Privacy Policy
Last updated: August 2026
Robotic Automation Solutions UG (haftungsbeschränkt)
Schellingstr. 109a
80798 München, Germany
Email: datenschutz@ras.solutions
Ejra is a business (B2B) platform for AI-powered phone and chat communication. For the operation of this website and the customer portal, and for our customers' contract, account and billing data, Robotic Automation Solutions UG (haftungsbeschränkt) is the controller within the meaning of the GDPR.
Where our customers use Ejra to process personal data of their own end customers (e.g. call data, transcripts, chat histories, appointment bookings), the respective customer is the controller; we process such data exclusively as a processor pursuant to Art. 28 GDPR on the basis of a data processing agreement (DPA). We provide a DPA to every customer — please contact datenschutz@ras.solutions.
When you access our website and portal, our server automatically processes technical access data (IP address, date and time, page accessed, browser type and operating system). This data is required for secure and stable operation and is not combined with other data sources. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest). Log data is deleted as soon as it is no longer required for this purpose.
We only use technically necessary cookies — no marketing or tracking cookies.
Storing and reading these cookies is permitted under Sec. 25 (2) of the German TDDDG, as they are strictly necessary for the service you use; the associated data processing is based on Art. 6 (1) (b) and (f) GDPR.
When you register for and use a customer account, we process master and contact data (name, business email address, company details, roles and permissions), security data (e.g. password hash, multi-factor settings, passkeys) as well as billing and usage data. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR for statutory retention obligations.
If you contact us via the contact form, we process your details (name, email address, message) to handle your enquiry (Art. 6 (1) (b) or (f) GDPR). To protect against automated abuse, we use a bot-protection service operated by an external provider; it checks technical characteristics of your browser without performing advertising tracking. Your message is delivered to us via a cloud service provider.
In operating the platform — depending on the configuration chosen by the respective customer — the following data in particular is processed: phone numbers and connection data, audio data during calls, transcripts, chat histories, appointment and enquiry data, as well as log and quality data. This processing is carried out on behalf of and under the instructions of our customer (Art. 28 GDPR); the controller is the customer whose phone or chat service you use. For information about a specific call or chat, please first contact the respective company.
To deliver our services, we use carefully selected service providers in the following areas:
Data processing agreements pursuant to Art. 28 GDPR are in place with all service providers. We provide customers with an up-to-date list of sub-processors on request.
Some of our service providers process data (also) in third countries, in particular in the USA. Transfers are based on an adequacy decision (EU-U.S. Data Privacy Framework) or on the EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR, supplemented by technical safeguards such as transport encryption.
We store personal data only for as long as necessary for the purposes described. For platform content data, the respective customer, as controller, sets the retention period in its organisation settings. In detail:
Once the period has elapsed, or after deletion by the customer, the data is removed from the database or anonymised. Where statutory retention obligations prevent deletion, processing is restricted instead (Art. 18 GDPR).
You have the right, vis-à-vis the respective controller, to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You may object to processing based on Art. 6 (1) (f) GDPR pursuant to Art. 21 GDPR; you may withdraw any consent you have given at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — the authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach, Germany.
We protect your data with state-of-the-art measures, in particular transport encryption (TLS), encryption of stored credentials and secrets, role-based access controls, tenant isolation and logging of security-relevant events.
We update this privacy policy when our services or the legal situation change. The version published here applies.
For privacy enquiries, you can reach us at: datenschutz@ras.solutions