Lanternic

Privacy Policy

This Privacy Policy explains how Lanternic ("the service", "we", "us") processes personal data when you use this website and the software demo.

Controller

The data controller responsible for processing personal data is the person listed in the imprint (legal notice). You can contact the controller using the contact details provided there.

Privacy contact

If you have questions about data protection or wish to exercise your GDPR rights, you can contact us at:

Email: [email protected]

You can also use the contact details provided in the imprint.

Data we process

When you use this service, we may process the following data:

  • Chat messages and search queries submitted through the demo
  • A pseudonymous session identifier used to associate and restore chats
  • Audio recordings you start for the dictation feature
  • Technical usage data (browser type, operating system, device type)
  • Server request data (IP address, timestamps, requested pages)
  • Referrer information (the page you came from)
  • Performance and error logs
  • Email address and messages you submit through the contact form
  • Newsletter signup data such as email address and first name

Strictly necessary cookies and local storage

For the chat demo, we use the strictly necessary "lanternic_session" cookie. It contains a randomly generated session identifier and is used solely to associate chats with this browser, resume running requests after a reload, and prevent access from other sessions. It is not used for advertising, audience measurement, or profiling.

We also store the selected language ("lanternic.ui.locale") and the identifier of the currently selected chat ("lanternic_current_chat_id") in the browser's local storage. This information is only used to restore the selected language and current chat.

This storage is necessary to provide functions explicitly requested by the user. Consent is therefore not required under Section 25(2)(2) TDDDG.

The session cookie expires no later than 30 days after the last use. The associated server-side session and its chat data are deleted after 30 days of inactivity. Local storage entries remain until they are replaced or deleted through the browser settings.

Contact form and newsletter

If you use the contact form, we process your email address and the content of your message to handle your request and send an automatic receipt confirmation.

If you sign up for the newsletter, we process your email address and your first name. Signup uses double opt-in; you can unsubscribe later.

Purpose of processing

Data processing is necessary to provide and operate the demo service, restore chat histories, process search requests, display results, improve search relevance and system quality, ensure system security, monitor technical performance and stability, answer contact requests, and manage newsletter signups.

Legal basis (Art. 6 GDPR)

Data processing is based on Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interests include providing a functional demonstration of the software, maintaining system security, and improving the quality of the service.

Newsletter delivery is based on your consent under Art. 6(1)(a) GDPR.

Recipients and processors

To operate the service, we use carefully selected providers that process personal data solely on our behalf and on our instructions. We have concluded data processing agreements under Art. 28 GDPR with each of them. They only process data as far as necessary to provide their respective service.

  • Hetzner Online GmbH (Germany): hosting and server operation; data centers in Germany.
  • Cloudflare, Inc. (USA): secure delivery of the website and protection of the infrastructure.
  • Anthropic PBC (USA) and OpenAI, L.L.C. (USA): AI-assisted processing of your input to provide the service's search and voice features.
  • Zoho Corporation GmbH (EU): delivery of the contact form and newsletter emails; data centers within the EU.

Transfers to third countries

Some of the providers we use (Cloudflare, Anthropic, and OpenAI) are based in the USA. Personal data may therefore be transferred to a third country outside the EU/EEA.

For these transfers, appropriate safeguards under Art. 44 et seq. GDPR are in place, in particular the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR) and, where the respective provider is certified, its certification under the EU-US Data Privacy Framework. Processing by Hetzner and Zoho takes place within the EU.

Content transmitted to Anthropic and OpenAI is not used to train the AI models.

Data sharing

We do not sell personal data and do not share it with third parties for advertising purposes. Data is shared only with the processors listed above, to the extent necessary in each case.

Beyond that, data may be disclosed where we are legally required to do so or where it is necessary to protect the service against misuse.

Server log files

For security and operational reasons, the hosting provider automatically collects server log files. These may include IP address, date and time of request, requested resource, status codes, and user agent information.

These logs are used exclusively for security, stability, and technical troubleshooting and are not used for user profiling.

Data retention

Personal data is only retained for as long as necessary to operate and improve the service or to comply with legal obligations.

Pseudonymous sessions and their associated chat histories are deleted automatically no later than 30 days after the last use.

Technical logs are periodically deleted or anonymized unless required for security investigations.

Data security

We implement appropriate technical and organizational measures to protect data against unauthorized access, loss, or misuse.

Your rights under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that your personal data is being processed unlawfully (Art. 77 GDPR).

Changes to this policy

This privacy policy may be updated if the functionality of the service changes or legal requirements evolve.