Privacy notice
1. Responsibility and contact
Qunevo GmbH, Oestervenn 16, 33758 Schloß Holte-Stukenbrock, Germany, is the controller for website operations, account administration, contracting, security and voluntarily shared product feedback. Managing directors: Dr. Felix Johannes Grumbach and Stefan Görlitz. Contact for privacy requests: info@qunevo.com, +49 5207 957 3619.
The customer organization generally controls workspace content; Qunevo processes that content on its instructions under a DPA. Guests and employees may also contact the inviting organization. We help route requests appropriately.
2. Website, hosting and security
The application, its processing and key services, and PostgreSQL database run on Railway in US-West (SFO, United States). Requests involve IP address, time, requested path, browser/device information and technical status/error data. Session, authorization and abuse-prevention data are also processed. Legal bases are Article 6(1)(f) GDPR, our legitimate interest in reliable and secure operation, and Article 6(1)(b) where required to perform the usage contract.
Fonts and website images are served locally. Bloodhound currently embeds no Google Analytics, Vercel Analytics, advertising pixels or social-media trackers. External links connect to other services only when followed.
3. Cookies and browser storage
Storage is limited to what is necessary for requested features under section 25(2)(2) TDDDG. Subsequent personal-data processing rests on Article 6(1)(b) or (f) GDPR according to purpose. The cookie banner provides information and does not obtain consent to additional purposes.
| Storage | Purpose and duration |
|---|---|
| bloodhound-account.* (possibly with a Secure prefix) | Sign-in and session security; without Remember this device a session cookie and a server-side lifetime of at most 24 hours; when explicitly selected, up to 30 days, renewable during active use. Short-lived OAuth state is used only for an initiated third-party sign-in. |
| bh_<room ID> | Authorized room access, up to 30 days. Revocation and expiry are also checked on the server. |
| bloodhound-registration-terms | Signed evidence of your express business/terms confirmation during registration, up to 15 minutes; version and confirmation time are subsequently recorded with your account. |
| bloodhound-language / bloodhound-ui-language | Selected interface language; cookie up to one year, local storage until cleared. |
| bh-name, bh-rooms, bloodhound:room-navigation and room-specific navigation settings | Selected display name, recent rooms and navigation choices; locally until cleared. |
| bloodhound:open-rooms:<user ID> | Open rooms in session storage for the browser session. |
| bloodhound-privacy-notice | Acknowledgement with version, time and expiry; 180 days without extension merely by visiting pages. |
Reopen cookie settings from the website footer. If storage is blocked, acknowledgement lasts only for the current page. Browser data can be cleared at any time, which may remove sign-in and settings. Microphone and camera permissions can also be revoked in the browser. Any future optional services must require separate informed, revocable consent before loading.
When you expressly start a credit top-up, you move to Stripe's external checkout page. Bloodhound does not embed a Stripe payment script in its own website for this purpose. Stripe's cookie policy and privacy notice apply on that page; acknowledging necessary storage in Bloodhound does not give Stripe additional consent.
4. Accounts, organizations and communications
Updated legal information appears in the account workspace. We retain the latest notice version marked as read for each account; this is not consent to additional processing. For contractual changes explicitly requiring acceptance, an authorized organization owner can confirm their authority and accept the specific version. We record the organization, version, digest of the immutable published texts, timestamp and accepting account identifier. The account identifier is removed on account deletion; the organization-level evidence ends when the organization is deleted. While acceptance remains outstanding, we retain the first delivery time to calculate the notice period; this record is removed after acceptance or replacement of the notice. The legal bases are Article 6(1)(b) and (f) for contract administration and evidence of the agreed version. Marking a notice as read changes no feedback-sharing, microphone or other consent setting.
We process names, email addresses, password hashes, verification/session data, organization membership, roles, invitations, schedules and billing details. Billing details are optional for registration but required for a paid top-up. They are managed per organization under “Credit & payment”. Passwords are not stored in plaintext. Required account data enables registration and authentication; without it we cannot provide a personal account. Legal bases are Article 6(1)(b), or Article 6(1)(f) for employees of a customer to administer that business relationship.
Google or Microsoft sign-in is shown only when configured and starts only when selected. Authorized profile information and technical authentication data are exchanged. This does not grant access to the entirety of your mailbox, calendar or files.
Transactional email covers account verification, sign-in codes, password recovery, invitations, credit communications and invoices. Resend (Plus Five Five, Inc., United States) delivers these messages as a processor. Recipient addresses, subjects, message content and any calendar or invoice attachments are transmitted, and technical delivery information is generated. Open and click tracking are disabled in our sending configuration. Legal bases are Article 6(1)(b) or (f) GDPR for contract administration and communications, and point (c) for statutory invoicing duties. Support requests are processed under Article 6(1)(b) or (f). This does not subscribe anyone to a newsletter.
Verified accounts can enable sign-in by email code in personal settings as an alternative to their password. This is not two-factor authentication. The six-digit code expires after ten minutes, is invalidated after five failed attempts and can be used only once. A new code replaces the previous one. Codes are verified using a keyed hash; the encrypted mail payload is removed after sending or expiry. The option can be disabled at any time.
To provide and secure account operations, usage activity, organization attribution and timestamps are processed in per-minute records for 90 days; operator views provide activity and usage summaries. Conversation content is not collected for this purpose. The legal basis is Article 6(1)(f) GDPR, with the interest in reliable, accountable service operations. Outgoing mail content is removed from the queue after acceptance by the sending service; metadata for sent or failed jobs is cleaned up after seven days. Separately, Resend retains email content and delivery logs under its retention rules: 30 days on standard plans, or as separately agreed on Enterprise. Messages in recipient mailboxes and invoices subject to statutory retention have separate retention periods.
5. Workspaces, media and AI
The customer organization determines the purpose and legal basis for room processing. Data includes participant names, contributions and chats, transcripts, uploaded documents and extracted text, topics, insights, references, tasks and results. Room content is stored with application-level encryption in PostgreSQL; authorized background services decrypt it for requested processing.
Audio, video and screen sharing are media-encrypted between authorized browsers and the Bloodhound service permitted to perform speech functions. LiveKit Cloud relays encrypted media and processes connection and participant metadata. You initiate device permissions. When speech processing is enabled, the Bloodhound service decrypts audio for submission to OpenAI; transcripts are stored in the room. Media encryption hides content from the relaying media server, not from authorized participants or the instructed speech service. Ordinary conferencing does not include permanent video recording.
The processing mode controls transcription, knowledge building and AI collaboration. Manual AI chat requests require AI collaboration; switching to a more restricted mode stops running tasks no longer permitted there. Explicitly started AI setup authorizes a single recording of up to 120 seconds, transcription and preparation of the room form, even without ongoing meeting AI. Team chat is not ordinary AI context.
AI functions use the OpenAI API. Depending on the task, audio, text, selected document excerpts, room context and technical request data are transmitted. Web research may additionally submit searches derived from the task; speech generation processes answer text. Personal AI help submits your question, the associated help history and documentation excerpts. It does not independently access meeting knowledge. Help histories are separated per user and organization or participant and room, stored encrypted, and can be downloaded or deleted by the authorized user. They are added to neither team chat nor operator feedback.
For text responses, the application does not request storage as a retrievable OpenAI response object. This does not exclude separate security logs or technically necessary caching by the provider. Depending on API and feature, the OpenAI data controls describe default abuse-monitoring logs for up to 30 days and possible legal or safety exceptions. This does not promise an individual zero-retention agreement. Provider regions, retention and contractual safeguards must be specified in the DPA deployment record. Bloodhound itself makes no solely automated decisions with legal or similarly significant effect within Article 22 GDPR.
Read API integrations
A user-created API token grants only selected read permissions within the issuer's current authorization and expires within 90 days. External rooms require explicit selection and remain subject to guest access rules. Permitted room data or original files are transmitted to the system selected by the customer. Private help dialogs, operator feedback and billing data are excluded from the read API. Content-free access logs with token, organization and room identifiers, resource and time, and deletion/change notifications are retained for 90 days to secure access and synchronize copies. Security logging relies on Article 6(1)(f) GDPR; content is transmitted under the customer organization's instructions. Revocation blocks future access but does not delete copies already exported to another system.
6. Voluntary technical feedback
Category sharing and the additional sharing of product feedback text are separate. Category sharing is enabled for new organizations and can be disabled. After month end it releases fixed technical categories and coarse frequencies with contributions from at least five organizations, without text, source or tenant identifiers. Group size alone does not prove anonymity; reidentification risks require regular review.
Text sharing requires new, explicit activation by an authorized organization owner. Previous category settings do not authorize text access. Short product descriptions from new, already processed feedback by signed-in participants are then shared automatically without per-report approval. Full conversations, original documents and evidence excerpts are not part of this feed. Known names, contact details, room and organization labels are removed; personal data may remain. Internal source links allow withdrawal and source deletion to remove copies. Copies use application-managed encryption at rest and authorized operators can read them. This is not end-to-end encryption against the operator.
Qunevo controls the separate purpose of debugging and product improvement, not advertising or general-purpose model training. Reliance on Article 6(1)(f) GDPR requires a defensible, documented balancing assessment. Where consent is required, obtain it separately before processing or disable the feature. Organizations inform all participants, including external guests, and establish the legal basis for their processing. Neither this setting nor a yes/no clarification of product attribution replaces consent.
Signed-in individuals can block text sharing of their contributions in personal settings. Contributions from guests who are not signed in are not shared as text. Erasure, restriction and objection requests immediately block sharing of the requester's feedback text; other requested measures require separate review. Disabling the feature or an individual objection removes affected active operator copies. Source deletion or modification withdraws related copies. Remaining copies become inaccessible after 30 days and are deleted by the hourly cleanup. Backups and earlier disclosures remain part of the erasure review.
An additional option, disabled by default, enables automatic technical diagnostic cases from new activity: queue, execution, transcription and response times, job and retry counts, bounded error categories, and model, tariff and software versions. Operators can associate cases with the organization, room and job, so they are not anonymous. Conversations, documents, prompts, credentials and full error messages are excluded. Personal objections apply; rooms with unsigned guests are excluded. Sharing applies only to new activity, can be withdrawn at any time and permits neither advertising nor general-purpose model training. Access ends after 30 days; expired copies are deleted hourly. The same information duties and legal-basis requirements as for text feedback apply.
7. Credit, billing and retention
Organization and billing information (particularly legal name, address, billing email and any VAT identification number), top-ups, reservations, usage, prices, payment status, booking references and refunds are processed to perform the contract under Article 6(1)(b) GDPR, or point (f) for a customer's contact persons. Tax and commercial records are retained under Article 6(1)(c). Duration depends on record type, particularly section 14b UStG, section 147 AO and section 257 HGB: invoices and accounting vouchers generally eight years, other records sometimes six or ten years. Invoice retention starts at the end of the year of issue; statutory extensions may apply.
When a payment starts, we transmit the billing email, legal name, order reference, amount, currency and service description to Stripe. On its external checkout page, Stripe collects payment and security information, including card details and device/connection information. Bloodhound receives payment references, status and any refund information; we do not store full card details. Stripe Payments Europe, Limited and Stripe Technology Europe, Limited (Ireland) provide the payment services. Stripe processes data partly on our behalf and partly as an independent controller, particularly for fraud prevention, regulatory duties and work with payment networks. Further information, including Stripe's own retention criteria and data subject rights, is available in Stripe's privacy notice.
The PDF invoice generated by Bloodhound is sent through Resend to the configured billing email, with a copy to invoice@qunevo.com for Qunevo's accounting. An encrypted invoice copy and the corresponding payment records remain on the infrastructure described in section 2, separately from the short-lived mail queue. Billing profile changes do not alter historical invoices. Refunds generate corresponding correction documents.
Operational room content is not retained solely for tax purposes. Organization deletion separates that content from required payment evidence. Creating an uncompleted payment order does not itself make that order subject to invoice retention; continued storage must be limited to necessary payment reconciliation, abuse investigations or specific claims.
8. Recipients and international processing
Technical providers include Railway Corporation (hosting/database), OpenAI (AI/transcription/speech), LiveKit (real-time communication) and Resend / Plus Five Five, Inc. (transactional email). Stripe receives the payment data described in section 7, not conversation content. Google or Microsoft may additionally act as your selected identity provider. These providers or their subprocessors may process data in the US and other third countries. There is no blanket EU data-residency commitment.
Resend's active sending region is US East (us-east-1); Resend stores customer data in the United States. Its data processing agreement forms part of its service terms and includes EU Standard Contractual Clauses for applicable third-country transfers. Stripe may also process payment data internationally; its Privacy Center describes the relevant agreements and transfer safeguards. An Irish contracting entity does not mean that all processing takes place in the EU.
Transfers must meet Articles 44 et seq. GDPR, for example an applicable adequacy decision for the actual recipient or agreed EU Standard Contractual Clauses with necessary supplementary measures. Naming a provider does not establish certification or an executed agreement. Information about recipients, regions and safeguards for your deployment and copies of relevant safeguards are available from info@qunevo.com. Specific approval is documented in the DPA annex.
9. Retention and safeguards
Room content is processed during agreed use and under the customer's deletion instructions. Authorized users can delete documents, rooms or organizations. Account and contract data is retained only as needed, subject to statutory duties or establishing or defending specific claims. Provider logs, backups and external exports have their own deletion cycles; binding periods for each deployment must be specified in the DPA deployment record.
Stored room texts, original files, preparation, working states and results, including their protected histories, use authenticated AES-256-GCM encryption. Keys and content are bound to the organization, room and record. A separate key service checks permissions and processing tasks. The application additionally encrypts protected content requests and responses between the browser or SDK and the processing service; the web service relays them encrypted. Public connections also use HTTPS. Personal help histories have separate user-bound keys.
Authorized processing services and instructed AI providers need readable content to perform requested features. Qunevo manages infrastructure and keys; privileged administrators are not technically excluded from access. Human support access requires documented express authorization, subject to mandatory legal obligations. Account identities, organization name and design, billing data, access identifiers and operational metadata are not part of room encryption.
A deletion ledger kept separately from database backups retains identifiers necessary for access denial and restore protection. After a restore, these denials are reapplied before application access is enabled. Minimal deletion identifiers remain necessary for as long as relevant backups could be restored. This prevents renewed availability through the application; it does not physically erase all provider backups or previously exported copies. Their removal or expiry is separately reviewed in the erasure process.
Privacy requests in your account
Signed-in users can request erasure, access, rectification, restriction, objection and portability in personal settings. A warning, entry of the account email address and explicit acknowledgement precede submission. Receipt, progress, the usual one-month deadline and replies appear in the account. Before account deletion, export content you need and save the case reference. Sole organization owners must first transfer responsibility or separately close the organization.
Once ownership is resolved, automatic erasure starts without further operator approval. It blocks account access and removes attributable contributions, files, private help histories, feedback copies and derived content; this can change shared work. Other people's contributions are not removed indiscriminately. Additional free-text mentions, recipient copies, providers, backups and statutory retention are reviewed separately. An internally applied erasure therefore does not mean the entire rights case is complete. After access is blocked, and for people without an account, info@qunevo.com remains available.
Request details and replies are stored with application-managed encryption, are accessible to authorized case handlers and are removed by hourly cleanup 180 days after closure. This supports fulfillment and evidence of data-subject rights under Article 6(1)(c) GDPR. Statutory exceptions and other people's rights are assessed and explained individually.
10. Your rights
Subject to statutory conditions, you may request access, rectification, erasure, restriction or portability and complain to a supervisory authority. Qunevo's competent authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia. You may also contact another competent authority.
Objection: You may object under Article 21 GDPR to processing based on Article 6(1)(f) for reasons relating to your particular situation. Any consent may be withdrawn prospectively without affecting the lawfulness of prior processing. Contact info@qunevo.com. We require only identity evidence needed to handle your request securely. For customer-controlled data, we assist the responsible organization.