Skip to content
PPerstivo
ProductUse casesPricing
DE/EN
Sign inCreate organisation

Legal

Privacy notice

Last updated: 23 July 2026

1. Controller

Greck Consulting GmbH & Co. KG
Mondscheinweg 15
80997 München
Deutschland

Represented by

Dr. Greck GmbH
Mondscheinweg 15
80997 München
Deutschland

Registration court: HRB
Registration number: 272306

Represented in turn by:
Dr. Peter Greck

Contact for privacy requests

Email: kontakt@greck-consulting.de
Phone: +49 89 2441 67631

This notice applies to the public Perstivo website, registration and sign-in, and use of the Perstivo application.

2. Responsibilities for organisation accounts

We are the controller within the meaning of the GDPR for the public website, registration, secure operation of the platform and our own contractual and payment processing.

Where a customer organisation uses Perstivo for its own training and processes personal content relating to its members, employees or other participants, that organisation will generally determine the purposes and means of the processing. In that context, we process data on its instructions as a processor. Further details are set out in the data processing agreement with the respective organisation.

3. Website, server logs and language preference

When you access our website or application, we process technically necessary connection data. This may include the IP address, time, requested address, HTTP status, volume of data transferred, and browser and device information. This is necessary to deliver the pages, identify errors and defend against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of Perstivo.

The public website stores your language choice under perstivo-language in your browser. On your first visit, the browser language may be used to select the German or English version. The application also stores the organisation most recently selected on that device. These details remain on the relevant device until deleted through the browser functions. This storage is necessary to provide the convenient use requested by you (section 25(2)(2) TDDDG; Article 6(1)(f) GDPR).

We currently do not use analytics, marketing or advertising trackers, or cookies intended for these purposes.

4. Registration, account and organisation administration

To begin registration, we process your email address, selected language and plan, as well as a verification token stored only in hashed form and delivery, time and status information. The verification link is valid for one hour. Only after successful verification do we additionally process your name, organisation name, securely hashed password and acceptance of the contractual terms shown during registration. We then create the user account, organisation, membership and prepaid account.

When organisation administration is used, we process information including memberships, roles, invitations, scenarios, prices and budgets, and security- and administration-related events. The legal basis is Article 6(1)(b) GDPR for taking steps prior to entering into a contract and performance of the contract. Where actions are logged for security and traceability, processing is additionally based on Article 6(1)(f) GDPR.

5. Sign-in, security and email delivery

We use technically necessary secure cookies for the server-side session and protection against forged requests. They are not used for advertising or audience measurement. We process session identifiers, time information, the last access and, where applicable, a device label. If multi-factor authentication is enabled, we also process the necessary security secrets and recovery codes in protected form.

Confirmations, invitations, password resets and other transactional messages are sent through our configured email service provider. For this purpose, the recipient address, message content, and delivery and status information are processed. The legal basis is Article 6(1)(b) GDPR; security measures are additionally based on Article 6(1)(f) GDPR.

6. Voice training and AI services

Perstivo requires microphone access for voice training. During training, the voice input, resulting conversation content, responses, selected scenario and technical usage data are processed. The audio data is streamed to the AI service provider selected for the organisation by the platform administrator. Perstivo does not permanently store the audio as an audio file.

Depending on the configuration, OpenAI or Mistral AI may perform speech recognition, dialogue generation, speech output and evaluation. A transcript, training feedback, scores and supporting passages may be generated from the conversation and stored in the organisation account. The legal basis is Article 6(1)(b) GDPR where you are the contracting party. For training provided by a customer organisation, that organisation determines the applicable legal basis and informs its participants.

Please do not mention real names, confidential business information or special categories of personal data during training unless your organisation has expressly provided for and legally authorised their processing.

7. Prepaid balance and payments

Perstivo is used on a prepaid basis in euros. For top-ups, we process the organisation, amount, currency, payment status, provider reference and associated ledger entries. Depending on the enabled payment method, you are redirected to Mollie or PayPal. The relevant provider processes the payment details entered there; we receive the reference, status and amount information required for allocation and confirmation.

The legal basis is Article 6(1)(b) GDPR. We process records required under tax and commercial law on the basis of Article 6(1)(c) GDPR.

8. Recipients and international transfers

Personal data is received only by parties that need it for the purposes described above. These may include:

  • hosting, infrastructure, logging and email service providers;
  • OpenAI or Mistral AI as the configured AI service provider;
  • Mollie or PayPal when you initiate a top-up;
  • advisers, authorities or courts where we are legally required to disclose data or need to protect legal claims.

Where required, service providers are contractually engaged as processors. Depending on the selected provider and contractual setup, processing may take place outside the EU or EEA. Such a transfer takes place only where the legal requirements are met, in particular on the basis of an adequacy decision or appropriate safeguards under Article 46 GDPR, such as the EU Standard Contractual Clauses. On request, we will provide information on the providers used for the relevant contract and a copy of the applicable safeguards.

9. Retention

  • Technical production logs are generally retained for no more than 30 days unless a security incident requires longer preservation.
  • Unconfirmed or completed registration records are deleted during routine cleanup within a further seven days after expiry or completion.
  • Sign-in sessions end after 30 minutes of inactivity and no later than eight hours after creation. Expired or revoked session records are cleaned up within a further seven days.
  • Conversation transcripts are automatically deleted no later than 30 days after their last update; a shorter period may be configured.
  • Account, organisation, scenario, training, evaluation and security data is retained for as long as necessary for use, administration, evidence or the establishment, exercise or defence of legal claims.
  • Payment and accounting data is retained in accordance with statutory retention obligations.

When a purpose no longer applies, we delete or anonymise the data unless statutory obligations or legitimate reasons require further restricted retention.

10. Sources and requirement to provide data

We receive data from you, administrators of your organisation, your browser or device, and the payment, email and AI service providers used. Required fields are necessary for registration, entering into a contract, secure access or the respective function. Without this information, we cannot provide the service concerned. Voluntary details are marked accordingly or are evident from the context.

11. Automated decisions

Perstivo automatically generates training feedback and scores. These are intended for personal practice and do not themselves produce legal or similarly significant effects through Perstivo. We do not make decisions based solely on automated processing within the meaning of Article 22 GDPR. A customer organisation is responsible for any separate use it makes of training results.

12. Your rights

Subject to the statutory requirements, you have in particular the right to:

  • access your personal data and receive a copy;
  • rectify inaccurate data and complete incomplete data;
  • erasure or restriction of processing;
  • data portability;
  • object to processing based on Article 6(1)(e) or (f) GDPR;
  • withdraw consent with effect for the future where processing is based on consent;
  • lodge a complaint with a data protection supervisory authority, in particular at your habitual residence, place of work or the place of the alleged infringement.

For privacy requests, you can contact us at kontakt@greck-consulting.de. Where your organisation is the controller for the processing concerned, you may also contact its responsible contact point directly.

13. Changes to this notice

We update this privacy notice when functions, service providers or legal requirements change. The current version is available on this page.

PPerstivo

Practice difficult conversations with confidence.
Practice calm under pressure.

PerstivoProductUse casesPricing
LegalLegal noticePrivacyTerms
Get startedCreate organisationSign in
© 2026 PerstivoPractice calm under pressure