Privacy Policy
Information on the processing of personal data pursuant to Art. 13 / Art. 14 GDPR. Last updated: 31.05.2026.
Please note: This is an informational English translation. The legally binding version is the German privacy policy, available at /de/legal/privacy.
1. Controller
The controller responsible for the processing of personal data within the meaning of Art. 4 (7) GDPR is:
Benjamin Lison
Lindoza (sole proprietorship)
Am Kohlgarten 10
38442 Wolfsburg
Germany
Email: software@lindoza.com
2. Competent supervisory authority
Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection Lower Saxony)
Prinzenstraße 5
30159 Hannover
https://lfd.niedersachsen.de
3. What is Lindoza? — Briefly and honestly
Lindoza is a voice AI training room: you describe a person (e. g. your boss, a customer, a family member) and practice a difficult conversation in a spoken role-play — before it happens in real life. In doing so, we process particularly sensitive data(your voice, your descriptions of other people, conversation contents on topics such as conflict, job applications, relationships). We take this seriously — and disclose what happens.
4. What data we process
Obligation to provide the data (Art. 13 (2)(e) GDPR). Providing your email address is contractually requiredfor account creation and authentication — without it Lindoza cannot be used. Providing your voice audio data is required for the core function (practice sessions); without it the spoken role-play is not possible. Other data (persona descriptions, wallet top-up for paid sessions) arevoluntary— if you do not provide them, you can use the service without the conversation function or with the free trial allowance.
4.1 Account data
- Email address— for login (magic link) and for transactional notifications
- Wallet balance and top-up history— for billing
- IP address + user agent— briefly in server logs for abuse detection
4.2 Content data
- Persona descriptions— texts that you yourself create about fictional or real people (name, character, typical phrases, triggers)
- Voice audio— the voice you speak while conducting a practice session (biometric data, Art. 9 GDPR). Processed exclusively live for transcription and not stored— see retention period.
- Transcripts— your spoken language is automatically converted into text
- Conversation history— your sentences + AI-generated responses of the persona
- Pattern recognition— AI-based analysis of your conversation style (pauses, word choice, topics) for personal reflection
4.3 Payment data
- Credit card data is processed not by us, but directly by Stripe (PCI-DSS Level 1, EU contractual partner Stripe Payments Europe Ltd. in Ireland). We only see the payment confirmation + amounts.
5. What we use the data for (processing purposes)
5.1 Provision of the practice sessions
Purpose:to provide you with the core tool — conducting spoken conversations with AI personas.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR),explicit consent for biometric and, where applicable, health-/life-related data (Art. 9(2)(a) GDPR).
5.2 Account management & wallet
Purpose: login, authentication, billing of your balance.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
5.3 Analysis of your own sessions
Purpose:to show you patterns (e. g. „You speak faster in moments of stress“) so that you can improve.
Legal basis: performance of a contract + your legitimate interest in your personal reflection (Art. 6(1)(b), (f) GDPR).
5.4 Security & abuse prevention
Purpose: to protect the platform against attacks, fraud and automated abuse.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
5.5 Legal obligations
Purpose:fulfilment of statutory retention and reporting obligations (e. g. tax law for Stripe invoices).
Legal basis: legal obligation (Art. 6(1)(c) GDPR).
6. Retention period
- Account data: until account deletion; thereafter max. 30 days in backups, then complete deletion.
- Voice audio: is not stored— the voice is processed exclusively live for real-time transcription (transport via LiveKit, speech recognition via Deepgram at the EU endpoint with model-improvement opt-out) and not retained. Only the text transcript is persisted.
- Transcripts + persona texts: until you delete them yourself or close your account.
- Wallet-/payment receipts: 10 years (statutory tax retention obligation, § 147 AO).
- Server logs (IP, etc.): max. 14 days.
7. Who has access (recipients / sub-processors)
We use carefully selected service providers who help us to provide Lindoza. With each of them we have a data processing agreement (DPA) pursuant to Art. 28 GDPR and — where data flows to third countries — EU Standard Contractual Clauses 2021/914 + where applicable the EU-US Data Privacy Framework.
At a glance — structured by processing category:
- Database & authentication:Supabase (🇪🇺 Frankfurt, EU main processing — no third-country transfer for account, persona and session data; no audio— this is not persisted)
- Web hosting & serverless functions:Vercel (🇪🇺 Frankfurt compute + 🇺🇸 edge cache, with DPF + SCCs 2021/914)
- Speech and AI processing (voice pipeline):specialized providers for speech recognition, AI role-play (LLM), speech synthesis and voice transport (predominantly 🇺🇸 USA, each with SCCs 2021/914 + additional data protection measures such as log retention limits, zero-retention mode and EU endpoints, insofar as available with the respective provider)
- Background analysis jobs:job orchestration provider (🇺🇸 USA, with SCCs 2021/914)
- Payment processing:Stripe (EU contractual partner SPEL in 🇪🇺 Ireland + 🇺🇸 PCI vault affiliates, with SCCs 2021/914)
- Transactional emails:Resend (🇺🇸 USA, with SCCs 2021/914)
- Marketing conversion tracking on the public landing page(only after cookie consent, see section 11.3): Google LLC (🇺🇸 USA, with EU-US Data Privacy Framework + SCCs 2021/914)
- Product analytics & session replay:PostHog Inc. (main processing 🇪🇺 EU cloud, with EU-US Data Privacy Framework + SCCs 2021/914). Exclusively on the public marketing pages and only after cookie consent — not in the logged-in app area (see section 11.4).
A complete list of the individual providers including data categories, region, technical protective measures and data processing agreements is made available on request to software@lindoza.com. Supervisory authorities, auditors and business customers whose compliance requires it receive the list immediately.
8. Third-country transfers (USA)
Several of our sub-processors process data in the USA. The legal basis for these transfers is:
- the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10 July 2023), insofar as the respective provider is certified;
- in addition or as an alternative, EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914 of 4 June 2021);
- in each case accompanied by technical protective measures such as AES-256 encryption, DTLS-SRTP for voice streams, TLS 1.2+ in transit.
We are aware that US authorities may have access rights under the CLOUD Act and FISA 702. We actively minimize third-country exposure (e. g. EU endpoint at Deepgram, EU region at Vercel, Supabase Frankfurt) and continuously close gaps (see internal roadmap: ElevenLabs EU residency, EU region for Anthropic as soon as available).
For our Google Ads conversion tracking (see section 11.3) we use Google Consent Mode v2 with the additional setting ads_data_redaction. Beforeyour consent, Google sends no identifying data and sets no cookies; only anonymous, cookieless pings for statistical measurement of advertising success are transmitted. A connection to Google's infrastructure (at the TCP level with IP header) is unavoidable when the tag script is loaded — Google contractually commits not to use these IPs for identification or profiling in cookieless mode. After your explicit consent, this is upgraded to full conversion tracking including cookies.
9. Your rights
Under the GDPR you have the following rights:
- Access(Art. 15 GDPR) — which data we process about you
- Rectification(Art. 16 GDPR) — of incorrect data
- Erasure(Art. 17 GDPR) — of your data ("right to be forgotten")
- Restriction(Art. 18 GDPR) — of processing
- Data portability(Art. 20 GDPR) — your data in a machine-readable format
- Withdrawal of consent(Art. 7 (3) GDPR) — at any time with effect for the future
- Complaint to the supervisory authority(Art. 77 GDPR) — to the LfD Niedersachsen (see section 2)
Special notice on the right to object (Art. 21 GDPR) — separately highlighted pursuant to Art. 21 (4) GDPR:
You have the right, at any time, on grounds relating to your particular situation, to object to the processing of your personal data which is based on our legitimate interests (Art. 6(1)(f) GDPR). We will then no longer process this data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. An objection is sufficient in free form by email to software@lindoza.com.
Directly in the app: under Settings → Accountyou can delete people, sessions and your entire account at any time with a single click — without any query, without any residual data. For all other rights, write to us at software@lindoza.com.
10. Automated decisions / profiling
We do not make any automated individual decisionswithin the meaning of Art. 22 GDPR. The AI-based pattern recognition of your sessions serves exclusively your personal reflection — it leads to no legal effect concerning you or an impairment of your rights.
11. Cookies & tracking
11.1 Technically necessary cookies
We set technically necessary cookies (session cookie for login, CSRF token). These are required for the operation of the app (Art. 6(1)(b) GDPR / § 25 (2) No. 2 TDDDG) and require no consent.
11.2 Cookieless analytics (Plausible)
If we activate the cookieless analytics tool Plausible, it runs in a GDPR-compliant manner: servers in Germany (Falkenstein), no cookies, no cross-site trackers, no personal data. We will name it here as soon as it is active.
11.3 Marketing conversion tracking (Google Ads + Consent Mode v2)
With Google Ads conversion trackingwe measure the effectiveness of our advertising (e. g. how many visitors sign up after seeing a Google ad). Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We use Google Consent Mode v2 and operate the tracking in two stages:
- Before / without your consent (default): The gtag.js script does load, but sends exclusively anonymous, cookieless pings. No cookies are set, no advertising IDs or click IDs are transmitted, and through the setting
ads_data_redactionGoogle removes remaining identifiers server-side. At the TCP level — unavoidable when loading a script — your IP address is transmitted as part of the HTTP request; Google contractually commits not to use it for identification, profiling or personalization in cookieless mode. From these cookieless pings, Google statistically estimates („modeled conversions“) the advertising success without any individual person being tracked. Legal basis: legitimate interest in data-minimized measurement of advertising success (Art. 6(1)(f) GDPR). § 25 (1) TDDDG does not apply, as no information is stored or read on your device in the default state. - After your consent („Accept all“): We upgrade via
gtag('consent', 'update', 'granted')to full conversion tracking. In doing so, conversion cookies (max. 90 days, Google default) are set and conversions are individually attributed to your visit. Legal basis: consent (Art. 6(1)(a) GDPR + § 25 (1) TDDDG) via our cookie banner.
Data transfer to the USA:transfer to the USA on the basis of the EU-US Data Privacy Framework (adequacy decision of 10 July 2023, Google LLC is certified) as well as additionally on the basis of EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914 of 4 June 2021).
Withdrawal / objection:You can withdraw your consent at any time via „Cookie settings“ in the footer — from the withdrawal onwards no more full conversion cookies are set and we send Google only cookieless pings. If you do not want these either (Art. 21 GDPR objection against legitimate interest), an informal email to software@lindoza.com suffices. Additionally, you can deactivate ad personalization in your Google account at myadcenter.google.com. Further information in the Google privacy policy.
Data minimization: We have configured the tag with send_page_view: false — gtag sends no automatic page-view beacons. Google receives data exclusively when an explicit conversion event is triggered (currently: successful sign-up in onboarding). On nopage — neither the landing page nor the logged-in app area — are URLs, click paths, contents of your sessions, personas, transcripts or voice audio transmitted to Google.
11.4 Product analytics & error tracking (PostHog)
To improve our public marketing pages we use PostHog. Provider: PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. Data processing takes place in the EU cloud (region eu.i.posthog.com); PostHog Inc. is based in the USA as the parent company.
Where & when: PostHog loads exclusively on our public marketing pages (home page, legal texts) and only after your consent. In the logged-in app area no PostHog runs — there no product events, interactions or sessions are recorded whatsoever.
What we record:
- Page views & interaction metadata (autocapture: which buttons/links are clicked) on the marketing pages.
- Session replays: recording of mouse, scroll and click interactions on the marketing pages. All input fields are masked — entered contents are not recorded.
- Error traces (JavaScript exceptions) for stability improvement. Sets first-party analytics cookies (
ph_*). - No voice audio, no persona contents, no transcripts — these arise exclusively in the app area, in which PostHog does not load at all.
Legal basis:consent (Art. 6(1)(a) GDPR + § 25 (1) TDDDG) via the cookie banner. Before your click on „Accept all“, no PostHog script loads, there is no connection to PostHog servers and no transmission of your IP address.
Data transfer to the USA:main processing takes place in the EU cloud. Insofar as PostHog Inc. (USA) receives data as the parent company, this happens on the basis of the EU-US Data Privacy Framework (adequacy decision of 10 July 2023, PostHog is certified) as well as EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914 of 4 June 2021).
Retention period: event data max. 12 months, then automatic deletion or aggregation.
Withdrawal:cookie consent can be withdrawn at any time via „Cookie settings“ in the footer. After withdrawal, no further events or session replays are recorded.
12. Voice AI: what we protect in particular
Your voice and your descriptions of other people are the most sensitive things that reach us. We commit to:
- No training use— neither Lindoza nor our sub-processors train AI models with your data.
- Audio is not stored— your voice is only processed live for transcription and not retained; only the transcript is persisted (as long as you keep it).
12.1 Persona data of third parties (Art. 14 GDPR)
Lindoza is a practice room: you create personas with whom you practice. Insofar as you enter data of real third parties (boss, partner, family members) in doing so, the following applies:
- You are the controller (Art. 4 (7) GDPR) for the contents of your persona descriptions. Lindoza acts in this respect as a processor (Art. 28 GDPR) — we process this data exclusively to provide the practice function according to your inputs.
- Please do not use real names or clearly identifiable details of third parties — they have not authorized us to do so. Pseudonyms, initials or nicknames are sufficient for realistic practice.
- We do not analyze persona contents to identify third parties, do not pass them on to external recipients (beyond the sub-processors named in section 7) and do not use them for our own purposes.
- Informing all potentially affected third parties pursuant to Art. 14 GDPR is impossible for us due to a lack of contact data; in this respect we rely on Art. 14 (5)(b) GDPR (disproportionate effort) and document this balancing internally.
13. Security
We encrypt your data in transit (TLS 1.2+, DTLS-SRTP for voice) and at rest (AES-256 in our EU databases). Access to the system is secured by multi-factor authentication, role-based access control and audit logs.
14. Data protection impact assessment (DPIA, Art. 35 GDPR)
Due to the systematic processing of biometric data (voice audio), the use of new AI technologies (LLM, TTS, STT) and the sensitivity of the typical conversation contexts (conflict, relationship, mental health), Lindoza carries out a data protection impact assessment pursuant to Art. 35 GDPR and updates it regularly. Result: the identified risks are manageable through the measures named in section 7 (DPA + SCCs), section 12 (persona notices) and section 13 (encryption). We make a summary of the DPIA available on request in the case of a legitimate interest at software@lindoza.com.
15. AI transparency under the EU AI Act (Art. 50)
Lindoza uses generative AI (Anthropic Claude for role-play responses; ElevenLabs for speech synthesis; Deepgram for speech recognition). In every practice session you are talking to an AI, never to a human. The responses of your persona are algorithmically generated.
This transparency obligation arises from Art. 50 of Regulation (EU) 2024/1689 (EU AI Act), which is fully applicable to affected AI providers from 02.08.2026. We label all AI outputs accordingly and ensure that synthetic audio remains recognizable as such.
16. Changes to this privacy policy
We update this policy when something changes in our data processing (new sub-processor, new function). We communicate substantial changes by email to all users. You can always see the currently valid version here with the update date at the top.
Last updated: 31.05.2026. If you have questions, write to us at software@lindoza.com.