BISpicy Inventory Management - Cloud Software
Data Controller within the meaning of the General Data Protection Regulation (GDPR):
(1) This Privacy Policy informs you about the type, scope, and purpose of the processing of personal data within our software "BISpicy Inventory Management" and the associated online services.
(2) Legal basis:
What data is collected?
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Storage period: Until account deletion + 30 days
What data is processed?
Note: This data is processed on behalf of the customer (data processing agreement pursuant to Art. 28 GDPR).
Fault diagnosis (error logs): To detect and resolve technical faults, we log error events from server operation and from the user's browser (error message, technical call chain, timestamp, page accessed, browser identification, user ID). Access credentials, tokens and payment information are automatically redacted before storage. Detailed troubleshooting recording beyond error events takes place only for a limited time (maximum 72 hours), only upon express instruction with a documented reason, and ends automatically. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fault-free operation) or Art. 28 GDPR within the scope of data processing. Retention period: error events 14 days, other technical operational data 3 days; automatic deletion thereafter.
Device purchase (§25a German VAT Act / margin scheme): When purchasing used devices (e.g. in a phone shop), in order to fulfil the statutory recording obligation (purchase ledger pursuant to §25a UStG in conjunction with the German Anti-Money Laundering Act) we store the seller's data – name, address, ID number and telephone number – as well as the device data (IMEI/serial number, purchase and sale price). Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation). Access is restricted to authorised employees.
Email delivery of receipts, invoices and reports: On request, we send point-of-sale receipts, digital receipts and invoices (e.g. from the connected POS app) by email to the email address provided by the customer. Operators and authorised employees may also have reports, analyses and documents sent to a self-configured email address (email export). We process the respective email address solely to deliver the requested document. Legal basis: Art. 6(1)(b) GDPR (contract performance) or (f) GDPR (legitimate interest in the requested delivery); where a receipt is sent at the customer's voluntary request, it is based on their consent pursuant to Art. 6(1)(a) GDPR. The transfer is made solely to our server or to the mail service provider configured by the operator (a processor for delivery only); no disclosure to third parties for their own purposes takes place. Retention period: only for as long as required for delivery or the statutory retention of the document.
Appointments can be booked online via the public booking page at https://bispicy.com/app/booking/<business>. You receive a confirmation by email if you provide an email address; the business is notified of the booking.
What data is processed?
Purpose: Scheduling, confirming and handling the booked appointment.
Controller: For bookings via our own booking page (bispicy.com/app/booking/bispicy) we are the controller. Businesses that use the appointment planner for their own customers are themselves controllers for these bookings; in that case we process the data on their behalf (data processing pursuant to Art. 28 GDPR). Please direct any questions or requests regarding such bookings to the respective business.
Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request). The processing is not based on consent.
Storage period: We store the information for as long as it is needed for scheduling and handling the appointment and as required by statutory retention obligations.
In the customer portal (Kundencenter) on bispicy.com you take part in promotions – currently the BISpicy Startaktion (launch promotion) for businesses of all sectors that are new to BISpicy, which offers a starting credit of €15 and – for businesses that take in repairs – free months for the repair status page. No application or receipt is required.
What data is processed?
Purpose: Carrying out the promotion (activating and extending the repair status page; checking, crediting and offsetting the starting credit; review and correction at your request; and, where applicable, reclaiming the credit in the event of abuse).
Legal basis: Art. 6(1)(b) GDPR (carrying out the promotion in accordance with the promotion terms).
Automated check, crediting and offsetting: Each day, the system checks whether the requirements for the free months and the starting credit are met, using the criteria stated in the promotion terms (paid TSE licence, first SumUp card payment – terminal or Tap to Pay –, turnover threshold); if they are met, it activates the status page or credits the balance without any further action and then automatically applies the credit as a customer balance at Stripe to your next invoice. The system decides on the forfeiture of the starting credit only from 3 February 2027 onwards, so that daily closings transmitted late with payments up to 31 January 2027 are still taken into account. The check relies solely on these criteria, which are the same for all participants, does not evaluate you as a person and can only grant or not grant a benefit. Insofar as it constitutes an automated decision within the meaning of Art. 22 GDPR, it is necessary for carrying out the promotion (Art. 22(2)(a) GDPR). In any case, you have the right to obtain human intervention, to express your point of view and to contest the decision (Art. 22(3) GDPR): upon your message, a member of staff reviews the case and may credit the balance subsequently or – as long as it has not yet been offset – reverse it; we record the reason, the time and the person handling the case. Simply contact us (see contact details below).
Offsetting via Stripe: For the offsetting, Stripe Payments Europe Ltd. (see Section 4) receives the amount, internal identifiers (user, booking and participation identifiers plus a technical key preventing duplicate bookings) and your Stripe customer number; Stripe already receives your payment data for the billing of your licences.
Disclosure to SumUp: SumUp only receives aggregated figures on the promotion without names or details of individual participants – and a figure only if it is based on at least five participants.
Storage period: We store participation, check and correction data for as long as benefits under the promotion may be granted or claims arising from it exist, and beyond that only insofar as statutory retention obligations require. The crediting of the balance and its offsetting are accounting records and are retained under Section 147 of the German Fiscal Code (AO) until 31 December of the eighth year after the year in which the credit was granted.
(1) Principle: Your data will only be disclosed to third parties if:
(2) Data recipients:
| Recipient | Purpose | Location | Legal Basis |
|---|---|---|---|
| DigitalOcean LLC | Hosting (BIS ERP, database, cloud backups in Spaces) | Frankfurt (EU) | Art. 6(1)(b) GDPR |
| Cloudflare, Inc. (engaged by DigitalOcean) | Reverse proxy and content delivery network (website delivery, connection data/IP) — engaged by DigitalOcean as its own sub-processor for the App Platform; no separate contractual relationship with the processor | EU/USA (standard contractual clauses) | Art. 6(1)(f) GDPR |
| Stripe Payments Europe Ltd. | Payment processing for software licenses | Dublin (EU) | Art. 6(1)(b) GDPR |
| Shipping carriers (DHL, DPD, GLS, Hermes, UPS, FedEx) | Shipping label creation, track & trace | EU | Art. 6(1)(b) GDPR |
| Marketplaces and shops (Amazon, eBay, Etsy, Shopify, Magento, WooCommerce, Shopware) — only when enabled | Order and article synchronization | EU / worldwide | Art. 6(1)(b) GDPR (upon the Controller's instruction) |
| Google LLC (Firebase Cloud Messaging) | Push notifications to connected POS devices (no personal content) | EU/USA (Standard Contractual Clauses) | Art. 6(1)(f) GDPR |
| Anthropic PBC (only when AI features are used) | AI-assisted recognition of incoming invoices, AI article creation, AI repricing (not used for model training) | USA (Standard Contractual Clauses) | Art. 6(1)(b)/(f) GDPR in conjunction with Art. 46 GDPR |
| Fiskaly GmbH (only when POS integration is active) | TSE cloud signing (KassenSichV / RKSV) | Germany / Austria | Art. 6(1)(c) GDPR (legal obligation) |
The full list of processors and sub-processors with locations and processing purposes can be found in the Data Processing Agreement (DPA).
The BIS AI Bridge is a program that runs on your own computer and connects your JTL database to an AI service of your choice (such as Claude, ChatGPT or Cursor). A clear separation applies:
Exception — access via browser chats: If you connect the bridge to an AI service in the browser (such as claude.ai or ChatGPT), that service cannot start a program on your computer. In this case the query runs via our servers: we forward it to the BISConnect installation on your computer, which submits it to your database, and return the result to your AI service. The following applies:
We have implemented extensive technical and organizational measures:
For questions about data protection, please contact:
Last Updated: September 30, 2026