Privacy policy (Datenschutzerklärung)
Last updated: 25 July 2026
Courtesy English translation. The German version (Deutsche Fassung) is the legally controlling text.
This privacy policy applies to our entire offering under snori – both the website snori.de and the logged-in application at app.snori.de (together "snori"). There is one single privacy policy for both.
We take the protection of your personal data seriously and process it exclusively in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller responsible for data processing at snori (website and application) is:
INREMA Unternehmensberatung GmbH Rentmeister-Wilhelm-Weg 16 33181 Bad Wünnenberg, Germany Represented by the managing director: Tanja Rüdiger Email: helpdesk@snori.de (privacy and support) · info@inrema.de (general)
Full details are available in the legal notice.
2. Principles of processing
We only process personal data where there is a legal basis for doing so, in particular:
- Art. 6(1)(b) GDPR – to perform a contract or take pre-contractual steps (e.g. when you contact us),
- Art. 6(1)(f) GDPR – to protect our legitimate interests (e.g. a secure, stable and well-designed website),
- Art. 6(1)(c) GDPR – to comply with legal obligations.
We do not pass your data on for advertising purposes and we do not sell it.
3. Hosting and server log files
Our website and the application app.snori.de are hosted at IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany (hosting provider), in an ISO/IEC 27001-certified data center in Germany. IONOS processes data as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
When you access the website, information is automatically recorded in so-called server log files, as is technically necessary for any website visit:
- the IP address of the requesting device,
- the date and time of access,
- the specific page or file requested and the amount of data transferred,
- the previously visited page (referrer), where transmitted,
- the browser and operating system used.
This data is used for the technical provision, security and stability of the website and is not merged with other data sources. The legal basis is our legitimate interest in secure, trouble-free operation (Art. 6(1)(f) GDPR). Log files are stored for a short period only and then deleted, unless they are exceptionally required to investigate a specific security incident.
4. Content delivery network and security (Cloudflare)
To deliver the website securely and quickly and to protect it against attacks (e.g. overload and bot attacks), we use Cloudflare. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, represented in the EU by Cloudflare Germany GmbH, Munich.
All traffic between your device and our website is routed through Cloudflare's servers. In doing so, Cloudflare processes in particular your IP address and technical request metadata in order to detect and block malicious traffic and to deliver content efficiently. The legal basis is our legitimate interest in the security and availability of our website (Art. 6(1)(f) GDPR). A data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare.
This may involve a transfer of data to the USA. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, EU standard contractual clauses are agreed, ensuring an adequate level of data protection.
For storing the files uploaded in the application (e.g. attachments and images) we additionally use the object storage Cloudflare R2 in the EU region. The storage is private; access takes place exclusively through the application's permission check. A data processing agreement pursuant to Art. 28 GDPR is in place for this as well, together with EU standard contractual clauses for any processing by the US parent. In addition, we also use the object storage of our hosting provider IONOS (Germany).
5. Analytics with Umami
To analyze the use of our website statistically, we use Umami – privacy-friendly analytics software that we run ourselves on our own infrastructure (stats.inrema.de). No cookies are set and there is no cross-device recognition. Umami collects only anonymized, aggregated data such as pages viewed, approximate origin (country level), referring page and browser/device type. The IP address is not stored and is at most processed briefly and in anonymized form.
Because Umami works without cookies and does not store or read any information on your device, no consent is required. No data is shared with third parties. The legal basis is our legitimate interest in a needs-based design and improvement of our website (Art. 6(1)(f) GDPR).
6. Cookies
This website generally does not use tracking or advertising cookies. Only a single, technically necessary cookie is set:
lang– stores the language you have selected (German/English) so the website is shown in the correct language. Lifetime: up to 12 months. No analysis of user behavior takes place.
This cookie is strictly necessary for the function you requested; no consent is therefore required (§ 25(2)(2) TDDDG). You can delete cookies at any time in your browser settings or prevent them from being set.
7. Locally hosted fonts
All fonts used on the website are served locally from our own server. There is no connection to Google Fonts or other third-party services; no data is transferred to third parties when fonts are loaded.
8. Contacting us
If you contact us by email (e.g. at helpdesk@snori.de), we process the data you provide (in particular your email address, name and the content of your message) in order to handle your request. The legal basis is Art. 6(1)(b) GDPR where the request concerns a contract, otherwise our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). Your data is deleted once the request has been fully dealt with, unless statutory retention obligations apply.
9. Account, registration and login (application app.snori.de)
To use the application at app.snori.de you create an account and log in. The "Log in" and "Start for free" buttons take you there. To provide access and perform the contract we process the data required for this: email address, name, a password stored only in encrypted (hashed) form, two-factor security (2FA) and your workspace membership and account settings. The legal basis is Art. 6(1)(b) GDPR (contract or pre-contractual steps).
This account data serves solely to provide you with login and use of the application. We do not collect usage data for analytics, profiling or advertising purposes and do not evaluate your behavior in the application. For login the application sets a strictly necessary session cookie (§ 25(2)(2) TDDDG); no consent is required for this.
The content you store in your workspace (documents, notes, tables) is processed by us as a processor on your behalf; the details are governed by the data processing agreement (DPA). Account and workspace data is stored in the ISO/IEC 27001-certified data center in Germany (see section 3).
10. Payment processing (Stripe)
For paid subscriptions we handle payment via the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland; depending on your location possibly Stripe, Inc., USA). As part of subscription and payment processing we pass the data required for this to Stripe – in particular name, email address and payment/billing data. The actual payment-method data (e.g. card number) you enter directly with Stripe; it is processed by Stripe and is not available to us in clear text.
The legal basis is performance of the subscription contract (Art. 6(1)(b) GDPR) and compliance with tax and commercial-law obligations (Art. 6(1)(c) GDPR). Where data is transferred to the USA, this is safeguarded by the EU-US Data Privacy Framework or EU standard contractual clauses. For details of Stripe's processing, see Stripe's privacy policy.
11. Recipients of your data
Beyond the processors named above, we do not disclose personal data to third parties. The service providers we use are:
- IONOS SE – hosting for the website and the application and object storage (Germany),
- Cloudflare – content delivery network and attack protection, and the Cloudflare R2 object storage for uploaded files (EU region/USA, safeguarded as described in section 4),
- Stripe – payment and subscription processing (EU/USA, safeguarded as described in section 10),
- OpenAI Ireland Limited and/or Anthropic Ireland Limited – AI service providers (EU).
AI-assisted features. For individual AI-assisted features we use both external AI service providers (in each case exclusively via their commercial interfaces) and our own, self-hosted AI models on our own infrastructure. In no case – neither with external providers nor with our self-hosted models – is your content used to train models; it is processed solely to answer the respective request. We use these systems only to provide and improve our own services. The legal basis is our legitimate interest in functioning services (Art. 6(1)(f) GDPR); for any third-country transfers to external providers, EU standard contractual clauses apply.
AI connected by you. If you connect your own AI (e.g. ChatGPT, Claude, Gemini or Perplexity) to your workspace in the application, you choose that service and decide which content it may read or write. That provider is not our processor; you yourself establish the data-protection basis for it with the AI provider of your choice. The details are governed by the data processing agreement (Section 7).
12. Your rights as a data subject
With regard to your personal data, you have the following rights:
- access to the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing (Art. 21 GDPR),
- withdrawal of a given consent with effect for the future (Art. 7(3) GDPR).
To exercise your rights, an informal message to helpdesk@snori.de is sufficient.
13. Right to object
Where we process your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation.
14. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW). You may also contact the supervisory authority at your usual place of residence.
15. Encrypted transmission
For security reasons, this website uses TLS encryption (HTTPS). You can recognize an encrypted connection by the padlock symbol in your browser's address bar.
16. Storage period
We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention periods. After that, the data is deleted.
17. Automated decision-making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place at snori.
18. Currency and changes to this privacy policy
This privacy policy is currently valid. As our website evolves or due to changed legal requirements, it may become necessary to amend it. The current version published on this page applies in each case.