We, iteratec GmbH, believe that you should have control over your data. We take the protection of your personal data very seriously and strictly adhere to data protection laws. This privacy policy provides you with an overview of how we ensure this protection, the type of data we collect, the purpose for which we collect it, and your rights concerning your personal data.
If you have questions about data protection, you can contact us at any time.
Changes that we make to the "Privacy Policy of iteratec GmbH" in the future will be posted on this page. This privacy policy is effective as of December 11, 2024.
Responsible Party
Company: iteratec GmbH Address: St.-Martin-Str. 114 Postal Code, City: 81669 Munich Commercial Register Number: HRB 113519 Managing Directors: Klaus Eberhardt, Jörg-Stefan Rauch, Michael Schulz, Alexander Youssef Telephone: +49 89 61 45 51 0 Email: office@iteratec.com
Data Protection Officer
You can reach our Data Protection Officer at datenschutz@iteratec.com.
1.1. This privacy policy informs you about the type, scope, and purpose of the processing of personal data within our websites, features, and content (hereinafter referred to collectively as "Website"). The privacy policy applies regardless of the domains, systems, platforms, or devices (e.g., desktop or mobile) used to access the online offering.
1.2. The terms used, such as "personal data" or its "processing," refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
1.3. The personal data of users processed within the online offering include usage data (browser type and version, operating system, URL of the previously visited page, IP address of the accessing device, and time of request) and content data (e.g., inputs in the application form).
1.4. The term "user" encompasses all categories of persons affected by the data processing. These include our business partners, customers, prospects, and other visitors to our online offering. The terms used, such as "user," are gender-neutral.
1.5. We process personal data of users only in compliance with the relevant data protection regulations. This means that user data is processed only when legally permitted, especially if the data processing is required by law, if the users have given consent, or based on our legitimate interests (e.g., interest in analyzing, optimizing, and economically operating and securing our online offering in accordance with Art. 6(1)(f) GDPR, particularly for reach measurement, profile creation for advertising and marketing purposes, data access tracking, and the use of third-party services).
1.6. We point out that the legal basis may include consent for processing, the fulfillment of our services and execution of contractual measures, compliance with legal obligations, or protection of our legitimate interests (Art. 6(1)(a) and Art. 7 GDPR).
1.7. Sources and Data Usage: We process personal data from customers, suppliers, prospects, applicants, and employees in the context of business relationships, application procedures, or employment. We also use data from publicly accessible sources where processing is permissible. The legal basis is compliance with (pre-)contractual obligations, legitimate interest, legal requirements, or consent from the data subject.
2.1. We implement organizational, contractual, and technical security measures in accordance with the state of the art to ensure compliance with data protection laws and to protect the data we process against accidental or intentional manipulation, loss, destruction, or unauthorized access.
2.2. Security measures include the encrypted transmission of data between your browser and our server.
Found a security vulnerability? Please contact us at security@iteratec.com. We will respond as quickly as possible. For encrypted contact, you can use our certificate.
2.3. As the security team at iteratec, we take care of your safety on the internet. If you experience issues such as the misuse of our or your network access or receive spam from one of our addresses, please contact us at abuse@iteratec.com.
3.1. Data sharing with third parties occurs only within the framework of legal requirements. User data is shared with third parties only if necessary for contractual purposes (Art. 6(1)(b) GDPR) or based on our legitimate interests (Art. 6(1)(f) GDPR) in operating our business efficiently.
3.2. If we use subcontractors to provide our services, we take appropriate legal precautions and adopt suitable technical and organizational measures to ensure the protection of personal data under relevant legal provisions.
3.3. If this privacy policy references content, tools, or other means provided by third-party providers (hereinafter referred to collectively as "third-party providers"), such transfers occur only to countries with an adequate level of data protection or within the GDPR's jurisdiction.
This application sets only cookies that are necessary to operate it — sign-in, protection of the sign-in forms, and carrying an invitation through the sign-in process — plus one cookie holding the interface language you selected. It uses no advertising, tracking or analytics cookies and embeds no third-party scripts, so it asks for no cookie consent.
Every entry, its purpose and its storage duration is listed on the separate cookies page.
Stored data will be deleted as soon as it is no longer needed for its intended purpose, and legal retention obligations do not prevent deletion. If data cannot be deleted, its processing will be restricted. This applies, for example, to user data retained for commercial or tax purposes.
Users may object to the future processing of their personal data at any time, following legal provisions. This includes objection to processing for direct marketing purposes. Objections should be addressed to the Responsible Party.
DRAFT — not yet reviewed. The sections above were inherited from a text that describes a marketing website. This one was written from the application's own code and infrastructure on 2026-08-07 so the gap is at least visible; it has not been checked by anyone qualified to sign it off. Where a decision is missing, it says so rather than inventing one.
8.1. Account data. When you sign in through Microsoft Entra ID we store your name, your email address and your role. We do not store a password; authentication happens at Microsoft.
8.2. Sprint content. Everything you and your team enter: artifacts and their version history, cards, decisions, todos, board tickets, workshop boards (stakeholders, event storming, pain points, opportunities, evaluations, PoC scope), interviews, briefings, learnings and feedback. This content is visible to the other members of that sprint.
8.3. Conversations with the AI co-pilot. Your messages and the assistant's replies are stored with the sprint phase they belong to, so a conversation survives a reload.
8.4. Recordings and transcripts. Where you use the voice features, speech is transcribed and the transcript is stored with the sprint; audio may be stored alongside it. Transcription runs on Microsoft Azure Speech, and the voice assistant on Azure's realtime speech model.
8.5. Uploads. Documents and images you upload are stored in Azure Blob Storage. They are served through signed links that expire after one hour.
8.6. Technical data. Container logs go to Azure Log Analytics. When tracing is enabled, each AI call is recorded with its token count and cost for operational review.
8.7. Where it is stored. All of it in Microsoft Azure, region West Europe (Netherlands): a PostgreSQL server reachable only from the application's own private network, a storage account, and the Azure OpenAI resource in the same region.
8.8. Who else sees it. Microsoft, as our processor, for the services named above — sign-in, the language model, speech, storage and logging. Content you enter is sent to the Azure OpenAI resource when you use the co-pilot. There are no advertising, analytics or tracking third parties.
8.9. How long we keep it. Open — to be decided. Today an invitation link expires after seven days and an abandoned voice session is closed automatically; beyond that the application deletes nothing on a schedule. Sprint content stays until it is deleted by hand. Ask us to delete your data and we will.
We reserve the right to amend this privacy policy to reflect changes in legal requirements, our services, or data processing. Such changes apply only to declarations regarding data processing. Where user consent is required or contractual terms are affected, changes will occur only with user consent.
Users are encouraged to review the privacy policy regularly.
Munich, December 11, 2024 The Management