1. Controller and data protection officer
The controller for the processing of personal data in the innoGPT app is:
Inno KI GmbH
Osloer Str. 6, 49377 Vechta, Germany
Phone: +49 4441 8859759
Email: info@inno-ki.de
Commercial register: Local Court (Amtsgericht) Oldenburg, HRB 220654
Managing directors: Maurice Brumund, Mike Koene
You can reach our data protection officer at:
Carla Holterhus (Datenschutzheldin)
Mühlenbachstraße 16, 49808 Lingen, Germany
Email: datenschutz@inno-ki.de
Phone: +49 591 97784798
2. Scope
This Privacy Policy applies to the innoGPT app at app.innogpt.de, the innoGPT desktop app and the innoGPT API (together the "Service"). Our website innogpt.de has its own privacy policy.
Your role and our role. For your account, billing, security and the development of the Service, we are the controller within the meaning of Art. 4(7) GDPR.
If you use innoGPT through a workspace of your employer or another organisation, we process the content of that workspace (for example chats, files, assistants and knowledge bases) on behalf of that organisation. The organisation is then the controller and we are the processor under Art. 28 GDPR. This is based on a data processing agreement (DPA). Please send requests about this content to the organisation first.
3. Data we process
Account and profile data, for example name, email address, profile picture, language, login data (for sign-in with Microsoft, Google or single sign-on also the identifier of that account) and your settings.
Workspace data, for example the name of the organisation, memberships, roles, invitations and the settings that administrators make.
Content, that is everything you enter into or upload to the Service, and everything the Service generates from it: inputs (prompts), files, images, audio recordings, answers of the AI models, generated files and media, assistants, knowledge bases, notes, memories ("Memory"), workflows and scheduled tasks.
Integration data. If you connect a service such as Microsoft 365, Google Workspace, Dropbox or another integration, we process the access tokens (encrypted) and the data retrieved from that service for your specific request.
Meeting data. If you use the meeting assistant, we process the audio and video data, participant names and transcripts of the meeting and the summaries created from them.
Billing data, for example billing address, VAT ID, booked plan, invoices and payment status. Our payment provider Stripe collects card details and bank details directly. We do not store them.
Communication data, when you contact us, for example through support, by email or through the feedback portal.
Usage and device data, for example IP address, browser, operating system, timestamps, pages viewed, features and models used, token usage, error reports and technical logs.
Advertising attribution data. If you came to us through an ad and gave consent on our website, we carry campaign parameters and click identifiers (for example UTM parameters, gclid, fbclid) over into the app. Section 8 has the details.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the Service: account, sign-in, workspaces, chats, assistants, files, integrations, meeting assistant | Account, workspace, content, integration and meeting data | Art. 6(1)(b) GDPR (contract). For workspaces of organisations: processing on behalf under Art. 28 GDPR |
| Billing, invoicing, record-keeping obligations | Account and billing data | Art. 6(1)(b) and (c) GDPR (contract, legal obligation) |
| Support and communication with you, notices about the Service (for example security notices, changes) | Account and communication data | Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering requests) |
| Security, prevention of abuse and fraud, enforcement of usage limits, error analysis | Usage and device data, account identifiers | Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation), Art. 6(1)(c) GDPR |
| Improving the Service and product statistics | Usage and device data (no content) | Art. 6(1)(f) GDPR (legitimate interest in a working and improved product) |
| Attribution of advertising campaigns (conversion measurement) | Advertising attribution data, hashed email address, plan and amount | Art. 6(1)(a) GDPR, Section 25(1) TDDDG (consent) |
| Compliance with legal obligations and legal defence | All data required in each case | Art. 6(1)(c) and (f) GDPR |
No use of your content to train AI models. We do not use your content to train AI models. We use all AI providers under business or API contracts that exclude training on customer data.
No automated decision-making. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Automatic model selection ("Smart Select") only selects the technical model for a request.
5. Processing by AI models
When you send a request, we send your input, the attachments and the necessary conversation history to the selected AI model. The answer comes back to you and is stored in your workspace.
- Hosting location per model. The model picker shows for each model where it is processed. By default, automatic model selection prefers models processed in the EU.
- Models outside the EU. Some models are processed outside the EU. Administrators can switch these models off for their workspace.
- Redaction of personal data. On request, a service that we operate ourselves in Germany detects personal data and redacts it before the input goes to a model.
- Web search and tools. If a request uses web search, code execution, image or video generation or an integration, we send the necessary parts of the request to that service (see section 9).
- Marking. We mark AI-generated images, audio and video files in a machine-readable way as AI-generated.
AI answers can be wrong. Check important results before you rely on them.
6. Integrations and Google Workspace data
You connect integrations yourself. We access only the data you release in the provider's consent screen, and only to fulfil your specific request. You can disconnect any connection at any time in the settings under "Integrations". We store access tokens encrypted and delete them when you disconnect.
Google Workspace data (Google API Services User Data Policy). For Gmail, Google Calendar and Google Drive, we request only the permissions that the respective feature needs:
drive.readonly: read access to Google Drive, so that the assistant can find and open documents and answer with a source. innoGPT does not write, delete or share anything in Google Drive.gmail.modify: read, draft, send and label emails, each on your instruction. This permission does not allow permanent deletion of messages.calendar.eventsandcalendar.calendarlist.readonly: view, create, move and cancel events. innoGPT does not create, share or delete calendars.
We use data from Google APIs only to provide the features you use. We do not sell it, do not share it for advertising and do not build profiles from it. We do not use data from Google APIs, whether raw, aggregated or derived, to develop, train or improve generalised AI or foundation models.
innoGPT's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies and similar technologies
The Service stores information on your device (cookies, local storage) where this is strictly necessary for the Service (Section 25(2) no. 2 TDDDG). This includes:
- session and security cookies for sign-in (Clerk),
- your language, colour scheme and interface settings,
- settings of individual chats, for example which integrations are active in a chat.
For product statistics, we use PostHog (EU hosting) without automatic click capture and without session recording. For error analysis, Sentry records a small share of sessions and sessions with errors. In these recordings, all text and inputs are masked and all images are hidden.
8. Conversion measurement and partner programme
If you consented to marketing cookies on innogpt.de and came to us through an ad from Google or Meta, we store the click identifier when you subscribe to a paid plan. After the first successful payment, we report the subscription to Google Ads (Google Ireland Limited) or Meta (Meta Platforms Ireland Limited). We send the click identifier, the plan amount and, for Meta, your email address as a SHA-256 hash. The purpose is to measure the success of our advertising. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw your consent at any time with effect for the future, for example through the cookie settings on innogpt.de or by email to datenschutz@inno-ki.de.
Partner programme. If you came to us through a partner's link, Rewardful (Rewardful Inc., Canada) attributes a later subscription to that partner, so that we can pay the commission. For this, Rewardful stores an identifier of the partner link in a cookie.
9. Recipients and processors
We share personal data only if there is a legal basis. Our service providers process data as processors on our instructions and on the basis of a contract under Art. 28 GDPR.
| Task | Provider | Processing location |
|---|---|---|
| Hosting and running the application | Vercel Inc., USA | Frankfurt am Main (EU) |
| Database and file storage (hosting) | Supabase Pte. Ltd., Singapore (run on Amazon Web Services) | Frankfurt am Main (EU) |
| Backups (backup server) and redaction of personal data | Hetzner Online GmbH, Germany | Falkenstein (EU) |
| Sign-in and user management | Clerk Inc., USA | USA |
| Background tasks | API Hero Ltd (Trigger.dev), United Kingdom | Frankfurt am Main (EU) |
| Usage limits (rate limiting) | Upstash Inc., USA | Frankfurt am Main (EU) |
| Payment processing | Stripe Payments Europe, Limited, Ireland | EU |
| Error analysis | Functional Software Inc. (Sentry), USA | Frankfurt am Main (EU) |
| Product statistics | PostHog Inc., USA | Frankfurt am Main (EU) |
| Email delivery | Astrodon Inc., USA | USA |
| File processing | LlamaIndex Inc., USA | EU |
| AI models | Amazon Web Services EMEA SARL | EU |
| AI models | Google Ireland Limited, Ireland | EU |
| AI models | Microsoft Ireland Operations, Ltd., Ireland | EU (Sweden). "Global" models that you actively select: worldwide |
| AI models | Mistral AI, France | EU (France) |
| AI models | OpenAI Ireland Ltd, Ireland | EU |
| AI models | Perplexity AI, Inc., USA | USA |
| AI models (image generation) | Replicate, Inc., USA | USA |
| Web search | Exa Labs Inc., USA | USA |
| Retrieval of web pages | Sideguide Technologies Inc., USA | USA |
| Voice input and output | Eleven Labs Inc., USA | EU (Brussels) |
| Third-party integrations | Pipedream Inc., USA | USA |
| Feedback portal | Cordnet OÜ (Featurebase), Estonia | EU |
| Partner programme (affiliate) | Rewardful Inc., Canada | Canada |
This overview matches the list of sub-processors in Annex 4 of our data processing agreement. For some additional features that you activate yourself (for example the meeting assistant, code execution or learning videos), we use further specialised service providers. We name them on request.
If you connect an integration or a messenger yourself (for example Microsoft 365, Google Workspace, Slack, Telegram or WhatsApp), we exchange data with that provider. The provider's terms and privacy notices apply to the processing by that provider.
Data can also go to tax advisers, auditors and lawyers who are bound by professional secrecy, and to authorities where there is a legal obligation.
10. Transfers to third countries
Some service providers are based in the USA or process data there. We transfer data to third countries only if the requirements of Art. 44 et seq. GDPR are met. The basis is either an adequacy decision of the European Commission, for US providers in particular the EU-U.S. Data Privacy Framework (Art. 45 GDPR), or the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). Adequacy decisions exist for the United Kingdom and for Canada (commercial organisations). You can get a copy of the safeguards on request at datenschutz@inno-ki.de.
11. Retention
We store personal data only as long as it is necessary for the respective purpose.
- Content is stored until you or an administrator of your workspace deletes it. Administrators can set automatic deletion of chats for their workspace (30 to 365 days without activity). Without this setting, chats stay stored until they are deleted. We remove deleted content permanently from the database. We delete backups no later than 60 days after the end of the contract.
- Account data is stored as long as your account exists. After the account is deleted, we delete the related personal data within 30 days, unless there is a retention obligation.
- Billing data is kept as long as commercial and tax law requires (Section 257 HGB, Section 147 AO), usually up to ten years.
- Technical logs and error reports are stored only as long as we need them for operation, error analysis and security. Then we delete them.
12. Obligation to provide data
To use the Service, we need at least your email address and your login data. Without this data, we cannot set up an account. All other information is voluntary. Some features are then not available.
13. Your rights
Under the GDPR, you have the following rights:
- access to your data (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdrawal of consent with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR). If we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We then no longer process the data, unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. You can object to processing for direct marketing at any time without giving reasons.
You can view, change and delete much of your data yourself in the settings. For all other requests, write to datenschutz@inno-ki.de. We may ask for proof of your identity before we process a request.
14. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
lfd.niedersachsen.de
15. Security
We protect your data with technical and organisational measures under Art. 32 GDPR. Inno KI GmbH is certified under ISO 27001. The measures include:
- transport encryption with TLS 1.2 or higher and encryption of stored data with AES-256, including backups,
- access tokens and API keys stored encrypted,
- separated workspaces with access rules at database level and a role-based permission concept that follows the least-privilege principle,
- two-factor authentication for administrative access,
- backups at least daily and regular restore tests,
- logging of access, continuous monitoring and a procedure for security incidents,
- yearly external audits and penetration tests.
No system is completely secure. We improve our measures continuously. Business customers receive the full technical and organisational measures (TOMs) as an annex to the data processing agreement.
16. Minimum age
The Service is intended for people aged 18 and over. We do not knowingly collect data from children. If you believe that a child has sent us data, write to us. We then delete the data.
17. Changes to this Privacy Policy
We adapt this Privacy Policy when the Service or the law changes. The current version is always at app.innogpt.de/legal/privacy. We inform you about material changes in the app or by email.