Privacy Policy
Version 1.0
Preamble
In this privacy policy, we inform you about which personal data we process in connection with the use of the "ProfitPilot" web app, for what purposes this is done and on what legal grounds the processing is based. You will also receive information about the recipients of the data, any data transfers to third countries and your rights as a data subject.
"ProfitPilot" is a SaaS tool for economic project, order and profitability calculations for freelancers, the self-employed, small agencies and other service providers.
Data controller and contact
Data controller within the meaning of the General Data Protection Regulation (GDPR):
Christina Junkmann
Albert-Roßhaupter-Straße 25
81369 Munich (Germany)
Email: info@profit-pilot.eu
Website: https://profit-pilot.eu
No company data protection officer has been appointed.
For data protection enquiries, you may use the following contact details in particular: Email: info@profit-pilot.eu
Scope and user group
This privacy policy applies to:
- the website at the domain profit-pilot.eu and
- the SaaS web app "ProfitPilot" accessible via this website, which is used for economic project and order costing, post-project costing, risk analysis and the preparation of profitability forecasts.
The application is primarily aimed at:
- business customers (B2B),
- freelancers and the self-employed.
There are different user roles within the app (e.g. admin and standard user). Assignment to a role determines the respective access and editing rights. Information on the scope of functions, pricing and contractual provisions can be found in the relevant terms and conditions and service descriptions on the website.
General purposes and legal bases for processing
Overview
We process personal data in particular for the following purposes:
- Provision and operation of the website and SaaS app (including registration, login, user management)
- Execution and administration of user agreements (SaaS service for cost-effective project calculation and analysis)
- Storage and management of projects, quotations, calculations, time, cost and revenue data
- Preparation of profitability forecasts, margin and target price calculations, and risk analyses
- Payment processing (Stripe)
- Communication and support (e.g. for enquiries, errors, feedback)
- Ensuring security, stability and error analysis (including via server and application logs)
- Usage analysis and product improvement (including via Google Search Console)
Processing is carried out – depending on the operation – on the following legal bases:
- Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR), insofar as processing is necessary for the use of ProfitPilot (in particular account creation, login, core app functions, payment processing).
- Compliance with legal obligations (Art. 6(1)(c) GDPR), in particular commercial and tax law retention obligations in connection with billing and contract data.
- Legitimate interests (Art. 6(1)(f) GDPR), in particular when processing usage and technical data to ensure IT security, for error analysis and to improve our service (including analytics via Google Search Console).
We do not currently use any features that rely on consent within the meaning of Article 6(1)(a) of the GDPR or Article 7 of the GDPR. In particular, we do not use marketing or advertising cookies for tracking purposes, nor do we pass on any personal data to advertising networks.
For clarity, the main categories of data can be assigned to the following legal bases:
- Registration, account and contract data (e.g. name, email address, login details, tariff information): Article 6(1)(b) GDPR.
- Business and content data processed in the app (e.g. project, order, customer and calculation data): Article 6(1)(b) GDPR; with regard to the third parties concerned (e.g. your customers/employees), this is generally carried out within the framework of data processing on behalf of a controller pursuant to Article 28 GDPR.
- Payment and billing data (e.g. invoice information, payment status): Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.
- Usage, log and system data (e.g. IP address, access times, error/crash logs): Article 6(1)(f) GDPR.
- Communication data (e.g. support enquiries, email correspondence): Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
No tax or business advice, no automated individual decision-making
The calculations, analyses and recommendations provided by ProfitPilot are intended solely for the internal calculation and organisation of your projects and business processes. They do not constitute tax, legal or business advice and are no substitute for individual advice from tax advisers or other specialists.
No decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22(1) of the GDPR) are made in the context of using ProfitPilot.
ProfitPilot does not currently use any AI-supported profiling procedures in which comprehensive personality or behavioural profiles of individual users are created automatically. Should we introduce AI functions in the future that carry out independent assessments or classifications of individuals, we will provide separate information on this and – where necessary – obtain explicit consent in accordance with Article 6(1)(a) and Article 7 of the GDPR.
No use for advertising purposes / no disclosure to advertising networks
Your data will not be sold for the purpose of direct marketing on behalf of third parties or passed on to advertising networks or other marketing platforms. No retargeting or remarketing services and no tracking technologies are used for advertising purposes.
We do not use your data processed in ProfitPilot to create individual marketing profiles about you or to display personalised third-party advertising to you on this basis. The use of usage data for our own marketing purposes is limited – insofar as this is permissible under Article 6(1)(f) of the GDPR – to general information about our services (e.g. notifications of new features), without any detailed analysis of your individual usage behaviour. Similarly, we do not carry out profiling within the meaning of Article 4(4) of the GDPR for marketing or advertising purposes.
Special categories of personal data and minors
The app is not intended to process special categories of personal data within the meaning of Article 9 of the GDPR (e.g. health data, data on religious affiliation, trade union membership, biometric data) or data relating to criminal convictions and offences within the meaning of Article 10 of the GDPR. Such input is not required within the scope of the intended use.
The use of ProfitPilot is not intended for children or minors. Data relating to children shall not be processed (Article 8 of the GDPR).
Product development, statistics and anonymised analyses
We reserve the right to compile anonymised or aggregated analyses from the data generated during the use of ProfitPilot (e.g. statistics on average usage intensity, success rates for specific types of functions, and general performance indicators that do not relate to specific individuals). Such analyses do not contain any information that allows conclusions to be drawn about individual persons or specific customer relationships. They serve exclusively to further develop and optimise our product, as well as to produce general market and usage analyses. The legal basis is our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Where possible, processing is carried out without personal reference (e.g. aggregation, anonymisation).
Visits to our website / web app (without logging in)
Server log files and technical access data
Data collected
When you visit our website or web app, certain technical data is processed automatically, including:
- IP address,
- Date and time of access,
- Pages/files accessed,
- Amount of data transferred,
- browser type and operating system,
- referrer URL (if applicable).
Purposes of processing
- Display and provision of the website/web app,
- Ensuring functionality, stability and security (e.g. to defend against attacks),
- technical error analysis and improvement of the service.
Legal basis
The processing of this access data is based on our legitimate interest in the secure, stable and technically error-free provision of our website and web app (Art. 6(1)(f) GDPR).
Retention period
Server log data is generally stored for between 7 and 30 days and is subsequently deleted or anonymised, unless longer retention is required in individual cases (e.g. to investigate security incidents).
Technically necessary cookies and similar technologies
We use technically necessary cookies and/or similar technologies (e.g. local storage, session storage) in the web app to:
- enable logins and sessions,
- ensure security (e.g. protection against CSRF attacks),
- provide basic app functions and save user settings.
Insofar as this involves accessing information already stored on your device or storing information on your device, this is done exclusively to the extent that it is technically essential for the provision of a telemedia service expressly requested by you. The legal basis for this access is Section 25(2)(2) of the German Telemedia Act (TDDG).
The subsequent processing of personal data is based – depending on the purpose – on Article 6(1)(b) of the GDPR (performance of a contract, e.g. login, session management) or Article 6(1)(f) of the GDPR (legitimate interest in a technically functional and secure online service).
Registration and user account
Registration of a user account is required to use the SaaS app.
Data processed
During registration and in the course of account use, we process in particular:
- Email address,
- username,
- Password (stored only in hashed form),
- Profile data and settings (e.g. language, configuration),
- account status, subscribed tariff or contract model.
Purposes
- Set-up, management and use of the user account,
- Authentication upon login,
- Assigning your activities in the app to your account,
- Management of contractual relationships (e.g. freemium model, subscriptions, where applicable ‘lifetime’ models and permanent premium activations).
Legal basis
The legal basis is the necessity for the performance of the user agreement regarding the use of the SaaS app (Art. 6(1)(b) GDPR).
Retention period
The data is stored for the duration of the active user account. Following the deletion of the account or termination of the contractual relationship, personal data is generally deleted within 30 days or – where required by law – stored in separate systems for the duration of the statutory retention obligations (e.g. invoice data), cf. Art. 6(1)(c) GDPR.
Use of the SaaS app (projects, calculations, content)
Data processed
When using ProfitPilot, the following personal data, amongst other things, may be processed:
- project data, quotation data, order data and internal designations,
- customer and order data (e.g. customer names, contact details where applicable),
- invoice and billing data (e.g. amounts, items),
- turnover data, cost and time recording data, employee hourly rates,
- other business-related data that you store in the system,
- uploaded content/documents containing personal data (e.g. files, spreadsheets).
This data may relate to your own employees, your customers, end customers and other business partners.
Purposes
- Carrying out project, order and quotation calculations,
- carrying out profitability, margin and economic viability analyses,
- Post-calculation, risk analysis and assessment of the economic viability of orders,
- Documentation of your projects and business processes.
Legal basis
With regard to you as a user (customer), this data is processed for the purpose of fulfilling the user agreement (Art. 6(1)(b) GDPR).
Responsibility for content
You are personally responsible for all content that you enter or upload to the app. In particular, you must not store any unlawful content, infringe the rights of third parties, or enter any special categories of personal data (Art. 9 GDPR) or data relating to children (Art. 8 GDPR), unless this is strictly necessary and legally permissible.
With regard to the allocation of roles under data protection law, the following applies in summary: We are the data controller in relation to your own registration, account and usage data, as well as our communication with you. Insofar as you process personal data of third parties (e.g. your customers or employees) via ProfitPilot, you are the data controller for this. We act as a data processor in this respect. The details are set out in Section 14 of this Privacy Policy.
Logging of activities
To ensure traceability and security, certain actions within the app (e.g. creating, modifying or deleting projects, orders or user accounts, in particular by administrators) may be logged. These logs are used to safeguard the integrity of the system, for error analysis and to assist with support and compliance enquiries, Art. 6(1)(f) GDPR.
Optional features: Company location and calendar integration
Company location
You may optionally provide your company’s location data (e.g. address, region) to enable certain analyses and visualisations (e.g. regional analyses). Processing in this context is based on the performance of a contract (Art. 6(1)(b) GDPR), insofar as the feature forms part of the service, or on your legitimate interest in optimised use of the app (Art. 6(1)(f) GDPR). This information is provided on a voluntary basis. The app can generally be used without providing this information.
Calendar integration
ProfitPilot can optionally be connected to an external calendar. The following principles apply:
- ProfitPilot retrieves only information from the connected calendar regarding whether specific time slots are ‘free’ or ‘booked’;
- The content of appointments (title, description, attendees, notes, etc.) is not retrieved;
- Access is granted within the scope of the permissions you have granted (e.g. via the calendar API).
The legal basis for access is – depending on the implementation – the performance of a contract (Art. 6(1)(b) GDPR) or your consent/authorisation to the calendar provider (Art. 6(1)(a) GDPR). Use of this integration is voluntary. You can also use ProfitPilot without a calendar connection. You may revoke any consents given to the calendar provider at any time with future effect (Art. 7(3) GDPR).
Communication and Support
General contact
When you contact us (e.g. by email or via support functions provided in the app), we process:
- your contact details (e.g. email address),
- the content of your enquiry (including any personal data it may contain),
- communication metadata (e.g. time, technical parameters).
The data is processed for the purpose of handling your enquiry and for further communication with you. The legal basis is – depending on the context – Article 6(1)(b) of the GDPR (where the enquiry relates to an existing or proposed contractual relationship) or Article 6(1)(f) of the GDPR (legitimate interest in processing other enquiries). The data will be deleted as soon as it is no longer required for processing, subject to statutory retention obligations (Article 6(1)(c) of the GDPR).
Data protection enquiries and support regarding data subjects’ rights
You may address data protection-related enquiries (e.g. access, erasure, rectification) in particular to info@profit-pilot.eu .
In our role as a data processor, we assist our business customers – upon request – in handling data subjects’ rights (access, erasure, rectification) in relation to data stored in the app (e.g. your end customers).
Payment processing with Stripe
We use the payment service provider Stripe for paid plans and the processing of payments.
Data processed and recipients
The following data, among others, is processed as part of payment processing:
- Contract and billing data (e.g. subscribed plan, payment amount, billing periods),
- payment information (e.g. card/account details, payment tokens, transaction IDs),
- technical data relating to the payment (e.g. IP address, browser data).
The recipient of this data is Stripe, which regularly also engages companies based in third countries (in particular the USA) (Art. 44 et seq. GDPR). Stripe also processes certain data under its own responsibility (e.g. for payment processing, fraud prevention).
Purpose and legal basis
The purpose is to process the payments you have initiated, manage subscriptions and document payment and billing transactions, as well as to comply with statutory retention obligations. The legal basis is Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(c) of the GDPR (statutory retention obligations).
Use of external service providers and data transfers to third countries
Hosting / Infrastructure (Base44)
ProfitPilot is operated via cloud infrastructure in the USA. In particular, Base44 is used as the hosting and infrastructure provider. The processing includes, amongst other things, the storage and processing of application, user and log data. The purpose of these services is to provide a scalable, high-performance technical infrastructure for the web app.
The legal basis for the use of these service providers is Article 6(1)(b) of the GDPR (provision of the contractually agreed SaaS service) and our legitimate interest in a high-performance, scalable technical infrastructure (Article 6(1)(f) of the GDPR). For further details, please refer to Section 10.6.
Email service provider (Resend)
We use the service provider Resend to send certain emails (e.g. registration confirmations, system-related notifications, support messages). In doing so, we process, among other things, your email address, metadata relating to the dispatch, and email content or templates. Processing is carried out on the basis of Article 6(1)(b) of the GDPR (e.g. sending contract-related information) or Article 6(1)(f) of the GDPR (legitimate interest in efficient communication). Where Resend transfers data to third countries, Section 10.6 applies.
Error and stability analysis (internal logs)
We use internal server and application logs to detect and analyse errors and stability issues. In particular, we process technical information (e.g. browser type, operating system), IP address or truncated IP address, timestamps and the context of error messages. The legal basis is our legitimate interest in a stable, secure system (Article 6(1)(f) of the GDPR).
Analysis of website discoverability
We use Google Search Console to analyse the discoverability and performance of the website in search engines (e.g. search queries, click counts, technical status messages). The purpose is to improve user-friendliness and optimise our offering. The legal basis is our legitimate interest pursuant to Article 6(1)(f) of the GDPR.
Third-party content: Maps (OpenStreetMap / OpenMaps)
The application may incorporate map services (e.g. OpenMaps / OpenStreetMap), for example to display location-based information. When such maps are accessed, the provider may process technical access data (e.g. IP address and browser data). The legal basis for this integration is our legitimate interest in the user-friendly display of location information (Art. 6(1)(f) GDPR). Insofar as information on the end device is accessed in this context, this is done only to the extent that it is technically essential for the provision of the map (Section 25(2)(2) TDDDG). Data processing in this context is the responsibility of the respective map provider. Please refer to the privacy policy of the respective service in this regard.
Data transfers to third countries (in particular the USA) and protective measures
Several of the service providers used (in particular Base44, Stripe and Resend) have their registered offices or server locations outside the EU/EEA, in particular in the USA. These are so-called third countries within the meaning of Art. 44 et seq. GDPR.
When personal data is transferred to such third countries, it cannot be ruled out that authorities in the recipient country may access the data and that you may not have legal remedies available to you comparable to those in the EU. We select our service providers carefully, include – where necessary – appropriate contractual safeguards (e.g. EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR) and implement additional technical and organisational safeguards (e.g. TLS encryption, password hashing, access restrictions). Nevertheless, a level of data protection identical to that in the EU cannot be guaranteed in all cases.
Email hosting (e.g. IONOS)
We use an email hosting service provider to handle email communication (in particular support and contractual communication). In doing so, communication and content data are processed (e.g. email address, communication content, metadata). The legal basis is – depending on the context – Article 6(1)(b) of the GDPR (contract/pre-contractual steps) or Article 6(1)(f) of the GDPR (legitimate interest in efficient communication). Where the service provider is based outside the EU/EEA or processes data from there, the information in section 10.6 applies accordingly.
Retention period and erasure
Principle
We generally store personal data only for as long as is necessary for the respective purposes (Article 5(1)(e) GDPR) or where statutory retention obligations apply (Article 6(1)(c) GDPR).
User data in the account
All data linked to your user account is stored for as long as your user account is active. If you delete your user account or the SaaS contract ends, the associated personal data is generally deleted within 30 days or – where required by law – archived in a separate system (e.g. billing data, tax-relevant information). Before the contract ends, you have the option to export your data. Upon request, business customers can receive a confirmation of deletion or destruction. The legal bases are your right to data portability (Art. 20 GDPR) and your right to erasure (Art. 17 GDPR).
Log data and backups
Server logs are regularly deleted or anonymised after approximately 7 to 30 days, unless longer retention is required in individual cases (Art. 6(f) GDPR). Backups are typically retained for 14 to 30 days and then overwritten by newer backups.
Deletion and retention policies
There is a documented deletion and retention policy. Personal account data is generally deleted within 30 days of the end of the contract. Log data is regularly deleted or anonymised after approximately 7–30 days. Backups are typically retained for 14–30 days and then overwritten. Statutory retention obligations (in particular for invoicing and billing data) remain unaffected. Export and deletion functions are available.
Data subject rights
You have – within the framework of the legal requirements – the following rights regarding your personal data:
- Right to access your personal data processed by us (Art. 15 GDPR).
- Right to rectification of inaccurate or incomplete data (Art. 16 GDPR).
- Right to erasure (Art. 17 GDPR), provided that no statutory retention periods or other legal grounds preclude this.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR), in particular with regard to data stored in the app, which you can request or export using export functions.
- Right to object to processing based on Article 6(1)(f) of the GDPR on grounds relating to your particular situation (Article 21 of the GDPR), e.g. against certain forms of usage analysis or logging.
- Insofar as processing is based on consent in future, you have the right to withdraw your consent at any time with effect for the future (Art. 7(3) GDPR).
To exercise your rights, you may in particular use the following address: Email: info@profit-pilot.eu
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR).
Security of processing
We take appropriate technical and organisational measures to ensure a level of security appropriate to the risk, Article 32 of the GDPR. These include, in particular:
- end-to-end TLS/HTTPS encryption for communication with the app,
- password hashing,
- access restrictions and a role/permissions system (e.g. admin vs. standard user),
- regular backups of data,
- client-separated processing of data from different customers (logical separation),
- Internal processes for identifying, documenting and resolving security and data protection incidents.
Customers may, upon request, receive internal documentation regarding the technical and organisational measures. Remote audits (e.g. via video conference, document review) are generally possible.
Specifics of the allocation of roles (controller / processor)
For your own user data – in particular registration, account and usage data, as well as our communication with you – we are the controller within the meaning of Article 4(7) of the GDPR.
Insofar as you store or have processed personal data of third parties (in particular your customers, employees or other data subjects) in ProfitPilot, you are the controller within the meaning of Article 4(7) and Article 24 of the GDPR. In particular, you must ensure that:
- there is an appropriate legal basis for this processing (e.g. Article 6(1)(b) or (f) of the GDPR),
- the data subjects are duly informed about the processing and our involvement as a data processor (Articles 13, 14 and 28 of the GDPR),
- your internal processes for erasure, retention and data subject rights are compatible with the functions available in ProfitPilot (e.g. export, erasure).
With regard to the personal data of third parties that you have entered, we process the data exclusively for the purpose of providing the app functions you use and thus on your behalf and on your instructions as a data processor within the meaning of Article 28 of the GDPR. The relevant data processing agreement forms part of our contractual documents (e.g. Terms and Conditions / SaaS Agreement) and specifically names the sub-processors used (currently including Base44, Resend, Stripe). Access to data by these sub-processors takes place solely on the basis of these agreements and within the framework of the legal requirements (Articles 28, 44 et seq. of the GDPR).
Where we process data generated during the use of ProfitPilot for our own purposes – for example, in pseudonymised or aggregated form for error analysis, ensuring security and stability, preventing misuse or improving the product – we do so as a separate data controller on the basis of Article 6(1)(f) of the GDPR. In doing so, we ensure data minimisation and process this data, where possible, without direct reference to individuals (e.g. through aggregation or pseudonymisation) and only to the extent that your legitimate interests do not preclude this.
We support you as the data controller within the scope of the contractually agreed services and legal requirements (in particular Articles 28 and 32 of the GDPR), e.g. through:
- export and deletion functions provided within the app,
- support with the processing of data subjects’ rights (Articles 12–22 of the GDPR) upon request,
- information on our technical and organisational measures and on the sub-processors used,
- support in handling data protection and security incidents (Articles 33 and 34 of the GDPR), for example as part of the incident processes described in Section 15.
Reporting of data protection incidents
Data protection or security incidents may affect both your own data and the data of your end customers.
Please report any incidents to us immediately:
Email: info@profit-pilot.eu
We respond immediately, usually within 48 hours of becoming aware of an incident. We have internal processes in place for identifying, assessing, documenting and resolving data protection and security incidents. Where we act as a data processor, we assist our clients in fulfilling their reporting and information obligations towards supervisory authorities and data subjects.
No specific industry certifications
There are currently no specific industry-specific certifications that would be relevant in connection with the use of ProfitPilot.
Changes to this privacy policy
This privacy policy may be amended if data processing or the underlying legal framework changes, e.g. due to:
- the introduction of new functions or services (e.g. additional payment service providers, analytics tools),
- Changes to the infrastructure used (e.g. hosting providers, sub-processors),
- Changes to legal or regulatory requirements.
The current version of the privacy policy is available on the website profit-pilot.eu. In the event of significant changes affecting your consent or your contractual relationships, we will also inform you – where possible – within the app or by email.
The German version of this Privacy Policy is legally binding. This English version is provided for convenience only. In case of discrepancies, the German version shall prevail.
Date: 05.06.2026
© 2026 ProfitPilot · info@profit-pilot.eu
