app.pantares.ai — 85/100 (Χαμηλός κίνδυνος απορρήτου)
Τελευταία ανάλυση
Pantares GmbH · pantares.ai
Λεπτομέρειες αναφοράς
Χαμηλός κίνδυνος απορρήτουΗ πολιτική απορρήτου της ιστοσελίδας της Pantares GmbH είναι διαφανής, συμμορφώνεται με τον GDPR και ελαχιστοποιεί τη συλλογή δεδομένων, αλλά η πλατφόρμα AI της (app.pantares.ai) έχει ξεχωριστή πολιτική με ασαφή λεπτομέρειες σχετικά με την εκπαίδευση AI και τη μεταφορά σε τρίτους.
Pantares GmbH’s website privacy policy is well-structured, clearly outlines data collection (e.g., IP addresses for form protection, minimal cookies), and restricts processing to necessary purposes. It uses EU-based hosting (Microsoft Azure) and requires explicit consent for analytics (Matomo) and reCAPTCHA. However, the separate policy for its KI-platform (app.pantares.ai) introduces ambiguity: it mentions third-party AI providers (including US-based ones) and data transfers under SCCs, but lacks explicit opt-outs for AI model training. The policy also notes that user data in the platform may be processed if third parties (e.g., a user’s employer) upload it, which could affect non-users.
Δεν μπορέσαμε να μεταφράσουμε αυτή την αναφορά αυτή τη στιγμή, γι' αυτό οι λεπτομέρειες παρακάτω είναι στα αγγλικά.
Αξιολόγηση ανά κατηγορία
Ανάλυση της πολιτικής σε βασικούς τομείς συμμόρφωσης. Καλό = ισχυρό, μέτριο = μικτό, κακό = ανησυχητικό.
Collects only necessary data (e.g., IP for form protection, minimal cookies) and avoids unnecessary tracking by default.
Policy is detailed, with clear sections on purposes, legal bases, and third-party processors, though the KI-platform’s separate policy is less accessible.
Shares data with a limited set of processors (Azure, Cloudflare, Matomo, Google) but the KI-platform’s use of third-party AI providers (including US-based) introduces uncertainty.
Mostly EU-based, but Cloudflare, Google, and KI-platform AI providers involve US transfers under SCCs/DPF, which are not risk-free.
Explicitly states KI-platform data is *not* used for training models, but this only applies to direct user inputs—third-party data (e.g., uploaded by others) may still be processed without opt-outs.
Clearly lists GDPR rights (access, deletion, portability, etc.) and provides contact details for the DPO, but non-users of the KI-platform must rely on the data controller (e.g., their employer) to exercise rights.
Βασικά ευρήματα
Σημαντικές ρήτρες, ζητήματα ή θετικές πρακτικές (κρίσιμα πρώτα)
Separate KI-platform policy creates ambiguity for non-users
Section 7 states that non-users’ data (e.g., in emails or documents uploaded by others) may be processed in the KI-platform under Art. 6(1)(f) GDPR, with transfers to US-based AI providers. However, the policy does not clarify how non-users can object or opt out, or whether their data is used for model training. This is a critical gap for GDPR compliance (Art. 21 right to object).
AI training opt-out missing for KI-platform
Section 7 explicitly states that user data in the KI-platform is *not* used for training models, but this assurance does not extend to third-party data (e.g., uploaded by a user’s employer). The policy lacks a mechanism for non-users to prevent their data from being used in AI training, which is a significant compliance risk under GDPR (Art. 9, 22).
US transfers rely on SCCs and DPF, but risks remain
Sections 6.2 (Cloudflare), 6.4 (Google reCAPTCHA), and 7 (KI-platform AI providers) note that US transfers are covered by SCCs and/or the EU-US Data Privacy Framework. However, SCCs have been challenged in courts (e.g., Schrems II), and DPF’s adequacy is not yet legally settled. The policy does not address supplementary measures (e.g., encryption) for these transfers.
Retention periods for KI-platform data are unclear for non-users
Section 8 outlines retention periods for website data but is vague for the KI-platform. It states that user-uploaded content remains until deletion by the user, but does not specify how long third-party data (e.g., non-users’ data in uploaded documents) is retained or how non-users can request deletion.
Consent granularity for analytics and reCAPTCHA is strong
Sections 6.3 and 6.4 describe a two-click consent mechanism for Matomo analytics and Google reCAPTCHA, ensuring no data is collected without explicit user action. This is a best practice for GDPR compliance (Art. 7, 49).
Περίληψη για τον χρήστη
For the website (pantares.ai), your data is handled carefully with clear consent mechanisms and EU-based processing. For the KI-platform (app.pantares.ai), be cautious: your data might be shared with US-based AI providers, and there’s no explicit guarantee it won’t be used for model training unless you’re a direct user with control over your inputs.
Στάση συμμόρφωσης
Strong for the website: explicit legal bases (Art. 6 GDPR), consent for non-essential processing, and clear user rights. Mixed for the KI-platform: relies on legitimate interest (Art. 6(1)(f)) for processing third-party data, uses SCCs for US transfers, but lacks granularity on AI training opt-outs and data retention for non-users.
Μεταφορές ΕΕ
Most processing for the website occurs in the EU (Azure, Matomo Cloud in Frankfurt/Dublin). Exceptions include Cloudflare (US parent, EU processing with SCCs + DPF certification) and Google reCAPTCHA (EU/US with SCCs + DPF). For the KI-platform, data may be transferred to US-based AI providers under SCCs, but the policy does not specify safeguards beyond this.
Εντοπισμένα σήματα
Συγκεκριμένα δεδομένα και πρακτικές που εντοπίστηκαν στο κείμενο
Αποσπάσματα αποδείξεων
Απευθείας αποσπάσματα από την πολιτική που υποστηρίζουν αυτά τα ευρήματα
Für unsere KI-gestützte Software-Plattform unter app.pantares.ai und für die Erweiterungen für Microsoft Office gilt eine eigene Datenschutzerklärung (Ziffer 3).
Die Daten werden nicht zum Training von KI-Modellen genutzt.
Zur Bearbeitung werden die Inhalte an KI-Anbieter übermittelt, teils mit Sitz in der EU, teils in den USA. Übermittlungen in die USA erfolgen auf Grundlage der EU-Standardvertragsklauseln (Art. 46 DSGVO).
Cloudflare ist zusätzlich nach dem EU-U.S. Data Privacy Framework zertifiziert.
Reichweitenmessung — Matomo Cloud (InnoCraft) [...] Verarbeitungsort: EU — die von uns genutzte Matomo-Cloud-Instanz wird in Frankfurt am Main betrieben, Sicherungskopien in Dublin.
Ihre Rechte: Es gelten die Rechte nach Ziffer 9 einschließlich des Widerspruchsrechts nach Art. 21 DSGVO.
Λείπει ή ασαφές
- No opt-out mechanism for non-users whose data is processed in the KI-platform
- No clarity on whether third-party data in KI-platform is used for AI model training
- No supplementary measures (e.g., encryption, pseudonymization) described for US transfers
- No retention period specified for third-party data in KI-platform
- No direct contact method for non-users to exercise GDPR rights for KI-platform data
Ερωτήσεις προς υποβολή
- How can non-users (e.g., individuals whose data is uploaded by a KI-platform user) object to or opt out of their data being processed in the platform?
- Is third-party data (e.g., in uploaded documents or emails) ever used for AI model training in the KI-platform, and if so, how can this be disabled?
- What supplementary measures (e.g., encryption, access controls) are in place for data transferred to US-based AI providers under SCCs?
- What is the retention period for third-party data processed in the KI-platform, and how can non-users request deletion?
- Why is the KI-platform’s privacy policy not publicly accessible without an account, and can it be provided proactively to all affected individuals?
Κοινοποίηση αυτής της ανάλυσης
Οποιοσδήποτε με αυτόν τον σύνδεσμο μπορεί να δει το αποτέλεσμα παραπάνω.
Δημιουργήθηκε από το DentroChat
100% ευρωπαϊκό AI chat για όλους
Συνομιλήστε με AI, εργαστείτε με αρχεία, δημιουργήστε εικόνες και αναζητήστε στο διαδίκτυο. Τα δεδομένα παραμένουν στην Ευρώπη.
Άλλες πολιτικές απορρήτου που αναλύθηκαν
Προβολή όλωνkolsetu.com
85/100
Χαμηλός κίνδυνος απορρήτουΑυτή η σύνοψη μεταφράζεται…
Προβολή αναφοράς →tuta.com
87/100
Χαμηλός κίνδυνος απορρήτουΑυτή η σύνοψη μεταφράζεται…
Προβολή αναφοράς →gdprchat.eu
88/100
Χαμηλός κίνδυνος απορρήτουΤο GDPRchat προσφέρει εξαιρετικά ισχυρή προστασία απορρήτου με επίκεντρο την ΕΕ, χωρίς παρακολούθηση και με στοιχεία ελέγχου δεδομένων αυτοεξυπηρέτησης, αλλά οι χρήστες θα πρέπει να γνωρίζουν ότι τα prompts εικόνων ενδέχεται να χρησιμοποιηθούν για εκπαίδευση τεχνητής νοημοσύνης από έναν τρίτο πάροχο.
Προβολή αναφοράς →proton.me
88/100
Χαμηλός κίνδυνος απορρήτουΑυτή η σύνοψη μεταφράζεται…
Προβολή αναφοράς →