GardenPilot Professional
HomePricingAI in landscaping
Private clientsGarden pros
EN
  • Deutsch
  • English
Partner login Sign up To the partner portal
Log in Portal
EN
  • Deutsch
  • English
HomePricingAI in landscaping
Private clientsGarden pros

Private clients: Planning for your own garden

Sign up To the partner portal

Privacy Policy – GardenPilot Professional

Version: privacy-b2b-2026-09-v2
Effective: upon publication
Language version: English

1. Controller

The controller for processing in which GardenPilot Professional processes personal data for its own purposes is:

PUENJER, S.L.U.
Avinguda Mèxic 17
07007 Palma de Mallorca
Spain
C.I.F.: B22974018
Email: support@gardenpilot.de
Telephone: +34 684 774 631
Represented by: Fin Pünjer, sole director (administrador único)

2. Role allocation and scope

This Privacy Policy applies to processing for which PUENJER, S.L.U. itself acts as controller within the meaning of the GDPR, in particular company and contact data, registration, account administration, contract and billing data, GardenPilot's own security/usage data, support communications and GardenPilot's own lawful product/operations analysis.

Where a Professional customer processes personal data of its own end clients, contacts or other third parties in GardenPilot and GardenPilot processes those data solely on the Professional customer's documented instructions to provide the platform service, the Professional customer is the controller and PUENJER, S.L.U. is the processor. The Data Processing Agreement (DPA) then applies in addition.

Providers used in production and their respective roles are documented in the current Provider and Subprocessor Register.

3. Principles and required information

GardenPilot processes personal data only for specified purposes and only to the extent necessary for platform operation, contract/account performance, billing, support, security, legal obligations, lawful internal analysis or – where required – on the basis of consent.

Information required for registration, an order or a function is identified in the relevant input flow. If required information is not provided, the relevant function or contract may not be available or capable of being concluded. Voluntary information may be omitted.

Choosing the German or English language version determines the language of the interface and the relevant contractual/information version. It is not automatically treated as a statement about the customer's registered office, billing country or target market.

4. Website access, technical delivery and security

When GardenPilot Professional is accessed and used, the data processed may include in particular:

  • IP address,
  • date and time,
  • requested address/resource,
  • referrer,
  • browser and device information,
  • technical request, error and security data.

Purposes are technical delivery, availability, IT security, error analysis, abuse prevention and fraud prevention.

Legal basis: Article 6(1)(f) GDPR. The legitimate interests are secure, stable and abuse-resistant operation of the platform.

GardenPilot's own full-IP server/security logs are generally deleted no later than after 14 days unless a specific security incident requires longer documented retention. Infrastructure and security providers may process their own technical logs under their contractually documented retention periods; details are set out in the Provider Register.

5. Internal usage statistics

GardenPilot may create internal statistics concerning reach, technical quality and product usage. Data may include in particular page/screen views, timestamps, broad device type and browser category, referrer domain and technical product or funnel events.

For long-term internal usage statistics, GardenPilot does not store a full IP address as a persistent analytics identifier. Short-lived pseudonymous identifiers for bot filtering, deduplication or technically limited measurement windows are deleted or rendered technically unusable after the required short period.

Legal basis: Article 6(1)(f) GDPR. The legitimate interests are data-minimising reach, functionality and quality analysis and avoiding obviously distorted statistical values.

6. Registration, company, contacts and account

Data processed may include in particular first and last name, company, business email address, password hash, billing address, VAT ID where provided, account, role and permission status, Credit, order, contract and invoice data, language/locale information and security events.

Legal bases:

  • Article 6(1)(b) GDPR where the data subject is itself the contracting party as a sole trader/self-employed professional or pre-contractual steps are taken at the data subject's request;
  • Article 6(1)(f) GDPR where contacts, employees or representatives of a company are processed. The legitimate interests are initiating, performing, administering and documenting the business relationship and secure user and permission administration;
  • Article 6(1)(c) GDPR where statutory tax, accounting, commercial-law or evidential obligations apply.

7. Sources of contact data

We regularly obtain personal business contact data directly from the data subject, from the Professional customer or its account administrator, in connection with an order, support request or contractual communication and, where required, from payment or billing providers.

Where users are created or invited by a company administrator, name, business email address, company and role/permission information may originate from that company.

8. Project, image, text and input data

Depending on the function, the data processed may include garden/property photographs, location information, project texts, wishes, preferences, project/concept data, generated results and chat/assistant content.

Where such data contain personal data of the Professional customer's end clients or other third parties and GardenPilot processes them solely to provide the instructed service on the customer's instructions, processing is governed by the DPA.

Where GardenPilot exceptionally processes project information for its own purposes, a separate legal basis must exist and the data subject is informed in accordance with the GDPR.

GardenPilot does not use personal project and content data to train its own general-purpose AI models.

9. AI services and automated assessments

GardenPilot Professional uses specialised AI services. Depending on the function, project information, text or images may be transmitted to one or more external AI providers.

GardenPilot uses business, API or cloud products for this purpose. Providers used in production, purpose, role, processing region, relevant retention/training information and transfer mechanisms are documented in the Provider and Subprocessor Register.

GardenPilot may use automated systems for technical/substantive quality control, error detection or pre-assessment of support and complaint cases. Where GardenPilot acts as controller in this context, processing is based on Article 6(1)(b) or (f) GDPR depending on the purpose.

Under the current product design, GardenPilot does not make solely automated decisions concerning natural persons that produce legal effects or similarly significant effects without the possibility of appropriate human review.

10. Payment, invoice and tax data

For orders, Credits, payments and invoices, we process in particular contract, transaction, billing and tax information. Payments may be processed through Stripe.

Legal bases:

  • Article 6(1)(b) GDPR where the data subject is itself a party to the contract;
  • Article 6(1)(f) GDPR for contact/representative data of a legal entity where necessary for contract and payment administration;
  • Article 6(1)(c) GDPR for statutory tax, accounting and evidential obligations.

Stripe may act as an independent controller for individual processing steps required for its own legal obligations or purposes. Current role and transfer information is set out in the Provider Register and Stripe's information.

11. Email, support and marketing

Contract, security, payment, invoice, product-status and support communications are processed on the basis of Article 6(1)(b) GDPR where the data subject is itself the contracting party, or Article 6(1)(f) GDPR for business contacts and required support/security communications.

Resend may be used for technical email delivery.

Electronic marketing communications are sent only where an applicable legal basis exists. This may include consent or – where the statutory requirements are met – legally permitted existing-customer communications concerning GardenPilot's own similar services. A simple and free opt-out/unsubscribe mechanism is provided where required.

12. Infrastructure, recipients and processors

GardenPilot uses external infrastructure, cloud, AI, payment, email, security and, where applicable, marketing providers.

The current list, respective role and material transfer/retention information is maintained in the Provider and Subprocessor Register.

Where providers act as processors, they are contractually bound in accordance with Article 28 GDPR.

13. International transfers

Where personal data are processed or made accessible outside the EEA, this occurs only under the conditions of Chapter V GDPR, in particular on the basis of an adequacy decision or appropriate safeguards such as Standard Contractual Clauses.

The specific basis for each provider is documented in the Provider Register.

Where processing is additionally subject to Swiss data-protection law, the provisions of the DPA concerning Swiss data-protection law additionally apply to processing on behalf of the customer.

14. Cookies, local storage and marketing technologies

Technically necessary cookies, local storage or comparable technologies may be used for login, security, session management, language settings and expressly requested functions.

Non-essential analytics, marketing or tracking technologies are used only where the consent or other legal basis required under applicable law exists.

Where Google Ads, Meta Pixel or Microsoft Advertising are actually used on Professional pages, the corresponding published consent and provider information applies.

15. Retention

  • Account/contract data: for the contractual relationship and thereafter only to the extent required by statutory retention, evidence or legal defence.
  • Payment/invoice/tax data: according to the applicable statutory retention periods.
  • Security logs: GardenPilot's own full-IP logs generally for no more than 14 days unless a specific incident requires longer retention.
  • Support communications: for handling the matter and thereafter only for as long as required by statutory retention, evidence or specific legal defence.
  • Consent, contract and legal evidence: for as long as necessary to demonstrate lawfulness or to establish, exercise or defend claims.
  • Professional-customer data processed on instructions: according to the DPA.
  • Data Act switching/export data: according to the switching/retrieval period and thereafter only where statutory duties or another lawful basis permit continued retention.

After the applicable period expires, data is deleted or – where genuine irreversible anonymisation has occurred – used only in anonymised form.

16. Data-subject rights

Subject to the GDPR, data subjects have in particular the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21) and withdrawal of consent with future effect (Article 7(3)).

Contact: support@gardenpilot.de

Where we process data on the basis of Article 6(1)(f) GDPR, the data subject may object on grounds relating to their particular situation. There is an unconditional right to object to direct marketing at any time.

17. Right to lodge a complaint

Data subjects may lodge a complaint with a data-protection supervisory authority.

For PUENJER, S.L.U., the relevant authority is in particular:

Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan 6
28001 Madrid
Spain
www.aepd.es

Subject to Article 77 GDPR, data subjects may in particular also contact a competent supervisory authority in the Member State of their habitual residence, place of work or place of the alleged infringement.

18. Data security

GardenPilot uses appropriate technical and organisational measures, in particular encrypted transmission, role- and need-to-know-based access restrictions, protection of privileged access, security logging, secret/credential management, monitoring and incident-response processes.

Details concerning data processed on behalf of Professional customers are additionally set out in the TOMs of the DPA.

19. Changes to this Privacy Policy

We update this Privacy Policy where processing purposes, technical operations, providers or legal requirements change.

Material changes are published as a new immutable legal version. Where additional information or consent is required by law, it is provided or obtained before the relevant processing. Historical versions used for a contract or evidential purpose are not subsequently altered.

Further documents for GardenPilot Professional

  • Provider and subprocessor register — the providers, legal bases and third-country safeguards named in the text
  • General Terms and Conditions (B2B)
  • Data Processing Agreement (Art. 28 GDPR)
  • Legal notice

As of: 15.09.2026

GardenPilot Professional

The B2B platform for landscaping businesses – visualizations, client folders and advertised garden projects in your region.

Navigation

  • Home
  • Pricing
  • AI in landscaping

Support

  • Partner login
  • Sign up
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Imprint

Follow us

For private clients (B2C) →

© 2026 PUENJER, S.L.U. All rights reserved.

Terms• Privacy• Imprint