Seite wird geladen …
Seite wird geladen …
This is a courtesy translation. In case of any discrepancy, the German version is legally binding.
Last updated: 20 September 2026
This agreement supplements OfferPilot’s Terms of Service. It applies whenever a user enters personal data of their own customers, employees, or other individuals into OfferPilot. To this extent, the using person is the controller; Jan Meier, Hulmenweg 82, 8352 Ricketwil (Winterthur), Switzerland, is the processor. This agreement does not apply to purely private use that involves no processing of third-party personal data.
The subject matter is the storing, structuring, editing, displaying, generating, and transmitting of data, to the extent required for accounts, customer master data, quotes, invoices, contracts, reminders, PDF files, email sending, and expressly used AI features. Processing continues until the relevant data is deleted or the account ends, subject to statutory retention obligations and backup copies that are deleted with a technical delay.
Data that may be processed includes in particular names, companies, addresses, email addresses, phone numbers, service and contract details, prices, payment details, document content, signatures, attachments, and communication data. Data subjects may include customers, prospects, suppliers, employees, contracting partners, and signatories of the using person. Special categories of particularly sensitive personal data should only be entered where necessary and legally permitted.
OfferPilot processes the data only to provide the chosen features, in accordance with documented instructions from the using person, and to the extent a statutory obligation does not require otherwise. Use of the application and support requests count as documented instructions. Persons involved in processing are bound to confidentiality. If OfferPilot considers an instruction unlawful, execution may be suspended and clarification requested.
OfferPilot takes technical and organisational measures appropriate to the risk. These include encrypted transmission, role- and account-restricted access, private file areas, authentication, confidentiality of login credentials, backup and recovery procedures, and appropriate logging and updating of the systems used. The measures are further developed taking into account the state of the art and the risk involved.
The using person grants general authorisation for the following categories and current providers. OfferPilot contractually obliges them to appropriate data protection to the extent they act as processors:
Material changes to this list will be announced via the website or by email. In the event of a reasoned data-protection objection, the parties will seek a reasonable solution; if no solution is possible, the affected feature or the contract may be terminated.
Depending on the provider, data may be processed in Switzerland, the European Economic Area, or the United States. Where no adequate level of data protection is recognised, the statutorily required safeguards are used, in particular recognised standard contractual clauses and supplementary measures. Further information is available in the privacy policy and the respective linked provider terms.
OfferPilot supports, to a reasonable and technically feasible extent, requests for information, correction, deletion, release, data protection impact assessments, and inquiries from authorities. Relevant breaches of data security will be reported to the controller without undue delay, with the information available. The decision on notifications to authorities or affected individuals lies with the party legally responsible for that decision.
During the contract term, data can be released via the intended export and document features. After the contract ends, OfferPilot deletes or anonymises data on request, unless statutory obligations or overriding evidentiary or security interests prevent this. Backup copies are removed in the regular overwrite cycle. On reasonable request, OfferPilot provides appropriate information to demonstrate compliance with this agreement; audits are to be coordinated so that security, confidentiality, and operations for other users are preserved.
The using person remains responsible for the lawfulness, accuracy, and required notification of data subjects. They assign secure login credentials, restrict access, and do not enter data for which they lack the necessary legal basis or authorisation to process.