Data protection

Privacy Policy

Pursuant to Art. 13 / 14 GDPR · Version: July 2026

No tracking cookies

No cookie banner required.

Stored in the EU

Ideas are stored encrypted in Frankfurt (EU Central); the AI analysis runs at Anthropic (USA) under EU standard contractual clauses.

No AI training

Anthropic does not use your ideas for model training; inputs and outputs are deleted there within 30 days.

1

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:

Stefan Schmechel
Walter-Klausch-Straße 1b
14482 Potsdam
Germany

Email: info@ideontics.com
Data protection: datenschutz@ideontics.com

2

Processing principles

Ideontics is designed to operate with a minimum of personal data. No user accounts are created and no tracking cookies are set. Submitted ideas are stored encrypted in the EU in order to provide your assessment and are automatically deleted 12 months after creation. For the AI analysis they are transferred to Anthropic (USA) under EU standard contractual clauses, are not used there for model training, and are deleted within 30 days.

Personal data is collected only where technically necessary to provide the service or required by law. Processing is always based on one of the legal bases set out in Art. 6 GDPR.

3

Data collected when the site is accessed (server logs)

Each time the platform is accessed, the hosting provider (Vercel) automatically records technical access data in so-called server log files. These contain:

  • IP address (anonymised by Vercel)

  • Date and time of access

  • URL requested and HTTP method

  • Volume of data transferred and HTTP status code

  • Browser type and version (user agent)

  • Referrer URL (where applicable)

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in system security and error analysis). Retention period: In its default configuration Vercel stores logs for 24 hours. No attribution to individual persons is intended.

4

Processing of submitted ideas (AI analysis)

To produce the assessment, the texts entered by the user (ideas, descriptions, answers to follow-up questions) are transmitted to the Anthropic API (USA).

Data transmitted

Texts entered by the user. There is no obligation to provide personal data.

Legal basis

Art. 6 (1) (b) GDPR (performance of a contract). The transfer is technically indispensable in order to deliver the service.

Retention and training

Anthropic processes the data to generate the response and does not use it for model training (Commercial Terms). Inputs and outputs are deleted at Anthropic within 30 days by default.

Server location and transfer

The idea is stored encrypted in the EU (Supabase, Frankfurt, AWS eu-central-1). The AI processing by Anthropic takes place in the USA; the transfer is based on EU standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR.

Anthropic PBC

Purpose

Generation of the assessment by AI language models, technically indispensable for performance of the contract.

Data processed

The texts entered by the user (ideas, descriptions, answers to follow-up questions). No user accounts, no email addresses, no payment data.

Legal basis

Art. 6 (1) (b) GDPR (performance of a contract)

Transfer to third countries

Anthropic processes the content in the USA. Legal basis: EU standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR. The content is not used for model training; inputs and outputs are deleted within 30 days.

Provider's privacy policy →

Recommendation: Users should not include particularly sensitive data (names of real persons, health data, third-party trade secrets and the like) in the description of their idea.

5

Email communication (assessment link)

After a successful payment the user receives an email containing the direct link to their assessment. This email is sent automatically as soon as the payment has been confirmed by Stripe.

Data processed

Email address (supplied by Stripe Checkout), title of the submitted idea (for the subject line), assessment URL.

Source of the email address

Stripe collects the email address during the payment process for the payment receipt. Once payment is confirmed it is passed to Ideontics and used exclusively to send the assessment link.

Legal basis

Art. 6 (1) (b) GDPR (performance of a contract). Sending the assessment link is technically necessary to deliver the service paid for.

Retention period

Where the email address forms part of an accounting record it is deleted after the statutory retention period (8 years for accounting vouchers, Section 147 of the German Fiscal Code); otherwise together with the assessment after 12 months.

No newsletter, no marketing

The email address is used solely for the one-off delivery of the assessment link. No advertising or newsletter emails are sent.

The service provider Resend is used to send these emails (see section 7).

6

Payment processing (Stripe)

Payments are processed exclusively via Stripe, Inc. Ideontics never stores card details or other sensitive payment information.

Stripe, Inc.

Purpose

Secure payment processing, technically necessary for performance of the contract.

Data processed

Payment data (card, IBAN and similar), IP address, browser information, transaction data. Ideontics receives only the email address and a confirmation that the payment succeeded.

Legal basis

Art. 6 (1) (b) GDPR (performance of a contract) · Art. 6 (1) (c) GDPR (statutory retention obligation)

Transfer to third countries

Stripe processes some data in the USA. Legal basis: EU standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR.

Provider's privacy policy →
7

Hosting and infrastructure (Vercel, Supabase, Resend)

The following infrastructure providers are used to operate the platform. A data processing agreement pursuant to Art. 28 GDPR has been concluded with each of them:

Vercel Inc.

Purpose

Provision of the web infrastructure, CDN and TLS termination.

Data processed

IP addresses (anonymised), HTTP requests, response times.

Legal basis

Art. 6 (1) (f) GDPR (legitimate interest in reliable operation)

Transfer to third countries

Vercel handles requests globally via CDN nodes. Edge requests may pass through servers outside the EU; compute functions run in eu-central-1 (Frankfurt).

Provider's privacy policy →

Supabase, Inc.

Purpose

Database and authentication infrastructure. Stores assessments, payment records and consent records.

Data processed

Submitted ideas (title, description), email address (where supplied via Stripe), payment status, consent timestamps (acceptance of the privacy policy and terms).

Legal basis

Art. 6 (1) (b) GDPR (performance of a contract) · Art. 6 (1) (c) GDPR (statutory retention obligation)

Transfer to third countries

Supabase runs the database on AWS eu-central-1 (Frankfurt). No data transfer outside the EU.

Provider's privacy policy →

Resend, Inc.

Purpose

Transactional email delivery, used solely to send the assessment link after a successful payment.

Data processed

Recipient's email address, subject line (contains the idea title), assessment URL.

Legal basis

Art. 6 (1) (b) GDPR (performance of a contract)

Transfer to third countries

Delivery is handled in the EU region Ireland (eu-west-1). Resend, Inc. is based in the USA and, as the operator, retains the ability to access the data; the transfer therefore continues to rely on EU standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR.

Provider's privacy policy →
8

Website analytics (Vercel Web Analytics)

Ideontics uses Vercel Web Analytics to see how often individual pages are viewed and how visitors arrive at the website. The tool works without cookies and does not recognise individual people beyond a single visit.

Vercel Web Analytics (Vercel Inc., USA)

Purpose

Evaluation of page views, referrer sources and approximate region, in order to improve the content and structure of the website.

Data processed

Page viewed, referring page, country or region, device type, browser and operating system. No cookies, no advertising identifiers, no cross-device profile. To count repeat views within a single day, Vercel derives a non-reversible hash from the IP address and browser identifier; the IP address itself is not stored for this purpose, and the hash changes daily.

Legal basis

Art. 6 (1) (f) GDPR (legitimate interest in improving the service). As no information is stored on or read from the device, Section 25 TDDDG does not apply and no consent is required.

Transfer to third countries

Vercel Inc. is based in the USA. The transfer relies on EU standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR — the same basis as for hosting, see section 7.

Vercel's privacy policy →

Because no cookies are set and no personal profiles are created, no cookie banner and no active consent are required.

9

Cookies

Ideontics only sets strictly necessary cookies that are required to operate the service (for example the session token for the Stripe payment process). No tracking, marketing or analytics cookies are set.

Strictly necessary cookies are exempt from consent under Section 25 (2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). A cookie banner is therefore not required.

You can disable the storage of cookies in your browser settings. Doing so may, however, impair the payment process.

10

Retention periods

We store personal data only for as long as is necessary for the respective processing purpose or as required by statutory retention periods.

Submitted ideas (title, description)

Stored encrypted in the EU (Supabase, Frankfurt); automatically deleted 12 months after creation. Deletion on request is possible at any time.

Email address

Where it forms part of an accounting record: 8 years pursuant to Section 147 of the German Fiscal Code (period starting at the end of the calendar year of payment); deleted thereafter.

Payment records (Stripe session ID, amount)

8 years pursuant to Section 147 of the German Fiscal Code (accounting vouchers, since 1 January 2025; previously 10 years).

Consent record (privacy policy and terms accepted)

At least 3 years from the date of consent (GDPR duty of proof, Art. 7 (1)).

Server log files (Vercel)

24 hours (Vercel default configuration).

AI processing (Anthropic API, USA, SCCs)

No training on the data; deleted at Anthropic within 30 days (the API's standard retention).

11

Your rights as a data subject

Under the GDPR you have the following rights, which you may assert against the controller at any time:

Access (Art. 15 GDPR)

You have the right to know whether and which personal data we process about you.

Rectification (Art. 16 GDPR)

You may request that inaccurate data be corrected or incomplete data completed.

Erasure (Art. 17 GDPR)

You may request erasure of your personal data unless statutory retention obligations prevent it.

Restriction (Art. 18 GDPR)

You may request that processing be restricted if you contest the accuracy of the data or the processing is unlawful.

Data portability (Art. 20 GDPR)

You may receive your data in a structured, commonly used and machine-readable format.

Objection (Art. 21 GDPR)

You may object to processing of your data where it is based on legitimate interest (Art. 6 (1) (f)).

Withdrawal of consent (Art. 7 (3) GDPR)

Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with the competent supervisory authority. For Brandenburg this is the LDA Brandenburg (www.lda.brandenburg.de).

To exercise your rights, please contact us by email at: datenschutz@ideontics.com

Special notice on the right to object (Art. 21 GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data carried out on the basis of Art. 6 (1) (f) GDPR (legitimate interest), for example the processing of server log files.

If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.

Important distinction: The right to object does not apply to processing that is strictly necessary for the performance of the contract (Art. 6 (1) (b) GDPR), in particular the processing of your idea for the assessment and the delivery of the assessment link.

12

Data security

All data is transmitted exclusively in encrypted form via HTTPS/TLS. The platform uses current security standards to protect data against unauthorised access.

Payment data is never stored on our own servers; it is processed exclusively via Stripe's PCI DSS certified infrastructure.

13

Validity and amendments to this privacy policy

This privacy policy is currently valid and dated March 2025. Further development of the platform or changes in legal requirements may make it necessary to amend this policy. The current version is always available at ideontics.com/en/privacy (German version: ideontics.com/datenschutz).

Version: September 2026 · This privacy policy is based on the GDPR and on German data protection law (TDDDG, DDG).

This English version is a translation of the German policy at ideontics.com/datenschutz. Both describe the same processing operations.