Skip to content
Skip to main content

This page was translated from German with the help of AI. In case of discrepancies, the German version prevails.

Learn more

Privacy Policy

1. Privacy at a Glance

General information The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

2. Data Collection on This Website

Who is responsible for data collection on this website? The party responsible for data processing on this website is Curved Corner UG (haftungsbeschränkt), Kampenwandstraße 18, 83104 Ostermünchen, Germany, represented by its Managing Director Fabian Fuchs (VAT identification number: DE463880349). Further details can be found in the imprint of this website. How is your data collected? Your data is collected when you provide it to the provider. This may include, for example, your email address that you enter in a registration form. Other data is automatically collected by IT systems when you visit the website. This is primarily technical data (e.g., internet browser, operating system, or time of page access).

3. Local Data Storage

Without a user account, grafcet.io stores only your current GRAFCET locally in your browser (LocalStorage). In that case the data is not transmitted to the provider. You can remove it at any time by clearing your browser cache. As soon as you are logged in, you can save your GRAFCET to the cloud with a single click on "Save to cloud"; from that point on, this GRAFCET is automatically synchronized (see section 5).

4. User Accounts and Authentication

You can create a free user account with your email address and password. An account enables cloud storage with automatic synchronization (autosave) and the sharing features for your GRAFCETs as well as, optionally, the Pro features. Authentication is handled via Supabase Auth. Supabase is hosted on EU servers (Frankfurt, Germany). Data stored: email address, hashed password, profile data, and license status. By registering, you accept the Terms of Use and acknowledge this Privacy Policy. For evidentiary purposes, the provider stores the time, the applicable version (version identifier) and a checksum (hash) of the wording of both documents. The full wording of each version is kept in the provider's database (Supabase, EU); all versions are stored there, so that it remains traceable at any time which Terms of Use you accepted and which Privacy Policy version was presented to you. Legal basis: Art. 6(1)(b) GDPR (establishment of the usage relationship) and Art. 6(1)(f) GDPR (legitimate interest in being able to demonstrate the effective incorporation of the terms). You can delete your account yourself at any time in the account tab via "Delete account", or contact the provider for this at hi@grafcet.io. Upon deletion, your user account including your login data (email address, password hash or linked Google login), your profile and all GRAFCETs you have stored in the cloud are irrevocably removed. Activated license keys are detached from your account in the process; the associated purchase/billing data that must be retained by law is held by the reseller Paddle (see section 6) and is not affected by this. Optionally you can sign in with Google (OAuth 2.0 / OpenID Connect). Your email address and Google account ID are transferred to Google Ireland Ltd.; processing takes place partly in the USA under the EU-US Data Privacy Framework and Standard Contractual Clauses. Legal basis: Art. 6(1)(b) GDPR (contract performance). Use by minors The free GRAFCET editor can be used by people of any age, as long as no personal data is transmitted to the provider in the process (local use without an account). For consent-based processing (e.g. optional usage analytics, see section 8), consent given by children is only effective once they have reached the age of 16; for younger children, the consent of those holding parental responsibility is required (Art. 8 GDPR). Concluding a paid contract (Pro license) requires full legal capacity (having reached the age of 18) or the consent of the legal representatives (§§ 104 et seq. German Civil Code).

5. Cloud Storage

As soon as you are logged in, you can save a GRAFCET to Supabase on EU servers with a single click on "Save to cloud". From that point on, this GRAFCET is automatically synchronized (autosave) until you delete it (free accounts: up to 3 GRAFCETs; Pro: unlimited). Stored are the name and content of your GRAFCET (steps, transitions, actions and the associated editor state) as well as technical management data: the assigned account identifier, the time of creation and modification, and a technical share token for the optional sharing feature. Your stored GRAFCETs are in principle only accessible to you as an authenticated user. However, if you actively create a share link for a GRAFCET, anyone who has that link can open a copy of that GRAFCET without logging in. As long as you do not create a share link, the GRAFCET remains private. You can end a sharing permission once granted at any time; the previous share link then becomes invalid and the GRAFCET is private again. If a Pro license expires, the account falls back to the free allowance of 3 cloud GRAFCETs. GRAFCETs exceeding this allowance remain stored and retrievable for a transition period of 90 days. Within this period, you can export or download all your GRAFCETs at any time (individually or together as a ZIP archive). After the 90 days have elapsed, the GRAFCETs exceeding the free allowance are automatically deleted; the 3 most recently edited GRAFCETs are retained. You are informed in advance by email about the upcoming deletion. You can delete your cloud data yourself at any time.

6. Payment Processing

Payments are processed by Paddle (Paddle.com Market Limited); Paddle acts as Merchant of Record and thus as the legal reseller of the license. The contractual partner of the purchase contract is Paddle; payment processing, including tax and invoicing, takes place entirely there. In terms of data protection law, Paddle is an independent controller (Art. 4(7) GDPR) for processing the purchase contract and the payment and — in line with the reseller construction — is not a processor of the provider. Insofar as data is transmitted to Paddle to initiate the checkout (in particular your email address), or the provider receives the order data named above from Paddle, the legal basis is Art. 6(1)(b) GDPR (performance of the usage/license contract; provision and management of the license key). Paddle's own data processing is governed by its privacy policy. To create and manage the license, the provider processes from the order only the data required for this purpose: email address, transaction or order ID, the purchased variant and quantity (e.g. annual or monthly license, number of keys) and a link to the invoice; in the case of a refund, additionally the refunded amount. Credit card data or other payment information is never received by the provider; it is processed exclusively by Paddle or its payment service providers. As an alternative to direct checkout, schools, universities and companies in particular can pay by invoice (payment within 14 days by bank transfer). For invoicing, the provider processes the data you provide (e.g. name or contact person, email address, name of the institution and — if provided — order/reference number); the invoice is issued via Paddle. Legal basis: Art. 6(1)(b) GDPR (initiation and performance of the contract). Paddle privacy policy: https://www.paddle.com/legal/privacy Volume licenses: When purchasing multiple licenses, you receive multiple independent individual license keys, which are delivered to you as a list by email and which you activate individually. There is no central license management, no administrator or seat roles, and no substantive link between the keys; only the shared transaction or order ID of the purchase allows a connection between the keys to be recognized. The provider therefore processes no data about the subsequent distribution or the individual users of the keys, even in the case of a volume purchase. When you activate a license key in the account panel, the provider additionally stores the time of your express consent, the applicable version (version identifier) and a checksum (hash) of the consent text. The full wording of each version is kept in the provider's database (Supabase, EU). This information is the evidence trail for the early lapse of the right of withdrawal under § 356(5) German Civil Code. Legal basis: Art. 6(1)(b) GDPR (performance of contract). You additionally receive this consent as well as the notice on the lapse of the right of withdrawal by confirmation email (durable medium under § 126b German Civil Code). As long as you do not activate a license key, your 14-day right of withdrawal remains in place; you can return an unactivated key within this period via the self-service form (see the Withdrawal Policy).

7. Email Communication and Forms

Transactional and authentication emails (e.g., license key delivery, account notifications, password reset) are sent via Resend (Plus Five Five, Inc., USA). The transfer to the USA is safeguarded by the EU-US Data Privacy Framework and standard contractual clauses. Only your email address is shared with Resend. The contract-related service emails also include a reminder when your Pro license is about to expire or has expired. This reminder is purely service/contractual information (not a promotional offer) and is sent on the basis of Art. 6(1)(b) GDPR (contract handling); no separate consent is required for this. Any discount or renewal offers are displayed exclusively in the logged-in account area and are not sent by email. Promotional emails (marketing) are only sent with your explicit consent. The forms on this website — the contact form on the "Contact" page, the cooperation enquiry, the feedback form in the editor and waitlist forms (e.g. for announced features) — are operated by the provider itself; no third-party forms are embedded. The entries are stored in the provider's own database at Supabase (location: EU, Frankfurt). The information you enter (e.g. email address and message) as well as language and country are processed; for contact and cooperation enquiries the provider additionally receives a notification by email (sent via Resend, see above). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in capturing and handling form submissions and, in the case of waitlists, in notifying about announced features).

8. Cookies, Reach Measurement and Other Technical Services

In basic operation this website uses only technically necessary cookies (e.g. authentication session). Any further cookies are set only with your consent. LocalStorage is used to store your current GRAFCET and editor settings. Without your consent, no cookies are used for tracking or marketing purposes and no services for cross-device recognition are employed. Only an anonymous, cookieless reach measurement (see below) takes place without consent; it does not access your device and does not allow you to be identified. For usage analytics the provider uses PostHog (PostHog Inc., EU region eu.i.posthog.com). The analysis is two-tiered: (1) Without your consent, only an anonymous, cookieless reach measurement is performed. No cookies are set and no access to your device takes place (no cookie or local-storage access). Only page views are counted; recurring visitors are estimated via a server-side, daily-rotating hash value (derived from, among other things, IP address and browser identifier) that is deleted at the end of the day and does not allow you to be identified. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in a data-minimizing, anonymous reach measurement). (2) Only with your explicit consent are additional individual events, persistent identifiers, session recordings (session replays) and error reports captured, with all input fields (e.g., passwords and email addresses) masked. The legal basis for this is Art. 6(1)(a) GDPR (consent) in conjunction with Section 25(1) TDDDG. The consent banner is provided by Cookiebot (Cybot A/S, Denmark). You can withdraw your consent at any time via the "Cookie settings" link in the footer. See the Cookie Policy for details.

9. Other Services and Recipients

Hosting & CDN: The site runs on Vercel Inc. (USA). Vercel processes connection and server log data (including IP address, user agent, request URL) for delivery and abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Transfer to a third country: EU-US Data Privacy Framework and Standard Contractual Clauses. Bot and spam protection (Cloudflare Turnstile): To protect the login, registration and password-reset forms against automated misuse, Cloudflare Turnstile (Cloudflare, Inc., USA) is used. It processes technical data such as IP address, browser identifier and interaction signals; Turnstile works without tracking cookies. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in defending against bots and spam). Transfer to a third country: EU-US Data Privacy Framework and standard contractual clauses. Privacy policy: https://www.cloudflare.com/turnstile-privacy-policy/ Amazon Partner Program (affiliate links): On the "Recommendations" page, links to amazon.de are marked as advertising. Only when you actively click such a link will you reach Amazon — until then no cookies are set and no data is transmitted to Amazon (no preconnect, no embedded script). Once you click an affiliate link, Amazon's privacy notice applies (Amazon Europe Core S.à r.l., Luxembourg): https://www.amazon.de/gp/help/customer/display.html?nodeId=GVP69FUJ48X9DK8X.

10. Subprocessors (overview)

The following providers process personal data on behalf of grafcet.io (processors under Art. 28 GDPR) or are recipients within the meaning of Art. 13 GDPR. An exception is Paddle: as Merchant of Record and reseller, Paddle is an independent controller for the purchase processing (Art. 4(7) GDPR), not a processor (see section 6). Third-country transfers to the USA are safeguarded by the EU-US Data Privacy Framework and/or standard contractual clauses. Supabase Inc. — authentication, database, cloud storage, form submissions. Location: EU (Frankfurt). Data: email, password hash, profile, licences, stored GRAFCETs, form entries. No third-country transfer. Vercel Inc. — hosting, CDN, cron jobs. Location: USA. Data: server/request logs, IP address (short-term), user agent. Safeguard: DPF + standard contractual clauses. Cloudflare, Inc. — bot/spam protection in the auth flow (Turnstile). Location: USA. Data: IP address, browser identifier, interaction signals. Safeguard: DPF + standard contractual clauses. Paddle.com Market Limited — payment processing (Merchant of Record / reseller; independent controller, not a processor). Location: United Kingdom. Data: email, transaction ID, payment status (no cardholder data). Safeguard: EU adequacy decision (United Kingdom). Resend (Plus Five Five, Inc.) — transactional and authentication emails. Location: USA. Data: email address. Safeguard: DPF + standard contractual clauses. PostHog Inc. — reach measurement and (consent-gated) usage analytics. Location: EU hosting (Frankfurt); provider USA. Data: without consent an anonymous daily hash and page views; with consent session ID, events, URLs, session replays (passwords masked). Safeguard: EU data residency, additionally standard contractual clauses. Cybot A/S (Cookiebot) — consent management. Location: EU (Denmark). Data: consent choices, cookie ID. No third-country transfer. Google Ireland Ltd. — optional OAuth login and embedded YouTube videos (click-to-load via youtube-nocookie.com). Location: EU/USA. Data: email and Google account ID (login); for YouTube additional usage data after a click. Safeguard: DPF + standard contractual clauses. On request the provider will provide a data processing agreement (DPA): hi@grafcet.io.

11. Your Rights

Under the GDPR, you have the following rights: Right to information (Art. 15 GDPR) Right to rectification (Art. 16 GDPR) Right to deletion (Art. 17 GDPR) Right to data portability (Art. 20 GDPR) Right to object (Art. 21 GDPR) Right to restriction of processing (Art. 18 GDPR) Right to withdraw consent with effect for the future (Art. 7(3) GDPR) Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — the competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA) Contact: hi@grafcet.io

Version v2 · As of August 2026