ASK SEISI
Privacy policy
Updated: 1 October 2026
1. Controller
Merktweg 10
1170 Wien
Österreich
Email: hello@askseisi.com
Commercial register number: FN 295169y
2. Accessing and technically operating the website
When you access ASK SEISI, technically necessary data may be processed. This may include, in particular, your IP address, access time, the page or file requested, browser and device information, referrer information and technical error or security data. This processing is necessary to deliver the website and to ensure stability, protection against misuse and security.
The legal basis is Article 6(1)(f) GDPR.
3. Contacting us
If you contact us by email at hello@askseisi.com or via the contact form, we process your name, email address, message and any information you voluntarily provide in order to handle and answer your request.
Requests submitted through the contact form are stored in the application's backend. To protect against automated misuse, a hash derived from the IP address is also used; the IP address itself is not stored as clear text in the contact record. After successful storage, a server-side email notification about the new request may be sent.
The legal basis is Article 6(1)(b) GDPR where the request is contractual or pre-contractual, and otherwise Article 6(1)(f) GDPR. Email infrastructure may be provided by World4You Internet Services GmbH, Austria.
4. Use of the ASK SEISI concierge
ASK SEISI can be used without a user account. To process a request, we may process, in particular, your chat messages, voluntarily entered travel preferences, information about destination, time, people or budget, selected recommendations, an anonymous session identifier and the previous conversation history.
The anonymous session identifier is used to technically associate related requests. It is stored in the browser only for the respective tab session. Conversation content is stored in the backend in sessions, conversations and messages so that the concierge can refer to previous context within a conversation.
Please do not enter special categories of personal data or other sensitive information unless this is necessary for your travel request. Depending on the use, the legal basis is Article 6(1)(b) and/or Article 6(1)(f) GDPR.
5. Saved full-day and half-day plans
If you expressly use the “Save plan” function, ASK SEISI stores a separate snapshot of the generated full-day or half-day plan. This may include the destination, date, schedule, selected places, publicly available place information and, where available, the weather information used when the plan was created.
The saved plan is provided through a randomly generated, unlisted link with a long access token. Anyone who has this link can open the plan. The link should therefore be treated like an access key and shared only with people who are allowed to view the plan. Saved plans currently do not require a login.
The published plan does not include, in particular, the chat history, session or conversation IDs, the exact private starting address or the original free-text input. The saved plan is technically separated from the chat and therefore remains accessible even if the underlying chat session is deleted later.
In addition, the browser on the respective device may maintain a local list of up to 20 recently saved or opened plans. This local list is device- and browser-specific and is not a user account. If local browser storage is deleted, the list disappears from that device; an existing plan link may still continue to work.
Standalone plan pages under /plan/ are not analysed by PostHog and are not recorded in Session Replay. The legal basis for storage and provision requested by the user is Article 6(1)(b) GDPR; Article 6(1)(f) GDPR may additionally apply for secure and stable operation.
My places
The “My places” feature stores up to 50 selected places on your device, including name, category, neighbourhood, visit duration and selection status. The list remains available after the browser is closed. For a requested full-day or half-day plan, the IDs of selected places are sent to the backend. No user account is required. You can remove entries individually or delete the browser storage.
6. Artificial intelligence / OpenAI
ASK SEISI uses OpenAI API services to generate concierge responses. Content entered by the user and the curated context required for the response are transmitted to OpenAI on the server side. Where applicable, OpenAI Ireland Limited may be responsible for customers in the European Economic Area.
The OpenAI API requests currently used are configured with store: false.
Limited live research
For specific factual questions about a curated place, the backend may send the question, place name and required response language to OpenAI with web search. The response and sources are stored temporarily in the research cache so that the same question does not need to be researched again. New entries store a hash of the complete question instead of the free-text question; existing older entries may still contain the original free text.
Depending on the type of fact, entries remain valid for 6 to 72 hours. Expired entries are no longer used and are deleted during the daily cleanup run after an additional 24-hour grace period. An expiry date alone does not replace deletion. The legal basis is processing the requested concierge query and efficient operation under Article 6(1)(b) and/or Article 6(1)(f) GDPR.
7. Technical infrastructure / Lovable Cloud / Supabase
ASK SEISI uses Lovable Cloud and Supabase-based infrastructure for hosting, the application, server-side functions and database services. In particular, application data required for the concierge, anonymous conversation data, contact requests and travel plans saved at the user's express request are processed there. Where required, processing takes place on the basis of applicable data processing agreements.
8. Google services
ASK SEISI uses the Google Places API on the server side to retrieve current place information where needed, such as business status, opening hours, ratings, map links and location data. Place or Place IDs and location information required for the respective request may in particular be transmitted to Google.
The website also loads fonts from fonts.googleapis.com and fonts.gstatic.com. When these fonts are loaded, your browser connects to Google. Technical connection data such as your IP address may be transmitted to Google.
Embedded maps and map services
When a place map is displayed, your browser loads a Google Maps embed. Full-day and half-day plan pages load OpenStreetMap tiles from tile.openstreetmap.org, and the Leaflet map library is loaded from unpkg.com. These services receive technical connection data such as IP address, browser information and the map areas requested. These connections occur when the map is displayed, including on a saved plan, and not only when an external map link is opened. Leaflet files are loaded with integrity checking.
9. Weather data / WeatherAPI
For full-day and half-day plans, ASK SEISI may retrieve weather forecasts from WeatherAPI.com. The request is made server-side using the destination coordinates stored in ASK SEISI and the required forecast period. Free-form chat text is not sent to WeatherAPI as a weather request.
Weather data is used to take planning information such as temperature, rain risk and suitable time windows for activities into account. Weather forecasts may change after a plan is created; a saved plan contains the information available at the time it was created.
10. Location information
The “Near me” feature can request the browser location only after you grant permission in the browser or on your device. The resulting coordinates may be transmitted to the ASK SEISI backend and used to select or calculate nearby recommendations and, where necessary, for supporting place and location services.
You can revoke location permission at any time in your browser or device settings. Where consent is required, the legal basis is Article 6(1)(a) GDPR.
11. External links, affiliate and partner offers
ASK SEISI may link to maps, websites, booking platforms or other services offered by external providers. When you open such a link, you leave ASK SEISI; the privacy policy of the respective third party applies to subsequent data processing.
Where implemented, ASK SEISI may internally record pseudonymous information about affiliate or partner clicks, such as recommendation, partner, time or session reference. Non-essential cookies or comparable tracking technologies are not activated without any prior consent that may be required.
12. Analytics and Session Replay / PostHog
Only if you expressly consent to analytics functions does ASK SEISI use PostHog Cloud in the EU region to understand usage, usability and the technical quality of the website and to further develop the product. PostHog is not initialised before consent.
Data processed may include page views and page changes, sessions, referrers, browser and device information, pseudonymous usage identifiers and selected, predefined product interactions such as opening the concierge, using quick prompts or actions on recommendations. Automatic click tracking is disabled in our current configuration.
Free-form chat text, email addresses, hotel or address details and precise location coordinates are not sent to PostHog as analytics properties. In addition, the application filters analytics properties with typical sensitive labels such as message, prompt, address, email or coordinates.
After consent, Session Replay may be used to understand usability issues through a technical reconstruction of the user interface. Form inputs are fully masked; chat messages and chat areas are additionally marked for text masking. Session Replay does not start before consent and is disabled on standalone saved-plan pages.
The legal basis is Article 6(1)(a) GDPR. You can change your decision at any time with effect for the future via If you reject or withdraw consent, no further analytics events are collected; an already initialised PostHog session is disabled for further collection and the local analytics identity is reset.
13. Cookies, Local Storage and Session Storage
ASK SEISI uses browser storage for functions that are necessary for the selected use or have been expressly enabled by the user. These currently include in particular:
- ask-seisi-language in Local Storage for a manually selected language; the entry is removed when “Automatic” is selected,
- ask-seisi-analytics-consent in Local Storage for your analytics decision,
- ask-seisi-saved-plans-v1 in Local Storage for the local list of recently saved or opened plans,
- ask-seisi-my-places-v1 in Local Storage for up to 50 saved places including their selection for planning, and
- ask-seisi-session in Session Storage as an anonymous identifier for the current browser-tab session.
After consent, PostHog also uses Local Storage for its pseudonymous analytics persistence. Non-essential analytics or marketing technologies are not activated before any required consent has been given.
14. Retention periods
Anonymous concierge sessions and the associated conversations and messages are currently deleted automatically in the backend when the session has been inactive for more than 90 days. Deletion runs regularly and covers the conversation data belonging to the session.
Contact requests are retained for as long as necessary for processing, evidence, misuse prevention or legal obligations and are then deleted or anonymised.
Travel plans saved at the user's express request are separate from the chat and currently have no automatic expiry period. A deletion request can be sent to hello@askseisi.com; because there is no user account, the relevant plan link may be required for unambiguous identification. Local plan lists and other browser settings remain on the respective device until overwritten or deleted by the user or browser.
PostHog analytics data is subject to the retention periods configured in the PostHog project in use. Statutory retention obligations remain unaffected.
15. Recipients
Depending on the function used, categories of recipients may include:
- hosting, cloud and database providers,
- AI service providers, in particular OpenAI,
- email service providers,
- Google and place-information services where used,
- WeatherAPI for weather forecasts,
- PostHog for analytics and Session Replay where consent has been given, and
- Google Maps, OpenStreetMap and unpkg when embedded maps are displayed, as well as external affiliate, booking or partner providers when their offers are opened.
16. Transfers to third countries
Some service providers or their subprocessors may process data outside the European Economic Area. Where legally required, appropriate safeguards such as adequacy decisions or standard contractual clauses are used. An EU data region has been selected for PostHog; this does not in every case exclude possible processing in third countries by providers or subprocessors.
17. Data subject rights
Subject to the statutory requirements, you have in particular the following rights:
- access,
- rectification,
- erasure,
- restriction of processing,
- data portability,
- objection, and
- withdrawal of consent with effect for the future.
To exercise your rights, contact us at hello@askseisi.com.
18. Right to lodge a complaint
You have the right to lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Wien, Österreich.
19. Changes to this privacy policy
This privacy policy is updated when functions, services, providers or legal requirements change. The version currently published on this website applies.