Privacy policy

As at: August 2026

Draft version
This text describes the actual data flows of ETSpilot to the best of our knowledge and is intended as a basis for legal review. It does not replace that review.

Controller

The controller for the processing of personal data within the meaning of the GDPR is:

Splendid Minds GmbH
Spitzwiesenstraße 33
90765 Fürth
support@splendidminds.de

What this policy covers

ETSpilot consists of three parts that handle data differently:

Legal bases for processing

We process personal data only on one of the following bases:

We do not process special categories of personal data under Art. 9 GDPR. If you enter such data into a request, this happens at your instigation; we ask you to refrain from doing so.

This website

The website uses no advertising or analytics services. No tracking takes place, no cookies are set for analytics purposes, and no consent is required.

Server logs

When the page is requested, our web server processes the IP address, date and time, the address requested, the referring link and details of the browser and operating system. This is technically necessary in order to deliver the page and to detect attacks. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). The logs are deleted after 14 days.

Fonts

The fonts used are delivered from our own server. No request is made to Google Fonts or any other third party; your IP address is therefore not passed on to anyone.

Local storage

If you switch between light and dark appearance, your browser remembers that choice locally. This information does not leave your device.

Account portal and add-in

An account is required in order to use ETSpilot. The following data is processed in that context:

DataPurposeRetention period
E-mail addressSign-in via one-time code, account management, system messagesuntil the account is deleted
API key of your AI providerForwarding your requests to the provider you have chosenuntil deleted by you; stored encrypted
Project-related content from the ETSAnswering your requests by the AI modelin the chat history, until you delete it
Planning documents in the project folderSearchability by the assistantuntil deleted by you; stored encrypted
Usage data (time, model, token count)Billing, detection of misuse, capacity planning400 days
Ratings of answersImproving the quality of answersuntil the account is deleted

Transfer to the AI provider

Your requests do not go directly to the AI provider but first to our server in Germany. There they are supplemented with KNX expertise and then forwarded to the provider via the account you have stored. Depending on your choice, that is:

For transfers to the USA we rely on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) or – where the provider is certified under it – on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). For their business accounts, the providers undertake not to use transmitted content to train their models. If you wish to avoid transfers to third countries, choose an Azure endpoint within the EU.

What you can exclude from transmission

For every project you can define in the portal which data categories must never leave your computer – security keys, device parameters or the building structure, for example. Blocked categories are neither transmitted nor made available to the assistant.

Voice input

The add-in's dictation function uses the online speech recognition of Windows. Your voice recording is processed by Microsoft in the process. The function can only be used if you have enabled it beforehand in the Windows privacy settings; ETSpilot itself does not transmit any audio data.

Hosting and processors

We operate our servers, database and e-mail dispatch with service providers within the European Union. We have concluded data processing agreements pursuant to Art. 28 GDPR with all service providers that process personal data on our behalf. You use the AI providers named in the preceding section via your own account; their terms additionally apply in that respect.

Security measures

In accordance with Art. 32 GDPR we take technical and organisational measures appropriate to the risk: end-to-end transport encryption (TLS), encrypted storage of access keys and uploaded documents, access only for those people who need it to perform their duties, separate environments for development and operation, and regular updates of the systems in use. Sign-in is by one-time code; we do not store passwords.

Deletion of data

We delete personal data as soon as the purpose of processing ceases to apply and no statutory retention obligation stands in the way. We retain commercial and tax records for six and ten years respectively; such data is restricted in processing rather than deleted until the period expires. If you delete your account, we remove chat histories, stored access keys and uploaded documents immediately.

Your rights

Under the GDPR you have the following rights:

You can carry out access, export and deletion yourself in the portal under “Account” – without a request to us.

Withdrawal and objection

You may withdraw consent you have given at any time with effect for the future. You may object at any time to processing we base on a legitimate interest; we will then cease it unless we can demonstrate compelling legitimate grounds. An informal message to support@splendidminds.de is sufficient.

Complaint to the supervisory authority

Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany.

Changes

We adapt this policy when the processing changes. The version currently in force can be found on this page.