Privacy Policy
How we handle your personal data
Last updated: February 2026
Controller
The controller responsible for data processing on this website is:
Ellmann Consulting GmbH
Ballindamm 3, 20095 Hamburg
Phone: +49 40 2396 99771
Email: pricing@ellmann-consulting.com
Overview of Data Processing
We process personal data only to the extent necessary for providing a functional website and our services. The processing of personal data takes place regularly only with the consent of the user. An exception applies in cases where prior consent cannot be obtained for practical reasons and the processing of data is permitted by law.
Hosting & Infrastructure
This website is hosted on cloud infrastructure provided by Vercel Inc. (USA) and Amazon Web Services (AWS). When you visit our website, your browser automatically transmits certain technical data (IP address, browser type, operating system, time of access) to our servers. This data is processed to ensure the secure and stable operation of our website. Server log files are stored for a maximum of 30 days and then automatically deleted.
User Account Data
When you create an account on PricingOS, we collect and store the following personal data to provide our services:
- Name (for personalization)
- Email address (for authentication and communication)
- Password (stored encrypted, never in plain text)
- Company information (name, industry, size – for service personalization)
Product & Pricing Data
When you use PricingOS, you provide business data through our pricing framework. This data is used exclusively to generate personalized pricing recommendations:
- Answers provided in the 9-step pricing wizard (product descriptions, customer profiles, competitive analysis, financial data)
- Uploaded documents (pitch decks, business plans) – processed for text extraction and analyzed by AI
- Chat conversations with your AI Pricing Brain
AI Data Processing
PricingOS uses artificial intelligence to analyze your business data and generate pricing recommendations. Your data is sent to OpenAI's API for processing.
AI Provider: OpenAI, Inc. (San Francisco, USA). Data is transmitted to the USA under EU Standard Contractual Clauses (SCCs).
Important: Your data is not used to train OpenAI's models. We use the API with data processing agreements in place. AI-generated outputs are stored in your account and can be deleted at any time.
Payment Processing
We use Stripe as our payment processor. When you subscribe to PricingOS Pro, your payment information (credit card details, billing address) is collected and processed directly by Stripe. We never store your full credit card number on our servers. We only receive a reference ID, subscription status, and last four digits of your card from Stripe.
Cookies
Our website uses cookies to ensure proper functionality and improve user experience. Cookies are small text files stored on your device.
Essential Cookies
Required for authentication (session tokens), language preference, and cookie consent status. These cookies are necessary for the website to function and cannot be disabled.
Analytics Cookies (optional)
If you consent, we may use analytics cookies to understand how visitors interact with our website. These cookies are only set with your explicit consent and can be managed through our cookie settings.
Your Rights
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
- Right of Access – You can request information about your stored personal data (Art. 15 GDPR)
- Right to Rectification – You can request correction of inaccurate personal data (Art. 16 GDPR)
- Right to Erasure – You can request deletion of your personal data (Art. 17 GDPR)
- Right to Restriction – You can request restriction of processing of your data (Art. 18 GDPR)
- Right to Data Portability – You can request your data in a structured, commonly used format (Art. 20 GDPR)
- Right to Object – You can object to processing based on legitimate interests (Art. 21 GDPR)
- Right to Withdraw Consent – You can withdraw any given consent at any time with effect for the future (Art. 7(3) GDPR)
Data Retention
We store your personal data only as long as necessary for the purposes for which it was collected, or as required by law. Account data is retained for the duration of your active account. After account deletion, data is removed within 30 days, except where retention is required by law (e.g., tax-related data is retained for 10 years per German fiscal law). Chat histories and AI-generated content are deleted immediately upon account deletion.
Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. The responsible supervisory authority for our company is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 7. OG, 20459 Hamburg
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal reasons. We will notify registered users of significant changes via email. The current version is always available on this page.