Privacy Policy

The legally binding version of this privacy policy is the German version at eloqole.com/datenschutz (updated 14 July 2026). This translation is provided for convenience and may lag behind.

1. Controller

The controller for the processing of personal data is: Janike Arent, trading as eloQole Lavendelweg 7 30880 Laatzen Germany Email: [email protected]

2. Overview and principles

eloQole processes personal data only to the extent necessary to provide the website and the Studio, to perform contracts, for communication, for payment processing, for security, or on the basis of consent. Depending on the processing, we rely in particular on: • Art. 6(1)(b) GDPR for entering into and performing a contract and for pre-contractual measures; • Art. 6(1)(c) GDPR for legal obligations; • Art. 6(1)(f) GDPR for security, abuse prevention, enforcement of rights, and data-minimising reach measurement; • Art. 6(1)(a) GDPR for consent-based analytics and the newsletter; • § 25(2) TDDDG (German TTDSG successor law) for strictly technically necessary storage of, or access to, information on the end device; • § 25(1) TDDDG for non-essential local identifiers based on consent. We do not use any personal data from the eloQole Studio to train our own language models. External AI providers process the transmitted content under the agreements applicable to the business account used.

3. Accessing the website and hosting with Cloudflare

The website, database, and security functions are provided via Cloudflare services. When the site is accessed, technically necessary connection data is processed, in particular IP address, time, requested URL, browser and device information, referrer, and security events. The purposes are delivery of the website, protection against attacks, error analysis, and ensuring availability. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of the service. Processor: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, and affiliated companies. A data processing addendum is in place with Cloudflare. For transfers to the USA, Cloudflare may rely on its certification under the EU-U.S. Data Privacy Framework; in addition, the DPA includes EU standard contractual clauses. Server and security logs are stored for up to 90 days, unless longer retention is required to investigate a specific security incident.

4. User account and passwordless login

For the Studio, a user account is created with email address, account status, plan, technical identifiers, and, where applicable, channel profiles. Sign-in is via a time-limited login link. The login email is sent via Resend. This involves processing, in particular, the email address, message content, time of sending, and delivery status. The legal basis is Art. 6(1)(b) GDPR. Security logs may additionally be based on Art. 6(1)(f) GDPR. Processor: Plus Five Five, Inc., trading as Resend, USA. The Resend DPA forms part of the contractual terms; Resend states that it is certified under the EU-U.S. Data Privacy Framework and uses additional contractual safeguards. Login and delivery logs are stored for 30 days in our systems; delivery logs held by the sending service provider are subject to that provider’s contractual retention periods.

5. Content in the Studio and local storage

Depending on the function, we process briefings, keywords, names, anecdotes, tone, target audiences, drafts, speeches, scripts, channel profiles, and editing states. Some drafts may be stored exclusively in the browser’s local storage. This storage is necessary so that editing states are not lost every time you navigate between pages. The legal basis for accessing local storage is § 25(2) no. 2 TDDDG; further processing is carried out to perform the contract under Art. 6(1)(b) GDPR. Locally stored content can be deleted via the browser’s site data. It is not automatically removed from the respective end device when an account is deleted on the server side. Server-side stored projects are retained until deleted by the user, until account deletion, or until the storage period provided for the product expires. Currently planned periods: • Occasion Pass: deletion 30 days after the end of the 90-day term • Subscription projects: deletion 30 days after the end of the contract or account deletion • Free-tier projects: deletion after 12 months without sign-in, with prior notice by email

6. Speech and script creation with AI

To create and edit texts, inputs and the necessary conversation context are transmitted to Anthropic and/or OpenAI. Only the content required for the requested function is transmitted, together with technical metadata for processing and error analysis. The purpose and legal basis are the provision of the selected function and performance of the contract under Art. 6(1)(b) GDPR. Security and abuse checks may additionally be based on Art. 6(1)(f) GDPR. — Anthropic: Processor: Anthropic, PBC, USA. For commercial API use, according to Anthropic the data processing addendum with EU standard contractual clauses is automatically incorporated into the Commercial Terms. Under its standard terms, Anthropic generally deletes API inputs and outputs within 30 days. Exceptions may apply in particular for legal obligations, other agreed retention, certain API features, and to enforce its usage policies. Longer retention periods may apply to content flagged as a policy violation. — OpenAI: Under the OpenAI Services Agreement, the processor for customers in the EEA is generally OpenAI Ireland Ltd.; further affiliated companies and sub-processors may be involved. The OpenAI data processing addendum forms part of the terms of business and contains provisions for third-country transfers. By default, OpenAI may store API inputs and outputs for up to 30 days in abuse-monitoring logs, unless a different data retention has been agreed or enabled for the endpoint used. Longer storage may occur where required by law or for security reasons. API content is used to train general models only where this is expressly provided for or authorised under the terms applicable to the business account.

7. Voice input and transcription

When the dictation function is used, audio content is transmitted to OpenAI for transcription. Use is voluntary. The audio, the text generated from it, and technical metadata are processed. The legal basis is Art. 6(1)(b) GDPR. Retention by OpenAI is governed by the API rules described in Section 6. The phrasing “is not stored permanently” is deliberately avoided as long as no zero-data-retention status has been contractually confirmed.

8. File and photo upload

Documents such as PDF or Word files are, under the current technical setup, read directly in the browser. The original file is not transmitted to eloQole. Only when the user uses the extracted text for a function is that text processed like a normal Studio input. Photos are transmitted to Anthropic for text recognition. The processing covers the image, the recognised text, and technical metadata. The legal basis is Art. 6(1)(b) GDPR, where the upload is part of the desired function. Please do not upload photos showing identifiable individuals. Documents and photos may only be used where the user is authorised to do so. Unnecessary third-party data and special categories of personal data should be removed or anonymised before uploading.

9. Shared speeches

When a user creates a share link, the shared text, occasion, language, share ID, time of creation, and technical access information are stored on the server side. Anyone who knows the link can access the content. Users must therefore not share content that has to remain confidential. Shared content is automatically deleted after 90 days, or earlier if the user deactivates the link. The legal basis is Art. 6(1)(b) GDPR.

10. Payment processing via Stripe

Paid products are processed via Stripe. Payment data is collected directly by Stripe. eloQole receives, in particular, Stripe customer and transaction identifiers, product, amount, currency, payment status, invoicing, and, where applicable, tax information. Processor and, depending on the processing, independent controller: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, and affiliated Stripe companies. The legal bases are Art. 6(1)(b) GDPR for contract and payment processing, Art. 6(1)(c) GDPR for tax and commercial law obligations, and Art. 6(1)(f) GDPR for fraud prevention and enforcement of rights. The Stripe data processing agreement forms part of the Stripe contract. Stripe may process personal data worldwide and, according to its own information, relies among other things on the EU-U.S. Data Privacy Framework and EU standard contractual clauses. Payment and accounting records are generally retained for eight years from the end of the relevant calendar year within the scope of statutory retention obligations; in individual cases longer periods may apply.

11. Newsletter “Der Redenbrief”

For the newsletter we use a double opt-in procedure. We process the email address, language, subscription source, subscription and confirmation time, and technically necessary sending and delivery information. The legal basis is consent under Art. 6(1)(a) GDPR. Consent can be withdrawn at any time via the unsubscribe link. The lawfulness of processing up to the withdrawal remains unaffected. Sending is carried out via Resend. Information on the processor and third-country transfer is provided in Section 4. After unsubscribing, the address is removed from the active distribution list. A minimal suppression record may be retained so that no further mailings are sent. Double opt-in records are stored for three years after unsubscribing.

12. Our own reach measurement

— Level 1 – without storage on the end device: For data-minimising reach measurement, the requested path, referrer, campaign parameters, coarse country, coarse device type, and time are processed on the server side. A daily-changing pseudonymous short value is generated from the IP address and browser information; the IP address is not stored as a separate analytics value. The purpose is to measure use and improve the service. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in data-minimising, non-advertising performance measurement. Users may object on grounds relating to their particular situation. Raw data is deleted or aggregated after 90 days. Aggregated statistics are stored for 24 months. — Level 2 – only with consent: With consent, a random pseudonymous identifier is stored in the browser’s local storage. This makes it possible to analyse returning visits, screen width, time spent, and the path across several pages. The legal bases are § 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent can be withdrawn at any time in the consent dialog. The identifier and associated events are deleted after 12 months or upon withdrawal.

13. Communication and support

When you contact us by email or via support functions, we process sender data, content, time, technical metadata, and the processing history. The legal basis is, depending on the matter, Art. 6(1)(b), (c), or (f) GDPR. Enquiries are deleted once they have been conclusively handled and there are no longer any statutory retention, evidentiary, or legal defence interests. Standard deletion period: 24 months after conclusion of the enquiry.

14. Recipients and third-country transfers

Recipients of personal data are only internal authorised persons and the processors required for the respective purpose. Currently these are, in particular, Cloudflare, Anthropic, OpenAI, Resend, and Stripe. For transfers outside the EEA, depending on the provider we rely on an adequacy decision, in particular a valid certification under the EU-U.S. Data Privacy Framework, EU standard contractual clauses, or other legally permissible safeguards. As certifications and sub-processors may change, provider documentation is reviewed regularly.

15. Storage period

Personal data is deleted as soon as the purpose of processing ceases to apply and no legal obligations or overriding legal defence interests prevent deletion. Individual periods are set out in the respective sections and in the internal deletion policy.

16. Obligation to provide data

For registration and entering into a contract, a reachable email address, the selected product information, and the necessary payment data are required in particular. Without this data, the account or the paid contract cannot be provided. Voluntary content can be omitted, provided the respective function does not require it.

17. Automated decisions

eloQole does not make any solely automated decisions with legal or similarly significant effects on users. AI models generate text suggestions but do not decide on rights, access to public benefits, employment, credit, or comparable areas of life.

18. Rights of data subjects

Subject to the statutory requirements, data subjects have, in particular, the rights to access, rectification, erasure, restriction, data portability, and objection. Consent can be withdrawn at any time with effect for the future. Requests can be sent to [email protected]. There is also a right to lodge a complaint with a data protection supervisory authority. The authority responsible for the provider is, in particular, the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen); data subjects may also contact another competent supervisory authority.

19. Security

eloQole uses TLS encryption, access restrictions, separately held secrets for API keys, role-based permissions, logging of security-relevant events, and regular updates. Despite these measures, absolute security cannot be guaranteed.

20. Minors

Paid contracts are aimed at persons of legal age. The service is not designed for children to create accounts or enter personal data on their own. Parents and other users should only enter minors’ data where this is necessary and legally permissible.

21. Changes

This privacy policy will be adjusted when functions, processors, or the legal situation change. The current version is available at eloqole.com/datenschutz. In the event of significant changes for registered users, appropriate information will be provided.

For questions regarding data protection and your rights: [email protected]

Version: 14 July 2026