Privacy Policy

Datenschutzerklärung — Last updated: 13/06/2026

This Privacy Policy explains how Acteams ("Acteams", "the Service", "we") collects, uses, and shares personal data, and describes your rights under the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and the German Federal Data Protection Act (BDSG). For German users, this document also serves as the Datenschutzerklärung in the sense of Art. 13 / Art. 14 GDPR.

1. Controller (Verantwortlicher)

The controller responsible for processing your personal data is:

A Data Protection Officer (DPO) has not been appointed because the legal thresholds in § 38 BDSG are not met. If a DPO is appointed in the future, contact details will be added here.

2. Scope

This policy applies to the Acteams website at acteams.chenio.de and the associated web application, including project workspaces (literature, notes, documents, R/Python analyses, LaTeX, discussions/chat) and supporting APIs.

3. Categories of Personal Data

3.1 Account & identity data

3.2 User-generated project content

The Service is designed for collaborative research. Depending on how you use it, content you produce may contain personal data (your own or about others).

3.3 Technical & usage data

3.4 Payment data

If you subscribe to a paid plan, payment is processed by Stripe Payments Europe, Limited (Ireland). We do not see or store your full card number. We receive a customer ID, the subscription status, and metadata about your invoices.

3.5 Preferences & local-storage state

4. Purposes and Legal Bases (Art. 6 GDPR)

We process personal data only when we have a valid legal basis. Each purpose below is mapped to the relevant Art. 6 ground.

5. AI Features (OpenAI)

Some features send user-provided text to OpenAI, L.L.C. (United States) as a processor on our behalf. These include: literature citation extraction, full-text URL lookup, document drafting/revision, AI assistant questions, retrieval-augmented synthesis over your literature, embedding generation for semantic search, and code generation in analysis notebooks.

6. Document Collaboration (Collabora)

Real-time collaborative editing of office documents is provided by an instance of Collabora Online that we host ourselves alongside the rest of the Service. Document content does not leave our infrastructure for the purpose of rendering or editing.

7. Real-Time Collaboration (Yjs)

Live co-editing of notes, analyses and LaTeX documents uses a self-hosted Yjs WebSocket server. Document state and presence (cursor position, selection, user name shown next to your cursor) flow over a short-lived signed token bound to a specific document. No third party is involved.

8. Recipients & Subprocessors

We do not sell personal data. We share personal data only with processors acting on our instructions under data-processing agreements (Art. 28 GDPR):

ProcessorPurposeLocationTransfer mechanism
Amazon Web Services EMEA SARL — RDS PostgreSQLApplication databaseFrankfurt (eu-central-1)EU — no transfer
Amazon Web Services EMEA SARL — S3File storage and backupsFrankfurt (eu-central-1)EU — no transfer
Amazon Web Services EMEA SARL — SESTransactional emailFrankfurt (eu-central-1)EU — no transfer
OpenAI, L.L.C.AI features (see Section 5)United StatesEU SCCs (Art. 46 GDPR); EU-US Data Privacy Framework where applicable
Stripe Payments Europe, Ltd.Subscription paymentsIreland (parent: USA)EU SCCs for any onward transfer
Amazon Web Services EMEA SARL — EC2Application server hostingFrankfurt (eu-central-1)EU — no transfer

We may also disclose information when required by law or to protect the rights, safety or security of our users, third parties, or the Service.

9. Cookies & Local Storage

The Service uses only cookies and local-storage entries that are strictly necessary to deliver features you have explicitly requested. Under § 25 (2) Nr. 2 TDDDG no consent is required for these. We currently use:

We do not use analytics, advertising or third-party tracking cookies. We do not embed third-party content (Google Fonts, YouTube, Maps, social widgets, etc.) that would set cookies on your device. See our Cookie Policy for details.

10. International Data Transfers

Personal data is primarily processed within the European Union. Where we use OpenAI as a processor, data is transferred to the United States. The transfer is safeguarded by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), supplemented where applicable by reliance on the EU-US Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795). We have documented a transfer impact assessment for this transfer and apply organisational safeguards (no submission of special-category data without explicit user action).

11. Data Retention

12. Your Rights (GDPR)

If GDPR applies to you, you have the right to:

To exercise any of these rights, contact us at the email above. You also have the right to lodge a complaint with your local data protection authority. For German users, the competent supervisory authority is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart (baden-wuerttemberg.datenschutz.de).

13. Security

We implement appropriate technical and organisational measures (Art. 32 GDPR), including TLS-encrypted transport, hashed passwords (bcrypt/scrypt), role-based access control, signed short-lived tokens for real-time collaboration, scoped per-project access checks on every API endpoint, encrypted database and S3 backups, and least-privilege credentials. No system is 100% secure; we will notify users and the supervisory authority of any personal data breach as required by Art. 33 / Art. 34 GDPR.

14. Children

The Service is not directed at children under 16. We do not knowingly process personal data of children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

15. Changes to This Policy

We may update this policy from time to time. The current version with the "Last updated" date above is the binding version. Material changes will be communicated by email or in-app notice.

16. Contact

Privacy questions and rights requests: support@chenio.de.