Privacy Policy – GardenPilot
Version: privacy-b2c-2026-09-v5
Effective: upon publication
Language version: English
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
PUENJER, S.L.U.
Avinguda Mèxic 17
07007 Palma de Mallorca
Spain
C.I.F.: B22974018
Email: support@gardenpilot.de
Represented by: Fin Pünjer, sole director (administrador único)
2. Principles of processing
GardenPilot processes personal data only for specified purposes and only to the extent necessary to provide the platform, perform a contract, maintain security, comply with legal obligations or – following your consent – carry out marketing.
GardenPilot uses cloud, payment, email and AI service providers. The providers actually used and their purposes are listed in our current Provider and Subprocessor Register.
Which information is required for registration, a purchase or a requested function is indicated by the relevant input form. If data required to create an account, conclude a contract, process a payment or provide the requested service is not provided, the relevant function or contract may not be available or capable of being concluded. Voluntary information may be omitted.
Choosing the German or English language version determines only the language of the interface and of the relevant contractual/information version. It is not automatically treated as a statement about residence, billing country or another target market.
3. Website access and technical delivery
When GardenPilot is accessed, technically required access data is processed. This may include in particular:
- IP address,
- date and time of access,
- requested address or resource,
- referrer,
- browser and device information,
- technical request, error and security data.
Processing is carried out to deliver GardenPilot technically, ensure availability and security, analyse errors and detect and prevent automated, fraudulent or abusive access.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and abuse-resistant operation of the platform.
Where full IP addresses are stored in GardenPilot's own technical security or server logs, they are generally deleted no later than after 14 days. Longer retention occurs only where a specific security incident makes it necessary; in that case further retention is limited to the necessary scope and period.
Infrastructure and security providers may process their own technical logs under their contractually agreed retention periods. Details are set out in the Provider Register.
4. Internal usage statistics
GardenPilot creates internal statistics to understand reach, technical quality and product usage. The data processed may in particular include:
- page or screen view,
- timestamp,
- broad device type and browser category,
- referrer domain,
- technical product or funnel events,
- country where lawfully collected, and internal market metadata where required for the relevant transaction.
For long-term internal usage statistics, GardenPilot does not store a full IP address as a persistent analytics identifier.
Where an IP address is temporarily required to exclude bots, filter GardenPilot's own traffic or deduplicate events within a limited time window, it is used only during the technical processing or transformed into a short-lived pseudonymous identifier. The identifier is deleted after the required window or rendered unusable by key rotation.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interests are data-minimising reach, function and quality analysis and the prevention of obviously distorted statistical values.
These internal statistics are not used to create individual movement or interest profiles over months based on an IP address.
5. Registration, login and user account
When a user account is registered and used, we process in particular:
- first and last name, where provided or required,
- email address,
- a cryptographic password hash; the password itself is not stored in plaintext,
- user ID and account status,
- language and, where separately collected, country or market information,
- account and security events,
- information about Credit balances, orders and functions used.
Legal basis: Article 6(1)(b) GDPR where the data is required for the account and contract performance.
Security and abuse data is processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is protecting users, accounts and the platform against abuse and fraud.
6. Projects, photographs, text and other inputs
Depending on the function, when you use GardenPilot we process in particular:
- garden and property photographs,
- text, wishes and preferences entered by you,
- postal code, country and location information provided by you,
- project, concept and planning data,
- generated images, text, planning materials and other results,
- chat and assistant content.
Legal basis: Article 6(1)(b) GDPR where processing is necessary to provide the GardenPilot service you requested.
Please avoid uploading unnecessary third-party personal data. Photographs with clearly identifiable persons, vehicle registration plates, house numbers or other identifying features should be used only where you have a sufficient legal basis to do so.
7. AI functions and external AI providers
GardenPilot uses specialised AI services for different functions. Depending on the function, text, project information or garden photographs may be transmitted to one or more AI providers.
We transmit only data required for the function requested in each case.
GardenPilot does not use your personal project and content data to train its own general-purpose AI models.
External AI services are used through business, API or cloud products. The rules applicable to the particular service concerning training, short-term security/abuse logs, processing regions and international transfers depend on the specific provider and product. The AI providers currently used in production and the documented conditions applicable to them are identified in the Provider Register.
Legal basis: Article 6(1)(b) GDPR where AI processing is required to provide the service you requested.
8. Automated quality and complaint assessment
GardenPilot may use automated AI systems to check generated content for identifiable technical or substantive defects or to pre-assess a user complaint.
This may involve processing the original garden photograph, the generated result, the project requirements and the reason for complaint provided by you.
Legal basis: Article 6(1)(b) GDPR where the assessment serves contract performance or complaint handling; additionally Article 6(1)(f) GDPR for abuse prevention and consistent quality control.
Under the current product design, GardenPilot does not make a solely automated decision that produces legal effects concerning you or similarly significantly affects you without the possibility of human review. If an automated complaint or quality assessment is adverse to you, you may request manual review by Support.
9. Payment processing
For paid services we use in particular Stripe.
The data processed may in particular include:
- name,
- email address,
- billing address,
- order and transaction data,
- amount and currency,
- payment status,
- tax information required by law,
- payment details entered directly with Stripe.
Legal bases: Article 6(1)(b) GDPR for contract and payment processing; Article 6(1)(c) GDPR where statutory tax, accounting or evidential obligations apply.
Stripe may act as an independent controller for certain processing steps based on its own legal obligations or purposes. The current role and transfer information is described in the Provider Register or in Stripe's privacy information.
10. Email communication
10.1 Contract and service emails
We send emails required for registration, login/security, payment processing, invoices, project status or other contract performance.
Legal basis: Article 6(1)(b) GDPR.
10.2 Voluntary reminders and marketing
Project reminders, newsletters or other marketing emails are sent only where an appropriate legal basis exists, in particular your consent.
Legal basis: Article 6(1)(a) GDPR where consent is used.
You may withdraw consent at any time with future effect.
10.3 Email delivery provider
GardenPilot may use Resend for technical email delivery. In particular, the recipient address and the content of the relevant email are processed.
11. Hosting, database, file storage and security
GardenPilot uses external infrastructure and cloud service providers in particular for web hosting/CDN, database and authentication, file storage, server/lambda functions and technical security.
According to the current Provider Register, these include in particular Cloudflare, Supabase and AWS.
Legal bases: Article 6(1)(b) GDPR where processing is required to provide the service; Article 6(1)(f) GDPR for security and stability purposes.
12. Cloudflare Turnstile / bot protection
GardenPilot uses Cloudflare Turnstile to detect automated or abusive requests and protect forms or support functions. Turnstile runs in invisible mode: you will normally not see a checkbox and do not have to solve a task; the check runs in the background when you send a message through the support chat on our contact page.
Technical network, browser and device information may be processed.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is protecting the platform and its users against automated abuse, spam and attacks.
Where Turnstile accesses or stores information on your terminal equipment, this takes place only under the conditions of the applicable rules governing terminal equipment.
13. Cookies, Local Storage and similar technologies
GardenPilot uses technically necessary cookies, Local Storage or similar technologies where required in particular for login, session management, security, language settings or an expressly requested function.
Where German law applies, access to or storage of information on your terminal equipment is governed in particular by Section 25 TDDDG. In all other cases, the applicable national rules on access to terminal equipment and implementation of ePrivacy requirements apply. Technically strictly necessary operations may be permissible without consent under those rules; non-essential marketing or tracking technologies are used only after the consent required in the relevant case has been obtained.
14. Consent management
Before activating non-essential tracking technologies, we may ask you for consent through a consent interface.
You may change or withdraw consent at any time with future effect through the consent settings.
We store evidence of your consent decision where necessary to demonstrate compliance with legal requirements.
15. Google Ads
With your consent, we may use Google Ads to measure advertising performance and, where applicable, for remarketing.
Depending on the configuration, the data processed may in particular include technical browser/device data, IP address, page views, referrer, cookie or click identifiers and GardenPilot-defined conversion events.
Legal basis: Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG or the corresponding national provisions governing non-essential storage of or access to information on terminal equipment.
The technology is activated for marketing purposes only after the required consent has been obtained.
16. Meta Pixel
With your consent, we may use the Meta Pixel provided by Meta Platforms Ireland Limited to measure the success of advertising on Facebook and Instagram.
Depending on the configuration, the data processed may in particular include IP address, browser and device data, page/referrer, _fbp, where applicable fbclid, and GardenPilot-defined conversion events.
Under the configuration currently envisaged, GardenPilot does not transmit the content of your garden projects or chat messages through the Pixel.
Legal basis: Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG or the corresponding national provisions governing access to information on terminal equipment.
17. Microsoft Advertising / Bing UET
With your consent, we may use Microsoft Advertising / Bing UET for conversion measurement.
Depending on the configuration, the data processed may in particular include IP address, browser and device data, page views/referrer, UET cookie identifiers, where applicable msclkid, and technical names of funnel/conversion events.
Under the configuration currently envisaged, GardenPilot does not transmit the content of your garden projects or chat messages through UET.
Legal basis: Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG or the corresponding national provisions governing access to information on terminal equipment.
18. Recipients and processors
Personal data is disclosed only to external recipients whose services are required for the relevant GardenPilot function.
Processors are bound by contract in accordance with Article 28 GDPR.
The current list of infrastructure, email, AI, payment and marketing providers used is published in the Provider and Subprocessor Register.
19. International transfers
Where personal data is processed outside the European Economic Area or made accessible from there, this takes place only under the statutory conditions.
Depending on the provider, the transfer may in particular be based on an adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the specific recipient is covered, Standard Contractual Clauses of the European Commission and, where appropriate, supplementary safeguards, or another lawful basis.
The basis used for the relevant provider is documented in the Provider Register. Further information on the safeguards used in each case and, where applicable, a means of obtaining a copy may be requested via support@gardenpilot.de or is linked in the Provider Register.
20. Retention periods
We retain personal data only for as long as required for the relevant purpose or justified by a statutory obligation or a necessary legal-defence purpose.
Technical server and security logs
GardenPilot's own full-IP server/security logs are generally deleted no later than after 14 days, unless a specific security incident requires longer documented retention.
Internal usage statistics
Long-term internal statistics do not contain a full IP address as a persistent user identifier. Short-lived pseudonyms used for bot filtering/deduplication are deleted after the required short time window or technically rendered unusable.
Account and profile data
For the duration of the active account. After account deletion, the data is removed from the operational system unless retention or legal-defence grounds prevent this.
Project photographs, inputs and generated content
Generally until the project or user account is deleted or the relevant purpose ceases to apply. Following a deletion request, operational media is not retained for years solely because of an abstract limitation period. Further restricted retention occurs only where required by specific statutory obligations or for the establishment, exercise or defence of specific legal claims.
Payment, invoice and tax data
For the applicable statutory retention period. Records falling within the EU One Stop Shop scheme may be subject to a retention period of ten years. Other Spanish commercial or tax obligations may provide for different periods.
Contract, consent and performance evidence
For as long as required to comply with statutory evidential obligations and to establish, exercise or defend possible claims. Where the general Spanish civil limitation period is relevant, retention may generally be necessary for up to five years; different special periods, suspension or interruption remain unaffected.
Support and complaint data
For handling the matter and subsequently only for as long as required for evidential purposes, statutory retention or specific legal defence.
Consent records
For as long as GardenPilot relies on the consent and subsequently for as long as necessary to demonstrate its lawfulness.
After the relevant period has expired, data is deleted or, if it has been genuinely and irreversibly anonymised, used only in anonymised form.
21. Your rights
Subject to the GDPR, you have in particular the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent with future effect (Art. 7(3)).
Contact: support@gardenpilot.de
Where we process data on the basis of Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You have the right to object to direct marketing at any time.
22. Right to lodge a complaint
You have the right to lodge a complaint with a data-protection supervisory authority.
For PUENJER, S.L.U., the relevant authority in Spain is in particular:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6
28001 Madrid
Spainwww.aepd.es
Under Article 77 GDPR, you may in particular also lodge a complaint with a competent supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
23. Data security
GardenPilot uses appropriate technical and organisational measures, in particular encrypted transmission, role-based access restrictions, protection of privileged access, security logging and measures provided by the cloud and infrastructure providers used.
24. Changes to this Privacy Policy
We update this Privacy Policy when processing purposes, technical operations, providers or legal requirements change.
Material changes are published as a new legal version. If personal data is to be further processed for a new purpose, we provide prior information where required by law. Where additional information or consent is legally required, it is provided or obtained before the relevant processing.
Further documents
- Provider and sub-processor register
- Terms and Conditions
- Withdrawal policy
- AI transparency notice
- Legal notice
Version date: 14.09.2026