Privacy Policy

Last updated: 02-10-2026

1. Who we are and how to reach us

1.1 The controller is conclusia GmbH, Straße am Flugplatz 52D, 12487 Berlin, Germany ("we", "us"). Our company details are in the imprint at www.conclusia.io/imprint.

1.2 For every question about your data and every request under this Privacy Policy, write to kontakt@conclusia.io or to the postal address above. Product support is available at support@conclusia.io.

2. Which part applies to you

2.1 You use the Service as an Authorised User. Every account belongs to a business, the Customer, also on the free plan. If you registered with your own business, that business is the Customer. Two roles apply:

(a) For your account and the operation of the Service we are the controller. Section 3 describes this processing.

(b) For Customer Data, that is the content you and your colleagues put into the Service and the results it produces, the Customer is the controller and we are its processor under the Data Processing Agreement at www.conclusia.io/legal/data-processing-agreement. Section 4 gives an overview.

2.2 You visit our website. We are the controller (section 6).

2.3 You represent a company or your business contact details are published. We are the controller for the Company Database. Section 5 is our notice to you under Article 14 GDPR, with a short German version. You can object at any time (section 11). Where a Customer researches companies or contacts with the Service, the Customer is the controller for those results. We do not tell third parties which Customers have researched them. If you send us a request about such results, we forward it to the Customer concerned where we can identify it.

3. What we process for our own purposes

3.1 The overview below shows the processing for which we are the controller. The Company Database and the website are described in sections 5 and 6.

Registration and account, including member management and service emails

  • Data: First and last name, business email address, your confirmation that you act for a business and may accept our terms for it, the versions of the Terms of Service and the Data Processing Agreement you accepted and when, plan, role in the account, invitations, settings

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(b). Art. 6(1)(f): proving the contract and its terms, and letting a business see and manage the accounts that act for it

  • Retention: While the account exists. Deleted within 30 days of a deletion request. The record of accepted terms is kept for three years from the end of the year in which the account was closed

Sign-in and security

  • Data: Email address, password (stored in hashed form only), sign-in events, session tokens, IP address, browser or AI client information, security and audit log entries, technical error logs

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(b) for the sign-in. Art. 6(1)(f): a secure and working Service, preventing misuse, finding and fixing errors. Art. 6(1)(c) with Art. 32 for required security measures

  • Retention: As a rule, application logs 30 days and security and audit logs 90 days

Usage metering and plan limits

  • Data: Pseudonymous user and account identifiers, plan, counters and cost figures for the use of the Service (for example lists, chat messages, research columns), the research credit balance and its use, technical events of research columns without question or answer text

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(b) for applying and billing the plan. Art. 6(1)(f): running the Service economically and reliably, preventing abuse of free resources

  • Retention: 390 days. Events of research columns until the account is deleted or the contract ends

Billing (paid plans and research credits)

  • Data: Name and address of the Customer, contact person, billing email, VAT identification number, plan, seats, invoices, amounts, payment status and payment method

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(b). Art. 6(1)(c) with § 147 AO and § 257 HGB for keeping records

  • Retention: Statutory periods, currently up to 10 years

Support, feedback and problem reports

  • Data: Email address, name, content of your message or feedback, the list concerned, a pseudonymous user identifier, the email domain of your account, technical context needed to reproduce a problem

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(b) where the request concerns the contract. Art. 6(1)(f): answering enquiries and improving the Service

  • Retention: 24 months from receipt. Data protection requests and our answers for three years from the end of the year of the request

Contacting users

  • Data: Name, email address, information about your use of the Service

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(b) where the contact serves the contract. Art. 6(1)(f): helping users to use the Service successfully

  • Retention: While the account exists

Seat check (paid plans and free trials only)

  • Data: See section 3.3

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(f): making sure the number of seats agreed with the Customer is respected

  • Retention: 90 days

Usage statistics

  • Data: Usage and operational data from the rows above, turned into aggregated, anonymous figures

  • Legal basis (GDPR) and legitimate interest: Art. 6(1)(f): planning and improving the Service

  • Retention: Anonymous statistics are no longer personal data

3.2 Legal basis for Authorised Users. Where the overview names Art. 6(1)(b), the processing is necessary for the contract with the Customer. If you are not the contracting party yourself, we rely on Art. 6(1)(f) instead. The legitimate interest, ours and the Customer's, is to provide the Service the Customer has ordered to the people it authorises.

3.3 Seat check. Paid plans are licensed per seat, and one seat is for one person. To notice when a seat is probably used by several people, we keep a small record of how each seat is used. This applies only to accounts on a paid plan or a free trial. We never record users of the free plan.

(a) A record is made at most once per sign-in session and 15-minute window. It contains a pseudonymous user identifier, an identifier of the sign-in session, the 15-minute window, the channel (web app or AI assistant), the browser family or the name of the AI client, and, for the web app, a one-way value computed with a secret key from the network range of your IP address. We never store your full IP address here, and we record no content, no location and no device fingerprint.

(b) Our team reviews the records internally. There is no automated decision: nobody is blocked or charged because of a record. If a seat is probably shared, we may talk to the Customer about the number of seats. We do not give the Customer records or evaluations about individual users. The only exception is where disclosure is required to establish, exercise or defend legal claims, and then only in pseudonymised form. We use the records for no other purpose and do not combine them with Customer Data.

(c) The record uses only information that your browser or AI client sends with each signed-in request. It stores nothing on your device and reads nothing from it beyond the sign-in token that the Service needs (§ 25(2) no. 2 TDDDG).

(d) You can object to the seat check (section 11). Unless we have compelling legitimate grounds that override your interests, we then exclude your user from the seat check and delete the records about you.

3.4 Contacting you. We may email you about your use of the Service, for example to help you get started, to offer support and to give you important product information. We send advertising only as permitted by law. You can object to the use of your data for advertising at any time (section 11).

3.5 Billing through a payment provider. Payments for plans and research credits, subscriptions and invoices are handled by Stripe Payments Europe, Limited, Dublin, Ireland. Stripe receives the billing data listed in section 3.1 and the payment details entered in its payment forms, together with technical data of the device used, such as the IP address. We do not store full card numbers. Stripe acts on our behalf when it collects payments and manages invoices. For fraud prevention, money laundering checks and its duties as a payment institution it is an independent controller under its own privacy policy at stripe.com/privacy. Our legal basis for secure payment is Art. 6(1)(f), our interest being the prevention of payment fraud.

3.6 Accounts of a business. Administrators of a Customer account see the members of that account. We may tell a business which accounts are registered in its name or with its email domains. Before we give this information, we verify that the person asking is authorised to represent the business.

4. Content of a Customer's own account

4.1 Who decides. Each Customer's account is its own. The lists, chats, uploads and research results in it belong to the Customer, which decides how they are used and answers requests about them (it is the controller). We store and process this content only to provide the Service to that Customer, under the Data Processing Agreement (we are its processor). Each account is kept separate. If you ask us about content in a Customer's account, for example to have your name removed from a Customer's list, we pass your request on to that Customer and help it to answer.

4.2 What it includes. Briefs and chat messages to the assistant, lists and the companies in them, uploaded files, research columns and their results, exports, and data that a user retrieves on request from Data Providers, such as business contact data, register data and financial data. It also includes short project notes that the Service derives automatically from the conversation, for example which kind of companies a user is looking for, so that the assistant stays consistent across a project.

4.3 How it is processed. To answer a request, the Service sends the relevant parts of Customer Data to our sub-processors (section 7).

4.4 How we may use it. We use Customer Data as follows:

(a) We process it to provide the Service to the Customer.

(b) Authorised members of our staff, who are bound to confidentiality, may access it where this is needed for support, for troubleshooting and fixing defects, and for security.

(c) We analyse how the Service is used in order to operate, secure and improve it (section 3.1).

(d) On the Customer's instruction we anonymise Customer Data, so that no Customer, project or person can be identified. We may use the anonymised data to improve the Service, including developing, training and evaluating models. Customer Data that has not been anonymised is not used to train AI models, neither by us nor by our providers.

(e) Public company websites that become known through the Service, for example when a user adds a company to a list by its web address or imports it, are visited by us and added to the Company Database as our own processing (section 5). The Company Database stores no link to the Customer, the user or the list.

4.5 Data Providers. Data Providers are optional, and the Customer decides whether to retrieve data from them. They are controllers for their own databases and their own privacy notices apply. We pass them only what identifies the company concerned, such as its name, web domain or register number.

4.6 Third-party AI assistants. If a Customer's users connect the Service to an AI assistant of a third party, the provider of that assistant processes what the user types and what the Service returns under the Customer's or the user's own contract with it. These providers are not our sub-processors.

5. Company Database: information under Article 14 GDPR

This section is for you if you are, for example, a managing director, shareholder or other representative of a company, or if your business contact details are published. A short German version is in section 5.9.

5.1 What we do. We build a database of companies so that businesses can find suppliers, partners and customers. It describes companies: name, address, website, industry, products and services, size, legal form and register data. Most of it is not personal data. Some entries contain personal data because companies are represented by people and publish their names.

5.2 Categories of personal data. Names and roles of managing directors, board members, authorised signatories, shareholders and other representatives as published in public registers or on company websites. Business contact details that a company publishes, for example in its imprint. Other information a company publishes about itself where it names people, for example on team pages. We do not seek private addresses, private contact details or special categories of personal data (Art. 9 GDPR). If we find such data, we delete it.

5.3 Sources. Publicly accessible websites of companies, which we visit ourselves and also find through public web archives. Public commercial and company registers, including through providers of register data. Websites of companies that users of the Service add to a list, without a record of who added them.

5.4 Purpose and legal basis. We provide a business information service in which companies can be found and assessed. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest, and that of our Customers, is to identify relevant companies and the people who represent them in business. In weighing the interests we take into account that the data was published by the company or in a public register in order to be found in business, that we use it only in its business context, and that you can object at any time without giving reasons.

5.5 Recipients. Customers see company entries when they search for companies or build lists. Names and contact details of people are not shown in company entries; they can appear in the answer to a research question that a Customer asks about a company. Once such an answer is part of a Customer's list, the Customer is the controller for it (section 2.3). Service providers for hosting, AI models and search process the data on our behalf in the EU, the USA and Singapore (sections 7 and 8).

5.6 Retention. We keep personal data in a company entry for as long as the entry is part of the Company Database, which is the case while the company can be found in the public sources we use. When we visit a source again, we update the entry from it.

5.7 Your rights. You have the rights in section 10 and the right to object in section 11. If you object, we delete your personal data from the Company Database and keep only the minimum needed, for example your name and the company, on a suppression list, so that the data is not collected again.

5.8 Why we inform you this way. We usually do not have your contact details, and contacting everyone whose name appears in a public source would involve disproportionate effort. We therefore publish this information (Art. 14(5)(b) GDPR) and honour every objection without asking for reasons.

5.9 Kurzfassung auf Deutsch: Informationen nach Art. 14 DSGVO zu unserer Unternehmensdatenbank

  • Verantwortlicher: conclusia GmbH, Straße am Flugplatz 52D, 12487 Berlin, kontakt@conclusia.io.

  • Was wir tun: Wir betreiben eine Datenbank über Unternehmen aus öffentlichen Quellen, damit Unternehmen Lieferanten, Partner und Kunden finden können.

  • Welche Daten: Namen und Funktionen von Geschäftsführern, Vorständen, Prokuristen, Gesellschaftern und anderen Vertretern, wie sie in öffentlichen Registern oder auf Unternehmenswebsites veröffentlicht sind; geschäftliche Kontaktdaten, die ein Unternehmen selbst veröffentlicht, zum Beispiel im Impressum.

  • Quellen: öffentlich zugängliche Unternehmenswebsites, auch über öffentliche Webarchive; öffentliche Handels- und Unternehmensregister, auch über Anbieter von Registerdaten; Websites, die Nutzer unseres Dienstes einer Liste hinzufügen, ohne dass wir speichern, wer sie hinzugefügt hat.

  • Zweck und Rechtsgrundlage: Betrieb eines Unternehmensinformationsdienstes, Art. 6 Abs. 1 lit. f DSGVO. Unser berechtigtes Interesse und das unserer Kunden ist es, relevante Unternehmen und die Personen zu finden, die sie im Geschäftsverkehr vertreten.

  • Empfänger: Kunden von conclusia sehen Unternehmenseinträge, ohne Namen und Kontaktdaten von Personen; diese können in der Antwort auf eine Recherchefrage eines Kunden zu einem Unternehmen erscheinen. Dienstleister für Hosting, KI-Modelle und Suche verarbeiten die Daten in unserem Auftrag, auch in den USA (EU-US Data Privacy Framework oder Standardvertragsklauseln) und in Singapur (Standardvertragsklauseln). Die Liste steht unter www.conclusia.io/legal/subprocessors.

  • Speicherdauer: solange der Unternehmenseintrag Teil unserer Datenbank ist, also solange das Unternehmen in den genutzten öffentlichen Quellen zu finden ist.

  • Ihre Rechte: Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung und Beschwerde bei einer Datenschutzaufsichtsbehörde, zum Beispiel der Berliner Beauftragten für Datenschutz und Informationsfreiheit.

  • Widerspruchsrecht: Sie können der Verarbeitung Ihrer Daten in unserer Unternehmensdatenbank jederzeit widersprechen, ohne Gründe anzugeben. Schreiben Sie an kontakt@conclusia.io oder an unsere Postanschrift und nennen Sie das betreffende Unternehmen. Wir löschen dann Ihre Daten aus der Unternehmensdatenbank und speichern nur das Nötigste, zum Beispiel Ihren Namen und das Unternehmen, in einer Sperrliste, damit die Daten nicht erneut erfasst werden.

6. Website and web app

6.1 Website hosting. Our website www.conclusia.io is hosted by Framer B.V., Amsterdam, Netherlands, and delivered through a worldwide content delivery network. When you visit it, the host processes on our behalf the technical data needed to deliver the pages: IP address, time, pages requested, browser and operating system, and the referring page. It also counts page views for us without cookies and without creating a profile of you. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is presenting our business securely and knowing how many people visit which pages. The host keeps these data for a limited period.

6.2 Fonts. The web app and the sign-in pages of our interface for AI assistants use fonts that we host ourselves. The website loads its fonts from Google's font servers, so your browser sends your IP address and technical browser data to Google. The legal basis is Art. 6(1)(f) GDPR, our interest being a consistent and readable website.

6.3 Icons of research sources. When the web app shows which websites a research step visited, it loads each source's small icon from Google's icon service. Your browser then sends Google your IP address and the domain of that source, which may be the website of a company being researched. The legal basis is Art. 6(1)(f) GDPR, our interest being that sources of research results are easy to recognise.

6.4 Map. The geographic filter in the web app shows a map whose tiles are loaded from the map provider CARTO in the USA. Your browser sends your IP address and the map section requested. No Customer Data is sent. The legal basis is Art. 6(1)(f) GDPR, our interest being to show the map the filter needs.

6.5 Independent controllers. Google and CARTO process the data in sections 6.2 to 6.4 as independent controllers under their own privacy notices. Details are at www.conclusia.io/legal/subprocessors.

6.6 Storage in your browser. The web app stores sign-in tokens and interface settings in your browser's local storage. This is strictly necessary to provide the Service you request (§ 25(2) no. 2 TDDDG). We use no cookies or similar technologies for advertising or tracking.

7. Recipients

7.1 Single list. The names of all service providers, the service each one provides, the data, the location and the transfer mechanism are at www.conclusia.io/legal/subprocessors. How we announce changes to sub-processors is set out in the Data Processing Agreement.

7.2 Categories of recipients. Your data may be received by:

(a) sub-processors for Customer Data: providers of hosting, databases and storage, of AI models, of web search and website reading, and of email;

(b) processors for our own purposes: the same categories, and providers of payment and invoicing, of internal messaging for support and problem reports, and of website hosting. They process data only on our instructions;

(c) Data Providers, where a Customer chooses to use them (section 4.5);

(d) third parties contacted by your browser (section 6.5);

(e) Customers, who see entries of the Company Database (section 5.5), and the administrators of your Customer's account, who see its members;

(f) tax advisers, auditors and lawyers, who are bound to professional secrecy, and authorities and courts where the law requires disclosure.

7.3 We do not sell personal data.

8. Transfers outside the EU

8.1 Data is processed in the EU and in the USA, and for one function of the Company Database in Singapore. Some providers also use locations of their worldwide infrastructure. The location and safeguard for each provider are on the page named in section 7.1.

8.2 USA. Where a recipient is certified under the EU-US Data Privacy Framework, the transfer is based on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). Otherwise, and in addition where our contracts provide for it, we use the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR).

8.3 Other countries. There is no adequacy decision for Singapore. Transfers there, and to any other country without an adequacy decision, are based on Standard Contractual Clauses.

8.4 AI processing. Our hosting provider may route individual AI requests between its regions in the EU and the USA to balance capacity. The data stays with that provider, is processed only for the time needed to answer the request, and is covered by our contract with it, including Standard Contractual Clauses.

8.5 You can ask for a copy of the safeguards used for a transfer at kontakt@conclusia.io.

9. Retention

9.1 We delete personal data when it is no longer needed for its purpose, unless the law requires us to keep it. The periods for our own purposes are in section 3.1 and, for the Company Database, in section 5.6. The following periods apply to Customer Data and in general.

All Customer Data after the end of the Customer's contract: Deleted at the latest 44 days after the end of the contract (30 days for retrieving the data plus 14 days), including caches and search indexes

Lists and research results: Until the Customer asks for deletion or the contract ends. Removing a list in the Service archives it. Permanent deletion on request within 30 days

Conversations: 90 days

Project notes: Until the account or the list concerned is deleted, the Customer asks for deletion or the contract ends

Uploaded files: 180 days

Export files created through the interface for AI assistants: 2 days

Cached data from Data Providers: No longer used after 30 days (register identifiers 90 days); deleted at the latest with the Customer Data

Suppression list after an objection: As long as needed to honour the objection

9.2 If you were a member of a Customer's account, deleting your own account does not delete the lists and other Customer Data of that account. They remain with the Customer.

9.3 Deleted data remains in backups until they are overwritten. We restore it only to recover from an incident and then delete it again.

9.4 Where data is needed to establish, exercise or defend legal claims in a specific case, we keep it until the matter is closed.

10. Your rights

10.1 You have the right to:

(a) access the personal data we hold about you and receive a copy (Art. 15 GDPR);

(b) have inaccurate data rectified (Art. 16 GDPR);

(c) have data erased, including your account (Art. 17 GDPR);

(d) have processing restricted (Art. 18 GDPR);

(e) receive data you gave us on the basis of a contract in a portable format (Art. 20 GDPR);

(f) object to processing (Art. 21 GDPR, section 11).

10.2 How. Write to kontakt@conclusia.io. To have your account deleted you can also write to support@conclusia.io. We answer within one month. If a complex request takes longer, we tell you within that month. We may ask you to confirm your identity, usually by answering from the email address of your account. Exercising your rights is free of charge.

10.3 Complaint. You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State where you live, where you work or where the alleged infringement took place. Our lead authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

11. YOUR RIGHT TO OBJECT (ARTICLE 21 GDPR)

11.1 Processing based on legitimate interests. Where we process your personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. This concerns in particular the seat check, security and error analysis, contacting users, the Company Database and the website. If you object, we stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

11.2 Direct marketing. Where we process your data for direct marketing, you can object at any time without giving reasons. We then stop processing it for that purpose.

11.3 Company Database. If your name or business contact details appear in the Company Database, you can object at any time and we will not ask you for reasons. We delete your data as described in section 5.7.

11.4 How to object. Write to kontakt@conclusia.io or to our postal address. Please tell us which processing your objection concerns and, for the Company Database, which company.

12. No automated decisions

12.1 We make no decisions based solely on automated processing, including profiling, that have legal effects for you or similarly significantly affect you (Art. 22 GDPR). This includes the seat check (section 3.3).

13. Required data

13.1 To register and use the Service you must provide your name, your business email address, a password and your confirmation that you act for a business and may accept our terms for it. Without these we cannot conclude the contract or provide the Service. Billing data is required for paid plans and for buying research credits. Everything else you enter, such as briefs, uploads and feedback, is voluntary, although the Service cannot answer a request you do not make. No law obliges you to provide personal data to us.

14. Security

14.1 We take technical and organisational measures appropriate to the risk (Art. 32 GDPR): connections to the Service are encrypted in transit (TLS), we use encryption at rest for many of our data stores, access to production systems is limited to the people who need it and uses personal credentials, access is logged, we keep backups, we use pseudonymous identifiers where the purpose allows it, and each Customer's data is separated by account. If a personal data breach occurs, we inform affected Customers without undue delay, aiming at 48 hours, and notify the supervisory authority and the people affected as Articles 33 and 34 GDPR require.

15. Changes

15.1 We update this Privacy Policy when our processing changes. The current version with its date is always at www.conclusia.io/legal/privacy-policy. Where a change materially affects registered users, we inform them by email or in the Service before it takes effect.