Skip to content

Privacy Notice

As of 1 October 2026 · GDPR Art. 13/14 · The German version is the authoritative text.

1. Controller

Schübeler Consulting
Johann Jörgen Schübeler
Am Kreuzberg 10, 37688 Beverungen, Germany
Email: info@schuebeler-consulting.de

2. Data we process

Legal basis for the access log: Art. 6(1)(f) GDPR. Our legitimate interest is being able to show who retrieved which knowledge and when. Without that record, no one can establish after a security incident which content was affected. We keep the intrusion small by storing extracts and metadata only, and by deleting each entry automatically once the retention period in section 9 has passed.

Your right to object: you may object to this processing under Art. 21 GDPR. The access log cannot be switched off while knowmind is in use, because it carries the evidential value. We examine every objection individually and tell you the outcome.

What remains after a deletion: if you delete a single memory, log entries about earlier access to it remain until the retention period in section 9 has passed, and they can contain the title of the deleted memory. Individual log entries can neither be changed nor removed before their retention period ends: the entries are linked into a chain, and that chain proves the log is complete. We delete log entries in two ways. Every day we delete the entries whose retention period has passed. When you delete your workspace, we delete its entire log (section 9).

3. Processors

4. AI providers (your own keys)

You may optionally store your own provider keys (Anthropic, OpenAI, Google, Mistral, local models). Inference requests then go from our server directly to the provider you chose. We recommend using a provider outside the EU only if you have your own data processing agreement with them.

Third-country note: choosing a provider outside the EU/EEA means inference transfers data to a third country. You initiate and are responsible for that transfer through your choice of provider; the legal basis for it (for example EU standard contractual clauses or an adequacy decision) has to exist between you and that provider. Schübeler Consulting does not cover this transfer with its own standard contractual clauses. If you use EU providers or local models only, content does not leave the EU through knowmind.

Indexing stays local: the vector indexing of your memories (embeddings) happens inside our server environment in Germany. No content is sent to external providers for indexing.

5. Connectors to your own systems

You can set up a connector through which a system you operate — Jira, for example — hands content to knowmind. knowmind retrieves nothing: it holds no credentials for your system and only receives what you have it send. Which events those are is decided in your system.

What that involves: the content itself plus whatever your system includes — for Jira that means issue key, summary, description, resolution and the names of the people involved, such as assignees or comment authors. These are stored like any other memory in your workspace, processed in Germany and not passed to third parties.

Your responsibility: since you decide which events your system sends, you also decide which personal data is handed over. Before setting a connector up, check whether the people concerned — employees or customers whose names appear in issues — may be included, and whether your works council has to be involved. We process this data solely on your instructions under Art. 28 GDPR.

Deletion: you delete content received through a connector like your other memories. Every intake through a connector is also recorded in your workspace's access log, and that entry can contain the name of the item received. It remains until the retention period in section 9 has passed or you delete your workspace. Together with the workspace we also delete the received content and its log entries (section 9).

6. Use through the ChatGPT app

If you use knowmind through the app directory of ChatGPT, OpenAI operates that surface. In that setting OpenAI and Schübeler Consulting are separate controllers: your conversation with ChatGPT is governed by OpenAI's terms and privacy notice, what you store in knowmind is governed by this notice. There is no data processing agreement between us and OpenAI, because neither of us processes on behalf of the other.

Practically this means: what our app returns to ChatGPT — the memories you retrieve — passes through OpenAI's systems and is subject to their developer terms, under which OpenAI may use app responses. Your stored content itself stays in Germany. If that separation matters to you, use knowmind through a client where you control the model, or through your own provider key.

7. Your rights

You have the right to:

You do not have to ask us for most of these. You can export your data yourself at any time (how that works). You delete single memories and documents in the dashboard, and your entire workspace including your account under “Arbeitsbereich löschen” (delete workspace) in the dashboard. What that deletes and what we keep is described in section 9. If you cannot trigger the deletion yourself, write to info@schuebeler-consulting.de; we handle your request without undue delay and within one month at the latest (Art. 12(3) GDPR). For anything else, write to info@schuebeler-consulting.de. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.

8. Cookies

Only what the service needs to work: cookies for signing in and, if you switch the language, a cookie with your language choice (valid for 1 year). No tracking, no advertising cookies, no consent banner — because there is nothing to consent to. The Stripe checkout sets its own cookies; Stripe's privacy notice describes them.

9. Retention

Memories, documents and account data stay stored for as long as your workspace exists. If a paid plan ends, your workspace continues on the free Private plan and your data is kept in full. If your data exceeds the limit of that plan, you can still read and retrieve it but cannot store anything new. If you terminate the contract as a whole, your data remains available for 30 days; after that we delete the workspace as described below. We delete access log entries after a period that depends on your plan: 1 month on Private, 3 months on Pro, 12 months on Team, 24 months on Business, 5 years on Enterprise. For other plans, the period is shown in the audit area of your dashboard.

Deleting your workspace: as soon as you delete your workspace in the dashboard, we block all access. You can no longer sign in, and your access keys stop working. From that moment the workspace can no longer be restored. In the same step we delete your entries in the knowledge graph, which stores the links between your memories. No earlier than 24 hours later we delete all remaining data of the workspace from our database; a deletion run that runs every hour does this. It deletes account data, memories, documents with all their parts, the access log, the change log (which records when memories were created, changed or deleted), and your plan and billing details except the invoices (see below). The retention periods of the access log end early as a result. If entries are left in the knowledge graph because deleting them there did not fully succeed, the deletion run waits until we have deleted them.

What remains after the deletion:

10. Personal data breaches

If we become aware of a breach — unauthorised access, loss or accidental disclosure — we follow a fixed procedure: analyse, contain, document, and assess the risk to the people affected.