- Home
- Privacy Policy
Privacy Policy
Last updated: November 10, 2025
1. Introduction
Welcome to Office AI ze, a product of Innov-AI-tive GmbH. We are committed to protecting your personal data and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Data Controller:
Innov-AI-tive GmbH
Bahnhofplatz 1
91054 Erlangen
Germany
Phone: +49 (0) 9131 918 947 30
Email: info@innov-ai-tive.de
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
- Account information: name, email address, password (encrypted)
- Organization information: company name, business address
- Profile information: avatar, language preferences, notification settings
- Payment information: billing details, credit card information (processed securely via PayPal)
2.2 Business Data
When using our AI-powered features, we process:
- Contract documents and extracted data
- Meeting transcripts and audio recordings
- Email content and metadata (when using email categorization)
- Calendar events and task information
- Cloud storage files (Google Drive, OneDrive, Dropbox)
2.3 Technical Information
- IP address, browser type, device information
- Usage data: pages visited, features used, time spent
- Cookies and similar tracking technologies
- API usage logs and error reports
3. How We Use Your Information
We use your information for the following purposes:
- To provide and maintain the Office AI ze service
- To process documents using AI (OpenAI GPT, Whisper)
- To sync with external integrations (Google, Microsoft, Trello, Slack)
- To send notifications and reminders about tasks and deadlines
- To process payments and manage subscriptions
- To improve our AI algorithms and service quality
- To detect and prevent fraud or security issues
- To comply with legal obligations
4. AI Processing & Third-Party Services
Important:
Your business data is processed by third-party AI services. By using Office AI ze, you consent to this processing.
4.1 OpenAI Processing
We use OpenAI's GPT models to:
- Extract data from contracts and documents
- Generate meeting summaries and action items
- Categorize emails and prioritize tasks
Your data is sent to OpenAI's servers (located in the USA). OpenAI states they do not use API data to train their models. See OpenAI's Privacy Policy.
4.2 External Integrations
We integrate with:
- Google Drive/Calendar: Access to your files and calendar events (OAuth 2.0)
- Microsoft OneDrive/Outlook: Access to your files and calendar events (OAuth 2.0)
- Dropbox: Access to your files (OAuth 2.0)
- Slack/Teams: Send notifications to your channels (OAuth 2.0)
- Trello: Create and update tasks (OAuth 1.0)
- Salesforce/HubSpot: Sync CRM data (OAuth 2.0)
We only access data you explicitly grant permission for during OAuth authorization.
5. Data Storage & Security
5.1 Where We Store Your Data
- PostgreSQL Database: Hosted in EU data centers (GDPR compliant)
- ChromaDB Vector Store: Self-hosted, stores embeddings for semantic search
- File Storage: Your uploaded files stored securely on our servers
- Third-Party Processing: OpenAI (USA), Google (USA/EU), Microsoft (USA/EU)
5.2 Security Measures
- All data encrypted in transit (TLS/SSL)
- Database encryption at rest
- Password hashing using industry-standard algorithms
- OAuth 2.0 for third-party integrations (no password storage)
- Multi-tenant architecture with strict data isolation
- Regular security audits and updates
5.3 Data Retention
We retain your data:
- Account data: Until you delete your account
- Business data: Until you delete it or your account
- Backup data: 30 days after deletion
- Transaction logs: 7 years (legal requirement)
6. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Delete your account and data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Export your data in a machine-readable format
- Right to Object: Object to processing for direct marketing
- Right to Withdraw Consent: Revoke consent for AI processing
To exercise your rights, contact us at info@innov-ai-tive.de or use the settings in your account.
7. Cookies & Tracking
We use cookies for:
- Essential Cookies: Login sessions, CSRF protection (required)
- Preference Cookies: Language, theme, dashboard layout
- Analytics Cookies: Usage statistics, performance monitoring (optional)
You can manage cookies in your browser settings. Disabling essential cookies may affect functionality.
8. Children's Privacy
Office AI ze is not intended for users under 18 years of age. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately.
9. International Data Transfers
Your data may be transferred to and processed in countries outside the EU/EEA (e.g., USA for OpenAI processing). We ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs) with third-party processors
- EU-US Data Privacy Framework compliance (where applicable)
- Privacy Shield certification (for legacy data)
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use of the service after changes constitutes acceptance.
11. Contact Us
For privacy-related questions or to exercise your rights, contact us:
Data Protection Officer:
Innov-AI-tive GmbH
Bahnhofplatz 1
91054 Erlangen
Germany
Email: info@innov-ai-tive.de
Phone: +49 (0) 9131 918 947 30
You also have the right to lodge a complaint with your local data protection authority.