This Privacy Policy explains how Argumentree collects, uses, and protects your personal data in compliance with the EU General Data Protection Regulation (GDPR) and German data protection law. We are committed to transparency and your data rights.
Argumentree ("we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We operate as a business-to-business (B2B) SaaS platform providing structured argumentation, meeting intelligence, and collaborative decision-making tools. Our Service is designed for organizations and their authorized users.
This Privacy Policy is designed to help you understand:
Our Commitment: We collect only the data necessary to provide and improve our Service. We do not sell your personal data to third parties. We implement strong security measures and respect your data rights under applicable law.
For the purposes of the EU General Data Protection Regulation (GDPR) and German Federal Data Protection Act (BDSG), the data controller for your personal data is:
Argumentree.AI is a product operated by Argumentree.
Dieter Stölzel, trading as Argumentree
Business Address:
Havelberger Str. 1
10559 Berlin, Germany
Owner (Inhaber):
Dieter Stölzel
VAT ID (USt-IdNr.): DE369356725
Important Note on Roles: The specific role we play in processing your data depends on the context:
See Section 12 for detailed explanation of these roles.
3.1 Who This Policy Applies To:
3.2 What This Policy Covers:
3.3 What This Policy Does NOT Cover:
3.4 Relationship to Other Documents:
This Privacy Policy should be read together with:
We collect different types of data depending on how you interact with our Service. Below is a comprehensive breakdown:
Information you provide when creating an Organization account:
Legal Basis: Contract performance (GDPR Article 6(1)(b)) - necessary to provide the Service
Financial information for paid subscriptions (processed by our payment processor, Stripe):
Important: Full credit card details are NOT stored by us. Stripe (our PCI-DSS compliant payment processor) handles all payment card data securely. We only receive payment confirmation and minimal card identifiers.
Legal Basis: Contract performance + Legal obligation (tax/accounting requirements under German law)
Information about Authorized Users within your Organization:
Legal Basis: Contract performance + Legitimate interest (providing personalized user experience)
Content and data you upload, create, or generate within the Service:
Important: For Customer Data, YOU are the data controller and WE are the data processor. We process this data only per your instructions. See Section 12 for details.
Legal Basis: Contract performance - we process this data to provide the Service as instructed by you
Technical information automatically collected when you use the Service:
Purpose: Improve Service performance, troubleshoot issues, understand usage patterns, enhance security
Legal Basis: Legitimate interest (Service improvement and security)
If you choose to authenticate using a blockchain wallet:
We DO NOT collect or store:
Legal Basis: Consent + Contract performance (optional authentication method)
See Section 15 for detailed blockchain wallet privacy information.
Information from your interactions with us:
Legal Basis: Legitimate interest (customer support and service improvement)
Data collected via cookies and similar technologies:
Legal Basis: Essential cookies (legitimate interest), Analytics/Marketing cookies (consent via cookie banner)
See Section 16 for complete Cookie Policy and how to manage your preferences.
To protect your privacy, we explicitly do NOT collect:
We collect personal data through the following methods:
5.1 Directly From You:
5.2 Automatically Through Service Use:
5.3 From Third Parties:
5.4 From Other Users in Your Organization:
Under GDPR, we must have a lawful basis to process your personal data. Below we explain which legal basis applies to each processing activity:
| Processing Activity | Legal Basis (GDPR) |
|---|---|
| Account registration & management | Contract performance (Article 6(1)(b)) |
| Providing the Service features | Contract performance (Article 6(1)(b)) |
| Processing Customer Data per your instructions | Contract performance (Article 6(1)(b)) |
| Payment processing & billing | Contract performance + Legal obligation (Article 6(1)(b) + (c)) |
| Tax & accounting records retention | Legal obligation (Article 6(1)(c)) - German HGB/AO |
| Service improvement & analytics | Legitimate interest (Article 6(1)(f)) |
| Security monitoring & fraud prevention | Legitimate interest (Article 6(1)(f)) |
| Customer support | Legitimate interest (Article 6(1)(f)) |
| Marketing to existing B2B customers | Legitimate interest (Article 6(1)(f)) - B2B soft opt-in |
| Analytics & marketing cookies | Consent (Article 6(1)(a)) |
| Blockchain wallet authentication | Consent (Article 6(1)(a)) + Contract (optional feature) |
| Legal claims & compliance | Legal obligation (Article 6(1)(c)) + Legitimate interest (Article 6(1)(f)) |
Legitimate Interest Balancing:
Where we rely on legitimate interest, we have conducted a balancing test to ensure our interests do not override your rights and freedoms. Key considerations:
You have the right to object to processing based on legitimate interest. See Section 13 for how to exercise this right.
We use your personal data for the following purposes:
7.1 To Provide the Service:
7.2 For Billing & Payment:
7.3 For Service Improvement & Development:
Important Commitment: We do NOT use your identifiable Customer Data (discussions, arguments, meeting transcripts) to train AI models that benefit other customers. Data is processed in real-time for YOUR benefit only. We may create anonymized, aggregated analytics (e.g., "average discussion length") where no individual or organization can be identified.
7.4 For Security & Fraud Prevention:
7.5 For Customer Support:
7.6 For Communications:
7.7 For Legal Compliance:
We DO NOT sell your personal data to third parties. We only share data in the following limited circumstances:
8.1 Service Providers (Subprocessors):
We engage carefully vetted third-party service providers to perform functions on our behalf. These providers process data only per our instructions and are bound by data protection agreements.
Microsoft Azure (Germany West)
Purpose: Cloud hosting and infrastructure
Location: Germany (EU)
Data: All Service Data and Customer Data
Stripe
Purpose: Payment processing
Location: United States (EU-US Data Privacy Framework certified)
Data: Billing information, payment card data
Azure AI / Meta Llama — Default LLM Provider
Purpose: Content translation, argument analysis, fallacy detection, debate analysis
Location: Sweden (EU) — Microsoft Azure Sweden Central
Data: Discussion and argument text for real-time analysis (no personally identifiable information)
Perplexity AI (Sonar API) — Argumentree.AI Only
Purpose: Web-search-augmented research features in Argumentree.AI product only (not used by other products)
Location: United States
Data: Text content for real-time analysis only
Complete Subprocessor List: Available at argumentree.ai/subprocessors. We will notify you 30 days before adding new subprocessors.
8.2 Within Your Organization:
8.3 Business Transfers:
8.4 Legal Requirements & Protection of Rights:
We may disclose personal data if required to:
Transparency Commitment: Where legally permitted, we will notify you before disclosing data to authorities and provide an opportunity to challenge the request. We will disclose only the minimum data necessary.
8.5 With Your Consent:
8.6 Anonymized & Aggregated Data:
Primary Data Location: Your data is primarily hosted on Microsoft Azure servers in Germany (Germany West region), ensuring data remains within the European Union.
9.1 Transfers Outside the EU/EEA:
In limited circumstances, your data may be transferred to countries outside the EU/EEA for specific services:
United States - Stripe (Payment Processing)
Safeguard: Stripe is certified under the EU-US Data Privacy Framework and uses Standard Contractual Clauses (SCCs)
Data Type: Billing information only
Sweden (EU) - Azure AI / Meta Llama (Default LLM Provider)
Safeguard: No international transfer — processed within EU on Microsoft Azure (same DPA as hosting)
Data Type: Discussion and argument text for real-time AI analysis (no PII transmitted)
United States - Perplexity AI (Argumentree.AI Only)
Safeguard: Standard Contractual Clauses (SCCs)
Data Type: Text content for web-search-augmented research (no PII transmitted)
9.2 GDPR-Compliant Transfer Mechanisms:
All international data transfers comply with GDPR Chapter V requirements through one or more of the following mechanisms:
9.3 Your Rights Regarding International Transfers:
9.4 Future Changes:
We are actively working to minimize international data transfers by:
We will update this Privacy Policy and notify you of any changes to international transfer practices that materially affect your data.
10.1 Where Your Data is Stored:
10.2 Security Measures:
We implement industry-standard technical and organizational measures to protect your data:
10.3 Your Security Responsibilities:
10.4 Data Breach Notification:
Security Contact: To report security vulnerabilities or incidents, email security@argumentree.ai. We take all reports seriously and will respond promptly.
10.5 Limitations:
While we implement strong security measures, no system is 100% secure. The internet and electronic communications are inherently insecure. We cannot guarantee absolute security, but we commit to:
We retain personal data only as long as necessary for the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
11.1 Retention Schedule:
| Data Type | Retention Period | Legal Basis / Reason |
|---|---|---|
| Account Information | Active account + 30 days after termination | Customer data retrieval window |
| Customer Data (Discussions) | Active + 30 days post-termination | ToS commitment, data export window |
| Billing Records & Invoices | 10 years | German tax law (HGB §257, AO §147) |
| Security Logs | 12 months | Security investigation needs |
| Anonymized Analytics | Indefinitely | Not personal data under GDPR |
| Support Tickets | 3 years after closure | Customer service quality, legal defense |
| Marketing Consent Records | Until withdrawn + 3 years | Proof of compliance (GDPR Article 7(1)) |
| Rolling Backups | 60 days | Disaster recovery, technical necessity |
| Meeting Transcripts [Future] | 90 days (auto-delete) | Data minimization (highly sensitive) |
| Blockchain Wallet Addresses | Until account deletion | Authentication method (public data) |
11.2 Account Deletion Process:
Users can request deletion of their account through Settings > Privacy > Delete Account. The deletion process includes:
What Gets Deleted vs Anonymized:
| Data Type | Action | Reason |
|---|---|---|
| Email, Username, Profile | Permanently Deleted | Personal identifiers removed |
| Password, Auth Tokens | Permanently Deleted | Security credentials removed |
| Profile Picture | Permanently Deleted | Visual identifiers removed |
| Arguments, Discussions, Comments | Anonymized | Attributed to "[Deleted User]" - preserves discussion integrity |
| Votes, Reactions | Anonymized | Preserved for aggregates, user link removed |
Deletion Timeline:
11.3 Legal Hold Exceptions:
Notwithstanding the retention schedule above, we may retain data longer if:
11.4 Data Export (Article 20 - Data Portability):
You can export all your personal data through Settings > Privacy > Export My Data.
Export File Structure:
profile.json/csv - Your account informationarguments.json/csv - All arguments you createddiscussions.json/csv - Your discussion contributionsvotes.json/csv - Your voting historyconsent-history.json - Record of your consent preferencesImportant: Data deletion is permanent and irreversible. We recommend exporting your data before requesting account deletion. Export links expire after 7 days - download promptly.
11.5 GDPR Email Notifications:
We send automated email notifications to keep you informed about your data rights actions:
| Action | Email Sent | Content |
|---|---|---|
| Deletion Requested | Immediately | Confirmation of scheduled deletion, grace period info, cancellation instructions |
| Deletion Cancelled | Immediately | Confirmation that account remains active |
| Account Deleted | After grace period | Final confirmation of deletion, list of data removed/anonymized |
| Data Export Ready | When processed | Download link, expiration date (7 days), file details |
Email Delivery:
11.6 Data Handling Upon Refund:
If you request and receive a refund under our 30-Day Money-Back Guarantee or any other refund policy, the following data handling applies:
Understanding data controller and data processor roles is important for GDPR compliance, especially for B2B services.
12.1 When We Are the Data Controller:
For Service Data (data about your use of the Service), Argumentree is the data controller:
Our Responsibility: We determine the purposes and means of processing this data. We are responsible for GDPR compliance for Service Data, including responding to data subject rights requests.
12.2 When We Are the Data Processor:
For Customer Data (content you create and upload), YOU (the customer) are the data controller and we are the data processor:
Our Responsibility: We process Customer Data only according to your documented instructions (via your use of the Service features). We provide technical and organizational measures to protect Customer Data per GDPR Article 28.
12.3 Data Processing Agreement (DPA):
12.4 Your Responsibilities as Data Controller:
12.5 Our Assistance to You:
As your data processor, we will assist you in fulfilling your GDPR obligations:
Key Takeaway: For Customer Data, YOU control what data is processed and how. We simply provide the tools and infrastructure. You remain responsible for GDPR compliance with respect to your Customer Data.
Under the EU General Data Protection Regulation (GDPR) and German Federal Data Protection Act (BDSG), you have the following rights regarding your personal data:
You can request a copy of the personal data we hold about you. We will provide this in a commonly used electronic format.
How to exercise: Email privacy@argumentree.ai or use the data export feature in your account settings.
You can request correction of inaccurate or incomplete personal data.
How to exercise: Update your account information in settings or contact support@argumentree.ai.
You can request deletion of your personal data in certain circumstances (e.g., data no longer necessary, consent withdrawn, unlawfully processed).
Limitations: We may retain data if required by law (e.g., billing records for tax compliance).
You can receive your personal data in a machine-readable format and transmit it to another service provider.
How to exercise: Use our data export feature (JSON/CSV formats) in account settings.
You can request temporary restriction of processing in certain circumstances (e.g., disputing data accuracy, unlawful processing).
How to exercise: Email privacy@argumentree.ai with your request.
You can object to processing based on legitimate interests (e.g., marketing, analytics). We will stop processing unless we have compelling legitimate grounds.
Absolute right to object to direct marketing - we will always honor this.
Additional Rights:
13.1 Consent Management Center:
You can manage all your consent preferences in one place through Settings > Privacy:
Key Features of Our Consent System:
How to Exercise Your Rights:
Contact Methods:
Response Time: We will respond to requests within one month (extendable to two months for complex requests with notice).
Verification: We may request proof of identity to prevent unauthorized access.
Free of Charge: Requests are generally free. We may charge a reasonable fee for manifestly unfounded or excessive requests.
Supervisory Authority Contact:
You have the right to lodge a complaint with the German Data Protection Authority or your local supervisory authority:
German Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Straße 153
53117 Bonn, Germany
Website: www.bfdi.bund.de
Email: poststelle@bfdi.bund.de
The Service uses artificial intelligence (AI) and machine learning to enhance your experience. Under GDPR Article 22, you have rights regarding automated decision-making.
14.1 AI-Powered Features:
14.2 AI Service Providers:
14.3 Data Processing for AI:
Privacy Commitment: Your discussions, arguments, and meeting transcripts are analyzed to provide insights to YOU. We don't use your data to improve AI for other customers. Your data remains yours.
14.4 Automated Decision-Making (GDPR Article 22):
14.5 Your Rights Regarding AI:
14.6 Transparency & Labeling:
Argumentree supports optional blockchain wallet authentication (Ethereum, Cardano, Polkadot) as an alternative login method. This section explains how we handle blockchain-related data.
15.1 What Wallet Data We Collect:
Critical: Argumentree is NOT a wallet provider or cryptocurrency service. We only use wallets for identity verification (authentication).
15.2 How Wallet Authentication Works:
15.3 Public Nature of Wallet Addresses:
15.4 No On-Chain Data Storage:
15.5 Your Wallet Security Responsibilities:
15.6 Data Retention for Wallet Addresses:
15.7 No Cryptocurrency Payments:
While we support wallet authentication, we do NOT accept cryptocurrency for Service payments. All payments are processed via traditional methods (credit card, bank transfer) through Stripe.
17.1 Types of Communications:
We may send you the following types of emails:
📧 Transactional Emails (Cannot Opt-Out)
Essential Service-related emails: Account notifications, password resets, billing receipts, security alerts, Terms/Privacy Policy updates.
Legal Basis: Contract performance + Legal obligation
📬 Product Updates & Feature Announcements (Opt-Out Available)
Information about new features, product improvements, Service updates relevant to your subscription.
Legal Basis: Legitimate interest (GDPR Article 6(1)(f)) - B2B soft opt-in for existing customers
🎯 Marketing & Promotional Emails (Opt-In Required)
Newsletters, case studies, webinar invitations, promotional offers, industry insights.
Legal Basis: Consent (GDPR Article 6(1)(a)) or Legitimate interest for existing B2B customers with opt-out
17.2 B2B Marketing (Soft Opt-In):
Under German and EU law, we may send marketing communications to existing B2B customers about similar services based on legitimate interest, provided:
17.3 How to Opt-Out (Unsubscribe):
Our Commitment: We respect your inbox. We will:
17.4 Custom Marketing Tool:
We use a custom internal marketing tool to manage email communications. This means:
17.5 Communication Preferences:
You can customize:
18.1 Age Restriction:
Argumentree is a business-to-business (B2B) service intended for use by adults aged 18 years and older. The Service is not directed at children, and we do not knowingly collect personal data from individuals under 18.
18.2 Account Registration Requirements:
18.3 No Intentional Collection from Children:
18.4 If We Discover Data from a Minor:
If we become aware that we have collected personal data from someone under 18:
18.5 Customer Organization Responsibilities:
If you are an Organization administrator:
Parents/Guardians: If you believe your child under 18 has provided personal data to Argumentree, please contact us immediately at privacy@argumentree.ai and we will promptly delete the information.
18.6 Compliance with Children's Privacy Laws:
19.1 External Links:
The Service may contain links to third-party websites, services, or resources that are not owned or controlled by Argumentree. For example:
19.2 Our Responsibility (Limited):
Your Responsibility: When you leave our Service and visit third-party websites, you should read their privacy policies and terms. We encourage you to be aware when you leave our Service and to review the policies of any third-party services you interact with.
19.3 Third-Party Integrations:
We may offer integrations with third-party services (e.g., productivity tools, cloud storage). When you enable these integrations:
19.4 Subprocessors vs. Third-Party Links:
Distinction: Subprocessors (Section 8) are service providers we engage to help deliver our Service (e.g., Azure hosting, Stripe payments). Third-party links are external websites/services you choose to visit. We control subprocessors through data processing agreements; we do not control third-party websites.
19.5 User-Shared Links:
20.1 Overview:
In accordance with the Digital Services Act (DSA) and our commitment to maintaining a safe platform, we process certain personal data for content moderation purposes.
20.2 Data Processed for Moderation:
20.3 Legal Basis (GDPR Art. 6):
20.4 Retention of Moderation Data:
20.5 Your Rights Regarding Moderation:
20.6 Automated Content Moderation:
We may use automated tools to detect obviously illegal content (e.g., CSAM hash-matching). Per GDPR Art. 22, decisions significantly affecting your account will always include human review. You have the right to contest automated decisions and request human intervention.
20.7 Reporting Concerns:
To report content or submit a moderation appeal:
20.1 Right to Modify:
We may update this Privacy Policy from time to time to reflect:
20.2 Notice of Material Changes:
For material changes that significantly affect how we process your personal data:
Material changes include:
20.3 Non-Material Changes:
Minor changes (corrections, clarifications, formatting) may be made without advance notice. These include:
20.4 Acceptance of Changes:
20.5 Version History:
Current Version Information:
20.6 Review Recommendation:
We recommend reviewing this Privacy Policy periodically to stay informed about how we protect your data. The "Last Updated" date at the top of this document shows when changes were last made.
For questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
Legal Entity (Data Controller):
Argumentree
Business Address:
Havelberger Str. 1
10559 Berlin, Germany
Privacy Contact Email:
Primary contact for: Data subject rights requests, privacy questions, consent management
Data Protection Officer:
Email: dpo@argumentree.ai
Note: DPO appointment is currently not required based on our processing activities and scale. If this changes, DPO contact will be listed here.
Other Contact Points:
21.1 Response Time:
21.2 Supervisory Authority:
You have the right to lodge a complaint with a data protection supervisory authority:
German Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Address:
Graurheindorfer Straße 153
53117 Bonn, Germany
Phone: +49 (0)228 997799-0
Fax: +49 (0)228 997799-550
Email: poststelle@bfdi.bund.de
Website: www.bfdi.bund.de
If you are located outside Germany, you may also contact your local data protection authority. A list of EU/EEA authorities is available at: European Data Protection Board
Depending on your location, you may have additional privacy rights under local laws. This section provides information for residents of specific regions.
GDPR rights are covered throughout this Privacy Policy (particularly Section 13). Key points:
UK Residents: Following Brexit, UK GDPR applies similarly to EU GDPR. UK supervisory authority: Information Commissioner's Office (ICO) - ico.org.uk
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have specific rights:
Right to Know: Request disclosure of personal information collected, used, and shared (past 12 months)
Right to Delete: Request deletion of personal information (with exceptions)
Right to Opt-Out of Sale/Sharing: We do NOT sell or share personal information, so no opt-out needed
Right to Correct: Request correction of inaccurate personal information
Right to Limit Sensitive Personal Information: We do not use sensitive personal information for purposes beyond providing services
Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights
How to exercise: Email privacy@argumentree.ai with "California Privacy Rights" in subject line
Verification: We may request verification of identity before fulfilling requests
Authorized Agent: You may designate an authorized agent to make requests on your behalf with proper authorization
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA):
Canadian Privacy Commissioner: priv.gc.ca
Additional US states have enacted comprehensive privacy laws:
If you are a resident of these states, contact privacy@argumentree.ai to exercise your rights
22.1 International Users:
If you are located outside the regions listed above, you may still exercise the rights described in Section 13 (GDPR rights). We apply GDPR as our baseline standard globally, providing strong privacy protection regardless of location.
22.2 Evolving Privacy Laws:
Privacy laws are rapidly evolving worldwide. We monitor developments and update our practices to comply with new requirements. If new laws in your region grant additional rights, we will honor them even if not explicitly listed here.
Last Updated: January 1, 2026
Version: 1.0
Effective Date: January 1, 2026
By using the Argumentree Service, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service.
© 2025 Argumentree. All rights reserved.
Questions about this Privacy Policy? Contact our privacy team