Privacy Policy
Information on data processing within the Peduno Application.
1. Controller and Scope
This Privacy Policy applies to the use of the web application \"Peduno\" (hereinafter \"App\").
Responsible Provider / Controller:
Philipp Rajkovic
Kirchdorfstrasse 18
39037 Vals
Italy
Email: support@peduno.de
Target Audience and Responsibility:
Our services are directed exclusively at law firms, legal professionals, and institutional entities (\"Users\"). When users input personal data of their clients into the App, they act as the Controllers under GDPR. Peduno acts as a technical service provider and processor. The responsibility for the lawful collection and input of client data into the App lies solely with the User.
2. Hosting and Infrastructure
Our App is hosted by Vercel Inc. (USA). Vercel provides the technical frontend infrastructure. Connection data (e.g., IP address, browser information) is processed in server logs to ensure security and stability. Data transfers to the USA are covered by Standard Contractual Clauses (SCC).
3. Data Processing & Storage (Supabase)
We use Supabase as our central database and backend solution. We strictly differentiate storage between client case files and our general Knowledge Base.
A) Case Files (Strictly Isolated Storage)
All files, case data, uploaded documents, and subsequent AI analyses are stored in strict isolation.
- Access Control: Secure \"Row-Level-Security\" (RLS) guarantees that only you (and authorized team members) have access to these files.
- Purpose: Providing app functionality, full-text search, and knowledge retrieval for the Kanzlei-Gedächtnis.
- Deletion: Upon deleting your account, these case files are permanently and irrevocably deleted.
B) Kanzlei-Gedächtnis (firm-isolated)
Optionally, your firm builds its own Kanzlei-Gedächtnis (standard positions, internal rules, your own documents). This knowledge belongs to your firm alone.
- Strict Isolation: Like your case files, the Kanzlei-Gedächtnis is strictly separated per firm via Row-Level Security. Only authorized members of your firm have access; there is no cross-firm sharing.
- No crowd intelligence: Your content is never pooled, and is never used to train models or to improve the application for other users.
- Deletion: When your firm account is deleted, the Kanzlei-Gedächtnis is permanently and irrevocably removed along with it.
C) General Legal Knowledge (public sources)
For general legal research, Peduno maintains a knowledge base drawn exclusively from publicly available legal sources — in particular published court decisions and statutes. No user, client, or case data is used for this.
Storage Location: All databases are hosted on servers in the EU (Frankfurt am Main) within AWS infrastructures managed by Supabase.
4. Use of Artificial Intelligence
Peduno's AI features rely on the professional API platforms of several specialized providers. All operate under their enterprise / commercial terms with a Data Processing Agreement (DPA):
- Anthropic PBC (USA) – deep legal analysis and subsumption (Claude).
- OpenAI, L.L.C. (USA) – chat dialogue and semantic search (embeddings).
- Google LLC (USA) – the spoken VoiceMode dialogue (Gemini).
No Training on Your Data
None of these providers use the files, prompts, or analyses submitted via our API connections to train their models. Your data remains fully confidential.
(Source: OpenAI Enterprise Privacy)
Encryption & Data Retention
All transfers are encrypted (TLS 1.2+). Providers retain API payload data, if at all, only briefly for abuse monitoring and then delete it automatically (OpenAI, for example, for up to 30 days).
Note on Attorney-Client Privilege
Transfers to the USA are safeguarded by appropriate guarantees (e.g. the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses; providers are certified to standards such as SOC 2 Type II). However, we recommend pseudonymizing highly sensitive files prior to upload if required by local professional regulations.
5. Transactional Emails (Resend)
We use Resend (USA) exclusively for technical transactional emails (e.g. login magic links, team invites, deadline notifications). No marketing emails are sent.
6. Cookies and Tracking
We do not use any third-party tracking tools (such as Google Analytics or PostHog) or marketing pixels. Only essential technical cookies are utilized.
7. Data Security
We apply advanced cryptographic technologies (TLS/SSL, AES-256) and strict Row-Level-Security (RLS) to safeguard database access.
8. Your Rights and Deletion Requests
You have the right to information, rectification, restriction, and deletion of your data. To request account deletion, email support@peduno.de.
9. Amendments
We reserve the right to amend this Privacy Policy to align with new legal requirements or app features.
Last updated: June 2026