Privacy Policy
This Privacy Policy explains how personal data is processed in connection with Cortee.ai (the “Service”). Cortee.ai is a service provided by Nándor Babina (Einzelunternehmen) with its place of business in Stuttgart, Germany (“we”, “us”, or “our”). Complete contact and identification details, including the correspondence address, are set out in the Imprint. Cookies are described in the Cookie Policy, and use of the Service is governed by the Terms of Service. Cortee.ai is offered exclusively to Customers located in the United States, the United Kingdom, Switzerland, or a member state of the European Union, namely Austria, Belgium, Bulgaria, Croatia, Cyprus, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden. Where the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection (FADP) applies, this Privacy Policy is intended to meet the transparency requirements of those laws.
1. Who is responsible
1.1 Controller
We are the controller for personal data processed in connection with Cortee.ai, except where Section 1.2 provides otherwise. We have not appointed a Data Protection Officer. Privacy requests may be submitted using the contact details in the Imprint.
1.2 Organizations and individuals
Where Cortee.ai is used within an organization, that organization is the controller of notes and documents in its workspace, and we process that content on its behalf in order to provide the Service, under the Data Processing Agreement. Where a private individual subscribes for their own use, we are also the controller of the notes and documents in that account.
2. What we collect and why
We process the following categories of personal data for the purposes stated below. Most data is provided directly by you or by people the Customer invites. Account data for invitees may also come from the Customer’s administrators.
| Category | Purpose |
|---|---|
| Account data | To create and operate the Customer’s account |
| Workspace content | To provide the workspace |
| Contact messages | To respond to enquiries sent via the contact form or email |
| Audit and access logs | To secure and audit the Service |
| Network data | To block abuse and keep the Service available |
| Operational data | To detect and address issues with the Service early |
| Traffic and performance measurement | To understand how the website is used and how quickly it loads, in anonymized form |
| Payment data | To take payment and determine which plan is active |
Account, workspace, and payment data are needed to perform the contract to provide Cortee.ai. Without them we cannot create an account, run the workspace, or take payment. Contact messages are optional; if you do not send them, we simply cannot reply to that enquiry.
The legal basis for processing account, workspace, and payment data is the performance of that contract.
For security, audit, network, and operational data we rely on our legitimate interest in operating a safe and reliable Service; you may object to processing based on legitimate interests where the law allows.
For traffic and performance measurement we rely on our legitimate interest in understanding how the website is used and how well it performs; that measurement is anonymized so that we cannot tell who a visitor is.
Contact messages are processed on the basis of our legitimate interest in responding to enquiries, or on consent where you contact us without a prior customer relationship.
We do not use personal data for marketing. We do not use customer content to train models. We do not use personal data for solely automated decisions that produce legal or similarly significant effects on the data subject.
3. Who receives data
3.1 No sale of personal data
We do not sell personal data or workspace content, and we do not share it for advertising. Personal data is processed by the companies named below solely in order to provide Cortee.ai.
3.2 Processors
The following companies process personal data on our behalf in order to provide Cortee.ai.
| Recipient | Categories of data | Location |
|---|---|---|
| Clerk, Inc. | Account data | United States |
| Amazon Web Services EMEA SARL | Account data, workspace content, audit and access logs, network data, and operational data | Ireland |
| Marqo Inc. | Workspace content | United States |
| Vercel Inc. | Traffic and performance measurement, contact messages | United States |
| GitHub, Inc. | Contact messages | United States |
3.3 Merchant of record
Paddle Payments Ltd., established in Ireland, sells subscriptions to Cortee.ai as merchant of record and processes payment data as an independent controller. Payment data is therefore collected by Paddle Payments Ltd. directly from the Customer at checkout, and may be processed in Ireland and in other countries in which Paddle Payments Ltd. processes payments, including the United States.
3.4 No data residency
Unless otherwise agreed in a separate written agreement between the Customer and us, we do not confine EU, UK, or Swiss data to those regions, or United States data to the United States. There is no regional split: every Customer in the eligible territories uses the same processors and regions described above. Where personal data is transferred to a third country, we rely on appropriate safeguards, such as an adequacy decision (including the EU–US Data Privacy Framework for Clerk, Inc., and corresponding UK or Swiss mechanisms where they apply) or standard contractual clauses, where required.
4. How long we keep data
We retain account and workspace data for as long as the Customer’s organization uses Cortee.ai. Thereafter we delete data we are not required to keep, as follows:
- Documents deleted by the Customer, and the claims belonging to them: seven (7) days after the document is deleted.
- After an organization is deleted: thirty (30) days for the remainder of its workspace and account data.
- After a subscription ends without the organization being deleted: ninety (90) days.
- Audit and access logs: ninety (90) days.
- Contact messages: as long as needed to handle the enquiry, then deleted unless a longer retention is required by law.
We retain records for longer only where the law requires it, for example invoices and tax records. Paddle Payments Ltd. retains its own payment records as merchant of record. The export right described in the Terms of Service in the event of discontinuation of Cortee.ai remains unaffected.
5. How we protect data
Workspace data is separated by organization. Every request runs with credentials scoped to that organization’s records, so that one organization cannot read another’s. Data is encrypted in transit and encrypted at rest by our cloud provider. We keep audit logs of requests to production systems.
No service is perfectly secure. Where a personal-data breach affects your personal data, we will notify you and the competent authorities where the law requires it.
6. Your rights
You may request access to, rectification or erasure of, personal data, restriction of processing, data portability, and, where the law allows, the right to object. Where processing is based on consent, you may withdraw that consent at any time. We will respond within one month, or tell you if we need more time where the law allows. Requests may be submitted using the contact details in the Imprint. If we refuse a request, you may ask us to review that decision.
You may lodge a complaint with a data protection authority in the European Union where you live or work, with the UK Information Commissioner’s Office if you are in the United Kingdom, with the Swiss Federal Data Protection and Information Commissioner (FDPIC) if you are in Switzerland, or with the authority for our place of business: the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI). In the United States you may ask us what personal data we collect and to delete it. We do not sell personal data, so there is no sale to opt out of.
Where notes or documents sit in an organization workspace, please address the request to that organization first. We will assist the organization where the law requires.
7. Changes
We may amend this Privacy Policy, in which case the amended version supersedes all previous versions as of the effective date stated above. Where material changes are made, notice will be given to the extent required by law.