Privacy Notice

Which personal data PflichtPilot processes, for which purposes — and which rights you have as a data subject.

As of: July 17, 2026

Summary

This privacy notice explains which personal data PflichtPilot processes, for which purposes this is done, and which rights you have as a data subject. PflichtPilot allows creating and documenting obligations and uploading record files.

1. Controller

Andreas Fetscher

Sauggarter Str. 33

88524 Uttenweiler

Germany

2. Processing purposes and legal bases

PflichtPilot processes personal data to provide the application, in particular for account operation, creating and managing obligations, record uploads, and sending required emails (for example login links).

Typical legal bases are Art. 6(1)(b) GDPR (contract performance / pre-contractual steps) and Art. 6(1)(f) GDPR (legitimate interests, for example operation and service security). To a limited extent, PflichtPilot may contact registered users once by email to request feedback on service quality and product improvement; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving the service). You may object to such contact at any time. Separate consent is requested where required.

3. Categories of personal data

Account data
Email address, login session token, and profile information (for example Pro status).
Obligations
Title, description, due date, risk, archive marker, and related metadata.
Record uploads
Uploaded files (photos, PDFs, screenshots), file name, upload timestamp, and optional metadata entered by the user.
Log data
Connection data (for example IP address), timestamps, and user agent for security and analysis purposes in pseudonymized form.
Payment-related data
Only where required: payment confirmations and transaction references handled by your payment provider. PflichtPilot does not store complete card data.

4. Technical service providers / processors

PflichtPilot uses technical service providers to operate the service. Current partners include:

Supabase
Database, authentication, and object storage (files). Provider: Supabase, Inc. (USA). Application data is hosted in the EU region Frankfurt am Main (AWS eu-central-1). Supabase is engaged as a processor under Art. 28 GDPR on the basis of the Supabase Data Processing Addendum (supabase.com/legal/dpa). Insofar as support or administrative access involves transfers to third countries (in particular the USA), Supabase relies on EU Standard Contractual Clauses (SCC) under Art. 46 GDPR.
Brevo (Sendinblue SAS)
Delivery of login magic-links, transactional system emails (account confirmation, notices), and the evidence-package template. Provider: Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France. Only the fields required for delivery (email address, language, occasion) are transmitted. Legal basis: Art. 6 (1) (b) GDPR (contract / pre-contractual measures) or (f) (legitimate interest in a reliable login flow). Data processing agreement under Art. 28 GDPR. Brevo privacy policy: brevo.com/legal/privacypolicy.
Hosting provider (Netcup)
The public website is hosted by netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe, Germany). Technical access data (IP address, timestamp, requested resource, user agent) may be recorded in server logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in availability and security). Data processing agreement under Art. 28 GDPR. Netcup privacy policy: netcup.com/en/contact/data-protection-statement.
Cloudflare
PflichtPilot uses services provided by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) as a CDN (Content Delivery Network), DDoS protection layer, and reverse proxy. Technical access data (in particular IP address, HTTP headers, timestamps) may be processed by Cloudflare before requests reach the hosting server. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the availability and security of the service). For transfers to the USA, Cloudflare relies on Standard Contractual Clauses (SCC) under Art. 46 GDPR. Cloudflare privacy policy: cloudflare.com/privacypolicy.
Stripe (payment processing)
For processing paid subscriptions and one-time payments, PflichtPilot uses Stripe Payments Europe, Limited (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When you purchase a paid plan, your payment data (card information, bank details, name, billing address, VAT-ID if applicable, email) is transmitted directly to Stripe and processed there. Legal basis is Art. 6(1)(b) GDPR (contract execution) and Art. 6(1)(f) GDPR (fraud prevention). Stripe acts as an independent controller for payment processing; PflichtPilot only receives status information from Stripe (payment success/failure, subscription status). For data transfers outside the EU, Stripe relies on Standard Contractual Clauses (SCC) under Art. 46 GDPR. Stripe privacy policy: stripe.com/en/privacy.

Data processing agreements according to Art. 28 GDPR are in place with processors where required.

5. Storage, deletion, and protection

Personal data is stored only as long as necessary for stated purposes or required by legal retention periods. Uploaded files are stored in object storage. Once attached, individual evidence entries cannot be deleted one by one during normal operation — this protects the integrity of the documentation chain. Full account deletion removes your application data including uploaded files; in rare technical edge cases a follow-up cleanup may be required. Your statutory right to erasure under Art. 17 GDPR remains unaffected and can be exercised at any time via account deletion or the privacy contact.

Regular backups are created. Backup copies may be retained for a limited period for restoration purposes.

5a. Retention overview

The table below summarises storage duration per data category. The specific purpose and legal basis described in section 5 prevail in individual cases; the table serves as orientation.

Data category Purpose Legal basis Storage duration
Account base data (email, login identity, profile) Login, performance of contract Art. 6 (1) (b) GDPR until account deletion; afterwards a follow-up period of up to 30 days for technical cleanup
Obligations and iterations (content data) Product use, structuring the evidence file Art. 6 (1) (b) GDPR; for B2B use possibly processing on behalf under Art. 28 until account deletion or customer instruction
Uploaded record files Product use, evidence structure For B2B use typically Art. 28 GDPR (processing on behalf) until deletion by user or account deletion
Verify and export metadata (manifest hash, snapshot timestamp, verify-code hash) Technical reconciliation of export artifacts Contract (Art. 6 (1) (b)) or legitimate interest (Art. 6 (1) (f)); for B2B on behalf as long as subscription and export structure are active; after account deletion, cleanup as with other content data
Payment and invoice data Billing, statutory commercial and tax obligations Art. 6 (1) (b) and (c) GDPR in conjunction with §§ 257 HGB, 147 AO statutory retention (typically 10 years)
Security and access logs Operational security, abuse detection Art. 6 (1) (f) GDPR (legitimate interest) up to 90 days, then deletion or anonymisation
Database and storage backups Restoration in the event of an incident Art. 6 (1) (f) GDPR (legitimate interest) or contract (b) rolling backup TTL up to 30 days; deleted data is cleaned up with the backup rotation
Technical login and payment helper data Security of the login flow; reliable booking of payment events without duplicate triggers Art. 6 (1) (b) GDPR (contract) or (f) (legitimate interest in operational security) Login-link codes (with companion data: request IP, user-agent, language; for abuse correlation and forensics): up to 30 days past expiry, then deletion. Stripe payment-event data: up to 90 days in full form, then reduced to a compact reference (event ID and timestamp) retained for the duplicate-detection requirement. Both cleanups run daily via an automated database job (03:00 UTC).
Internal audit log (action history for obligations and evidence) Traceability and integrity of documentation chains, abuse detection Art. 6 (1) (f) GDPR (legitimate interest) permanent. The log currently persists after account deletion: the user identifier loses its personal reference when the account is deleted, but details contained in log metadata (e.g. self-assigned obligation titles) may remain. Automatic redaction of this metadata on account deletion is in preparation.
Marketing / waitlist requests (evidence-package template, Pro-Team waitlist) Contact within the requested context, invitation at product launch Art. 6 (1) (b) GDPR (pre-contractual measures) or (a) (consent) Evidence-package template requests: up to 12 months, then deletion or anonymisation; Pro-Team waitlist: until Pro-Team launch and invitation sent, then deletion within 30 days or earlier on withdrawal

Statutory rights of deletion, restriction, and objection under Art. 15 ff. GDPR remain unaffected. The product's "archiving" logic applies only within an active account and does not restrict these rights.

5b. “Archiving” in the product — no restriction of GDPR rights

Archiving in the product means: within an active account, completed obligation iterations are not hidden but kept visible as part of the history. This way, existing records, gaps, and timestamps remain traceable. It is purely product and display logic — not a legal or revision-safe archive in the sense of separate trust services.

Statutory rights of deletion, restriction, and objection under the GDPR remain unaffected. When an account is deleted we delete or anonymise personal application data according to our deletion logic (see section 5a). Data we need to retain for statutory reasons, billing, security, or legal defence is stored only for the period required in each case.

Before deleting an account, users should export their records. After deletion the hosted evidence structure, including verify links, cannot be restored.

5c. External payment master data on account deletion (Stripe)

When an account is deleted, the connection to the payment provider Stripe is dissolved alongside the cleanup of application data: an active subscription is first cancelled and the customer object held in Stripe (Customer ID) is then deleted via the Stripe API. Both steps run as best-effort within the same deletion operation; the outcome of each sub-step is logged.

Stripe itself, as an independent payment service provider, is subject to statutory retention requirements. Invoices already issued and the related payment master data remain stored with Stripe for the legally mandated period (typically ten years under § 147 AO; legal basis Art. 6 (1) (c) GDPR). This retention lies outside PflichtPilot's sphere of influence and is part of the contractual relationship between Stripe and the customer regarding payment processing.

If the customer deletion at Stripe is technically not possible (for example with an open balance or a temporary API error), the event is recorded in the deletion log. The link between the PflichtPilot account and the Stripe customer is removed locally in that case; the master data at Stripe can be removed on request directly via Stripe's customer portal or Stripe support.

6. Cookies, local storage, and reach measurement

PflichtPilot does not set cookies. To operate the application, technically required information is stored in your browser's local storage (localStorage): the login session token (pp_access_token) and your color-scheme (theme) and language preferences. This storage is strictly necessary to provide the service you explicitly requested and is therefore exempt from consent under § 25 (2) no. 2 of the German TDDDG; no consent prompt (cookie banner) is required.

For anonymous reach measurement on public pages (marketing, knowledge articles, pricing, roadmap, manifest, and the legal pages — imprint, terms, and this privacy notice) we use Plausible Analytics — a privacy-friendly, EU-hosted analytics solution that sets no cookies, collects no personal data, and stores no device identifiers. Only aggregated metrics (page views, referrer, country, browser type) are recorded, with no link back to individuals. No consent banner is required under § 25 (2) no. 2 TDDDG. Provider: Plausible Insights OÜ, Tallinn, Estonia (data policy). Reach measurement is not performed inside the app area (/app/).

7. Security

Technical and organizational measures are applied to protect personal data against accidental loss, unauthorized access, and misuse. These include access restrictions, encrypted transmission (TLS), and limited access rights.

8. Your rights

You have rights of access, rectification, deletion, restriction of processing, and data portability. You may revoke consent at any time.

Right to object under Art. 21 GDPR: Where we process personal data on the basis of Art. 6 (1) (f) GDPR (legitimate interest), you have the right to object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.

You also have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for the provider is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI, State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany, baden-wuerttemberg.datenschutz.de. You may also contact the supervisory authority of your habitual residence or place of work.

To exercise your rights, please contact the privacy contact below.

9. Contact

For privacy questions, please contact:

[email protected]