Translation for convenience, the German version is legally binding.

Privacy Policy

As of: 26 September 2026 · Version 2026.8

This privacy policy informs you, pursuant to Art. 13 and 14 GDPR (General Data Protection Regulation), which personal data we process when you create an account on our platform app.rinqo.de or interact with an AI agent operated by us (chat, phone, email, Personal agent). A separate privacy policy applies to visits to our marketing website rinqo.de (rinqo.de/privacy). From rinqo’s perspective as a service provider, this policy supplements the privacy policy that our customers provide on their own websites and end-customer channels.

1. Controller

Sven Pflüger, trading as “rinqo”
Schusterstraße 40
79098 Freiburg im Breisgau
Germany
Data protection email: privacy@rinqo.de
General contact: hello@rinqo.de

2. Data Protection Officer

The statutory obligation to appoint a data protection officer under § 38 BDSG (German Federal Data Protection Act; as a rule from 20 persons constantly engaged in automated processing) does not currently apply to rinqo. As soon as the threshold is reached, we will appoint an external data protection officer and update this policy. Until then, the address given above handles data protection enquiries.

3. At a glance: what we process

  • Platform account: name, email, hashed password, organisation and team memberships, subscription and credit balance.
  • Platform usage: cookieless usage events on app.rinqo.de (e.g. registration steps, page views), which we count with audience measurement that we run ourselves in Germany, without accessing your device (section 11), plus technical server logs.
  • Customer content (Art. 28 GDPR): chat messages, call transcripts, email content, knowledge-base documents, processed on behalf of our business customers.
  • Mollie B.V. processes payment data as an independent controller. We store customer and payment identifiers, payment status, invoice details and, for SEPA, the mandate reference, evidence of acceptance and pre-notification and any bank details transmitted by Mollie.

4. Legal bases

  • Art. 6(1)(b) GDPR: Contract and steps before entering into a contract: account creation, subscription management, platform use, partner applications and performance of customer and partner contracts.
  • Art. 6(1)(c) GDPR: Legal obligation: invoicing and retention under commercial and tax law (section 147 AO, section 257 HGB).
  • Art. 6(1)(f) GDPR: Legitimate interests: IT security, rate limiting, abuse detection, correct partner and commission accounting, presentation of genuine customer references and product and quality improvement using anonymised aggregate figures.
  • Art. 6(1)(a) GDPR and section 25(1) TDDDG: Consent: newsletters and the recording of telephone calls.
  • Art. 28 GDPR: We process the end-customer data of our business customers only on documented instructions. In relation to the data subject, the customer's legal basis applies, usually Article 6(1)(b) or (f) GDPR.

5. In detail: account, platform and dashboard

5.1 Registration

We collect your name, business email address and a password you choose yourself. Passwords are stored exclusively as a bcrypt hash with 12 salt rounds and cannot be reversed.

5.2 Login and sessions

After a successful login we set a technically necessary session cookie (NextAuth / JWT) with the attributes HttpOnly, Secure and SameSite=Lax. Basis: § 25 Abs. 2 Nr. 2 TDDDG (strictly necessary).

5.3 Log data

On every access to the platform, the IP address, timestamp, requested resource, user agent and status code are processed in server logs. Logs are kept for a maximum of 30 days and serve solely to defend against attacks and for technical error analysis. Errors flow, stripped of PII, into an error-tracking server we host ourselves in Germany (no external sub-processor).

5.4 Security measures

Rate limiting, account lock after five failed attempts, CSRF protection, HTTPS (TLS 1.3), encrypted credentials (AES-256-GCM) and audit logs for data-relevant operations. We make the full technical and organisational measures (TOMs) available to registered customers in the dashboard (the “Contracts & privacy” area).

5.5 Performance measurement (Web Vitals)

In the dashboard we measure the load time of individual pages anonymously (Core Web Vitals: LCP, INP, CLS, FCP, TTFB). Only the page type (e.g. /contacts/[id], not the specific contact ID), a browser class (e.g. “chrome/mobile”) and the measured values themselves are transmitted. Attribution to you as a person is not possible: user IDs are never recorded, the organisation ID only as a salted hash. Retention: 30 days. Purpose: detecting and fixing performance regressions. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning service).

5.6 Application for the partner programme

You need an account to apply. Companies and private individuals aged 18 or over may apply. We process your account and contact details, the information in the application, internal review notes, the decision and any reason for rejection. This serves steps before entering into a contract and conclusion of the partner contract under Article 6(1)(b) GDPR, and abuse and conflict of interest checks under Article 6(1)(f) GDPR. We delete application notes and reasons for rejection 365 days after the decision is completed. We process identity, contract and accounting evidence for an accepted partner separately for contract performance, accounting and statutory evidence obligations.

5.7 Referral and partner attribution

We do not use a referral cookie. A referral code from a link is entered in a visible, optional registration field. You can change or remove it. The code in the field is used for partner attribution only when you deliberately submit the form. We store the code, the attributed partner identifier, timestamps and reasoned attribution changes, as well as the customer and contract status, commission bases and commission amounts required for commission. Conversation content is not used for this. The legal bases are Article 6(1)(b) GDPR for performing customer and partner contracts and Article 6(1)(f) GDPR for traceable, abuse-resistant accounting.

5.8 Customer references

As a reference, we show only the company name and, where applicable, a verified logo of a genuine paying customer whose accepted terms govern the naming. We do not publish content, conversation data or statements about use. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in presenting our customer base truthfully, within the individually agreed use. For particularly sensitive sectors, we review the rights to the name and logo individually and publish only after express approval. You can object at any time; a message in text form to hello@rinqo.de is enough. Public display then stops immediately. We keep internal evidence according to its particular evidence and legal defence purpose.

5.9 Google Calendar

When you connect your Google Calendar to rinqo, we access it through the Google Calendar API with two permissions. With read access, we retrieve the list of your calendars and the start, end and status of your events. This lets rinqo know when you are busy, avoid double bookings and recognise events it created itself. In rinqo, these events appear only as “Busy”. We do not store the titles, descriptions or attendees of your events. Of the title we store only a check value computed with a secret key. It does not contain the title and serves only to let rinqo recognise its own events. With write access, rinqo creates booked appointments in calendars you own, and changes or deletes them when the booking is changed or cancelled in rinqo.

The data is stored on servers in Germany, with backups in the EU. We do not share it with anyone except our hosting provider, and not with any AI model provider. We do not use it for advertising, do not sell it and do not use it to train AI models. Access tokens for your Google account are stored encrypted, and the connection to Google is encrypted. We store events from 30 days in the past to 180 days ahead and delete older entries. When you disconnect in rinqo, we revoke access at Google and delete the access tokens and all event data retrieved from Google. You can also revoke access at any time in your Google Account at myaccount.google.com/permissions.

rinqo’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. In detail: AI agents (chat, phone, email)

When you reach a rinqo agent on a customer website, under a customer phone number or in a customer mailbox, we act as a processor towards you (Art. 28 GDPR); the controller (Art. 4(7) GDPR) is always the customer whose channel you have used. Our obligations towards you arise from the data processing agreement concluded between that customer and rinqo and from the customer’s own privacy policy.

Technically, the following data flows for the three agent types:

  • Chat agent (widget): messages, optional contact details, a random visitor identifier in browser storage (consent required under TDDDG), IP (truncated to /24), browser and device metadata.
  • Phone agent: the caller’s number (where transmitted), audio stream via an EU telephony provider, transcript, response audio, call metadata. Permanent recording of the call is switched on by default for a new phone agent; the customer, as controller, can turn it off per agent. The default greeting informs the caller of the recording at the start of the call and tells them of their right to object. If the customer changes the greeting, the customer is responsible for keeping this notice in it. If the caller objects, the audio captured up to that point is discarded and the call is ended. Continuing after the notice counts as consent (Article 6(1)(a) GDPR, § 201 StGB). The recordings are stored on the server of the voice service in Germany.
  • Email agent: sender address, subject, message text, attachments, timestamp.

The customer can block phone numbers, email addresses and entire email domains (the “Blocked” area). We keep the entry until the customer removes it. The agents do not accept calls or emails from blocked senders. In the chat, the block takes effect as soon as the person has given a blocked phone number or email address.

7. Knowledge base

Content that customers upload to the knowledge base (texts, URLs, PDFs) is stored in our database, split into small text fragments and stored as vector embeddings in a vector database we operate ourselves on our servers in Germany. Embeddings contain no readable original texts. PDF pages without a readable text layer, such as scanned pages, are read by an AI service in the European Union (France). If someone dictates a voice note for the knowledge base, an AI service in the European Union (France) transcribes it. We do not store the recording, only the text. Storage period: as long as the customer uses the platform or the source is active.

8. Hosting and operating infrastructure

Our entire core infrastructure is operated by a hosting provider certified to ISO/IEC 27001 in data centres in Germany. This includes the application, the database, the self-operated cache together with the job queue, the self-operated vector database and the voice service that handles the phone calls. A data processing agreement pursuant to Art. 28 GDPR is in place.

9. Services and recipients used

We use carefully selected sub-processors under Article 28 GDPR to provide the platform. We also transmit payment data to Mollie B.V., which processes it as an independent controller. The services are described here by category. Customer content is primarily processed and stored in data centres in Germany:

  • Infrastructure and operations: a hosting provider certified to ISO/IEC 27001 with data centres exclusively in Germany, including protection against overload attacks at network level; no external delivery or relay service sits in the data path.
  • AI services: providers for the agents’ answers, for speech recognition during a call and for speech output. All of them process exclusively within the European Union and are contractually obliged not to train on customer data.
  • Telephony: a provider established in the Union that supplies the numbers and the line. The call itself is not analysed there.
  • Business services: Mollie B.V. in Amsterdam as independent controller for payments, a transactional email service and a service that checks our availability from outside and operates the status page. We run audience measurement and error tracking ourselves in Germany, without an external provider.

We make the complete list of names of all sub-processors, with registered office, processing location, data categories and DPA status, available to registered customers in the dashboard (the “Contracts & privacy” area). Prospective customers receive it on request during contract initiation at privacy@rinqo.de. A vendor-free overview is available at app.rinqo.de/sub-processors.

Customer content that we and our sub-processors process on your behalf is not transferred to a third country. Separately, Mollie processes payment data as an independent controller. According to Mollie's privacy statement, providers outside the European Economic Area may be involved. Mollie identifies adequacy decisions and EU Standard Contractual Clauses in particular as transfer mechanisms.

If you, as a customer, connect an application of your own, this takes place on your instructions and under your responsibility; the classification is set out in section 5 of the Data Processing Agreement.

10. Data Act, ICT jurisdiction and non-personal data (Art. 28)

In addition to the data protection information above, we make the following transparency statement pursuant to Art. 28 of Regulation (EU) 2023/2854 (“Data Act”; transparency obligation since 12 September 2025) publicly available. It expressly also concerns non-personal data processed in the EU and is to be distinguished from the data protection provisions of the other sections. The provisions on switching providers and data export under Art. 23–25 Data Act can be found in Section 7 of our Terms and Conditions (AGB).

10.1 Jurisdiction of the ICT infrastructure (Art. 28 (1) (a))

The ICT infrastructure used for processing (hosting of the application, database, self-operated vector database, cache, job queue and voice service) is operated in data centres in Germany and is subject to German and EU law; the contracting party is a hosting provider certified to ISO/IEC 27001 and established in Germany. Individual sub-processors for specific functions, such as the AI services and telephony, are companies established in other Member States of the EU. Where we know their parent companies, these are also established in the EU. The measures described under 10.2 apply to all sub-processors. We make a complete list of names of the services used available to registered customers in the dashboard; publicly we state them as categories (see Section 9 and app.rinqo.de/sub-processors).

10.2 Measures against third-country government access (Art. 28 (1) (b))

We have taken technical, organisational and contractual measures to prevent governmental access to, or transfer of, non-personal data held in the EU that is prompted by international or third-country law, in so far as such access would conflict with Union law or the law of a Member State:

  • Technical: operation in data centres in Germany / the EU, encryption of data at rest (AES-256-GCM) and in transit (TLS 1.3), access controls, network segmentation and logging.
  • Organisational: data minimisation, restriction of access to the necessary personnel (need-to-know), documented access and authorisation processes, and case-by-case review of incoming government requests.
  • Contractual: engagement of sub-processors only with a data processing agreement and, for any third-country links, with EU standard contractual clauses; contractual obligation of sub-processors to review and, where legally permissible, challenge unlawful government requests and to notify us of such requests.

We do not thereby guarantee that third-country government access is technically or legally excluded in full. We take the measures described in order to prevent such access in so far as it would conflict with applicable Union law or the law of a Member State.

11. Cookies and comparable technologies

The app.rinqo.de platform uses only cookies that are technically necessary for the session, CSRF protection and language settings under section 25(2)(2) TDDDG. A selected plan may be stored for functional purposes. Referrals use only the visible optional field described in section 5.7. We run the platform's audience measurement ourselves on our servers in Germany. It works without cookies and without any script in the browser: our server reports each page view to the measurement tool together with the page requested, the IP address and the browser's user agent. From these, the tool derives a value that changes every day and allows visits on the same day to be counted together. It stores neither the IP address nor the user agent. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in usage statistics. The app does not receive advertising identifiers, pixel cookies or referrer data. The separate privacy statement for the rinqo.de marketing website applies there. Optional marketing cookies on that website are set only after separate consent and are removed when consent is withdrawn.

12. Payments and billing

Payments are processed by Mollie B.V. Mollie and rinqo are independent controllers for their respective processing. We do not use Mollie Invoicing and create our invoices ourselves. We store customer and payment identifiers, payment status, invoice details and, for SEPA, the mandate reference, evidence of acceptance and pre-notification and any bank details transmitted by Mollie. Mollie processes payment and bank data in particular to execute payments, prevent fraud and comply with its own regulatory obligations. According to its privacy statement, Mollie may use providers outside the EEA under the transfer bases stated there. Our legal basis is Article 6(1)(b) GDPR. We retain invoices and accounting vouchers for eight years, and books and annual financial statements for ten years. Each period starts at the end of the relevant calendar year under sections 147(3) and (4) AO, 257(4) and (5) HGB and 14b UStG.

13. Communication by email

Transactional emails (password reset, invoices, system notifications, security-relevant warnings) are sent via an EU transactional email service provider (France). The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Through the same service, the agents send emails on behalf of our customers to the customers’ own clients, such as appointment confirmations and reminders. For this we act as a processor (section 6). The newsletter offered on the marketing website is described in the privacy policy there (rinqo.de/privacy).

We occasionally inform existing customers by email about our own similar services (§ 7 Abs. 3 UWG, German Act Against Unfair Competition, Art. 6(1)(f) GDPR). Each such email contains a one-click unsubscribe link; objection is possible at any time free of charge.

14. AI processing and the EU AI Act

Pursuant to Art. 3(3) of Regulation (EU) 2024/1689 (EU AI Act), rinqo is a provider of an AI system with limited risk. We meet the transparency and competence obligations set out therein as follows:

  • Art. 50 EU AI Act (transparency, binding since 2 August 2026): the chat agent, phone agent and email agent are instructed to identify themselves as an AI system. The default greetings contain the notice, and emails from the agents carry it when they are sent. If the customer changes a greeting, the customer is responsible for keeping the notice in it (section 9 of our Terms and Conditions).
  • Art. 4 EU AI Act (AI literacy, in force since 02.02.2025): all persons at rinqo entrusted with operating the AI system receive documented AI-competence training. Supervisory authorities have been enforcing it since 2 August 2026.
  • No automated decision with legal effect: our agents prepare responses but do not make decisions with legal effect on data subjects within the meaning of Art. 22 GDPR. Decision-relevant matters (e.g. conclusion of a contract, termination, appointment scheduling) are the responsibility of the customer.
  • No transfer for training: content of our customers and end customers is not used to train external foundation models. The LLM, STT and TTS providers we use are contractually obliged not to use it to train their general models.

15. Storage period

  • Account data: until termination; complete deletion within 30 days of termination, unless a statutory retention obligation applies.
  • Conversations, transcripts, recordings: 90 days by default, set separately for phone, chat and email. The customer, as controller, decides the actual period: 7 to 365 days for calls, 7 to 3,650 days for chat and email. A period beyond 365 days requires the customer to confirm a statutory retention obligation.
  • Server logs: 30 days.
  • Invoices and accounting vouchers: 8 years from the end of the calendar year in which they were issued (§ 147(3) AO, § 257(4) HGB as amended by the Fourth Bureaucracy Relief Act).
  • Books, annual financial statements, inventories: 10 years (§ 147(3) AO).
  • Audit logs of data-protection-relevant actions: 365 days.
  • Earlier versions of agent settings (for “Undo”): 30 days.
  • Attachments to the Personal agent: the extracted text for 30 days after sending; attachments that were never sent for 24 hours.
  • Block list (the “Blocked” area): until the customer removes the entry.
  • Businesses and reservations registered by partners: 365 days after completion or expiry.
  • Application notes and reasons for rejection: 365 days after the decision is completed. Identity, contract and accounting evidence follows its own contractual and statutory periods.
  • Open security and deletion tasks: until their documented completion, even if the regular period ends earlier.

16. Your rights

Under the GDPR you have the right to

  • access (Art. 15),
  • rectification (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20),
  • object (Art. 21),
  • withdraw consent given (Art. 7(3)), with effect for the future.

Exercising these rights is free of charge for you. To do so, contact privacy@rinqo.de. In addition, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW) as the authority responsible for us, or the supervisory authority of your federal state or place of residence.

17. Data security and notification obligations

We use technical and organisational measures (TOMs) in line with the state of the art to protect your data against unauthorised access, loss and manipulation. Should a notifiable personal data breach within the meaning of Art. 33 and 34 GDPR nonetheless occur, we will inform the competent supervisory authority within 72 hours and the affected persons without undue delay, as soon as a high risk is to be assumed.

18. No automated individual decision

A solely automated decision within the meaning of Art. 22 GDPR with legal effect or similarly significant impact does not take place with us.

19. Target group and minors

The platform is intended for businesses and their staff in a B2B context from the age of 18. Private individuals aged 18 or over may participate in the partner programme as referrers. Access by private individuals to a demo is governed by the purchase path approved in the specific case. This does not grant a general B2C subscription option. We do not knowingly process data of minors. If customers use rinqo agents with end users and minors may be expected, they must provide age-appropriate notices. We do not perform this assessment.

20. Customer use and text templates

If you yourself use rinqo agents on your website, in your telephony or in your mailbox, we make non-binding text templates available as guidance at app.rinqo.de/compliance-muster. They are expressly not legal advice and do not replace your own review by a data protection officer or lawyer.

21. Changes to this policy

We update this privacy statement when our processing or the law changes. The version stated above applies. Under the Data Processing Agreement, we announce new or changed sub-processors at least 30 days before their first production use. Material changes to the Terms and Conditions are offered separately at least 60 days in advance and require express acceptance. Silence does not count as acceptance. This statement does not replace any contractually required acceptance.

Last updated: 26 September 2026.