Privacy Policy Application
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is Mr. Simply GmbH, Oberjesinger Str. 1 71154 Nufringen, Germany (hereinafter Provider). Data protection enquiries may be submitted by email to hello@getblitzy.app.
Scope
This Privacy Policy describes the processing of personal data of users in connection with the use of the Blitzy platform as a software-as-a-service solution (SaaS). The platform can be accessed via a web-based application and native applications for iOS and Android. For the purposes of this Privacy Policy, users are the employees of the respective company using the platform.
The Application is offered exclusively to entrepreneurs within the meaning of Section 14 of the German Civil Code (BGB). Use by consumers is excluded.
Where the subscribing business enters and manages personal data of third parties within the Application, the Provider acts as a processor pursuant to Art. 28 GDPR on the instructions of the subscribing business as controller. This subject matter is governed by the separate Data Processing Agreement and falls outside the scope of this Privacy Policy.
Registration and Account Management
The subscribing business registers a business account and creates user accounts for its employees. The data recorded includes name, work email address, job title, language preference, and an optional profile picture. Sign-in to the Application is carried out by email and one-time password. This processing is necessary for the performance of the contract. The legal basis is Art. 6(1)(b) GDPR. Provision of the required data is a precondition for the use of the Application. Without it, registration and performance of the contract are not possible.
Use of the Application
In the course of ongoing use, the account profile data and business data of the subscribing business are processed. The Application maintains an audit log that records changes to records, including user identity and timestamp, and displays these to all signed-in users of the respective business account. This processing is necessary for the performance of the contract. The legal basis is Art. 6(1)(b) GDPR.
Payment Processing
For the processing of subscription payments, billing-relevant data is transmitted to the payment service provider Stripe, Inc. (USA). The Provider does not store payment card data. The legal basis is Art. 6(1)(b) GDPR.
AI-Assisted Features
The Application provides AI-assisted features through which text inputs or document content are transmitted for processing to OpenAI, LLC (USA). Processing is carried out exclusively for the respective functional purpose. Contractual arrangements with OpenAI exclude the use of transmitted content for training purposes. The legal basis is Art. 6(1)(b) GDPR.
Notifications
For the delivery of push notifications, device-specific tokens are stored. Email notifications are sent to the user's registered email address. Both channels may be disabled individually by the user. The legal basis is Art. 6(1)(f) GDPR. The Provider's legitimate interest lies in informing users of relevant events within the Application.
Technical Operations
To ensure stable operations, the Provider uses Sentry to record technical errors and crashes. The data processed includes, in particular, the error type, stack trace, app version, operating system, device type and time of the error. Error reports are not linked to user accounts; names, email addresses, user or business account IDs, unique device identifiers and application content are not intentionally transmitted. Session recordings, screenshots, view hierarchies, console logs and performance monitoring are disabled. The IP address technically generated during transmission is not stored in the error reports. The legal basis is Art. 6(1)(f) GDPR. The Provider's legitimate interest lies in detecting and resolving technical faults.
Usage Analytics
For statistical analysis and improvement of the Application, the Provider uses Plausible Analytics provided by Plausible Insights OÜ (Estonia). Only abstract application routes, selected events and the platform used are recorded. The IP address and User-Agent transmitted for technical reasons are processed temporarily but not stored. The analysis is not linked to user accounts or application content. The legal basis is Art. 6(1)(f) GDPR.
Local Data Storage
To support the offline functionality of the Application, data is temporarily stored on the user's device. Upon sign-out or session expiry, this local data is automatically deleted. The Provider has no access to locally stored data.
Processors and International Transfers
The Provider engages the following processors.
Amazon Web Services EMEA SARL (AWS) operates the cloud infrastructure in Frankfurt am Main, Germany. No transfer of personal data to third countries takes place in connection with this processing.
Stripe, Inc. (USA) processes subscription payments. The transfer of data to the USA is based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
OpenAI, LLC (USA) processes inputs in connection with AI-assisted features. The transfer of data to the USA is based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
650 Industries, Inc. (USA) provides the infrastructure for push notifications. The transfer of data to the USA is based on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Plausible Insights OÜ (Estonia) processes technical usage data for statistical analysis of the Application. Processing and storage take place within the European Union.
Functional Software, Inc. (USA) provides error and crash analysis under the name Sentry. Error reports are stored in Germany. Where access from the USA or another international transfer takes place, it is based on the EU-U.S. Data Privacy Framework or, additionally, on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Retention Periods
Personal data is processed for the duration of the contractual relationship and deleted from active systems upon its termination. In automated backup systems, data is retained for a technically conditioned period beyond termination and subsequently deleted. For data subject to statutory retention obligations, the applicable statutory periods apply. Device-specific tokens for push notifications are deleted upon closure of the business account or upon permanent delivery failure. Technical error reports are deleted once they are no longer required for troubleshooting.
Rights of Data Subjects
Data subjects have the following rights against the Provider, subject to the applicable legal requirements in each case.
- Right of access to processed data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
Where personal data within the Application is processed on the instructions of the subscribing business in the context of processing on behalf, rights of data subjects are to be asserted against the subscribing business as controller.
To exercise rights against the Provider as controller, the Provider is entitled to verify the identity of the requesting party prior to processing the request. Requests should be submitted in text form to hello@getblitzy.app.
Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent supervisory authority at the Provider's registered seat is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.