Privacy Policy

Last updated: 3 January 2025

1. Controller

The controller responsible for data processing on this website pursuant to Art. 4 (7) GDPR is:

Prof. Dr. Marco Barenkamp
MBSAS.AI Prof. Dr. Marco Barenkamp Advisory
Pastor-Lichtenbäumer-Str. 33
49134 Wallenhorst
E-mail: kontakt@profbarenkamp.com

2. Collection and storage of personal data

When using ThinkSnap, the following personal data are collected:

  • Username
  • E-mail address
  • Full name
  • Password (stored in encrypted form)
  • Created notes and tags
  • Audio recordings (temporarily, see details below)
  • Usage data (login times, features used)

3. Audio recordings and speech transcription

Function: ThinkSnap allows you to create notes via speech input.

Data processing:

  • Live transcription: Takes place directly in your browser via the Web Speech API. No storage on the server.
  • Audio recording: May optionally be recorded in parallel to live transcription and stored on our server.
  • Automatic transcription: Audio files older than 5 minutes are automatically transcribed with Whisper (open source, running locally on our server).
  • Deletion: After successful transcription, the audio file is automatically deleted.

Important:

  • All audio data remain on our server (no cloud services)
  • No transfer to third-party providers (e.g. Google, OpenAI Cloud)
  • Whisper runs locally on-premise on our server
  • You can delete audio files manually at any time
  • Maximum storage time: 5 minutes until automatic transcription

4. Purpose of data processing

The collected data are used for the following purposes:

  • Provision and management of your user account
  • Enabling the use of the platform’s features
  • Communication with you (e.g. password reset, important notifications)
  • Improvement of our services
  • Ensuring IT security

5. Legal basis

The processing of personal data is based on:

  • Art. 6 (1) (b) GDPR (performance of a contract)
  • Art. 6 (1) (a) GDPR (consent)
  • Art. 6 (1) (f) GDPR (legitimate interest)

6. Disclosure of data

Your personal data will not be passed on to third parties unless:

  • you have expressly consented to this,
  • there is a legal obligation to do so, or
  • disclosure is necessary to assert our rights.

7. Storage period

Your data are stored for as long as your user account is active. After your account is deleted, your data are deleted without delay, unless there are statutory retention obligations.

8. Cookies and tracking

We use cookies on this website. Detailed information can be found in our Cookie Policy.

8.1 Necessary cookies

These cookies are required for the operation of the website:

  • Session cookie: For authentication and login status
  • Remember-me cookie: For automatic login (only when the "Stay signed in" option is enabled)
  • Cookie consent cookie: Stores your cookie preferences

8.2 Google Analytics (optional)

Analytics tool: With your consent, we use Google Analytics to analyse website usage.

  • Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
  • Purpose: Analysis of user behaviour, improvement of the website
  • Legal basis: Art. 6 (1) (a) GDPR (your consent)
  • Data processing: Data processing agreement in accordance with Art. 28 GDPR has been concluded
  • IP anonymisation: Enabled (your IP address is truncated)
  • Storage period: 14 months (automatic deletion by Google Analytics)
  • Data transfer to the USA: Possible, Google uses EU standard contractual clauses
  • Withdrawal: Possible at any time via cookie settings

Disable Google Analytics: You can also disable Google Analytics by installing the browser add-on: Download browser add-on

Further information: Google Privacy Policy

Your choice: On your first visit you will be asked whether you consent to Google Analytics. You can change your settings at any time via the "Cookie settings" link in the footer.

9. Integration of external services

On our website, we integrate external resources via Content Delivery Networks (CDNs) to improve presentation. When the website is accessed, technically necessary data (IP address, browser information, referrer URL) are transmitted to the respective CDN providers.

9.1 Font Awesome (Cloudflare CDN)

Provider: Cloudflare CDN (cdnjs.cloudflare.com)

Purpose: Provision of icon fonts for the visual appearance of the website

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a technically flawless and attractive presentation)

Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/

9.2 Flag Icons (jsDelivr CDN)

Provider: jsDelivr CDN (cdn.jsdelivr.net)

Purpose: Provision of flag icons for multilingual display

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a technically flawless and attractive presentation)

jsDelivr privacy policy: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net

Note: The external libraries are only used on the public website (landing page), not in the application itself.

10. Your rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

11. Data security

We use technical and organisational security measures to protect your data against manipulation, loss, destruction or access by unauthorised persons. These include in particular:

  • Encrypted data transmission (HTTPS)
  • Encrypted password storage (BCrypt)
  • Regular security updates
  • Access restrictions

12. Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy to changed legal situations or changes to the service. The current Privacy Policy is available on our website at any time.

13. Contact

If you have any questions about data protection or wish to exercise your rights, please contact us at:

E-mail: kontakt@profbarenkamp.com

Back to homepage