Privacy policy
We take the protection of your personal data seriously. This policy informs you, pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR), about the processing of your data.
This is an English reading version. The legally binding version is the German original - only it counts in the event of a dispute.
1. Controller
The controller for the data processing within the meaning of Art. 4(7) GDPR is:
Einzelunternehmen Bazid Aldemir
August-Horch-Straße 35
56751 Polch, Deutschland
Email: kontakt@praeferenzpilot.de
2. Your rights
As a data subject you have the following rights towards us:
- Access to your processed data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to the processing (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.
3. Accessing the website (server log files)
When you access our application, our hosting service provider automatically processes information transmitted by your browser (including IP address, date and time, page accessed, volume of data transferred, browser type). This serves technical delivery, security and stability. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the technical security, stability and functioning of our systems and in preventing misuse and attacks.
4. Cookies
We use only technically necessary cookies, which are required for signing in and maintaining your session. There is no tracking by third parties or for advertising purposes. Storage and access take place under § 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) (strictly necessary cookies). The subsequent processing is based on Art. 6(1)(b) GDPR (sign-in and session for the performance of the contract) and Art. 6(1)(f) GDPR; our legitimate interest lies in secure, functioning operation.
5. Registration and user account
To use PräferenzPilot you create an account. In doing so we process your email address and your company or account name. This data is necessary to establish and perform the usage relationship. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Providing this data is necessary to establish and perform the usage contract; without it we cannot provide the user account or deliver the service.
6. Processing of the application data
As part of your use we process the business data you enter (e.g. articles, bills of materials, suppliers' declarations, generated draft proofs). The binding origin calculation is carried out exclusively deterministically according to stored rules — no AI model decides the origin result. For optional convenience features (plain-language explanations, input suggestions, reading uploaded documents and the assistant) we use Google Gemini as a processor (see the section on sub-processors and the list in the DPA); only the details passed for the respective function are processed, and the outputs are non-binding suggestions with no legal effect. Automated decision-making including profiling within the meaning of Art. 22(1) and (4) GDPR does not take place. The legal basis is Art. 6(1)(b) GDPR.
6a. Suppliers' declarations: data of supplier contacts
Our customers can store contact details of contacts at their suppliers (name, business email address) — including by CSV import — and request suppliers' declarations through the application. In that case we send email requests and reminders on behalf of and in the name of the respective customer; in that respect the customer is the controller within the meaning of the GDPR and we are the processor (Art. 28 GDPR, see our data processing agreement). Informing the supplier contacts about this processing (Art. 14 GDPR) is the customer's responsibility; we support them in doing so.
If a supplier completes a declaration form via a personal link, we collect the name of the responsible person directly (Art. 13 GDPR): this detail is required under customs law so that the electronic supplier's declaration is recognised without a signature (Implementing Regulation (EU) 2015/2447), and it is stored together with the declaration for the requesting customer. Legal bases: processing on behalf of the customer (Art. 28) and Art. 6(1)(f) GDPR (legitimate interest in legally compliant, provable documentation of the chain of declarations). The storage period follows the customs retention periods (see section 10).
6b. Email dispatch and application programming interface (API)
For sending transactional emails (in particular requests and reminders concerning suppliers' declarations) we use Resend (Plus Five Five, Inc., USA) as a processor. Dispatch takes place via the EU region (Ireland); for transfers to the USA, EU standard contractual clauses are in place and the provider is additionally certified under the EU-U.S. Data Privacy Framework. The recipient address, sender details and message content (including the form link) are processed.
When you use our REST API we store account-bound API keys as a cryptographic hash (SHA-256), plus the first characters of the key (prefix) so it can be recognised in the interface, together with usage metadata (time of last use) for security and to prevent misuse (Art. 6(1)(b) and (f) GDPR). The full key cannot be reconstructed after creation.
7. Payment processing
Subscription payments are handled by the payment service provider Stripe. The data required for payment is processed directly by Stripe; we ourselves do not store complete payment data. The legal basis is Art. 6(1)(b) GDPR. Details can be found in Stripe's privacy policy at stripe.com/privacy.
8. Recipients and processors
To deliver our service we use carefully selected service providers that process data on our behalf and on our instructions (Art. 28 GDPR):
- Vercel Inc. — Hosting and delivery of the web application. USA — transfer on the basis of the EU standard contractual clauses and a data processing agreement.
- Supabase, Inc. — Database, authentication and storage of the application data. Stored in the Frankfurt am Main data centre (EU); provider based in the USA, safeguarded by standard contractual clauses and a data processing agreement.
- Stripe Payments Europe, Ltd. — Handling of subscription payments (for the payment processing itself, Stripe acts in part as an independent controller). Ireland (EU).
- Resend (Plus Five Five, Inc.) — Sending transactional emails, in particular requests and reminders concerning suppliers' declarations on behalf of our customers. USA — transfer on the basis of the EU standard contractual clauses (the provider's DPA) and the EU-U.S. Data Privacy Framework; email is sent via the EU region (Ireland).
- Google (Google Cloud EMEA Ltd. / Gemini API) — AI-assisted convenience features (plain-language explanations, input suggestions, reading uploaded documents, the assistant). Only the article, bill-of-materials and document details passed for that purpose are processed. The binding origin verdict is made by the verified engine, not by the AI. Under paid use of the Gemini API, the content transmitted is not used for training.. USA/EU — transfer on the basis of the EU standard contractual clauses and the Google data processing agreement (Cloud Data Processing Addendum).
- INWX GmbH & Co. KG — Domain and email hosting. Germany (EU).
- Cloudflare, Inc. (Turnstile) — Abuse protection for the open forms (registration, sign-in, password reset). It checks whether the request comes from a human; the IP address and technical browser characteristics are processed for that purpose. Turnstile sets no advertising cookies and builds no cross-site profiles.. USA — transfer on the basis of the EU standard contractual clauses and the Cloudflare data processing agreement.
Insofar as data is transferred to a third country (e.g. the USA), this takes place on the basis of appropriate safeguards, in particular the EU standard contractual clauses. We will provide you with a copy of these clauses on request via the email address given above.
9. Contacting us
If you contact us by email, we process your details in order to handle the enquiry. The legal basis is Art. 6(1)(b) or (f) GDPR; our legitimate interest lies in the proper handling of your enquiry.
10. Storage period
We store personal data only for as long as it is necessary for the purposes stated or as statutory retention periods require. Server log files are generally deleted within 30 days. Account and application data is deleted after the contract ends, unless statutory retention obligations prevent this. Contract and invoice data is subject to the commercial and tax retention periods of six and ten years respectively (§ 257 of the German Commercial Code, § 147 of the German Fiscal Code).
11. Data security
Transmission is encrypted via TLS (HTTPS). Access to your data is secured by strict tenant separation, so that each account can see only its own data.
12. Currency and changes
We adapt this privacy policy as soon as changes to our processing make that necessary. The version published on this page at the time applies.
As of: 19. August 2026