greenpt.com privacy policy — score 82/100 (low risk)

Utolsó elemzés

A jelentés tartalma (összefoglaló, megállapítások, idézetek) angolul készült és nincs lokalizálva.

Új elemzés futtatása másik szabályzaton

GreenPT BV · greenpt.ai

Jelentés részletei

low kockázat

GreenPT offers strong EU data sovereignty and minimal tracking, but its policy is suspiciously silent on whether your chat data is used to train AI models, and it relies on a weak safeguard for US-based search transfers.

GreenPT BV demonstrates a strong commitment to EU data sovereignty, hosting data in France with renewable energy and offering robust security certifications. Data minimization is evident in the handling of API payloads and audio input, which are processed in RAM and not persistently stored. However, the policy contains a critical ambiguity regarding AI model training and an inadequate legal mechanism for transferring search data to the US via Brave Search.

Utolsó elemzés
ForrásURL
Hossz10,105 karakter

Kategória szerinti értékelés

A szabályzat bontása a fő megfelelőségi területekre. Jó = erős, közepes = vegyes, gyenge = aggasztó.

Data Minimizationgood

API payloads and audio inputs are processed in RAM and discarded immediately, and ad tracking is strictly limited to specific landing pages.

Transparencyfair

The policy is clear on data flows and retention, but completely omits any mention of whether user inputs are used for AI model training.

Third-party Sharinggood

Sharing is limited to essential sub-processors and highly scoped ad attribution pixels, with an explicit statement that data is never sold.

International Transfersfair

Data is hosted in the EU, but search queries go to Brave Search in the USA with only a privacy policy listed as a safeguard, which is inadequate under GDPR.

AI/Model Trainingpoor

The policy is entirely silent on whether user chat content or prompts are used to train, fine-tune, or improve AI models, a critical transparency failure for an AI provider.

User Rightsgood

Standard GDPR rights are clearly listed with a one-month response time, and account data export is explicitly mentioned before deletion.

Fő megállapítások

Fontos záradékok, problémák vagy jó gyakorlatok (kritikusak először)

Figyelmeztetés

Silence on AI Model Training

The policy mentions 'Anonymized research and service improvement' as a purpose for data use, but completely fails to explicitly state whether user chat content or prompts are used to train, fine-tune, or improve AI models, which is a critical transparency requirement for AI services.

Figyelmeztetés

Inadequate Safeguard for US Data Transfer

For the Brave Search sub-processor located in the USA, the policy lists 'Brave Search API Privacy Policy' as the safeguard. Under GDPR, a third-party privacy policy is not a valid legal mechanism for international data transfers; Standard Contractual Clauses (SCCs) or similar mechanisms are required.

Info

Narrow and Transparent Ad Tracking

The policy restricts tracking cookies and data sharing with advertising partners (Google and Meta) exclusively to specific landing and thank-you pages for visitors arriving via ads, explicitly stating no other personal data or browsing activity is shared, which is a highly privacy-friendly approach.

Info

Strong Ephemeral Data Processing

The policy explicitly states that API payloads and audio inputs for Speech-to-Text are processed in-memory (RAM) only and not persistently stored, demonstrating strong data minimization for sensitive transient data.

Összefoglaló a felhasználónak

Your data stays in the EU and is well-protected, but you should assume your chat prompts might be used for AI improvement unless you clarify with the company, as the policy avoids the topic entirely.

Megfelelőségi helyzet

Largely compliant with GDPR, featuring clear user rights, DPA availability, and strict sub-processor controls, but falls short on explicit AI training disclosures and valid international transfer mechanisms for US sub-processors.

EU-s átvitelek

Data is primarily hosted in France, but search queries are sent to Brave Search in the USA. The policy lists 'Brave Search API Privacy Policy' as the safeguard, which is legally insufficient under GDPR (Schrems II) without Standard Contractual Clauses (SCCs) or another valid transfer mechanism.

Észlelt jelek

A szövegben azonosított konkrét adatok és gyakorlatok

Gyűjtött adatok
First nameLast nameOptional company nameEmail addressAuthentication identifiersChat message promptsChat responsesVoice recordings (transient)Aggregated energy-consumption metricsToken usage countsBilling metadata
Adatkezelési célok
Provision, maintenance, and optimization of AI servicesUser authentication and account managementBilling and payment processingCustomer support and technical assistanceCompliance with legal obligations and fraud preventionAnonymized research and service improvementDisplaying environmental impact metrics
Harmadik felekkel való megosztás
Scaleway SAS (Primary cloud infrastructure)Mollie B.V. (Payment processing)Brave Search (Search index for GreenPT Search)Google (Ad attribution on landing pages only)Meta (Ad attribution on landing pages only)
Nemzetközi átvitelek
Data hosted exclusively in EU data centres (France)Brave Search processes search queries in the USA
AI / Modelltanítás
Policy is silent on AI model training

Bizonyító részletek

Közvetlen idézetek a szabályzatból e megállapítások alátámasztására

API payloads are processed in-memory only and not stored

voice recordings for Speech-to-Text are processed in RAM and discarded immediately after transcription.

To advertising partners (Google and Meta), but only when you arrive at our website via their ads. In those cases, they learn that you visited a specific landing page and, if applicable, a thank-you page (only those two pages).

Safeguards: Brave Search API Privacy Policy

Hiányzó vagy nem egyértelmű

  • Explicit opt-in or opt-out mechanism for AI model training using user chat data
  • Valid GDPR transfer mechanism (e.g., Standard Contractual Clauses) for Brave Search in the USA
  • Details on how 'Anonymized research' is performed and verification that anonymization is irreversible

Felteendő kérdések

  • Is chat content or audio input used to train, fine-tune, or improve your AI models, and if so, how can users opt out?
  • What specific legal mechanism (e.g., Standard Contractual Clauses) is used to authorize the transfer of search queries to Brave Search in the USA?
  • How exactly is chat content anonymized for 'Anonymized research and service improvement,' and can you guarantee it cannot be re-identified?
Ezt az elemzést AI generálja, és nem minősül jogi tanácsadásnak. Megfelelőségi döntésekhez mindig kérj képzett jogász véleményét.

Elemzés megosztása

Bárki, aki rendelkezik ezzel a linkkel, megtekintheti a fenti eredményt.

A DentroChat készítette

100%-ban európai AI chat mindenkinek

Csevegj AI-val, dolgozz fájlokkal, generálj képeket és keress a weben. Az adatok Európában maradnak.

EU-ban üzemeltetett infrastruktúraSzöveg, fájlok, képek és webes keresésGyors, Gondolkodó és Kreatív módokAdatvédelem alapbólEgyetlen adat sem hagyja el Európát
Próbáld ki ingyen →