Privacy Policy
This Privacy Policy explains how personal data is processed in connection with Cortee (the “Service”). Cortee is a service provided by Nándor Babina (Einzelunternehmen) with its place of business in Stuttgart, Germany (“we”, “us”, or “our”). Complete contact and identification details, including the correspondence address, are set out in the Imprint. Cookies are described in the Cookie Policy, and use of the Service is governed by the Terms of Service. Cortee is offered exclusively to Customers located in the United States, the United Kingdom, Switzerland, or a member state of the European Union, namely Austria, Belgium, Bulgaria, Croatia, Cyprus, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden. Where the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection (FADP) applies, this Privacy Policy is intended to meet the transparency requirements of those laws.
1. Who is responsible
1.1 Controller
We are the controller for personal data processed in connection with Cortee, except where Section 1.2 provides otherwise. We have not appointed a Data Protection Officer. Privacy requests may be submitted using the contact details in the Imprint.
1.2 Organizations and individuals
Where Cortee is used within an organization, that organization is the controller of notes and documents in its workspace, and we process that content on its behalf in order to provide the Service, under the Data Processing Agreement. Where a private individual subscribes for their own use, we are also the controller of the notes and documents in that account.
2. What we collect and why
We process the following categories of personal data for the purposes stated below. Most data is provided directly by you or by people the Customer invites. Account data for invitees may also come from the Customer’s administrators.
| Category | What we collect | Purpose |
|---|---|---|
| Account data | The organization's name. Clerk, Inc. holds the account, including the email address and sign-in. | To create and operate the Customer's account. |
| Workspace content | Pages you write: the title, the text, where the page sits, and its language and tone. Claims taken from a page, and embeddings of those claims, used to search them. Earlier versions of a page. Files you upload, with the file name, type, size, a short description, and the result of the malware scan. Each record stores the id and name of the person who created or edited it. | To provide the workspace. |
| Contact messages | What you write in a contact form or email to us, including your email address and the message. | To respond to enquiries sent via the contact form or email. |
| Audit and access logs | For each request: the IP address, the browser's user agent, the user id, the organization id, the time, the route, the method, the status, and the id of the page, version, or file. Request paths, headers, and related network metadata from use of the website and the application. | To secure and audit the Service, and to block abuse and keep it available. |
| Operational data | How long the language model takes, how many tokens it uses, and a hash of the organization id. The note and the page are left out. | To detect and address issues with the Service early. |
| Traffic and performance measurement | Anonymized information about page views, load times, and performance, without data that identifies a specific person. | To understand how the website is used and how quickly it loads, in anonymized form. |
| Payment data | Which plan is active, its price and status, the billing period, how much of the plan has been used, and the customer and subscription ids from Paddle. Card details stay with Paddle. | To take payment and determine which plan is active. |
Account, workspace, and payment data are processed to perform the contract to provide Cortee. Security, audit, operational, and traffic-measurement data are processed on the basis of our legitimate interest in a safe, reliable Service and in understanding how the website performs; you may object where the law allows. Contact messages are optional and are processed on legitimate interest in responding, or on consent if there is no prior customer relationship.
We do not use personal data for marketing. We do not use customer content to train models. We do not use personal data for solely automated decisions that produce legal or similarly significant effects on the data subject.
3. Who receives data
3.1 No sale of personal data
We do not sell personal data or workspace content, and we do not share it for advertising. Personal data is processed by the companies named below solely in order to provide Cortee.
3.2 Processors
The following companies process personal data on our behalf in order to provide Cortee. Where a row shows an effective or until date, that change takes effect on that date.
| Recipient | Categories of data | Location | Applies |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Workspace content, including pages, claims, files, and embeddings; the organization name; subscription and plan usage; audit and access logs; firewall and network data; and monitoring. | Europe | — |
| Marqo Inc. | Notes, pages, and files, to run the language model. | United States | Until 12 Oct 2026 |
| Clerk, Inc. | Account data and sign-in. | United States | — |
| Lyceum Technology Germany GmbH | Notes, pages, and files, to run the language model. | Europe | Effective 12 Oct 2026 |
| Melious AI GmbH | Notes, pages, and files, to run the language model. | Europe | Effective 12 Oct 2026 |
| Vercel Inc. | The website and the application, including pages, audit and access logs, firewall data, network data, and traffic and performance measurement. Data passes through its servers on the way to ours. | Europe | — |
Contact messages are handled through Google LLC as our email service provider. Google LLC is not listed above as a Cortee product processor for that purpose.
3.3 Merchant of record
Paddle Payments Ltd., established in Ireland, sells subscriptions to Cortee as merchant of record and processes payment data as an independent controller. Payment data is therefore collected by Paddle Payments Ltd. directly from the Customer at checkout, and may be processed in Ireland and in other countries in which Paddle Payments Ltd. processes payments, including the United States.
3.4 Where data is processed
Every Customer in the eligible territories uses the same processors and regions described above. Documents and related workspace records are stored in Europe. From 12 October 2026, authorization and language-model inference for the Service move to European providers listed in the table above and in the Trust center updates. Other supporting services may still involve providers outside Europe until we replace them. Where personal data is transferred to a third country, we rely on appropriate safeguards, such as an adequacy decision (including the EU–US Data Privacy Framework where it applies to a listed United States processor, and corresponding UK or Swiss mechanisms where they apply) or standard contractual clauses, where required.
4. How long we keep data
We retain account and workspace data for as long as the Customer’s organization uses Cortee. Thereafter we delete data we are not required to keep, as follows:
A page the Customer deletes, including its claims, versions, and files: seven (7) days after the page is deleted.
A claim that is retired while its page is still there: three hundred and sixty-five (365) days.
An upload that is started and not accepted: five (5) minutes.
After an organization is deleted: thirty (30) days for the remainder of its workspace and account data, and for plan usage.
After a subscription ends and the organization is still there: ninety (90) days for the remaining workspace data and for plan usage. The subscription record itself is kept, including after the organization is deleted.
Audit and access logs, including related network metadata: thirty (30) days after the request.
A note used to update a page is not saved. It is deleted immediately after it is used to update the page.
Model monitoring traces, meaning how long the language model takes, how many tokens it uses, and a hash of the organization id, without the note or the page: no deletion period is set. Langfuse GmbH in Europe receives those traces.
Contact messages: one (1) year after the customer’s request has been resolved, unless deleted earlier on the customer’s request, and longer only where the law requires it. Google LLC receives those messages as our email service provider.
Traffic and performance measurement: one (1) year after the measurement is recorded, unless the law requires a longer period.
We retain records for longer only where the law requires it, for example invoices and tax records. Paddle Payments Ltd. retains its own payment records as merchant of record. The export right described in the Terms of Service in the event of discontinuation of Cortee remains unaffected.
5. How we protect data
Workspace data is separated by organization. Every request runs with credentials scoped to that organization’s records, so that one organization cannot read another’s. Data is encrypted in transit and encrypted at rest with a customer managed key (CMK) held in our cloud account. That key is not issued one per customer. We keep audit logs of requests to production systems.
No service is perfectly secure. Where a personal-data breach affects your personal data, we will notify you and the competent authorities where the law requires it.
6. Your rights
You may request access to, rectification or erasure of, personal data, restriction of processing, data portability, and, where the law allows, the right to object. Where processing is based on consent, you may withdraw that consent at any time. We will respond within one month, or tell you if we need more time where the law allows. Requests may be submitted using the contact details in the Imprint. If we refuse a request, you may ask us to review that decision.
You may lodge a complaint with a data protection authority in the European Union where you live or work, with the UK Information Commissioner’s Office if you are in the United Kingdom, with the Swiss Federal Data Protection and Information Commissioner (FDPIC) if you are in Switzerland, or with the authority for our place of business: the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI). In the United States you may ask us what personal data we collect and to delete it. We do not sell personal data, so there is no sale to opt out of.
Where notes or documents sit in an organization workspace, please address the request to that organization first. We will assist the organization where the law requires.
7. Changes
We may amend this Privacy Policy, in which case the amended version supersedes all previous versions as of the effective date stated above. Where material changes are made, notice will be given to the extent required by law.