KI-Denkraum
Privacy policy
Which data we process, what for, who receives it and how long we keep it.
Version of 4 October 2026 · identifier denkraum-datenschutz-2026-10-04
This is an earlier version. In force is the version of 10 October 2026.
This English text is a translation for information purposes. Only the German version is authoritative: Datenschutzerklärung.
This policy applies to the KI-Denkraum Platform at kidenkraum.com. It tells you which personal data we process, for what purpose, on which legal basis, to whom it goes and for how long we store it (Art. 13 and 14 GDPR). For the company website de.lennartgehl.com, its own privacy policy applies.
1. Controller and contact
The controller for data processing on the Platform is:
lennartgehl.com GmbH
Hans-Henny-Jahnn-Weg 53
22085 Hamburg, Germany
represented by the managing director Lennart Maximilian Gehl
Telephone: +49 176 40781724
Email: hallo@kidenkraum.com
This address also applies to all questions about data protection.
We have not appointed a data protection officer because, in our current assessment, there is no obligation to do so (Art. 37 GDPR, § 38 of the German Federal Data Protection Act (BDSG)).
A special rule applies to teams: for teams and the accounts of their members, we act on behalf of the business that pays for the team subscription (section 10).
2. The key points in brief
The KI-Denkraum is an online platform with curated insights from podcast conversations about AI in companies. The service is aimed only at businesses. We process personal data only insofar as we need it for the operation of the Platform, your account, billing, security and legal obligations.
- We do not use any analytics, advertising or tracking services and do not create usage profiles.
- We do not store what you read, search for, save or download against your account. Your saved list stays in your browser.
- We do not use your data to train AI models. An AI model is used in two cases only: if you search with full access, a model from Cohere converts your search term into a sequence of numbers, without reference to your account (section 5). If we handle an enquiry from you or an error, Claude can help us (section 11). Both run via Amazon Web Services in the EU, without storage and without training.
- The Platform does not embed any players and does not load fonts or images from third-party servers. Even the podcast covers are delivered by our own server (section 4). The only thing your browser loads from a third-party server is Cloudflare’s bot protection at registration and password reset (section 7).
- You use the preview without an account and without providing any details about yourself.
What applies to you depends on how you use the KI-Denkraum: with your own account in the trial or with your own subscription (sections 7 to 9), as a member of your business’s team, or as an invited person who has not yet accepted the invitation (section 10).
Contractual basis. We conclude contracts for the KI-Denkraum with businesses. If you are the contracting party yourself, for example as a sole trader, we process the data for the account and the contract under Art. 6(1)(b) GDPR. If you act for a business, we rely on Art. 6(1)(f) GDPR; our legitimate interest is to perform the contract with your business and to provide you with an account for that purpose. In the following sections, this is referred to in short as the “contractual basis”.
3. Accessing the Platform and hosting
The Platform runs on Vercel. The server functions operate in Frankfurt am Main. Vercel delivers pages and files via its worldwide server network, usually from a location near you.
- Data: IP address, date and time, requested address, status code and browser identifier (details of browser and operating system). For individual events such as registration, sign-in, purchase or errors, our application writes short entries about them, for example the identifier of your account. Email addresses appear in them only in shortened form.
- Purpose: to deliver pages, find errors, and fend off attacks and misuse. For this, the application counts requests per IP address, for example at most five per minute at registration. This count is held only in the server’s working memory and is not stored.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the Platform.
- Recipients: Vercel Inc., USA, as processor (section 13).
- Retention period: Vercel deletes these logs automatically, on our plan after 30 days at the latest.
4. Cover images and links to podcast platforms
Cover images. The images of the podcast episodes come from the podcasts’ public feeds. There the podcasts themselves provide them for podcast apps and directories. Our server fetches them there and delivers them itself. Your browser does not connect to the podcasts or their providers for this, and they learn nothing about you. We find out which image belongs to an episode through the podcast data service Podscan. Here too, no data about you goes to third parties.
Links. Links to Spotify, Apple Podcasts and other platforms lead to external services. Only when you click a link does your browser connect to the respective provider. That provider’s privacy information applies there.
5. Search
With “Search” in the page header and the search field on the overview, you search all rooms of the KI-Denkraum.
- Data: your search term, your IP address, whether you have chosen a room, and whether you are signed in and have full access.
- Without an account and without full access, only our server searches for the words you entered and shows how many hits there are. No AI model is used.
- With full access (trial or subscription), an AI model additionally converts your search term into a sequence of numbers that describes its meaning. This lets the search also find conversations that use different words from yours. For this we use the Embed model from Cohere via the Amazon Bedrock service of Amazon Web Services, processed in data centres in the EU. Only the search term is transmitted, without any identifier of your account. Under AWS’s commitments, the search term is not stored there, not passed on to Cohere and not used for training. Our server keeps the sequence of numbers in memory for up to one hour so that the same search does not have to be converted again; we do not write it to disk. If the model does not answer in time, the search shows only the hits for the words you entered.
- Purpose: showing you matching key findings, conversations and use cases, and preventing misuse. For this the application counts searches per IP address, without an account at most 20 per minute, for example. This count is held in memory only.
- Logs: The search term is part of the requested address and therefore remains in Vercel’s logs for at most 30 days (section 3). Our application logs only figures and attributes per search, without the search term: the type of access, the number of hits, the duration, and whether a suggested question, a room or the AI model was involved.
- Legal basis: with an account, the contractual basis (section 2); if your access runs via a team, we process the search on behalf of your business (section 10); without an account, Art. 6(1)(f) GDPR; our legitimate interest is to show visitors what the KI-Denkraum holds on their question. Section 3 applies to the count per IP address.
- Recipients: Vercel Inc. (section 3); with full access, Amazon Web Services EMEA SARL as processor (section 13).
- Retention period: We do not store search terms against your account or in logs of our own; they remain in Vercel’s logs for at most 30 days.
6. Cookies and browser storage
We store in your browser only what is strictly necessary for the Platform. There are no analytics or advertising cookies. That is why we do not need consent. The cookie notice only informs you and does not switch anything on.
| Entry | Type | Purpose | Duration |
|---|---|---|---|
sb-…-auth-token (in several parts if needed) | Cookie, only after sign-in | keeps you signed in | until you sign out, at most 400 days |
ki-denkraum-bibliothek-… | Local storage (localStorage) | your saved list: identifiers of saved episodes and use cases per edition | until you empty it or delete your browser data |
ki-denkraum-cookie-notice-v1 | Local storage | remembers, without a user identifier, that you have acknowledged the cookie notice | until you delete your browser data |
ki-denkraum-vorschau-hinweis | Session storage (sessionStorage) | remembers that you have seen the preview notice | until you close the tab |
google_oauth_state, google_oauth_redirect | Session storage, only when signing in with Google | security value against forged sign-in requests, return address | until you return from Google, at the latest until you close the tab |
The application never transmits the saved list or the acknowledgement of the notice to a server.
- Legal basis: for storing and reading out, § 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), because the entries are strictly necessary for the functions you wish to use. For the sign-in data, the contractual basis (section 2); for the notices, Art. 6(1)(f) GDPR; our legitimate interest is not to show notices again on every visit.
Via “Cookie notice” in the footer, you can open the notice again at any time. You can delete all entries via your browser settings; without the sign-in cookie, you sign in again.
7. Account and registration
Registration. For an account, you provide your name, your business email address and the name of your business. The Platform does not accept addresses from free email providers such as gmail.com because the service is aimed only at businesses. We send you a confirmation link that is valid for one hour; after that, you set your password. Supabase stores the password only as a hash; we do not know it. If you register from an invitation, the invited address applies, and there is no confirmation email because the invitation already went to that address. For members of a team, section 10 also applies.
- Data: name, email address, business, language, password hash; times of the registration steps (start, sending of the link, confirmation, first sign-in) and of the last sign-in. For each session, Supabase stores IP address, browser identifier and times; Supabase also logs the sign-in events.
- Purpose: to set up and provide the account, secure the sign-in, and detect errors in registration and delivery.
- Legal basis: for the account, the contractual basis (section 2). For registration steps, session data and sign-in logs, Art. 6(1)(f) GDPR; our legitimate interest is a working and secure sign-in.
- Recipients: Supabase (database and sign-in), Vercel (hosting), Postmark (emails, section 11).
- Retention period: account data and registration steps until you delete your account (section 12). Session data until you sign out or the account is deleted. Supabase keeps sign-in logs for seven days on our plan.
Bot protection with Cloudflare Turnstile. On the registration page and on the page for resetting your password, your browser loads Turnstile from Cloudflare. Turnstile checks whether a human is submitting the form and for this processes your IP address, your browser identifier, technical characteristics of the connection and the address of our page. Our server sends the result together with your IP address to Cloudflare for verification. Cloudflare checks on our behalf and additionally processes individual signals under its own responsibility in order to improve bot detection.
- Legal basis: § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR. Our legitimate interest is protection against automated registrations, against automated password reset requests and against misuse.
- Recipients: Cloudflare, Inc., USA (section 13).
Confirmation as a business. At registration, after a sign-in with Google before the start of the trial, at the first sign-in of an already existing account and before the purchase, you confirm that you act for a business and not as a consumer. For this, we store the time, the wording of the confirmation, the applicable version of the Terms, your account, your email address, the name of your business, your IP address and your browser identifier.
- Purpose: to prove that the contract was concluded with a business.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is evidence of the conclusion of the contract and the defence against claims.
- Retention period: for the term of the contract and thereafter until the limitation periods expire (section 14).
Sign in with Google. Instead of using a password, you can voluntarily sign in with your Google account. Your browser switches to Google for this. After your approval, Google transmits to us your name, email address, Google identifier and a link to your profile picture. Here too, the Platform accepts only business addresses. If you sign in with a private address, an account is created all the same, because the sign-in at Google is completed before we can check the address; we delete this account by the following day at the latest. You add the name of your business in the next step.
- Legal basis: contractual basis (section 2), because you choose this way of signing in.
- Responsibility: Google Ireland Limited is itself responsible for the sign-in at Google. Google may transfer data to the USA (section 13).
- Retention period: the link with Google remains stored until your account is deleted.
8. Trial
With your first sign-in to the KI-Denkraum, a free trial of 14 days begins, once per account and without payment details. It ends automatically and at no cost.
- Data: start, end and status of the trial for your account.
- Purpose: to activate access, grant the trial only once per account, and inform you by email about three days before the end and at the end.
- Legal basis: contractual basis (section 2).
- Retention period: until your account is deleted; thereafter without any link to a name or email address (section 12).
9. Subscription, payment and invoices
Payment is made via Stripe. When you buy, you switch to Stripe’s checkout (Stripe Checkout). There you enter your name or company name, email address, billing address, your VAT identification number if applicable, and your payment details. Stripe calculates the VAT, processes the payment, creates the invoices as PDFs and operates the customer portal in which you cancel, change the payment method and retrieve invoices.
- Data held by us: Stripe customer number, email address of the paying account, plan, status and term of the subscription, number of seats and payment status. Before the purchase, we create a customer at Stripe with your name and email address. We do not receive complete payment details such as card numbers. At the time of purchase, we also store which version of the Terms and of the data processing agreement applied.
- Purpose: to conclude and perform the contract, process payments, issue invoices, fulfil accounting and tax obligations, and send emails about the subscription (section 11).
- Legal basis: contractual basis (section 2). For retention, Art. 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code (AO), § 257 of the German Commercial Code (HGB) and § 14b of the German VAT Act (UStG).
- Recipients: Stripe Payments Europe, Limited, Ireland. Stripe is itself responsible for fraud prevention, security, legal obligations such as anti-money-laundering checks and the further development of its services; for these, Stripe’s privacy policy applies. Stripe may transfer data to companies of the Stripe group in the USA (section 13).
- Retention period: subscription data for the term of the contract, invoices and accounting records according to the statutory periods (section 14).
10. Teams and invitations
Who is responsible for what. An account with a paid subscription can create a team. The team subscription is paid by the owner’s business. Owners and admins of the team decide whom they invite, which role someone gets and who leaves the team. For this team management, we process the data on behalf of the business (Art. 28 GDPR). The basis is the data processing agreement, which applies as an annex to our Terms upon purchase. The controller for team management is therefore the business. Its legal basis is usually its legitimate interest in providing employees with access (Art. 6(1)(f) GDPR). As long as your access runs via the team, we also process your account, your sign-in, your search and the emails about the account and the invitation on behalf of your business (DPA § 2). We ourselves remain responsible for the security of the Platform as a whole, billing with your business, legal obligations, and for your account before the invitation and after the end of your team membership (DPA § 4 and § 10(3)).
What your team sees. Owners and admins see the names, email addresses and roles of the members as well as open invitations with address, role and expiry date. Members see the team and their own role. Your team does not see what you read, save or download, because we do not store it.
Team management in detail.
- Data: name of the team; memberships with role (owner, admin, member) and time; invitations with email address, role, inviting person, times and a random invitation code; a log of changes in the team (invitation, resending, withdrawal, acceptance, removal, change of role) with time, acting person and affected address.
- Purpose: to provide access via the team, to book and bill seats (each invitation immediately books a seat; open invitations count too), and to make changes in the team traceable.
- Recipients: Supabase, Vercel and Postmark for the invitation email. Stripe learns only the number of seats, not who occupies them.
- Retention period: memberships until someone leaves the team, is removed or deletes their account. For invitations and the log, see section 14.
Information for invited persons (Art. 14 GDPR). If you have received an invitation to a team, the following applies to you:
- Source: your business email address was entered by a person from your business who is an owner or admin of a team in the KI-Denkraum.
- Data: your email address, the intended role, the team, the inviting person and the times of the invitation.
- Purpose: to deliver the invitation to you and to ensure that only this address can accept it.
- Responsibility and legal basis: on behalf of your business, as described above. We are ourselves responsible for ensuring that invitations go only to business addresses (Art. 6(1)(f) GDPR; our legitimate interest is protection against misuse).
- If you do not accept: the invitation is valid for seven days; after that, you can no longer accept it. We delete it 30 days after it expires (section 14). You can object to the processing (section 15), with your business or at hallo@kidenkraum.com.
If you accept the invitation, section 7 applies to your account, and your access runs via the team. If you leave the team or are removed, your account with the preview remains until you delete it (section 12).
11. Emails and contact
Emails to you. We send only emails that relate to your account, your subscription or an invitation: confirmation of registration, password reset, invitation to the team, notice about three days before the end of the trial, notice at the end of the trial, start of the subscription after a purchase during the trial, order confirmation and reminder before the renewal of an annual subscription. We do not send newsletters or advertising.
- Sending: via Postmark (AC PM, LLC, USA). Postmark processes email address, name, content, time and delivery status. We do not track whether you open an email or click links in it. Postmark reports to us whether an email was delivered or bounced; we store these reports with the registration steps.
- Legal basis: contractual basis (section 2) for emails about the account and the contract; for the invitation email, section 10 applies.
- Retention period: Postmark stores the content and metadata of the emails for 45 days (Postmark’s default setting). Postmark keeps addresses to which delivery was not possible, spam complaints and blocked recipients indefinitely so that no further emails go to these addresses.
Contact by email. If you write to hallo@kidenkraum.com, your message lands in our mailbox at Microsoft 365.
- Data: sender, content and time of your message and the details it contains.
- Purpose: to answer your enquiry.
- Legal basis: Art. 6(1)(b) GDPR insofar as you yourself are or wish to become a contracting party; otherwise Art. 6(1)(f) GDPR; our legitimate interest is the handling of business enquiries.
- Recipients: Microsoft Ireland Operations Limited as processor (section 13).
- Retention period: until the enquiry has been dealt with; business letters relating to a contract for six years (§ 257 HGB).
AI assistance for support and operations. If we handle an enquiry from you, an invitation that does not arrive or an error in your account, an AI model may help us, for example when looking up the data of your account. For this, we use exclusively Claude via the Amazon Bedrock service of Amazon Web Services, processed in data centres in the EU, and only in a separate working session set up specifically for this purpose.
- Data: the details needed for the case, for example name, email address, team and times.
- Purpose: to answer enquiries, and to find and fix errors.
- Legal basis: contractual basis (section 2); when searching for errors, also Art. 6(1)(f) GDPR; our legitimate interest is a functioning operation.
- Recipients: Amazon Web Services EMEA SARL as processor (section 13). AWS does not store the inputs and outputs, does not pass them on to the developer of the model and does not use them for training.
- Retention period: we delete the history of such a session on our encrypted computer as soon as the session ends.
12. Data export and account deletion
Data export. On your account page, you download a file in JSON format via “Download your data”. Among other things, it contains your profile, your registration data, your team memberships, invitations sent and received, and your customer record (Art. 15 and 20 GDPR). In addition, you can obtain full information about your data at any time via hallo@kidenkraum.com.
Deleting your account. On your account page, you delete your account yourself. This is possible as soon as your own subscription has been cancelled or you have none, and you are not the sole owner of a team whose subscription is still running. The free trial does not prevent this. Upon deletion
- we delete your sign-in account with email address, password hash, sessions and Google link, your registration data and registration steps, and your team memberships. Your seat in the team is freed in the process.
- we anonymise your profile as well as the customer and subscription data. We remove the name and email address; the entries themselves are retained without any link to you because accounting and tax law require their retention. Invitations you have sent remain with the team, but without any reference to you.
- we retain: records of the confirmation as a business and of the acceptance of the contract, with email address and business, until the limitation periods expire (section 14).
- the customer record remains at Stripe together with the invoices, insofar as Stripe and we are obliged to retain them.
Logs at Vercel, Supabase and Postmark expire according to their periods (section 14). You delete your saved list in your browser.
13. Recipients, processors and transfers to third countries
We pass on personal data only insofar as it is necessary for the purposes stated. We have concluded contracts under Art. 28 GDPR with our processors; they process the data only on our instructions.
| Provider | Task | Role | Third country and basis |
|---|---|---|---|
| Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Hosting, server functions in Frankfurt, logs | Processor | USA; DPF, additionally standard contractual clauses |
| Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513 | Database and sign-in; storage location Frankfurt (AWS eu-central-1) | Processor | Access from third countries possible; standard contractual clauses |
| Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland | Checkout, payment, invoices, VAT, customer portal | Partly processor (checkout, customer portal, tax), partly independently responsible (payment processing, fraud prevention) | USA (Stripe group); DPF, standard contractual clauses |
| AC PM, LLC (Postmark, ActiveCampaign group), 1 N Dearborn Street, Suite 500, Chicago, IL 60602, USA | Sending of emails | Processor | USA; DPF, standard contractual clauses |
| Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Turnstile at registration and password reset | Processor, partly under its own responsibility | USA; DPF |
| Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland | Mailbox hallo@kidenkraum.com | Processor | Access from the USA cannot be ruled out; DPF and contractual safeguards |
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg | AI assistance for support and operations (Claude via Amazon Bedrock); conversion of search terms with full access (Embed from Cohere via Amazon Bedrock) | Processor | Processing in the EU, no storage of inputs; Amazon in the DPF, additionally standard contractual clauses |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Sign in with Google, only if you choose it | Under its own responsibility | USA (Google LLC); DPF |
We base transfers to the USA on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (DPF) where the recipient is certified under it, and otherwise or additionally on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR). For Singapore, where Supabase has its registered office, there is no adequacy decision; the standard contractual clauses apply there. You can request a copy of the safeguards via hallo@kidenkraum.com; we reserve the right to make redactions required by law.
Further recipients may be: your business if you are in a team (section 10), as well as legal and tax advisers, banks, authorities and courts where there is a legal obligation or where it is necessary for the performance of the contract or for legal defence.
14. Retention periods at a glance
We store personal data only for as long as we need it for the respective purpose. After that, we delete it unless statutory retention obligations or the assertion of or defence against legal claims require further storage. In that case, we block the data for other purposes.
- Account and registration: until you delete your account (section 12); an account that a sign-in with Google created for a private address, by the following day at the latest (section 7); for entries in your browser, see section 6.
- Search terms: not against your account and not in logs of our own; in Vercel’s logs for at most 30 days (section 3).
- Invitations: 30 days after acceptance, withdrawal or expiry (an invitation expires after seven days).
- Team management log: twelve months after the respective entry.
- Data of a team after the end of its subscription: 30 days; after that, we delete the team, memberships, invitations and log. The members’ accounts remain until the members delete them themselves.
- Records of the confirmation as a business and of the acceptance of the contract: for the term of the contract and thereafter until the limitation periods expire, usually three years from the end of the year in which the contract ends.
- Invoices and other accounting records: eight years; books of account and annual financial statements: ten years; business letters: six years; in each case from the end of the calendar year (§ 147 AO, § 257 HGB, § 14b UStG).
- Logs at service providers: Vercel at most 30 days, Supabase seven days, Postmark 45 days for content and metadata of the emails.
15. Your rights
Subject to the statutory requirements, you have the right to
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object (Art. 21 GDPR, see below).
To do so, write to us at hallo@kidenkraum.com. We usually reply within one month (Art. 12(3) GDPR). For team management data that we process on behalf of your business (section 10), your business is the right point of contact. If you write to us, we forward the request to your business and support it in responding.
Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your data that we base on Art. 6(1)(f) GDPR. We will then no longer process this data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. We do not engage in direct marketing. An informal message to hallo@kidenkraum.com is sufficient.
Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State in which you reside or work or in which the alleged infringement took place. The authority responsible for us is:
The Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit)
Ludwig-Erhard-Straße 22, 7th floor
20459 Hamburg
Email: mailbox@datenschutz.hamburg.de
datenschutz-hamburg.de
16. Obligation to provide data and automated decisions
You are not legally obliged to give us data. You use the preview without providing any details. For an account, we need your name, your business email address, the name of your business and the confirmation as a business; for a purchase, additionally the details in Stripe’s checkout. Without these details, we cannot set up an account or conclude a contract.
We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR and do not create profiles. There are automatic checks at registration, invitation and password reset: whether an email address belongs to a free email provider and whether Turnstile classifies a registration or a password reset request as automated. If one of these checks wrongly stops you, write to us; we will then look at it personally.
17. Changes to this policy
We adapt this policy when the Platform, the services used or the legal requirements change. Each version carries its date and identifier at the top. The version published on the Platform is authoritative.