Privacy Policy
Last updated: 15 September 2026
This privacy policy explains how personal data is processed in the Question-Intelligence-Workbench (QIW) at entreater.com.
Data controller
Torsten Schindler (sole proprietorship)
Voltastrasse 102, 4056 Basel, Switzerland
Email: help@entreater.com · Phone: +41 76 383 09 01
Scope and legal bases
The Swiss Data Protection Act (revDSG) applies. For users in the EU/EEA, the General Data Protection Regulation (GDPR) applies in addition. The legal bases are performance of the contract (providing the service), your consent, and our legitimate interest in a secure, functioning service (Art. 6(1)(a), (b), (f) GDPR).
What data we process
- Account data: email address, display name and role; when signing in via Google, Microsoft or GitHub, the profile details they provide.
- Content you enter: questions, placeholder values, selected sources, and the answers, evidence and rankings generated from them.
- Usage and log data: technical logs (e.g. timestamps, errors) produced during operation.
- Local settings: interface preferences stored in your browser (e.g. collapsed/expanded sidebar, language choice).
Purposes of processing
We process this data to manage your account, run your batch jobs, generate and display source-bound results, operate the service securely, and meet legal obligations.
Processors and disclosure
We use carefully selected providers that process data on our behalf. For each provider we state the purpose:
- Supabase – authentication, database, storage of your content and reports, encrypted storage of provider keys (Vault) and delivery of sign-in emails.
- Hostinger – hosting of the application and email delivery via our mailbox host@entreater.com (invitations, sign-in links, password resets).
- OpenAI – language models for answers, source discovery, assessments (ranking judges), evidence intake and translations: the questions, placeholder values and content you enter are sent to the selected model; when web grounding is enabled, search queries as well.
- Anthropic – language models for the same tasks as OpenAI when you select an Anthropic model; transfer as above.
- Google Gemini – language models for the same tasks when you select a Gemini model; web grounding via Google Search Grounding.
- Google OAuth – sign-in service "with Google"; we receive the profile details Google provides.
- Microsoft OAuth – sign-in service "with Microsoft", if offered; we receive the profile details Microsoft provides.
- GitHub – sign-in service "with GitHub", if offered; also hosting of our source code and trigger of deployments (no user data).
- Stripe – billing, checkout and customer portal. For fraud detection and legal compliance checks in payment processing, Stripe is an independent controller; for operating billing on our behalf, Stripe is a processor.
- Sentry – error analysis on signed-in pages and on our servers (stored in the EU/Frankfurt). Transmitted are error type, affected page without parameters, time, software version and browser type. We do not send account or organisation identifiers; email addresses, UUID identifiers and access keys in error texts are masked before transmission. Other details in an error text (such as a display name or a payment provider customer number) may be transmitted. Sentry technically receives the IP address of the connection; IP addresses are not stored (project setting).
- Better Stack – availability checks of our home page, the sign-in page and an internal heartbeat from EU locations; no visitor data is processed.
E-mail delivery
Invitations to an organisation, sign-in links and password-reset emails are sent via Supabase Auth using the SMTP mailbox provided by Hostinger. The sender address is host@entreater.com. Transmitted are the recipient address and the respective link.
Transfers abroad
Our database, authentication and your content are hosted by Supabase in the eu-west-1 region (Ireland). Whether data of a provider goes to the USA and which safeguard covers the transfer is listed below:
- Supabase – USA: no (data in eu-west-1, Ireland) – standard contractual clauses for sub-processors outside the EU.
- Hostinger – USA: unknown (data centre not documented; provider based in the EU) – standard contractual clauses.
- OpenAI – USA: yes – standard contractual clauses or adequacy decision; the contracting party for the EU/Switzerland is OpenAI Ireland Ltd.
- Anthropic – USA: yes – standard contractual clauses with Swiss addendum.
- Google Gemini – USA: yes (no fixed region) – EU-US Data Privacy Framework and Swiss-US Data Privacy Framework.
- Google OAuth – USA: yes – EU-US Data Privacy Framework and Swiss-US Data Privacy Framework.
- Microsoft OAuth – USA: yes – EU-US Data Privacy Framework and Swiss-US Data Privacy Framework.
- GitHub – USA: yes – EU-US Data Privacy Framework, Swiss-US Data Privacy Framework and standard contractual clauses.
- Stripe – USA: unknown (storage location not documented) – EU-US Data Privacy Framework, Swiss-US Data Privacy Framework and standard contractual clauses.
- Sentry – USA: no for stored error data (stored in Frankfurt); Sentry sends error alerts by email to our operator via email service providers in the EU or the USA; our operator account data is held in the USA – EU-US Data Privacy Framework and Swiss-US Data Privacy Framework, with standard contractual clauses as fallback.
- Better Stack – USA: unknown (US provider, processing in the EU and the USA) – EU-US Data Privacy Framework and Swiss-US Data Privacy Framework, with standard contractual clauses as fallback.
Your own provider key
If your organisation uses its own API key of an LLM provider (OpenAI, Anthropic or Google Gemini), requests run through your organisation’s account. That transfer is governed by your organisation’s contract with the respective provider. We store the key encrypted and do not pass it on.
Retention
We keep personal data only as long as necessary for the stated purposes or to meet legal retention obligations. Account and content data are removed on request or when the account is deleted.
Cookies and local storage
We use only strictly necessary cookies: Supabase session cookies for sign-in (split across several cookies depending on size; they contain your user identifier and email address, and when you sign in with Google, Microsoft or GitHub also the profile details provided there such as name and profile picture address, and last up to 400 days) and one for the currently selected organisation (qiw_active_org, httpOnly). In addition, local browser storage holds interface settings such as the language choice. When you switch from the sign-in form to password reset, your email address is briefly kept in the browser’s session storage (sessionStorage); it is deleted when first read, otherwise when the tab is closed; if the tab is duplicated before that, the copy receives the value as well. No cookies are used for advertising or tracking.
Data security
Access to user data is isolated via row-level security. API keys are stored encrypted server-side only. Data is transmitted over an encrypted connection (TLS).
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. To exercise them, email help@entreater.com. You may also lodge a complaint with the competent supervisory authority (in Switzerland: the FDPIC; in the EU: your local data protection authority).
Note on AI results
QIW generates answers and rankings using language models. Results may contain errors and do not replace professional, legal or medical advice. Do not enter special categories of personal data into questions or values unless necessary.
Changes
We update this privacy policy as needed. The version published on this page applies.