Privacy Policy
Version: 28 August 2026
I. Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
CERTENTIC GmbHKempener Str. 42
41334 Nettetal
Germany
Email: [email protected]
Further information about CERTENTIC GmbH can be found in the Legal Notice (in German).
II. Data Protection Officer
No data protection officer has been appointed, as there is no statutory obligation to appoint one.
III. General Information on Data Processing
We process personal data only to the extent necessary to provide our website and connector service or where another legal basis applies.
Where processing is necessary to provide the service requested by you or to take steps prior to entering into a contract, it is carried out on the basis of Art. 6(1)(b) GDPR. Where we are subject to a legal obligation, processing is based on Art. 6(1)(c) GDPR. Processing to ensure secure and reliable operation, for error analysis, or to prevent misuse is carried out on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR. Where we obtain your consent, Art. 6(1)(a) GDPR is the legal basis.
We implement appropriate technical and organisational measures to protect personal data.
IV. Provision of the Website and Connector Service
When you access our website or use the connector service, technically necessary connection and access data are processed. This may include, in particular, the IP address, date and time of access, the requested resource, and technical request, status and error information.
Processing serves to provide and ensure the secure and reliable operation of our services, to detect and analyse technical faults, and to protect against misuse and attacks.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and uninterrupted operation of our services.
V. Registration and Use of the Connector Service
1. Registration and Email Verification
For registration and provision of the connector service, we process the data required for these purposes. This includes, in particular, your contact email address, country and language, information concerning required legal confirmations, and the account and access information required to set up and use the service.
Registration may take place in advance using a registration function provided by CERTENTIC or as part of connecting a supported AI service to CERTENTIC Bridge. When registration takes place as part of such a connection, you will be redirected from the respective AI service to CERTENTIC Bridge.
Your contact email address is verified using a one-time code that is valid for a limited period. For this purpose, we temporarily process the data required to carry out and secure the verification process.
When sending transactional emails, in particular verification codes or necessary system notifications, the email address, time of sending, delivery information and technical log data are processed in particular.
We also use the contact email address you provide for necessary contractual, account-related and security-related communications. These include, in particular, notifications concerning material changes to CERTENTIC Bridge, changes to the Terms of Use or Privacy Policy, suspensions or other restrictions of the user account, termination or material changes to the Open Beta, and notifications that we are legally required to provide. These may include, in particular, information about personal data breaches or other security-related incidents.
Where such communication serves the performance of the user agreement, processing is based on Art. 6(1)(b) GDPR. Where notification is required to comply with a legal obligation, processing is based on Art. 6(1)(c) GDPR. Where we inform users about security-related matters that are not already based on one of these legal bases, processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in the security of our services and in informing affected users.
The legal basis for registration and provision of the service is Art. 6(1)(b) GDPR. Where data is additionally processed to secure the registration process and prevent misuse, this is based on Art. 6(1)(f) GDPR.
2. Connection to iCloud
To connect to iCloud, you provide your Apple Account identifier and an app-specific password generated by Apple. These data are used to establish and verify access to the iCloud services requested by you.
Your normal Apple Account password is neither requested by CERTENTIC nor should it be transmitted to CERTENTIC.
The app-specific password and other access credentials required for the connection are stored in encrypted form to protect them against unauthorised access.
CERTENTIC does not use the app-specific password to access your Mail or Calendar data on its own initiative. During normal product operation, the stored iCloud credentials are used exclusively when you use CERTENTIC Bridge through a connected AI service and thereby initiate a corresponding request for your iCloud data.
You may revoke the app-specific password at any time through your Apple or iCloud account. After revocation, CERTENTIC Bridge can no longer retrieve iCloud results for connected AI services using those credentials.
After verification of your contact email address, you can replace the stored iCloud credentials using the self-service function provided by CERTENTIC.
The legal basis is Art. 6(1)(b) GDPR.
3. Processing of iCloud Mail and Calendar Data
When you access your iCloud data through a supported AI service, CERTENTIC Bridge processes the Mail or Calendar data required to execute your respective request.
This may include, in particular, senders, recipients, subjects, time information, message content, calendar events, participants, locations, event text and technical metadata, insofar as these are required for the respective request.
The connector currently provides read-only access. It does not create, modify, send, move or delete emails or calendar entries.
CERTENTIC does not permanently store content retrieved from iCloud Mail and iCloud Calendar through CERTENTIC Bridge. Retrieval from iCloud and processing to provide the result to the connected AI service take place during the respective request. The retrieved content and the results returned to the AI service are not subsequently stored by CERTENTIC.
Mail or Calendar content, returned results, and substantive search and request parameters are not stored in the technical telemetry of the connector service.
Processing is carried out to provide the connector functionality requested by you on the basis of Art. 6(1)(b) GDPR.
4. Connection to AI Services and OAuth Authorisation
CERTENTIC Bridge is connected to supported AI services by means of an OAuth-based authorisation process.
For this purpose, you are redirected from the respective AI service to CERTENTIC Bridge. There, if no user account yet exists, you can complete registration or confirm an existing user account and subsequently authorise the requested connection.
To carry out and secure the authorisation process, CERTENTIC processes the technically necessary data. This includes, in particular, information about the requesting AI service, the requested scope of permissions, and technical authorisation, session and security information.
As part of the OAuth connection process, CERTENTIC does not automatically receive your name, your email address held by the AI provider, information about your subscription with that provider, or comparable profile data. You provide and verify the contact email address used with CERTENTIC directly to CERTENTIC.
Following successful authorisation, CERTENTIC provides the connected AI service with technical access authorisations. In particular, OAuth access and refresh tokens are processed for this purpose. Authorisation and token values issued by CERTENTIC are not permanently stored in plaintext. Derived values and the connection and lifecycle information required for authorisation are stored for technical assignment and verification.
Security-relevant token values, authorisation codes and other secrets used for the authorisation process are not included in application logs or technical telemetry.
When you initiate a corresponding request through the connected AI service, the results requested to answer that request are transmitted to that AI service.
The transmission takes place at your initiative in order to provide the connector functionality requested by you. The legal basis for processing by CERTENTIC is Art. 6(1)(b) GDPR.
The storage and further processing by the provider of authorisation information and of results transmitted to the AI service selected by you are governed by that provider's technical, contractual and data protection terms and take place outside systems controlled by CERTENTIC.
The AI services and applications supported at any given time are specified in the current product description of CERTENTIC Bridge.
VI. Technical Logging and Error Analysis
To ensure secure and reliable operation, for error analysis, technical support, analysis of failed registration and connection processes, and detection and prevention of misuse, we process technical log and diagnostic data.
Where necessary to assign and analyse a specific registration, connection or support process, the contact email address provided by you may also be processed in narrowly defined server-side registration and support events.
Diagnostic data from the registration and administration service are generally stored for 30 days. In the narrowly defined cases described above, these data may also contain information directly attributable to a user, in particular the contact email address.
Technical telemetry from the connector service is generally stored for 90 days. It does not contain the contact email address or directly identifying user data. A pseudonymous internal user identifier may be processed for the technical assignment of processes. The user's name or email address cannot be derived from this identifier alone.
The connector service telemetry may include, in particular, the AI service or technical client used, the connector function called, technical process and status information, runtimes, and success and error categories.
Mail or Calendar content, results returned by the connector, and substantive search terms and request parameters are not stored in this technical telemetry.
Security-relevant authentication data, in particular verification codes, OAuth access and refresh tokens, authorisation codes, PKCE secrets, and Apple and iCloud credentials, are not included in application logs or technical telemetry.
Diagnostic data are retained for longer periods only where this is necessary in an individual case due to a specific security incident, for the establishment, exercise or defence of legal claims, or due to a statutory obligation.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests lie in the secure and reliable operation of the service, error analysis and technical support, and protecting our services and users against misuse.
We do not use these data for advertising, profiling or personalised marketing.
VII. Recipients and Service Providers Used
1. Microsoft Azure
For hosting, technical infrastructure, operational monitoring and the sending of transactional emails, we use services provided by:
Microsoft Ireland Operations LimitedOne Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
CERTENTIC Bridge is hosted in Azure data centres within the European Union.
Where Microsoft processes personal data on our behalf, this is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
2. Cloudflare
We use Cloudflare services for the secure and reliable provision of our publicly accessible services and for protection against abusive access and attacks.
In particular, technical connection data such as your IP address may be processed. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient provision of our services.
3. AI Services Selected by the User
CERTENTIC Bridge does not transmit iCloud data to an AI service on its own initiative.
Transmission takes place when you connect CERTENTIC Bridge to a supported AI service and initiate a request there which requires data to be retrieved from your connected iCloud account.
The recipient is the AI service selected by you. During the Open Beta, this may include, in particular, services provided by OpenAI or Anthropic.
The contractual and data protection terms of the respective provider apply to the further processing of data transmitted to that AI service. As a general rule, CERTENTIC has no influence over how the respective provider subsequently processes the information you transmit to it.
4. Transfers to Third Countries
When using the service providers referred to above or an AI service selected by you, personal data may be processed outside the European Union or the European Economic Area, in particular in the United States.
Where an adequacy decision of the European Commission applies to the respective recipient, the transfer is made on that basis. This applies in particular to US companies certified under the EU-U.S. Data Privacy Framework, insofar as the respective processing is covered by the certification.
Where no applicable adequacy decision exists, a transfer takes place only on the basis of other safeguards permitted under the GDPR, in particular the Standard Contractual Clauses pursuant to Art. 46 GDPR and, where necessary, supplementary protective measures.
VIII. Cookies and Local Storage in the Browser
We do not use cookies or comparable technologies for advertising, profiling or cross-site tracking purposes.
For the OAuth-based registration and authorisation process, we use a technically necessary session cookie. It is used to securely associate the browser with the authorisation process that has been initiated and to protect the process against unauthorised use. The cookie is used only for the duration of the respective registration and authorisation process and is technically protected against access by client-side JavaScript.
In addition, technically necessary local browser storage is used, in particular, to store your selected language setting and to temporarily process a pseudonymous session identifier for the registration and connection process.
Where information is stored on or read from your terminal device for these purposes, this is carried out on the basis of Section 25(2) TDDDG, insofar as this is strictly necessary to provide the service expressly requested by you.
No storage requiring consent takes place for advertising, analytics or tracking purposes.
Your contact email address, Apple and iCloud credentials, verification codes, and OAuth access and refresh tokens are not stored by CERTENTIC in local or session-based browser storage.
IX. Retention Period
Personal data are generally stored only for as long as necessary for the respective processing purpose or for as long as statutory retention obligations apply.
In particular:
- Diagnostic data from the registration and administration service pursuant to Section VI are generally deleted after 30 days.
- Technical telemetry from the connector service pursuant to Section VI is generally deleted after 90 days.
- Email verification data are processed only temporarily for the purpose of carrying out and securing the verification process.
- Data relating to registration and authorisation processes that have not yet been completed are processed only temporarily to carry out and secure the respective process. Once their validity has expired, they can no longer be used to continue the process and are removed as part of the intended technical cleanup processes.
- Account data are stored for as long as they are required to provide your user account and the connector service. This also applies to a user account set up in advance for as long as it is maintained for your intended use of CERTENTIC Bridge.
- Authorisation and security data required for an OAuth connection are actively processed only for as long as necessary for the respective connection and its secure administration. Expired, revoked or deactivated access authorisations may be retained for a limited period for secure processing, misuse detection and technical cleanup and are subsequently deleted in accordance with the applicable lifecycle and cleanup rules.
- Following termination of the user account, the stored iCloud credentials are deleted and the user account and its OAuth-based access authorisations are deactivated. OAuth connection data that are no longer required are deleted in accordance with the lifecycle and cleanup rules applicable to them.
- Where certain data remain necessary after termination of the user account due to statutory obligations or for the establishment, exercise or defence of legal claims, they are retained only for those purposes and only for the period required.
- Content retrieved through the connector from iCloud Mail and iCloud Calendar is not persistently stored by CERTENTIC.
X. Automated Decision-Making and Profiling
CERTENTIC does not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
XI. Rights of Data Subjects
Subject to the applicable statutory requirements, you have, in particular, the right to:
- access your personal data pursuant to Art. 15 GDPR,
- rectification of inaccurate data pursuant to Art. 16 GDPR,
- erasure pursuant to Art. 17 GDPR,
- restriction of processing pursuant to Art. 18 GDPR,
- data portability pursuant to Art. 20 GDPR, and
- object to processing based on Art. 6(1)(e) or (f) GDPR pursuant to Art. 21 GDPR.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future pursuant to Art. 7(3) GDPR.
To exercise your rights, you may contact [email protected].
XII. Right to Lodge a Complaint
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information of North Rhine-WestphaliaKavalleriestraße 2–4
40213 Düsseldorf
Germany
Email: [email protected]
Website: www.ldi.nrw.de
XIII. Amendments to this Privacy Policy
We may amend this Privacy Policy if legal requirements, our services or the processing of personal data change.
The current version published on this website applies.
Version: 28 August 2026
Note on the authoritative version
This English translation is provided for convenience only. In the event of any discrepancy, ambiguity or conflict between this English translation and the German-language Privacy Policy, the German-language version shall prevail. The authoritative German version is available at: