Privacy policy

Last updated: September 2026

This English version is a translation for convenience. The German version is authoritative.

1. General information

This privacy policy explains how personal data is processed when using this website, the Coveniq AI platform and the associated support and platform functions. Coveniq AI is an AI platform that supports organizations in their use of AI functions. Part of the platform is a Privacy Guard, which analyses inputs before any possible transfer to connected AI models and replaces detected personal data with neutral placeholders.

This policy distinguishes three situations:

  • A: Visiting this website (without registration)
  • B: Registration and use of Coveniq AI
  • C: Requesting a demo through the form on this website

The subsequent sections (Privacy Guard, service providers, retention periods, data subject rights and others) apply across all situations to the use of the platform.

2. Controller and allocation of roles

The controller within the meaning of the GDPR for the operation of the website, the provision of the platform, user administration, support, contract handling and system security is:

AITAS UG (haftungsbeschränkt)
Brombergstraße 8
79102 Freiburg
Deutschland

Email: info@aitas.org

Where users access Coveniq AI through their organization, that organization is generally responsible for the content entered, uploaded or processed by it or by its users. In that respect AITAS processes this content data as a processor on the instructions of the organization, on the basis of a data processing agreement. The details are governed by the data processing agreement (DPA), available under Legal documents. For data protection questions, users may contact their organization or the data protection contact named above.

3. The three usage situations

Which data is processed, for which purposes and on which legal basis, depends on which of the following situations applies to you.

A

Visiting this website

Applies to all visitors to this website, without registration and without use of the Coveniq AI platform.

Data processed

  • Technical access data (IP address, date and time of access, page requested, referrer URL)
  • Browser and device information, operating system

Purposes

  • Delivery and secure presentation of the website
  • Ensuring stability, availability and IT security

Legal bases

  • Art. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website)

Particulars

No AI processing takes place. We do not use tracking cookies, advertising networks or third-party analytics services. Access data is stored for a maximum of seven days and then deleted automatically; it is not passed on to third parties. The demo request form is loaded only after a click on "Request a demo"; until then no connection to the form provider is established (see situation C).

B

Registration and use of Coveniq AI

Applies to the use of Coveniq AI under a contractual or usage relationship, whether through an organization or directly.

Data processed

  • Account and master data (name, business email address, organization, role, permissions, login information)
  • Usage and log data (functions used, technical events, session and security logs)
  • Content data (prompts, chat histories, uploaded documents, AI responses)
  • Privacy Guard data (detected personal data, placeholders, mapping information)
  • Support and feedback submissions
  • Contract and billing data under the usage relationship

Purposes

  • Provision, operation and protection of the platform
  • Administration of user accounts, roles and permissions
  • Processing of prompts and content to generate AI responses
  • Detection and pseudonymisation of personal data by the Privacy Guard
  • Contract handling, billing and compliance with legal obligations
  • IT security, support, prevention of misuse and further development

Legal bases

  • Art. 6(1)(b) GDPR (performance of a contract / usage relationship)
  • Art. 6(1)(f) GDPR (legitimate interests, in particular IT security, error analysis and improvement of the platform)
  • Art. 6(1)(c) GDPR (statutory retention obligations)
  • Art. 6(1)(a) GDPR (consent, where required, for example for voluntary feedback and optional functions)

AI providers in use

OpenAIAnthropic

Named as a precaution, not currently in use

Perplexity AIGamma AIMistral AIAI models via AWS Bedrock

Particulars

Only OpenAI and Anthropic are currently in use. The providers named as a precaution are contractually prepared but not enabled; before any of them is enabled, the relevant provider agreements, processing locations and third-country safeguards are reviewed and this policy is updated. Where Coveniq AI is used through an organization, that organization is responsible for the content data entered; AITAS processes it as a processor on instructions, on the basis of a data processing agreement. A current overview of sub-processors is provided as part of the contract documents or on legitimate request.

C

Requesting a demo through the form on this website

Applies if you select "Request a demo" on this website and complete the form that then opens in a window above the page.

Data processed

  • Your entries in the form (name, business email address, organization, type of organization, role, expected number of users)
  • Voluntary entries (areas of interest, use case, time frame, telephone number)
  • Origin information passed by the website to the form (page visited, page language, point of click, campaign parameters where contained in the address)
  • Technical connection data arising at the form provider when the form is opened (IP address, browser and device information), and the time of submission

Purposes

  • Handling and answering the request
  • Preparing and holding the requested demonstration appointment
  • Initiating a contractual relationship as well as recording and attributing the request

Legal bases

  • Art. 6(1)(b) GDPR (pre-contractual measures taken at your request)
  • Art. 6(1)(f) GDPR (legitimate interest in handling, attributing and documenting requests)

Particulars

The form is provided by Tally BV, Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium, as a processor. It is loaded only when you click the "Request a demo" button; merely visiting this website establishes no connection to Tally. According to the provider, form data is transmitted in encrypted form and stored in Europe; Google Cloud in Belgium is used as the hosting provider. Notification of an incoming request is sent by Tally via the service provider SendGrid (USA), safeguarded by EU standard contractual clauses. Name, business email address, organization, type of organization, role and the expected number of users are mandatory; without them the request cannot be handled. All other fields are voluntary. No AI processing of the request takes place.

4. Privacy Guard

The Privacy Guard is a technical protective measure within Coveniq AI. Inputs are analysed before any possible transfer to connected AI models; detected personal data can be replaced with neutral placeholders. The AI model's response can then be reunited with the original values within the platform, to the extent required for display.

The mapping between original values and placeholders remains within the Coveniq and Privacy Guard infrastructure provided for that purpose. Original values and the re-identification mapping are not transmitted to external AI model providers, unless expressly agreed otherwise or technically necessary and separately released.

The Privacy Guard reduces the risk of personal data being disclosed. Complete detection of all personal, sensitive or confidential information cannot, however, be technically guaranteed. Users and organizations remain responsible for avoiding the entry of sensitive or unreleased data, or for regulating it organizationally.

5. No training and no retention at the model providers

AITAS does not use personal data, prompts, documents or other content of the using organizations to train its own or third-party AI models, unless expressly agreed separately.

Zero data retention applies to the model providers in use, OpenAI and Anthropic: content transmitted is not stored there after the request has been answered and is not used to train the providers' models. The commitment is contractually secured and technically configured. Before any further provider is enabled, it is reviewed whether an equivalent commitment exists; otherwise no provider is enabled without a separate agreement with the customer.

6. Hosting, infrastructure and service providers

Coveniq AI is operated through separate but functionally interacting infrastructure components. Data processing agreements pursuant to Art. 28 GDPR, or comparable data protection agreements, are in place with the service providers used:

Vercel Inc.

Hosting of the Coveniq AI frontend and of the technical application component of the Privacy Guard. Under the current configuration in the EU, at the Frankfurt location. Separate instances exist for Coveniq AI and for the Privacy Guard.

Supabase Inc.

Database hosting and authentication. Separate databases for Coveniq AI and the Privacy Guard, under the current configuration in the EU, at the Frankfurt location. The Privacy Guard database serves in particular the administration of placeholders and their restoration.

Tally BV

Provision and operation of the demo request form on this website. Registered office: Sint-Pietersnieuwstraat 11, 9000 Ghent, Belgium. According to the provider, form data is transmitted in encrypted form and stored in Europe; Google Cloud in Belgium is used as the hosting provider, and SendGrid (USA) for notification emails. For transfers outside the EEA, the EU standard contractual clauses under Implementing Decision (EU) 2021/914 apply. The data processing agreement pursuant to Art. 28 GDPR is part of Tally's terms of service.

AI model and API providers

Requests to external AI models are made exclusively with pseudonymised content after processing by the Privacy Guard. OpenAI and Anthropic are in use; zero data retention applies to both. Named as a precaution but not enabled are Perplexity AI, Gamma AI, Mistral AI and AI models via AWS Bedrock. Original personal data and the re-identification mapping are not transmitted to these providers.

A complete, current overview of sub-processors including services, processing locations and third-country safeguards can be found in the sub-processor annex under Legal documents.

7. Recipients and third-country transfers

Where necessary, personal data may be disclosed to authorised internal persons (operations, support, security), hosting, database and infrastructure service providers, AI model providers, and authorities or advisers, where a legal obligation exists or this is required to enforce legal claims. Data is passed on only where there is a legal basis for doing so or the processing is safeguarded as processing on instructions.

Where service providers outside the EU/EEA are used, or access from a third country cannot be ruled out, this takes place only in accordance with data protection requirements, in particular on the basis of an adequacy decision or EU standard contractual clauses together with additional safeguards. With connected AI model providers, a third-country transfer may be possible depending on the provider, region and configuration.

8. Retention and deletion

Personal data is stored only for as long as is necessary for the purposes stated or as statutory retention obligations require:

  • Account and permission data: for the duration of the usage entitlement or contractual relationship, then deletion or blocking.
  • Chat, prompt, document and content data: in accordance with the platform configuration and the user or organization settings.
  • Technical logs and security records: as a rule up to 30 days, unless a different period is required.
  • Contract and billing data: in accordance with statutory retention periods (for example up to ten years under commercial and tax law).
  • Demo requests through the form on this website: until the request and the ensuing correspondence have been concluded, then deletion in the form service, unless statutory retention obligations require otherwise.

9. Cookies and local storage

This website and the Coveniq AI platform use technically necessary cookies or comparable technologies, to the extent required for login, session management, security, language settings or platform operation. On the website itself, no tracking, analytics or marketing technologies are used. Should non-essential cookies be used, this takes place only on an appropriate legal basis, in particular with consent where legally required. The demo request window is delivered by the form provider and may set technically necessary cookies or comparable storage access of that provider; it is loaded exclusively after a click on "Request a demo", that is, at your instigation.

10. Special categories of data and automated decisions

The entry of special categories of personal data within the meaning of Art. 9 GDPR (for example health data, religious or political information) is permissible only where the using organization has provided an appropriate legal basis, an express release and adequate safeguards.

Coveniq AI serves to support the processing of information. Decisions about persons that are legally binding or similarly significantly affect them should not be taken solely on an automated basis using Coveniq AI, unless an express legal basis, release and human review are provided for.

11. Data subject rights

Subject to the statutory requirements, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to withdraw consent with effect for the future
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

Where processing takes place on behalf of an organization, it may be necessary to forward data subject requests to that organization. To exercise your rights, please contact: info@aitas.org

12. Security of processing

AITAS applies technical and organizational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. These include in particular transport encryption, access restrictions, role and permission concepts, the separation of instances, logging of security-relevant events, backup and recovery measures, and the Privacy Guard as an additional protective measure.

13. External links

Our website may contain links to external third-party websites. We have no influence over their content and accept no liability for it. The respective provider is always responsible for the content of linked pages.

14. Changes to this privacy policy

AITAS may adapt this privacy policy if technical, legal or organizational conditions change, for example when a further model provider is enabled or when processing locations change. Registered users are informed of material changes. The current version published on this page applies in each case.