GardenPilot Professional
HomePricingAI in landscaping
Private clientsGarden pros
EN
  • Deutsch
  • English
Partner login Sign up To the partner portal
Log in Portal
EN
  • Deutsch
  • English
HomePricingAI in landscaping
Private clientsGarden pros

Private clients: Planning for your own garden

Sign up To the partner portal

Data Processing Agreement (DPA) under Article 28 GDPR – GardenPilot Professional

Version: dpa-b2b-2026-09-v3
Effective: upon acceptance / publication
Language version: English

between the relevant GardenPilot Professional business customer – the “Controller” – and

PUENJER, S.L.U.
Avinguda Mèxic 17
07007 Palma de Mallorca
Spain
C.I.F.: B22974018
Email: support@gardenpilot.de
Telephone: +34 684 774 631
represented by Fin Pünjer, sole director (administrador único)

– the “Processor” –

§ 1 Subject matter and scope

  1. This DPA applies to the extent that the Processor processes personal data solely on behalf of and on the documented instructions of the Controller in connection with GardenPilot Professional.
  2. It supplements the main GardenPilot Professional agreement.
  3. Processing for the Processor's own purposes, in particular account administration, billing, the Processor's own IT security, fraud/abuse prevention and legal obligations, falls outside this DPA and is governed by the B2B Privacy Policy.

§ 2 Subject matter, purpose and duration

  1. The subject matter of the processing is the technical and functional provision of GardenPilot Professional for projects of the Controller.
  2. Purposes may include in particular storage and processing of project images and files; processing of location and project information; AI-supported analysis; creation of concepts, visualisations, texts and planning documents; project-related assistant and chat functions; exports and project management; technical safeguarding, availability and erasure of Controller personal data.
  3. Processing generally continues for the term of the main agreement or until the relevant Controller personal data are erased or returned in accordance with this DPA.

§ 3 Nature of processing

Processing may include in particular: collection/receipt, recording, storage, organisation, structuring, retrieval, consultation, disclosure to approved subprocessors, AI analysis, technical modification, generation, availability, export, restriction and erasure.

§ 4 Categories of personal data

Depending on use, in particular:

  • project/property photographs and other project files,
  • postal code, country and other location information,
  • project-related wishes and preferences,
  • project-related free text,
  • technical project metadata,
  • contact/end-client data where provided,
  • chat/assistant content where it contains Controller personal data.

Special categories of personal data under Article 9 GDPR are not intended for normal use and should not be entered unless their processing has been expressly agreed in advance and is supported by an appropriate legal basis.

§ 5 Categories of data subjects

Depending on the project, in particular:

  • end clients of the Controller,
  • owners, occupants or users of a photographed property,
  • contacts,
  • employees or project participants,
  • other identifiable persons incidentally appearing in supplied content.

§ 6 Instructions and processing required by law

  1. The Processor processes Controller personal data only on documented instructions from the Controller unless Union or Member State law or other mandatorily applicable law requires processing.
  2. Documented instructions include the main agreement, this DPA, intended use of the platform, platform actions initiated by authorised users and additional instructions in text form.
  3. Where the Processor is legally required to process personal data without an instruction, it informs the Controller of that legal requirement before processing, unless the applicable law prohibits such information on important grounds of public interest.
  4. If the Processor considers an instruction to be unlawful under data-protection law, it informs the Controller without undue delay to the extent legally permitted.

§ 7 Obligations of the Processor

The Processor shall in particular:

  1. process Controller personal data only in accordance with Article 28 GDPR, this DPA and documented instructions;
  2. ensure that authorised persons are committed to confidentiality or are subject to an appropriate statutory duty of confidentiality;
  3. implement appropriate technical and organisational measures under Article 32 GDPR;
  4. comply with the subprocessor rules in § 9;
  5. reasonably assist the Controller with data-subject rights taking into account the nature of processing;
  6. reasonably assist the Controller with obligations under Articles 32 to 36 GDPR;
  7. erase or return data under § 12;
  8. make available the information and evidence required under Article 28 GDPR;
  9. allow audits under § 13;
  10. not use Controller personal data to train the Processor's own general-purpose AI models.

§ 8 Obligations and rights of the Controller

  1. The Controller determines the purposes and essential means of processing for which it is responsible and is in particular responsible for lawfulness and legal bases, transparency information to data subjects, data minimisation, lawful, complete and clear instructions, deciding which data may be placed in GardenPilot, and handling data-subject requests and regulatory obligations incumbent on it as Controller.
  2. The Controller should not enter unnecessary personal data or special categories of personal data into GardenPilot.
  3. The Controller may issue additional instructions provided that they fall within the agreed service scope, are technically feasible and lawful. Additional work outside the agreed service scope may require a separate agreement.

§ 9 Subprocessors

  1. The Controller grants general authorisation for the use of subprocessors.
  2. The current list of providers that process Controller personal data is maintained in the Provider and Subprocessor Register.
  3. The Processor generally informs the Controller with reasonable advance notice of an intended addition or replacement of a subprocessor that processes Controller personal data.
  4. Urgent security, legal or availability reasons may justify shorter notice.
  5. The Controller may object to a change on objectively substantiated data-protection grounds. The parties seek an appropriate solution; where this is not possible, the affected services or the main agreement may be terminated under the applicable contractual rules.
  6. Subprocessors are contractually bound by data-protection obligations that ensure an essentially equivalent level of protection for the relevant Controller personal data and comply with Article 28 GDPR.
  7. The original Processor remains responsible to the Controller for performance of the subprocessor's data-protection obligations to the extent provided by law.

§ 10 International transfers

  1. Transfers of Controller personal data outside the EEA, or access from third countries, occur only under the conditions of Chapter V GDPR.
  2. The transfer mechanisms used and material processing locations are documented in the Provider and Subprocessor Register.
  3. Where Standard Contractual Clauses, adequacy decisions or supplementary safeguards are required, the Processor ensures their use or selects a subprocessor with correspondingly sufficient safeguards.
  4. Where Swiss data-protection law applies, § 19 additionally applies.

§ 11 Data-subject rights, data protection impact assessments and authorities

  1. Requests from data subjects that clearly concern Controller personal data are generally forwarded to the Controller unless another course of action is required by law.
  2. Taking into account the nature of processing and information available, the Processor reasonably assists the Controller through appropriate technical and organisational measures with access, rectification, erasure, restriction, portability and other data-subject rights.
  3. Taking into account the nature of processing and information available, the Processor reasonably assists the Controller with data protection impact assessments and, where required, prior consultations with a supervisory authority under Articles 35 and 36 GDPR.
  4. Where a supervisory authority requests information in connection with Controller personal data, the parties cooperate to the extent required by law.

§ 12 Erasure and return

  1. After processing ends, the Processor erases or returns Controller personal data at the Controller's choice unless statutory retention obligations or another mandatory legal basis require continued retention.
  2. Where platform export or deletion functions are available, the Controller may use them during the contractual term.
  3. Data subject to statutory retention are restricted or separated from normal operational use and are not used for unrelated purposes.
  4. Backup copies are overwritten or erased through regular backup rotation where immediate item-level deletion is technically disproportionate, provided that the data are not used operationally in the meantime.
  5. Further rights to export and switching under the EU Data Act arise, where applicable, from the main agreement and statutory requirements; they do not alter the data-protection erasure/return obligations under this DPA.

§ 13 Evidence and audits

  1. The Processor makes available the information required under Article 28 GDPR.
  2. Suitable existing evidence, security documentation, certifications, audit reports or remote audits have priority where they adequately satisfy the audit purpose.
  3. On-site audits take place only where less intrusive evidence is insufficient, on reasonable advance notice and with appropriate protection of confidentiality, security, operations and the rights of other customers.
  4. Audits must not unreasonably interfere with ongoing operations and must be limited to the scope necessary to demonstrate compliance with this DPA.
  5. Mandatory investigation and supervisory rights of competent data-protection authorities remain unaffected.

§ 14 Personal-data breaches

  1. The Processor informs the Controller without undue delay after becoming aware of a personal-data breach affecting Controller personal data.
  2. The notification includes, to the extent available, the nature and description of the incident, affected categories of data and data subjects, where possible scale/number, known or likely consequences, measures taken or proposed, and a contact point for follow-up.
  3. Information not yet available may be provided in phases without undue delay.
  4. Notification does not constitute an admission of breach of duty or liability; statutory obligations remain unaffected.

§ 15 Technical and organisational measures

GardenPilot maintains in particular:

  • role- and need-to-know-based access;
  • separation of user and administrative permissions;
  • protection of privileged accounts;
  • current transport encryption;
  • protected authentication and secret/credential management;
  • logical project/account assignment and authorisation checks;
  • backup and recovery mechanisms;
  • monitoring and error detection;
  • security logging and incident response;
  • project/account-related deletion processes;
  • time-limited technical logs;
  • no persistent raw-IP use as an internal analytics identifier.

The TOMs may be adapted to technical developments provided that the overall level of protection is not reduced. Material changes adversely affecting the level of protection are communicated to the Controller as appropriate.

§ 16 Term and precedence

  1. This DPA applies for the duration of processing for which GardenPilot acts as Processor.
  2. In the event of conflict with the main agreement, this DPA prevails with respect to protection and processing of Controller personal data.
  3. Mandatory data-protection law prevails over conflicting contractual provisions.

§ 17 Form, version, language and acceptance

  1. This DPA may be concluded electronically.
  2. GardenPilot offers the DPA in German and English. The language version used in the acceptance flow is the relevant version for the specific agreement. No general priority of the German version is agreed.
  3. GardenPilot records the accepted version with legal version, locale, timestamp and content hash or equivalent content evidence.
  4. Material changes are released as a new immutable version. Whether renewed acceptance is required is assessed separately from technical versioning under the applicable legal and contractual requirements.
  5. Historical accepted versions are not subsequently altered.

§ 18 Governing law

Spanish law applies to the extent not displaced by mandatory data-protection law of the European Union, the EEA, Switzerland or other mandatorily applicable law.

§ 19 Swiss data-protection law (revFADP)

  1. This DPA is an international version. It applies to processing under Article 28 GDPR where the GDPR applies, and under Article 9 of the Swiss Federal Act on Data Protection (FADP, SR 235.1) where Swiss data-protection law applies to the Controller or to the processing. Where processing is subject to both regimes, they apply in parallel. For Controllers subject only to the GDPR, this section changes nothing.
  2. Terms. Where Swiss law applies, “Controller” and “Processor” have the meaning given in the FADP and “personal data” means personal data within the meaning of the FADP. Sensitive personal data is determined by Article 5(c) FADP and additionally includes, in particular, data on administrative and criminal proceedings or sanctions and data on social assistance measures.
  3. Permissibility of delegation (Article 9(1) FADP). The Processor processes Controller personal data only as the Controller itself would be permitted to process them. The Controller ensures that no statutory or contractual duty of confidentiality prevents the delegation and informs GardenPilot without undue delay if that changes.
  4. Subprocessors (Article 9(3) FADP, Article 7 DPO). The general authorisation under § 9(1) is at the same time the prior authorisation within the meaning of Article 9(3) FADP. Information on intended changes and the right to object are governed by § 9(3) to (5).
  5. Data security (Article 8 FADP, Articles 1–5 DPO). § 15 applies accordingly. Where the requirements of Article 4 DPO or Article 5 DPO apply in a specific case, the Processor complies with those obligations.
  6. Record of processing activities (Article 12 FADP). The Processor maintains its own record of processing activities. On request, it provides the Controller with information needed for the Controller's own record, in particular the country of a disclosure abroad and the safeguards used under Article 16(2) FADP.
  7. Data-security breaches (Article 24 FADP). Notification under § 14 is also made to a Controller subject to Swiss law. The Processor supports that Controller with notification to the FDPIC and with informing data subjects to the extent required under Swiss law.
  8. Disclosure abroad (Articles 16 and 17 FADP). Where Swiss data-protection law applies, the permissibility of disclosure abroad is governed by Swiss law. In particular, the list of states in Annex 1 to the Swiss Data Protection Ordinance (DPO, SR 235.11) is relevant. An adequacy decision of the European Commission is not automatically a legal basis for disclosure from Switzerland.
  9. United States. A disclosure to the United States relying on an adequacy status under Swiss law requires that the recipient's certification covers the Swiss-U.S. Data Privacy Framework. Otherwise another permissible basis under Swiss law is required.
  10. Standard Contractual Clauses. Where European Union Standard Contractual Clauses are used for disclosures subject to the FADP, they apply with the adaptations required under Swiss law, in particular concerning Swiss terminology, the competent supervisory authority and applicable transfer requirements.
  11. Supervision. The competent supervisory authority for the part of the processing subject to the FADP is the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB).
  12. Precedence. Where Swiss data-protection law applies, this section prevails over the other provisions of this DPA to the extent required to comply with mandatory Swiss data-protection law. The choice of law under § 18 does not displace mandatory Swiss data-protection law.

Further documents for GardenPilot Professional

  • Provider and subprocessor register — the list of engaged providers owed under section 8(2)
  • General Terms and Conditions (B2B)
  • Privacy Policy (B2B)
  • Legal notice

As of: 15.09.2026

GardenPilot Professional

The B2B platform for landscaping businesses – visualizations, client folders and advertised garden projects in your region.

Navigation

  • Home
  • Pricing
  • AI in landscaping

Support

  • Partner login
  • Sign up
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Imprint

Follow us

For private clients (B2C) →

© 2026 PUENJER, S.L.U. All rights reserved.

Terms• Privacy• Imprint