Privacy Policy
Convenience translation. This English version of the privacy policy is provided for convenience only and is not legally binding. Only the German version (Datenschutzerklärung) is authoritative. In the event of any discrepancy or conflict between the German version and this English translation, the German version shall prevail.
For the website, web application, iOS app, Android app, CONUS Basic and CONUS Intelligence
Last updated: 3 August 2026, 11:35 p.m. CEST
1. Controller and contact
The controller is CONUS Medical Solutions GmbH, Alte Ziegelei 2 - 4, 51491 Overath, Germany.
Phone: +49 175 208 55 13
E-Mail: info@conus-med.com
CONUS Inc. is exclusively a holding company. It does not operate the CONUS software and does not receive any user data.
2. Scope and roles
This privacy policy applies to the public website, the web application, the iOS app, the Android app, CONUS Basic, CONUS Intelligence, projects, document uploads, notes, user accounts, institution administration, newsletters, push notifications, support and paid subscriptions.
CONUS is generally the controller in its own right for personal user accounts, general use of the platform, CONUS Intelligence, product analytics, security, support and billing.
For individual institutional processing operations, a medical institution may be the controller and CONUS the processor. This concerns in particular content that an institution makes available exclusively for its internal area.
3. Principles and legal bases
We process personal data only for defined purposes and only for as long as this is necessary.
Depending on the processing operation, we rely in particular on Article 6(1)(a), (b), (c) and (f) GDPR.
Where storing information on, or accessing information in, a terminal device requires consent, we additionally rely on Section 25(1) TDDDG. Strictly necessary access to terminal devices takes place pursuant to Section 25(2) TDDDG.
CONUS is not intended for the processing of patient data or personal health data. Users must not enter such data.
4. Categories of processed data
- Master data such as name, e-mail address, telephone number, job title, specialty, employer, hospital, department and role.
- Account data such as user ID, registration status, roles, permissions and authentication data.
- Device and technical data such as IP address, device identifier, push token, browser, operating system, app version, language, timestamps and technical logs.
- Usage data such as features accessed, search and interaction events, product interactions and technical session data.
- User content such as prompts, responses, AI histories, memory content, projects, notes, documents, feedback and support content.
- Institution data such as assignment, invitations, activation status, internal contact persons, product portfolios, SOPs and organisational information.
- Communication and marketing data such as newsletter consent, delivery status and preferences.
- Contract and payment data in the case of paid subscriptions.
5. Website, hosting, DNS and server logs
Our website and parts of the platform are operated on our own infrastructure and with hosting providers in Germany. We use in particular Hetzner Online GmbH and STRATO AG.
For object storage we use Amazon Web Services in the eu-central-1 region in Frankfurt.
DNS services are provided by Hetzner and in part by STRATO.
When content is retrieved, technically necessary data is processed. This includes the IP address, time, requested resource, referrer, browser, operating system and status information.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in secure, stable and efficient provision.
Technical server and security logs are generally stored for 90 days. In the event of a specific security incident, relevant data may be stored for longer until the investigation has been concluded and for any necessary legal defence.
6. Registration and user account
In order to use functions requiring registration, we process the data provided during the registration process, institutional assignment, roles, invitation and activation status as well as security and login information.
The legal basis is Article 6(1)(b) GDPR. Security and abuse checks are additionally carried out on the basis of Article 6(1)(f) GDPR.
Account data is stored for the duration of the account. After account deletion, operational data is generally deleted or anonymised within 30 days. Backup copies are overwritten within 90 days at the latest.
Statutory retention obligations and any necessary legal defence remain unaffected.
Invitations that are not accepted are generally deleted after 90 days, unless the institution revokes or resends them beforehand.
7. Institution assignment and administrators
Administrators of an institution can view and manage the names, business e-mail addresses, roles, departments, invitation status and activation status of the users assigned to their institution.
In the regular product, administrators do not receive access to personal search terms, AI histories, prompts, responses, content accessed, personal notes, personal documents or individual usage duration.
The processing takes place in order to perform the institution and user contracts pursuant to Article 6(1)(b) GDPR and for secure permission management pursuant to Article 6(1)(f) GDPR.
8. CONUS Basic, search and personal notes
When CONUS Basic is used, we process search queries, feature calls, favourites, personal notes and other interactions insofar as this is necessary to provide the requested function.
The legal basis is Article 6(1)(b) GDPR.
Personal notes are stored until deleted by the user or until the account is terminated. After deletion, the periods for production systems and backup copies apply.
9. CONUS Intelligence, projects, uploads and memory
When CONUS Intelligence is used, we process prompts, search queries, uploaded documents, extracted document content, retrieved sources, model responses, feedback, projects, AI histories and memory content.
The processing serves to answer the request, source research, document analysis, reranking, retrieval, creation of embeddings and search indices, translation, summarisation, quality assurance, abuse prevention and technical provision.
The legal basis is Article 6(1)(b) GDPR. Security, error and quality analyses are carried out on the basis of Article 6(1)(f) GDPR.
AI histories, projects, personal documents and memory content are stored until deleted by the user or until the account is terminated. Inactive AI histories are deleted after 24 months of inactivity. Embeddings, indices and memory data are deleted together with the underlying content.
CONUS and the model service providers used do not use the content to train general AI models.
CONUS may use content in access-restricted and, as far as possible, pseudonymised form for error analysis, security, quality assessment and improvement of the respective CONUS function.
Before transmission to external AI and document services, CONUS uses technical procedures intended to detect, anonymise or block possible patient data. Complete detection cannot be technically guaranteed.
10. OpenAI
We use the OpenAI API for generative AI functions.
For customers in the European Economic Area, OpenAI Ireland Ltd. is generally the contracting party under the provider's terms. Depending on the service and configuration, content may be processed by companies of the OpenAI group and sub-processors in the USA.
Under the provider's terms, API content is not used by default to train the models.
As zero data retention is currently not activated for CONUS, content may in principle be stored for up to 30 days for abuse and security checks. Insofar as the endpoints used offer a parameter to avoid additional application storage, CONUS applies it in line with the target configuration.
The legal basis is Article 6(1)(b) GDPR. Third-country transfers take place in accordance with Articles 44 et seq. GDPR.
11. Microsoft Azure Document Intelligence
We use Microsoft Azure Document Intelligence in the Azure West Europe region in the Netherlands for the automated extraction and structuring of document content.
Inputs and analysis results are processed in encrypted form in the same European region and temporarily stored in Azure Storage in that region. Analysis results are generally kept available for retrieval by the provider for up to 24 hours.
CONUS deletes analysis results after successful retrieval via the interface provided for this purpose, insofar as this is technically available.
The legal basis is Article 6(1)(b) GDPR. The primary processing and temporary storage take place within the European Union. Insofar as Microsoft processes or makes data accessible from a third country in an individual case, the requirements of Articles 44 et seq. GDPR additionally apply.
12. Cohere
We use Cohere for reranking and for assessing the relevance of search results.
Processing may take place in the USA. The use of inputs for model training is deactivated in the data controls.
According to the provider's information, logged prompts and outputs are generally deleted after 30 days, unless legal, contractual or security-related reasons preclude this.
The legal basis is Article 6(1)(b) GDPR. Third-country transfers take place in accordance with Articles 44 et seq. GDPR.
13. Institutional SOPs and internal content
Institutional administrators can make SOPs, internal contact persons and organisational information available.
The data is generally available only to authorised users of the same institution.
CONUS generally processes such data on behalf of the institution. The integrated data processing agreement in the institution terms applies.
Where necessary, CONUS creates embeddings, indices, metadata and technical auxiliary data.
Institutional content is not used to train general AI models and is not used for responses to other institutions.
After the end of the contract, content is deleted from production systems within 30 days. Backup copies are overwritten within 90 days.
14. Technically privileged access
Only specifically authorised internal development and administration roles are technically able to access AI histories, documents or institutional content.
Access takes place only insofar as this is necessary for operation, maintenance, security, support, troubleshooting or statutory obligations.
Access is limited by role and permission concepts, confidentiality obligations and logging.
Where possible, content is anonymised or pseudonymised before any manual review.
15. Cookies, local storage and consent management
For login, security, language settings, consent status and other technically necessary functions, we use cookies, local storage or comparable technologies.
Technically necessary technologies are used on the basis of Section 25(2) TDDDG and, insofar as personal data is processed, Article 6(1)(b) or (f) GDPR.
Non-necessary analytics, personalisation or marketing technologies are activated only after prior consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.
Users can change their selection at any time via the privacy or cookie settings. Withdrawal takes effect for the future.
The specific storage period depends on the purpose of the respective technology and is shown in the consent interface.
16. Product analytics with PostHog
We use PostHog in the EU cloud in Frankfurt for technical operational analysis and, subject to consent, for extended product analytics.
Essential tracking: Without consent, we process exclusively technically necessary events that are not permanently linked to a user. The target configuration does not store any IP address in PostHog, does not set any permanent personal user identifier and does not create any session replays. The processing serves error detection, security, stability and provision. The legal basis is Article 6(1)(f) GDPR. Insofar as access to a terminal device is strictly necessary, Section 25(2) TDDDG applies.
Extended tracking: Only after active consent may we process a pseudonymous user identifier, IP address, usage paths, feature interactions, device information and session replays. Text inputs, passwords, prompts, responses, notes, document content and sensitive fields are masked or excluded from recording. The legal basis is Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Consent can be withdrawn at any time in the privacy or cookie settings. Withdrawal takes effect for the future.
Extended event data is generally stored for 12 months. Session replays are stored for 30 days. Records of consent may be stored for up to three years after withdrawal.
17. Technical AI tracing
For technical AI metrics we use exclusively PostHog Cloud EU, whose infrastructure is operated in the AWS eu-central-1 region in Frankfurt.
Only technical metadata such as trace ID, model, latency, token count, cost, error type and number of sources is transmitted to the tracing service.
Complete prompts, responses and document excerpts are not transmitted to the tracing service.
Technical trace metadata is stored for 30 days. Aggregated performance indicators without any reference to content or persons may be stored for up to twelve months.
18. Amazon Web Services
We use Amazon Web Services for object storage and for sending transactional e-mails.
S3 buckets and Amazon Simple Email Service are operated in the eu-central-1 region in Frankfurt.
S3 content is deleted in accordance with the periods described for the respective data category. Versions and backup copies are limited by technical lifecycle rules.
Depending on the processing operation, the legal basis is Article 6(1)(b) or (f) GDPR.
19. Push notifications
When push notifications are activated, we process a device-related push token, device settings and delivery status.
Delivery takes place via the infrastructure of the operating system provider.
We send technically or contractually necessary messages and, subject to the corresponding consent, newsletters, product information or events.
Push tokens are stored until deactivation, account deletion or, at the latest, 90 days after permanent inactivity has been determined.
20. E-mail, newsletter and communication
For transactional e-mails and newsletters we use Amazon Simple Email Service in the eu-central-1 region.
We process in particular the e-mail address, time of dispatch, delivery status and technical metadata.
Contract, security and account notifications are sent on the basis of Article 6(1)(b) or (f) GDPR.
We generally send newsletters and other electronic advertising subject to consent pursuant to Article 6(1)(a) GDPR and Section 7 UWG.
Newsletter data is stored until withdrawal. Records of consent may be stored for up to three years thereafter.
21. Contact and support
When you contact us, we process your name, contact details, institution, content, attachments and technical metadata.
The legal basis is Article 6(1)(b) GDPR insofar as the request concerns a contract. Otherwise the legal basis is Article 6(1)(f) GDPR.
Support communication is generally stored for three years after completion. Statutory retention obligations remain unaffected.
22. Subscriptions and payments
For paid web subscriptions we use Stripe.
Depending on the function, Stripe may act as a processor and as a controller in its own right. We process in particular the name, e-mail address, payment instrument, invoice data, transaction data, IP address, device information and fraud prevention data.
For purchases via the Apple App Store or Google Play, payment processing is carried out by the respective store operator.
CONUS generally does not receive complete payment instrument data, but transaction and subscription information.
The legal basis is Article 6(1)(b) GDPR.
Accounting records required by law are stored for eight years and commercial and business correspondence generally for six years.
23. Manufacturer information and communication
Manufacturers do not receive access to individual user accounts, personal search queries, AI histories, content accessed, institutional product portfolios or the competing products of individual institutions.
CONUS may provide platform-wide anonymised and sufficiently aggregated statistics.
General manufacturer events may be displayed on manufacturer pages.
Targeted commercial messages are sent only where there is a sufficient legal basis. Specific product-related safety information may be communicated following review by CONUS.
24. Anonymised and aggregated data
CONUS may anonymise personal data and aggregate it with other data.
Following effective anonymisation, the data is no longer subject to the GDPR.
CONUS may use anonymised and sufficiently aggregated data without any time limit for product development, statistics, benchmarking, research, market analysis, sales planning, commercial evaluations, investor communication and the publication of general findings.
CONUS does not undertake any re-identification.
25. Recipients and service providers
We transfer data only insofar as this is necessary for provision, performance of the contract, security, payment, communication, legal defence or on the basis of a statutory obligation.
The categories of recipients include hosting and infrastructure providers, e-mail and push service providers, analytics providers, AI and document services, payment service providers, support and consulting service providers as well as public authorities where there is a statutory obligation.
The providers used include in particular Hetzner Online GmbH, STRATO AG, Amazon Web Services EMEA SARL and affiliated AWS companies, Microsoft Ireland Operations Limited and affiliated Microsoft companies, OpenAI Ireland Ltd. and affiliated OpenAI companies, Cohere Inc., PostHog Inc., Stripe Payments Europe Limited as well as Apple and Google for the corresponding store functions.
26. Third-country transfers
Some service providers process data in countries outside the European Economic Area, in particular in the USA and Canada.
Transfers take place only in accordance with Articles 44 et seq. GDPR.
We use in particular adequacy decisions, standard contractual clauses, contractual data protection agreements, encryption, data minimisation and access restrictions.
When OpenAI and Cohere are used, content required for the respective request may be processed outside the European Economic Area, in particular in the USA. Azure Document Intelligence is operated by CONUS in the European West Europe region in the Netherlands.
27. Automated decision-making
CONUS does not take any decisions based solely on automated processing which produce legal effects concerning the user or similarly significantly affect the user.
AI outputs are research results and not binding decisions.
28. General storage periods
Unless a more specific period is stated, we store data only for as long as it is necessary for the respective purpose.
Once the purpose no longer applies, we delete or anonymise data, unless statutory retention obligations, security requirements or legitimate purposes of evidence and legal defence preclude this.
Deletions in production systems generally take place within 30 days. Backup copies are generally overwritten within 90 days.
29. Data security
We implement appropriate technical and organisational measures.
These include in particular encryption in transit, role and permission concepts, tenant separation, logging of administrative access, data backup, patch and vulnerability management, access restriction and procedures for handling security incidents.
Complete protection against all risks is technically not possible.
30. Rights of data subjects
Subject to the statutory requirements, data subjects have the rights to information, rectification, erasure, restriction of processing, data portability and objection.
Consent may be withdrawn at any time with effect for the future.
In the case of processing based on Article 6(1)(f) GDPR, an objection may be lodged on grounds relating to the data subject's particular situation.
Direct marketing may be objected to at any time without any specific reason.
A message to info@conus-med.com is sufficient to exercise these rights.
31. Right to lodge a complaint
Data subjects may lodge a complaint with a data protection supervisory authority.
For CONUS, the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia is generally responsible.
Address: Kavalleriestraße 2 - 4, 40213 Düsseldorf, Germany.
32. Changes to this privacy policy
We update this privacy policy in the event of changes to functions, service providers, the legal situation or data processing.
The current version is made available on the website and in the apps.