Privacy Policy
Last updated: August 2026
See also: Sub-processors · Data Processing Agreement · Cookie Policy · Terms of Service
1. Data Controller
The controller responsible for data processing is:
Kaufmann Elsner GbR
Email: [email protected]
2. Overview
This privacy policy explains how Workshop Weaver ("we", "our" or "us") collects, processes and protects your personal data when you visit our website (workshopweaver.com) or use our AI-powered workshop planning platform (app.workshopweaver.com). We process this data in compliance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications-Telemedia Data Protection Act (TTDSG).
3. Data We Collect
3.1 Data you provide directly
- Account information: Name, email address and password when you register. The password is stored solely as a cryptographic hash.
- Workshop content: Goals, agendas, descriptions, notes, target audiences, location and scheduling data, and all planning data you create.
- Chat history: Your messages to the AI companion and its replies are stored permanently with the relevant workshop so that context is preserved across sessions.
- Uploaded files: PDF, DOCX, TXT and Markdown files as well as images (PNG, JPEG, WebP) up to 5 MB that you upload into the chat — including the text extracted from them.
- Voice recordings: If you use voice input, the recording is processed to convert it into text. We do not store the audio file itself; only the resulting text is kept.
- Contact inquiries: Name, email and message content when you use our contact form.
- Payment information: Billing data processed by our payment provider Stripe — full card details never reach our servers.
- Consent records: The time you accepted the Terms of Service and this privacy policy, together with your answer to the question about product emails and when you gave it.
3.2 Data collected automatically
- Server log data: IP address, browser type, operating system, referring URL, pages visited, and the date and time of access.
- Cookies and local storage: See Section 5.
- Product and usage data: Which features you open, when you create a workshop or generate an agenda, and technical measurements of AI calls (model, token count, cost, duration). The content of your prompts is not transmitted.
- Email delivery logs: Whether an email we sent was delivered, opened, or a link within it was clicked, each with a timestamp and the recipient address.
- Security data: Your IP address and bot-detection signals during registration and sign-in, to defend against automated attacks. Failed attempts are counted per account; the email address is only processed as a hash for this purpose.
4. Legal Basis for Processing
We process your personal data on the following legal bases under Art. 6(1) GDPR:
- Consent (Art. 6(1)(a) GDPR): For analytics and marketing cookies on our website and for product and marketing emails. You may withdraw your consent at any time with future effect.
- Contract performance (Art. 6(1)(b) GDPR): For providing the platform, managing your account, processing payments and all AI features — agenda generation is the core service.
- Legal obligations (Art. 6(1)(c) GDPR): For tax and accounting records and statutory retention requirements.
- Legitimate interests (Art. 6(1)(f) GDPR): For server logs and error diagnostics (IT security and operability), for defending registration and sign-in against automated attacks, for delivery logs of our emails (proof of deliverability), and for product analytics inside the signed-in application. The latter rests on our legitimate interest in understanding which features of the application are actually used; it is not part of the cookie consent and you may object to it at any time under Art. 21 GDPR.
5. Cookies and Local Storage
We use cookies and comparable technologies. In accordance with § 25 TTDSG, we set non-essential cookies on our website only after your explicit consent via the cookie banner.
5.1 Necessary cookies
These cookies are required for operation and cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
| CookieConsent | Stores your cookie consent preferences | 1 year |
| NEXT_LOCALE | Stores the language selected on the website | 1 year |
| preferred_lang | Carries your language choice between website and application | 1 year |
| ww_attribution | Remembers campaign parameters (utm_*, gclid, fbclid) to attribute sign-ups | 30 days |
5.2 Analytics cookies (consent required)
These services help us understand how visitors interact with our website.
| Service | Provider | Purpose | Data location |
|---|---|---|---|
| PostHog | PostHog Inc. | Product analytics | EU (eu.i.posthog.com) |
| Google Analytics 4 | Google Ireland Ltd. | Website audience measurement | EU / USA* |
| Google Tag Manager | Google Ireland Ltd. | Management of analytics scripts | EU / USA* |
5.3 Marketing cookies (consent required)
These services are used for marketing and for attributing inquiries.
| Service | Provider | Purpose | Data location |
|---|---|---|---|
| HubSpot | HubSpot Inc. | CRM and marketing automation | EU (eu1 region) |
5.4 Local storage in the application
Within the application itself we store some entries in your browser's local storage. This data does not leave your device and is not transmitted to us; it is removed when you sign out or clear your browser storage.
| Entry | Purpose | Duration |
|---|---|---|
| wasp:sessionId | Keeps you signed in (session identifier) | until you sign out |
| View and layout preferences | Sidebar, density, view mode, theme | indefinite, until you clear them |
| ww-collaborator-guest-name / -email | Pre-fills the comment form on share links | indefinite, until you clear them |
*Google may transfer data to the USA. This transfer is based on the EU-US Data Privacy Framework (adequacy decision by the European Commission, July 2023); Google LLC is certified under that framework.
6. Processors and Recipients
We use the following service providers as processors or recipients. A complete and continuously maintained list including addresses and data categories is available on our page Sub-processors.
6.1 Hosting and infrastructure
The application and its database run on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in a data centre inside the EU. The web interface is delivered and protected against overload via Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA). Our marketing website is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). All three process server log data including IP addresses. Legal basis: Art. 6(1)(b) and (f) GDPR.
6.2 AI processing (Anthropic and OpenAI)
For our AI features we use the interfaces of Anthropic, PBC (548 Market St, PMB 90375, San Francisco, CA 94104, USA) and OpenAI, L.L.C. (1960 Bryant Street, San Francisco, CA 94110, USA). Anthropic (Claude) generates agendas, powers the workshop companion and reads uploaded documents and images. OpenAI converts voice recordings into text, answers questions in the help chat, and takes over agenda and chat requests when the primary provider is unavailable. What is transmitted: the content you enter, the chat history so far and uploaded files.
- Under their respective terms, Anthropic and OpenAI do not use inputs and outputs submitted through their programming interfaces to train their models by default.
- Processing takes place on servers in the USA. The transfer is safeguarded by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
- We do not ourselves transmit personal data about third parties to the AI providers. What is transmitted is determined solely by you, through what you type and what you upload — please do not enter other people's personal data there.
- Legal basis: Art. 6(1)(b) GDPR — AI generation is the core function of the service.
6.3 File storage
Uploaded files are stored with Cloudflare, Inc. in its R2 object storage. We use a storage region explicitly restricted to the EU, so the files do not leave the European Union. Access is only ever granted through short-lived signed links valid for 60 seconds. Legal basis: Art. 6(1)(b) GDPR.
6.4 Email delivery (Mailgun)
We send transactional and product emails via Sinch Mailgun (Mailgun Technologies, Inc.) using its EU infrastructure; the recipient address, subject and message content are transmitted there. Mailgun places a counting pixel in our emails and rewrites the links they contain, so that we can tell whether an email was delivered and opened and whether a link was clicked. For this we store the recipient address, subject, status and the timestamps of these events — but not the content of the email, your IP address or your browser. Legal basis: Art. 6(1)(b) GDPR for transactional email, Art. 6(1)(f) GDPR for delivery measurement, and Art. 6(1)(a) GDPR for product and marketing email.
6.5 Product analytics (PostHog)
We use PostHog Inc. for product analytics; processing takes place in the EU (eu.i.posthog.com). On our website PostHog is activated only after your consent via the cookie banner (Art. 6(1)(a) GDPR). Inside the signed-in application, however, we collect product events on the basis of our legitimate interest (Art. 6(1)(f) GDPR); your user identifier and your email address are transmitted as attributes. In addition we transmit technical measurements of our AI calls — model, token count, cost, duration and error type. The content of your prompts and of the AI replies is not transmitted.
6.6 Error diagnostics (Sentry)
To detect and fix software faults we use Sentry (Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA). Transmitted are error messages, technical state data and, for server-side errors, your user identifier and email address. A share of sessions is captured as a screen recording for fault analysis; all text is masked before transmission and media content is blocked. Legal basis: Art. 6(1)(f) GDPR.
6.7 Abuse prevention (Cloudflare Turnstile)
Registration and sign-in are protected by Cloudflare Turnstile, a method for distinguishing humans from automated scripts. Your IP address and technical characteristics of your browser are transmitted to Cloudflare in the process. Turnstile sets no advertising cookies and builds no cross-site profile. Legal basis: Art. 6(1)(f) GDPR (protection against automated attacks).
6.8 Payment processing (Stripe)
We use Stripe Inc. (510 Townsend Street, San Francisco, CA 94103, USA) to process payments. When you take out a paid subscription, your payment data is transmitted directly to Stripe; we do not store full payment details. We transmit your email address and your internal user identifier to Stripe. Stripe is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(b) GDPR.
6.9 Website analytics and customer relations
On our marketing website we use Google Analytics 4 and Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) as well as HubSpot Inc. (25 First Street, Cambridge, MA 02141, USA). These services are activated only after your consent via the cookie banner. Legal basis: Art. 6(1)(a) GDPR.
6.10 Contact form
Messages from our contact and inquiry form are delivered by email to our mailbox and handled there. Name, email address and your message text are transmitted in the process. We retain the correspondence for as long as is necessary to deal with your request. Legal basis: Art. 6(1)(b) or (f) GDPR (handling your inquiry).
6.11 Facilitation methods library
Our methods library contains descriptions of facilitation methods from our own sources, openly licensed sources (Creative Commons) or sources rewritten in our own words. Methods taken from third parties are attributed on the relevant page. No personal data is transmitted to third parties when browsing the library.
7. Collaboration, Share Links and Guests
Workshop Weaver is built for collaboration. The following features make data visible to other people — please consider what you share through them:
- Teams: If you assign a workshop to a team, every member of that team can see its full content — including goals, context, chat history and uploaded files. Team members also see each other's names and email addresses. Personal workshops with no team assignment remain private.
- Public participant links: You can share an agenda via a link that is accessible without signing in. Anyone who knows the link sees the agenda including location, times and any stored video-conference address. The page is excluded from search engines, but the link itself carries no further protection. You can revoke the share at any time in the application.
- Collaboration links: For feedback you can generate a separate link, which can optionally carry a password and an expiry date.
- Comments from guests: Anyone commenting via a collaboration link provides a name and may voluntarily leave an email address. These details are stored and are visible to the person who shared the link; other guests see only the name. If you pass such a link on, please inform the recipients about this processing. Guests may request deletion of their details at any time at [email protected].
8. Data Transfers to Third Countries
Some of our service providers are based in the USA. Where personal data is transferred there, this is safeguarded as follows:
- EU-US Data Privacy Framework: For providers certified under the framework — Google and Stripe.
- Standard Contractual Clauses (SCCs): For providers not covered by an adequacy decision — in particular Anthropic, OpenAI and Sentry.
- Processing in the EU: PostHog, Mailgun and HubSpot process in their EU data centres; our servers, databases and file storage are located exclusively in the EU.
9. Data Retention
We retain your data only for as long as necessary for the purposes described:
- Account data: For the duration of your account. Following a deletion request it is deleted within 30 days.
- Workshop content and chat history: For the duration of your account; deleted together with the account.
- Uploaded files: 30 days after you archive the associated workshop, after which they are deleted automatically. If you delete a workshop permanently, they are removed immediately.
- Unconfirmed registrations: 14 days, after which the account is deleted in full.
- Empty drafts: 7 days.
- Email delivery logs: 180 days.
- Server log data: 7 days. It arises at our hosting providers and is deleted automatically thereafter; longer storage occurs only insofar as a specific security incident requires it.
- Security and abuse data: 2 hours (counters for sign-in attempts and request rates).
- Payment and billing records: 10 years after the end of the contract (§ 147 AO, § 257 HGB).
- Contact inquiries: 3 years after the last communication, or longer where required for legal claims.
- Product analytics data: 12 months.
- Error diagnostics data: 90 days.
Where statutory retention obligations prevent deletion, processing is restricted instead and the data is deleted once the period expires.
10. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): Obtain confirmation of whether we process your data and request a copy.
- Right to rectification (Art. 16 GDPR): Request correction of inaccurate personal data.
- Right to erasure (Art. 17 GDPR): Request deletion of your personal data ("right to be forgotten").
- Right to restriction (Art. 18 GDPR): Request restriction of processing in certain circumstances.
- Right to data portability (Art. 20 GDPR): Receive your data in a structured, commonly used and machine-readable format. We provide this on request.
- Right to object (Art. 21 GDPR): Object at any time to processing based on legitimate interests — this expressly includes product analytics in the signed-in area.
- Right to withdraw consent (Art. 7(3) GDPR): Withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise these rights, contact us at [email protected].
11. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
HolstenstraĂźe 98, 24103 Kiel, Germany
Phone: +49 431 988-1200
Website: www.datenschutzzentrum.de
12. AI Processing and Automated Decision-Making
Workshop Weaver uses artificial intelligence to generate workshop agendas, suggest methods, analyse uploaded documents and convert speech into text. This AI processing:
- is based on the information you provide — goals, context, constraints, uploaded files and chat messages;
- makes no legal or similarly significant decisions about you; automated decision-making within the meaning of Art. 22 GDPR does not take place;
- does not use your content to train AI models — the interfaces of Anthropic and OpenAI do not use submitted inputs and outputs for that purpose by default;
- is provided by Anthropic and OpenAI (see Section 6.2); your input is transferred to the USA for this purpose;
- also extends to content you upload: images and scanned documents are transmitted in full to the AI provider for text recognition.
Recommendation: Do not enter sensitive personal data about third parties (e.g. employees or participants) into AI input fields, and do not upload documents containing such data. Describe goals and context in general terms where possible. You remain responsible for the content you enter into the application.
13. Data Security
We take appropriate technical and organisational measures to protect your personal data: TLS encryption of all transmissions, encryption of stored data, passwords held only as hashes, encrypted storage of any keys you deposit, protection of registration and sign-in against automated attacks, access controls limited to authorised personnel, and regular updates of the components we use.
14. Changes to This Privacy Policy
We may update this privacy policy to reflect changes in our processing or in the legal framework. We will notify registered users of material changes by email. The current version is always available at: workshopweaver.com/privacy
15. Contact
For questions about this privacy policy or your personal data, you can reach us at:
Kaufmann Elsner GbR
Email: [email protected]