Skip to content
Meritevo
DEBack to home
// Legal information

Privacy policy.

This privacy policy explains how personal data is processed when you visit our websites www.meritevo.de and www.meritevo.eu and when you use our application Meritevo at app.meritevo.de.

As at: 09 Sept 2026 · Version 1.1

Contents
1. Controller and contact2. Two roles: controller and processor3. Legal bases4. Server log files5. Cookies and local storage6. Registration and user account7. Use of the application8. AI-assisted features9. Payment processing10. Email delivery11. Contacting us12. Recipients and processors13. Retention periods14. Your rights15. Obligation to provide data16. Data security17. Changes to this policy

1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Quantevo GmbH
Keffenbrinkweg 6
12249 Berlin, Germany

Email: contact@meritevo.eu
Data protection enquiries: contact@meritevo.eu

Authorised managing director: Oliver Diekmeier · Local Court of Charlottenburg (Berlin), HRB 289900 B · VAT ID: DE464420390

Data protection officer: No data protection officer has been appointed at present, as the statutory conditions (§ 38 German Federal Data Protection Act, BDSG) are not met. Please address any enquiries to the contact details above.

2. Two roles: controller and processor

Please note the distinction between two types of processing:

a) We act as controller for the data arising from the use of our website, from registration, contract performance, billing, support and the safeguarding of operations. These processing activities are described in sections 4 to 11.

b) We act as processor for all content our customers store in their workspaces, such as proposal texts, project ideas, budget data, contact persons at partner organisations, publication lists and uploaded files. Where such content contains personal data relating to third parties, we process it exclusively on the instructions of the customer concerned, on the basis of a data processing agreement under Art. 28 GDPR. The controller for that data is the customer, that is, as a rule, your university, your institute or your company.

If you are recorded as a contact person of a partner organisation in a workspace and wish to request access or erasure, please contact the institution that operates that workspace. We are happy to forward your request.

3. Legal bases

We process personal data on the following legal bases:

Art. 6 (1) (b) GDPR
Performance of a contract or steps taken prior to entering into a contract (registration, provision of the application, billing, support).
Art. 6 (1) (c) GDPR
Compliance with legal obligations, in particular retention obligations under commercial and tax law.
Art. 6 (1) (f) GDPR
Pursuit of legitimate interests (security and stability of operations, prevention of misuse, further development of the application, assertion of legal claims).
Art. 6 (1) (a) GDPR
Consent, where we obtain it separately (for example for product news by email). You may withdraw consent at any time with effect for the future.
Art. 28 GDPR
Processing on behalf of our customers (see section 2 b).

4. Access to the website and the application (server log files)

Each time the website or application is accessed, our server automatically collects technical access data:

  • the IP address of the requesting device,
  • the date and time of access,
  • the address requested (URL) and the HTTP status code,
  • the volume of data transferred,
  • the referrer URL,
  • the browser type, browser version and operating system.

Purpose: provision of the website, safeguarding system stability, detecting and preventing attacks and misuse, error analysis.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and uninterrupted operation) and Art. 6 (1) (b) GDPR.

Retention period: log files are deleted or truncated after 30 days at the latest. In the event of a specific security incident, we retain the entries concerned until the matter has been finally resolved.

5. Cookies and local storage

We use strictly necessary cookies only. We do not use analytics, tracking, advertising or profiling cookies, and we do not integrate any third-party audience measurement tools.

NamePurposeRetention
Session cookie (sign-in)Maintaining your signed-in session after loginup to 12 hours, or until you sign out
Workspace selectionRemembering the workspace you last useduntil you sign out
Interface preferences (local)for example light or dark appearancestored in your browser, can be deleted at any time

Legal basis: § 25 (2) no. 2 German Telecommunications Digital Services Data Protection Act (TDDDG) (strictly necessary storage) in conjunction with Art. 6 (1) (b) and (f) GDPR. As we use strictly necessary cookies only, consent is not required and no cookie banner is displayed.

You can delete cookies at any time through your browser settings. Deleting the session cookie signs you out.

6. Registration and user account

A user account is required in order to use the application.

Data processed: name or display name, email address, password stored in encrypted form (hashing), time of registration and of email confirmation, times of sign-in and sign-out, membership of organisations and workspaces, role and permissions, and optionally details of two-factor authentication and of your own research profile (for example thematic focus, ORCID identifier).

Purposes: provision of access, authentication, permission management, confirmation of the email address, password reset, invitation of team members, prevention of misuse.

Legal basis: Art. 6 (1) (b) GDPR; for security measures additionally Art. 6 (1) (f) GDPR.

Prevention of misuse during registration: to protect against automated mass registrations, we limit the number of registration, sign-in and password requests per IP address within a given time window. For this purpose we briefly store counters relating to IP addresses (retention between 5 and 60 minutes, depending on the measure). We also check the email domain provided against a locally held list of disposable email providers; no data is transferred to third parties in this process. The legal basis is Art. 6 (1) (f) GDPR.

Retention period: until the account is deleted. After the contract ends, we delete account data in accordance with section 13.

7. Use of the application (customer content)

Content that you create or upload in your workspace, in particular project ideas, proposal texts and their versions, comments, chat messages, budget plans, partner and contact data, publication details and file attachments, is processed by us as a processor on behalf of the respective customer (section 2 b).

In addition, we log events within a workspace that are relevant to security and accountability (for example who granted which approval at what time, or who changed which record). These logs serve traceability and the prevention of misuse.

8. AI-assisted features

Our application includes features based on large language models and image generation models, such as the assessment of funding calls, the drafting of text, the critical review of sections, the drafting of budgets and the generation of images.

What is transmitted: in order to run an AI feature, the content required for it, for example the section concerned, the call text or the associated evidence, is transmitted to the respective model provider. Such content may contain personal data if you have included personal data in your documents.

Providers used: the default inference provider is the intermediary service OpenRouter, Inc. (USA), through which requests are routed to the respective model providers. Alternatively, workspaces can be set to a provider that processes exclusively within the EU, currently Nebius and TensorX. The specific models used may change as the technology develops; the current list of recipients is set out in section 12.

Semantic search: for semantic search we compute embeddings (vectors) using a model hosted in the EU by Nebius. This applies to all workspaces and cannot be changed; no transfer to a provider outside the EU takes place in this process.

The place of processing depends on your workspace configuration. We cannot give a general assurance that processing takes place exclusively within the EU. The application's servers, database and backups are located in Germany; for AI processing, the inference provider to be used, and whether only providers with a zero-retention commitment are permitted, is determined when the workspace is created. That setting can subsequently be changed only through our support team, not within the application itself.

Setting chosen when the workspace is createdEffect
Inference provider: OpenRouter (default)Requests are routed through OpenRouter (USA) to the respective model providers. Depending on the model, processing may take place in the EU or in the USA; the safeguards set out in section 12 apply to the transfer.
Inference provider: EU providers (Nebius, TensorX)Requests are routed exclusively to providers that process data within the EU or the EEA. No transfer to a third country takes place for AI processing.
Providers with zero retention only (default)This option is enabled by default. While it is enabled, only providers are used that have contractually undertaken neither to store transmitted content nor to use it to train their models. Only if the workspace owner expressly disables the option may providers be used that temporarily store content, for example for abuse monitoring, and that reserve the right under their own terms to use content to train their AI models.

Sandbox and free trial: in sandbox workspaces and during the free trial these settings cannot be configured. AI processing there runs through OpenRouter and therefore through a provider established in the USA that contractually guarantees zero retention. Please do not use confidential or personal content in these workspaces if that content must not leave the EU.

Training: we ourselves never use your content to train our own or any third-party models. Whether the same applies to the respective model provider depends on the zero-retention setting, which is enabled by default: where it is enabled, storage and any use for training purposes at the provider are contractually excluded. If the workspace owner expressly disables the option, temporary storage and, depending on the provider's terms, use of the content to train its models cannot be ruled out.

Processing only on deliberate action: AI features are triggered exclusively by an express action (for example clicking "create draft"). Background processes that monitor funding calls do not process proposal content.

No automated decision-making within the meaning of Art. 22 GDPR: the application's assessments and recommendations are decision aids. They have no legal effect and are always reviewed by, and remain the responsibility of, people.

Legal basis: Art. 6 (1) (b) GDPR (contractually owed functionality). Where the content contains personal data relating to third parties, processing takes place on behalf of the customer under Art. 28 GDPR.

Please note: before using AI features, check whether confidentiality agreements or your institution's rules prevent certain content from being transmitted to external model providers.

9. Payment processing

For paid plans we use Stripe Payments Europe, Ltd. (Dublin, Ireland).

Data processed: name, email address, billing address, VAT ID where applicable, plan selected, payment amount, payment status. Payment instrument data (card numbers, bank details) is processed exclusively by Stripe; we neither receive nor store it.

Purpose: processing of payments, invoicing, detection of fraudulent transactions.

Legal basis: Art. 6 (1) (b) GDPR; for fraud prevention Art. 6 (1) (f) GDPR; for the retention of invoicing data Art. 6 (1) (c) GDPR.

Retention period: invoices and accounting records are retained for ten years in accordance with § 147 German Fiscal Code (AO) and § 257 German Commercial Code (HGB).

Stripe acts in part as an independent controller; its own privacy notices apply in addition.

10. Email delivery

We send operational emails, in particular to confirm your email address, to reset passwords, to issue workspace invitations and to provide information about your contract. We use the service Brevo (Brevo GmbH, Berlin / Sendinblue SAS, France) for delivery.

Data processed: email address, display name, content and time of the message, and technical delivery information.

Legal basis: Art. 6 (1) (b) GDPR (operational messages); for product information without a direct contractual connection, Art. 6 (1) (a) GDPR (consent), which may be withdrawn at any time.

Product news: messages about new features and product changes are sent only with express consent (opt-in). You can give and withdraw that consent yourself at any time in your account settings within the application; unsubscribing takes effect for the future and does not affect operational messages. Without consent you will not receive product news.

11. Contacting us

If you contact us through the contact form or by email, we process your name, your email address, optionally your organisation, and your message in order to respond to your enquiry.

Legal basis: Art. 6 (1) (b) GDPR for contract-related enquiries, otherwise Art. 6 (1) (f) GDPR (legitimate interest in responding).

Retention period: we delete enquiries once they have been finally dealt with and no retention obligations apply, and after 24 months at the latest.

12. Recipients and processors

We disclose personal data only where this is necessary to provide our services, where we are legally obliged to do so, or where you have consented. Data processing agreements under Art. 28 GDPR are in place with all service providers that process personal data on our behalf.

Service providerPurposePlace of processing
Hetzner Online GmbH, GunzenhausenHosting, data centre operations, backupsGermany
Brevo GmbH / Sendinblue SASEmail deliveryEU
Stripe Payments Europe, Ltd.Payment processing, invoicingEU / USA
OpenRouter, Inc.Routing of requests to AI modelsUSA
Model providers via OpenRouterLanguage and image models for text, analysis and image features; zero retention and exclusion of any use for training are enabled by default and can be disabled in the workspaceEU/EEA or USA, depending on the workspace setting (section 8)
NebiusEmbedding model for semantic search (all workspaces); on request also inference providerEU/EEA
TensorXOptional inference provider for workspaces set to EU processingEU/EEA

In addition, we retrieve publicly available information from academic services to enrich records, including OpenAlex, Crossref, ORCID, CORDIS and publications of the German Federal Statistical Office. In doing so we generally transmit only search terms or identifiers (such as a DOI or an ORCID identifier), never account data. If you link your ORCID profile, the information you have published there is retrieved.

No disclosure for advertising purposes. We do not sell personal data and we do not pass it to third parties for advertising purposes.

Transfers to third countries

In the case of the providers listed in the table that are established outside the EU or the EEA, personal data is transferred to a third country. Such transfers take place on the basis of the European Commission's standard contractual clauses under Art. 46 (2) (c) GDPR, supplemented by technical and organisational safeguards (transport encryption, data minimisation, no transfer of account data to model providers), and, where applicable, on the basis of an adequacy decision (for example the EU-US Data Privacy Framework for certified companies).

We note that third countries may not offer a level of data protection equivalent to European law, and that access by public authorities cannot be excluded to the same extent.

The application itself, that is servers, database and backups, is operated exclusively in Germany (Hetzner). Beyond that, we do not give a general assurance of EU-only processing: whether AI requests leave the EU depends on the inference provider selected when the workspace was created, while the embeddings for semantic search are computed within the EU for all workspaces. In sandbox and trial workspaces, AI processing runs through OpenRouter and therefore through a US provider with zero retention (section 8). If you need clarity about the specific processing path for a project, write to us at contact@meritevo.eu.

13. Retention periods

We store personal data only for as long as it is necessary for the purposes described:

Server log files
max. 30 days (section 4).
Account and usage data
until the account is deleted or the contractual relationship ends.
Customer content
after the contract ends, export remains possible for 30 days; complete deletion then follows within 90 days. For sandbox workspaces the shorter period stated in each case applies.
Backups
deletions take effect in backups with a delay of up to 35 days; the data is removed there afterwards.
Invoices and accounting records
10 years (§ 147 AO, § 257 HGB).
Commercial letters
6 years (including relevant business correspondence).

14. Your rights

You have the following rights against us in respect of personal data concerning you:

  • access to the data processed (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR),
  • withdrawal of consent with effect for the future (Art. 7 (3) GDPR).

Right to object (Art. 21 GDPR)

Where we process data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.

To exercise your rights, a message to contact@meritevo.eu is sufficient. You can also view, change or export much of your data directly in your account settings.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for us is:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61, 10555 Berlin, Germany
mailbox@datenschutz-berlin.de

15. Obligation to provide data

Providing your name, email address and, for paid plans, billing details is necessary in order to enter into a contract. Without this information we cannot set up an account or provide the application. All other information (such as details of your research profile) is voluntary; without it, individual features may be available only to a limited extent.

16. Data security

We take technical and organisational measures appropriate to the state of the art in order to protect your data. These include, in particular, transport encryption of all connections (TLS), storage of passwords solely as a cryptographic hash, role-based access control with strict separation of workspaces, optional two-factor authentication, regular backups and the logging of security-relevant events.

17. Changes to this privacy policy

We update this privacy policy when the legal situation, our services or the nature of the processing changes. The current version published on this page applies. In the case of material changes we additionally inform registered users by email or within the application.

This English text is provided for convenience. The binding version is the German Datenschutzerklärung; in the event of any discrepancy, the German wording prevails.

Version 1.1, as at 09 Sept 2026, Quantevo GmbH, Berlin

Meritevo by Quantevo
HomeLegal noticeTerms and conditionsContact
© 2026 Quantevo | Meritevo. All rights reserved.Hosted in Germany · AI services partly EU/USA