Privacy Policy
Authoritative version
This English version is provided for convenience only. The legally authoritative version is the German version available at https://paless.eu/de/privacy. In the event of inconsistency between language versions, the German version prevails.
1. Controller
Entalys GmbH
Carmenstr. 18
40668 Meerbusch
Germany
Represented by the managing director: Christoph Kleinhans
Email for data protection: datenschutz@paless.eu
Phone: +49 176 63057818
The controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: "GDPR") and of other national data protection laws is the above-named Entalys GmbH.
Registered in the commercial register of the Amtsgericht Neuss, HRB 25084. VAT identification number: DE460863235. General email: info@paless.eu. For data protection matters, please primarily use the email address datenschutz@paless.eu.
2. Data Protection Officer
A data protection officer has not been appointed at this time. Based on our current assessment, the controller is not under a legal obligation to appoint one pursuant to Article 37 GDPR in conjunction with § 38 of the German Federal Data Protection Act (BDSG). The need for an appointment is kept under continuous review, in particular with a view to the start of live operation of the service; should an appointment be made, the contact details of the data protection officer will be published here.
For all data protection matters, please use the contact address datenschutz@paless.eu stated in Section 1.
3. General Information on Data Processing
This section describes which processing operations this privacy policy covers and the meaning in which the terms used are to be understood.
3.1 Scope
This privacy policy applies to the processing of personal data (a) when you access and use the website paless.eu including all subpages, (b) in the initiation, conclusion and performance of contracts for the use of the "paless" service, (c) when you contact the controller via the communication channels stated in the legal notice or in this policy, and (d) when you support the controller via the crowdfunding platform Kickstarter (Section 7).
Where the controller processes personal data on behalf of a customer within the meaning of Article 4(7) GDPR (processing on behalf of a controller), this is pointed out separately in the relevant sections (in particular Sections 6.2 and 6.3). The data processing agreement concluded between the parties (Annex 2 of the controller's GTC) is decisive for such processing.
3.2 Definitions
This privacy policy uses the terms in the meaning given to them by Article 4 GDPR. In particular:
- "personal data" means any information relating to an identified or identifiable natural person (Article 4(1) GDPR)
- "processing" means any operation performed on personal data (Article 4(2) GDPR)
- "controller" means the body which determines the purposes and means of the processing (Article 4(7) GDPR)
- "processor" means the body which processes personal data on behalf of the controller (Article 4(8) GDPR)
4. Legal Bases of Processing
Where we obtain the data subject's consent for processing operations involving personal data, Article 6(1)(a) GDPR serves as the legal basis.
For the processing of personal data required for the performance of a contract to which the data subject is a party, Article 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations required to carry out pre-contractual measures.
Where the processing of personal data is required to comply with a legal obligation to which the controller is subject (e.g. retention obligations under commercial or tax law), Article 6(1)(c) GDPR serves as the legal basis.
Where processing is necessary to safeguard a legitimate interest of the controller or a third party and the interests, fundamental rights and freedoms of the data subject do not override the former interest, Article 6(1)(f) GDPR serves as the legal basis. The respective legitimate interest is stated for each individual processing operation.
5. Processing When Visiting the Website paless.eu
This section explains which personal data is processed when you visit the website paless.eu, for which purposes and on which legal basis.
5.1 Server Log Files
Each time the website is accessed, the browser of your device automatically transmits information to the website's server; the website is delivered via our processor Bunny.net (Section 8). The following information is collected without any action on your part and stored temporarily in a so-called server log file:
- IP address of the requesting device
- date and time of access
- name and URL of the file retrieved
- website from which access was made (referrer URL)
- browser used and, where applicable, the operating system of your device and the name of your access provider
Purposes: ensuring smooth connection setup and comfortable use of the website, evaluating system security and stability, and investigating abuse or fraud; this also constitutes our legitimate interest. Legal basis: Article 6(1)(f) GDPR. Storage period: a maximum of 30 days, followed by automated deletion or anonymisation; longer retention in individual cases is possible where necessary to investigate a specific security incident.
5.2 Cookies and Similar Technologies; Consent Management
The website uses cookies and similar technologies (together: "cookies"). Cookies are small text files stored in the browser of your device.
Strictly necessary cookies, whose use is essential for the operation of the website (for example to store your cookie settings, for language selection or to maintain a session), are set without consent. The legal basis is § 25(2) no. 2 of the German Act on Data Protection in Telecommunications and Digital Services (TDDDG) in conjunction with Article 6(1)(f) GDPR; our legitimate interest lies in the technically error-free and secure operation of the website.
Other cookies that go beyond what is strictly necessary are set only with your explicit consent. The legal basis is § 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR. You may withdraw any consent given at any time with effect for the future.
Consent is managed via the open-source cookie consent manager Klaro!. Via the displayed banner you can give consent, make individual selections and withdraw or adjust your consent at any time. The script and configuration files of Klaro! are delivered via the content delivery network of our processor Bunny.net (Section 8); for technical reasons, your IP address is processed in the course of this. No data is transmitted to the publisher of Klaro! or to any other third parties.
5.3 Locally Hosted Fonts
The website uses the fonts "Inter" and "Schibsted Grotesk", which originally come from the Google Fonts offering. To protect your privacy, the font files are delivered exclusively together with the website from our own domain (Section 5.1). No connection is made to servers of Google LLC or Google Ireland Limited; your IP address and other personal data are not transmitted to Google.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in a consistent and visually appealing typographic presentation of the website without the involvement of external font services.
5.4 Contact by Email
If you contact us by email (for example at the addresses info@paless.eu or datenschutz@paless.eu), the data you provide (at least your email address, the content of your message and any further information you voluntarily provide, such as name, company or telephone number) is processed for the purpose of handling your enquiry and for possible follow-up questions. The website does not currently offer a contact form.
Legal basis: Article 6(1)(b) GDPR where your enquiry is aimed at the conclusion or performance of a contract, otherwise Article 6(1)(f) GDPR; our legitimate interest lies in responding to your enquiry.
Storage period: we delete the personal data arising in this context as soon as its storage is no longer necessary, as a rule no later than three years after the end of the calendar year of the last substantive correspondence, or we restrict its processing where statutory retention obligations exist.
5.5 Newsletter
On the website you can subscribe to our email newsletter, in which we inform you about the development, the launch (in particular the Kickstarter campaign) and new features of the "paless" service.
Registration uses a double opt-in procedure: after signing up you receive an email with a confirmation link; we add you to the mailing list only after your confirmation. We process your email address, optionally your name, and the time of registration and confirmation together with the IP address used, as proof of consent. The signup form is loaded only after you have consented, via the Klaro! cookie consent manager, to the integration of the Sender service required for this purpose.
Legal basis: your consent pursuant to Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future, for example via the unsubscribe link at the end of every newsletter email or by writing to marketing@paless.eu; the lawfulness of processing carried out before the withdrawal remains unaffected.
For sending the newsletter and providing the signup form we use the Sender service (Sender.net) of UAB Sender.lt, Lvivo g. 25, 09320 Vilnius, Lithuania (EU), as a processor pursuant to Article 28 GDPR. To evaluate and improve the newsletter, the service may measure whether and when newsletter emails are opened and whether links contained in them are clicked; this reach measurement is covered by your consent.
Storage period: until you withdraw your consent or unsubscribe from the newsletter.
5.6 Embedded Videos (YouTube)
We embed videos on the website that are hosted on the YouTube service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When the page is opened, initially only a preview delivered locally from our own website is displayed; no connection to YouTube or Google is established at this point.
Only when you actively start a video is the content loaded from YouTube in extended privacy mode via the domain youtube-nocookie.com. In the course of this, your IP address is transmitted to YouTube or Google and cookies or similar technologies may be set; this may involve a transfer to the USA (Section 9). The legal basis for this loading is the consent you give by clicking (Article 6(1)(a) GDPR).
We have no influence over the further processing by Google; for details, please see Google's privacy policy at https://policies.google.com/privacy.
6. Processing in Connection with the "paless" Service
The "paless" service is a software-based document management solution with integrated artificial intelligence components. These include text recognition (OCR) of uploaded documents, semantic tagging and AI-supported classification, as well as the dialogue-based assistant "Pal", which finds and summarises documents and, at the customer's instigation, creates drafts, for example for emails or for filling in forms. The service is currently in the pre-market stage; the following information applies to the use of the service from the time it is made available. Personal data is processed in different roles in this context (Sections 6.1 to 6.4).
6.1 Account and Contract Data (Own Responsibility)
In the course of initiating and performing the contract for the use of the service, the controller processes, under its own responsibility, in particular the following categories of personal data:
- master data: name, company, address, legal form, where applicable commercial register and VAT identification numbers of the contracting parties and of the contact persons named by the customer
- contact and login data: email addresses, telephone numbers, login identifiers of the user accounts
- contract and billing data: contractually agreed services, booking and plan information, payment and invoicing data
- usage and support metadata: date and type of support services used, tickets, correspondence in the course of contract performance
Purposes: initiation, conclusion and performance of the contract, provision and billing of the agreed services, compliance with legal obligations and communication with the customer. Legal bases: Article 6(1)(b) GDPR (performance of the contract), Article 6(1)(c) GDPR (compliance with legal obligations, in particular under commercial and tax law) and Article 6(1)(f) GDPR (legitimate interest in ensuring the secure operation and further development of the service). Storage period: master, contract and billing data is stored for the duration of the contractual relationship and for the duration of the applicable statutory retention periods (in particular 6 or 10 years under § 257 of the German Commercial Code (HGB) and § 147 of the German Fiscal Code (AO)); support metadata is as a rule deleted no later than three years after the respective matter is closed.
6.2 Customer Content (Processing on Behalf of the Customer)
Where, in providing the service, the controller processes personal data for which the customer is the controller within the meaning of Article 4(7) GDPR (in particular personal data contained in the documents uploaded to the service by the customer and the associated metadata), the controller acts as a processor within the meaning of Article 4(8) GDPR. Processing takes place exclusively on the documented instructions of the customer.
Content is placed in the service at the customer's instigation via the channels chosen by the customer, in particular by direct upload, by ingestion from an email mailbox of the customer (mail ingest), from a cloud storage connected by the customer or from a network share provided by the customer. Uploaded documents undergo text recognition (OCR), which extracts content such as text and tables in order to make the documents searchable.
The data processing agreement (DPA), which is concluded with every customer as Annex 2 of the controller's GTC, is decisive. The DPA governs in particular the subject matter, duration, nature and purpose of the processing, the categories of data subjects and data, the obligations of the processor, the engagement of sub-processors, the technical and organisational measures pursuant to Article 32 GDPR and the procedure at the end of the contract.
In this constellation, the customer remains the controller under data protection law within the meaning of the GDPR. The obligation to inform data subjects about the processing (Articles 13, 14 GDPR) and to fulfil data subject rights rests with the customer; the controller supports the customer in this in accordance with the DPA.
6.3 AI-Supported Processing in the Service
The service contains AI systems within the meaning of Article 3(1) of Regulation (EU) 2024/1689 (AI Act). This concerns in particular the dialogue-based assistant "Pal" based on the retrieval-augmented generation (RAG) method, which answers questions about the customer's documents, creates summaries and, at the customer's instigation, generates drafts (for example for emails or for filling in forms), as well as embedding models for semantic search and classification and tagging models.
With regard to this processing, the controller warrants, in line with Section 10(3) and Section 12(4) of the GTC: customer content is used neither for training nor for fine-tuning the controller's own or third-party AI models. In the standard configuration of the service, inference of the AI models used takes place entirely on the controller's own infrastructure within the European Union; in the standard configuration, no customer content is transmitted to external AI providers. Should optional features that integrate external services be offered in the future, customers will be informed of this separately before any activation; without such activation, processing remains entirely within the European Union. Customer content is not passed on to third parties for the purpose of content analysis; only anonymised or pseudonymised operational metrics are collected.
Transparency notice pursuant to Article 50 of the AI Act: the assistant "Pal" is an AI system that interacts with the person using it. You are informed of this in the user interface before the first interaction.
6.4 Authentication
Login to the service takes place via a self-operated identity provider based on the OpenID Connect (OIDC) standard. For this purpose, the controller uses the open-source software Authentik on its own infrastructure within the European Union. No external identity service provider is involved; there is no separate sub-processor for identity management.
In the course of authentication, the identifiers required for login are processed, in particular username or email address, authentication factors (such as passkeys or hardware security keys), session and access tokens and the associated OIDC claims. Legal bases: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR (legitimate interest in secure access to the service).
7. Support via Kickstarter
We plan to finance the development of the service through a crowdfunding campaign on the Kickstarter platform. If you support us via Kickstarter, you conclude the pledge agreement via the platform; Kickstarter, PBC, 58 Kent Street, Brooklyn, NY 11222, USA, is responsible as an independent controller for the data processing on the platform. For details, please see Kickstarter's privacy policy at https://www.kickstarter.com/privacy.
In the course of handling the campaign, we receive from Kickstarter the backers' details required for this purpose, in particular name or username, email address, the chosen pledge level and your answers to closing surveys (such as the plan selected). We process this data to run the campaign, to grant the promised founder terms and for the associated communication. Legal basis: Article 6(1)(b) GDPR, otherwise Article 6(1)(f) GDPR (legitimate interest in the orderly handling of the campaign).
Our processing takes place on infrastructure within the European Union. Storage period: for the duration of the campaign handling and the granting of the founder terms, at most until the expiry of statutory retention periods (Section 10).
8. Recipients and Processors
To provide the service and operate the website, we share personal data with the following recipients, whom we have carefully selected and contractually bound to the level of data protection required by the GDPR:
- OVHcloud SAS (sovereign cloud offering), registered in France (EU): hosting, compute, object storage and backups for the "paless" service; data processing agreement pursuant to Article 28 GDPR.
- Bunny.net (BunnyWay d.o.o.), registered in Slovenia (EU): delivery of the marketing website paless.eu via a content delivery network, DNS services, and issuance and renewal of TLS certificates; data processing agreement pursuant to Article 28 GDPR.
- Sender (UAB Sender.lt), registered in Vilnius, Lithuania (EU): sending of the email newsletter and provision of the newsletter signup form (Section 5.5); data processing agreement pursuant to Article 28 GDPR.
Transactional emails of the service (such as account confirmations, password resets and system notifications) are sent by the controller by default via its own infrastructure; no external service provider is currently used for this. Should a service provider established in the EU be engaged in the future, a data processing agreement will be concluded beforehand and this policy as well as Annex 3 of the GTC will be updated. In addition, personal data may be shared with the controller's advisers (in particular lawyers, tax advisers and auditors) where this is necessary to safeguard legitimate interests or to comply with legal obligations; these recipients are subject to special statutory confidentiality obligations. Note on Hugging Face: the controller obtains AI model artefacts once, at build or setup time, from Hugging Face Inc. or Hugging Face S.A.S.; no personal data of the customer and no usage data is transmitted in the course of this, so Hugging Face is not a sub-processor within the meaning of Article 28 GDPR with regard to the live operation of the service. The current list of sub-processors used is set out in Annex 3 of the GTC ("List of Sub-Processors"). Customers are informed of changes in text form pursuant to Section 4 of the data processing agreement (Annex 2 of the GTC) at least four weeks before the planned change; they have a right to object in accordance with the DPA.
9. Transfers to Third Countries
The "paless" service is operated entirely on infrastructure within the European Union (sovereign cloud offering of OVHcloud SAS); for the operation of the website we likewise use only service providers established in the European Union. Personal data is transferred to countries outside the European Economic Area (third countries) only in the following exceptional cases:
- YouTube videos (Section 5.6): if you actively start an embedded video, a transfer to Google in the USA may occur. Google LLC is certified under the EU-US Data Privacy Framework; in this respect an adequacy decision of the European Commission pursuant to Article 45 GDPR is in place. In addition, the video is loaded only on the basis of your consent.
- Support via Kickstarter (Section 7): the campaign is handled via the platform of Kickstarter, PBC, established in the USA; Kickstarter is responsible as an independent controller for the processing on the platform.
Should a transfer to a third country become necessary in an individual case beyond this, it will take place exclusively on a legal basis under Chapter V GDPR, in particular on the basis of an adequacy decision of the European Commission (Article 45 GDPR), on the basis of appropriate safeguards such as the European Commission's standard contractual clauses (Article 46(2)(c) GDPR), supplemented by additional measures where appropriate, or on the basis of your explicit consent pursuant to Article 49(1)(a) GDPR after you have been informed of the associated risks. Data subjects will be informed of any such transfer in an appropriate manner.
10. Storage Periods
Personal data is stored only for as long as is necessary to achieve the respective processing purposes or as required by statutory retention obligations. Once the purpose ceases to apply or the retention period expires, the data is routinely deleted or its processing is restricted. In detail, the following standard periods apply in particular:
- server log files (Section 5.1): a maximum of 30 days; in the event of security incidents, until final clarification.
- email correspondence (Section 5.4): until the enquiry has been dealt with, as a rule no later than 3 years after the end of the calendar year of the last substantive correspondence.
- newsletter data (Section 5.5): until consent is withdrawn or you unsubscribe from the newsletter.
- account and contract data (Section 6.1): for the duration of the contractual relationship; thereafter retention within the scope of legal obligations (in particular 6 or 10 years under § 257 HGB and § 147 AO).
- customer content in the service (Section 6.2): in accordance with the data processing agreement and Section 11 of the GTC (data export and provider switching under the Data Act); deleted content is removed from backups after expiry of the documented rotation cycles (incremental backups 30 days, full backups 90 days, cf. Annex 3 of the GTC).
- authentication and session data (Section 6.4): for the duration of the active session and the configured token lifetime; audit-relevant authentication logs in accordance with the technical and organisational measures (Appendix A of Annex 2 of the GTC).
- Kickstarter backer data (Section 7): for the duration of the campaign handling and the granting of the founder terms, at most until the expiry of statutory retention periods.
11. Rights of the Data Subject
You have the following rights vis-à-vis us with regard to the personal data concerning you:
- right of access (Article 15 GDPR): you may request information on whether and which personal data we process about you, as well as the further information listed in Article 15(1) GDPR.
- right to rectification (Article 16 GDPR): you may request the rectification of inaccurate personal data concerning you or the completion of incomplete personal data.
- right to erasure (Article 17 GDPR): you may request the erasure of personal data concerning you where one of the grounds listed in Article 17(1) GDPR applies and no exception under Article 17(3) GDPR is relevant.
- right to restriction of processing (Article 18 GDPR): you may request the restriction of processing of personal data concerning you under the conditions set out there.
- right to data portability (Article 20 GDPR): you have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and to transmit that data to another controller or have it transmitted directly, where technically feasible.
- right to withdraw consent (Article 7(3) GDPR): where processing is based on consent you have given, you may withdraw that consent at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
- right to lodge a complaint with a supervisory authority (Article 77 GDPR): without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.
To exercise the above rights, an informal message to the contact details stated in Section 1 is sufficient, preferably by email to datenschutz@paless.eu. To verify your identity, we may request appropriate proof. Your right to object under Article 21 GDPR is set out separately in Section 12.
12. Right to Object (Article 21 GDPR)
Where we process personal data on the basis of Article 6(1)(f) GDPR (legitimate interest), you have the right to object to the processing at any time on grounds relating to your particular situation. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
No processing for direct marketing purposes on the basis of Article 6(1)(f) GDPR takes place; our newsletter is sent exclusively on the basis of your consent (Section 5.5).
The objection may be declared informally, preferably by email to datenschutz@paless.eu.
13. Competent Supervisory Authority
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) — State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Postfach 20 04 44
40102 Düsseldorf
Germany
Phone: +49 211 384 24-0
Email: poststelle@ldi.nrw.de
The authority named above is the data protection supervisory authority responsible for the controller.
The right to lodge a complaint exists without prejudice to any other administrative or judicial remedy and may in particular also be exercised with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement (Article 77(1) GDPR).
14. Data Security
We take appropriate technical and organisational measures within the meaning of Article 32 GDPR to ensure a level of protection appropriate to the risk for the personal data we process. These include in particular:
- state-of-the-art encryption of the communication between the device and the service (TLS 1.3 or higher)
- encryption of data at rest on the underlying storage media (AES-256)
- role- and permission-based access management following the principle of least privilege
- mandatory multi-factor authentication for administrative accounts
- tenant-based separation of the data of different customers
- regular backups with documented rotation and retention cycles
- logging of administrative and security-relevant events
- documented recovery plans and regular testing of the recovery procedures
- commitment of all persons involved in the processing to confidentiality
A detailed description of the technical and organisational measures used can be found in Appendix A of Annex 2 of the GTC (data processing agreement).
15. Automated Decision-Making and Profiling
No automated individual decision-making, including profiling, within the meaning of Article 22(1) GDPR that produces legal effects concerning the data subject or similarly significantly affects them takes place in the context of the service.
The AI-supported features described in Section 6.3 (text recognition, semantic tagging, AI-supported classification, the dialogue-based assistant "Pal") support the customer in managing, finding and working with their own documents, including the creation of drafts. They do not make decisions with legal effect vis-à-vis data subjects and do not similarly significantly affect them within the meaning of Article 22 GDPR. The decision on the use of the AI suggestions always remains with the customer; actions such as sending emails or releasing content are carried out only after explicit confirmation by the customer.
16. Changes to This Privacy Policy
We reserve the right to update this privacy policy if the legal situation, the service or the data processing changes. The current version is available on our website; it carries a version number and an effective date, and earlier versions remain available there.
In the event of significant changes, in particular changes that require renewed consent from the data subject, we will inform the data subjects separately in an appropriate manner.
The German version is authoritative.