Privacy Policy
We manage our website according to the principles set out below. We undertake to comply with the statutory provisions on data protection and endeavour to always take into account the principles of data avoidance and data minimisation.
1. Name and address of the controller
Controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states of the European Union as well as other data protection regulations is:
RG Ventures GmbH
Managing Director: Ralf Gehrer
Fliederstraße 32
73066 Uhingen
Amtsgericht Ulm, HRB 741919
Email: info@go10x.ai
Website: https://go10x.ai/
Imprint: /en/imprint/
We are not legally required to appoint a data protection officer. For questions about data protection and to exercise your rights, you can reach us at the contact details above at any time.
2. Explanation of terms
We have designed our privacy policy according to the principles of clarity and transparency. However, if there are any ambiguities regarding the use of various terms, the relevant definitions can be found in Art. 4 GDPR.
3. Legal basis for the processing of personal data
a) Processing of personal data under the GDPR
We process your personal data, such as your name, your email address or your IP address, only if there is a legal basis for doing so. Under the General Data Protection Regulation, the following provisions come into consideration in particular:
- Art. 6 para. 1 sentence 1 lit. a GDPR: The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Art. 6 para. 1 sentence 1 lit. b GDPR: The processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Art. 6 para. 1 sentence 1 lit. c GDPR: Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Art. 6 para. 1 sentence 1 lit. f GDPR: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
We will refer you again to the legal basis for the processing at the relevant points in this privacy policy.
b) Consent of guardians under Art. 8 GDPR
A guardian must consent to all data processing on this website for which the consent of a minor under the age of 16 is required. You can withdraw consent at any time. Processing carried out until withdrawal remains lawful.
c) Processing of information under Section 25 (1) TDDDG
We also process information pursuant to Section 25 (1) TDDDG by storing information on your terminal equipment or accessing information that is already stored there. This may concern personal as well as non-personal data, for example cookies or entries in your browser’s local storage.
As a rule we process this information on the basis of your consent, Section 25 (1) TDDDG. If an exception under Section 25 (2) no. 1 and no. 2 TDDDG applies, we do not require consent. Such an exception applies if we exclusively access or store information for the sole purpose of carrying out the transmission of a message over a public telecommunications network, or if this is strictly necessary in order to provide a telemedia service expressly requested by you.
Withdrawing consent does not affect the lawfulness of the processing carried out on the basis of that consent until withdrawal.
4. Transfer of personal data
Transferring personal data is also processing within the meaning of item 3 above. Data is only passed on to third parties if there is a legal basis for the processing. For example, we disclose personal data to persons or companies that act as processors for us pursuant to Art. 28 GDPR, meaning they are instructed and controlled by us.
In accordance with the requirements of the GDPR, we conclude a contract with each of our processors to bind them to data protection regulations.
5. Storage period and erasure
We will erase your personal data if it is no longer necessary for the purposes for which it was collected or otherwise processed, and the processing is not necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims. The specific storage and erasure periods for each processing activity are set out in the sections below.
6. SSL / TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL / TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line. When encryption is active, the data you transmit to us cannot be read by third parties.
7. Cookies
We use cookies and comparable storage technologies on our website. Cookies are small data packages that your browser automatically creates and that are stored on your terminal device when you visit our website.
a) Technically necessary storage
To preserve your cookie settings, we store the choice you make in your browser’s local storage. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR, our legitimate interest in the error-free operation of the website and in not asking you again on every page view.
b) Other cookies
The other cookies include cookies for statistical purposes (see item 10) and cookies of external media (see item 11). We use these exclusively on the basis of your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR.
You can withdraw your consent at any time. To do so, you can edit your cookie settings on our website, deactivate the use of cookies in your browser settings, or set an opt-out for the respective service in individual cases.
8. Consent banner and consent management
To obtain consent for the services we use, we use our own consent banner. It stores the choice you make in your browser’s local storage in order to query and process your consent status. This storage is technically necessary and is used on the basis of our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR, Section 25 (1) TDDDG. It is never transmitted to a server.
In the consent banner you consent per individual service, not to a cookie category as a whole. The categories statistics (see item 10) and external media (see item 11) are headings only; you make the choice at the service itself.
For every service, the page Services and cookies in detail sets out the provider with postal address, the purpose, any transfer outside the European Economic Area, and every cookie set, with its name, storage location, lifetime and purpose. Technically necessary storage is always active and is listed there as well. The page is linked from the consent banner and is reachable without consent.
Without your consent, no consent-requiring service is loaded. Your consent is voluntary; using this website does not depend on it.
We store your choice, the time of your decision, and the version of the service list it refers to. If that list changes, we ask again rather than extending your earlier decision to a service you never saw.
You can change your choice at any time via the “Cookie Settings” link in the footer of every page. If you withdraw a consent, we delete the cookies and storage entries of the service concerned and reload the page, so that a service that has already started actually stops.
9. Collection and storage of personal data, and the nature and purpose of its use
a) External hosting
Our website is hosted by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. For this reason, all personal data collected on our website is processed on the servers of our host, unless an external service of a third party is integrated. The host processes your data only on our instructions and insofar as this is necessary for the performance of the services on the website. We have concluded a data processing agreement with Cloudflare.
b) When visiting the website
When you access our website, the browser used on your terminal device automatically sends information to the server of our website, which is temporarily stored in a log file. The following information is collected without your intervention:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the retrieved file
- Website from which access is made (referrer URL)
- The browser used and, if applicable, the operating system of your computer as well as the name of your access provider
We process this data to ensure a smooth connection to the website, to evaluate system security and stability, to analyse errors, and for further administrative purposes.
Data that allows conclusions to be drawn about your person, such as the IP address, is deleted after 7 days at the latest. If we store the data beyond this period, it is pseudonymised so that it can no longer be assigned to you.
The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest follows from the purposes listed above. In no case do we use the collected data to draw conclusions about your person.
c) Cloudflare as a content delivery network and web firewall
On our website we use a content delivery network and the web firewall of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. For this purpose Cloudflare may process IP addresses, information regarding the routing of data traffic, the system configuration and other information about the traffic.
For the content delivery network, the information transfer between your browser and our server is technically routed via the Cloudflare network so that we can optimise the loading speed of our website. The web firewall is intended to prevent unauthorised access, automated abuse and other illegal activities. This includes limiting the number of requests per IP address to our form endpoint.
The processing is carried out pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR on the basis of our legitimate interest in the secure and efficient provision of our website.
We have concluded a data processing agreement with Cloudflare. Insofar as data is transferred to the USA, this is safeguarded by the certification of Cloudflare, Inc. under the EU-U.S. Data Privacy Framework pursuant to Art. 45 para. 1 GDPR as well as by EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR. Further information: https://www.cloudflare.com/privacypolicy/
d) Inquiry form
On the page /engineering/ we provide a form through which you can send us a request for agentic engineers. Your name, a valid email address, a phone number and a description of the role you are looking for are required. We need your name and email address to know who the request is from and to reply to you. We need the phone number because the briefing on the role you are looking for takes place by phone.
When you send us a request via the form, we process your details to handle your enquiry pursuant to Art. 6 para. 1 sentence 1 lit. b and f GDPR, that is, to take steps at your request prior to entering into a contract, and to safeguard our legitimate interest in exercising our business activity.
We do not store the request in a database on this website. It is delivered to us as an email only (see letter e) and processed in our mailbox thereafter. Requests and the associated data are deleted no later than 6 months after the enquiry has been dealt with, unless they are required for a further contractual relationship. If a contractual relationship comes about, we are subject to the statutory retention periods, for example under the German Commercial Code and Fiscal Code, and delete the data once they expire.
e) Email delivery (Resend)
To send the notification about incoming form requests, we use the email service Resend of Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. The data required for delivery, in particular your name, your email address and the content of your request, is transmitted to Resend and processed there.
The legal basis is Art. 6 para. 1 sentence 1 lit. b and f GDPR, to handle your request and to safeguard our legitimate interest in reliable email communication. As Resend is based in the USA, a transfer of your data to the USA is possible. This is safeguarded by the conclusion of EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR. We have concluded a data processing agreement with Resend pursuant to Art. 28 GDPR.
Further information: https://resend.com/legal/privacy-policy
f) Contact by email
You have the option of contacting us by email. The data you transmit, in particular your name, your email address and the content of your message, is processed in order to handle your request. Processing is carried out pursuant to Art. 6 para. 1 sentence 1 lit. b and f GDPR. The same erasure periods apply as under letter d.
g) Protection against spam and abuse
To protect our form against automated abuse, we use technical measures that work without cookies and transmit no data to third parties. These include a field that is invisible to you and an evaluation of how long the form took to fill in. In addition, we limit the number of requests per IP address to our form endpoint; your IP address is used only transiently for that count and is not stored by us.
The legal basis is our legitimate interest in warding off abusive submissions pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR.
h) Appointment booking (TidyCal)
On our website we offer you the option of booking an appointment for a free AI strategy call. For this we use TidyCal, a service of Sumo Group, Inc., 1305 E. 6th St #3, Austin, TX 78702, USA. When you click the booking link, you are forwarded to a booking page operated by TidyCal. No booking tool is embedded on our website, so no TidyCal content is loaded unless you click the link.
In the course of the appointment booking, TidyCal processes the data you enter there, in particular your name, email address and appointment preferences, as well as technical information including IP address, browser and device information.
Since TidyCal’s infrastructure is located in the USA, a transfer of your data to the USA takes place. Where required, this is safeguarded by the conclusion of EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR. We have concluded a data processing agreement with TidyCal pursuant to Art. 28 GDPR. The legal basis for processing your booking data is Art. 6 para. 1 sentence 1 lit. b GDPR, to take steps prior to entering into a contract.
Further information: https://tidycal.com/privacy
i) CRM system (HubSpot)
To manage and process inquiries and business contacts, we use the CRM system (customer relationship management) HubSpot of HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany (“HubSpot”). HubSpot does not set cookies on our website and does not load a tracking script.
Data that may be stored includes in particular name, company, email address, phone number, subject or message, as well as the time and origin of an inquiry. We use the stored data to handle your request and to contact you.
We use HubSpot with data hosting in the European Union; data is stored and processed in a data centre in Frankfurt am Main, Germany. HubSpot Germany GmbH uses the group company HubSpot, Inc., Two Canal Park, Cambridge, MA 02141, USA, to provide its services; access to your data from the USA, for example for support or maintenance, can therefore not be completely ruled out. Any such transfers are safeguarded by the conclusion of EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR as well as by the certification of HubSpot, Inc. under the EU-U.S. Data Privacy Framework pursuant to Art. 45 para. 1 GDPR.
The legal basis for the processing is Art. 6 para. 1 sentence 1 lit. b and f GDPR, to take steps at your request prior to entering into a contract or to safeguard our legitimate interest in the efficient handling and management of incoming inquiries. We have concluded a data processing agreement with HubSpot pursuant to Art. 28 GDPR. HubSpot does not acquire any right to pass on your data.
Further information: https://legal.hubspot.com/privacy-policy
j) Business email communication (Brevo)
For sending business emails, in particular in the context of our B2B outreach, we use the email tool Brevo of Brevo GmbH, Köpenickerstraße 126, 10179 Berlin. For this purpose, the contact data required for sending, in particular name, email address and company, is passed on to Brevo and processed there. This tool also allows us to evaluate how emails are opened and used.
Brevo is a German company whose servers are located in Germany. We have concluded a data processing agreement with Brevo pursuant to Art. 28 GDPR. Brevo does not acquire any right to pass on your data.
The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR, to safeguard our legitimate interest in efficient business communication. Independently of this, the requirements of the German Act against Unfair Competition (UWG) for electronic advertising remain unaffected.
Further information: https://www.brevo.com/legal/privacypolicy/
10. Analysis and tracking tools
We use the analysis tool listed below on our website. It serves to ensure the continuous optimisation of our website and to design it to meet your needs.
We use it exclusively on the basis of your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. Without your consent, the service is not loaded. You can withdraw your consent at any time by changing your cookie settings. Processing carried out until withdrawal remains lawful.
a) PostHog
On this website we use PostHog, a product analysis platform that enables us to analyse how our website is used and to develop our offering on that basis. The platform includes functions such as event tracking, analysis of page views and user flows, and the evaluation of click and scroll behaviour.
The provider is PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. We use PostHog in the hosting variant “PostHog Cloud EU”, in which all data is stored and processed exclusively on servers in Frankfurt am Main, Germany.
PostHog processes technical information about the terminal device used, for example browser type, operating system and screen resolution, as well as information about the website visit, for example pages viewed, dwell time, click and scroll behaviour and origin URL. For this purpose, cookies are used that enable cross-session recognition of the browser. Session recording is switched off, and no personal profile is created for anonymous visitors.
Although all data is stored and processed exclusively on servers in Frankfurt am Main, PostHog, Inc., based in the USA, is the contractual partner. Access to stored data by employees of PostHog, Inc. from the USA, for example for support or maintenance purposes, can therefore not be completely ruled out. In this case, any transfers are safeguarded by the certification of PostHog, Inc. under the EU-U.S. Data Privacy Framework pursuant to Art. 45 para. 1 GDPR as well as by EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR.
The legal basis is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. You can withdraw it at any time with effect for the future by adjusting your cookie settings. Since PostHog processes data on our behalf, we have concluded a data processing agreement with PostHog, Inc. pursuant to Art. 28 GDPR.
Further information: https://posthog.com/privacy
11. YouTube and video embedding
On this website we embed videos from YouTube, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. They are embedded inside an iframe in enhanced data protection mode via the domain youtube-nocookie.com.
Videos are loaded only after you consent to the “YouTube” service. Without that consent you see a placeholder in their place, and nothing is loaded from Google. This expressly includes a video’s thumbnail, because retrieving it would already establish a connection to a Google server. The placeholder contains a link that opens the video on YouTube directly; in that case only Google’s terms apply.
If you play a video, a connection to the YouTube servers is established and the YouTube server is informed which of our pages you have visited. This allows YouTube to assign your surfing behaviour to your personal profile. You can prevent this by logging out of your member account before visiting our website. In addition, YouTube sets various cookies when starting the service in order to improve its services and prevent misuse, according to its own information.
Embedding YouTube may also load Google Fonts dynamically. These web fonts are retrieved by a server call, as a rule to a Google server in the USA. This may transmit the following to the server, where Google stores it: name and version of the browser used, referrer URL, operating system and screen resolution of your computer, IP address of the requesting computer, and the language settings of the browser or operating system.
The legal basis is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. You can withdraw it at any time by changing your cookie settings.
Further information: https://policies.google.com/privacy
12. Social media profiles
We maintain public profiles on the social networks listed below in order to inform people about our services and to get in touch with visitors. When you visit these profiles, the respective platform operator processes personal data under its own responsibility; the details are set out in its privacy policy. Where platforms provide us with statistics about the use of our profiles (“insights”), we are joint controllers together with the operator within the meaning of Art. 26 GDPR; the essence of the respective arrangement is linked below. The legal basis for our processing is Art. 6 para. 1 sentence 1 lit. f GDPR (public presentation and communication). We do not see raw data, only aggregated statistics and whatever users address to us publicly or by message; we delete such interaction data as soon as the purpose no longer applies. The operators process data partly in third countries, in particular the USA, on the basis of the EU-U.S. Data Privacy Framework or of standard contractual clauses. You can assert data subject rights (section 14) against us and against the respective operator; the right to object under Art. 21 GDPR applies here as well.
| Platform | Provider | Privacy policy | Arrangement under Art. 26 GDPR |
|---|---|---|---|
| LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland | Privacy policy | Page Insights Joint Controller Addendum | |
| X | X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland | Privacy policy | none |
| Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland | Privacy policy | Information about Page Insights | |
| YouTube | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Privacy policy | none |
| Substack | Substack Inc., 548 Market Street PMB 72296, San Francisco, CA 94104, USA | Privacy policy | none |
| Google Business Profile | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Privacy policy | none |
13. Use of AI systems
To optimise our processes, we may use artificial intelligence technologies when handling your enquiry, for example to prepare responses or to structure requests. The systems used operate in accordance with the principles of the GDPR. Decisions that have legal or similarly significant effects on you are not made solely by automated means; a human is always responsible for them.
14. Rights of the data subject
You have the following rights:
a) Information
Pursuant to Art. 15 GDPR, you have the right to request information about your personal data processed by us. This includes the processing purposes, the categories of personal data, the recipients, the planned storage period, the existence of a right to rectification, erasure, restriction or objection, the right to lodge a complaint, the origin of your data, and the existence of automated decision-making.
b) Rectification
Pursuant to Art. 16 GDPR, you have the right to the immediate rectification of incorrect or incomplete personal data.
c) Erasure
Pursuant to Art. 17 GDPR, you have the right to demand the immediate erasure of your personal data, insofar as further processing is not necessary, for example for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims.
d) Restriction of processing
Pursuant to Art. 18 GDPR, you can request the restriction of processing, for example where you contest the accuracy of the data, or where the processing is unlawful and you object to erasure.
e) Data portability
Pursuant to Art. 20 GDPR, you have the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, and to request the transmission of this data to a third party.
f) Withdrawal
Pursuant to Art. 7 para. 3 GDPR, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of the processing carried out until then.
g) Complaint
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
h) Objection
Insofar as your personal data is processed on the basis of legitimate interests pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing, insofar as there are grounds arising from your particular situation or the objection is directed against direct advertising. If you wish to exercise your right of withdrawal or objection, an email to info@go10x.ai is sufficient.
i) Automated decisions in individual cases
You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. No such automated decision-making takes place on our website.
15. Amendment of the privacy policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements or to reflect changes to our services. If we amend the privacy policy, this will be indicated on the website.
Last updated: 2026-08-19