Privacy Policy

Last updated: July 2026

1. Privacy at a Glance

General Information

The following gives a simple overview of what happens to your personal data when you use NegoAnalyzer® or visit this website. Personal data is any data by which you can be personally identified.

Data Collection

Data is collected when you provide it to us (e.g. by email or when booking an appointment), when we set up your access to the platform, and when you use the platform — in particular through the content you enter into the assistants.

How We Use Your Data

To provide the platform, to fulfil contractual obligations, to communicate with you, and to ensure security and prevent misuse.

Your Rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection at any time. Two of these rights can be exercised directly within the platform: a full export of your data and permanent deletion of your account (see section 10). For anything else, contact us at privacy@negoanalyzer.ai.

2. Controller

NegoAnalyzer® - operated by Andreas Goßen
Marie-Hüllenkremer-Str. 17
50859 Cologne, Germany
Email: privacy@negoanalyzer.ai
Web: andreasgossen.de

The controller is the natural or legal person who determines the purposes and means of the processing of personal data.

3. Legal Bases for Processing

We process personal data on the following legal bases:

  • Art. 6(1)(a) GDPR - with your consent
  • Art. 6(1)(b) GDPR - to perform a contract or take pre-contractual steps
  • Art. 6(1)(c) GDPR - to comply with legal obligations
  • Art. 6(1)(f) GDPR - based on our legitimate interests (e.g. platform security, misuse prevention, recoverability through backups)

4. Data Collected and Purposes of Processing

4.1 Contact and Appointment Booking

If you contact us by email, we store your details in order to handle your enquiry. Legal basis: Art. 6(1)(b) or (f) GDPR. Erasure: once the matter is concluded, at the latest after 3 years.

To book a demo appointment we use Calendly (Calendly LLC, USA). When you click "Book a Demo" you leave our website; the data you enter there (name, email, preferred time) is processed by Calendly as our processor, subject to Calendly's privacy policy. Legal basis: Art. 6(1)(b) GDPR. For transfers to the USA, see section 8.

4.2 Access to the Platform

To use the platform we set up an account for you. We store: email address, first and last name, assigned role, account status and the time of your last sign-in.

Sign-in works without a password, via a single-use magic link sent to you by email. Of that link we store only a cryptographic digest, its expiry and whether it has already been used — never the link itself. Used and expired links are deleted automatically. Legal basis: Art. 6(1)(b) GDPR.

4.3 Content You Enter into the Assistants

When working with the assistants, we process and store:

  • Your messages and the assistants' responses, grouped into a conversation with a title
  • Documents you upload to a conversation or project — text is extracted at upload time; we do not store the original file, only the extracted text and its mathematical representation used for search
  • Images you upload, downscaled and attached to the conversation
  • Projects as workspaces with a personal knowledge base shared across several conversations
  • Usage data per day: consumed compute quota (tokens), number of messages and voice seconds — for quota management, billing and misuse prevention

This content may contain sensitive business information. Please do not enter data you are not permitted to have processed — in particular no special categories of personal data relating to third parties (Art. 9 GDPR). Legal basis: Art. 6(1)(b) GDPR.

Your content is not used to train AI models — neither by us nor by the providers we use (see section 7).

4.4 Voice Mode

If you use voice mode, your voice is streamed to our AI provider in real-time and converted to text there. The audio recording itself is not stored. Only the transcript is added to your conversation, marked as voice input. In addition, we count the voice seconds consumed. Legal basis: Art. 6(1)(b) GDPR.

4.5 Access by Us as the Operator

To assist with incidents, prevent misuse and assure quality, the operator's administrators can access user accounts and conversations. Access is restricted to a small number of named individuals and takes place only to the extent necessary for the respective purpose. Legal basis: Art. 6(1)(b) and (f) GDPR.

4.6 Server Log Files

When you visit our website, our hosting provider automatically records access data (IP address, browser type, operating system, referrer, date/time). This data is not combined with other sources and is deleted after 7 days. Legal basis: Art. 6(1)(f) GDPR.

To fend off automated attacks we limit the number of requests per IP address. The counters required for this are held only transiently in memory and are not stored.

4.7 Cookies

We use strictly necessary cookies only, for which no consent is required (Section 25(2) TDDDG):

  • frontendSession – your sign-in to the platform, valid for 7 days
  • authToken – sign-in to the administration area (operator accounts only)

We also store your display preferences (language, light/dark appearance) locally in your browser. This information is not transmitted to us.

We do not set analytics or tracking cookies. Our pages embed no external scripts, fonts or tracking pixels.

5. Retention and Automatic Erasure

We store personal data only for as long as necessary for the respective purpose. Fixed, technically enforced retention periods apply to the platform:

DataRetention
Conversations including messages and uploaded files30 days without activity, then deleted automatically
Projects including their personal knowledge base180 days without activity, then deleted automatically
Daily usage data (tokens, messages, voice seconds)14 months
Magic linksuntil used, at the latest until they expire
Account datauntil the account is deleted
Server log files7 days

"Without activity" means the period restarts with every new message or upload. Conversations and projects in active use never expire. You can also extend any period manually in the sidebar; you will see a notice there well before expiry.

After you delete your account, all of the above data is removed immediately and irreversibly. It disappears from running backups (see section 9) once the backup retention period of no more than 30 days has elapsed. Statutory retention obligations (e.g. 10 years under German commercial and tax law for invoice data) remain unaffected; your content is not subject to these.

The details of erasure are laid down in an internal data deletion policy.

6. Disclosure to Third Parties

We do not disclose your data to third parties, except:

  • to processors acting for us under a data processing agreement (see section 7)
  • where we are legally required to do so
  • with your explicit consent

Your data is not shared with third parties for advertising purposes. We do not sell data.

7. Processors We Use

ProviderPurposeData transferred
OpenAI (OpenAI Ireland Ltd. / OpenAI L.L.C., USA)AI responses, speech recognition and synthesis, text analysisyour messages, extracts from uploaded files, voice transcripts
Hosting provider (servers in Germany)operation of the platform and databaseall data listed in section 4
Email service providerdelivery of magic linksemail address, name
Calendly LLC (USA)booking demo appointmentsname, email, preferred time

On processing by OpenAI in detail: so that an assistant can follow the course of a conversation, responses are technically cached at OpenAI. According to OpenAI, this data is retained there for 30 days and is not used to train models. When you delete a conversation or your account, we additionally trigger deletion of that cached data at OpenAI — so you do not have to wait out the 30 days.

8. Data Processing Outside the EU

The platform's database and object storage are located in Germany. Where we use providers in third countries (in particular OpenAI and Calendly, USA), we base the transfer on an adequacy decision of the EU Commission (EU-US Data Privacy Framework) where the provider is certified, and otherwise on standard contractual clauses under Art. 46 GDPR together with supplementary safeguards.

9. Data Security and Backups

We use industry-standard security measures to protect your data, including TLS/SSL encryption of all connections, role-based access controls, passwordless sign-in via single-use links, per-IP request limiting and inspection of uploaded files. Further information is available on our security page.

To ensure recoverability in the event of an incident, we create regular encrypted backups. They are stored separately from the production system and deleted after no more than 30 days. Legal basis: Art. 6(1)(f) GDPR.

10. Your Rights as a Data Subject (Art. 15–22 GDPR)

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR) - what data do we store about you?
  • Rectification (Art. 16 GDPR) - correction of inaccurate data
  • Erasure (Art. 17 GDPR) - the "right to be forgotten"
  • Restriction (Art. 18 GDPR) - restriction of processing
  • Data portability (Art. 20 GDPR) - your data in a machine-readable format
  • Objection (Art. 21 GDPR) - to processing based on legitimate interests
  • Withdrawal - of consent given, at any time and without giving reasons

Immediately and without a request: self-service in the platform

Using the profile menu at the bottom left of the platform, you can at any time:

  • "Export my data" – you receive an archive containing all data stored about you: account, all conversations with all messages, projects, the contents of your uploaded files and your usage data. It includes a machine-readable version (JSON, Art. 20 GDPR) and a readable version to browse.
  • "Delete account" – your account and all associated data are deleted irreversibly, including the cached data held by the AI provider. Please export your data first if you wish to keep it.

You can also delete individual conversations, your entire history and individual projects directly in the application at any time.

To exercise your other rights, contact: privacy@negoanalyzer.ai. We will respond within one month (Art. 12(3) GDPR).

11. Objection to Direct Marketing

IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU MAY OBJECT AT ANY TIME. FOLLOWING AN OBJECTION, YOUR DATA WILL NO LONGER BE USED FOR MARKETING PURPOSES.

12. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, www.ldi.nrw.de.

13. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in the law or in our services. The current version is always available on this page. We will notify registered users by email of any material changes.