Information about data processing

Privacy Notice

Updated: 3 September 2026 · Version 2026-09-03-v1

1. Controller and privacy contact

Cleero – Achilleas Pliakas
Sole proprietorship, owner: Achilleas Pliakas
Orleansstraße 41
81667 München
Deutschland
Email: info@cleerotrustschutz.com

2. Provision of the website

The website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. When the site is accessed, technically necessary connection data is processed, including IP address, time, requested resource, browser information and status code. Processing serves secure and stable delivery, attack prevention and error analysis. These legitimate interests support processing under Article 6(1)(f) GDPR. Log data is deleted once it is no longer required for operations, security or statutory evidence.

3. Contact form

When you contact us through the form, we process your name, company, contact details, selected topic and message in order to handle the enquiry. The legal basis is Article 6(1)(b) GDPR where pre-contractual steps are involved, and otherwise Article 6(1)(f) GDPR. Our legitimate interests are efficient handling of business enquiries, abuse prevention and traceable communication records. Required fields are necessary to assign and answer the enquiry. Please do not transmit sensitive data or documents through the general form.

Enquiries are deleted after processing is complete unless statutory retention or evidence duties apply. If no contract is formed, the regular maximum retention period is 180 days. A daily automated cleanup removes expired records.

4. Security and session cookie

A technically necessary session cookie is set on the contact page and in the Cleero Check. It protects forms against abusive requests and is deleted when the browser is closed. It is not used for analytics, advertising or profiling. Access to the device is based on section 25(2)(2) TDDDG; subsequent processing is based on Article 6(1)(f) GDPR.

5. Cleero quick checks and assessment release

For the general Cleero Check and the Article 50 quick check, answers are initially processed only in the browser. The general check also records selected business topics and a broad size band to display relevant review topics; these details do not change the orientation score. After completion, the check details are submitted together with your full name, company and business email when you unlock the full assessment. A phone number remains optional. Cleero may contact you once about the requested assessment. Processing is necessary to provide the requested assessment and take pre-contractual steps under Article 6(1)(b) GDPR.

The orientation score is calculated through fixed rules from the answers and serves only as a non-binding working aid. Cleero does not use it to make a solely automated decision with legal or similarly significant effects under Article 22 GDPR.

Check enquiries are stored securely and deleted after no more than 180 days if no contract is formed and no statutory evidence or retention duty applies. A daily automated cleanup removes expired records. Data is not used for newsletters or disclosed for advertising.

6. Secure Intake, order processing and automated assessment

For an activated Cleero order, we process business contact details, company, product, payment status and case number, as well as information entered in the secure area, uploaded documents, document metadata, workflow steps, findings, tasks and results. The purpose is to perform the contract, including securely requesting and receiving information, structured assessment, creating the agreed outputs, communication and evidence of workflow status. The legal basis is Article 6(1)(b) GDPR. Security, access and event logs are based on Article 6(1)(f) GDPR; our legitimate interests are abuse prevention, access control, error investigation and traceable operations.

The personal link contains a random, non-guessable access value in the URL fragment; that fragment is not transmitted to the web server during a normal page request. The registered email is also verified by a time-limited one-time code. A technically necessary session cookie maintains the protected login (section 25(2)(2) TDDDG). Case records, documents and result files are encrypted at rest outside the public web directory. Access is limited to the relevant customer and expressly authorised internal personnel; the back office also requires a time-limited security code. The case history records only necessary events and no document contents.

Cleero separates file security screening, local content analysis, the Evidence Engine and versioned rule decisions. Customer statements initially count only as claims; documents, source locations, links and retests increase the evidence level. The result is always resolved, further information required or human legal review required. The assessment is a non-binding working aid and does not make a solely automated decision with legal or similarly significant effects. Ambiguous legal issues are prepared with facts and sources for human review.

Two external AI functions are technically prepared and disabled by default. The Review Copilot receives only pseudonymous control IDs, findings, priorities, document types and evidence status; document text is excluded from that function. After local extraction, the optional document AI may receive shortened and automatically pseudonymised text segments in order to identify the document type and facts. The original file, filename, customer identity and case number are not transmitted. Particularly sensitive contexts are processed only after a separate technical release; automated pseudonymisation carries residual risk. Cleero sets store=false for API requests so that no durable API application state is requested. This does not automatically provide Zero Data Retention. Unless ZDR has been confirmed for the OpenAI organisation and the specific project in use, prompts, responses and derived metadata may, according to the provider, generally be processed for up to 30 days in abuse-monitoring logs; legal or security reasons may require longer retention. Prompt caching can create additional temporary state for supported models. Document AI therefore remains blocked for real customer documents until the project, endpoint, region, ZDR/MAM status, caching and actual retention have been documented and approved. AI output is treated as a working draft or fact extraction, may not itself determine legal or control obligations, and is never sent automatically. An independent lawyer receives access only after a transparent separate engagement or documented instruction.

Active case files are retained to perform the contract. After completion, technical case content is normally deleted no later than 180 days after the last update unless statutory retention, evidence or legal-defence needs apply. Internal test cases are automatically deleted after no more than 30 days. Customers can request deletion in Secure Intake; final deletion is performed after checking conflicting obligations. Invoices and contract records may be subject to separate statutory retention periods.

7. Cleero App and local device storage

The Cleero App can generally be used without a user account. Optional profile details, diagnoses, tasks, incident notes, vendor data and AI-register entries are stored locally on the device. Access to local storage is technically necessary to provide the app workspace explicitly requested on that device (section 25(2)(2) TDDDG). The Article 50 assessment release is an exception: the answered scope and implementation questions, full name, company and business email are deliberately submitted to Cleero and stored as a check enquiry. A phone number remains optional. Other app content is not transmitted. You can export or erase the local working data. Please do not enter unnecessary personal data, sensitive documents or secrets.

8. Privacy-conscious reach and quality measurement

Cleero records only aggregated events on its own webspace, such as page views, views and clicks on notice elements on the website and in the app, quick-check starts and completions, unlocked assessments, report or consultation requests, app opens, app setup, completed app diagnoses and Article 50 checks, install and contact actions, and technical quality classes. For these statistics, no analytics cookies, persistent identifier, IP address, full referrer, check answers, app content or form entries are stored. The browser classifies origin only into broad categories such as direct, internal, search engine or social network; the full referrer is not transmitted. Separately stored check enquiries are used to provide the requested assessment and handle the contact, not for reach measurement. The statistics are not designed to identify individuals or build profiles and are retained for no more than 400 days, with a daily automated expiry check. Our legitimate interests are privacy-conscious reach measurement, functional control, error detection and service improvement; the legal basis is Article 6(1)(f) GDPR.

No external analytics or marketing services, externally loaded fonts or embedded social-media content are used.

9. Recipients, law firms and international transfers

Recipients may include the hosting and email provider and operational support expressly authorised by Achilleas Pliakas and bound to confidentiality. Lawyers or law firms do not gain access to Cleero enquiries or project files merely because they cooperate with Cleero. If a client appoints an independent law firm, this creates a separate contractual and controller relationship; Cleero transfers data only on documented instruction or another valid legal basis.

The OpenAI API is technically prepared as an optional AI service. No data is transmitted while the function is disabled. Document AI is additionally blocked by a technical ZDR release gate. Before production activation, the data processing agreement, project and endpoint, processing region, ZDR/MAM status, prompt caching, actual retention, possible subprocessors, international-transfer safeguards, deletion and security settings, and the legal basis are documented and reviewed. When enabled, the service receives only the minimised data described in section 6.

Required data processing agreements are concluded with processors. Cleero reach measurement itself does not transfer data to third countries. Where a service provider processes data outside the European Economic Area, this is permitted only under Articles 44 et seq. GDPR.

10. Your rights and right to complain

Subject to statutory requirements, you have rights of access, rectification, erasure, restriction and data portability. Consent can be withdrawn with effect for the future.

You may also lodge a complaint with a data protection supervisory authority. For private-sector businesses in Bavaria, the competent authority is generally the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany.

11. Security

Transmission is encrypted via HTTPS. Security headers, server-side input validation, CSRF protection, input length limits and controls against automated abuse protect forms and data transfer.

12. Last updated

03.09.2026 · 2026-09-03-v1

The German version is authoritative.

Book a consultation