# Retorik — Privacy notice

Version 4 · 9 September 2026

For everyone with a Retorik account, for the executives whose writing is in it, and for anyone who visits `retorik.pro` or `app.retorik.pro`.

Canonical: https://www.retorik.pro/legal/privacy/

## In short

- **We hold little about you as a person.** A name, a work email, a password hash or a passkey, and the record of what you did in Retorik: who wrote, checked, approved and published what.
- **The executive's writing and the drafts belong to the institution.** It is the controller. We process that content on its instructions, under a data processing agreement, and never for our own purposes.
- **The AI model reads the drafts.** Anthropic, in the United States, under EU standard contractual clauses. It keeps API data for up to 30 days and does not train on it.
- **Everything else stays in the EU**, on Scaleway's servers in France and the Netherlands.
- **No advertising, no tracking, no selling, no training.** The app sets one sign-in cookie and nothing else. The website counts visits without cookies.
- **Your rights**: see, correct, export or erase your data. Email info@retorik.pro. Complaints go to the Dutch data protection authority.

## i. Who is responsible


RAAK.work, a sole proprietorship of Wessel Janse van Rensburg, registered in the Netherlands and trading as Retorik, is the controller for the data in sections 2, 5 and 6: your account, the running of the service, and the websites. Contact: info@retorik.pro. We have no data protection officer because the law does not require one at our size and for this kind of processing.

For the content an institution puts into Retorik (section 3) and for the connected accounts (section 4), the institution is the controller and we are its processor. Our data processing agreement, part of the terms of service, governs that.

**Solo executives.** If you use Retorik on your own for your business or profession, you are the controller of your content and we are your processor, exactly as for an institution; the data processing agreement applies to you. If you use it as a private person, we are the controller for your content as well as your account. We then process it only under the contract with you, in the same way, with the same confidentiality, and never for our own purposes; everything the data processing agreement promises an institution, we promise you.


## ii. People with a Retorik account


| What | Why | Legal basis | How long |
|---|---|---|---|
| Name, work email, role, organisation | To run your account, sign you in, and show your colleagues who wrote, checked and approved what | The contract with your institution; our legitimate interest in running the service | Until 30 days after your institution's agreement ends, or until it removes you |
| Password, stored only as a salted hash; or a passkey's public key and device label | To sign you in. We never see a passkey's private key; it stays on your device | Same | Same |
| Signed-in sessions and a version number that lets us sign you out everywhere | To keep you signed in and to end every session at once when needed | Same | While the session lasts |
| Invitation and password-reset links, stored only as hashes | To let you in and to reset a password safely | Same | Seven days, or until used |
| Sign-in attempts and generation requests, counted per account and per IP address in memory | To stop password guessing and abuse | Our legitimate interest in a secure service | Fifteen minutes; never written to disk |
| The audit log: every workflow action with who did it and when | So that your institution can see who did what, and so can you | The contract; the institution's legitimate interest in an audit trail | For as long as your institution's data is kept |
| How much AI usage each feature caused, in tokens and cost, without the text | To watch our own costs | Our legitimate interest | Two years |
| Support email you send us | To answer you | Our legitimate interest in answering | Two years |
| The record that your organisation accepted the terms: the organisation, your name and work email, and which version of each document | To show what was agreed and when | Our legal duty to keep an administration, and our legitimate interest in being able to show the agreement | Seven years, like invoices. This one is kept when the rest is erased |

We use your email only to sign you in, to send invitations and resets, and to tell you about the service or these documents. No newsletter. We make no automated decisions about you: everything that matters is decided by a person.


## iii. The executive's writing, the drafts and the record


An institution uploads what its executive has written and said: posts, articles, speeches, memos. Retorik stores that writing per executive, extracts the ideas and the style from it, and builds a profile of the executive's voice. From then on drafts, their versions, review notes, references and the record of who approved what are stored for that executive.

This content is personal data of the executive and may name other people. The institution decides what to put in and what to publish, so **the institution is the controller** and we are its processor. We process it only to run Retorik for the institution: to draft, refine, check, store, back up, export and publish on its instruction. We do not read it except to fix a fault or answer a support request, and then only the one person who runs Retorik. We never train a model on it and never use it for anyone else.

The AI processing in section 5 happens on the institution's behalf. Embeddings, the numbers that let Retorik find related ideas in the executive's writing, are computed on our own server and leave it for no one.

If you are an executive and have a question about what your institution put in, ask your institution first; it holds the content. If you cannot reach it, email us and we pass the question on. A solo executive asks us directly.


## iv. Connected accounts


An executive connects their own LinkedIn, X or Bluesky account. We store the access tokens, encrypted with keys held outside the database, and the name and account identifier the platform gives us at connection. We use them to publish what the institution approved and to show whether the connection is live. When a post is published we keep the post's identifier so that the record can point to it. Disconnecting deletes the tokens and the profile details; the post identifiers stay in the record.

Each platform then handles the published post under its own terms, as an independent controller, and may process it outside the EU. What the executive publishes there is between the executive, the institution and the platform.


## v. The AI model and where data goes


To draft, refine and check text, Retorik sends the relevant writing, drafts and instructions to **Anthropic, PBC** in the United States, the maker of the Claude models, through its API. Anthropic is our sub-processor under a data processing addendum with EU standard contractual clauses. Anthropic does not train on this data. It keeps API inputs and outputs for up to 30 days for abuse detection and then deletes them. When you press "Look it up", Anthropic's web search runs the query; the found page's address comes back to Retorik and nothing else about you goes out.

We tell institutions 30 days before we add or change an AI provider, and they can object. An option to keep AI processing inside the EU is on our roadmap for institutions that need it.


## vi. Cookies, logs and the websites


**Cookies.** The app sets one cookie, `ev_session`, which keeps you signed in. It is strictly necessary, so no consent is needed and there is no banner. The app sets no analytics, advertising or tracking cookies and loads nothing from third parties.

**Logs.** Our web server records each request: IP address, time, address requested, browser type and the response. We keep these for at most 30 days, to find faults, stop abuse and answer lawful orders. Legal basis: our legitimate interest in running a secure service.

**The website `retorik.pro`.** It uses Pirsch Analytics, a German service that counts visits without cookies and without storing anything in your browser: pages viewed, referrer, country, device and browser, as aggregate statistics. The request form on the website opens your own email program; nothing is stored on the site.


## vii. Who else sees data


| Company | Where | What it does |
|---|---|---|
| Scaleway SAS | France; servers in Paris and Amsterdam | Runs the service: the server, the database, the storage of the executives' writing, the backups, and the email we send |
| Anthropic, PBC | United States | The AI model that drafts, refines and checks text, and its web search (section 5) |
| Pirsch Analytics (Emvi Software GmbH) | Germany | Counts visits to the website `retorik.pro`, not the app |
| LinkedIn, X, Bluesky | Their own terms; may be outside the EU | Receive the posts the institution publishes, as independent controllers, on the executive's instruction (section 4) |

Each processor is bound by a contract that meets the GDPR. Personal data leaves the European Economic Area only for Anthropic, under standard contractual clauses, and for the platforms, on the executive's own instruction. We do not sell data, share it with advertisers, or use it to train anything.

We hand over data to a court or authority only when the law requires it, and we tell the institution unless the law forbids that.


## viii. Security


Passwords are stored only as salted hashes; passkeys mean no password need exist. An administrator can remove a person's access at once, and it takes effect everywhere on their next request. Sessions can be revoked on every device at once. Sign-in and AI generation are rate-limited. Platform tokens are encrypted with keys held outside the database, one key per platform. Every organisation's data is separated from every other's on every request. Uploads are checked by size and by content before they are read. Every URL a user asks Retorik to fetch is checked before it is fetched. Every response carries strict security headers. Data is encrypted in transit. Backups are made nightly and kept for 30 days. If a breach affects your data we tell the institution within 48 hours and the authority within the time the law sets.


## ix. Your rights


You can see, correct, export and erase your data, restrict or object to processing based on our legitimate interest, and ask for a copy. Email info@retorik.pro; we answer within one month. If you use Retorik through an institution, we pass a request about the content to the institution, because it holds and controls it.

If you are unhappy with our answer you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in your own country.


## x. Changes


When this notice changes we update the version and date at the top and, for changes that matter, tell institutions 30 days before they apply.


Questions about this document go to info@retorik.pro.
