Legal information about Presio.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Presio UG (haftungsbeschränkt) i. Gr.
Hohenzollernstr. 7
80801 München, Germany
Email: info@presio.eu
[If appointed: contact details of the data protection officer.]
We process our users' personal data, as a rule, only to the extent necessary to provide a functional website as well as our content and services. The legal bases are in particular:
This website is hosted via [Hosting provider, e.g. GitHub Pages] provided. The app's data is processed at [Backend provider, e.g. Supabase] processed and stored in a data centre within the European Union (EU). Data processing agreements pursuant to Art. 28 GDPR are in place with the service providers used.
When the website is accessed, the browser automatically transmits information to the server and temporarily stores it in so-called log files. The following may be recorded:
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in the technically error-free provision and security of our website.
Our website does not use any tracking or marketing cookies for its operation. The app stores technically necessary information (e.g. for login/session) locally on your device; this is required for operation (Art. 6 (1) (b) and (f) GDPR or § 25 (2) TDDDG). [If further cookies/services are used, add them here.]
To see which pages are opened and which buttons are used, we record only the following information for each page view and each click on a link or button:
No IP addresses, no full browser identifiers, no form entries and no cookies are stored. It is therefore not possible to attribute data to individuals or to recognise anyone across several visits. Storage takes place with our processor on servers in the European Union. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in designing our offering to meet demand).
A user account is required to use Presio. As part of time tracking, we process the data required for this, in particular:
Processing takes place to perform the usage contract (Art. 6 (1) (b) GDPR) and to fulfil legal obligations (Art. 6 (1) (c) GDPR, e.g. working-time documentation).
Insofar as Presio is used by an employer for its employees, that employer is the controller under data protection law for the employee data processed in the app; the provider acts in this respect as a data processor (see section 10).
With your consent, we send push notifications to your device (e.g. reminders to clock out, notices about requests and decisions). For technical delivery, the push services of the respective platform are used: Apple Push Notification service (APNs) for iOS and [Firebase Cloud Messaging (FCM) / Google] for Android. In this process, a device token is processed. The legal basis is Art. 6 (1) (a) GDPR; consent can be withdrawn at any time in the settings or via your device's system settings.
If you contact us by email, we process the data you provide in order to handle your request. The legal basis is Art. 6 (1) (b) or (f) GDPR.
Website assistant (AI chat): On this website we offer an AI-powered chat assistant that answers questions about the Presio product. Your chat inputs are transmitted via an interface operated by us (an Edge Function in the EU) to Mistral AI (a provider based in Paris, France) and processed there to generate the response. Processing takes place within the European Union (EU); Mistral processes the content as a data processor.
We process the messages you enter as well as - to limit abuse and costs (Rate-Limiting) - your IP address. Please do not enter any personal or confidential data in the chat. The conversation history is not stored on the server side; it remains only temporarily in your browser's session storage (sessionStorage) and is deleted when the tab is closed. No cookies are set.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in providing straightforward product information); use of the chat is voluntary. No transfer to a third country outside the EU (e.g. the USA) takes place for the chat.
AI features in the app (shift planning): In Presio, an AI supports shift planning - it creates schedule suggestions, understands requests in free text and answers questions in the chat. For this, we use Mistral AI (Mistral AI, Paris, France) as a processor. Processing takes place in the European Union (EU); no transfer to the USA occurs for these AI functions.
Only the data required for the respective function is transmitted - as a rule just first names along with shift and duty master data, no complete personal data and no clock-time profiles. The AI produces suggestions only; the decision on the schedule and its publication rests with authorized persons within the business. The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement); a data processing agreement under Art. 28 GDPR is in place with the provider. [Before publication, review and supplement the AI provider's terms regarding the use of API inputs, e.g. exclusion of use for training purposes.]
To provide our services, we use carefully selected service providers (in particular for hosting/backend, push delivery and the AI chat). Where required, we have data processing agreements with them in accordance with Art. 28 GDPR. We operate both the website assistant and the AI features of the scheduling tool via Mistral AI (France) with processing in the EU (see item 9) - meaning all of Presio's AI runs within the EU. Any transfer to third countries takes place only on the basis of appropriate safeguards (e.g. EU standard contractual clauses). [Add further service providers used here in concrete terms, e.g. hosting/backend and push.]
We store personal data only for as long as is necessary for the respective purposes or as prescribed by statutory retention periods (e.g. commercial and tax obligations). The data is subsequently deleted or anonymised.
Under the GDPR, you have the following rights:
To exercise your rights, an informal message to the email address mentioned above is sufficient.
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR), in particular in the Member State of your residence, place of work or the place of the alleged infringement.
We take technical and organisational measures to protect your data against manipulation, loss and unauthorised access (including encrypted transmission via TLS, role-based access rights). This privacy policy is updated as needed to take account of changes in the legal situation or changes to our services.
Sign up, create your team, get started - try Presio free and with no obligation, no credit card needed.
Start your free trial