App Privacy Policy | Casebase

Last updated: 04.05.2026

Who we are

Alexander Thamm GmbH (hereinafter: "AT") operates Casebase, a Software-as-a-Service platform for managing AI and data use cases. Under the General Data Protection Regulation (GDPR), AT is the controller for the processing of personal data described in this privacy policy, i.e. for all processing activities that AT carries out for its own purposes in connection with providing the Casebase application.

Note on the B2B context: Casebase is a B2B SaaS product made available to companies (hereinafter: "customers") for use by their employees. Where AT processes end users' personal data solely on the instructions of a customer — in particular content entered by users within the application — AT acts as a processor within the meaning of Art. 4 No. 8 GDPR. In that case, the respective customer is the controller. End users who wish to exercise their data subject rights in this context should contact their employer (the customer) directly. Should you nevertheless contact us, we will forward your request to the controller (your employer) without delay.

User data is processed as follows: personal data is collected when users register in the application, create or update their user profile, and through normal interaction with the application's features during ongoing use.

Alexander Thamm GmbH
Sapporobogen 6–8
80637 Munich
Germany
Phone: +49 89 30760880
contact@alexanderthamm.com
www.alexanderthamm.com

Contact for the Data Protection Officer

The appointed Data Protection Officer is:

DataCo GmbH
Sandstraße 33
80335 Munich
Germany
Phone: +49 89 452459 900
Email: info@dataguard.de
Website: www.dataguard.de

General information on data processing

On this page we inform you about the processing of your personal data in the Casebase application.

How we collect and use your personal data depends on how you interact with us or the services we offer. We only collect, use, or share your personal data where we have a legitimate purpose and a legal basis for doing so.

What do we mean by "legal basis"?

Consent (Art. 6(1)(a) GDPR) — You have given us your consent to process your personal data for the purpose explained to you. You have the right to withdraw your consent at any time.

Contract (Art. 6(1)(b) GDPR) — We need to use your data to fulfil a contract with you or to take pre-contractual steps at your request.

Legal obligation (Art. 6(1)(c) GDPR) — We need to use your data to comply with a legal obligation.

Legitimate interests (Art. 6(1)(f) GDPR) — Processing your data is necessary to safeguard the legitimate interests of us or a third party, provided your own interests do not override them.

Please note: where your data is processed for the performance of a contract or due to a legal obligation, failure to provide the required data may mean we are unable to provide you with the Casebase application.

Your rights

To the extent your personal data is processed, you are a data subject within the meaning of the GDPR and have the following rights:

To exercise these rights, please contact us by email at privacy@alexanderthamm.com or in writing at the address of Alexander Thamm GmbH given above. We will process your request without delay and within one month of receipt.

1. Right of access (Art. 15 GDPR)
You may request confirmation as to whether personal data concerning you is being processed, as well as access to that data and information on the purposes, categories, recipients, storage period, and your existing rights.

2. Right to rectification (Art. 16 GDPR)
You have the right to request the immediate correction of inaccurate personal data or the completion of incomplete personal data concerning you.

3. Right to restriction of processing (Art. 18 GDPR)
Under certain conditions, you may request the restriction of the processing of your personal data, e.g. if you dispute the accuracy of the data or have objected to the processing.

4. Right to erasure — "right to be forgotten" (Art. 17 GDPR)
You may request the erasure of your personal data if it is no longer necessary for the purpose for which it was collected, if you withdraw your consent, or if the processing was unlawful.

5. Right to data portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.

6. Right to object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6(1)(e) or (f) GDPR.

7. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. A list of the competent supervisory authorities in Germany can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html

Data sharing and international data transfers

We use various service providers to operate the Casebase application and to protect your data. Where necessary, your personal data is shared with these providers on the basis of data processing agreements that obligate them to comply with data protection requirements.

Where personal data is transferred outside the EEA, we ensure an equivalent level of protection through appropriate safeguards — such as the European Commission's Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework, depending on the provider. On request, you may obtain a copy of the relevant Standard Contractual Clauses via the email address given in this privacy policy.

Note on residual risks of third-country transfers (in particular the USA): Despite the safeguards described above (SCCs, EU-US Data Privacy Framework), transfers of personal data to the USA carry residual risks. In particular, US authorities may, under certain legal provisions (e.g. FISA Section 702, Executive Order 12333), access data stored or processed in the USA, and data subjects in the EU may have only limited legal remedies available. We have assessed these risks and implemented appropriate contractual and technical measures to minimise them. By using the Casebase application, you acknowledge this residual risk. You may object to the relevant processing at any time by contacting privacy@alexanderthamm.com.

Provision of the app and creation of log files

1. Description and scope of data processing

Each time the Casebase application is accessed, our system automatically collects the following data:

  • Browser type and version
  • Operating system
  • Internet service provider
  • Date and time of access
  • IP address (pseudonymised after the end of the session)

2. Purpose of processing
Temporary storage of the IP address is necessary to deliver the application to your device. Log files are used to ensure the functionality of the application, to optimise it, and to secure our IT systems. No analysis for marketing purposes takes place.

3. Legal basis
Art. 6(1)(f) GDPR — legitimate interest in the technically error-free operation of the application.

4. Storage period
Log data is deleted after seven days at the latest. IP addresses are anonymised so that it is no longer possible to associate them with a particular client.

5. Exercising your rights
Collecting this data is technically required to operate the application. You may object; whether the objection is successful will be decided as part of a balancing of interests.

Hosting

The Casebase application is hosted exclusively on servers operated by Amazon Web Services (AWS) in Frankfurt, Germany (EU region). AT has entered into a data processing agreement with AWS pursuant to Art. 28 GDPR.

Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg
Further information: https://aws.amazon.com/privacy/

App registration

1. Description and scope of data processing

Users can register for the Casebase application by providing the following personal data:

  • First and last name
  • Email address
  • Password (stored encrypted)
  • Date and time of registration

2. Purpose of processing
Registration is required to fulfil the contract between AT and the customer and to grant the customer's users access to the application.

3. Legal basis
Art. 6(1)(b) GDPR — performance of a contract.

4. Storage period
Registration data is deleted once it is no longer required for the performance of the contract. Where statutory retention obligations apply — in particular under commercial or tax law — the data is retained for the legally required period (generally 6 to 10 years pursuant to § 257 HGB and § 147 AO) on the basis of Art. 6(1)(c) GDPR (legal obligation) and then deleted. Any further retention for internal purposes takes place on the basis of Art. 6(1)(f) GDPR (legitimate interest).

5. Objection and deletion
Users can update their personal data (name, email address, profile information) directly in their user profile within the Casebase application. Account deletion can be carried out by a workspace administrator within the application. Alternatively, users may contact their administrator or submit a deletion request directly to Alexander Thamm GmbH at customer_support@casebase.ai. Upon receipt of a verified request, Alexander Thamm GmbH will process the deletion within a reasonable period.

Data processing when using the Casebase app

1. Description and scope of data processing

The following data is processed when using the Casebase application:

  • Name and email address
  • Job title (optional)
  • Organisational information (company, department, role)
  • Usage and interaction data relating to the use of the application's features

2. Purpose of processing
User profile data is an essential part of the application, e.g. for assigning responsibilities and tracking content changes. Usage data is processed to detect errors, ensure stable operation, and further develop the application.

3. Legal basis
Art. 6(1)(b) GDPR for core profile data required for contract performance. Art. 6(1)(f) GDPR for usage and interaction data, based on AT's legitimate interest in providing a stable and continuously improved application.

4. Storage period
Data is deleted once it is no longer required for the purpose for which it was collected or once the contractual relationship ends. Where statutory retention obligations apply (e.g. under § 257 HGB or § 147 AO, generally 6 to 10 years), the data is retained for the legally required period on the basis of Art. 6(1)(c) GDPR (legal obligation) and then deleted. Any further retention for internal purposes takes place on the basis of Art. 6(1)(f) GDPR (legitimate interest).

5. Exercising your rights

For data processed by AT as controller: Users may object to the processing of their personal data or withdraw consent at any time by contacting their workspace administrator or submitting a request directly to Alexander Thamm GmbH at privacy@alexanderthamm.com. AT will process the objection within a reasonable period. Please note that objecting to the processing of data that is technically required to operate the Casebase application may mean the service can no longer be provided.

For data processed by AT as processor on behalf of a customer: End users should direct their requests to their employer (the customer), who acts as controller for this processing. Should you nevertheless contact AT, we will forward your request to the controller (your employer) without delay.

Use of cookies

1. Description and scope of data processing

Technically necessary cookies — required for the technical operation of the application. Without these cookies, the application cannot function properly. The following data is stored:

  • Login information / session token
  • User settings and application preferences
  • Frequency of page views and use of application features

Non-essential cookies — used to provide in-app guides, onboarding tours, and contextual user support via Pendo.io (see separate section). Usage data is also collected in pseudonymised form. The following data is processed:

  • IP address
  • Date and time of access
  • Pages accessed and features used (tracking of usage behaviour)

2. Purpose of processing
Technically necessary cookies ensure the application functions properly. Non-essential cookies are used to analyse user behaviour within the Casebase application, improve usability, detect and fix errors, and further develop and optimise the software. The data collected is used exclusively for these purposes and not for advertising or marketing purposes.

3. Legal basis
For technically necessary cookies: § 25(2) No. 2 TDDDG in conjunction with Art. 6(1)(b) GDPR (where strictly necessary for use of the service, e.g. login/session management) and/or Art. 6(1)(f) GDPR (legitimate interest in the secure and technically functional provision of the application, e.g. to comply with internal policies).

For non-essential cookies: § 25(1) TDDDG in conjunction with Art. 6(1)(f) GDPR — AT's legitimate interest in improving and further developing the application. The use of non-essential cookies by Pendo.io is governed by Section 5.4 of the Casebase Terms of Use, to which the customer agrees upon entering into the contract. You may object to this processing at any time by contacting privacy@alexanderthamm.com.

Overview of the cookies used and their legal bases:

  • Session cookie (login/authentication) — technically necessary — § 25(2) No. 2 TDDDG, Art. 6(1)(b) GDPR
  • CSRF token (security) — technically necessary — § 25(2) No. 2 TDDDG, Art. 6(1)(f) GDPR
  • Pendo.io cookie (in-app guidance and user support) — non-essential — § 25(1) TDDDG, Art. 6(1)(f) GDPR (legitimate interest, governed by Section 5.4 of the Terms of Use)

4. Exercising your rights
You can prevent the storage of cookies through the appropriate settings in your browser. Please note that this may affect the functionality of the application.

Location-based access restrictions (geo-blocking)

AT processes users' IP addresses to determine their approximate geographic location. This is done solely to restrict access to the Casebase application from certain countries or regions in accordance with applicable export control and sanctions regulations (pursuant to § 4.3 of the AT Terms of Use) and to ensure compliance with applicable trade restrictions and embargo requirements.

No precise location data is stored. The IP address is used solely for access control and is not used for profiling or advertising purposes. The IP address is deleted immediately after the access check and is not stored further.

Legal basis: Art. 6(1)(c) GDPR (compliance with legal obligations in the area of export control and sanctions law).

Content delivery network – Amazon CloudFront

1. Description and scope of data processing
We use the Amazon CloudFront content delivery network, provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. CloudFront delivers application content via a distributed server network and improves load times and security. When you access the application, a connection is established to CloudFront servers, which may process device and browser information (including IP address and operating system) in server log files. Further information: https://aws.amazon.com/privacy/

2. Purpose
Delivery and acceleration of the application and its content.

3. Legal basis
Art. 6(1)(f) GDPR — legitimate interest in the technically error-free and optimised delivery of the application.

4. Storage period
Data is stored for as long as necessary to fulfil the purposes described or as required by law.

5. Exercising your rights
Further information: https://aws.amazon.com/privacy/

App performance monitoring

1. Description and scope of data processing

We collect telemetry data to monitor, analyse, and optimise the performance and stability of the Casebase application. The following providers are used for this purpose:

  • Amazon CloudWatch (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg) — infrastructure and system monitoring
  • Sentry (see separate section) — error monitoring and crash reporting

2. Purpose
Infrastructure monitoring, application monitoring, resource optimisation, error resolution, and product improvement.

3. Legal basis
Art. 6(1)(f) GDPR — legitimate interest in ensuring the stable and secure operation of the application.

4. Storage period
Data is stored for as long as necessary to fulfil the purposes described or as required by law.

5. Exercising your rights
You may object to the processing of your data at any time by sending an email to the address given in this privacy policy.

Use of Sentry (error monitoring)

1. Description and scope of data processing

We use the error monitoring service Sentry, provided by Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Data processing takes place exclusively on EU servers. Sentry automatically captures technical errors and exceptions in the Casebase application. The following data may be processed:

  • Error messages and stack traces
  • IP address (anonymised)
  • Browser and operating system information
  • Pseudonymised user ID

2. Purpose
Early detection and resolution of technical errors to ensure the stability and security of the Casebase application.

3. Legal basis
Art. 6(1)(f) GDPR — AT's legitimate interest in technical quality assurance and the secure operation of Casebase. This legitimate interest lies in ensuring technically error-free, stable, and secure operation of the application and in protecting against misuse. The interests of affected users are adequately safeguarded through IP address anonymisation, pseudonymisation of user data, short retention periods, and the right to object. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Sentry.

4. Storage period
Data stored by Sentry is automatically deleted after a maximum of 90 days.

5. Further information
https://sentry.io/privacy/

Use of Pendo.io (product guidance and user support)

1. Description and scope of data processing

We use the product guidance platform Pendo.io, provided by Pendo.io, Inc., 150 Fayetteville St, Raleigh, NC 27601, USA. Pendo primarily provides in-app guides, onboarding tours, and contextual user support, and in doing so automatically collects pseudonymised usage data within the Casebase application. The following data may be processed:

  • Pages accessed and features used
  • Session duration and session information
  • Device and browser information
  • Pseudonymised user ID

Note on data transfer: Pendo.io, Inc. is based in the USA. The data transfer takes place on the basis of the EU-US Data Privacy Framework and/or the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Pendo.io.

2. Purpose
Provision of in-app guides and contextual user support (e.g. onboarding tours, feature hints, assistance), as well as collection of pseudonymised usage data to analyse application usage and support the continuous improvement of the software.

3. Legal basis
Art. 6(1)(f) GDPR — AT's legitimate interest in providing contextual user support (in-app guides, onboarding) and the continuous improvement and quality assurance of the Casebase application. Pendo.io primarily delivers in-app guides and onboarding tours that are necessary for end users to make effective use of the application, and in doing so collects usage data in pseudonymised form. The use of Pendo.io is governed by Section 5.4 of the Casebase Terms of Use, to which the customer agrees upon entering into the contract. The interests of affected users are adequately safeguarded through data pseudonymisation, a maximum storage period of 24 months, and the right to object. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Pendo.io. The transfer of data to the USA takes place on the basis of the EU-US Data Privacy Framework and the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.

4. Storage period
Usage data stored by Pendo.io is deleted after a maximum of 24 months. This retention period was deliberately chosen to enable meaningful trend analysis of usage behaviour while limiting the storage period of personal data.

5. Exercising your rights
You may object to processing by Pendo.io at any time by contacting privacy@alexanderthamm.com or your workspace administrator. Upon receipt of a verified objection, AT will activate the Pendo "Do Not Process" (DNP) setting for your account. Please note that disabling usage analytics may limit AT's ability to improve and maintain the service.

Further information: https://www.pendo.io/legal/privacy-policy/

Use of Software Development Kits (SDKs)

The Casebase application integrates the following third-party SDKs:

Sentry SDK
Provider: Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Purpose: Automated collection and analysis of technical errors to ensure the technical stability, reliability, and security of the Casebase application.
Data collected: Pseudonymised user ID, device information, error and usage data.
Privacy policy: https://sentry.io/privacy/

AWS SDK for Java
Provider: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg
Purpose: Communication with the AWS cloud infrastructure (hosting, database, storage, CDN) required to operate the Casebase application.
Privacy policy: https://aws.amazon.com/privacy/

Pendo.io JavaScript SDK
Provider: Pendo.io, Inc., 150 Fayetteville St, Raleigh, NC 27601, USA
Purpose: Provision of in-app guides, onboarding tours, and contextual user support; collection of pseudonymised usage data to support the continuous improvement of the software.
Privacy policy: https://www.pendo.io/legal/privacy-policy/

Legal basis for SDK use
The Sentry SDK and the AWS SDK for Java are technically required to provide the core services of the Casebase application; processing takes place on the basis of Art. 6(1)(f) GDPR (legitimate interests in stable and secure operation). The Pendo.io JavaScript SDK is primarily used to provide in-app guides and contextual user support and is used on the basis of AT's legitimate interest pursuant to Art. 6(1)(f) GDPR in conjunction with Section 5.4 of the Casebase Terms of Use, to which the customer agrees upon entering into the contract.

Contacting us by email

1. Description and scope
You can contact us using the email address provided within the application. Personal data submitted with your email is stored and used solely to process your request.

2. Legal basis
Art. 6(1)(f) GDPR — legitimate interest in responding to your request. Where the contact is aimed at concluding a contract, Art. 6(1)(b) GDPR also applies.

3. Storage period
Data is deleted once the matter has been conclusively resolved. Any additional data collected during transmission is deleted after seven days at the latest.

4. Exercising your rights
You may object to the storage of your personal data at any time by email. In that case, all personal data stored in connection with the contact will be deleted.

Automated decision-making and profiling

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place in connection with the Casebase application.

Withdrawal of consent and right to object

You may withdraw consent you have given at any time, with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected. Where processing is based on our legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. In that case, we will cease the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.

Changes to this privacy policy

We may update this privacy policy from time to time to reflect changes in our data processing practices, legal requirements, or the features of the Casebase application. The current version is available at any time within the Casebase application and on our website. In the event of material changes affecting your rights or the nature of the processing of your personal data, we will — where technically feasible — inform you in advance by email or via an in-app notification. The version date at the top of this privacy policy indicates when it was last updated. We recommend that you review this privacy policy regularly.

This privacy policy was created with the support of DataGuard.