Privacy Policy
Last updated: 5 October 2026
This is an English translation provided for your convenience. Only the German version is legally binding; in case of any discrepancy, the German version prevails.
In this privacy policy we inform you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process when you visit our website, contact us, apply to work with us or work with our apps and web dashboard as a self-employed delivery partner, why we do so and what rights you have.
For readability we refer to self-employed delivery partners simply as “partners”.
At a glance
- The controller is PJ Logistik GmbH in Vienna, Austria. For any privacy question, contact us at info@pjlogistik.at.
- Website: we use no analytics, tracking or marketing cookies. Google Maps is only loaded once you click it.
- Applicants and partners: we process the data we need for your application, contract, assignments, invoicing and payouts – including your identity and trade documents.
- Location: our servers, databases and files run on Google Cloud in the EU (Belgium region).
- Artificial intelligence: we use Google Vertex AI (Gemini) in the EU for document recognition, our assistant and translations. Decisions with legal or similarly significant effects are always taken by a human.
- Deletion: you can request the deletion of your account in the app. What the law requires us to keep, we keep for 3 or 7 years and then delete.
- Your rights: access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and a complaint to the data protection authority.
1. Controller and contact
The controller responsible for processing your data (Art. 4(7) GDPR) is:
PJ Logistik GmbH
Gablenzgasse 21
1150 Vienna, Austria
Company register number: FN 537261 s
VAT ID: ATU75750509
Email: info@pjlogistik.at
Phone: +43 660 536 9990
We have not appointed a data protection officer, as we are not legally required to do so. For any data protection matter – in particular to exercise your rights – please contact info@pjlogistik.at.
2. Who this privacy policy applies to
This privacy policy applies to the processing of personal data of
- visitors to our website pjlogistik.at (section 3),
- people who use our AI assistant or send us an inquiry (section 4),
- applicants who register through our apps or our web dashboard (section 5), and
- self-employed partners who use our iOS and Android apps, our web dashboard (dashboard.pjlogistik.at) and, where applicable, our Telegram bot (section 6).
The sections on artificial intelligence, legal bases, recipients, retention, account deletion and your rights apply to all of these groups.
3. Visiting our website
Providing the website
Our website is delivered through Firebase Hosting, a Google service. When you open a page, technically necessary data are processed, in particular your IP address, the date and time of access, the address requested and information about your browser and operating system. These data are needed to deliver the website and to keep it secure, for example to fend off attacks. The content is delivered over a worldwide server network, so your IP address may also be processed outside the EU (section 9).
The legal basis is our legitimate interest in a functioning and secure website (Art. 6(1)(f) GDPR).
No analytics or marketing cookies
We use no analytics, tracking or advertising services on our website and set no cookies for such purposes. No profiling takes place on the website.
In your browser’s local storage we store only the following – and only if you use the feature concerned:
- the history of your conversation with the AI assistant together with a randomly generated conversation ID; the history is discarded automatically 24 hours after the conversation started,
- your chat window preferences (position and docking).
This storage is strictly necessary to provide the service you have explicitly requested (§ 165(3) of the Austrian Telecommunications Act 2021, TKG 2021) and therefore does not require consent. This is also why we do not show a cookie banner. You can delete these entries at any time in your browser settings.
Google Maps (only after you click)
In the contact section you can display a Google Maps map. The map is only loaded when you click “Load map”. Only then is a connection to Google’s servers established; Google receives in particular your IP address and may set or read cookies. Google may also process these data in the USA (section 9).
The legal basis is your consent (Art. 6(1)(a) GDPR, § 165(3) TKG 2021), which you give by clicking. We do not store this choice: on a new page view the map is only loaded after another click. You can withdraw your consent at any time with effect for the future by not loading the map again and deleting any cookies set by Google in your browser. For more information see Google’s privacy policy.
Links to other services
Our website contains links, for example to WhatsApp, Google Maps or our web dashboard. Data are only transmitted to the provider concerned if you follow such a link.
4. AI assistant and inquiries to our office
Public AI assistant
On our website and in our apps (before you sign in), an AI assistant answers questions about applying as a partner and about contacting us. You are communicating with an AI system, not with a human. The assistant can make mistakes; only information from our office is binding.
To answer, your messages are sent to Google Vertex AI (Gemini) in the europe-west1 region (Belgium). We store your messages and the assistant’s replies for 90 days from the last message in order to detect misuse and to review and improve the quality of the answers; our staff can view these conversations. Together with the conversation log we store neither your IP address nor any other identifier, only a randomly generated conversation ID. Your IP address is processed only to limit the number of requests (protection against misuse) and in short-lived server logs.
Please do not enter sensitive data in the chat, such as identity or bank details. For your contact details the assistant provides a separate form (see below). At your request the assistant can trigger a password-reset email to the address you name, provided an account exists for it.
Legal bases: where you are asking about working with us, steps prior to entering into a contract (Art. 6(1)(b) GDPR); otherwise our legitimate interest in answering inquiries efficiently, in quality assurance and in preventing misuse (Art. 6(1)(f) GDPR).
Inquiries via the form, by email or by phone
If you send us an inquiry through the form in the assistant, we process your name, your email address, optionally your phone number, your message and any attachments (photos or PDF documents). So that our office quickly understands your request, it also receives the chat history so far and an AI-generated summary; the details in the form itself are not read by the AI assistant. Through a personal link you can view and reply to your inquiry; messages there can be machine-translated at your request.
If you wish, we notify you by email as soon as our office replies. The legal basis for this is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future.
If you contact us by email or phone, we process your details to handle your request.
Depending on your request, the legal basis is steps prior to entering into a contract or the performance of a contract (Art. 6(1)(b) GDPR), or our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR).
If you write to us on WhatsApp, your messages are transmitted through this messaging service; the service itself is governed by its provider’s terms of use and privacy policy, and the provider may process data (in particular metadata) outside the EU as well. Using WhatsApp is voluntary – you can always reach us by email or phone instead. Our own processing of your messages is based on the legal bases mentioned above.
5. Application and registration
When you apply as a partner, you create an account in our app (iOS, Android) or in our web dashboard. We process:
- Account data: email address, phone number and password (we store passwords only as a cryptographic hash); when you sign in with Google or Apple, the identifier, name and email address that provider sends us,
- Identity and master data: first and last name, date of birth, social security number and home address,
- Business data: bank details (IBAN, BIC, account holder), VAT ID, GISA number (Austrian trade register) and your vehicle’s licence plate,
- Documents: identity card, passport or residence permit, e-card, driving licence, registration certificate (Meldezettel), trade licence, vehicle registration, proof of insurance and proof of your VAT ID, together with the details read from them (e.g. name, date of birth, document number, validity, nationality and type of residence permit),
- Verification data: codes confirming your email address, together with the IP address from which the code was requested and redeemed.
AI document recognition: uploaded documents are analysed with Google Vertex AI (Gemini) in the EU. This checks whether it is the right document and whether it is legible; the details recognised are extracted to pre-fill your data and to make the review easier. If a document is illegible or does not match, the app asks you to upload it again. Our staff decide on your application after their own review.
Checks in public registers: we check your trade licence in the Austrian trade register (GISA) and your VAT ID in the EU VAT information exchange system (VIES). For this we transmit the GISA number or VAT ID to the body concerned and receive the related register entries from it.
Protection against misuse: on the sign-in and registration pages of the web dashboard we use Google reCAPTCHA Enterprise (see “Web dashboard” in section 6).
The legal bases are steps prior to entering into a contract (Art. 6(1)(b) GDPR) and – for checking your trade licence and VAT ID – compliance with obligations under trade and VAT law (Art. 6(1)(c) GDPR).
If we do not end up working together, you can request the deletion of your account at any time; the procedure described in section 11 applies.
6. Working with us as a partner
As a self-employed partner, you handle your work with us through our apps and our web dashboard. In addition to the data listed in section 5, we process the following.
Contract
Your contract including addenda, your electronic signature (the name you type and the date of signing) and the PDF documents generated from them. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
Assignments and performance data
From the delivery platforms you deliver for (e.g. Foodora) we receive assignment and performance data, such as your rider ID, completed orders, times and breaks, cancellations, delivery-speed evaluations as well as complaints and deductions. We use them for invoicing, quality assurance and to meet the platforms’ requirements. We keep the platforms’ raw data for 3 months.
If contractual obligations are breached, warnings (“strikes”) may be issued or restrictions imposed. The system may highlight anomalies and make recommendations, but the decision is always taken by a member of staff after review.
The legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in proper, quality-assured performance (Art. 6(1)(f) GDPR).
Invoicing and payouts
We process invoices and credit notes, your account statement (e.g. payouts, deductions, deposits and equipment issued) and payment data. Payouts are made by SEPA transfer through our bank; for this we transmit in particular your name, IBAN, BIC and the amount. We also send you invoices and credit notes by email. Our accounting records are received by our tax adviser or accountant.
The legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and statutory record-keeping and retention obligations (Art. 6(1)(c) GDPR in conjunction with § 132 of the Austrian Federal Fiscal Code (BAO) and § 212 of the Austrian Commercial Code (UGB)).
Support, tickets and chats
When you contact our office through tickets or chats, we process your messages, voice messages and attachments. Messages can be machine-translated, and AI-generated summaries of tickets are created for our staff. We store tickets and chats encrypted. The app only accesses the microphone when you record a voice message, and photos and files only when you select or save them yourself.
The legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and – for translations and summaries – our legitimate interest in handling your requests efficiently (Art. 6(1)(f) GDPR).
AI assistant in the app, web dashboard and Telegram
Once you are signed in, an AI assistant is available to you. You are communicating with an AI system, not with a human. To answer your questions, the assistant can access the data in your account (e.g. your profile including bank details, invoices or tickets) and open tickets for you. Conversations are stored and can be viewed by our staff, for example to follow up on your request or to review quality.
To prevent misuse, the system evaluates behaviour in the conversation. In the event of clearly abusive behaviour, access to the assistant can be paused automatically; all other features remain unaffected. Our staff can restore access – please contact our office.
For image suggestions the assistant may send a search term to Google’s image search. In the web dashboard, the icons of linked websites are loaded from Google’s servers; Google receives your IP address in the process.
The legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in fast, multilingual support and in preventing misuse (Art. 6(1)(f) GDPR).
Feedback
You can also give feedback anonymously. We remove metadata (e.g. the location where a photo was taken) from uploaded photos. Feedback is checked automatically with AI for inadmissible content. The legal basis is our legitimate interest in improving our processes (Art. 6(1)(f) GDPR).
Notifications, emails and Telegram
We send push notifications via the Apple Push Notification service (iOS) or Google’s Firebase Cloud Messaging (Android); for this we store a device token. You only receive push notifications if you have allowed them in your device settings; you can withdraw this permission there at any time (Art. 6(1)(a) GDPR).
We send emails – such as verification codes, invoices and credit notes or replies to inquiries – through the Gmail interface of Google Workspace.
Optionally, you can link your account to our Telegram bot. We then store your Telegram chat ID and your notification settings and send you notifications via Telegram; messages to the bot may be answered by the AI assistant. We only send invoice information via Telegram with your express consent. The legal basis is your consent (Art. 6(1)(a) GDPR); you can remove the link at any time with the /unlink command or in your profile.
Sign-in, device data, security and error reports
- Sign-in sessions: we store your sign-in sessions per device so that you stay signed in and individual sessions can be ended specifically.
- App PIN and Face ID: we store your app PIN only as a cryptographic hash. Face ID, Touch ID and other biometric methods run exclusively on your device; we receive no biometric data.
- IP addresses: to prevent misuse (e.g. to limit sign-in attempts), with verification codes and when approving devices.
- Error reports: if an error occurs in the app or the web dashboard, we transmit an error report with technical details (e.g. device type, operating system and app version, page opened) and your user ID, but without your IP address.
The legal basis is our legitimate interest in secure and error-free operation (Art. 6(1)(f) GDPR).
Web dashboard
In the web dashboard we store your sign-in tokens and a device identifier in your browser’s local storage so that you stay signed in and your device is recognised. When you sign in (in particular with Google or Apple) we set technically necessary cookies that, depending on their purpose, are kept for a few minutes, for the duration of the sign-in or for up to 30 days. This storage is strictly necessary for the service you have requested (§ 165(3) TKG 2021).
On the sign-in, registration and contract-signing pages we use Google reCAPTCHA Enterprise to fend off automated access (bots). Google processes in particular your IP address and information about your browser and device, and may also process these data in the USA (section 9). The legal basis is our legitimate interest in protecting our services against misuse (Art. 6(1)(f) GDPR).
7. Use of artificial intelligence
We use AI models (Gemini) through the Google Vertex AI service. Processing takes place in the Google Cloud region europe-west1 (Belgium); Google acts as our processor and, under the contractual terms, does not use the content to train its own AI models. We use AI for
- recognising and checking uploaded documents and receipts,
- the AI assistant on the website, in the apps, in the web dashboard and in the Telegram bot,
- translating messages, tickets and inquiries,
- summaries of tickets and inquiries for our staff and wording suggestions for their messages, and
- checking feedback for inadmissible content.
Transparency: wherever you communicate with an AI system, we tell you so (Art. 50 of the EU AI Act). AI output can be wrong; what counts is your contract, your statements and the information given by our office.
No solely automated decisions: we take no decisions that produce legal effects concerning you or similarly significantly affect you based solely on automated processing (Art. 22 GDPR). In particular:
- The AI checks documents for type and legibility and may ask for a new photo; our staff decide on applications.
- Warnings and restrictions are decided by our staff.
- An automatic pause only affects the AI assistant and can be lifted by our office.
Depending on the purpose, the legal bases are the performance of the contract or steps prior to entering into it (Art. 6(1)(b) GDPR) and our legitimate interest in efficient, multilingual and secure processing (Art. 6(1)(f) GDPR).
8. Legal bases at a glance
| Legal basis | What we use it for |
|---|---|
| Contract and pre-contractual steps (Art. 6(1)(b) GDPR) | Registration and application, contract, assignments, invoicing and payouts, support |
| Legal obligation (Art. 6(1)(c) GDPR) | Retention of books and records (§ 132 BAO, § 212 UGB), checks of trade licence and VAT ID |
| Legitimate interests (Art. 6(1)(f) GDPR) | IT security, fraud and misuse prevention, rate limiting, error diagnostics, AI translations and summaries for efficient handling, quality assurance of performance with human review, defence of legal claims |
| Consent (Art. 6(1)(a) GDPR) | Telegram notifications (incl. invoice information), push notifications, Google Maps on the website, email notifications about inquiries – revocable at any time with effect for the future |
Where we rely on legitimate interests, you may object to the processing at any time on grounds relating to your particular situation (section 12).
9. Recipients and transfers to third countries
Within our company, only those people who need your data for their tasks have access to it. We only pass data on to bodies outside our company where this is necessary for the purposes described:
| Recipient | Purpose | Place of processing |
|---|---|---|
| Google Cloud (processor) | Servers, databases and file storage (Cloud Run, Cloud SQL, Cloud Storage); AI service Vertex AI (Gemini) | EU – region europe-west1 (Belgium) |
| Google – Firebase Hosting (processor) | Delivery of the website and the web dashboard | worldwide server network, also outside the EU |
| Google – Google Workspace / Gmail (processor) | Sending emails | EU; processing outside the EU possible |
| Google – Sign-In, reCAPTCHA Enterprise, Firebase Cloud Messaging, Maps, image search and website icons | Sign in with Google, bot protection, push notifications (Android), map display, assistant features | worldwide, including the USA |
| Apple | Sign in with Apple, push notifications (iOS) | worldwide, including the USA |
| Telegram (only if you use the bot) | Delivery of notifications and bot messages | also outside the EU |
| Our bank (Erste Bank) | Payouts by SEPA transfer | Austria |
| Tax adviser and accountant | Bookkeeping, annual accounts, tax obligations | EU |
| IT service provider (processor under Art. 28 GDPR) | Development, operation and maintenance of our systems | EU |
| Partner logistics companies involved in handling assignments | Organising and handling delivery assignments, invoicing | EU |
| Delivery platforms you deliver for (e.g. Foodora) | Handling of assignments where necessary; also the source of assignment and performance data | EU |
| Authorities and public registers (e.g. GISA, VIES, tax authorities) | Checks of trade licence and VAT ID; compliance with legal obligations | Austria / EU |
Transfers to third countries: our core data – databases, files and AI processing – stay in the EU (region europe-west1, Belgium). With the global services of Google and Apple and with Telegram, however, data may also be processed outside the EU/EEA. We base transfers to the USA on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the EU standard contractual clauses (Art. 46(2)(c) GDPR). Using Telegram is voluntary; for the related transfer we rely on your explicit consent (Art. 49(1)(a) GDPR). Please note that third countries may not offer a level of data protection equivalent to the EU and that authorities there may find it easier to access data.
10. Retention
We keep personal data only for as long as is necessary for the purpose concerned or as statutory retention obligations require:
| Data | Retention period |
|---|---|
| Public AI assistant chat history in your browser | 24 hours from the start of the conversation |
| Conversations with the public AI assistant on our servers | 90 days from the last message |
| Inquiries to our office (form, email, phone, WhatsApp) | as long as necessary to handle your request; if the inquiry leads to working together, the periods for partners apply |
| Raw assignment and performance data from the delivery platforms | 3 months |
| Account, contract and invoicing data, documents, tickets and chats | for as long as your account exists; after its deletion as set out in the following rows |
| Login, device and app data (e.g. password hash, app PIN, sign-in sessions, device tokens, notifications and settings, profile picture, feedback, warnings and performance evaluations, links to Google, Apple and Telegram) | removed when your account is deleted |
| ID card, driving licence and other proof of identity (passport or residence permit, e-card, registration certificate) as well as support tickets and chats (including conversations with the AI assistant) | 3 years from the end of the calendar year in which the account was deleted (defence of legal claims, § 1489 of the Austrian Civil Code, ABGB); then deleted |
| Invoices, credit notes, payment records, contracts and business details (e.g. name, date of birth, address, social security number, bank details, VAT ID, GISA number, licence plate and the remaining documents) as well as tickets about invoices | 7 years from the end of the calendar year of the last business transaction or of the account deletion (§ 132 BAO, § 212 UGB); then deleted |
To prove the deletion we keep a deletion log; once all periods have ended it no longer contains any personal data.
11. Deleting your account
You can request the deletion of your account yourself at any time – in the app under Settings → Danger zone → Delete account, and likewise in the web dashboard – or contact our office.
- Your request will be sent to our office. Your account will be deleted after 30 days; until then you can still sign in and ask our assistant to keep your account.
- Until it is deleted, your account is restricted. You can still use the assistant, your support tickets and the settings.
- When your account is deleted, your login, device and app data are removed.
We keep only what the law requires:
- ID card, driving licence, support tickets and chats – 3 years (defence of legal claims)
- Invoices, credit notes, payment records and business details – 7 years (tax law)
After that, these are deleted as well. You will find the exact periods in section 10. You can register again later with the same details.
12. Your rights
Under the GDPR you have the following rights:
- Access to the data we process about you (Art. 15 GDPR),
- Rectification of inaccurate or incomplete data (Art. 16 GDPR),
- Erasure of your data, unless statutory retention obligations or other grounds prevent it (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability, i.e. receiving the data you have provided to us in a structured, commonly used and machine-readable format (Art. 20 GDPR),
- Objection to processing based on our legitimate interests, on grounds relating to your particular situation (Art. 21 GDPR),
- Withdrawal of any consent given, at any time with effect for the future; this does not affect the lawfulness of processing carried out before the withdrawal (Art. 7(3) GDPR).
To exercise your rights, an informal message to info@pjlogistik.at is sufficient. To protect your data we may ask you to prove your identity. We reply within one month (Art. 12(3) GDPR).
Right to lodge a complaint: if you believe that the processing of your data infringes data protection law, you can lodge a complaint with the supervisory authority. In Austria this is the Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40–42, 1030 Vienna, email: dsb@dsb.gv.at, website: www.dsb.gv.at.
13. Obligation to provide data and minimum age
The data we need for your application, the contract and invoicing are required to conclude and perform the contract; without them we cannot take you on as a partner. All other information – for example in the AI assistant, in feedback or for optional notifications – is voluntary.
Our apps and services are not intended for persons under 18.
14. Data security
We protect your data with technical and organisational measures. These include in particular encrypted transmission (TLS) on all connections, encrypted storage of tickets and chats, storing passwords and app PINs only as hashes, device-bound sign-in sessions and graduated access rights for our staff.
15. Changes to this privacy policy
We update this privacy policy when our data processing or the legal situation changes. The version published on this page applies; the date of the current version is shown at the top. We additionally inform partners of material changes that affect them in an appropriate manner.
