Skip to content
P

Privacy Policy

Last updated: TO BE SUPPLIED

This policy explains what personal data PIE processes, why, on what legal basis, and what rights you have. It covers the public website and the PIE applications.

1. Controller

The controller responsible for processing on this website is the provider named in the Imprint. For personal data processed inside a customer's organisation on the platform, that customer is the controller and PIE acts as a processor under a data-processing agreement.

2. What we process

Account data (name, business email, organisation, role) to provide the service. Authentication data (password hashes, session and multi-factor records) to secure it. Usage and audit data (actions taken, timestamps, IP address, request identifiers) to operate the service, meet the audit obligations our customers have, and investigate abuse. Support correspondence when you contact us. Server logs, kept for a limited period for security and troubleshooting.

3. Legal basis

Performance of a contract (Art. 6(1)(b) GDPR) for account and service data; legitimate interests (Art. 6(1)(f)) for security, abuse prevention and service improvement; legal obligation (Art. 6(1)(c)) where retention is required; and consent (Art. 6(1)(a)) where we ask for it, which you may withdraw at any time.

4. Processors and sub-processors

PIE is self-hosted on infrastructure within the European Union. We use an email service provider to deliver transactional messages such as invitations, notifications and password resets. Where an organisation enables AI features using platform-funded credits, the content submitted for processing is sent to the configured model provider; an organisation may instead supply its own provider key. The current sub-processor list is maintained below and customers are notified before it changes.

5. International transfers

Platform data is stored in the European Union. Where a sub-processor requires a transfer outside the EEA, it is covered by an adequacy decision or by standard contractual clauses; the current position is stated in the sub-processor list.

6. Retention

Account data is retained while the account exists and for a limited period afterwards to meet legal obligations. Audit records are retained for the period the customer configures or that the law requires. Server logs are kept for a short period. On termination, customer data is exported and then removed according to the offboarding process.

7. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Platform users can exercise access and erasure through the data-subject request tooling in the application. You may also lodge a complaint with a supervisory authority.

8. Cookies and tracking

The public website sets no advertising or analytics cookies. The applications set a session cookie required to keep you signed in, and a preference cookie for interface settings. Both are strictly necessary and are not used to track you across sites.

9. Contact

For any privacy question or to exercise a right, contact us using the address in the Imprint.

Current sub-processors

Hosting and infrastructure: operated on dedicated infrastructure in Germany. The database, cache, object storage and search index are self-hosted — no third party processes them. Transactional email: a German email service provider delivers invitations, notifications and password resets. Recipient address and message content are processed for delivery only. AI processing: only where an organisation uses platform-funded AI features. Content submitted for processing is sent to the configured model provider (Google, OpenAI-compatible or Anthropic, depending on configuration). An organisation may instead supply its own provider key, in which case the relationship is between that organisation and its provider. No AI feature is enabled by default, and no customer content is used to train any model. No analytics, advertising or tracking processors are used.