CAI World FLEX | Privacy Policy
Privacy Policy for CAI® World FLEX
Status: August 2026
We appreciate your interest in the application CAI® World FLEX (hereinafter "App" or "Service"). Protecting your personal data and safeguarding your privacy is our highest priority. Below, we inform you in detail about the handling of your data when using CAI® World FLEX, particularly regarding its provision via the Microsoft Marketplace.
1. Name and Address of the Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is:
CAI GmbH
Erbprinzenstraße 4–12
76133 Karlsruhe
Germany
contact_mail Email: info@cai-world.com
contact_phone Phone: +49 721 / 161 18 46
fax Fax: +49 721 / 161 18 47
public Website: flex.cai-world.com (CAI® World FLEX) and www.cai-world.com (CAI GmbH)
2. Contact Details for Data Protection Enquiries
If you have any questions about data protection or exercising your data subject rights, please contact:
contact_mail Email: datenschutz@cai-world.com
3. Integration into Third-Party Platforms & Authentication (Single Sign-On / SSO)
When using CAI® World FLEX – whether via the web application, as an app, or integrated into third-party platforms (e.g. Microsoft Teams, Microsoft 365) – we process data required for the technical provision of the service as well as for secure user authentication.
To enable simple and seamless login, we offer you the use of various Single Sign-On (SSO) services. When using an SSO service, your CAI World FLEX account is linked to your existing account with the respective provider. In doing so, the provider transmits basic identity data to us for the creation and management of your user account.
Depending on the chosen provider, we process the following data:
- Microsoft Entra ID (formerly Azure AD):
Transmitted data includes name, email address, and technical identifiers (unique User ID and Tenant ID of your organisation). - Google Sign-In (Google Workspace / Google Account):
Transmitted data includes name, email address, profile picture (if shared), and a unique Google User ID. - Sign in with Apple:
Transmitted data includes name, email address (or an anonymised relay email address generated by Apple when using the "Hide My Email" feature), and a unique Apple User ID.
Purpose of processing:
Processing takes place exclusively for identity verification, login authentication, and the provision and administration of your user account in CAI® World FLEX.
Legal basis:
The legal basis for this data processing is Art. 6 (1) (b) GDPR (performance of a contract or steps prior to entering into a contract). If login occurs within an employment relationship or via an enterprise license, processing also serves to fulfill our contractual obligations toward your employer or licensee.
4. Scope and Purpose of Data Processing in CAI® World FLEX
4.1 Registration and Account Data (SaaS Licenses and Invited Users)
The creation and use of a user account in CAI® World FLEX varies depending on whether you purchase a license yourself or are invited by a licensee or session organizer:
- Holder of an Own SaaS License (Session Organizer):
In the context of setting up and using an own SaaS license, CAI® World FLEX processes master data of registered users and organisations.- Processed data: Name, email address, password (for local registration), organisation/company, assigned user groups, contact database, role and rights management, as well as administrative data for created sessions.
- Purpose: Provision of platform access, administration of contacts, groups, and online sessions.
- Invited Contacts and Session Participants:
Users who do not hold their own SaaS license can be created as contacts by a session organizer and invited to sessions. In order to participate in sessions or access shared documents, an optional personal user account can also be created.- Processed data: Name, email address, assignment to inviting persons/organisations, status of session invitations, and login credentials where applicable.
- Purpose: Provision of access to the respective sessions, assignment within the contact management of the inviting licensee, and use of the optional user account.
- Storage: All account and contact data are stored in our secure database for as long as the user account or assignment exists in the system.
- Legal basis: Art. 6 (1) (b) GDPR (performance of a contract or pre-contractual measures with the user) as well as Art. 6 (1) (f) GDPR (legitimate interest of the licensee in organising and conducting sessions with their contacts).
4.2 Session Content, Tools, and Chat Data (Online Meetings)
Interactive tools and communication features are deployed when conducting online sessions (meetings, coaching, and consulting sessions).
- Automatic Storage: All results generated during an online session using CAI tools (e.g. digital whiteboards, visual drawing canvases, task lists) as well as associated chat histories are automatically stored in the secure database of CAI® World FLEX during the session and for follow-up purposes.
- Purpose of Storage: Ensuring continuous work progress, safeguarding results, and providing records and working results exclusively to authorized session participants.
- Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) as well as Art. 6 (1) (f) GDPR (legitimate interest in uninterrupted and reliable session documentation).
4.3 Retention Schedule and Storage Duration
We store your personal data only for as long as necessary to achieve the respective purposes or as required by statutory retention periods.
| Data Category | Storage Modalities and Erasure Options |
|---|---|
| Session Content and Tool Results | Stored in the database. The session organizer has the right and technical capability to manually delete individual work tools as well as complete sessions including their content (results and chats) at any time. |
| Contacts and Groups | Remain in the database to enable management by the licensee. Contact data of invited individuals will be deleted as soon as the affected contact deletes their account or the associated SaaS license is terminated. The relationship to contacts is deleted as soon as the respective licensee removes them from their contact list. |
| Account and Profile Data (Licensees and Contacts) | Irrevocably deleted after the deletion of the respective user account (whether licensee or invited user) or upon expiration of statutory retention obligations (e.g. commercial or tax retention requirements). |
4.4 Data Recipients and Data Processors
Your personal data will only be passed on to third parties within the framework of statutory provisions or with your explicit consent.
- Hosting and Infrastructure: CAI® World FLEX is operated on secure servers within the European Union (EU). Data processing agreements (DPAs) pursuant to Art. 28 GDPR have been concluded with all technical service providers.
- No Sale of Data: We never sell or rent your personal data to third parties.
4.5 Data Processing via the CAI® World FLEX Website
4.5.1 Personal Data
"Personal data" refers not only to obvious personal information, such as a person's name or address, but also to the IP address and information about which pages a person has visited on the internet (user behavior).
Depending on the reason for processing, providing personal data may be required by law or contract, or necessary for concluding a contract. Where this is the case, we will indicate this below as well as the possible consequences of non-provision. Automated decision-making or profiling pursuant to Article 22 (1) and (4) GDPR will only occur if explicitly indicated. If you do not provide us with data in the outlined cases, you will not be able to use the service, feature, or contact option.
When accessing our website, information is generally stored on the end user's terminal equipment or information already stored on the terminal equipment is accessed. Both the storage of information on the end user's terminal equipment or access to information already stored on the terminal equipment, as well as the processing of this information, generally require consent pursuant to Section 25 (1) TDDDG (Telecommunications Digital Services Data Protection Act), unless an exception regulated in Section 25 (2) TDDDG applies. This is the case, for example, if the data or information is necessary to transmit a message or display the website and its content, as described under Section 4.5.4.
4.5.2 Cookies
The storage of information on terminal equipment or access to information already stored on terminal equipment may take place via cookies and other technologies. This information varies depending on the configuration settings of website visitors.
Cookies are small text files stored on your device by your browser. Cookies serve various functions. They may be technically essential to display our website, or serve to make our services more user-friendly and secure, analyze visitor browsing behavior, or provide personalized advertising.
As a user, you can control the use of cookies. By modifying your browser settings, you can disable or restrict the transmission of cookies. Stored cookies can be deleted at any time – including automatically.
However, if you disable cookies or do not consent to certain cookies, you may no longer be able to fully use all features of the websites you visit or various online tools.
A general distinction is made between first-party cookies (set by the website operator, see Section 4.5.4) and third-party cookies (placed when third-party services are integrated).
Third-party cookies are used to provide third parties with information about user behavior on specific websites. Where we use third-party services that employ cookies, we inform you below.
Furthermore, a distinction is made between session cookies and persistent cookies.
While session cookies are deleted as soon as the browser is closed, persistent cookies remain stored in the browser for a longer period and are partially deleted automatically upon reaching an expiration date.
In addition, under the relevant legal basis, we will generally indicate whether placing a cookie and using other technologies for individual functions or integrated services requires the website visitor's consent.
If personal data generated by setting and reading non-essential cookies is to be processed in a subsequent step, additional consent from the website visitor is required. In this respect, two consents must be obtained, which, according to the German Data Protection Conference (DSK), may occur in a single action.
We request required consents via a cookie banner when you visit our website. We use the following software to manage consents:
CookieConsent - v2.8.8
GitHub Link: https://www.github.com/orestbida/cookieconsent
Author: Orest Bida
Released under the MIT License
In some cases, we integrate services and tools from service providers based in a third country outside the European Union (EU) or processing data on servers in third countries, particularly the USA.
These service providers regularly use cookies and other technologies that are generally non-essential when providing their services. This may result in data of our website visitors being processed by these providers.
To ensure maximum protection for your data, we have concluded EU Standard Contractual Clauses guaranteeing an adequate level of data protection as well as additional safeguards with these providers.
Nevertheless, it cannot be ruled out that, as in the USA, intelligence services or state authorities may access your data under national laws without notification.
In some cases, we use external service providers (data processors pursuant to Art. 28 GDPR, e.g. hosting providers) to process your data. They are carefully selected and commissioned, bound by our instructions, and monitored regularly. Data disclosure to other recipients otherwise only occurs if specified below.
4.5.3 Contacting Us - General
When you contact us (e.g. by email or fax), we process the data provided by you, such as your name, email address, and any additional contact details supplied.
| Purpose of processing: | Processing the aforementioned data is necessary to process and respond to your inquiry submitted via contact. |
| Legal basis: | Data processing may be based on various legal bases depending on the request. In any case, processing is necessary to safeguard our legitimate interests pursuant to Art. 6 (1) (f) GDPR. The legitimate interest arises from pursuing your request and fulfilling the purpose of processing. |
| Storage duration: | We will delete your personal data as soon as storage is no longer necessary. The exact timeframe is determined case-by-case, ending at the latest upon expiration of civil limitation periods or statutory criminal prosecution limits. |
4.5.4 Data Processing via Website
Encryption
To ensure your personal data is protected against unauthorized or unlawful processing as well as accidental loss, destruction, or damage, we employ SSL/TLS encryption across our entire website and subpages.
Visiting Our Website
Every time our website is accessed, our system automatically collects data and information from the computer system of the calling device. The following data is collected:
- Name of retrieved file
- Date and time of access
- Transferred data volume
- Notification of successful access
- IP address
- Browser type
- Browser version and language
- Operating system and interface
- Referrer URL
- Access status/HTTP status code
- Device type
Data is stored in log files of software installed on an IT system operated by our host provider.
| Purpose of processing | Processing of the above data is necessary to display the website and ensure the security and stability of our IT systems and website infrastructure. Processing also serves to provide law enforcement agencies with necessary information in the event of a cyberattack. |
| Legal basis | We have a legitimate interest pursuant to Art. 6 (1) (f) GDPR based on the specified purpose. Consent pursuant to Section 25 (2) TDDDG is not required. |
| Storage duration | Data is deleted as soon as storage no longer serves its purpose. The exact timeframe is determined case-by-case, ending at the latest upon expiration of civil limitation periods or statutory criminal prosecution limits. |
Our Cookies (First-Party Cookies)
We deploy session and persistent cookies.
For details on cookie functions and how to prevent cookie placement in general, please refer to Section 4.5.2.
Essential Cookies:
Session cookies store the following data:
- Cookie "JSESSIONID"
Assigns an anonymized ID (session ID) to your browser for the duration of your visit to group related server requests into a session. - Cookie "LFR_SESSION_STATE^"
Date information used to manage session expiration notifications. - Cookie "COMPANY_ID"
Used internally by the Liferay framework. - Cookie "ID"
Used to maintain the session when a user returns to the portal after closing the browser.
Persistent cookies store the following data:
- Cookie "GUEST_LANGUAGE_ID"
Language selection - Cookie "COOKIE_SUPPORT"
Indicates whether cookies are supported for additional functions. - Cookie "PRIVACY_READ"
Indicates that you agree to cookie usage on our pages. Set when confirming the cookie notice with OK. When present, the notice is hidden. - Cookie "COMPANY_ID"
Used internally by the Liferay framework. - Cookie "ID"
Maintains the user session upon return after browser closure. - Cookies "LOGIN", "PASSWORD", "REMEMBER_ME", "SCREEN_NAME"
Enable automatic login via the "Save login data" option in the login dialog.
Non-Essential Cookies:
Persistent cookies store the following data:
- Cookie "audioEnabled"
Automatic microphone activation when switching between breakout sessions. - Cookie "videoEnabled"
Automatic camera activation when switching between breakout sessions.
Cookies that are strictly necessary do not require consent and are set automatically.
| Purpose of processing: | Cookies enable us to recognize your browser on your next visit. We use cookies to provide the service, analyze user browsing behavior, and enhance user-friendliness. |
| Legal basis: | If setting cookies and processing data serves to analyze user behavior (tracking) or is not essential to provide the requested service, we obtain consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. For essential cookies, processing relies on Art. 6 (1) (f) GDPR based on our legitimate interest in fulfilling the processing purpose. |
| Storage duration: | Session cookies are deleted automatically when you leave. Persistent cookies remain stored for a specific period (generally one year) or until you delete them. |
4.5.5 Contacting Us - Contact Form
When contacting us via contact form, the data entered in the form mask is transmitted and stored. When submitting the contact form, the following additional data is stored at the time of sending:
- IP address
- Date and time
- Name of retrieved file
- Notification of successful retrieval
- Browser type
- Browser version and language
- Operating system and interface
| Purpose of processing: | Processing personal data from the input mask serves solely to handle your inquiry. Additional data processed upon submission prevents contact form misuse and ensures IT system security. |
| Legal basis: | Consent is obtained prior to submission with reference to this Privacy Policy. The legal basis is Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. |
| Storage duration: | Data is deleted as soon as storage no longer serves its purpose. The exact timeframe is determined case-by-case, ending at the latest upon expiration of civil limitation periods or statutory criminal prosecution limits. |
4.5.6 Registration on the Website
You may register/login on our website by providing personal data. The transmitted personal data results from the input mask used for registration/login. Registration/login also stores your IP address as well as date and time. Furthermore, we store the following data:
- Notification of successful access
- Browser type
- Browser version and language
- Operating system and interface
- Referrer URL
- Access status/HTTP status code
- Device type
| Purpose of processing: | Data provided during registration is required to provide the requested service and verify your authorization as a registered user. Additional data is stored to prevent service abuse and enable legal action if necessary. Processing may also serve to fulfill contractual obligations. |
| Legal basis: | Legal basis based on consent is Art. 6 (1) (a) GDPR and Section 25 (2) TDDDG. Legal basis may also derive from Art. 6 (1) (b) GDPR. |
| Storage duration: | We will delete your personal data as soon as storage is no longer necessary. The exact timeframe is determined case-by-case, ending at the latest upon expiration of civil limitation periods or statutory criminal prosecution limits. |
5. Data Processing Security
We implement appropriate technical and organizational security measures (TOMs) pursuant to Art. 32 GDPR to protect your personal data against accidental or intentional manipulation, partial or total loss, destruction, or unauthorized third-party access. Our security measures are continuously upgraded in line with technological developments.
6. Information on Data Subject Rights
As a data subject whose personal data is processed, you hold the following rights under the GDPR against us (referred to below as the "Controller"):
- Right of access, Art. 15 GDPR
You have the right to request confirmation from the controller as to whether personal data concerning you is being processed. If so, you have the right to access the information listed in Art. 15 GDPR.
- Right to rectification, Art. 16 GDPR
Pursuant to Art. 16 GDPR, you have the right to obtain from the controller without undue delay the rectification or completion of inaccurate or incomplete personal data concerning you.
- Right to erasure ("Right to be forgotten"), Art. 17 GDPR
Under Art. 17 GDPR, you have the right to request from the controller the immediate erasure of personal data concerning you.
- Right to restriction of processing, Art. 18 GDPR
As a data subject, you have the right under Art. 18 GDPR to request the controller to restrict processing.
- Right to notification, Art. 19 GDPR
Under Art. 19 GDPR, you have the right to be informed of recipients to whom your personal data was disclosed following your exercise of rights to rectification, erasure, or restriction of processing.
- Right to data portability, Art. 20 GDPR
Under Art. 20 GDPR, you have the right to receive personal data concerning you in a structured, commonly used, and machine-readable format and transmit it to another controller.
- Right to object, Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to data processing based on Art. 6 (1) (e) or (f) GDPR. Where data is processed for direct marketing purposes, you have the right to object at any time.
- Right not to be subject to automated decision-making, Art. 22 GDPR
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you.
- Right to withdraw consent, Art. 7 (3) GDPR
You have the right to withdraw your data protection consent at any time with future effect.
- Right to lodge a complaint with a supervisory authority, Art. 77 GDPR
Without prejudice to any other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.
7. Changes to this Privacy Policy
We reserve the right to amend this privacy policy to ensure that it always complies with current legal requirements or to reflect changes to our services (e.g. when introducing new features in the Microsoft Marketplace) in the privacy policy. The current privacy policy applies to your next visit.