Needs.expert - Text Summary
Privacy Policy
1. Controller
2. Data Protection Officer
3. Scope
4. Data Protection Roles
5. Data Subjects and Categories of Data
6. Website, Server Logs and Security
7. Registration, Account and Workspace
8. Team Workspace and Visibility of Chats
9. AI Processing and Agents
10. No Model Training and No Routine Content Review
11. Proactive Suggestions, Workflows and Automated Actions
12. Connectors and External Systems
13. Voice Input and Voice Output
14. Public Agent Without Registration
15. Company Analysis and Publicly Available Sources
16. Data Regions and AI Providers
17. Recipients and Service Providers
18. Transfers Outside the EEA
19. Cookies and Consent Management
20. Audience Measurement and Marketing
21. Contact, Support and Newsletter
22. Billing and Stripe
23. Storage and Deletion Periods
24. Security and Access Control
25. Automated Decisions and AI Transparency
26. Your Rights
27. Provision of Data
28. Amendments to This Privacy Policy
4.1 Direct Use as a Business User
4.2 Use Through a Company
7.1 Registration and Onboarding
7.2 Organisation Assignment
7.3 Demo, Managed Service and Appointment Enquiries
22.1 Plans, Checkout and Stripe
22.2 Usage and Budget Records
22.3 Contract-Related Declarations and Records
Current version - 27 August 2026
The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:
Our Data Protection Officer is:
This Privacy Policy applies to needs.expert, the registered Workspace, public AI Agent interfaces, apps and APIs, as well as AI Agents, chats, workflows, voice features and Connectors activated by the user.
Needs provides an AI Agent Team. A coordinating AI Agent and specialist Agents can analyse content, create suggestions and drafts, work on tasks and, in accordance with the user’s settings, perform actions in connected systems. Visible names, roles, representations and areas of expertise may vary depending on the function, Workspace and configuration.
Marketplace, Need, Expert, Service, matching, brokerage and partner programme functions are currently not part of newly bookable services. To the extent that Needs continues to process personal data from previous use, such processing is carried out solely to settle existing legal relationships, comply with statutory retention obligations or defend legal claims in accordance with the periods specified in Section 23.
If you use Needs as an entrepreneur or for an organisation, Needs is generally the controller for processing required for registration, performance of the contract, service provision, security and billing.
For a company account, the following distinction must be made:
The applicable contract, including a data processing agreement, specifies this allocation of roles. The data protection role always follows the actual determination of purposes and means, not merely its designation in the contract.
Depending on how the service is used, we process data relating to website visitors, prospects, registered users, organisation members, invoice recipients, gift voucher recipients, communication partners and persons whose data is lawfully introduced into a Workspace or a connected system.
This may include:
Please do not provide special categories of personal data within the meaning of Art. 9 GDPR unless this is necessary for a lawful purpose and an appropriate legal basis exists.
When our website is accessed, we process in particular the IP address, time, requested address, amount of data transferred, referrer, browser, operating system, device information and HTTP status. This is necessary to deliver content, defend against attacks, analyse errors and ensure stable operation.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are the secure and uninterrupted operation of the Platform and the prevention of abuse. Access to the end device that is technically necessary is carried out in accordance with Section 25(2) no. 2 TDDDG.
Ordinary web server access logs are generally deleted after seven days or anonymised in such a way that they can no longer be linked to a person. Security-related events may be stored for longer in accordance with the periods in Section 23.
When an account is registered and used, we process the account, organisation, role, settings and contract data required for this purpose. For direct use, this is carried out in particular pursuant to Art. 6(1)(b) GDPR. For users of a company account, Needs’ own account, role and security processing is generally based on Art. 6(1)(f) GDPR; Needs may process work content on behalf of the company.
Required information is marked accordingly. Without the data required for the account, authentication, performance of the contract and security, we cannot provide the relevant service.
Depending on the selected entry route, during onboarding we process in particular the name, business email address, function, optional telephone and LinkedIn data, company name, website or domain, initial objective, onboarding progress, results of a requested website analysis and the desired number of Seats transferred from Pricing. The number of Seats is stored as a pre-contractual billing intention and checked again before Checkout.
If a prospect starts a business onboarding process with a company website and does not continue it for at least ten minutes, the business contact, company and progress data provided up to that point may be transmitted to our sales workflow system. This serves to assign and process the initiated request, clarify technical interruptions and make appropriate business contact. The legal bases are Art. 6(1)(b) GDPR and our legitimate interest in processing specific B2B enquiries pursuant to Art. 6(1)(f) GDPR. You may object at any time to contact based on Art. 6(1)(f) GDPR.
We compare the business email domain and the specified company website with existing organisations, invitations and pending assignment requests. If an existing organisation is identified, a membership or ownership request may be required instead of creating a new organisation. For this purpose, we process identity, contact, domain, invitation and status data and transmit the information required for review to authorised administrators of the organisation concerned. Pending invitations may be taken into account when determining occupied Seat capacity.
Administrators of a company Workspace can manage members, roles and organisation-wide settings. The scope of their permissions is displayed on the Platform. The company is responsible for adjusting permissions when an employee changes roles or leaves the company.
If a Microsoft Bookings link is opened or an appointment is booked there, Microsoft processes technical connection data and the contact, appointment and content data entered on the booking page; this may include name, email address, telephone number, desired appointment and additional information. Microsoft may also process confirmations, changes, cancellations and reminders relating to the appointment. The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR; our legitimate interest lies in the efficient handling of specific business enquiries. No additional consent under data protection law is required for a response requested by the prospect.
New chats in a company Workspace are generally created as shared unless the user marks them as private. Shared chats, files, results, tasks and team workflow outputs may be visible to the authorised group of recipients within the organisation identified in the interface. The current visibility should be displayed before the first input and during use.
Users can mark a chat as private. “Private” restricts visibility to other members of the organisation, but does not prevent technically necessary processing by Needs and the systems used. Workspace administrators do not automatically gain access to private chat content solely by virtue of their role.
Changing a chat from “shared” to “private” at a later date does not retroactively undo access that has already occurred by other authorised persons. Shared company content may remain in the company’s Workspace after a user leaves. Private content is not automatically transferred to other users.
Agents process inputs, the Workspace context approved for the task and, where applicable, content from connected systems. This may result in responses, summaries, drafts, tasks, files, recommendations or tool calls.
For direct use, the legal basis is generally Art. 6(1)(b) GDPR. In a company account, content may be processed on behalf of the company. Security, technical logging and abuse prevention are additionally based on Art. 6(1)(f) GDPR.
The user interface informs users that they are interacting with an AI system. AI outputs may be incomplete or incorrect and must be reviewed before important decisions are made.
Whether an Agent action forms part of automated individual decision-making depends on its specific purpose, process and actual effect. In the context of processing for which Needs is the controller, Needs does not make decisions based solely on automated processing which produce legal effects concerning a data subject or similarly significantly affect that person within the meaning of Art. 22 GDPR. If a corporate customer determines the purposes and means of its own decision-making process, it is the controller for that process.
We do not use customer content to train our own or third-party AI models. We do not use customer content to participate in optional training, feedback or evaluation programmes offered by model providers. For production AI processing, we select contractual and API terms that exclude use for training. Depending on the provider, processing route and contract selected, limited processing or temporary storage by the provider for security and abuse detection may nevertheless take place.
Needs employees do not routinely read or evaluate chats, documents, transcripts and AI outputs for quality control or product evaluation. Event data intended for product analysis generally contains no semantic content from chats, documents or audio recordings. Technical error, security or automation logs may contain more extensive data in justified exceptional cases; the access restrictions and deletion rules in this Privacy Policy apply to such data.
For an expressly commissioned Managed Service, authorised employees may process the configuration and content that the customer specifically provides or makes available for onboarding, ongoing assistance, Agent optimisation or support. Booking a Managed Service plan does not grant Needs blanket access to all private chats or documents. The scope, purpose and authorised group of persons are determined by the specific assignment; access is restricted to what is necessary and logged in accordance with the procedure applicable to the relevant system.
Outside the scope of the specifically commissioned Managed Service, strictly limited human access to customer content is permitted only if:
Human access to content is not part of ordinary support, product analysis or administrative operations. Persons with technical permissions may view content only in the specifically justified circumstances described above. Such access is purpose-bound, limited to what is necessary and logged in accordance with the access and audit procedure applicable to the relevant system.
Needs is not a zero-knowledge or end-to-end encrypted service. The application, Agent systems and commissioned AI providers must be technically capable of processing content in plain text in order to perform the processing.
Agents can proactively create suggestions based on the approved Workspace context. For this purpose, we process the relevant context, settings, previous tasks and usage and timing information. A mere suggestion does not trigger any external action or action with significant legal effect.
Workflows can be run manually or on a schedule. Additional triggers are processed only to the extent that they are expressly offered in the Workspace and activated by the user. For this purpose, we process the workflow description, version, trigger, schedule, participating Agents, Connector actions, approvals, inputs, results, run status and audit data.
Depending on the selected autonomy and Connector setting, an action may:
If a workflow is permanently approved, the action concerned can be performed in subsequent runs without another request. The approval can be withdrawn with effect for the future. Actions already performed and necessary audit evidence remain unaffected by the withdrawal.
Whether an action can be permanently approved depends on the policy stored for that specific Action. The interface displays the scope and duration of the approval. Permanent approval is excluded for payments, entering into contracts or making other legally binding declarations, irreversible deletions and changes to access, permission or security settings. These require specific individual confirmation or are blocked.
Users can connect external accounts and specify which actions Agents are permitted to perform. Depending on current availability, this applies in particular to:
In this context, we process the provider, account and Workspace identifier, scope of permissions, encrypted OAuth tokens, Connector configuration, permitted actions and technical action logs. Depending on the assignment, content read or written by the Connector is also processed.
Organisation connections may be available for use by authorised members of the company. Personal connections are restricted to the authorising user. When a connection is disconnected, local access tokens are removed or rendered unusable and permissions are revoked at the provider where technically possible.
When a Connector action is performed, the necessary data is transmitted to the third-party provider selected by the user. That provider’s Privacy Policy and retention rules also apply to its own processing. The user is responsible for lawfully connecting the external account and possessing the required permissions.
For direct use, the legal basis is Art. 6(1)(b) GDPR. In company accounts, Needs may process work content retrieved or written via Connectors on behalf of the company pursuant to Art. 28 GDPR. Needs additionally processes its own approval, security and audit data on the basis of Art. 6(1)(f) GDPR to perform the requested actions securely and in a traceable manner.
For voice input, we process audio data to convert speech into text or provide a voice conversation. The voice feature begins only after the microphone has been deliberately activated. Needs does not store the raw audio of an ordinary voice input as permanent Workspace content. During transmission and processing, the voice services used may process audio data in accordance with their contractually specified security periods. The transcript may be stored as part of the chat.
For voice output, text is transmitted to the voice service used in each case to generate an audio file or audio stream. If a voice service may process data outside the European Union or the European Economic Area, the information on data regions and third-country transfers applies.
The legal basis for a voice feature requested by the user is Art. 6(1)(b) GDPR. The end device’s technical microphone permission does not automatically constitute consent within the meaning of the GDPR. Where consent is required for additional optional processing, it is obtained separately in accordance with Art. 6(1)(a) GDPR and can be withdrawn at any time with effect for the future.
If a user or company activates a meeting recording, the appointment reference, dial-in link, audio or video data, transcript, participant information and resulting notes and tasks may be processed. When used in a company account, the company is responsible for ensuring an appropriate legal basis and informing participants in good time; Needs generally processes the content on the company’s behalf. The applicable recording rule must be apparent before or upon activation. Covert recording is not provided for.
An AI Agent can be used without registration in publicly accessible areas. In this context, we process:
The processing serves the requested communication and, where applicable, pre-contractual measures pursuant to Art. 6(1)(b) GDPR. Secure and user-friendly operation is additionally based on Art. 6(1)(f) GDPR.
To allow a session to be continued locally, the browser may store a session reference and a limited number of the most recently displayed messages in the end device’s local storage. This local copy remains until it is overwritten by new data or deleted by clearing the browser data. It is not used as an analytics or marketing cookie.
Server-side conversations are deleted or anonymised no later than 30 days after the last activity, unless they are linked, at the user’s request, to an account subsequently created or a security investigation requires temporary further storage.
Please do not enter special categories of personal data or data relating to third parties in a public Agent unless you have the appropriate authorisation.
If a user specifies a company website or commissions business research, we may retrieve publicly available company information and structure it with AI support. This may also include names and professional functions.
The processing serves to set up and contextualise the Workspace and is carried out pursuant to Art. 6(1)(b) or (f) GDPR, depending on the process. Our legitimate interest lies in providing an up-to-date, company-related work context. We limit the research to factual, publicly available sources and do not use it to create a covert personal profile.
The data originates in particular from the specified company website, public registers, press or specialist publications and other freely accessible business sources. Special categories of personal data are not deliberately collected.
Where Art. 14 GDPR applies, we inform the data subject within a reasonable period, at the latest within one month of obtaining the data, or earlier upon the first communication or disclosure, unless an exception under Art. 14(5) GDPR applies. Data subjects may object to the processing pursuant to Art. 21 GDPR.
The Platform application and its central database are operated in Germany. For AI requests, an organisation administrator can select the processing profile offered for their company:
The providers and regions used for a specific function are set out in the current service description, the organisation settings and the list of processors.
Depending on how the service is used, data may be transmitted to the following categories of recipients:
Connector providers activated by the user may themselves be controllers or processors of the customer for their own service. The relevant role depends on the contractual relationship between the user, company and provider.
Under the “EU and international” AI processing profile and for certain voice, payment, communication, appointment or user-selected Connector functions, data may be processed outside the European Union or the European Economic Area.
Where no adequacy decision under Art. 45 GDPR applies, we base the transfer in particular on Standard Contractual Clauses pursuant to Art. 46 GDPR, assess the circumstances of the transfer and implement any necessary supplementary safeguards. For US companies certified for this purpose, the EU-US Data Privacy Framework may be used as the transfer basis.
Break-glass access or encryption does not replace a required legal basis for a third-country transfer. Despite the measures taken, statutory access rights of foreign authorities cannot be completely excluded.
We use technically necessary cookies and local storage where they are required for login, security, session management, language settings and expressly requested features. The legal basis is Section 25(2) no. 2 TDDDG; the subsequent processing of personal data is based in particular on Art. 6(1)(b) or (f) GDPR.
Optional analytics and marketing technologies are used only after consent in accordance with Section 25(1) TDDDG and Art. 6(1)(a) GDPR. The Consent Banner offers a choice between strictly necessary technologies only and additional consent to optional technologies and links to this Privacy Policy. Providers, purposes and material categories of data are described in particular in Sections 17 and 20.
The selection is generally stored for 180 days in the cookie_consent cookie. It can be changed or withdrawn at any time using the “Cookie settings” link in the Platform Footer. On pages without this link, the selection can be reset by deleting the cookie and revisiting a Platform page. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
With consent, Needs may use Google Analytics via Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This may involve processing truncated or otherwise protected IP and device information, session identifiers, page views and interactions, among other data. Google may also process data in the USA.
The Google Tag Manager container used may contain marketing tags as well as analytics tags and is therefore loaded only after joint consent to optional analytics and marketing technologies has been given. On pages whose current address contains query parameters or a URL fragment, Needs does not newly initialise Google Tag Manager or optional marketing pixels. Page-view events triggered by Needs contain only the URL path; Pricing and Seat parameters are not appended to external booking links.
Depending on the campaign, tags from LinkedIn, Meta or TikTok may also be used with consent. The providers that may technically be used are described in this Section and in the current list of processors; their actual activation depends on the campaign and configuration.
Workspace content such as chats, documents, transcripts and AI outputs is not made available for audience measurement, retargeting or marketing. Consent can be withdrawn at any time via the Cookie settings.
Independently of this, Needs may evaluate its own usage metadata for secure operation and to improve usability. This includes feature calls, timestamps, session and dwell time, usage volumes, technical performance and errors. Event data intended for product analysis generally contains no semantic Workspace content. The legal basis is Art. 6(1)(f) GDPR; our legitimate interests lie in capacity planning, troubleshooting, abuse prevention and product management. This metadata is not used to evaluate the performance or behaviour of individual employees.
If you contact us, we process the contact and content data you provide in order to handle the matter. Depending on the reason for contact, the legal basis is Art. 6(1)(b) or (f) GDPR. Art. 6(1)(c) GDPR may additionally apply where legal obligations are involved.
If you subscribe to a newsletter, we process your email address and evidence of the subscription on the basis of your consent pursuant to Art. 6(1)(a) GDPR. You can unsubscribe at any time using the unsubscribe link or by sending us a message.
Open and click tracking in the newsletter takes place only if it is covered by the consent given. The newsletter may be sent via a contractually engaged email service provider.
For paid plans, Seats, credit, plan gift vouchers and other payments, we process contract, invoice, tax and transaction data. This includes in particular the company name, business email address, billing address, tax or VAT ID, plan, number of Seats, price, tax treatment, discount or voucher data, agreement to the contractual terms and customer, Checkout, subscription, invoice and payment references. For a plan gift voucher, we also process the required recipient, delivery, redemption and status data.
Payment processing is carried out in particular through Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland. Depending on the payment method, Stripe processes in particular the name, business contact data, company and billing data, tax ID, payment method, payment token, transaction identifier and fraud and device data.
Complete card details are generally entered directly with the payment service provider and are not stored by Needs.
The legal bases are Art. 6(1)(b) GDPR, statutory obligations pursuant to Art. 6(1)(c) GDPR and legitimate interests in fraud prevention and record-keeping pursuant to Art. 6(1)(f) GDPR. Stripe may transfer data to affiliated companies outside the European Economic Area; the information in Section 18 applies.
To provide and bill the usage included in the plan and additional credit, we process in particular plan and Seat assignment, billing period, available budgets and credit, type and purpose of use, time, status, consumption and cost values and technical execution and transaction references. This data provides the company with a traceable usage overview and serves billing, abuse prevention, error investigation and record-keeping. The legal bases are Art. 6(1)(b) and (f) GDPR; we additionally process evidence relevant under tax or commercial law pursuant to Art. 6(1)(c) GDPR.
When a DPA is concluded digitally, we also process the confirmed legal company name and business address, organisation reference, identity of the authorised representative, declaration, acceptance timestamp, and the complete accepted document versions and their checksums. The agreement applies to the represented company. Its authorised administrators can download the record from the protected contracts area.
In the case of notices of termination, requests under the voluntary money-back guarantee and comparable contractual declarations, we process in particular the name, email address, contract reference, type and time of the declaration, requested termination date and, where applicable, a reason provided voluntarily or required for extraordinary termination. For evidentiary purposes, we may also store the relevant versions or checksums of legal texts, status and payment references and a confirmation document with a document checksum.
The processing serves to implement and document the declaration, perform the contract, comply with legal obligations and establish, exercise or defend legal claims. The legal bases are Art. 6(1)(b), (c) and (f) GDPR.
We store personal data only for as long as is necessary for the applicable purpose. The following overview specifies the relevant standard or maximum periods or the criteria for determining them. Earlier deletion remains possible if the purpose ceases to apply and no obligation or overriding reason for continued storage exists:
Data may be retained with access restricted for longer where this is necessary to comply with statutory obligations or to establish, exercise or defend legal claims. Any such legal hold is limited to the data specifically required.
When restoring from a backup, data that had been effectively deleted in the interim is deleted again. Backups are not searched for ordinary data access requests or product analyses.
We implement appropriate technical and organisational measures. These include in particular transport encryption, protected storage of Connector tokens, role-based permissions, tenant separation, short-lived signed Connector approvals and security and action logs.
Outside expressly commissioned Managed Services, human access to content is not envisaged in ordinary operations. The access and audit procedures of the relevant system apply to commissioned Managed Services and to specifically justified support, security, legal or restoration cases.
No internet service can guarantee absolute security. Security measures are therefore reviewed and further developed using a risk-based approach.
Whether an Agent action forms part of automated individual decision-making depends on its specific purpose, process and actual effect. In the context of processing for which Needs is the controller, Needs does not make decisions based solely on automated processing which produce legal effects concerning a data subject or similarly significantly affect that person. If a corporate customer determines the purposes and means of its own decision-making process, it is the controller for that process and must in particular ensure lawfulness, transparency, data quality and any necessary human review.
For AI systems intended to interact directly with persons, we inform users that they are interacting with an AI system unless this is already obvious. The relevant transparency obligations under Art. 50 of the EU AI Act have applied since 2 August 2026. Where AI-generated or manipulated content is subject to specific labelling obligations, these are implemented in the applicable function.
Subject to the statutory requirements, you have in particular the right to:
You may object to direct marketing at any time without giving reasons. For other processing pursuant to Art. 6(1)(e) or (f) GDPR, you may object on grounds relating to your particular situation.
Where Needs processes data solely on behalf of a corporate customer, please first address your request to that company. Needs assists the controller in handling the request.
Provision of the data marked as required for the account, authentication, contract, billing and security is necessary for the relevant service. Without this data, the contract or requested function cannot be provided.
Optional data and functions are marked accordingly. If a user introduces data relating to other persons into the Workspace, a voice feature or a Connector, the user must be authorised to do so and must have provided any required information or obtained any required consent.
We amend this Privacy Policy when functions, providers or the legal framework change. We will provide information about material amendments in an appropriate manner, for example in the Workspace or by email. The current version is available on our website.
Contract documents and information on providers and processing locations are available in the Trust Center.
Needs generally processes data under its own responsibility for registration, authentication, member and role management, billing, platform operation, security, abuse prevention, its own product metadata and statutory obligations.
Where an AI Agent is deployed externally by a customer company, that company is generally responsible for the communication and processing it specifies. Needs is the controller for Agents offered publicly by Needs itself.
basic and contact data, login and account data;
company affiliation, function, language, time zone, role and permissions;
onboarding, demo, appointment and sales data, in particular company website, initial objective, onboarding progress and desired team size;
contract, plan, Seat, billing and payment metadata;
contract and declaration snapshots, accepted versions of legal texts, evidence and payment references;
chats, prompts, AI outputs, files, notes, tasks, projects and knowledge content;
voice data and transcripts;
workflow definitions, versions, schedules, triggers, inputs, results and approvals;
Connector providers, connected accounts, OAuth permissions, access tokens stored in encrypted form, permitted actions and action logs;
AI and operational metadata such as timestamps, status, model or Connector reference, runtime, usage volumes, token and cost values, error class and technical IDs;
IP address, browser, device, session, server and security data;
support enquiries and feedback expressly submitted;
publicly available business information, in particular from a company website specified by the user.
the user expressly authorises it for a specific support case, deliberately submitted feedback, a requested restoration or a verified data fix;
a specific suspicion of a security issue or abuse must be investigated;
a security incident, legal obligation or the defence of legal claims requires it; or
documented emergency access to production systems is required.
be blocked;
require approval each time;
be permitted once or for a session; or
be permanently approved for a particular connection, Action or workflow.
Microsoft 365 and Outlook;
Gmail;
Pipedrive;
HubSpot;
Notion;
GitHub.
conversation content and AI outputs;
temporarily, audio data where voice input is activated;
technical connection, session and device data;
security and usage metadata for applying rate limits and preventing abuse.
EU/EEA only: AI requests are processed through routes for which processing within the European Union or the European Economic Area has been technically and contractually confirmed. Functions or models that do not meet this profile are not available under this setting.
EU and international: International model and infrastructure providers may also be used. Depending on the selected function, data may be processed in particular in the USA or other third countries.
hosting, storage, backup and infrastructure providers;
AI, model, voice, transcription and, where applicable, image providers;
technical automation, sales, CRM and research services, in particular n8n and, where used, Firecrawl or Pipedrive;
Microsoft services, in particular Outlook, Microsoft Graph and Microsoft Bookings, where they are used for email drafts, communication or appointment booking;
Connector providers activated by the user;
payment service providers, in particular Stripe;
email, notification and support service providers;
error analysis, security and monitoring services where required;
optional web analytics or marketing providers only with consent;
advisers, courts, public authorities or other bodies where required by law.
access pursuant to Art. 15 GDPR;
rectification pursuant to Art. 16 GDPR;
erasure pursuant to Art. 17 GDPR;
restriction of processing pursuant to Art. 18 GDPR;
data portability pursuant to Art. 20 GDPR;
object to processing pursuant to Art. 21 GDPR;
withdraw consent given with effect for the future;
lodge a complaint with a data protection supervisory authority.
Trust Center
Public guest or Agent chats without registration
on the server, no later than 30 days after the last activity; a limited local browser copy until it is overwritten or the browser data is deleted
Raw audio from voice input
after transcription or the end of the voice session; no permanent storage
Meeting recordings, transcripts and content generated from them
until deletion by the authorised person or the end of the applicable Workspace or company contract; technical copies held by the provider in accordance with the period agreed for the specific recording service
Onboarding drafts that have not been finalised
for as long as the process is continued or a specific pre-contractual enquiry is handled; drafts with website analysis or research are generally deleted after seven days if they are not finalised
Demo, appointment and other sales enquiries without a contract
until the enquiry has been completed and generally no longer than six months after the last substantive contact; earlier upon objection unless an evidentiary or retention obligation prevents this
Account, organisation and profile data
for the duration of the account-use or company contract; after it ends, a 30-day export option, followed by deletion from active systems generally within 30 days
Chats, projects, tasks, knowledge content, files and AI outputs
until deletion by the authorised person or the end of the applicable account-use or company contract; then generally deleted from active systems within 30 days
Shared content in a company Workspace
until deletion by the organisation or the end of the company contract; not solely because an individual user leaves
Workflow definitions and versions
for active use and generally twelve months after archiving
Workflow runs and results
generally twelve months unless the user deletes them earlier and no evidentiary obligation prevents this
Short-lived workflow and automation payloads
generally no longer than 14 days
Rejected or unadopted proactive suggestions
generally 90 days
Connector access tokens
until the connection is disconnected or authorisation is withdrawn; then deleted or rendered unusable without undue delay
Cached Connector content
generally no longer than 30 days
Connector, workflow and action audits
generally twelve months
Ordinary web server access logs
generally seven days
Other technical error and operational logs
generally 14 days
Authentication and security logs
generally 90 days; incident-related extracts until the investigation or legal defence is concluded
Break-glass access audits
at least twelve months
Content-free raw product analytics data
generally 90 days; then deletion or genuine anonymisation
Anonymised statistics that can no longer be related to persons
no personal data retention period
Support communications
generally three years from the end of the calendar year in which the matter was concluded; where it constitutes a commercial letter, six years where applicable
Records of consent and withdrawal
generally three years from the end of the calendar year in which the consent ended
Usage, budget and billing audits
for the duration of the contract and generally three years from the end of the calendar year of billing; eight years where they constitute an accounting record or are relevant for tax purposes
Contract-related declarations and records
for contract administration and generally three years from the end of the calendar year in which the matter was concluded; six years where they constitute a commercial letter or eight years where they constitute an accounting record
Temporary storage by AI providers
depending on the specific provider, processing route and contract; the agreed period is specified in the list of processors
Accounting records and invoices
generally eight years
Commercial books, annual financial statements and comparable documents
generally ten years
Other documents relevant under tax or commercial law
depending on the document, generally six years
Encrypted, rolling backups
until scheduled overwriting in accordance with the backup cycle applicable to the relevant system, generally no longer than 90 days
Data category
Standard or maximum period
EU/EEA only:
EU and international:
Datenschutz | Needs
EUR
Links
Home: https://needs.expert
How it works (Companies): https://needs.expert/how-it-works/companies
Preise: https://needs.expert/pricing
Text-only: https://needs.expert/text-only
Imprint: https://needs.expert/imprint
Privacy: https://needs.expert/privacy
AGB: https://needs.expert/agb