Legal

Privacy Policy

1. Who is responsible (controller)

For the hosted (SaaS) version of the service, the controller responsible for processing your personal data is:

If you have appointed or are required to appoint a data protection officer, add their contact details here: [DPO NAME AND CONTACT, IF APPLICABLE].

2. Self-hosted deployments

3. What data we collect

4. Why we process it and on what legal basis

We process personal data on the following legal bases under Article 6(1) GDPR:

5. AI processing

The AI co-facilitation features process the workshop content you submit to generate suggestions, summaries, and recommendations. This processing runs on Google Vertex AI (Gemini or Claude models served on Vertex) within an EU region. Your content is sent to Vertex AI only to produce the requested output. We do not send your data to any third-party AI API outside Google Cloud, and there is no data egress to external model providers.

6. Sub-processors

We use the following sub-processors to deliver the service. Each is bound by a data processing agreement and processes data only on our instructions.

Add or remove sub-processors here as your stack changes: [ADDITIONAL SUB-PROCESSORS, IF ANY].

7. International transfers

The service is hosted in the EU and we keep personal data inside the EU wherever the service permits it. Where a sub-processor (for example Stripe) may process limited data outside the EU or EEA, that transfer is covered by appropriate safeguards under Chapter V GDPR, such as the European Commission Standard Contractual Clauses. You can request details of these safeguards using the contact above.

8. How long we keep data

9. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, contact [CONTACT EMAIL]. We respond within one month. You also have the right to lodge a complaint with a supervisory authority, in Germany your competent state data protection authority: [SUPERVISORY AUTHORITY NAME AND CONTACT].

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and EU-region storage. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Changes to this policy

We may update this policy as the service or the law changes. We will post the new version here with an updated date, and notify you of material changes by email or in-app where appropriate.

12. Contact

Questions about this policy or your data: [CONTACT EMAIL].