1. Controller
Vincent SchmittOperating as a private individual
E-Mail: info@hekatool.de
2. Visiting the public website
When the site is accessed, technically necessary connection data is processed. This may include IP address, time, requested address, transferred data volume, referrer, browser/device information, and HTTP status. Processing serves delivery, stability, and abuse prevention.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is secure and reliable operation. The application itself does not include analytics, advertising, or user tracking.
The application does not log authentication headers or request content. Short-lived abuse counters in Redis expire after about one minute. Before production, the operator must technically limit upstream Coolify/Traefik and container log retention to no more than the documented security need and verify it regularly; this notice does not claim an unverified fixed period.
2a. Demo request
When you submit the demo form, we process your name, work email, company, and pilot scope. You may optionally provide employee band, current repository or source system, document volume, desired start, an SSO/Microsoft requirement, preferred operating model, and an additional question. These details are used solely to assess and handle your pilot request. Depending on the request, the legal basis is Article 6(1)(b) GDPR for pre-contractual measures or Article 6(1)(f) GDPR for handling business inquiries. The checkbox records acknowledgement of this notice and is not consent. Delivery uses an email service only when one is configured; Zenodex does not additionally store the form content in its application database.
3. Cookies and language
No language cookie is set merely by visiting the site. If you explicitly select German or English, Zenodex stores that choice in the “zenodex_locale” cookie for one year. It contains only “de” or “en,” uses SameSite=Lax, and serves only the requested language setting.
Storage is necessary for the explicitly requested language setting (Section 25(2)(2) TDDDG). Non-essential marketing or tracking cookies are not currently used, so no consent banner is shown.
4. Sign-in and user account
For user accounts, Zenodex processes in particular name, email address, company assignment, role, password hash, sign-in times, and security-related session information. After successful sign-in, an HTTP-only access cookie is set for up to 60 minutes and an HTTP-only refresh cookie for up to 30 days. Both use SameSite=Lax and Secure in production.
Processing is necessary to provide the agreed service under Article 6(1)(b) GDPR or, where the user is not the contracting party, based on the legitimate interest in secure, role-based company access under Article 6(1)(f) GDPR.
When transactional email is enabled, invitations and password-reset messages are sent through Resend (Plus Five Five, Inc.). This involves processing the recipient address, name, subject, message content, and technical delivery metadata. Emails contain time-limited one-time links; passwords are never sent by email.
5. Documents, search, chat, and feedback
When the protected workspace is used, uploaded files, extracted content, metadata, search queries, chat messages, source references, feedback, and audit events are processed. Processing supports document preparation, permission-aware search, source-grounded answers, quality assurance, and security.
For business customers, the respective customer generally determines the purposes and permitted content. Vincent Schmitt then processes this data as a processor under the customer’s contractual instructions. The specific roles, deletion periods, and permitted content must be defined in the applicable contract, including an Article 28 GDPR data processing agreement.
Business customers can embed the knowledge assistant in their own websites or applications. The submitted question, bounded conversation context resent by the browser for follow-ups, technically required Origin, short-lived rate-limit data, and source-based answer are processed. Widget conversations are not stored as chat history in Zenodex; only usage and audit records without question or answer text are created. The embedding customer must inform its users about the purpose, legal basis, recipients, and permitted content.
6. Use of OpenAI
Depending on configuration, separate processing steps may use an external AI provider: document and visual analysis may process excerpts, metadata, or protected visuals; embeddings send prepared text to the configured embedding provider. Separately, the chat model call sends the question and excerpts selected only after access checks, plus relevant visuals where applicable. OpenAI is a technically supported option, but this notice does not assume the actual provider, contracting entity, region, or retention for every installation. Those details must be confirmed for the concrete setup before activation.
OpenAI provides a Data Processing Addendum for business services. It provides, among other safeguards, standard contractual clauses or adequacy decisions for possible transfers outside the EEA. Before personal data is processed in production, the contract, processing agreement, subprocessors, and specific OpenAI configuration must be reviewed.
7. Recipients and hosting
Access is available to authorized users and administrators and recipients technically required for the concrete installation. The software supports, among other options, STRATO as a possible hosting environment and optional OpenAI, Resend, and Stripe services. Before each service is used, the actual accounts and contracts must confirm which services are active, the contracting entity, region, and retention, and this notice must be published accordingly. Disclosure for third-party advertising is not intended.
Stripe Payments Europe, Limited1 Grand Canal Street Lower
Dublin 2, D02 H210
Ireland
When a subscription is purchased or managed, Stripe processes contact, billing, tax, payment, and transaction data. Payment details are collected directly on Stripe-hosted pages; Zenodex does not store full card or bank-account details. Stripe privacy policy
Plus Five Five, Inc. (Resend)2261 Market Street #5039
San Francisco, CA 94114
USA
Resend provides a Data Processing Addendum for delivery data, including provisions for international transfers. The agreement, subprocessors, and delivery configuration must be reviewed before production activation. Resend Data Processing Addendum
STRATO GmbHOtto-Ostrowski-Straße 7
10249 Berlin
Germany
STRATO is contemplated as a possible hosting environment. Before production, the real account and contract must confirm whether STRATO is actually used for the published installation and which product, server and backup regions, contractual roles, subprocessors, support access, and log and deletion periods apply. Retention for self-operated Coolify, Traefik, container, and application logs must also be configured and verified. Until then, no concrete hosting or retention fact is promised.
8. Retention
Personal data may be retained only for documented purposes, contract performance, statutory evidence and retention duties, or specifically justified security needs. Deletion after contract end or a valid request follows the documented procedure and covers only systems confirmed technically and contractually. A complete automated tenant deletion or tenant-selective backup deletion is not currently promised; scope, exceptions, provider data, and the end of recoverability must be agreed and evidenced in advance. Authentication cookies expire after the periods stated above.
The technical privacy baseline deletes chat histories and associated feedback after 90 days, audit and AI usage logs after 365 days, and stored processing-job error details after 30 days in production. Expired token-blocklist entries are removed after expiry. Any contractually or legally required different periods must be documented and configured through the designated environment variables; disabling the cleanup job is blocked for production deployment.
Demo requests remain only in the configured recipient mailbox and with the delivery provider. Before enabling the form, their deletion period must be defined in the operational deletion policy and technically implemented.
Widget questions and answers are not stored as conversations. Rate-limit keys containing the technical client address expire after about one minute. Aggregated AI usage and audit entries without question or answer text follow the periods stated above.
9. Your rights
Subject to the GDPR, data subjects have rights including access, rectification, erasure, restriction, portability, and objection. Signed-in users can directly export account-associated data and delete their own chat history in settings. The export excludes company documents, credentials, and copied source text and does not replace review of a broader request. Consent can be withdrawn at any time for the future. Send requests to info@hekatool.de.
You also have the right to lodge a complaint with a data protection supervisory authority, particularly in your place of residence, workplace, or the place of the alleged infringement.
10. Automated decision-making
Based on the processing described here, Zenodex does not make solely automated decisions that produce legal or similarly significant effects for website visitors or users.
11. Official legal sources
12. Changes
This privacy notice will be updated when operations, providers, recipients, features, or applicable law change. The current version is available at this address.
