Privacy Policy

Last updated: March 2, 2026

1. Introduction

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Tagesplanr, an AI-powered CRM and GTM platform for startups ("the Service"). We are committed to protecting your privacy and ensuring compliance with the EU General Data Protection Regulation (GDPR), the EU AI Act, and other applicable data protection laws.

2. Data Controller & Data Protection Officer

The data controller responsible for your personal data is the operator of this service:

  • Company: BlackSwanAI
  • Location: Erlangen, Germany

Data Protection Officer (DPO):

For any privacy-related inquiries, please contact our DPO at the email address above.

3. Data We Collect

3.1 Account Information

  • Email address (required for account creation and authentication)
  • Name (required for account creation)
  • Company name (collected during application)
  • Application details (collected during access application)
  • Password (stored securely using industry-standard bcrypt hashing)

3.2 Business Data

  • Lead and contact information you input
  • CRM and pipeline data
  • Competitor analysis data
  • Content you create using our tools
  • Networking and event information
  • Time tracking and productivity data
  • LinkedIn engagement tracking data
  • Social media calendar entries

3.3 Subscription Data

  • Subscription status and billing information
  • Payment history (processed by third-party payment providers)

3.4 AI Usage Data

  • AI feature usage statistics (token counts, request frequency)
  • Content prompts and generated outputs for service improvement
  • AI audit logs (provider, use case, timestamp — EU AI Act compliance)

3.5 Technical Data

  • IP address (for security, rate limiting, and consent records)
  • Browser type and user agent (for session management and consent records)
  • Consent preferences and history

4. How We Use Your Data

We use your personal data for the following purposes:

  • Service Provision: To provide and maintain our service
  • Authentication: To verify your identity and secure your account
  • AI Features: To generate content, analyze leads, and provide business insights (with your explicit consent)
  • Service Improvement: To analyze usage patterns and improve our features (with your consent for analytics)
  • Communication: To send service-related notifications (password resets, verification, breach notifications)
  • Legal Compliance: To comply with GDPR, EU AI Act, and other applicable regulations

5. Legal Basis for Processing (GDPR Article 6)

  • Contract (Art. 6(1)(b)): Processing necessary for service provision (account management, core features)
  • Legitimate Interest (Art. 6(1)(f)): Security measures, fraud prevention, service reliability
  • Consent (Art. 6(1)(a)): AI data processing, analytics cookies, marketing communications
  • Legal Obligation (Art. 6(1)(c)): Data breach notifications, consent record keeping

6. Third-Party AI Providers

We use the following AI providers to power our features:

  • Perplexity AI (US-based): Lead generation, lead enrichment, competitor research — uses real-time web search to find company information
  • Groq (US-based): Content generation, quick analysis, fast inference tasks

Data sent to AI providers: Business-related data (company names, industry information, ICP criteria) is sent to these providers. We apply data minimization: personal contact details (email, phone) are stripped before sending to AI providers for company enrichment.

Consent requirement: Data is only sent to AI providers when you have explicitly granted AI data processing consent in your privacy settings. You can revoke this consent at any time.

Data sent to these providers is processed according to their respective privacy policies and data processing agreements. We ensure appropriate safeguards including Standard Contractual Clauses (SCCs).

7. Data Retention

We retain your personal data according to the following schedule:

  • Account data: Retained while your account is active; deleted upon account deletion request
  • Telemetry/analytics events: 30 days
  • AI audit logs: 90 days (EU AI Act requirement)
  • Consent records: 5 years (legal requirement for demonstrating consent)
  • Session data: 7 days
  • Business data (leads, CRM, etc.): Retained while account is active
  • Breach notification records: 5 years (regulatory requirement)

You may request deletion of your data at any time through Settings > Privacy & Data, or via the GDPR API endpoint.

8. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Request correction of inaccurate data
  • Right to Erasure (Art. 17): Request deletion of your data ("Right to be Forgotten")
  • Right to Restrict Processing (Art. 18): Request limited processing of your data
  • Right to Data Portability (Art. 20): Export your data in a machine-readable format
  • Right to Object (Art. 21): Object to certain types of processing
  • Right Not to be Subject to Automated Decisions (Art. 22): See Section 12 below

To exercise these rights: Use the Settings > Privacy & Data page in the application, or contact our DPO at datenschutz@blackswanai.de.

9. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit (HTTPS/TLS)
  • Secure password hashing (bcrypt with salt rounds)
  • JWT-based session management with httpOnly cookies
  • Rate limiting to prevent abuse
  • Role-based access control (admin/user separation)
  • Structured logging with automatic PII sanitization
  • Regular security assessments

10. International Transfers

Your data may be processed on servers located outside the European Economic Area (EEA), specifically by our AI providers (Perplexity AI, Groq) based in the United States. We ensure appropriate safeguards are in place including:

  • Standard Contractual Clauses (SCCs) where applicable
  • Data minimization before cross-border transfers
  • Explicit consent for AI data processing

11. Telemetry & Analytics

With your consent, we collect anonymized usage data to improve the service:

  • Page views: Which pages and modules you visit
  • Feature usage: Which features you use and how frequently
  • Error tracking: Application errors to improve reliability
  • Session data: Session duration and navigation patterns

Analytics data is collected only with your explicit consent (analytics cookies). You can disable analytics at any time via Settings > Privacy & Data.

12. Automated Decision-Making (GDPR Article 22)

Our AI-powered features provide suggestions and scores (e.g., lead relevance scores, ICP fit scores) that are suggestive in nature. These scores:

  • Do not produce legal effects on any individual
  • Do not make automatic decisions about users
  • Are used as tools to assist your business decisions, not replace them
  • Can be overridden or ignored at any time

No fully automated decisions with legal or similarly significant effects are made about you based on your personal data.

13. Cookie Policy

We use the following cookies and local storage:

  • exec_session (httpOnly cookie): Authentication session token, expires after 7 days
  • cookie_consent (localStorage): Your cookie preference settings
  • data_processing_consent (localStorage): Your data processing consent preferences
  • preferred_locale (localStorage): Your language preference (en/de)

Necessary cookies (session) cannot be disabled as they are required for the service to function. Optional cookies (analytics, marketing) require your explicit consent.

14. AI-Generated Content Disclosure

In compliance with the EU AI Act transparency requirements, please note that content generated using our AI features is computer-generated. AI-generated or AI-enriched data is clearly indicated within the application interface with visual badges.

15. Sub-Processors

The following third-party services process data on our behalf:

  • Perplexity AI (USA) — AI-powered lead generation and enrichment
  • Groq (USA) — AI-powered content generation and analysis
  • Neon (USA) — PostgreSQL database hosting
  • Netlify (USA) — Application hosting and deployment
  • SMTP Provider — Transactional email delivery

All sub-processors are bound by data processing agreements and appropriate safeguards.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. If consent version changes, you will be prompted to re-consent.

17. Contact Us

If you have any questions about this Privacy Policy or our data practices:

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

This privacy policy is designed to comply with GDPR, EU AI Act, and applicable data protection requirements. For questions about your data rights, contact datenschutz@blackswanai.de.