GDPR Compliance
This page sets out how PivotHero complies with the General Data Protection Regulation (Regulation (EU) 2016/679, 'GDPR') and the equivalent UK regime, for individuals located in the European Union, the European Economic Area, and the United Kingdom. It is intended to be read alongside our Privacy Policy, which addresses our data-handling practices more generally; this page focuses specifically on the legal rights GDPR affords you and how to exercise them.
Is PivotHero GDPR compliant?
PivotHero is designed and operated with the principles of GDPR in mind: data minimisation, purpose limitation, storage limitation, and accountability. We act as the data controller in respect of the account and billing information you provide to us directly, and as a data processor in respect of the content of spreadsheets you upload for the purpose of generating reports on your instruction. Compliance is an ongoing obligation rather than a static claim, and we welcome being held to it — if you believe any aspect of our practice falls short, contact us using the details below.
What is PivotHero's lawful basis for processing personal data under GDPR?
We rely on the performance of a contract (GDPR Article 6(1)(b)) as the lawful basis for processing the personal data necessary to create your account, operate your subscription, and generate the reports you request. Where you have given consent, such as for optional analytics or advertising cookies, we rely on consent (Article 6(1)(a)), which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal. Where applicable, we rely on legitimate interests (Article 6(1)(f)) for narrowly scoped purposes such as fraud prevention and maintaining the security of the Service, balanced against your rights and freedoms.
What personal data does PivotHero process as a data controller?
As data controller, we process the name, email address, country, and hashed password associated with your account; payment metadata such as invoice numbers, amounts, and payment status (full card details are processed by Stripe, our payment processor, and are never received by PivotHero); and correspondence you send us, such as support tickets and contact form submissions. Where you upload a spreadsheet containing personal data of third parties, such as customer or employee records, PivotHero processes that data as a processor acting on your instructions as controller of that data — you remain responsible for ensuring you have a lawful basis to upload it.
What are my rights as a data subject under GDPR?
Articles 15 to 22 of GDPR grant you the following rights in respect of your personal data: the right of access, to obtain confirmation of whether we process your data and a copy of it; the right to rectification, to have inaccurate data corrected; the right to erasure, to have your data deleted where certain conditions are met; the right to restriction of processing, to limit how we use your data in specified circumstances; the right to data portability, to receive your data in a structured, commonly used format; the right to object to processing carried out on the basis of legitimate interests; and rights related to automated decision-making, addressed separately below. None of these rights is absolute, and each is subject to the conditions and exemptions set out in GDPR itself.
How do I submit a GDPR data subject access request to PivotHero?
Email support@getpivothero.com from the address associated with your account, stating which right you wish to exercise. We will take reasonable steps to verify that the request genuinely originates from the data subject before acting on it, in order to protect your data from unauthorised access by a third party purporting to be you. There is no charge for a standard request; we reserve the right, as GDPR permits, to charge a reasonable administrative fee or decline a request that is manifestly unfounded or excessive, such as one made repeatedly with no substantive change in circumstances.
How long does PivotHero take to respond to a GDPR request?
In accordance with Article 12(3) of GDPR, we respond to data subject requests within one calendar month of receipt. Where a request is particularly complex or we have received a high volume of requests, this period may be extended by a further two months; if so, we will inform you of the extension and the reason for it within the initial one-month period.
Does PivotHero transfer personal data outside the EEA?
Because PivotHero relies on service providers that operate internationally, including our payment processor and hosting infrastructure, your personal data may be transferred to and processed in a country outside the EEA or UK. Where such a transfer occurs, we rely on the safeguards recognised under GDPR Chapter V, principally the European Commission's Standard Contractual Clauses, or a provider's participation in a recognised adequacy framework, to ensure your data continues to receive a level of protection essentially equivalent to that guaranteed within the EEA.
How long does PivotHero retain my personal data under GDPR?
We retain personal data for as long as your account remains active, in order to provide the Service, and for a limited period thereafter as required to comply with legal, tax, or accounting obligations, or to resolve disputes. Upon a verified deletion request, or upon closure of your account, personal data is deleted or irreversibly anonymised within a reasonable period, save where retention is separately required by law.
Does PivotHero use automated decision-making or profiling?
PivotHero's AI recommendation engine analyses the structure of a spreadsheet you upload, at your instruction, in order to suggest an appropriate pivot table configuration. This does not constitute automated decision-making producing legal or similarly significant effects on a data subject within the meaning of GDPR Article 22: the analysis concerns the shape of your data, not an evaluation of you as an individual, and no decision is made about you, your eligibility for anything, or your legal standing. PivotHero does not use profiling to make decisions about individuals.
What happens if there is a personal data breach?
In the event of a personal data breach likely to result in a risk to your rights and freedoms, PivotHero will notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with GDPR Article 33, and will notify affected individuals directly without undue delay where the breach is likely to result in a high risk, in accordance with Article 34.
Who is PivotHero's data protection contact?
Enquiries regarding this page, or the exercise of any right described here, should be directed to support@getpivothero.com. PivotHero has not appointed a statutory Data Protection Officer, as this is not presently a mandatory requirement given the nature and scale of our processing activities; this position is kept under periodic review.
How do I lodge a complaint with a supervisory authority?
If you are not satisfied with our response to a request, or believe our processing of your personal data infringes GDPR, you have the right to lodge a complaint with the data protection supervisory authority in your country of habitual residence, place of work, or the place of the alleged infringement. We would, however, welcome the opportunity to address your concern directly in the first instance.