Privacy Policy
How we handle your data on this website. The HYWOS application itself runs locally on your machine and does not send your documents anywhere.
Last updated: 20 July 2026
1. Controller
The controller responsible for data processing on this website is TROLUT UG (haftungsbeschränkt), Rosa-Luxemburg-Ring 10 B, 34253 Lohfelden, Germany — email {email}, phone +49 155 65268578. HYWOS is a product of TROLUT UG.
2. Website vs. application — the key point
There are two separate things. This website and account system handle your account, plan and billing. The HYWOS desktop application runs on your own computer: your documents, projects and questions are processed locally and stay on your machine. The AI model runs locally as well — we do not send your engineering documents or prompts to any external AI service or cloud. This policy describes the data we process through the website and account system.
3. What we collect
- Account data — when you register: your name (or company), email, phone, country, and optionally your company name.
- Enquiry data — when you use the contact or “Custom plan” form: the details you submit and your message.
- Licence & device data — when you activate the app on a computer: a device fingerprint, an optional device name, the platform (e.g. Windows), and a last-seen timestamp. This enforces the one-computer licence and lets the app confirm your plan is active.
- Payment data — processed by our payment provider (Stripe). We receive confirmation and invoice data (e.g. plan, amount, status), but we do not store your full card details.
- Essential cookies — see section 8.
- Server logs — our hosting provider processes standard technical data (e.g. IP address, timestamp, requested resource) to deliver and secure the site.
4. Why we process it (legal basis)
- To provide your account, licence and device activation — Art. 6(1)(b) GDPR (performance of a contract).
- To answer enquiries — Art. 6(1)(b)/(f) GDPR.
- To process payments and meet accounting/tax obligations — Art. 6(1)(b)/(c) GDPR.
- Essential cookies and secure operation of the site — Art. 6(1)(f) GDPR (legitimate interest in a working, secure service).
5. Processors and recipients
We only share data with providers who process it on our behalf under a data-processing agreement:
- Stripe — payment processing and subscription billing.
- Railway — hosting of the website and account backend.
We do not sell your data and do not use it for advertising or tracking.
6. International transfers
Some providers (e.g. Stripe) may process data outside the EU/EEA. Where that happens, the transfer is safeguarded by the EU Standard Contractual Clauses or an equivalent legal mechanism under Chapter V GDPR.
7. Retention
We keep account, licence and enquiry data for as long as your account exists. Invoices and billing records are retained for the periods required by German commercial and tax law (generally up to 10 years). After the applicable period we delete or anonymise the data.
8. Cookies
We use only essential cookies and local storage — no analytics, tracking or advertising cookies. Specifically: a session/authentication cookie to keep you signed in, and preferences such as your theme choice, your language and your cookie-banner decision. Because these are strictly necessary for the service, they do not require consent.
9. Data security
The website is served over encrypted connections (TLS/HTTPS) and passwords are stored only as salted hashes. We apply appropriate technical and organisational measures to protect your data.
10. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection. To exercise any right, contact {email}. You also have the right to lodge a complaint with a supervisory authority — for our seat this is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (Hesse, Germany).
11. Changes
We may update this policy. The current version, with its update date above, is always available on this page.