or GitHub, that provider gives us your name, email address, and profile picture, and learns that you signed in to Birdwave Atlas.
  • Maps and embedded content: the organisation and event maps load their map tiles from Mapbox. When you search for a place to look near, our server sends the place name you type to Mapbox, so Mapbox receives that text but not your IP address. Organisation logos may be fetched from logo.dev or Google’s favicon service using the organisation’s website domain, on any page that shows an organisation, whether or not you are signed in. Videos and posts shared on the platform are embedded from YouTube, LinkedIn, and X, and each loads only when you click it: until then you see a placeholder, not a YouTube thumbnail. An X post loads through Vercel, which hosts the embed service. Each of these services receives your IP address and browser details once you load its content. The same applies to the 3D viewer: when you open a product in 3D, its model files load from jsDelivr and GitHub.
  • Search the web: when a member uses “Search the web”, we send the words they typed, and nothing about their account, to Tavily (AlphaAI Technologies Inc., United States) to search the web. What Tavily does with them is described in Tavily’s privacy policy. The pages it finds are read by an AI model hosted by Nous Research (United States), which receives excerpts of those public pages but never your search words or your identity. We do not store your search words; the record of the search (your account and what was found) is deleted after 24 hours.
  • Transfers outside the EEA: some of these providers process data in the United States. Where that happens we rely on an adequacy decision, Standard Contractual Clauses, or another GDPR Chapter V safeguard.
  • Analytics: we use PostHog (EU cloud, Frankfurt) to understand how Atlas is used. It loads only after you accept analytics in the cookie banner, and records the pages you open (including any search words in their addresses), the searches you run from the header search box with their words, what you click, and session replays with all form inputs masked. Admin screens and member profiles are blanked in replays and are not click-tracked. Before anything is sent, names of members in page addresses, the place you chose to search near, and any other unexpected address parameters are removed. Once you are signed in, events are tied to your account ID and role — not your name or email. PostHog keeps event data for up to seven years, depending on our plan; you can ask us to delete yours at any time (section 8).
  • Suppliers and sourcing partners: when you submit a quote or sourcing request, we may forward the request details needed to answer it — your name, email, company, and what you asked for — to the supplier who can quote that product, and to no one else. Each acts as a separate controller for the data it receives, under its own privacy notice. Today those suppliers are:
    • robotics distributors in Germany
    • robot and component manufacturers in China (outside the EEA)

    You can ask which supplier received your request and we will tell you — write to the address in section 8.

    The recipients marked as outside the EEA are in China, for which the European Commission has not issued an adequacy decision. We transfer request details to them under Standard Contractual Clauses, or with your explicit consent under Art. 49(1)(a) GDPR where no other safeguard applies. Those transfers carry the risk that rights you have here may be harder to enforce there. If you would rather your request not leave the EEA, say so in the message and we will handle it through an EEA distributor or not at all.

  • Legal requirements: when required by law, regulation, or valid legal process.

6. Cookies and Storage on Your Device

Without asking, we store only:

  • Sign-in cookies, which keep you signed in. Strictly necessary.
  • Your cookie choice (in your browser’s local storage), with the date and the version of the banner you answered, so we do not ask again until what we ask about changes.
  • Choices you make yourself: your colour theme; whether the events page opens on the list or the map (a cookie, kept for one year); the country you buy from; the place you chose on the events map; tips and prompts you dismissed; and drafts of products or organisations you are editing.

With your consent, PostHog sets its own cookie and local storage (section 5). You can change or withdraw consent at any time through “Cookie settings” at the foot of every page; withdrawing deletes what PostHog stored.

7. Data Retention

Account data is retained while your account is active. When you delete your account, your sessions end and your profile is hidden immediately; you can restore it within 30 days by signing in again. After that window we delete the profile and anonymize the account record. The usage totals (section 3) contain no identity and are kept without a fixed end date. Analytics data in PostHog is kept as described in section 5. Backups containing personal data are purged within 90 days of deletion.

Our application logs record each request our backend receives, including the address requested, which can contain the words of a search, for operating and securing the service. They do not contain your IP address or account, and are kept for the log retention period of our hosting provider, Railway, which may also log requests at its network edge. Your sign-in sessions record the IP address and browser they were created from, to protect your account; a session record is deleted when you sign out.

Quote and sourcing request records are retained while the request is being handled and then normally for up to three years after the last activity, so we can document the commercial request and respond to follow-up or legal claims. Spam or invalid requests may be deleted sooner, and records may be kept longer where a legal obligation requires it.

8. Your Rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Request erasure of your data (“right to be forgotten”).
  • Restrict processing.
  • Data portability (receive your data in a structured format).
  • Lodge a complaint with your local data protection authority.

Right to object: where we process data on the basis of our legitimate interests (Art. 6(1)(f) GDPR, section 4), you may object at any time, on grounds relating to your particular situation (Art. 21 GDPR).

To exercise these rights, contact us at amine.kharrat@birdwave.de.

9. Security

We implement industry-standard security measures including encrypted data transmission (TLS), hashed passwords, and regular security audits. No system is 100% secure — if you discover a vulnerability, please report it to amine.kharrat@birdwave.de.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. Your continued use of the service after changes constitutes acceptance.

Birdwave.
ImprintPrivacy PolicyTerms of UseCommunity RulesData StandardReport Illegal ContentUse with ChatGPT & ClaudeContact

Logos provided by Logo.dev

© 2026 Birdwave Automation GmbH i. G.
Campus-Boulevard 55, 52074 Aachen, Germany. v0.1.4