Privacy Policy
Zuletzt aktualisiert: 13. July 2026
This Privacy Policy explains how nordwerk.online ("we", "us", "our") collects, uses, stores, and protects personal information when you use our website nordwerk.online and our AI email agent services (the "Service"). It also explains, in detail, how we handle data accessed through Google APIs (Gmail) when you choose to connect a Gmail account.
1. Controller
Daniel Forot, Leinsamenweg 98, 50933 Köln, Germany. Contact: privacy@nordwerk.online.
2. What data we collect
Account data: your email address, password hash, name (if provided), and account timestamps.
Workspace content: invoices, documents, notes, calendar events and any other content you upload or create inside nordwerk.online.
Usage data: log entries such as timestamps, IP addresses, and error traces for security and debugging.
Billing data: when you subscribe, payment details are entered directly with our payment processor Stripe. We only receive a customer ID, subscription status, and invoice metadata; card details never touch our servers.
3. How we use AI on your content
Uploaded documents and questions are sent to our AI model provider (Google Gemini and OpenAI via the Lovable AI Gateway) solely to extract data, generate answers, or produce the output you requested. Providers are contractually bound not to retain your content beyond what is needed to produce the response, and we do not use your content to train generalized AI/ML models. You can request full deletion of your account and all associated data at any time by emailing privacy@nordwerk.online — we will comply within 30 days.
4. Legal basis (GDPR)
We process personal data on the following bases: performance of a contract with you (Art. 6(1)(b) GDPR) to provide the Service; your explicit consent (Art. 6(1)(a)) for the Gmail connection; our legitimate interest (Art. 6(1)(f)) in securing the Service and preventing abuse.
5. Retention
Account data is kept while your account is active and up to 30 days after deletion for legal and backup purposes. Gmail OAuth tokens are kept until you disconnect. Message previews stored for duplicate-prevention are kept for 90 days and then purged. Log data is kept for 30 days.
6. Subprocessors
We use the following processors to operate the Service: Supabase (managed database and authentication, EU region), Cloudflare (hosting and edge compute), Google (Gemini AI model via Lovable AI Gateway, for generating replies), and Lovable (application platform and email delivery). Each processor is bound by a data processing agreement.
7. International transfers
Some processors may transfer data outside the EU/EEA. Such transfers rely on the European Commission's Standard Contractual Clauses or adequacy decisions.
8. Your rights
Under GDPR you have the right to access, rectify, delete, restrict processing of, and port your personal data, as well as to object to processing and to lodge a complaint with a supervisory authority. To exercise these rights, contact privacy@nordwerk.online.
9. Security
We use TLS in transit, encryption at rest for sensitive tokens, row-level security on our database, and standard operational safeguards. No system is 100% secure; we will notify affected users of a personal data breach in accordance with Art. 33/34 GDPR.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced inside the Service and by updating the "last updated" date above.
11. Contact
Questions about this policy or your data: privacy@nordwerk.online.